Visual interlocking specifications for industrial automation
By visualizing rules in the industrial process, the security engineers’ trust problem in automatic interlocking algorithms is solved, and faster and more accurate engineering design and higher trust levels are achieved.
Patent Information
- Application Number
- CN202180055901.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-10-08
- Filing Date
- 2021-08-26
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2041-08-26
AI Technical Summary
In industrial processes, safety engineers and others lack trust in the automatically running interlocking algorithm, leading to a possible regression to time-consuming and error-prone manual interlocking specification.
By providing a method to visualize rules of industrial processes or processing systems, including providing topological models, assigning attributes to the model, marking reasons, traversing and results, and visualizing elements of these rules.
Improves access to industrial plant and process behavior, provides visual feedback, reduces engineering design time, reduces error risk, and improves trust.
Smart Images

Figure CN116097629B_ABST
Abstract
Description
Technical Field
[0001] The invention relates to the field of methods for industrial processes, in particular for industrial plants and / or processes, such as chemical, mechanical and / or other production and / or treatment processes. The invention also relates to a computer-readable storage medium, an artificial neural network ANN and uses. Background Art
[0002] To describe industrial plants and / or processes, so-called "interlocks" are used in many cases. Algorithms can implement interlock specifications, for example, by taking a plant topology model from a process engineer as the basis for their construction. However, in at least some cases (e.g., where they are run automatically), safety engineers, service personnel, and / or other personnel whose work is related to these plants and / or processes may not trust these algorithms and may therefore fall back on manual interlock specifications, which may be time-consuming, labor-intensive, and prone to errors. Summary of the invention
[0003] Therefore, it is an object of the present invention to provide an improved capability for inspecting the behavior of industrial plants and / or processes. This object is achieved by the subject matter of the independent claims. Further embodiments are evident from the dependent patent claims and the following description.
[0004] One aspect relates to a method for visualizing rules of an industrial process or a processing system. The method comprises the following steps:
[0005] Providing a topological model of an industrial process or treatment system, wherein the industrial process or treatment system includes at least one sensor and at least one actuator;
[0006] Use rules to assign attributes to the topological model, where the rules include the triple <cause, traversal, result>,
[0007] in
[0008] The reason includes a range of values from at least one sensor,
[0009] The result includes an action performed by at least one actuator, and
[0010] Traversal includes the relationship between cause and effect;
[0011] Marking causes, traversals, and / or results; and
[0012] Visualize the elements of the rules in the topology model.
[0013] The industrial process may be an industrial automation application and / or an industrial process, in particular an industrial automation application and / or an industrial process in an industrial plant (e.g., in a chemical, mechanical and / or other production and / or processing process). The rule (or rules) may be part of a so-called interlocking specification, which describes at least some aspects of the industrial process. The rules may link two or more devices, for example, linking two or more devices based on the functions of the devices being interlocked. At least some interlocking specifications may include rules, which may represent the relationship of the devices, for example, their functions and / or other relationships. The rules may include safety constraints. For example, a pump may be started only when a valve on its outlet is open to prevent overpressure.
[0014] The visualization may be performed on a visual interface of a computing device, for example, on a display, screen, touch screen, projector, etc. The visualization may include generating a visual specification, for example, an interlocking specification. The visualization may be implemented as a computer-implemented method.
[0015] A topological model of an industrial process can describe the elements of a process or plant and their connectivity by visual means, for example, pipes, containers, etc. for carrying fluids and / or media, electrical connections, mechanical connections, logical connections and / or other connections. The topological model includes at least one sensor and one actuator. Of course, these devices of the topological model strongly depend on the type of process or plant they are used for. Sensors can, for example, include metering devices for pressure, temperature, light, sound, etc., including complex devices for distance, flow, chemical analysis and / or other purposes. Actuators can, for example, include switches, valves, heaters, coolers, mixers, etc. configured to produce physical results.
[0016] For the interlocking specification, the topology model has one rule or multiple rules, where each rule includes a triple <cause, traversal, result>.
[0017] The rule may include other entries. The entry "cause" includes a range of values from at least one sensor. The range of values may come directly from one or more sensors, or it may be preprocessed and / or as a result of linking several sensors. Depending on the type of actuator, the entry "result" includes any action (or actions) performed by the actuator. The entry "traversal" includes the relationship between cause and effect. One or more causes may contribute to one or more effects. One or more causes may be connected logically (and, or, ...) and / or in other ways, for example, via functional connections. One or more results may be connected logically and / or in other ways, for example, via functional connections.
[0018] Marking of causes, traversals and / or results may be achieved, for example, by a click on one or more sensors, on one or more actuators, on one or more traversal paths of the topology model and / or another input and / or by marking rules (or "lines") of interlocking specifications. Visualization of elements of rules in the topology model may be achieved, for example, by highlighting the affected components, for example, by coloring the relevant elements and / or their background. Additionally or alternatively, the relevant rules may be shown, for example, on a visual interface of a computing device. The visualization may be accompanied by other actions.
[0019] This can improve the ability to access the behavior of an industrial plant and / or process. It can advantageously facilitate visual interlock specifications that provide visual feedback on algorithmic interlock specifications to safety engineers and / or others working with the process or plant. As other results, the method can allow interlocks to be engineered more quickly, existing domain specific knowledge can be reused, may be less error prone, and significant inconsistencies in specifications (e.g., interlock specifications and / or other specifications of the plant and / or process) can be reduced or avoided.
[0020] In various embodiments, the topology model is attributed using rules based on visual means. This can be performed, for example, by marking causes and effects (e.g., by "clicking" them) and writing and / or programming other relationships between causes and effects in a visual manner. This also helps to intuitively handle the model.
[0021] In various embodiments, the method further comprises the step of approving or confirming the rules (specifically, the interlocks detected by the rules). This can be done by the safety engineer and / or other personnel responsible for the process or plant. This can advantageously contribute to a higher level of confidence in one or more specifications.
[0022] In various embodiments, the method further comprises the step of rejecting the rule, in particular the interlock detected by the rule.This may advantageously be part of a fast and intuitive "commissioning process" of one or more specifications of a process or plant.
[0023] In various embodiments, the method further comprises the step of refining the rule (particularly, the interlock) by performing at least one of the following: adding other causes; adding other results; adding other traversals; and / or adding other elements to the rule. Other elements may be, for example, comments, other outputs (e.g., sound signals, messages, etc.), and / or connections, for example, to a database or another interface. Thus, to be frank, the rule triples may become n-tuples (where n>3). This may advantageously contribute to a more intuitive engineering design of the plant.
[0024] Approvals, rejections and / or refinements may be tracked, for example, by means of a logging diary.
[0025] In various embodiments, the method further comprises the step of generating a topological model of the industrial process from a piping and instrumentation diagram (P&ID) of the industrial process. To date, at least some safety engineers may manually input instrument references from I / O lists and / or P&IDs, and often add free text comments. This manual construction may result in inconsistencies between different artifacts, for example, misspelled instrument references may result in inconsistent P&IDs. As a result of the method as described above and / or below, plant topology information may be derived from the P&IDs, thereby reducing error-prone "media breaks".
[0026] In various embodiments, the topology model includes multiple rules. This can bring the benefit of being able to handle complexity. So far, P&ID, C&E (cause & effect) matrix and / or other means can be used, which may be less intuitive than the method including visualization steps. The cognitive load of analyzing complex P&IDs with thousands of elements and combining various safety regulations and customer requirements may also lead to negligence, for example, missing required interlocks. Although the C&E matrix is usually thoroughly checked, errors or gaps may propagate into the automation system and cause damage to equipment or staff. Further, expensive clarification and feedback loops may be required between safety engineers and control engineers. The rule-based engineering design method using interlocking specifications can provide a good compromise between highly optimized plants and reusable plant knowledge in the form of interlocking rules. However, they may be damaged by insufficient intuitive user feedback on how to apply rules and which subset of plant structure topology is involved. This may be why at least some safety engineers do not rely on these tools. Therefore, the method described above and / or below can help improve this situation.
[0027] In various embodiments, the method further comprises a step of applying at least one step of the method as described above and / or below to each of a plurality of rules. By applying these methods, a check of the integrity of plant behavior can be achieved. Therefore, the semi-automatic method and the system configured to run the method can help enable safety engineers to quickly generate C&E matrices, thereby improving or ensuring correctness via visual feedback. Applying these methods can include feeding P&I diagrams into software tools by process engineers of process plants, wherein the rule engine can process these P&I diagrams based on pre-specified domain-specific rules to generate interlocks. For example, the result can be displayed as a visual overlay of a P&I diagram or a topological model, which includes marking the equipment, process paths, and affected equipment that cause the cause. The process engineer can evaluate the visual representation and approve, reject, correct, and / or otherwise process the generated causal relationship. Due to the high heterogeneity of at least some industrial plants with many possibilities for assembling equipment, the approval step can be advantageous. Further, this can increase the confidence of safety engineers to trust the method.
[0028] In various embodiments, the method further comprises the step of generating a causal C&E matrix from the topological model of the industrial process.This advantageously can help close "media breaks" between several representations used by different engineers, since at least some personnel trust this representation more than other methods.
[0029] In various embodiments, the method further comprises the step of generating a control logic according to IEC 61131-3 from a C&E matrix of the industrial process. This advantageously may make at least some parts or aspects of the interlocking specification directly applicable to a process or sub-process of a plant.
[0030] In various embodiments, the method further comprises the step of generating a piping and instrumentation diagram (P&ID) from the topological model of the industrial process. This may further help to better understand and / or verify the interlocking specifications and / or the topological model.
[0031] In various embodiments, the method further comprises the step of: if at least two rules relate to the same sensor, checking for overlapping ranges of related causes and / or gaps between their ranges. A "cause" may include a range of values from at least one sensor that do not necessarily have to agree, e.g., by typing and / or by construction error. This may help reduce such consistency errors.
[0032] In various embodiments, the method further comprises the step of checking the intersection of the relevant results if at least two rules relate to the same actuator. For example, if two power sources drive a motor, the method can check whether their cooperation is non-destructive. This check can be performed based on the rules.
[0033] One aspect relates to a non-transitory computer-readable storage medium having a program stored therein, which, when the program is executed on a processor, instructs the processor to perform the method according to any one of the aforementioned embodiments.
[0034] One aspect relates to an artificial neural network ANN configured to be trained by and / or perform a method of: checking whether at least two rules relate to the same sensor and / or whether at least two rules relate to the same actuator; and evaluating the result. To this end, the ANN can be trained using, for example, inconsistencies and / or destructive cooperative behaviors of actuators and / or their control. Additionally or alternatively, a machine learning model can be trained based on an engineer's decision regarding rule application.
[0035] The system adds the approved causal relationships to a matrix, which can then be fed to a control logic generation tool. In parallel, the system uses the safety engineer's decisions to train a machine learning mechanism (e.g., a neural network). This can refine the rule base and improve the quality of the interlocks generated in subsequent runs. Since the label names of the equipment or equipment can be derived directly from the original P&I diagram without human intervention, the solution can reduce the possibility of errors or oversights. Further, the rule engine can be enabled to handle complex topologies and therefore be prevented from suffering from cognitive overload. When existing domain knowledge is encoded into rules, it can be reused with limited effort. Additionally, the safety engineer can maintain full control of the process and can manually add interlocks to the generated C&E matrix, including publishing for peer review.
[0036] Additionally or alternatively, the system also allows engineers to visually specify new interlocking rules by marking equipment, drawing paths, and assigning attributes of causes, traversals, and / or results to them.
[0037] One aspect relates to the use of a method as described above and / or below for checking the safety and / or compliance of an industrial process.
[0038] For further explanation, the present invention is described with the aid of the embodiments shown in the accompanying drawings. These embodiments are to be regarded as examples only and not restrictive. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] The accompanying drawings depict:
[0040] Figure 1 are steps of a method according to an embodiment;
[0041] Figure 2 are additional or alternative steps of the method according to the embodiment;
[0042] Figure 3 are additional or alternative steps of the method according to the embodiment;
[0043] Figure 4 are additional or alternative steps of the method according to the embodiment;
[0044] Figure 5 is a visualization example according to an embodiment;
[0045] Figure 6 is another visualization example according to an embodiment. DETAILED DESCRIPTION
[0046] Figure 1 The steps of the method according to the embodiment are shown. Not all the steps shown in this article need to be performed in every embodiment. Figure 1 Components (eg, software components) are depicted as rectangles and artifacts, such as tables and / or other representations, may be stored in memory as rectangles with beveled corners. Figure 1 A process engineer is depicted feeding a P&I diagram to a P&ID importer, which extracts a topology model from the P&I diagram in step 1. The topology model standardizes diagrams of different types of shapes and naming conventions, and can further strip information that is not relevant to the interlock specification, such as manual valve elements, specific equipment attributes, or versioned comments. The rule engine processes the topology model in step 2 by identifying equipment that may be relevant to interlock generation. In step 3, rules from a rule base, such as rules in the form of pre-specified if-then-rules, are applied by checking whether an if-clause appears in the topology model and whether a path from the "cause" equipment to the "result" equipment can be constructed. For example, if a high / high temperature alarm is specified in a tank (the "cause"), a "traversal" from the tank to the heat exchanger (the "result") is attempted on the topology model; and if successful, a corresponding signal to stop the heat exchanger during runtime can be associated with the cause. Such rules can, for example, be coded by a domain expert or reverse engineered from a previous manual specification.
[0047] Then, in step 4, the rules engine passes the identified interlocking elements to the interlocking topology visualizer. This component creates a customized view on the topology model, which in step 5 focuses on the elements related to the identified interlocking and the background elements whose number is constrained. Then, for example, the causes, traversal paths and results are visually marked by using transparent (possibly colored) overlays. In step 6, the safety engineer responsible for the interlocking specification displays the visualization on the screen. Then, in step 7, the safety engineer can approve, reject, etc. the identified interlocking via a user interface, which in step 8 feeds the information back to the rules engine. Corrections can be made by manipulating the cause-effect markings in the visualization and adjusting the path topology.
[0048] The rule engine may train a machine learning model, such as an artificial neural network ANN, that supports the interlocking generation algorithm. In step 9, based on, for example, background information, decisions of safety engineers, and the history of applying specific rules, the rule engine may refine the rules or adjust the specific mechanism of the rules proposed for a given topology model. Steps 3 to 9 may be applied repeatedly until all rules have been applied to the entire topology model. Thereafter, in step 10, the rule engine may generate a C&E matrix, which may be expanded in a manual manner and later reviewed, for example, by other engineers. In step 11, the C&E matrix may be input into a control logic generation tool, such as according to IEC 61131-3.
[0049] As a variant, safety engineers can utilize interlocking topology visualization to visually specify new interlocking rules, for example, by drawing overlays on the topology model. In another variant, specifically in brownfield scenarios, existing interlocking control logic in the automation system can be reverse engineered into a C&E matrix and compared with the matrix generated by the system. This can help keep the specification consistent and can help detect any unexpected violations.
[0050] Thus, a visual overlay or another visually generated C&E on top of a customized streamlined plant topology model cutout is provided. This provides a mechanism that allows safety engineers and / or other personnel running the process to interact with the rule engine. Further, the machine learning model can be trained using human input in the context of the interlocking specification. For example, the rule engine can incorporate engineer decisions as "learning"; background information of the interlocking / C&E situation can be recorded, and the ML algorithm can be recalibrated, for example, by adjusting the weights in the ANN accordingly. Additionally, reverse engineering of the IEC 61131 control logic into a C&E matrix and comparing the original C&E matrix thereto can be performed. According to the methods described above and / or below, tools that allow visual specification of new interlocking rules by marking equipment, drawing paths, and assigning cause / traversal / result attributes to them can be obtained. In addition, an automatic path suggester can be added by calculating the shortest path between specified C&Es. The illustrated approach may result in faster interlock engineering, reuse existing knowledge encoded in rules, advantageously be less error-prone than, for example, manual and / or "media break" approaches, may help avoid human oversight, and / or may help avoid artifact inconsistencies.
[0051] Figure 2 Additional or alternative steps of the method according to an embodiment are shown. In step 1, visual feedback is provided to the engineer via the visualization tool described above and / or below. In step 2, the engineer approves, rejects, etc. the identified interlocking via the user interface. This can be repeated. In step 3, a C&E matrix can be generated from the verified interlocking topology. In step 4, the C&E matrix can be input into a control logic generation tool, such as according to IEC 61131-3.
[0052] Figure 3 Additional or alternative steps of a method according to an embodiment are shown. Thus, the control logic can be checked against the customer specification of the interlocking by using a C&E matrix. In step 1, customer input is given, for example in the form of C&E matrix #1. In step 2, control logic is generated, for example in accordance with IEC 61131-3. In step 3, automated reverse engineering can be performed by generating C&E matrix #2; this can be compared with C&E matrix #1 for consistency check. In step 4, feedback is given to the engineer. This person can then approve, reject, etc. the identified interlocking via a user interface.
[0053] Figure 4Additional or alternative steps of the method according to an embodiment are shown. In step 1, general rules are specified by an engineer (e.g., a domain expert, a process engineer, or a knowledge engineer) using P&ID shapes. This is the basis for verifying the interlocking specifications described above and / or below. In step 2, an automated translation of the rules into a formal language is performed. One syntax that may be used looks like this:
[0054] Valve closed
[0055] ->Valve / Pipeline / Reactor-1
[0056] -> Reactor-1\Pipeline\Valve-2
[0057] =>Valve-2 closed
[0058] In the example shown, closing a valve on a pipe supplying a reactor results in closing another valve on another pipe also supplying the reactor. The character " / " indicates a traversal of the topology model in the direction of material or logical flow, while the character "\" indicates a traversal of the topology model in the opposite direction to the material or logical flow. This embodiment interlocks all valves supplying the reactor and causes all valves to close once one of the valves is closed.
[0059] In step 3, an automated check is performed and feedback is given to the engineer.
[0060] In step 4, based on the feedback, existing rules are matched or new rules are created.
[0061] Figure 5 A visualization example according to an embodiment is shown. In this example, sensor B104 gives "high temperature alarm" as "cause" C. Via "traversing" T path "information flow connection" P-4, the signal is forwarded to "result" E, i.e., to actuator "heat exchanger E104" stopped by the rule. A syntax that might be used would look like this:
[0062] Cause: High temperature alarm B104
[0063] Traversal: Information Flow Connection
[0064] Result: Stop heat exchanger E104
[0065] In the tool, the "reason" C, the "traversal" T or traversal path, and the "result" E may be highlighted. Further, a window showing the rule may be shown, and a checkbox "Approve / Reject" may be displayed. The engineer may then approve or reject the highlighted rule.
[0066] Figure 6Another visualization example according to an embodiment is shown. This example depicts two actuators affected by a rule. The rule looks like this:
[0067] Cause: High level alarm B114
[0068] Traversal: All entries of connected containers
[0069] Result: Close valves V102 and V104
[0070] Therefore, the sensor "high level alarm B114" as the "cause" C causes the valves V102 and V104 to be closed as the "result" E.
Claims
1. A method for visualizing rules of an industrial process or a processing system, the method comprising the following steps: providing a topological model of the industrial process, wherein the industrial process includes at least one sensor and at least one actuator; Assigning attributes to the topology model using rules (R), wherein the rules (R) include a triplet <cause (C), traversal (T), result (E)>, in The cause (C) comprises a range of values from the at least one sensor, the effect (E) comprises an action performed by the at least one actuator, and The traversal (T) includes a relationship between the cause (C) and the effect (E), wherein the relationship represents a material flow or a logic flow between the cause (C) and the effect (E), wherein the material flow includes a fluid flow and / or a bulk material flow, and the logic flow includes signal transmission; marking, by a click and / or another input, the at least one sensor of the cause (C), one or more traversal paths of the traversal (T) and / or the actuator of the effect (E) of the topological model and / or marking a rule of an interlocking specification of a plant building, the one or more traversal paths comprising a fluid channel for the fluid and / or a signal path for the signal; as well as Elements of the rule (R) in the topology model are visualized.
2. The method according to claim 1, wherein attributing the topological model using rules (R) is based on visual means, and / or Wherein visualizing the elements of the rules (R) in the topology model comprises highlighting affected components and / or showing relevant rules (R) on a visual interface.
3. The method according to claim 1, further comprising the steps of: Agree to the rule (R) or reject the rule (R).
4. The method according to claim 1, further comprising the steps of: The rule (R) is improved by performing at least one of the following: Add other reasons (C); Add other results (E); Add additional Traversals(T); and / or Add additional elements to the rule (R).
5. The method according to claim 1, further comprising the steps of: The topological model of the industrial process is generated from a piping and instrumentation diagram (P&ID) of the industrial process.
6. The method according to claim 1, The topology model includes a plurality of rules (R).
7. The method according to claim 6, further comprising the steps of: Applying at least one step according to any one of the preceding claims to each rule (R) of the plurality of rules (R), wherein the at least one step comprises performing at least one of the following: Agree to the rules (R) or reject the rules (R), Improve the rules (R), and / or A topological model of the industrial process is generated from the P&ID.
8. The method according to claim 7, further comprising the steps of: A cause-and-effect C&E matrix is generated from the topological model of the industrial process.
9. The method according to claim 8, further comprising the steps of: A control logic according to IEC 61131-3 is generated from the C&E matrix of the industrial process.
10. The method according to claim 6, further comprising the steps of: A piping and instrumentation diagram (P&ID) is generated from the topological model of the industrial process.
11. The method according to claim 6, further comprising the steps of: If at least two rules (R) refer to the same sensor, the related causes (C) are checked for overlapping ranges and / or gaps between their ranges.
12. The method according to claim 6, further comprising the steps of: If at least two rules (R) refer to the same actuator, the intersection of the relevant results (E) is checked.
13. A non-transitory computer-readable storage medium storing a program which, when executed on a processor, instructs the processor to perform the method according to any one of the preceding claims.
14. An artificial neural network system, configured to be trained by the method according to claim 11 or 12 and / or to execute the method according to claim 11 or 12.
Citation Information
Patent Citations
Monitoring control system and work support method
US20170205819A1