Device integrating safety control system based on FMEDA failure prediction technology
By using FMEDA failure prediction technology and fault tree analysis, a small modular safety control system was designed, which solved the problem of calculating the failure probability of the safety control system for small chemical plants and achieved efficient system integration and improved stability.
Patent Information
- Application Number
- CN202111655090.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-30
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2041-12-30
AI Technical Summary
Existing technologies are insufficient to effectively manage the safety control systems of small-scale chemical plants, and lack methods for calculating failure probabilities during the design phase, leading to over-investment and insufficient system stability.
By employing FMEDA failure prediction technology and combining it with fault tree analysis, a small modular safety control system is designed. Through structural organization modules, functional model construction modules, and failure prediction modules, the failure probability of each functional module is predicted, the target structure is optimized, and a high-quality safety control system is integrated.
Accurately predict the failure probability of the safety control system during the design phase, optimize testing time, reduce costs, improve system stability and safety, and meet the actual needs of small-scale chemical plants.
Smart Images

Figure CN116414086B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of system safety control and optimization, and particularly relates to a device for integrating a safety control system based on FMEDA failure prediction technology, which is mainly applied to the petroleum chemical industry and the like. BACKGROUND
[0002] In actual production, in order to prevent and reduce the risk of employment of a factory site or a device of a petroleum chemical enterprise, a safety control system (SIS) needs to be set up. The reasonable design and stable operation of the system can directly provide protection for the safe operation of the site or device and control the influence of the risk of employment on business and human and material resources. The safety control system can monitor potential hazards in an industrial process, timely issue an alarm or automatically execute a preset protection function, and is the last and most critical protection layer in the initiative protection layer. When a device fails, the safety control system can make the entire device enter a safe state and issue an alarm to timely remind relevant personnel to check and eliminate the failure, so as to avoid accidents and reduce the loss of life and property caused to personnel and equipment and the adverse effects on the environment.
[0003] In recent years, small green chemical devices or equipment have been widely applied. Typical devices include a hydrogen production device by electrolysis of water, a hydrogen production device by cracking of methane, a hydrogen storage and transportation device, a compressor, a heating furnace (RTO furnace for waste gas treatment), an oil gas recovery device, a waste gas treatment device, a small oil and gas storage and transportation device (oil station), and the like. The devices have the characteristics of small scale, few control points, low investment cost, and simple and flexible setting. However, the management of small safety control systems is still blank in the technical field. The safety control system products at home and abroad are mainly used for medium and large chemical devices with more than 100 safety control points. Blindly setting the management strategy of the products in small chemical devices not only has the problems of excessive investment and setting, but also cannot guarantee the stability of the system operation, which is the main reason why small chemical enterprises do not set up safety instrument systems.
[0004] For the safety control business of the whole enterprise in multiple links, small modular safety control components at multiple levels are needed to meet the actual protection needs of the small devices. However, the manufacturers of the components used in integration, whether the components are safety function certified, the certification level, and the like are different, so how to calculate the operation reliability of the safety control system after modular integration is a problem to be solved.
[0005] Currently, researchers have proposed some methods to estimate the system failure probability, such as in the OREDA industry database published by the Norwegian Ship Classification Society in 2015, the failure probability is characterized as the maximum likelihood estimate (i.e. the total number of failures divided by the total time of operation). Meanwhile, technicians consider that the estimation of failure rate should also take into account the specific operating environment and conditions of the system, so different models need to be used to analyze the influence of various operating conditions from different environments. Foucher and Ratkowsky et al. proposed to use physical models based on Arrhenius law, voltage acceleration and Gurney law to estimate the failure probability. The standard IEC 6170-2017 proposes a failure analysis function of parameters, which involves temperature, humidity, stress, voltage or electric intensity. In addition, the trend of failure probability can also be predicted by statistical models using specific operation data, such as Cox model (proportional hazard model) and Bayesian model. Brissaud proposed a method to predict failure rate considering the influence of design, manufacturing or installation, etc. Vatn based on a similar method, while considering the implementation effect of risk reduction measures for prediction and evaluation.
[0006] However, most of the statistical models mentioned above require a large number of devices and large-scale sample data, which are not suitable for petrochemical enterprise devices that require small-scale safety control systems, and for new integrated safety control systems with small range of use and short time, there is no large amount of data to refer to in the design stage or initial operation period.
[0007] The information disclosed in the background section of the present invention is only intended to deepen the understanding of the general background of the present invention, and should not be regarded as acknowledging or implying in any form that the information constitutes prior art known to those skilled in the art. SUMMARY
[0008] To solve the above problems, the present application provides a device for integrating a safety control system based on FMEDA failure prediction technology, which can accurately integrate small modular safety control systems. The integrated system is used to identify the failure state of the enterprise device and automatically protect the device. In the process of integrating the design of the safety control system, based on the FMEDA theory and the fault tree analysis method in the present application, the failure probability of each functional module in the safety control system is predicted and calculated during the design process, providing data support for the selection and filtering of system structure during the design process. This scheme carries out reliability prediction of the safety control system in the design stage, which can ensure the overall performance quality of the final integrated system, and thus fundamentally improves the design of the product, reduces the cost, and optimizes the test time. In one embodiment, the device comprises:
[0009] a structure organization module configured to formulate an architecture of a target safety control system according to protection requirements of each device in the enterprise, and to organize all available structures of each target function module of the pre-constructed safety control system based on the formulated architecture; the available structures include independent devices and / or mature components;
[0010] a function model construction module configured to construct a corresponding function module relationship model for the complete architecture of the formulated safety control system based on the 1oo1 model;
[0011] a failure prediction module configured to analyze and calculate failure probabilities of the function modules during operation according to different available structures corresponding to each function module based on the constructed function module relationship model;
[0012] a target system selection module configured to select target structures of each function module according to the calculation results of the failure probabilities, and to integrate the selected target structures to obtain an integrated safety control system for formal use.
[0013] Preferably, in one embodiment, the structure organization module sets the target function modules of the safety control system to include:
[0014] an information acquisition module configured to acquire operation information of the protected devices in the enterprise in real time;
[0015] a logic control module communicatively connected with the information acquisition module, configured to receive the acquired device operation information, to carry out calculation and analysis according to matched program logic, and to generate control instructions;
[0016] a safety relay having an input end connected with the logic control module and an output end connected with a target control component, to realize automatic adjustment and conversion of the control component circuit;
[0017] Further, in one embodiment, the safety control system further includes a safety barrier function module connected between the information acquisition module and the logic control module, to limit the electrical signals supplied to the logic control module within a set safety range.
[0018] Specifically, in one embodiment, the logic control module adopts a programmable redundant logic controller including at least two internal control units, each of which carries out calculation on the device operation information according to the same program, and if the errors of the multiple calculation results satisfy a set condition, a final calculation result is generated and output, otherwise, a set operation parameter is output.
[0019] In an optional embodiment, the logic control module further includes an input safety card and an output safety card, the input safety card is connected with a downstream end of the safety barrier function module to receive the transmitted signals, and the output safety card is connected with an upstream end of the safety relay to output the control signals.
[0020] Further, in one embodiment, the logic control module further comprises a behavior monitoring circuit electrically connected with each internal control unit, which uses multiple different oscillators to cross-check the running state of the processor circuit of each internal control unit, each internal control unit using a clock to check whether the other internal control units are running, and if it is detected that there is an internal control unit that has not run within a set period, the logic control module is caused to enter a safe state.
[0021] On the other hand, in one embodiment, the logic control module further comprises a clock monitoring unit for monitoring the action time of each internal control unit and the time of executing program logic, and outputting corresponding safety parameters if there is a situation that exceeds the set condition.
[0022] In application, in one embodiment, the failure prediction module is configured to predict the failure probability of the operation function module by the following operations:
[0023] Step A1: For all different types and models of available structures, the corresponding product manual is consulted respectively to obtain the running failure parameters thereof relative to the overall safety control system, the running failure parameters including: the detected safety failure probability, the undetected safety failure probability, the sensing abnormal information ratio, and the undetected sensing abnormal information ratio;
[0024] Step A2: For each function module of the system, the fault tree analysis method is used to introduce the running failure parameters of each structure in sequence to calculate the comprehensive failure probability of the function module;
[0025] Step A3: According to the comprehensive failure probability of the function module and the optimization of the best organization scheme, a high-quality safety control system is integrated.
[0026] Specifically, in one embodiment, the failure prediction module further calculates the comprehensive failure probability of each function module according to the following operations:
[0027] Step A2-1: Each function module in the system is taken as an analysis object, and each available structure is taken as a sub-analysis object, the running failure parameters of the sub-analysis object are introduced to calculate the instantaneous failure probability corresponding to the available structure;
[0028] Step A2-2: Based on the instantaneous failure probability, the average failure probability corresponding to each available structure is further determined according to a set strategy;
[0029] Step A2-3: The detection cycle parameter is introduced to determine the unit time failure probability of each available structure based on the average failure probability;
[0030] Step A2-4: using the failure probability per unit time as the lower analysis basis, the logical calculation of the entire functional module is performed by the fault tree analysis method.
[0031] In an optional embodiment, before performing step A2-4, the failure prediction module is further configured to: compare the failure probability per unit time of each available structure with a set probability threshold value, if the threshold value is exceeded, the structure is removed from the available structure list, and only the remaining available structures are put into the operation of step A2-4.
[0032] Compared with the closest prior art, the present application also has the following beneficial effects:
[0033] The device for integrating a safety control system based on FMEDA failure prediction technology provided by the present application can design an overall framework around the operation target of the safety control system, and can design various types or brands of functional structures comprehensively, on the basis of the complexity of control operation, the comprehensiveness of the structure sample to be analyzed is ensured.
[0034] Further, the present application builds a corresponding functional module relationship model for the complete architecture of the safety control system based on the 1oo1 model, which can simulate the real operation process of the safety control system, ensure the authenticity and accuracy of the analysis of fault data, and then the failure prediction module quantitatively analyzes the failure probability of the functional module when running around different available structures corresponding to each functional module, optimizes the target structure of each functional module based on the failure probability, and integrates the formal integrated safety control system for use, which can provide clear reliability basis for early design decision of system product, control the failure probability of the designed integrated safety control system to the lowest, prolong the service life of the integrated safety control system, and provide the best safety control service for the equipment to be protected by the enterprise.
[0035] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be realized and achieved by the structure particularly pointed out in the specification, claims and drawings. BRIEF DESCRIPTION OF DRAWINGS
[0036] The accompanying drawings are included to provide a further understanding of the present application, and constitute a part of the specification, which together with the application embodiments, serve to explain the present application, and do not constitute a limitation to the present application; in the drawings.
[0037] Figure 1It is a structural schematic diagram of the device of the safety control system based on the FMEDA failure prediction technology provided by an embodiment of the present application.
[0038] Figure 2 It is a whole architecture schematic diagram of the safety control system constructed by the device of the integrated safety control system provided by another embodiment of the present application.
[0039] Figure 3 It is a failure fault tree analysis schematic diagram of the device of the integrated safety control system for the programmable redundant logic controller in an embodiment of the present application. DETAILED DESCRIPTION
[0040] The embodiments of the present application will be described in detail below with reference to the accompanying drawings and embodiments, so that the implementers of the present application can fully understand how the present application applies technical means to solve technical problems and achieve the implementation process of technical effects, and implement the present application according to the above implementation process. It should be noted that, as long as there is no conflict, each embodiment in the present application and each feature of each embodiment can be combined with each other, and the technical solutions formed thereby are all within the protection scope of the present application.
[0041] Although the flowchart describes the operations as sequential processes, many of the operations can be performed in parallel, concurrently or at the same time. The order of the operations can be rearranged. The process can be terminated when its operations are completed, but can also have additional steps not included in the figure. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.
[0042] The computer device includes a user device and a network device. The user device or client includes, but is not limited to, a computer, a smart phone, a PDA, etc.; the network device includes, but is not limited to, a single network server, a server group composed of multiple network servers, or a cloud composed of a large number of computers or network servers based on cloud computing. The computer device can be independently operated to implement the present application, or can be connected to a network and interact with other computer devices in the network to implement the present application. The network in which the computer device is located includes, but is not limited to, the Internet, a wide area network, a metropolitan area network, a local area network, a VPN network, etc.
[0043] The terms used herein are only used to describe specific embodiments and are not intended to limit the exemplary embodiments. Unless the context clearly indicates otherwise, as used herein, the singular forms "a", "an", and "the" are also intended to include the plural. It should also be understood that the terms "include" and / or "contain" specify the presence of stated features, integers, steps, operations, units and / or components, and do not exclude the presence or addition of one or more other features, integers, steps, operations, units, components and / or combinations thereof.
[0044] In the field of petrochemical engineering, a safety control system (SIS) is often set up to prevent and reduce the construction risk of a petrochemical plant or device, and the reasonable design and operation of the system directly affect the safe operation of the device. The safety control system can be used to monitor potential hazards in industrial processes and issue alarm information or automatically execute predetermined protection functions in a timely manner, and is the last and most critical layer of active protection. When a device fails, the safety control system can bring the entire device into a safe state and issue an alarm to remind relevant personnel to check and eliminate the fault in time, ultimately avoiding accidents and reducing the loss of life and property to personnel and equipment, and minimizing the adverse effects on the environment.
[0045] In recent years, the widespread application of small green chemical devices or packages has emerged, including typical devices such as electrolytic water hydrogen production, methane cracking hydrogen production, hydrogen storage and transportation, compressors, heating furnaces (waste gas treatment RTO furnace), oil gas recovery, waste gas treatment devices, small oil and gas storage and transportation devices (oil station), etc. The characteristics of these devices are small scale, few control points, low investment cost, and simple and flexible settings. However, the field of small safety control systems is still a blank, and the safety control system products currently used at home and abroad are mainly used for medium and large chemical devices with more than 100 safety control points. Forcedly setting them in small chemical devices will cause excessive investment and setting problems, which is also the main reason why small chemical enterprises do not set up safety instrument systems. Therefore, the integrated development of small modular safety control systems with less than 30 safety control points can well meet the actual needs of the above small devices. However, due to the different manufacturers of components used in integration, whether they are safety function certified, the certification level, etc., how to control the failure probability of the designed safety control system is a problem that needs to be solved.
[0046] Currently, methods to estimate the failure probability of a system are studied, such as in the OREDA industry database published by DNV in 2015, where the failure probability is estimated as the maximum likelihood estimate (i.e. the total number of failures divided by the total time of operation). At the same time, the estimation of the failure rate should also take into account the specific operating environment and conditions of the system, so it is recommended to use different models to analyze the influence of various operating conditions from different environments. Foucher and Ratkowsky et al. proposed that physical models based on physical laws such as Arrhenius law, voltage acceleration and Gurney law can be considered to estimate the failure probability. The standard IEC 6170-2017 proposes to analyze the failure function of parameters such as temperature, humidity, stress, voltage or electric strength. In addition, statistical models can also use specific operating data to predict the trend of failure probability, such as Cox model (proportional hazard model) and Bayesian model. Brissaud proposed a method to predict the failure rate considering the influence of design, manufacturing or installation, and Vatn proposed a similar method while considering the implementation effect of risk reduction measures in prediction. It should be noted that the physical model used to estimate the failure probability should use the knowledge of the physical mechanism leading to the failure as the basis, and this knowledge should be well known, and the prediction of failure probability is only based on statistical models in order to establish a general model.
[0047] However, most of the statistical models in the above cases need to rely on a large amount of data of equipment, but for new integrated SIS systems with small use range and short time, there is no large amount of data to be used as a reference. Therefore, the FMEDA theory can be combined with the fault tree method to predict the failure of the new safety control system device in the design stage. As a systematic analysis method, FMEDA needs to be analyzed and expanded in sequence through the whole system, subsystem, component, etc., and the relationship and hierarchical diagram between each system is drawn. Starting from the function of the product, the failure consequences and mechanisms of the possible failure modes are analyzed, and the failure consequences and the risks brought by them are scientifically evaluated, and practical measures are developed to prevent the occurrence of failure modes or reduce the risk of failure. Based on the above analysis, the researchers of the present application found that it is urgent to carry out the collection and arrangement of product failure data, and reliability prediction should be carried out in the early product design and development stage in order to support the product design process. Expanding reliability prediction can provide clear reliability requirements for the early development stage of the product, and excellent reliability prediction can provide potential product degradation awareness in the product life cycle. The results of expanding reliability prediction can improve the design of the product, reduce costs, optimize test time, etc.
[0048] To solve the above problems in the prior art, the application relates to a device and a scheme for integrating a safety control system based on FMEDA failure prediction technology, wherein the scheme is configured to integrate a small modular safety control system, which can effectively identify the fault state of enterprise equipment and automatically protect the device, and can accurately and rapidly respond; further, based on the FMEDA theory and in combination with the fault tree analysis method, the failure probability of each functional module in the safety control system is predicted and calculated in the design process, so as to realize the optimization and filtering of the integrated system structure, the reliability prediction of the safety control system is carried out in the design stage, the performance quality of the final integrated system as a whole can be ensured, and thus the product design is fundamentally improved, the cost is reduced, and the test time is optimized.
[0049] Next, the detailed flow of the method of the embodiment of the application is described in detail based on the accompanying drawings, the steps shown in the flowchart of the accompanying drawings can be executed in a computer system comprising, for example, a set of computer executable instructions. Although the logical order of the steps is shown in the flowchart, in some cases, the steps shown or described herein can be executed in an order different from that shown.
[0050] Example One
[0051] At present, the field of small safety control systems is still blank, and the existing safety control system products are mainly used for medium and large chemical plants with more than 100 safety control points, and forcibly setting them in small chemical plants will cause excessive investment and setting problems. Moreover, for the system failure probability calculation method, most of the existing statistical models need to rely on a large amount of historical data of devices or systems, but for new integrated SIS systems with small use range and short time, there is no large amount of data for reference.
[0052] Figure 1 The structure of the device for integrating a safety control system based on FMEDA failure prediction technology provided by the embodiment of the application is shown, and the device is configured to integrate a small modular safety control system, which can effectively identify the fault state of enterprise equipment and automatically protect the device, and can accurately and rapidly respond. Figure 1 It can be seen that the device comprises:
[0053] The structure organization module is configured to formulate the architecture of the target safety control system according to the protection requirements of each device in the enterprise, and to organize all available structures of each target functional module of the pre-constructed safety control system based on the formulated architecture; the available structures comprise independent devices and / or mature components;
[0054] The functional model construction module is configured to construct the corresponding functional module relationship model for the complete architecture of the formulated safety control system based on the 1oo1 model;
[0055] a failure prediction module configured to analyze the failure probability of the functional module in operation according to the built functional module relationship model and different available structures corresponding to each functional module;
[0056] a target system selection module configured to select the target structure of each functional module according to the calculation result of the failure probability and to integrate the integrated safety control system for formal use.
[0057] In actual application, the existing safety control system (SIS) in the field is large in size, and there is no small integrated product. The existing large-scale safety control system in the market includes a detection unit, an input module, a control module, an output module, an execution unit, etc., wherein the control module and the input / output card are separately arranged. The safety control system designed in the present application is a small modular safety control system integrated with multiple functional modules, and the complete integrated safety control system includes an information acquisition module, a logic controller module, a safety relay module, a safety barrier module and a power module.
[0058] The operation principle of the small integrated safety control system is as follows:
[0059] Logic one: the power module is responsible for power supply of the whole system.
[0060] Logic two: the sensor detects the current signal of the device on site, transmits the signal to the input card (DI card, AI card) in the logic controller through the safety barrier.
[0061] Logic three: the input card transmits the signal to the CPU unit of the logic controller, and the controller CPU performs logical operation and transmits the current control signal to the output card (DO card).
[0062] Logic four: the current signal from the output card flows through the safety relay and is transmitted to the final control component (such as a solenoid valve).
[0063] Preferably, in one embodiment, the target functional module of the safety control system comprises:
[0064] an information acquisition module configured to acquire the operation information of the protected equipment in the enterprise in real time;
[0065] a logic control module in communication connection with the information acquisition module, configured to receive the acquired equipment operation information, perform operation and analysis according to the matched program logic, and generate a control instruction;
[0066] a safety relay with an input end connected with the logic control module and an output end connected with the target control component, to realize automatic adjustment and conversion of the control component circuit.
[0067] Further, in an embodiment, the safety control system further comprises a safety barrier function module connected between the information acquisition module and the logic control module, which limits the electrical signal supplied to the logic control module within a set safety range.
[0068] The integrated module type safety control system designed in the application adopts a programmable redundant logic controller, and the safety type programmable logic controller module further comprises a power supply unit, a CPU unit, an input / output card interface unit, and a memory unit. Thus, the small-sized integrated safety control system (SIS) is of an integrated structure, and the safety type programmable logic controller contains both the controller and the safety card (DI, DO, AI). The memory is mainly used for storing system programs, user programs, and working data. The CPU unit can read the user programs from the memory one by one and execute them after interpretation.
[0069] The safety type programmable logic controller can read signals from the front-end sensors and execute pre-programmed actions to prevent the occurrence of danger. The safety control system adopts a safety type logic controller which can execute logic processing and decision functions and has input and output capabilities from the sensors to the final control components. In addition, it is emphasized that the logic controller in the application needs to be SIL certified, is designed to be fault-tolerant, has internal redundancy, and the safety type controller has additional internal detection (diagnosis) hardware and software to allow functional failure and increase safety to ensure accidental configuration changes. When the structure of the safety control system itself fails, it can also effectively play a safety control effect to protect the target equipment.
[0070] Specifically, in an embodiment, the logic control module adopts a programmable redundant logic controller which contains at least two internal control units. Each internal control unit respectively operates the device operation information according to the same program. If the errors of the obtained multiple operation results meet the set conditions, the final operation result is generated and output. Otherwise, the set operation parameters are output.
[0071] Preferably, in an embodiment, the logic control module further comprises an input safety card and an output safety card. The input safety card is connected with the downstream end of the safety barrier function module and is used for receiving the transmitted signals. The output safety card is connected with the upstream end of the safety relay and is used for outputting the control signals.
[0072] Further, in an embodiment, the logic control module further comprises a behavior monitoring circuit which is electrically connected with each internal control unit. Different oscillators are used to cross-check the running states of the processor circuits of each internal control unit. Each internal control unit uses a clock to check whether the other internal control units are running. If it is detected that there is no running within the set period of an internal control unit, the logic control module enters a safety state.
[0073] Optionally, in one embodiment, the logic control module further comprises a clock monitoring unit for monitoring the action time of each internal control unit and the time of executing program logic, and outputting corresponding safety parameters if there is a condition exceeding the set condition.
[0074] In actual application, the number of internal controllers of the safety programmable logic controller is at least two or more (redundant design), and the functions of the two controllers are: each of them executes the same function program logic once, and then compares the results together, if the error between the results meets the set condition, the normal electrical signal output will be performed, if not, the safe control result output will be selected (usually no output or output of the control parameters with the meaning of stopping).
[0075] In addition, the logic controller is provided with the following self-detection functions, including (behavior monitoring) clock measurement, monitoring clock, sequence check, memory check, etc. Among them, the behavior monitoring (clock measurement) function is achieved by using multiple different oscillators to cross-check the running state of each internal control unit processor circuit in the processor circuit of each internal processing unit of the controller, and each internal control unit uses a clock to check whether the other internal control unit is running, if it is detected that an internal control unit has not run within the set period, the logic control module will enter a safe state. Taking two internal processing units as an example, two different oscillators are provided to cross-check their behaviors, and each processor uses a clock to check whether the other one is running. If it is detected that the other one is not running within a certain period, the controller will enter a safe state.
[0076] In addition, the logic controller is provided with a corresponding special precision checking firmware for checking the precision of each oscillator every second.
[0077] Further, the monitoring clock process of the logic controller refers to the monitoring clock checking the activity practice and execution time of the user logic of the controller by setting a hardware and a firmware.
[0078] In actual application, in order to monitor the execution logic and sequence of different parts of the controller operating system in real time, a sequence check function unit can also be provided.
[0079] In addition, the logic controller of the present application also uses a set memory check function unit to detect all static memory areas, including Flash memory and RAM, using cyclic redundancy code (CRC), and double code execution. The dynamic memory area is protected by double code execution and is periodically detected. In the actual application process of the safety control system, these monitoring and detection function units are reinitialized at cold start.
[0080] Further, in one embodiment, the safety relay is composed of multiple relays and circuits, so as to complement each other's abnormal defects, and achieve the complete function of the relay with correct and low malfunction. The input end receives a 24V voltage signal from the controller, and the output end is connected to the final control component such as a solenoid valve with a voltage of 220V. In fact, it is a kind of "automatic switch" for controlling large current operation with small current, so it plays the role of automatic adjustment, safety protection, and conversion circuit in the circuit.
[0081] For example, the safety relay is provided with three internal relays, and one of the relays is in default operation. If it is detected that the running relay fails, the other relays are called to run. The control decision function is controlled by the logic level or functional circuit structure in the relay module.
[0082] Further, the safety barrier function module is connected between the intrinsically safe circuit and the non-intrinsically safe circuit, and limits the voltage or current supplied to the intrinsically safe circuit within a certain safety range. In actual design, one end is connected to the protected equipment such as instruments in the enterprise field, and the other end is connected to the logic controller.
[0083] The power module is configured to supply power to the controller module and other integrated modules or devices in the safety control system for 24 hours.
[0084] The present application provides a small modular safety control system with integrated development of safety control points within 30 points, and on this basis, the method of combining FMEDA theory and fault tree method is proposed to predict and calculate the operation failure probability of each functional hardware in the designed system, which can effectively predict the equipment failure of the safety control system in the design stage, and standardize the rationality and high work quality characteristics of the safety control system structure.
[0085] Based on the above idea, the researchers of the present application also provide a method for predicting and calculating the operation failure probability of each functional hardware in the designed system. In one preferred embodiment, the present application provides a basis for failure probability calculation by establishing a functional module relationship model based on the 1oo1 model of the internal functional modules of the safety control system.
[0086] In actual application, the functional model construction module can establish a functional module relationship model based on 1oo1 between the internal functional modules of the safety control system according to the functional structure characteristics of the safety control system, as shown in Figure 2
[0087] Further, in one embodiment, the failure prediction module is configured to predict the failure probability of the functional module by the following operations:
[0088] Step A1: For all different kinds and models of available structures, refer to the corresponding product manual to obtain its operating failure parameters relative to the overall safety control system, including: the detected safety failure probability, the undetected safety failure probability, the sensor abnormal information ratio and the undetected sensor abnormal information ratio; in actual application, by referring to the product manual of each available structure corresponding brand, the failure data λ SD , λ SU , λ DD , λ DU of each functional module can be obtained, which respectively represent the detected safety failure probability, the undetected safety failure probability, the sensor abnormal information ratio and the undetected sensor abnormal information ratio.
[0089] Step A2: Based on the preset requirements, for each functional module of the system, the fault tree analysis method is used to introduce the operating failure parameters of the structure to calculate the comprehensive failure probability of the functional module;
[0090] Step A3: According to the comprehensive failure probability of the functional module and the optimal organization scheme, a high-quality safety control system is integrated.
[0091] Further, in one embodiment, the failure prediction module further calculates the comprehensive failure probability of each functional module according to the following operations:
[0092] Step A2-1: Taking each functional module in the system as an analysis object, and taking each available structure as a sub-analysis object, introduce the operating failure parameters of the sub-analysis object to calculate the instantaneous failure probability of the available structure corresponding to the sub-analysis object;
[0093] In actual application, the instantaneous failure probability PFD of each structure of the functional system can be calculated according to the following formula:
[0094] (1-1).
[0095] Step A2-2: Based on the instantaneous failure probability, the average failure probability of each available structure is further determined according to the set strategy;
[0096] Specifically, the average failure probability PFD of each structure can be calculated according to the following formula: avg
[0097] (1-2)
[0098] Wherein, TI represents the operating time of the safety control system functional model, t is an integral parameter representing time, and MTTR represents the average failure-free time during the operation of the system functional model.
[0099] Step A2-3: Introducing detection cycle parameter, based on the average failure probability, determine the unit time failure probability of each available structure;
[0100] In practical application, the average failure probability at the required time can be divided by the detection cycle TI to obtain the risk failure probability PFH of the corresponding structure per unit time (such as per hour) avg :
[0101] (1-3).
[0102] Step A2-4: Taking the unit time failure probability of each available structure as the lower analysis basis, the logic of the fault tree analysis method is used to calculate the comprehensive failure probability of the entire functional module.
[0103] Further, according to the fault tree analysis method, the comprehensive failure probability (total fault occurrence probability) F (T) of the functional module to which it belongs is calculated according to the following formula:
[0104] (1-4)
[0105] In the formula, n represents the number of structures contained in the functional module, each structure is regarded as a sub-analysis object, λ i is the unit time failure probability (failure probability) of the ith component.
[0106] In practical application, in order to timely filter out structures that do not obviously meet the requirements, save operation resources and time consumption, in an optional embodiment, before the failure prediction module performs step A2-4, it is also configured to: compare the unit time failure probability of each available structure with the set probability threshold value, if it exceeds the threshold value, the structure is removed from the available structure list, only the remaining available structures are put into the operation of step A2-4.
[0107] The scheme of the above embodiments of the patent is mainly applied to the equipment of the petrochemical industry, and is used for integrated design and failure probability prediction calculation of the safety control system of small-scale production and storage devices. The integrated modular safety control system proposed in the patent can provide safety protection for the normal operation of the protected device, and the hardware failure probability calculation method based on FMEDA can effectively predict the equipment failure of the safety control system in the design stage, and improve the structural reliability of the integrated safety control system.
[0108] Taking a brand structure as an example, the data in the structure product manual is obtained as the operating failure parameters λ SD , λ SU , λ DD , λ DUAccording to formula (1-1), (1-2), (1-3), the unit time failure probability corresponding to the structure is calculated. Then, the comprehensive failure probability of the functional module in the requirement time is calculated according to formula (1-4).
[0109] For example, the programmable logic control module failure is caused by the failure of the power supply unit, the programmable redundant logic controller (CPU unit), the input / output card interface, and the memory unit, so the programmable logic controller module fault tree model can be constructed as shown in formula (1-4). Figure 3
[0110] For example, the programmable redundant logic controller, according to formula (1-1) to (1-3), can be calculated,
[0111]
[0112] Similarly, according to formula 1-1 to formula 1-3, the average failure probability PFD and the hourly failure probability PFH values of the power supply unit, the input / output card interface, and the memory unit are calculated, and then the comprehensive failure probability of the logic control module of the entire functional module is calculated according to formula 1-4.
[0113] Before calculating the comprehensive failure probability of the functional module, the unit time failure probability calculated by the structure is compared with the preset probability threshold value. If it exceeds, it means that the failure probability of the structure is too high, which cannot meet the operation requirements of the safety control system of the patent, and it is removed from the list of available structures.
[0114] Specifically, the standard mean time to repair parameter in the product manual and the standard MTTR that must be met according to the actual operation requirements can be combined to introduce the operation time TI consistent with the actual calculation, to obtain the upper limit of the average failure probability PFD of the corresponding structure in the safety control system according to the above logic, and to obtain the corresponding unit time failure probability PFH value as the preset probability threshold value. The state information can reflect whether the structure fails.
[0115] Further, for multiple structures with a unit time failure probability less than the set probability threshold value, in the step of calculating the comprehensive failure probability of the functional module, if there are multiple available structures, the one with the minimum comprehensive failure probability is selected as the target.
[0116] The safety control system designed based on the above logic can well control the failure probability of the structure used in the functional module to be the minimum.
[0117] The device based on the FMEDA failure prediction technology integrated safety control system provided by the embodiment of the application, each module or unit structure can be independently operated or combined to operate according to actual operation and organization requirements, so as to realize the corresponding technical effect.
[0118] For the implementation principle embodiments of the foregoing device, in order to simply describe, they are all expressed as a series of action combinations, but the person skilled in the art should know that the operation of the device of the application is not limited by the action sequence described, because according to the application, certain steps can be performed in other sequences or simultaneously. Secondly, the person skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions and modules involved are not necessarily necessary for the application.
[0119] It should be understood that the embodiments disclosed by the application are not limited to the specific structure, processing steps or materials disclosed herein, but should be extended to the equivalent alternatives of these features understood by the person skilled in the relevant art. It should also be understood that the terms used herein are only for the purpose of describing the specific embodiments and do not mean limitation.
[0120] It should be understood that the embodiments disclosed by the application are not limited to the specific structure, processing steps or materials disclosed herein, but should be extended to the equivalent alternatives of these features understood by the person skilled in the relevant art. It should also be understood that the terms used herein are only for the purpose of describing the specific embodiments and do not mean limitation.
[0121] Although the embodiments of the application are disclosed as above, the content described is only for the purpose of understanding the application and is not intended to limit the application. Any person skilled in the art of the application can make any modification and change in the implementation form and details without departing from the spirit and scope of the application disclosed, but the patent protection scope of the application should be subject to the scope defined by the appended claims.
Claims
1. An apparatus for integrating a safety control system based on FMEDA failure prediction techniques, characterized by, The device comprises: a structure organization module configured to formulate an architecture of a target safety control system according to protection requirements of each device in an enterprise, and to organize all available structures of each target function module of a pre-constructed safety control system based on the formulated architecture; the available structures include independent devices and / or mature components; a function model construction module configured to construct a corresponding function module relationship model for the complete architecture of the formulated safety control system based on a 1oo1 model; a failure prediction module configured to analyze and calculate a failure probability of each function module during operation according to the constructed function module relationship model and different available structures corresponding to each function module; a target system selection module configured to select a target structure of each function module according to the calculation results of the failure probability, and to integrate to obtain an integrated safety control system for formal use; the target function module of the safety control system comprises an information acquisition module configured to acquire operation information of a protected device in an enterprise in real time, a logic control module in communication connection with the information acquisition module and configured to receive the acquired device operation information, to carry out calculation and analysis according to a matched program logic, and to generate a control instruction, and a safety relay having an input end connected with the logic control module and an output end connected with a target control component to realize automatic adjustment and conversion of a control component circuit; the logic control module comprises a behavior monitoring circuit in electrical connection with each internal control unit, which uses multiple different oscillators to cross-check the operation state of each internal control unit processor circuit, each internal control unit uses a clock to check whether another internal control unit is running, and if it is detected that there is no running within a set period of an internal control unit, the logic control module enters a safe state; the failure prediction module is configured to compare the calculated failure probability of each available structure per unit time with a set probability threshold value, and if the threshold value is exceeded, the structure is removed from the available structure list, and only the remaining available structures are put into operation in the comprehensive failure probability calculation.
2. The apparatus of claim 1, wherein, The safety control system further comprises a safety barrier function module connected between the information acquisition module and the logic control module to limit the electrical signal supplied to the logic control module within a set safety range.
3. The apparatus of claim 1, wherein, The logic control module uses a programmable redundant logic controller containing at least two internal control units, each of which carries out calculation on the device operation information according to the same program, and if the error of the multiple calculation results meets a set condition, a final calculation result is generated and output, otherwise, a set operation parameter is output.
4. The apparatus of claim 1, wherein, The logic control module further comprises an input safety card and an output safety card, the input safety card is connected with a downstream end of the safety barrier function module to receive the transmitted signal, and the output safety card is connected with an upstream end of the safety relay to output a control signal.
5. The apparatus of claim 1, wherein, The logic control module further comprises a clock monitoring unit for monitoring the action time of each internal control unit and the time of executing the program logic, and if there is a condition exceeding the set condition, the corresponding safety parameter is output.
6. The apparatus of claim 1, wherein, The failure prediction module is configured to predict the failure probability of the operation function module by the following operations: Step A1: For all different kinds and types of available structures, the corresponding product manual is consulted to obtain the operation failure parameters thereof relative to the overall safety control system, the operation failure parameters including: the detected safety failure probability, the undetected safety failure probability, the sensing abnormal information ratio and the undetected sensing abnormal information ratio; Step A2: For each function module of the system, the fault tree analysis method is adopted to sequentially introduce each operation failure parameter of the structure to calculate the comprehensive failure probability of the function module; Step A3: According to the comprehensive failure probability of the function module and the priority selection of the best organization scheme, a high-quality safety control system is integrated.
7. The apparatus of claim 1, wherein, The failure prediction module further calculates the comprehensive failure probability of each function module according to the following operations: Step A2-1: Each function module in the system is taken as an analysis object, and each available structure is taken as a sub-analysis object, and each operation failure parameter of the sub-analysis object is introduced to calculate the instantaneous failure probability corresponding to the available structure; Step A2-2: Based on the instantaneous failure probability, the average failure probability corresponding to each available structure is further determined according to a set strategy; Step A2-3: The detection cycle parameter is introduced to determine the unit time failure probability of each available structure based on the average failure probability; Step A2-4: Taking the unit time failure probability as the lower analysis basis, the logic of the fault tree analysis method is used to calculate the comprehensive failure probability of the entire function module.
Citation Information
Patent Citations
Simplified-FTA-method-based numerical control device hardware safety protection method and apparatus
CN105652805A