Risk assessment method and system based on online analysis of SIS safety integrated parameters
By building an integrated safety risk model and online analysis method to dynamically evaluate safety integrity and information security levels, the problem of difficulty in achieving integrated safety management of high-risk and complex process equipment in existing technologies has been solved, and real-time monitoring and assessment of production site risks has been achieved.
Patent Information
- Application Number
- CN202410112082.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-26
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2044-01-26
AI Technical Summary
Existing technologies make it difficult to effectively achieve integrated safety management of high-risk and complex process equipment, especially when facing dynamic network threats and process changes, static security assessment methods can no longer meet the needs.
A risk assessment method based on online analysis of SIS safety integration parameters is adopted to construct a safety integration risk model. By online monitoring of key functional safety and information security parameters, the safety integrity level and information security level are dynamically analyzed to achieve real-time assessment of production site risks.
It realizes real-time risk monitoring of intelligent connected industrial production equipment, dynamically assesses safety risks at production sites, and improves the efficiency and accuracy of integrated safety management.
Smart Images

Figure CN117933714B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial control technology, and more particularly to a risk assessment method and system based on online analysis of SIS safety integration parameters. Background Art
[0002] The goal of integrated security protection is high-risk and complex process equipment. Whether it is functional safety or information security, what ultimately needs to be ensured is the safety of these high-risk and complex process equipment. The safety of process equipment is based on the integration and coordination of multiple security measures. Faced with dynamic network threats and real-time changes in processes, static analysis and evaluation oriented towards a single security has become difficult to be effective.
[0003] Therefore, providing a risk assessment method and system based on online analysis of SIS safety integrated parameters to achieve overall safety improvement is an urgent problem that needs to be solved by those skilled in the art. Summary of the Invention
[0004] In view of this, the present invention provides a risk assessment method and system based on online analysis of SIS safety integration parameters to solve the problems mentioned in the background technology.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] The risk assessment method based on online analysis of SIS safety integration parameters includes the following steps:
[0007] S1. Build a safety-integrated risk model, conduct hazard identification and initial risk assessment for initial intelligent connected industrial production equipment and systems, determine the overall safety requirements of the objects, and establish initial safety integrity level (SIL) and information security level (SL) objectives.
[0008] S2. Based on the key parameters that affect the safety integrity capability of the safety instrumented system and the real-time dynamic changes during operation, an online analysis model for key functional safety parameters is constructed. The relationship between safety parameters and SIL is then used to form a dynamic analysis of the SIL.
[0009] S3. Based on the completeness of information security protection capabilities and the possibility of real-time attacks, combined with key information security parameters that meet the requirements of the IEC62443 standard, an online analysis model for information security parameters is constructed to form a dynamic analysis of SL;
[0010] S4. Construct a description and semi-quantitative classification of the consequences of failure to achieve safety goals;
[0011] S5. Construct a typical risk matrix and, based on the dynamic analysis of real-time functional safety in step S2 and information security in step S3, combine the description and semi-quantitative classification of consequences in step S4, and use the constructed integrated safety risk model to achieve dynamic risk assessment.
[0012] Preferably, the security integrated risk model constructed is specifically as follows:
[0013] R=(Fa+Fe)×C
[0014] Among them, R is the combination of the possibility and consequences of unacceptable events at the production site, C is the consequence of adverse effects on people, property, environment or reputation at the production site, Fa is the possibility of functional safety failure, and Fe is the possibility of suffering information security attacks.
[0015] Preferably, the constructed functional safety parameter online analysis model is specifically:
[0016] Fa=DeXSLXPL
[0017] Where De is the demand rate, SIL is the safety integrity capability of the safety instrumented system, and PL is the probability of failure of other protection layers;
[0018] De determines the operating mode of the functional safety system, including the low-demand operating mode LowDe and the high-demand or continuous operating mode HicDe. Specifically:
[0019] Fa=LowDe×SIL×PL, when De<1 time / year
[0020] Fa=SIL×PL, when De>1 time / year
[0021] Preferably, the safety integrity capability of the safety instrumented system includes systemic safety integrity and hardware safety integrity;
[0022] Systemic safety integrity is achieved based on the inherent characteristics and engineering and operation and maintenance of each component that makes up the safety instrumented system;
[0023] The specific contents of hardware safety integrity are:
[0024] Real-time online analysis of key parameters that affect the safety integrity of the safety instrumented system, including failure rate λ, common cause failure β, verification test interval T1, diagnostic test interval T2, diagnostic coverage DC, voting structure MooN, hardware fault margin HFT, and mean time to recovery MTTR:
[0025] Based on the online analysis results of key parameters and in accordance with the requirements of the IEC61508 standard, probabilistic modeling is performed between various underlying parameters and PFDavg / PFH and architectural constraints, as well as the mapping relationship between PFDavg / PFH and architectural constraints and SIL.
[0026] Preferably, the specific content of the online analysis of key parameters is:
[0027] The failure rate λ includes the prior existing basic failure rate data and the failure statistics during operation;
[0028] The prior basic failure rate data is directly obtained from the manual of the safety system;
[0029] Failure statistics during operation are based on the collection of original failure conditions using the safety data dictionary, and statistical analysis and modeling are carried out:
[0030]
[0031] in, is the expected failure rate data during operation, n is the number of failures during operation, and τ is the total operation service time;
[0032] Construct an evaluation table for common cause failure factors based on the IEC 61508-6 standard, monitor each evaluation item in real time, and calculate common cause failure factors in real time;
[0033] Through the maintenance management system corresponding to the equipment, the time of each maintenance is obtained in real time, and the average test interval is calculated:
[0034] T1 = time difference between two inspection tests;
[0035] The diagnostic test interval T2 is obtained in real time through the self-diagnostic data of the corresponding safety equipment:
[0036] T2 = time difference between two diagnostic tests;
[0037] By monitoring the failure rate and the diagnostic status in real time, the diagnostic coverage DC is calculated in real time:
[0038] DC = Dangerous diagnosable failure λ DD / Dangerous failureλ D ;
[0039] The initial voting structure is input according to the design requirements of the safety equipment, and the equipment degradation status is automatically obtained through the real-time self-diagnosis of the safety equipment during operation;
[0040] According to the voting structure MooN, the hardware fault margin HFT is calculated in real time:
[0041] HFT=NM;
[0042] The mean time to recovery (MTTR) is calculated based on the time difference between when the equipment stops working and when it returns to normal operation.
[0043] The probability of failure of other protective layers PL is assigned using a fixed static probability.
[0044] Preferably, the constructed information security parameter online analysis model is specifically:
[0045] Fe=1-SLact×(1-A)
[0046] Among them, Fe is the possibility of information security, SLact is the completeness of the ability to achieve information security protection, and A is the possibility of launching an attack.
[0047] Preferably, the completeness of the ability to achieve information security protection SLact is various security attributes that affect information security, including timely response to information security incidents, controlled data flow, data confidentiality, identification and authentication control, use control, system integrity and resource availability;
[0048] Measure the security attribute parameters that affect information security, realize online monitoring of various security attributes, and determine the degree of loss of information security protection capabilities based on the monitoring conclusions and the weighted scoring table. The degree of loss is proportional to the risk of suffering information security damage.
[0049] Preferably, the information security integrity SLact is specifically:
[0050]
[0051] SeSum is the total information security attribute score calculated by adding all weights of applicable information security attributes configured on the device, and SeCal is the actual information security attribute score calculated in real time based on all effective technical measures.
[0052] The evaluation of the probability A of launching an attack is obtained by assigning a probability based on the conclusion of the initial SL assessment.
[0053] Preferably, the specific contents of the consequence description and semi-quantitative grading are:
[0054] Structuring a statement of consequences based on risks to people, property, the environment, and reputation;
[0055] categorize the severity of specific consequences for people, property, reputation, and the environment;
[0056] A semi-quantitative classification is carried out based on the risk consequence description and severity classification, and a risk matrix severity description table is established.
[0057] An intelligent connected industrial control safety integrated risk assessment system, based on the risk assessment method based on online analysis of SIS safety integrated parameters, includes an initial risk assessment module, an online analysis module for functional safety parameters, an online analysis module for information security parameters, a consequence analysis module, and a safety integrated risk model;
[0058] The initial risk assessment module is used to conduct hazard identification and initial risk assessment for initial intelligent connected industrial production equipment and systems, determine the overall safety requirements of the object, and establish the initial safety integrity level target (SIL) and information security level target (SL);
[0059] The functional safety parameter online analysis module is used to build an online analysis model for key functional safety parameters based on the key parameters that affect the safety integrity capability of the safety instrumented system and the real-time dynamic changes during operation. It also uses the relationship between safety parameters and SIL to form a dynamic analysis of SIL.
[0060] The information security parameter online analysis module is used to build an information security parameter online analysis model based on the completeness of information security protection capabilities and the possibility of real-time attacks, combined with key information security parameters that meet the requirements of the IEC 62443 standard, to form a dynamic analysis of SL;
[0061] Consequence analysis module, used to construct descriptions and semi-quantitative classifications of consequences when safety goals cannot be achieved;
[0062] The safety-integrated risk model is used to construct a typical risk matrix. Based on the real-time dynamic analysis of functional safety and information security, combined with the description of consequences and semi-quantitative classification, the safety-integrated risk model is used to achieve dynamic risk assessment.
[0063] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a risk assessment method and system based on online analysis of SIS safety integrated parameters. Compared with the existing static risk assessment process for SIS, this method provides a dynamic assessment method from the perspective of online monitoring, and designs the key parameters involved in the dynamic assessment, thereby realizing real-time risk monitoring of the SIS during operation.
[0064] Compared with the existing independent and separate analysis and evaluation processes for functional safety and information security, the present invention creatively proposes an evaluation method that integrates the functional safety and information security probability parameters Fa and Fe, and realizes integrated safety risk assessment by establishing a unified risk model. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0066] Figure 1 Schematic diagram of the risk assessment method based on online analysis of SIS safety integration parameters provided by the present invention;
[0067] Figure 2 Schematic diagram of online analysis of functional safety parameters provided by the present invention;
[0068] Figure 3 A schematic diagram of online analysis of information security parameters provided by the present invention;
[0069] Figure 4 A table describing the severity of the risks and consequences provided for this invention;
[0070] Figure 5 A matrix chart for risk assessment provided by the present invention. DETAILED DESCRIPTION
[0071] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0072] The embodiment of the present invention discloses a risk assessment method based on online analysis of SIS safety integration parameters, comprising the following steps:
[0073] S1. Build a safety-integrated risk model, conduct hazard identification and initial risk assessment for initial intelligent connected industrial production equipment and systems, determine the overall safety requirements of the objects, and establish initial safety integrity level (SIL) and information security level (SL) objectives.
[0074] S2. Based on the key parameters that affect the safety integrity capability of the safety instrumented system and the real-time dynamic changes during operation, an online analysis model for key functional safety parameters is constructed. The relationship between safety parameters and SIL is then used to form a dynamic analysis of the SIL.
[0075] S3. Based on the completeness of information security protection capabilities and the possibility of real-time attacks, combined with key information security parameters that meet the requirements of the IEC62443 standard, an online analysis model for information security parameters is constructed to form a dynamic analysis of SL;
[0076] S4. Construct a description and semi-quantitative classification of the consequences of failure to achieve safety goals;
[0077] S5. Construct a typical risk matrix and, based on the dynamic analysis of real-time functional safety in step S2 and information security in step S3, combine the description and semi-quantitative classification of consequences in step S4, and use the constructed integrated safety risk model to achieve dynamic risk assessment.
[0078] In order to further implement the above technical solutions, the security integrated risk model constructed is as follows:
[0079] R=(Fa+Fe)×C
[0080] Among them, R is the combination of the possibility and consequences of unacceptable events at the production site, C is the consequence of adverse effects on people, property, environment or reputation at the production site, Fa is the possibility of functional safety failure, and Fe is the possibility of suffering information security attacks.
[0081] In practical applications, a holistic, static, integrated hazard / threat identification is conducted for the initial intelligent connected industrial production equipment and systems. Methods with existing experience can be adopted, such as HAZOP analysis that takes into account information security threats, or FMEA+FMEVA, and risk reduction requirements are determined based on factors such as the possibility and consequences of specific hazardous events. Based on the conclusions of hazard identification and initial risk assessment, several safety goals SG (safety goal) are established. The safety goal is the top-level requirement to ensure the realization of safety integration. On the basis of the top-level requirements, the allocation of safety goals is executed, and appropriate functional safety systems and information safety systems are adopted to achieve overall risk reduction, thereby generating corresponding original SIL and SL targets.
[0082] In order to further implement the above technical solution, the functional safety parameter online analysis model constructed is as follows:
[0083] Fa=DeXSILXPL
[0084] Where De is the demand rate, SIL is the safety integrity capability of the safety instrumented system, and PL is the probability of failure of other protection layers;
[0085] De determines the operating mode of the functional safety system, including the low-demand operating mode LowDe and the high-demand or continuous operating mode HicDe. Specifically:
[0086] Fa=LowDe×SIL×PL, when De<1 time / year
[0087] Fa=SIL×PL, when De>1 time / year
[0088] In order to further implement the above technical solutions, Figure 2 ,The safety integrity capability of the safety instrumented system includes ,systematic safety integrity and hardware safety integrity;
[0089] Systemic safety integrity is achieved based on the inherent characteristics and engineering and operation and maintenance of each component that makes up the safety instrumented system;
[0090] The specific content of hardware security integrity is
[0091] Real-time online analysis of key parameters that affect the safety integrity of the safety instrumented system, including failure rate λ, common cause failure β, verification test interval T1, diagnostic test interval T2, diagnostic coverage DC, voting structure MooN, hardware fault margin HFT, and mean time to recovery MTTR:
[0092] Based on the online analysis results of key parameters and in accordance with the requirements of the IEC61508 standard, probabilistic modeling is performed between various underlying parameters and PFDavg / PFH and architectural constraints, as well as the mapping relationship between PFDavg / PFH and architectural constraints and SIL.
[0093] In order to further implement the above technical solution, the specific contents of the online analysis of key parameters are as follows:
[0094] The failure rate λ includes the prior existing basic failure rate data and the failure statistics during operation;
[0095] The prior basic failure rate data is directly obtained from the manual of the safety system;
[0096] Failure statistics during operation are based on the collection of original failure conditions using the safety data dictionary, and statistical analysis and modeling are carried out:
[0097]
[0098] in, is the expected failure rate data during operation, n is the number of failures during operation, and τ is the total operation service time;
[0099] Total service time can be measured in calendar time or in elapsed time;
[0100] In this embodiment, the expected failure rate can be expressed using a 90% confidence interval, that is, within the intervals L and U, the true value of the failure rate satisfies:
[0101] Pr(λ L ≤λ<λ U )=90%
[0102] For n failures within a total service time t, the 90% confidence interval is:
[0103]
[0104] Construct an evaluation table for common cause failure factors based on the IEC 61508-6 standard, monitor each evaluation item in real time, and calculate common cause failure factors in real time;
[0105] The inspection and testing interval is determined by the on-site testing and maintenance situation. The length of the test interval will directly affect the level of PFDavg and PFH. Through the maintenance management system corresponding to the equipment, the time of each inspection and maintenance is obtained in real time, and the average test interval is calculated:
[0106] T1 = time difference between two inspection tests;
[0107] As one of the safety design attributes of a safety device, the diagnostic test interval T2 is obtained in real time through the self-diagnostic data of the corresponding safety device:
[0108] T2 = time difference between two diagnostic tests;
[0109] The diagnostic coverage has a default value at the initial stage of safety equipment deployment, but it may change during operation due to changes in failure rate and diagnostic effectiveness. The diagnostic coverage DC is calculated in real time by monitoring the failure rate and diagnostic status in real time:
[0110] DC = Dangerous diagnosable failure λ DD / Dangerous failureλ D ;
[0111] The initial voting structure is input according to the design requirements of the safety equipment, and the equipment degradation status is automatically obtained through the real-time self-diagnosis of the safety equipment during operation;
[0112] According to the voting structure MooN, the hardware fault margin HFT is calculated in real time:
[0113] HFT=NM;
[0114] The mean time to recovery (MTTR) is calculated based on the time difference between when the equipment stops working and when it returns to normal operation.
[0115] The probability of failure of other protective layers PL is assigned using a fixed static probability.
[0116] In order to further implement the above technical solutions, the constructed online analysis model of information security parameters is as follows:
[0117] Fe=1-SLact×(1-A)
[0118] Among them, Fe is the possibility of information security, SLact is the completeness of the ability to achieve information security protection, and A is the possibility of launching an attack.
[0119] In order to further implement the above technical solutions, Figure 3 , the completeness of the ability to achieve information security protection SLact refers to the various security attributes that affect information security, including timely response to information security incidents, controlled data flow, data confidentiality, identification and authentication control, use control, system integrity and resource availability;
[0120] Measure the security attribute parameters that affect information security, realize online monitoring of various security attributes, and determine the degree of loss of information security protection capabilities based on the monitoring conclusions and the weighted scoring table. The degree of loss is proportional to the risk of suffering information security damage.
[0121] In order to further implement the above technical solutions, the information security integrity SLact is specifically as follows:
[0122]
[0123] SeSum is the total information security attribute score calculated by adding all weights of applicable information security attributes of the equipment configuration. SeCal is the actual information security attribute score calculated in real time based on all effective technical measures. For some safety instrumented system components that are not applicable to the evaluation items, the default is to permanently comply with the subtype requirements.
[0124] In this embodiment, in order to achieve a comprehensive evaluation of all information security attributes, the actual attribute scores that can be achieved by the device determine the final device information security status. The security protection capability percentage is calculated by dividing the sum of the weighted scores of the technical measures in the normal state by the total available score:
[0125] First, for the applicable information security attributes configured on the device, all weights are added together to calculate the total information security attribute score SeSum;
[0126] In actual operation, the device analyzes and transmits the status of various information security attributes in real time. The corresponding score is obtained only when the technical measures remain effective. Therefore, the actual information security attribute score SeCal can be calculated in real time based on all effective technical measures.
[0127] The probability A of launching an attack is evaluated by assigning probabilities based on the conclusions of the initial SL assessment;
[0128] The probability distribution of SL is as follows: SL1=0.05, SL2=0.005, SL2=0.0005, SL2=0.00005; for example, if the evaluated SL is level 2, then A=0.005.
[0129] The weighted scoring table is shown in Table 1:
[0130]
[0131]
[0132]
[0133]
[0134] In order to further implement the above technical solution, the specific contents of the consequence description and semi-quantitative classification are as follows:
[0135] Structuring a statement of consequences based on risks to people, property, the environment, and reputation;
[0136] categorize the severity of specific consequences for people, property, reputation, and the environment;
[0137] According to the risk consequence description and severity classification, semi-quantitative classification is carried out to establish the risk matrix severity description table, such as Figure 4 .
[0138] In this embodiment, for information security, different types of consequences have different applicability to the seven information security attributes. In other words, some information security protection measures have no positive effect on specific consequences. For example, confidentiality measures have no effect on the consequence of personal injury. Different consequences may be mapped to different information security protection measures. Different sets of information security technical measures are established for specific consequences, which affects the scoring in step 3. The mapping relationships between specific consequences for personnel, property, reputation, and environment and various information security attributes are shown in Table 2:
[0139]
[0140]
[0141]
[0142]
[0143] In practical applications, a unified risk analysis matrix is constructed based on possibility (frequency) and consequences, such as Figure 5 The real-time values of Fa and Fe can be obtained in real time through steps S2 and S3, while the value of C can be obtained through step S4. Therefore, the dynamic changes of the above real-time values, combined with the risk matrix diagram, can obtain the dynamic risk assessment conclusion of safety integration.
[0144] An intelligent connected industrial control safety integrated risk assessment system, based on a risk assessment method based on online analysis of SIS safety integrated parameters, includes an initial risk assessment module, an online analysis module for functional safety parameters, an online analysis module for information security parameters, a consequence analysis module, and a safety integrated risk model;
[0145] The initial risk assessment module is used to conduct hazard identification and initial risk assessment for initial intelligent connected industrial production equipment and systems, determine the overall safety requirements of the object, and establish the initial safety integrity level target (SIL) and information security level target (SL);
[0146] The functional safety parameter online analysis module is used to build an online analysis model for key functional safety parameters based on the key parameters that affect the safety integrity capability of the safety instrumented system and the real-time dynamic changes during operation. It also uses the relationship between safety parameters and SIL to form a dynamic analysis of SIL.
[0147] The information security parameter online analysis module is used to build an information security parameter online analysis model based on the completeness of information security protection capabilities and the possibility of real-time attacks, combined with key information security parameters that meet the requirements of the IEC 62443 standard, to form a dynamic analysis of SL;
[0148] Consequence analysis module, used to construct descriptions and semi-quantitative classifications of consequences when safety goals cannot be achieved;
[0149] The safety-integrated risk model is used to construct a typical risk matrix. Based on the real-time dynamic analysis of functional safety and information security, combined with the description of consequences and semi-quantitative classification, the safety-integrated risk model is used to achieve dynamic risk assessment.
[0150] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0151] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A risk assessment method based on online analysis of SIS safety integration parameters, characterized by: The following steps are involved: S1. Build a safety-integrated risk model, conduct hazard identification and initial risk assessment for initial intelligent connected industrial production equipment and systems, determine the overall safety requirements of the objects, and establish initial safety integrity level (SIL) and information security level (SL) objectives. S2. Based on the key parameters that affect the safety integrity capability of the safety instrumented system and the real-time dynamic changes during operation, an online analysis model for key functional safety parameters is constructed. The relationship between safety parameters and SIL is then used to form a dynamic analysis of the SIL. S3. Based on the completeness of information security protection capabilities and the possibility of real-time attacks, combined with key information security parameters that meet the requirements of the IEC 62443 standard, an online analysis model for information security parameters is constructed to form a dynamic analysis of SL; S4. Construct a description and semi-quantitative classification of the consequences of failure to achieve safety goals; S5. Construct a typical risk matrix and, based on the real-time functional safety analysis from step S2 and the dynamic information security analysis from step S3, combine the consequence description and semi-quantitative classification from step S4, and implement dynamic risk assessment using the constructed integrated safety risk model. The security integrated risk model constructed is as follows: ; Where R is the combination of the probability and consequences of unacceptable events at the production site, C is the consequence of adverse effects on personnel, property, environment, or reputation at the production site, Fa is the probability of functional safety failure, and Fe is the probability of information security attacks. The functional safety parameter online analysis model constructed is as follows: ; Where De is the demand rate, SIL is the safety integrity capability of the safety instrumented system, and PL is the probability of failure of other protection layers; De determines the operating mode of the functional safety system, including the low-demand operating mode LowDe and the high-demand or continuous operating mode HicDe. Specifically: ; ; The constructed online analysis model of information security parameters is as follows: ; Among them, Fe is the possibility of information security, SLact is the completeness of the ability to achieve information security protection, and A is the possibility of launching an attack.
2. The risk assessment method based on online analysis of SIS safety integrated parameters according to claim 1 is characterized in that: The safety integrity capability of the safety instrumented system includes systemic safety integrity and hardware safety integrity; Systemic safety integrity is achieved based on the inherent characteristics and engineering and operation and maintenance of each component that makes up the safety instrumented system; The specific content of hardware security integrity is Real-time online analysis of key parameters affecting the safety integrity of safety instrumented systems, including failure rate λ, common cause failure β, verification test interval T1, diagnostic test interval T2, diagnostic coverage DC, voting structure MooN, hardware fault margin HFT, and mean time to recovery MTTR; Based on the online analysis results of key parameters and in accordance with the requirements of the IEC61508 standard, probabilistic modeling is performed between various underlying parameters and PFDavg / PFH and architectural constraints, as well as the mapping relationship between PFDavg / PFH and architectural constraints and SIL.
3. The risk assessment method based on online analysis of SIS safety integrated parameters according to claim 2 is characterized in that: The specific contents of the online analysis of key parameters are as follows: The failure rate λ includes the prior existing basic failure rate data and the failure statistics during operation; The prior basic failure rate data is directly obtained from the manual of the safety system; Failure statistics during operation are based on the collection of original failure conditions using the safety data dictionary, and statistical analysis and modeling are carried out: ; in, is the expected failure rate data during operation, n is the number of failures during operation, is the total operating service time; Construct an evaluation table for common cause failure factors based on the IEC 61508-6 standard, monitor each evaluation item in real time, and calculate common cause failure factors in real time; Through the maintenance management system corresponding to the equipment, the time of each maintenance is obtained in real time, and the average test interval is calculated: T1 = time difference between two inspection tests; The diagnostic test interval T2 is obtained in real time through the self-diagnostic data of the corresponding safety equipment: T2 = time difference between two diagnostic tests; By monitoring the failure rate and the diagnostic status in real time, the diagnostic coverage DC is calculated in real time: DC = Dangerous diagnosable failure λ DD / Dangerous failureλ D ; The initial voting structure is input according to the design requirements of the safety equipment, and the equipment degradation status is automatically obtained through the real-time self-diagnosis of the safety equipment during operation; According to the voting structure MooN, the hardware fault margin HFT is calculated in real time: HFT=NM; The mean time to recovery (MTTR) is calculated based on the time difference between when the equipment stops working and when it returns to normal operation. The probability of failure of other protective layers PL is assigned using a fixed static probability.
4. The risk assessment method based on online analysis of SIS safety integrated parameters according to claim 1 is characterized in that: The completeness of the ability to achieve information security protection SLact refers to the various security attributes that affect information security, including timely response to information security incidents, controlled data flow, data confidentiality, identification and authentication control, use control, system integrity and resource availability; Measure the security attribute parameters that affect information security, realize online monitoring of various security attributes, and determine the degree of loss of information security protection capabilities based on the monitoring conclusions and the weighted scoring table. The degree of loss is proportional to the risk of suffering information security damage.
5. The risk assessment method based on online analysis of SIS safety integrated parameters according to claim 4 is characterized in that: The information security integrity SLact is specifically: ; SeSum is the total information security attribute score calculated by adding all weights of applicable information security attributes configured on the device, and SeCal is the actual information security attribute score calculated in real time based on all effective technical measures. The evaluation of the probability A of launching an attack is obtained by assigning a probability based on the conclusion of the initial SL assessment.
6. The risk assessment method based on online analysis of SIS safety integrated parameters according to claim 1 is characterized in that: The specific contents of the consequence description and semi-quantitative grading are as follows: Structuring a statement of consequences based on risks to people, property, the environment, and reputation; categorize the severity of specific consequences for people, property, reputation, and the environment; A semi-quantitative classification is carried out based on the risk consequence description and severity classification, and a risk matrix severity description table is established.
7. An intelligent networked industrial control safety integrated risk assessment system, characterized by: A risk assessment method based on online analysis of SIS safety integrated parameters according to any one of claims 1 to 6, comprising an initial risk assessment module, an online analysis module for functional safety parameters, an online analysis module for information security parameters, a consequence analysis module, and a safety integrated risk model; The initial risk assessment module is used to conduct hazard identification and initial risk assessment for initial intelligent connected industrial production equipment and systems, determine the overall safety requirements of the object, and establish the initial safety integrity level target (SIL) and information security level target (SL); The functional safety parameter online analysis module is used to build an online analysis model for key functional safety parameters based on the key parameters that affect the safety integrity capability of the safety instrumented system and the real-time dynamic changes during operation. It also uses the relationship between safety parameters and SIL to form a dynamic analysis of SIL. The information security parameter online analysis module is used to build an information security parameter online analysis model based on the completeness of information security protection capabilities and the possibility of real-time attacks, combined with key information security parameters that meet the requirements of the IEC 62443 standard, to form a dynamic analysis of SL; Consequence analysis module, used to construct descriptions and semi-quantitative classifications of consequences when safety goals cannot be achieved; The safety-integrated risk model is used to construct a typical risk matrix. Based on the real-time dynamic analysis of functional safety and information security, combined with the description of consequences and semi-quantitative classification, the safety-integrated risk model is used to achieve dynamic risk assessment.
Citation Information
Patent Citations
SIL (safety integrity level) judgment method for safety-instrument system for LNG (liquefied natural gas) project
CN104504502A
Risk-based optimization method for safety instrument system of heating furnace
CN104678955A