Safety integrity level (SIL) verification method and device based on wind-solar coupling hydrogen production device, computer device and storage medium

By constructing a SIL verification model and verifying the Safety Instrumented Function (SIF) loop of the wind-solar coupled hydrogen production unit, the problem of low system reliability was solved, the safety and stability of the unit were improved, and the operating costs were reduced.

CN118734556BActive Publication Date: 2025-10-17HUADIAN HEAVY IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410770993.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-14
Publication Date
2025-10-17
Estimated Expiration
2044-06-14

AI Technical Summary

Technical Problem

In practical production applications, wind-solar coupled hydrogen production units suffer from low system reliability, especially posing safety hazards when operating under high-pressure electrolysis and variable environments, and also incurring high maintenance costs.

Method used

By constructing a SIL verification model, a preset database of Safety Instrumented Function (SIF) loops in a wind-solar coupled hydrogen production unit is determined, and calculations and verifications are performed to ensure that each SIF loop meets the corresponding Safety Integrity Level (SIL), including failure rate, structural constraints, and systemic safety integrity verification.

Benefits of technology

It improves the system safety and reliability of the wind-solar coupled hydrogen production unit, reduces operating costs, and ensures stable operation of the unit in variable environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118734556B_ABST
    Figure CN118734556B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of SIL verification, and discloses a safety integrity level SIL verification method and device based on a wind-solar coupling hydrogen production device, computer equipment and a storage medium, wherein a preset database corresponding to a safety instrument function SIF loop in the wind-solar coupling hydrogen production device is determined; a SIL verification model is constructed; the SIF loop is calculated by using the SIL verification model according to the preset database; and a calculation result of the SIF loop is determined; and whether the SIF loop meets a corresponding SIL level is verified according to the calculation result. The technical scheme provided by one or more embodiments of the application can improve the system safety and reliability of the wind-solar coupling hydrogen production device by performing SIL verification on the wind-solar coupling hydrogen production device.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of SIL verification, and particularly relates to a safety integrity level SIL verification method and device based on a wind-solar coupling hydrogen production device, a computer device and a storage medium. BACKGROUND

[0002] The wind-solar coupling hydrogen production device uses renewable energy to produce hydrogen through water electrolysis, and is an important technical means for realizing green energy production. With the global emphasis on renewable energy utilization and carbon emission reduction, the wind-solar coupling hydrogen production technology has gradually become a research and application hotspot. However, the existing wind-solar coupling hydrogen production device has the problem of low system reliability in actual production application scenarios, and needs a better solution. SUMMARY

[0003] Therefore, the present application provides a safety integrity level SIL verification method and device based on a wind-solar coupling hydrogen production device, a computer device and a storage medium to solve the problem of low system reliability of the wind-solar coupling hydrogen production device.

[0004] In one aspect, the present application provides a safety integrity level SIL verification method based on a wind-solar coupling hydrogen production device. The method comprises determining a preset database corresponding to a safety instrument function SIF loop in the wind-solar coupling hydrogen production device; constructing a SIL verification model, using the SIL verification model to calculate the SIF loop according to the preset database, and determining the calculation result of the SIF loop; and verifying whether the SIF loop meets the corresponding SIL level according to the calculation result.

[0005] In another aspect, the present application further provides a safety integrity level SIL verification device based on a wind-solar coupling hydrogen production device. The device comprises a first determining module configured to determine a preset database corresponding to a safety instrument function SIF loop in the wind-solar coupling hydrogen production device; a second determining module configured to construct a SIL verification model, use the SIL verification model to calculate the SIF loop according to the preset database, and determine the calculation result of the SIF loop; and a verification module configured to verify whether the SIF loop meets the corresponding SIL level according to the calculation result.

[0006] In another aspect, the present application further provides a computer device. The computer device comprises a memory and a processor, which are communicatively connected with each other. The memory stores computer instructions. The processor implements the above-mentioned safety integrity level SIL verification method based on a wind-solar coupling hydrogen production device by executing the computer instructions.

[0007] The application also provides a computer readable storage medium, wherein the computer readable storage medium stores computer instructions for enabling a computer to implement the safety integrity level (SIL) verification method for the wind-solar coupling hydrogen production device.

[0008] In the process, the SIF loop of the wind-solar coupling hydrogen production device is verified by the SIL verification model, so as to determine whether the wind-solar coupling hydrogen production device meets the corresponding SIL level, which can improve the system safety and reliability of the wind-solar coupling hydrogen production device and reduce the operation cost of the device. BRIEF DESCRIPTION OF DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the specific embodiments or related art, the drawings needed in the specific embodiments or related art description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0010] Figure 1 is a flowchart of a safety integrity level (SIL) verification method for a wind-solar coupling hydrogen production device provided by an embodiment of the present application;

[0011] Figure 2 is a SIL verification flowchart of a safety integrity level (SIL) verification method for a wind-solar coupling hydrogen production device provided by an embodiment of the present application;

[0012] Figure 3 is a SIL verification flowchart of another safety integrity level (SIL) verification method for a wind-solar coupling hydrogen production device provided by an embodiment of the present application;

[0013] Figure 4 is a structural schematic diagram of a safety integrity level (SIL) verification device for a wind-solar coupling hydrogen production device provided by an embodiment of the present application;

[0014] Figure 5 is a structural schematic diagram of another safety integrity level (SIL) verification device for a wind-solar coupling hydrogen production device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0015] In recent years, with the global attention to renewable energy utilization and carbon emission reduction, wind-solar coupling hydrogen production technology has gradually become a research and application hotspot. However, due to the involvement of various complex physical and chemical processes in the device, and the changeable operation environment, the safety and reliability of the device become the key factors affecting the stable operation and large-scale application of the device.

[0016] The current scheme has the following problems:

[0017] First, the electrolysis process of the wind-solar coupling hydrogen production device is designed to couple high-voltage electricity with chemical reactions, which causes potential safety hazards during device operation.

[0018] Second, the wind-solar coupling hydrogen production device needs to be stably operated under variable environmental conditions, which requires high operation and maintenance costs.

[0019] To solve at least one of the above problems, various embodiments of the present application provide a safety integrity level (SIL) verification method based on a wind-solar coupling hydrogen production device, which includes: determining a preset database corresponding to a safety instrument function (SIF) loop in the wind-solar coupling hydrogen production device; constructing a SIL verification model, calculating the SIF loop using the SIL verification model according to the preset database, and determining the calculation result of the SIF loop; and verifying whether the SIF loop meets the corresponding SIL level according to the calculation result.

[0020] To make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0021] According to the embodiments of the present application, a safety integrity level (SIL) verification method based on a wind-solar coupling hydrogen production device is provided, Figure 1 which is a flowchart of the SIL verification method based on the wind-solar coupling hydrogen production device provided by the embodiments of the present application, as shown in Figure 1 which includes the following steps:

[0022] Step S101, determining a preset database corresponding to a safety instrument function (SIF) loop in the wind-solar coupling hydrogen production device;

[0023] Step S102, constructing a SIL verification model, calculating the SIF loop using the SIL verification model according to the preset database, and determining the calculation result of the SIF loop;

[0024] Step S103, verifying whether the SIF loop meets the corresponding SIL level according to the calculation result.

[0025] In one possible implementation, the wind-solar coupling hydrogen production device refers to a wind-solar coupling water electrolysis hydrogen production device, which realizes a clean hydrogen production process by coupling a wind power generation system, a light power generation system and a water electrolysis hydrogen production system; wherein the wind power generation system and the light power generation system generate electric energy for supplying the water electrolysis hydrogen production system to electrolyze water to produce hydrogen.

[0026] Exemplarily, the wind power generation system can include a wind turbine, and the light power generation system can include a photovoltaic panel.

[0027] In a possible implementation, a safety instrumented function (SIF) loop can be a basic functional unit in a safety instrumented system (SIS); the SIF loop is responsible for detecting, deciding, and performing necessary operations in a specific dangerous situation to ensure process safety.

[0028] Further, a safety integrity level (SIL) can be a standard for quantifying and defining the safety of SIS functions, and the SIL can be divided into four levels, including SIL1, SIL2, SIL3, and SIL4. The higher the SIL level, the higher the safety integrity requirement of the corresponding SIS, that is, the higher the safety performance that the system needs to achieve.

[0029] Among them, SIL1 is the lowest SIL level, suitable for low-risk application scenarios, SIL2 is the medium SIL level, suitable for medium-risk application scenarios, SIL3 is the high SIL level, suitable for high-risk application scenarios, and SIL4 is the highest SIL level, suitable for very high-risk application scenarios.

[0030] In a possible implementation, the SIL level corresponding to the SIS system is determined by determining the average probability (Probability of Failure on Demand, PFD) of dangerous failure that the SIS system can occur within a preset time; wherein the PFD range of SIL1 can be 10 -2 to 10 -1 , the PFD range of SIL2 can be 10 -3 to 10 -2 , the PFD range of SIL3 can be 10 -4 to 10 -3 , and the PFD range of SIL4 can be 10 -5 to 10 -4 .

[0031] In a possible implementation, constructing a SIL verification model can include:

[0032] Collecting preset parameters of the SIF loop;

[0033] Determining the working range and specific function of the SIF loop;

[0034] The system complexity of the SIF loop corresponds to a modeling method according to the data type; wherein the modeling method can include but is not limited to: fault tree analysis, Markov model.

[0035] Among them, the fault tree analysis (Fault Tree Analysis, FTA) can refer to a method of identifying and analyzing potential failure modes in a complex system and their paths leading to the top-level failure of the system; the Markov model can refer to a mathematical tool for describing the transition law between states in a random process.

[0036] In one possible implementation, the SIF loop is calculated using the SIL verification model according to the preset database, and the calculation result of the SIF loop is determined, which can include:

[0037] Determine the SIL verification model, input the collected preset parameters and system definition of the SIF loop into the model, and determine the PFD and other calculation results of each component in the SIF loop and the entire SIF loop.

[0038] Further, according to the calculation result, whether the SIF loop meets the corresponding SIL level is verified, which can include:

[0039] Compare the PFD of the SIF loop determined by the SIL verification model with the PFD range corresponding to the SIL level of the SIF loop to determine whether the SIF loop meets the corresponding SIL level;

[0040] Determine whether the SIL loop meets other performance and safety requirements.

[0041] In one possible implementation, if the calculation results of all SIF loops in the wind-solar coupling hydrogen production device meet the corresponding SIL level, it can be determined that the wind-solar coupling hydrogen production device passes the SIL verification.

[0042] Through the above method, by collecting the preset parameters of the SIF loop and constructing the preset database, the SIL verification model is determined according to the preset database, and whether the calculation result of the SIF loop meets the corresponding SIL level of the SIF loop is verified, thereby SIL verification is performed on the wind-solar coupling hydrogen production device, which can ensure efficient coordination and reliable operation between each SIF loop, thereby improving the operation stability of the wind-solar coupling hydrogen production device.

[0043] In one embodiment, determining the preset database corresponding to the safety instrument function SIF loop in the wind-solar coupling hydrogen production device includes:

[0044] According to the safety instrument system SIS in the wind-solar coupling hydrogen production device, the SIF loop corresponding to the SIS is determined;

[0045] Determine the preset parameters corresponding to the sensor subsystem, logic controller subsystem and actuator subsystem in the SIF circuit respectively; wherein, the preset parameters include but are not limited to: operation mode of the SIF circuit, SIL level requirement of the SIF, test interval, reliability data of the instrument, average recovery time, voting form, service life, test coverage, etc.

[0046] According to the preset parameters, determine the preset database of the SIF circuit.

[0047] In one possible implementation, the SIS system in the wind-solar coupling hydrogen production device can include: sensors, logic controllers and actuators; the SIS system can include at least one SIF circuit, and each SIF circuit can include: a sensor subsystem, a logic controller subsystem and an actuator subsystem.

[0048] The sensor subsystem can detect process variables (such as pressure, temperature, flow, liquid level, etc.) and convert them into electrical signals; the sensor subsystem can include various types of sensors, such as pressure sensors, temperature sensors, flow meters, etc.

[0049] The logic controller subsystem can receive sensor signals, determine whether there is a dangerous situation according to the preset logic, and decide whether to take protective measures; the logic controller subsystem can include programmable logic controllers (PLC) and safety relays.

[0050] The actuator subsystem can execute physical operations to eliminate or reduce danger according to the instructions of the logic controller; the components can include electric valves, pneumatic valves, hydraulic valves, motors, circuit breakers, etc.

[0051] In one possible implementation, according to the safety instrument system SIS in the wind-solar coupling hydrogen production device, the SIF circuit corresponding to the SIS can include:

[0052] Determine the working principle and running logic of the SIS system, for example, under what conditions the SIS system triggers safety functions, how to judge the occurrence of danger and take what measures to deal with the danger;

[0053] Combine the SIS components that perform specific safety functions to determine the SIF circuit, for example, it can include at least one sensor subsystem for detecting danger, at least one logic controller subsystem for analyzing data and triggering control actions, and at least one actuator subsystem for executing corresponding safety measures.

[0054] In one possible implementation, preset parameters of the sensor subsystem, the logic controller subsystem and the actuator subsystem in the SIF circuit are collected, and types of the preset parameters can include: an operation mode of the SIF circuit, a SIL level requirement of the SIF, an interval of proof test, reliability data of the instrument, an average recovery time, a voting form (M out of N, MooN), a service life, a proof test coverage, and the like.

[0055] The operation mode can refer to a running mode of the SIF circuit in the SIS system, the SIL level requirement of the SIF circuit can refer to a safety integrity requirement of the SIF circuit, the interval of proof test can refer to a time interval of performing a complete function test on the SIF circuit, the reliability data of the instrument can include failure rate, average failure interval time, average repair time and the like of each sensor subsystem, logic controller subsystem, actuator subsystem and the like, the average recovery time can refer to an average time required from fault detection to system recovery after a fault occurs, the service life can refer to a time period during which the device can be reliably operated before reaching the designed service life, and the proof test coverage can refer to a type and range of faults that can be detected by the proof test, and is usually expressed in percentage.

[0056] Further, in the voting form MooN, M can represent how many channels or devices need to work normally to meet the system function requirement, and N can represent a total number of redundant channels or devices.

[0057] Exemplarily, 1oo1 can represent a non-redundant configuration, a single channel. Any component failure will cause the system to fail; 1oo2 (1 out of 2): dual redundancy, either of the two channels working normally can meet the system function, which can improve availability, but a single failure will not be immediately detected.

[0058] By the above method, the preset database is constructed according to the collected preset parameters of the sensor subsystem, the logic controller subsystem and the actuator subsystem in the SIF circuit, and the failure rate information contained in the preset database can help to evaluate the expected number of failures of the SIF circuit within a specific time, thereby helping to improve the availability and stability of the system.

[0059] In one embodiment, a SIL verification model is constructed, and the SIL verification model is used to calculate the SIF circuit according to the preset database, to determine a calculation result of the SIF circuit, including:

[0060] The SIL verification model is used to verify the failure rate, the structure constraint and the systematic safety integrity of the SIF circuit;

[0061] The failure rate verification corresponds to a failure rate result, the structure constraint verification corresponds to a structure constraint result, and the systematic safety integrity verification corresponds to a systematic safety integrity result.

[0062] In one possible implementation, the failure rate of the SIF circuit is verified by the SIL verification model, and a failure rate result of the SIF circuit is determined. The failure rate result is compared with a preset failure rate. The structure constraint of the SIF circuit is verified, and a structure constraint result of the SIF circuit is determined. The structure constraint result is compared with a preset structure constraint. The systematic safety integrity of the SIF circuit is verified, and a systematic safety integrity result of the SIF circuit is determined. The systematic safety integrity result is compared with a preset systematic safety integrity.

[0063] Further, the failure rate result can include a failure probability on demand (PFD) and a failure probability per hour (PFH).

[0064] The systematic safety integrity result can include a safe failure fraction (SC) and a systematic capability (STR).

[0065] The structure constraint can include a hardware fault tolerance (HFT).

[0066] By the above method, the failure rate, the structure constraint, and the systematic safety integrity of the SIF circuit are verified, which can improve the reliability, stability, and safety of the system, reduce potential safety risks, and ensure that the system can reliably perform safety functions when facing potential dangers, thereby protecting the safety of the system and personnel.

[0067] In one embodiment, according to the calculation result, whether the SIF circuit meets the corresponding SIL level is verified, including:

[0068] If the failure rate result, the structure constraint result, and the systematic safety integrity result of the SIF circuit all meet the SIL level corresponding to the SIF circuit, it is determined that the SIL verification of the SIF circuit is qualified.

[0069] If each SIF circuit in the wind-solar coupling hydrogen production device is qualified, it is determined that the SIL verification of the wind-solar coupling hydrogen production device is qualified.

[0070] If there is an unqualified SIF circuit in the wind-solar coupling hydrogen production device, the configuration scheme of the SIF circuit is adjusted.

[0071] In a possible implementation, it is judged whether the failure rate result, the structure constraint result and the systematic safety integrity result of the SIF circuit all meet the SIL level corresponding to the SIF circuit. If all meet the SIL level, it is determined that the SIL verification of the SIF circuit is qualified. If any of the results does not meet the SIL level, it is determined that the SIL verification of the SIF circuit is unqualified, and the related configuration scheme of the SIF circuit is adjusted.

[0072] By the above method, the pre-verification can be performed in the preliminary design stage of the wind-solar coupling hydrogen production device, so as to avoid design changes and reduce overdesign and design cost of the wind-solar coupling hydrogen production device.

[0073] In an embodiment, if there is an unqualified SIF circuit in the wind-solar coupling hydrogen production device, the configuration scheme of the SIF circuit is adjusted, including:

[0074] If the SIF circuit is unqualified, the reliability parameters, engineering design files and availability requirements of the SIF circuit are adjusted. The reliability parameters include but are not limited to SIL certification, general data, the engineering design files include but are not limited to a cause-effect table, an interlocking logic diagram and a piping and instrumentation diagram.

[0075] The adjusted SIF circuit is re-verified according to the SIL verification model in terms of failure rate, structure constraint and systematic safety integrity until the failure rate result, the structure constraint result and the systematic safety integrity result of the SIF circuit all meet the SIL level corresponding to the SIF circuit.

[0076] In a possible implementation, if the SIF circuit is unqualified, i.e., does not meet the corresponding SIL level, the availability requirements, maintenance, engineering design files and reliability parameters of the SIL circuit are adjusted until the SIF circuit is qualified.

[0077] The cause-effect table can refer to corresponding actions caused by specific events, the interlocking logic diagram can represent the logical relationship and control strategy of the safety function, the reliability parameters can include reliability data of devices and systems, such as SIL certification and general reliability data, the safety requirements can refer to safety standards and performance indicators that the system must meet, and the availability requirements and maintenance affect the overall reliability and operability of the system and also need to be considered in the SIL verification.

[0078] Exemplarily, Figure 2 is a SIL verification flowchart of a safety integrity level SIL verification method based on a wind-solar coupling hydrogen production device provided by an embodiment of the present application, as shown in Figure 2 , wherein:

[0079] The SIL level of the SIS system is determined, and SIL verification is performed, and the verification result can include but is not limited to: HFT, SC, PFD, PFH, STR; whether the SIS system meets the preset SIL level is determined according to the verification result, if not, the engineering design file, reliability parameter, availability requirement and maintenance condition are adjusted.

[0080] In one embodiment, Figure 3 is another SIL verification flowchart of the safety integrity level SIL verification method based on the wind-solar coupling hydrogen production device provided by the embodiment of the application, comprising the following steps:

[0081] Step S301, constructing a preset database;

[0082] Here, the preset parameters corresponding to the sensor subsystem, the logic controller subsystem and the actuator subsystem in the SIF loop are collected to construct the preset database;

[0083] Step S302, reviewing the completeness of the file;

[0084] Here, the completeness of the preset parameters in the preset database is reviewed;

[0085] Step S303, determining whether it is complete; if yes, go to step S304, if not, return to step S301;

[0086] Here, if it is determined that the preset parameters in the preset database are not complete, return to S301 to re-construct the preset database;

[0087] Step S304, selecting SIF, and building a SIF verification model;

[0088] Here, the SIF loop is selected, and the SIF verification model is constructed according to the preset database;

[0089] Step S305, verifying the compliance, and going to steps S306, S307 and S308;

[0090] Here, according to the SIF verification model, whether the calculation result of the SIF loop meets the corresponding SIL level is verified;

[0091] Step S306, performing failure rate verification;

[0092] Step S30, performing structure constraint verification;

[0093] Step S308, performing system performance constraint;

[0094] Step S309, determining whether the SIF loop meets the SIL level; if yes, go to step S311, if not, go to step 310;

[0095] Step S310, adjust the configuration scheme, enter step S305;

[0096] Step S311, determine whether all SIFs have been verified; if yes, enter step S312, if not, enter step S304;

[0097] Step S312, form a verification report;

[0098] Here, the verification report of the wind-solar coupling hydrogen production device for SIL verification is determined.

[0099] Figure 4 It is a structure diagram of a safety integrity level SIL verification device based on a wind-solar coupling hydrogen production device provided by the embodiment of the application, as shown in the figure, the device can be applied to servers, computers and other intelligent electronic devices; the device comprises a first determination module 401, a second determination module 402 and a verification module 403; Figure 4

[0100] The first determination module 401 is configured to determine a preset database corresponding to a safety instrument function SIF loop in the wind-solar coupling hydrogen production device.

[0101] The second determination module 402 is configured to construct a SIL verification model, calculate the SIF loop using the SIL verification model according to the preset database, and determine a calculation result of the SIF loop.

[0102] The verification module 403 is configured to verify whether the SIF loop meets the corresponding SIL level according to the calculation result.

[0103] The first determination module 401 is configured to determine a SIF loop corresponding to a safety instrument system SIS in the wind-solar coupling hydrogen production device according to the SIS.

[0104] Determine the preset parameters corresponding to the sensor subsystem, the logic controller subsystem and the actuator subsystem in the SIF loop; wherein the preset parameters include but are not limited to: the operation mode of the SIF loop, the SIL level requirement of the SIF, the test interval, the reliability data of the instrument equipment, the average recovery time, the voting form, the service life, the test coverage, etc.

[0105] Determine the preset database of the SIF loop according to the preset parameters.

[0106] The second determination module 402 is configured to perform failure rate verification, structure constraint verification and systematic safety integrity verification on the SIF loop according to the SIL verification model.

[0107] ​determine the failure rate result corresponding to the failure rate verification, the structure constraint result corresponding to the structure constraint verification, and the systematic safety integrity result corresponding to the systematic safety integrity verification;

[0108] The verification module 403 is configured to determine that the SIL verification of the SIF circuit is qualified if the failure rate result, the structure constraint result, and the systematic safety integrity result of the SIF circuit all meet the SIL level corresponding to the SIF circuit.

[0109] If each SIF circuit in the wind-solar coupling hydrogen production device is qualified, it is determined that the SIL verification of the wind-solar coupling hydrogen production device is qualified.

[0110] If there is a SIF circuit that is not qualified in the wind-solar coupling hydrogen production device, the configuration scheme of the SIF circuit is adjusted.

[0111] The verification module 403 is configured to adjust the reliability parameters, the engineering design file, and the availability requirement of the SIF circuit if the SIF circuit is not qualified, wherein the reliability parameters include but are not limited to the SIL certification certificate and the general data, and the engineering design file includes but is not limited to the cause-effect table, the interlocking logic diagram, and the piping and instrumentation diagram.

[0112] The adjusted SIF circuit is re-verified in terms of the failure rate, the structure constraint, and the systematic safety integrity according to the SIL verification model until the failure rate result, the structure constraint result, and the systematic safety integrity result of the SIF circuit all meet the SIL level corresponding to the SIF circuit.

[0113] It should be noted that the above-mentioned embodiments provide a wind-solar coupling hydrogen production device-based safety integrity level SIL verification device for implementing a corresponding wind-solar coupling hydrogen production device-based safety integrity level SIL verification method. In actual application, the above-mentioned processing can be completed by different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-mentioned processing. In addition, the device and the corresponding method provided in the above-mentioned embodiments belong to the same concept, and the specific implementation process is described in the method embodiments, which will not be repeated here. Figure 1 The embodiments of the method shown in the above-mentioned embodiments belong to the same concept, and the specific implementation process is described in the method embodiments, which will not be repeated here.

[0114] To implement the method of the embodiments of the present application, the embodiments of the present application provide a wind-solar coupling hydrogen production device-based safety integrity level SIL verification device, as shown in the above-mentioned embodiments. Figure 5 The device includes a processor 501 and a memory 502 for storing computer programs capable of running on the processor; wherein,

[0115] The processor 501 is configured to determine a preset database corresponding to a safety instrumented function (SIF) loop in the wind-solar coupling hydrogen production device when the computer program is executed, construct a SIL verification model, calculate the SIF loop using the SIL verification model according to the preset database, determine a calculation result of the SIF loop, and verify whether the SIF loop meets the corresponding SIL level according to the calculation result. Specifically, the device can perform the method shown in Figure 1 The safety integrity level (SIL) verification method based on the wind-solar coupling hydrogen production device shown in Figure 1 The safety integrity level (SIL) verification method based on the wind-solar coupling hydrogen production device shown in

[0116] In actual application, as shown in Figure 5 The device can further include at least one network interface 503. The various components in the safety integrity level (SIL) verification device based on the wind-solar coupling hydrogen production device are coupled together through a bus system 504. It can be understood that the bus system 504 is used to realize the connection and communication between the components. The bus system 504 includes not only a data bus, but also a power supply bus, a control bus and a status signal bus. However, for the purpose of clear illustration, all kinds of buses are marked as the bus system 504 in Figure 5 The number of the processor 501 can be at least one. The network interface 503 is used for wired or wireless communication between the safety integrity level (SIL) verification device based on the wind-solar coupling hydrogen production device and other devices.

[0117] The memory 502 in the embodiment of the present application is used to store various types of data to support the operation of the safety integrity level (SIL) verification device based on the wind-solar coupling hydrogen production device.

[0118] The method disclosed in the above embodiment of the present application can be applied to the processor 501 or implemented by the processor 501. The processor 501 can be an integrated circuit chip with a signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit or the instruction in the form of software in the processor 501.

[0119] The processor 501 can be a general processor, a digital signal processor (DSP), or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, etc. The processor 501 can implement or execute the disclosed methods, steps, and logic block diagrams in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the foregoing method can be directly embodied as a hardware code processor for execution, or a combination of hardware and software modules in the code processor for execution. The software module can be located in the storage medium in the memory 502, and the processor 501 reads the information in the memory 502 and combines the hardware to complete the steps of the foregoing method.

[0120] In the example embodiments, the safety integrity level SIL verification device based on the wind-solar coupling hydrogen production device can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors (Microprocessors), or other electronic elements, for executing the foregoing method.

[0121] The embodiments of the present application also provide a computer readable storage medium having a computer program stored thereon; when the computer program is executed by a processor, the following steps are performed: determining a preset database corresponding to a safety instrument function (SIF) loop in a wind-solar coupling hydrogen production device; constructing a SIL verification model, calculating the SIF loop using the SIL verification model according to the preset database, determining a calculation result of the SIF loop; and verifying whether the SIF loop meets the corresponding SIL level according to the calculation result. Specifically, the computer program can also perform the method shown in Figure 1 The method shown in Figure 1 The method embodiments belong to the same concept as the method shown in

[0122] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented by other manners. The apparatus embodiments described above are merely illustrative, for example, the division of the units is merely a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed components can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0123] The units described above as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, that is, they can be located in one place or distributed on a plurality of network units; part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0124] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be realized in the form of hardware or hardware plus software functional unit.

[0125] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware, and the foregoing program can be stored in a computer readable storage medium, and the program executes the steps including the above-mentioned method embodiments when executed; and the foregoing storage medium includes mobile storage device, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disc or optical disc and various storage program codes.

[0126] Alternatively, the integrated unit of the present application, if implemented in the form of a software function module and sold or used as an independent product, can also be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the embodiments of the present application. The foregoing storage medium includes mobile storage device, ROM, RAM, magnetic disc or optical disc and various storage program codes.

[0127] It should be noted that "first", "second", and the like are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.

[0128] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0129] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A safety integrity level (SIL) verification method based on a wind-solar coupled hydrogen production device, characterized in that: The method comprises: Determine the preset database corresponding to the safety instrument function (SIF) loop in the wind-solar coupled hydrogen production device; Constructing a SIL verification model, calculating the SIF loop using the SIL verification model according to the preset database, and determining a calculation result of the SIF loop; Verifying whether the SIF circuit complies with the corresponding SIL level based on the calculation result; The determination of the preset database corresponding to the safety instrument function SIF circuit in the wind-solar coupled hydrogen production device includes: According to the safety instrument system SIS in the wind-solar coupled hydrogen production device, determine the SIF circuit corresponding to the SIS; Determining preset parameters corresponding to the sensor subsystem, the logic controller subsystem, and the actuator subsystem in the SIF loop, respectively; wherein the preset parameters include, but are not limited to: the operating mode of the SIF loop, the SIL level requirement of the SIF, the inspection and test interval, the reliability data of the instrument equipment, the mean time to recovery, the voting method, the service life, and the inspection and test coverage; Determining a preset database of the SIF loop according to the preset parameters; The constructing of the SIL verification model, calculating the SIF loop using the SIL verification model according to the preset database, and determining the calculation result of the SIF loop includes: Verify the failure rate, structural constraints and systemic safety integrity of the SIF circuit according to the SIL verification model; Determining a failure rate result corresponding to the failure rate verification, a structural constraint result corresponding to the structural constraint verification, and a systemic safety integrity result corresponding to the systemic safety integrity verification; Verifying whether the SIF circuit complies with the corresponding SIL level based on the calculation result includes: If the failure rate result, the structural constraint result, and the systemic safety integrity result of the SIF loop all meet the SIL level corresponding to the SIF loop, the SIL verification of the SIF loop is determined to be qualified; If each of the SIF circuits in the wind-solar coupled hydrogen production device is qualified, it is determined that the SIL verification of the wind-solar coupled hydrogen production device is qualified; If the SIF circuit in the wind-solar coupled hydrogen production device is unqualified, adjusting the configuration scheme of the SIF circuit; If the SIF circuit in the wind-solar coupled hydrogen production device is unqualified, adjusting the configuration scheme of the SIF circuit includes: If the SIF circuit fails, adjust the reliability parameters, engineering design documents, and availability requirements of the SIF circuit; wherein the reliability parameters include but are not limited to: SIL certification certificate, general data; the engineering design documents include but are not limited to: cause-and-effect table, interlocking logic diagram, piping and instrumentation diagram; The adjusted SIF loop is re-verified for failure rate, structural constraint and systemic safety integrity according to the SIL verification model until the failure rate results, structural constraint results and systemic safety integrity results of the SIF loop all meet the SIL level corresponding to the SIF loop.

2. The method according to claim 1, characterized in that The safety integrity level (SIL) verification device based on the wind-solar coupled hydrogen production device includes: The first determination module is used to determine the preset database corresponding to the safety instrument function SIF circuit in the wind-solar coupled hydrogen production device; A second determination module is configured to construct a SIL verification model, calculate the SIF loop using the SIL verification model according to the preset database, and determine a calculation result of the SIF loop; A verification module is used to verify whether the SIF circuit meets the corresponding SIL level based on the calculation result.

3. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the safety integrity level (SIL) verification method based on the wind-solar coupled hydrogen production device according to claim 1 or 2 by executing the computer instructions.

4. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, which are used to enable a computer to execute the safety integrity level (SIL) verification method based on the wind-solar coupled hydrogen production device according to claim 1 or 2.

Citation Information

Patent Citations

  • Method for verifying safety integrity level of oil and gas pipeline

    CN111598257A

  • Memory, safety instrument system SIL verification method, system and device

    CN113553687A