Safety analysis method and system for fire-related danger-related production line interlocking system

By establishing a system-level safety constraint table and an initial control feedback model, combining STPA analysis methods and refined processing, the limitations in the safety analysis of fire-related and hazardous production lines are solved, and more comprehensive safety design and analysis are achieved, and the safety of the production line is improved.

CN120235451AInactive Publication Date: 2025-07-01INFORMATION CENT OF CHINA NORTH IND GRP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510299534.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-07-01
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing technology has limitations in the safety analysis of fire-related and hazardous production lines. It is mainly based on the security analysis method based on event chains and the "brainstorm" method of hazards and operability analysis. It cannot effectively capture the hazards at the interactive level of the system, and the safety interlocking system of the industrial control system is not regarded as an important link, resulting in insufficient safety design.

Method used

The system-level security constraint table and initial control feedback model are adopted, combined with STPA analysis methods, unsafe control behavior and system-level hazards are identified, and personnel behavior intelligent identification, detection system and network security monitoring system are introduced through refined processing to form a refined control feedback model for design and development.

Benefits of technology

Through system-level safety analysis and refined processing, potential problems in fire-related and hazardous production line interlocking systems can be more effectively identified, safety design can be improved, rework needs can be reduced, and comprehensive overall safety analysis can be achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005311089130000081
    Figure BDA0005311089130000081
  • Figure BDA0005311089130000091
    Figure BDA0005311089130000091
  • Figure BDA0005311089130000101
    Figure BDA0005311089130000101
Patent Text Reader

Abstract

The invention discloses a safety analysis method and system for an interlocking system of a fire-related danger-related production line, and the method employs an STPA analysis technology to analyze the harm caused by the unsafe interaction between assemblies in the interlocking system of the fire-related danger-related production line. In combination with an abstract refinement analysis technology, safety analysis is executed in the early stage of fire-related danger-related production line interlocking system and demand development, potential problems can be identified more effectively, and the demand of future reworking is reduced. In addition, top-down analysis is realized through abstract and refined analysis, the analysis logic is strict, and the structure is clear; and finally, all intermediate results of the abstract refinement analysis process can be accumulated in the final model, so that comprehensive overall safety analysis can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of system security analysis, and particularly to a method and system for analyzing the security of an interlocking system for a fire and hazard-involved production line. Background Art

[0002] In the production process of products in industries involving fire and explosives, hazardous chemicals, civil explosives, etc., safety is the first element. In recent years, in order to improve the level of safe production, product quality and production efficiency, enterprises involving fire and hazards have adopted advanced process technology methods and technical means of automation, informatization, digitization and networking in the production processes of preparing fire and explosives, producing hazardous chemicals and assembling civil explosive devices, optimized and upgraded process equipment, constructed industrial software and hardware such as industrial control systems, manufacturing execution systems, safety monitoring systems, intelligent sensors, explosion-proof cameras, etc., and realized the effective operation of the material flow, information flow and energy flow of the fire and hazard-involved production line through system integration, improved the production capacity of the production line, reduced the number of dangerous operation personnel, and improved the level of safe production control to a certain extent.

[0003] With the continuous evolution of the diversification and dynamic nature of enterprise production factor resources, the trend of frequent occurrence of safety production accidents caused by personnel's illegal operations, system design defects, destructive viruses, chemical substances releasing combustible gases, etc. in the fire and hazard-involved production line has not been effectively curbed. The reason is that for a highly complex system such as a fire and hazard-involved production line, the causes of system accidents mostly occur at the system interaction level (such as component interaction, personnel operation errors, design defects, external threats, etc.). System Theoretic Process Analysis (STPA) is a new hazard analysis technology applicable to complex systems, which captures the hazard behaviors generated by component interaction. The main steps for implementing STPA are as follows: defining system objectives; determining system-level hazards and boundaries; constructing a hierarchical control structure; identifying unsafe control behaviors; and finding the causes of accidents. According to the steps provided by STPA, the cause of system hazards - control defects - can ultimately be found.

[0004] However, there are still some problems in the current research on the safety analysis of fire and hazard-involved production lines:

[0005] (1) The safety analysis of fire and hazard-involved production lines is still mainly limited to traditional event-chain-based safety analysis methods such as fault tree analysis, failure mode and effect analysis, and the "brainstorming" safety analysis method of hazard and operability analysis. The results of these methods no longer meet the safety requirements demonstrated by today's fire and hazard-involved production lines.

[0006] (2) In the process of implementing the industrial control system for fire- and hazard-involved production lines, only the functional designs of products such as the supervisory control and data acquisition system (SCADA), distributed control system (DCS), and programmable logic controller (PLC) have been considered currently. The safety interlock system (SIS) of the industrial control system has not been regarded as an important link in the prevention and control of production safety, resulting in insufficient consideration of the safety design of the production line and failure to systematically promote the design and requirements of the fire- and hazard-involved production line from the very beginning.

[0007] (3) In the process of implementing the safety interlock control for a small number of fire- and hazard-involved production lines, usually only the safety interlock control for process equipment data acquisition (such as liquid level control, temperature control, pressure control, flow control, etc.) has been considered, lacking the interaction between the safety of production line personnel behavior, the safety of production line equipment / tooling, the safety of production line network information, the safety of production line operating environment, etc. and the interlock system; moreover, the existing interlock control programs are only deployed on the production line and cannot meet the high requirements of multi-level supervision of production safety in the fire- and hazard-involved industries.

[0008] (4) In the implementation of the fire- and hazard-involved production line, part of the work has carried out the safety design of the production line industrial control system using STPA, but the overall system safety of the "fire- and hazard-involved production line" has not been taken as the research object. The safety of the fire- and hazard-involved production line needs to comprehensively consider the interaction relationships between manufacturing resources such as operators, process equipment, industrial software and hardware, and process flows and process methods. Its safety requirements include multiple aspects such as material safety, equipment safety, personnel behavior safety, industrial software process control safety, industrial software network information safety, and perimeter environment safety. Hazards or threats in each aspect may cause system-level safety risks, and there are potential risks of exclusive behaviors between some manufacturing resources. How to form an organically unified safety requirement for these aspects and provide a system-level solution is an urgent problem to be solved. Summary of the Invention

[0009] Aiming at the deficiencies of the prior art, the present invention aims to provide a method and system for analyzing the safety of the interlock system of a fire- and hazard-involved production line.

[0010] To achieve the above object, the present invention adopts the following technical solutions:

[0011] A method for analyzing the safety of the interlock system of a fire- and hazard-involved production line includes the following steps:

[0012] Step 100: Establish a system-level safety constraint table and an initial control feedback model for the interlock system of the fire- and hazard-involved production line; the system-level safety constraint table is used to describe and define system-level accidents and corresponding system-level hazards;

[0013] The initial control feedback model includes an industrial control system, a video monitoring and calling system, devices, isolation devices, and an interlocking system for the fire- and hazard-involved production line; the devices are various sensing elements and execution units in the fire- and hazard-involved production line, and the devices feed back their own startup, operation, and stop status information to the interlocking system for the fire- and hazard-involved production line; the industrial control system is used to send control instructions for the devices, as well as process route and process parameter information of the fire- and hazard-involved production line, to the interlocking system for the fire- and hazard-involved production line; the interlocking system for the fire- and hazard-involved production line is used to send control instructions for the devices to the corresponding devices, send control information for opening or closing the isolation device to the isolation device, send personnel quantity control requirements to the video monitoring and calling system, and feed back control information for the devices to the industrial control system; the isolation device is used to feed back the status information of whether the isolation device is enabled or not to the interlocking system for the fire- and hazard-involved production line; the video monitoring and calling system is used to feed back the personnel quantity information on the fire- and hazard-involved production line to the interlocking system for the fire- and hazard-involved production line;

[0014] Step 200: Based on the system-level safety constraint table constructed in Step 100, use the STPA analysis method to determine the safety analysis results of the initial control feedback model; the safety analysis results include unsafe control behaviors that may cause hazards, system-level hazards corresponding to the unsafe control behaviors, and safety constraints for the system-level hazards corresponding to the unsafe control behaviors;

[0015] Step 300: Judge whether the initial control feedback model meets the preset safety conditions, including judging whether the initial control feedback model is the final actually required safety control model and whether it can achieve the desired safety control effect;

[0016] Step 400: If the initial control feedback model meets the preset safety conditions, design and develop the interlocking system for the fire- and hazard-involved production line based on the safety analysis results of the initial control feedback model;

[0017] Step 500: If the initial control feedback model does not meet the preset safety conditions, perform refinement processing on the initial control feedback model to obtain a refined control feedback model; the refinement processing includes introducing one or more of intelligent recognition of personnel behavior, introducing a reagent or product detection system, introducing an equipment detection system, introducing a tooling detection system, introducing an environmental monitoring system, and introducing a network security monitoring system;

[0018] Step 600: Design and develop the interlocking system for the fire- and hazard-involved production line based on the safety analysis results of the refined control feedback model.

[0019] Further, in step 100, system-level accidents are defined as the following three categories: the occurrence of combustion and explosion of chemicals, equipment damage but no harm to personnel; the occurrence of combustion and explosion of chemicals, equipment damage and harm to personnel; the complete paralysis of the fire and hazardous chemical production line; accidents caused by the failure of the interlock system of the fire and hazardous chemical production line, which are system-level hazards.

[0020] Further, in step 200, analyze the control behaviors that may cause hazards to obtain a set of unsafe control behaviors corresponding to system-level hazards; for each control operation in the industrial control system, analyze whether the obtained unsafe control behaviors will cause system-level hazards and which system-level hazards will be caused; then set corresponding safety constraints according to the unsafe control behaviors and the corresponding system-level hazards.

[0021] Furthermore, unsafe control behaviors are divided into four types: a) no control operation is provided; b) an unsafe control operation is provided, which will cause hazards; c) a control operation with premature, late or incorrect sequence is provided; d) a control operation is provided, but the duration of the control behavior is too long or stops too early.

[0022] Further, in step 500, when performing multiple refinement processes, after each refinement process, obtain the corresponding safety analysis results for the obtained control feedback model according to step 200, and judge whether it meets the preset safety conditions. If it meets, use the control feedback model obtained this time as the refined control feedback model.

[0023] Further, the above method further includes: performing a cause analysis on the initial control feedback model to determine the inducing factors of the unsafe control behaviors corresponding to the system-level hazards.

[0024] The present invention discloses a safety analysis system for the interlock system of the above-mentioned fire and hazardous chemical production line, including:

[0025] A safety constraint and control model establishment module, used to establish a system-level safety constraint table and an initial control feedback model for the interlock system of the fire and hazardous chemical production line; the system-level safety constraint table includes system-level accidents and corresponding system-level hazards;

[0026] A safety analysis module, used to obtain the safety analysis results of the initial control feedback model by using the STPA analysis method based on the system-level safety constraint table; the safety analysis results include unsafe control behaviors that may cause hazards, the system-level hazards corresponding to the unsafe control behaviors, and the safety constraints of the system-level hazards corresponding to the unsafe control behaviors;

[0027] A control model judgment module, used to judge whether the initial control feedback model meets the preset safety conditions;

[0028] The first development module is used to design and develop the interlock system of the fire and hazard-involved production line based on the safety analysis result of the initial control feedback model when the initial control feedback model meets the preset safety conditions;

[0029] The refinement processing module is used to refine the initial control feedback model to obtain a refined control feedback model when the initial control feedback model does not meet the preset safety conditions; the refinement processing includes introducing one or more of intelligent identification of personnel behavior, introducing a reagent / product detection system, introducing an equipment detection system, introducing a tooling detection system, introducing an environmental monitoring system, and introducing a network security monitoring system;

[0030] The second development module is used to obtain the safety analysis result of the refined control feedback model by using the STPA analysis method based on the system-level safety constraint table, and design and develop the interlock system of the fire and hazard-involved production line based on the safety analysis result of the refined control feedback model.

[0031] The beneficial effects of the present invention are as follows: The method of the present invention adopts the STPA analysis technology to analyze the hazards caused by unsafe interactions between components in the interlock system of the fire and hazard-involved production line; combined with the abstract refinement analysis technology, safety analysis is performed in the early stage of the interlock system and requirement development of the fire and hazard-involved production line, which can more effectively identify potential problems, thereby reducing the need for future rework. In addition, the method of the present invention realizes top-down analysis through abstract refinement analysis, with strict analysis logic and clear structure; finally, all intermediate results of the abstract refinement analysis process can be accumulated in the final model, so as to realize comprehensive overall safety analysis. Description of the Drawings

[0032] Figure 1 It is the flowchart of the method in Embodiment 1 of the present invention;

[0033] Figure 2 It is the structure diagram of the preliminary control feedback model in Embodiment 1 of the present invention;

[0034] Figure 3 It is the structure diagram of the refined control feedback model in Embodiment 1 of the present invention;

[0035] Figure 4 It is the system structure diagram in Embodiment 2 of the present invention. Detailed Embodiments

[0036] The following will further describe the present invention with reference to the drawings. It should be noted that this embodiment is based on the present technical solution and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to this embodiment.

[0037] Embodiment 1

[0038] This embodiment provides a method for analyzing the safety of an interlock system for a fire and hazard - involved production line, as Figure 1 shown, which includes the following steps:

[0039] Step 100: Establish a system - level safety constraint table and an initial control feedback model for the interlock system of the fire and hazard - involved production line; the system - level safety constraint table is used to describe and define system - level accidents and corresponding system - level hazards.

[0040] Specifically, in this embodiment, a system - level safety constraint table is constructed based on the operating conditions and environment of the fire and hazard - involved production line. The overall safety goal of the interlock system for the fire and hazard - involved production line is to avoid accidents unacceptable to the fire and hazard - involved production line. In this embodiment, system - level accidents are defined as the following three categories: the occurrence of combustion and explosion of pharmaceuticals, equipment damage but no harm to personnel; the occurrence of combustion and explosion of pharmaceuticals, equipment damage and harm to personnel; the complete paralysis of the fire and hazard - involved production line.

[0041] Limit the system - level accidents to the controllable part of the interlock system for the fire and hazard - involved production line, so as to obtain the accidents caused by the failure of the interlock system for the fire and hazard - involved production line, that is, system - level hazards. Table 1 takes the high - energy explosive step - by - step pressing and charging production line as an example, showing the corresponding relationship between system - level hazards and system - level accidents in the interlock system for the fire and hazard - involved production line.

[0042] Table 1

[0043]

[0044]

[0045]

[0046]

[0047]

[0048] The structure of the initial control feedback model is as Figure 2 shown, where the solid lines represent control actions and information feedback. In the initial control feedback model, only the control actions of equipment startup and shutdown, the control actions of isolation device startup and shutdown, and the control requirements for the number of personnel on the production line are established. The initial control feedback model can intuitively and concisely reflect the control relationship in the interlock system for the fire and hazard - involved production line.

[0049] Specifically, the initial control feedback model includes an industrial control system (SCADA / DCS / PLC), a video monitoring and calling system, devices, isolation devices, and a production line interlock system related to fire and hazards (CI), where the production line interlock system related to fire and hazards is a key safety component of the control feedback model. The devices are various sensing elements and execution units in the production line related to fire and hazards, and the devices feedback their start, operation, and stop status information to the production line interlock system related to fire and hazards; the industrial control system (SCADA / DCS / PLC) is used to send control instructions for the devices (such as opening / closing and adjustment instructions for execution elements such as valves and motors) and process route and process parameter information of the production line related to fire and hazards to the production line interlock system related to fire and hazards; the production line interlock system related to fire and hazards is used to send control instructions for the devices to the corresponding devices, send control information for opening or closing the isolation device to the isolation device, send personnel quantity control requirements to the video monitoring and calling system, and feedback control information for the devices to the industrial control system; the isolation device is used to feedback the enabled or disabled status information of the isolation device to the production line interlock system related to fire and hazards; the video monitoring and calling system is used to feedback the personnel quantity information on the production line related to fire and hazards to the production line interlock system related to fire and hazards.

[0050] Step 200: Based on the system-level safety constraint table constructed in Step 100, use the STPA analysis method to determine the safety analysis result of the initial control feedback model; the safety analysis result includes unsafe control behaviors that may cause hazards, system-level hazards corresponding to the unsafe control behaviors, and safety constraints of the system-level hazards corresponding to the unsafe control behaviors.

[0051] According to Figure 2 , analyze the control behaviors that may cause hazards to obtain a set of unsafe control actions (UCA) corresponding to the system-level hazards. Unsafe control behaviors can be divided into four types: a) No control operation is provided (not provided as shown in Table 2); b) An unsafe control operation is provided, which will cause hazards (provided as shown in Table 2); c) A control operation is provided with an early, late, or incorrect sequence (wrong timing or sequence as shown in Table 2); d) A control operation is provided, but the duration of the control behavior is too long or stops too early (too long action time or ends too fast as shown in Table 2).

[0052] For each control operation in the industrial control system, analyze whether it will cause system-level hazards according to the above four types of unsafe control behaviors, and which (several) system-level hazards (H1-Hn) will be caused, as shown in Table 2 below.

[0053]

[0054]

[0055]

[0056] And further, corresponding safety constraints are set according to the unsafe control behaviors and the corresponding system-level hazards, as shown in Table 3.

[0057] Table 3

[0058]

[0059] Step 300: Determine whether the initial control feedback model meets the preset safety conditions, including determining whether the initial control feedback model is the ultimately actually required safety control model and whether it can achieve the desired safety control effect. Specifically, it can be determined by checking and analyzing each structure of the initial control feedback model.

[0060] Step 400: If the initial control feedback model meets the preset safety conditions, then design and develop the fire and hazard-involved production line interlock system based on the safety analysis results of the initial control feedback model, including aspects such as process interlocks, key action interlocks, and external interface condition interlocks that affect the safe operation of the fire and hazard-involved production line.

[0061] Step 500: If the initial control feedback model does not meet the preset safety conditions, then refine the initial control feedback model to obtain a refined control feedback model; the refinement process includes introducing one or more of intelligent identification of personnel behavior, introducing a reagent / product detection system, introducing an equipment detection system, introducing a tooling detection system, introducing an environmental monitoring system, and introducing a network security monitoring system.

[0062] Specifically, multiple refinement processes can be carried out. After each refinement process, the corresponding safety analysis results are obtained for the obtained control feedback model according to Step 200, and it is determined whether it meets the preset safety conditions. If it meets, the obtained control feedback model this time is used as the refined control feedback model.

[0063] In this embodiment, the initial control feedback model is refined six times, and the specific steps are as follows:

[0064] The first refinement: Upgrade the video surveillance call system to an intelligent video surveillance system, and implement personnel behavior safety monitoring events through an intelligent identification algorithm for personnel behavior.

[0065] The second refinement: Add a reagent / product detection system, including implementing quality qualification detection events for reagents or products.

[0066] Third refinement: Add an equipment detection system, including implementing the detection event for the qualified planar accuracy of the press-charging machine equipment.

[0067] Fourth refinement: Add a tooling detection system, including implementing the detection event for the qualified quality of the press-charging screw.

[0068] Fifth refinement: Add an environmental monitoring system, including implementing the detection event for the qualified system environment during the press-charging process.

[0069] Sixth refinement: Add a network security monitoring system, including implementing the detection event for the network information security of industrial software and hardware.

[0070] When the control feedback model obtained after the sixth refinement process meets the preset safety conditions, mark the control feedback model obtained after the sixth refinement process as the refined control feedback model. The structural schematic diagram of this refined control feedback model is as Figure 3 shown.

[0071] The safety analysis results of the refined control feedback model are specifically shown in Tables 3 and 4.

[0072] Table 3

[0073]

[0074]

[0075]

[0076] Table 4

[0077]

[0078] Step 600: Design and develop an interlock system for the fire and hazard-related production line based on the safety analysis results of the refined control feedback model.

[0079] The method of this embodiment further includes the step of performing a cause analysis on the initial control feedback model to determine the inducing factors of the control behaviors corresponding to the system-level hazards, so as to study why unsafe control behaviors occur and how unsafe control behaviors cause hazards. Taking UCA1 as an example, the cause analysis of UCA1 is given below. UCA1: The system provides incorrect process routes or process parameters, and the uncontrollable factors generated thereby include:

[0080] 1: There are vulnerabilities in the control logic algorithm of the industrial control system itself.

[0081] 2: The process control information sending module of the industrial control system fails to work properly and transmits incorrect process program information.

[0082] 3: The device start / stop information sending module of the industrial control system fails to work properly and transmits incorrect device start / stop information.

[0083] 4: During the operation of the equipment on the fire and hazard-involved production line, the industrial control system transmits incorrect process control instructions.

[0084] 5: The control instructions sent by the industrial control system to the interlock system of the fire and hazard-involved production line are affected by network attacks during transmission, and incorrect instruction information is transmitted.

[0085] 6: The receiving device of the interlock system of the fire and hazard-involved production line fails to work properly and receives incorrect process program information.

[0086] 7: The receiving device of the interlock system of the fire and hazard-involved production line fails to work properly and receives incorrect device start / stop information.

[0087] 8: The sending device of the interlock system of the fire and hazard-involved production line fails to work properly and feeds back incorrect process program information.

[0088] 9: The sending device of the interlock system of the fire and hazard-involved production line fails to work properly and feeds back incorrect device start / stop information.

[0089] 10: The device start / stop information receiving module of the industrial control system fails to work properly and receives incorrect device start / stop information.

[0090] 11: The control information fed back by the interlock system of the fire and hazard-involved production line to the industrial control system is affected by network attacks during transmission, and incorrect instruction information is transmitted.

[0091] In practical applications, by troubleshooting and analyzing the uncontrollable factors that lead to UCA1: The system provides incorrect process routes or process parameters, specifically by matching with the 11 known possible causes mentioned above to determine the cause of the dangerous behavior, and further ensuring the safety of the interlock system of the fire and hazard-involved production line during operation.

[0092] Embodiment 2

[0093] As Figure 4 shown, in order to implement the method described in Embodiment 1, this embodiment provides a safety analysis system for the interlock system of a fire and hazard-involved production line, including: a safety constraint and control model establishment module 101 for establishing a system-level safety constraint table and an initial control feedback model for the interlock system of the fire and hazard-involved production line; the system-level safety constraint table includes system-level accidents and corresponding system-level hazards.

[0094] A safety analysis module 201, configured to obtain a safety analysis result of the initial control feedback model by using the STPA analysis method based on the system-level safety constraint table; the safety analysis result includes unsafe control behaviors that may cause hazards, system-level hazards corresponding to the unsafe control behaviors, and safety constraints of the system-level hazards corresponding to the unsafe control behaviors.

[0095] A control model judgment module 301, configured to judge whether the initial control feedback model meets a preset safety condition.

[0096] A first development module 401, configured to, when the initial control feedback model meets the preset safety condition, perform design and development of the fire and hazard-involved production line interlock system based on the safety analysis result of the initial control feedback model.

[0097] A refinement processing module 501, configured to, when the initial control feedback model does not meet the preset safety condition, perform refinement processing on the initial control feedback model to obtain a refined control feedback model; the refinement processing includes introducing one or more of intelligent identification of personnel behaviors, introducing a reagent / product detection system, introducing an equipment detection system, introducing a tooling detection system, introducing an environmental monitoring system, and introducing a network security monitoring system.

[0098] A second development module 601, configured to obtain a safety analysis result of the refined control feedback model by using the STPA analysis method based on the system-level safety constraint table, and perform design and development of the fire and hazard-involved production line interlock system based on the safety analysis result of the refined control feedback model.

[0099] For those skilled in the art, various corresponding changes and deformations can be given according to the above technical solutions and concepts, and all such changes and deformations should be included within the protection scope of the claims of the present invention.

Claims

1. A safety analysis method for interlocking systems of fire-related and hazardous production lines, characterized in that: The steps include: Step 100: Establish a system-level safety constraint table and an initial control feedback model for the fire-related and hazardous production line interlocking system; the system-level safety constraint table is used to describe and define system-level accidents and corresponding system-level hazards; The initial control feedback model includes industrial control systems, video surveillance call systems, equipment, isolation devices, and fire-related and hazardous production line interlocking systems; the equipment is various sensor elements and execution units in the fire-related and hazardous production line, and the equipment feeds back its own start, run, and stop status information to the fire-related and hazardous production line interlocking system; The industrial control system is used to send control instructions for equipment and process routes and process parameter information of the fire-related and hazardous production line to the fire-related and hazardous production line interlocking system; The fire-related and hazardous production line interlocking system is used to send control instructions for equipment to corresponding equipment, send control information for opening or closing the isolation device to the isolation device, send personnel quantity control requirements to the video monitoring call system, and feed back control information for equipment to the industrial control system; the isolation device is used to feed back status information of whether the isolation device is enabled or not to the fire-related and hazardous production line interlocking system; the video monitoring call system is used to feed back information on the number of personnel on the hazardous and fire-related production line to the fire-related and hazardous production line interlocking system; Step 200: Based on the system-level safety constraint table constructed in step 100, the safety analysis results of the initial control feedback model are determined by using the STPA analysis method; the safety analysis results include unsafe control behaviors that may cause danger, system-level hazards corresponding to the unsafe control behaviors, and safety constraints of the system-level hazards corresponding to the unsafe control behaviors; Step 300: determine whether the initial control feedback model meets the preset safety conditions, including determining whether the initial control feedback model is the safety control model actually required in the end, and whether it can achieve the desired safety control effect; Step 400: If the initial control feedback model meets the preset safety conditions, the interlocking system of the fire-related and hazardous production line is designed and developed based on the safety analysis results of the initial control feedback model; Step 500: If the initial control feedback model does not meet the preset safety conditions, the initial control feedback model is refined to obtain a refined control feedback model; the refinement includes introducing one or more of intelligent identification of personnel behavior, introducing a drug or product detection system, introducing an equipment detection system, introducing a tooling detection system, introducing an environmental monitoring system, and introducing a network security monitoring system; Step 600: Design and develop an interlocking system for a fire-related or hazardous production line based on the safety analysis results of the refined control feedback model.

2. The method according to claim 1, characterized in that: In step 100, system-level accidents are defined as the following three categories: explosion of reagents, damage to equipment but no injuries to personnel; explosion of reagents, damage to equipment and injury to personnel; complete paralysis of fire-related or hazardous production lines; accidents caused by failure of the interlocking system of fire-related or hazardous production lines, which are system-level hazards.

3. The method according to claim 1, characterized in that In step 200, the control behaviors that may cause danger are analyzed to obtain a set of unsafe control behaviors corresponding to system-level dangers; for each control operation in the industrial control system, the obtained unsafe control behaviors are analyzed to determine whether they will cause system-level dangers and which system-level dangers will be caused; then corresponding safety constraints are set based on the unsafe control behaviors and the corresponding system-level dangers.

4. The method according to claim 3, characterized in that Unsafe control actions are divided into four types: a) no control action is provided; b) unsafe control action is provided, which may lead to danger; c) control action is provided too early, too late or in the wrong sequence; d) control action is provided, but the control action lasts too long or is stopped too early.

5. The method according to claim 1, characterized in that In step 500, when multiple refinement processes are performed, the corresponding safety analysis results are obtained for the control feedback model obtained after each refinement process according to step 200 to determine whether it meets the preset safety conditions. If so, the control feedback model obtained this time is used as the refined control feedback model.

6. The method according to claim 1, characterized in that Also includes: A causal analysis is performed on the initial control feedback model to determine the inducing factors of the unsafe control behavior corresponding to the system-level hazard.

7. A safety analysis system for the interlocking system of a fire-related or hazardous production line according to any one of claims 1 to 6, characterized in that: include: A safety constraint and control model establishment module is used to establish a system-level safety constraint table and an initial control feedback model for the fire-related and hazardous production line interlocking system; the system-level safety constraint table includes system-level accidents and corresponding system-level hazards; A safety analysis module, configured to obtain safety analysis results of the initial control feedback model based on the system-level safety constraint table by using an STPA analysis method; the safety analysis results include unsafe control behaviors that may cause danger, system-level dangers corresponding to the unsafe control behaviors, and safety constraints of the system-level dangers corresponding to the unsafe control behaviors; A control model judgment module, used to judge whether the initial control feedback model meets the preset safety conditions; A first development module is used to design and develop the fire-related and hazardous production line interlocking system based on the safety analysis results of the initial control feedback model when the initial control feedback model meets the preset safety conditions; A refinement processing module, used for refining the initial control feedback model to obtain a refined control feedback model when the initial control feedback model does not meet the preset safety conditions; the refinement processing includes introducing one or more of intelligent identification of personnel behavior, introducing a medicine / product detection system, introducing an equipment detection system, introducing a tooling detection system, introducing an environmental monitoring system, and introducing a network security monitoring system; The second development module is used to obtain the safety analysis results of the refined control feedback model based on the system-level safety constraint table by using the STPA analysis method, and to design and develop the fire-related and hazardous production line interlocking system based on the safety analysis results of the refined control feedback model.

Citation Information

Patent Citations

  • Safety monitoring and early warning system applied to hazardous chemical substance production

    CN111144700A

  • STPA-based formalization development method and system for safety-critical system and storage medium

    CN113469521A

  • Safety interlocking system development method based on fault tree analysis

    CN115544463A

  • Rail transit interlocking system safety analysis and development method and device

    CN116187104A

  • Rail transit interlocking system safety demand construction method and device, medium and product

    CN118529096A