High-risk scenario industrial automation safety redundant control system
By acquiring time-series sensing data of high-risk industrial objects to generate a hazardous energy state space and dynamic threshold group, the problem of existing technologies being unable to fully reflect the continuous process of hazardous energy and the deviation of response trajectory is solved, thereby improving the accuracy and reliability of the safety redundancy control system in high-risk industrial scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TIANJIN TOPTECH TECH CO LTD
- Filing Date
- 2026-06-17
- Publication Date
- 2026-07-14
AI Technical Summary
Existing industrial safety control technologies are insufficient to fully reflect the continuous process and response trajectory deviation of dangerous energy in high-risk industrial scenarios, resulting in inadequate reliability and adaptability of safety redundancy actions.
The time-series sensing data of high-risk industrial objects is acquired by the time-series sensing acquisition module, generating a dangerous energy state space, a safety target state, and a dynamic threshold group. Dynamic safety window control is then performed using the residual index and response deviation index to achieve safety-level regulation of high-risk industrial objects.
It improves the accuracy of state identification and process adaptability of high-risk industrial objects during the execution of safety redundancy actions, and enhances the reliability and pertinence of safety control.
Smart Images

Figure CN122386615A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial automation safety control technology, and more specifically, to a redundancy control system for industrial automation safety in high-risk scenarios. Background Technology
[0002] In high-risk industrial settings such as petrochemicals, gas transmission and distribution, hazardous chemical storage and transportation, energy and power, and metallurgy, industrial equipment typically operates under high pressure, high temperature, and with flammable, explosive, toxic, or corrosive media. To mitigate the risk of accidents escalating under abnormal operating conditions, engineering sites are generally equipped with safety instrumented functions, emergency shutdown, interlock protection, backup shut-off, pump shutdown, pressure relief, venting, inerting, ventilation, and fire-fighting linkage safety measures. When pressure, temperature, flow rate, liquid level, combustible gas concentration, or the feedback status of the final actuator reaches preset conditions, existing control methods can trigger corresponding safety actions, and redundant configurations improve the reliability of these safety actions.
[0003] In actual high-risk industrial processes, issuing safety redundancy action commands does not equate to the immediate elimination of the dangerous situation. Within the equipment volume, pipe sections, valve cavities, buffer spaces, and connecting branches of high-risk industrial objects, residual hazardous media, pressure energy, enthalpy, and residual flow may still exist. Especially in scenarios with multi-stage isolation, multiple branch connections, large upstream and downstream pressure differences, or hazardous media with volatile, flammable, or explosive characteristics, even if some shut-off valves, pump sets, or pressure relief devices have responded and acted correctly, hazardous energy may continue to migrate due to pressure backflow, media reversal, delayed pressure relief, heat accumulation, or changes in isolation topology.
[0004] Existing industrial safety control technologies typically rely on whether safety commands are triggered, whether actuators are in place, and whether process parameters exceed limits as key criteria for determining safety status. This approach is clear in structure and direct in response, making it suitable for most conventional interlocking protection scenarios. However, during the execution of safety redundancy actions, judging the safety of high-risk industrial objects solely based on single-point parameters or single execution feedback is insufficient to fully reflect the continuous process of dangerous energy converging from a high-risk state to a safe target state, and it is also difficult to characterize the degree of deviation between the actual response trajectory and the expected response trajectory.
[0005] Furthermore, the process safety time in high-risk scenarios varies with the residual level of hazardous energy, the degree of response deviation, the stage of operation, and the hazardous characteristics of the medium. If the safety confirmation time, transition observation time, upgrade trigger time, and reset prohibition time are still set to fixed values, it may not be able to adapt to the risk changes required at different stages such as accident isolation, shutdown depressurization, and anomaly recovery. Therefore, this invention proposes a safety redundancy control system for industrial automation in high-risk scenarios. Summary of the Invention
[0006] In view of the shortcomings of existing technologies, the purpose of this invention is to provide a safety redundancy control system for industrial automation in high-risk scenarios.
[0007] To achieve the above objectives, the present invention provides the following technical solution: A high-risk scenario industrial automation safety redundancy control system includes: The timing awareness acquisition module is used to acquire timing awareness data of high-risk industrial objects after they receive a safety redundancy action command. The timing awareness data includes process status parameters, isolation topology parameters, hazardous medium property parameters, operating condition stage parameters, feedback parameters of the final actuator, and process safety time. The state space configuration module is used to generate a hazardous energy state space, a safety target state, a set of expected response trajectories, and a set of dynamic thresholds based on time-series sensing data. The set of expected response trajectories includes a residual exponential change benchmark, a response time limit benchmark, and a topological order benchmark. The set of dynamic thresholds includes dynamic safety thresholds and dynamic deviation thresholds. The residual index generation module is used to generate the hazardous energy residual index based on time-series sensing data and the hazardous energy state space; The response deviation generation module is used to generate a command process response deviation index based on safety redundancy action commands, time-series perception data, hazardous energy residual index, and expected response trajectory set. The dynamic time window generation module is used to generate a dynamic safety window based on the residual hazardous energy index, command process response deviation index, time-series perception data, dynamic threshold group, and safety target state. The safety classification and control module is used to perform safety classification and control of high-risk industrial objects within a dynamic safety window, based on the hazardous energy residual index, command process response deviation index, and dynamic threshold group.
[0008] In one embodiment, the process status parameters include at least one of pressure, temperature, flow rate, liquid level, intervalve pressure, and downstream pressure; the isolation topology parameters include at least one of isolation boundary, equipment volume, pipe segment volume, buffer cavity, energy storage unit, transmission path, and safety action node.
[0009] In one embodiment, the state space configuration module is used to map process state parameters, isolation topology parameters, hazardous medium property parameters and operating condition stage parameters into hazardous energy dimensions, and establish state nodes and coupling edges according to isolation boundaries and transmission paths to form a hazardous energy state space.
[0010] In one embodiment, the state space configuration module is further configured to determine the target energy convergence interval based on the safety redundancy action command and the dangerous energy state space, so as to generate a safety target state, and generate a set of expected response trajectories and a dynamic threshold group based on the safety target state, process safety time, isolation topology parameters and operating condition stage parameters.
[0011] In one embodiment, the safety target state is used as the convergence endpoint, the process safety time is used as the constraint, the topological order of the safety action nodes is determined based on the isolation topological parameters, and the residual exponent change benchmark, response time limit benchmark and topological order benchmark are generated by combining the operating condition stage parameters.
[0012] In one embodiment, the generation of the hazardous energy residual index includes: mapping process state parameters, isolation topology parameters, and hazardous medium property parameters to inventory residual quantity, pressure stored energy, enthalpy residual quantity, and residual flow quantity; performing weighted fusion according to the state nodes and coupling edges in the hazardous energy state space; and correcting the fusion result by combining the feedback parameters of the final actuator, thereby generating the hazardous energy residual index.
[0013] In one embodiment, the generation of the command process response deviation index includes: using the safety redundancy action command as the response trigger benchmark, obtaining the change trajectory of the hazardous energy residual index based on the time-series perception data, comparing the change trajectory with the residual index change benchmark, the response time limit benchmark, and the topology sequence benchmark respectively, and combining the working condition stage parameters and hazardous medium property parameters for weighted fusion to generate the command process response deviation index.
[0014] In one embodiment, the dynamic security window includes a security confirmation sub-window, a transition observation sub-window, an upgrade trigger time, and a reset prohibition sub-window.
[0015] In one embodiment, when the dangerous energy residual index increases, the command process response deviation index increases, or the process safety time is shortened, the safety confirmation sub-window is shortened, the transition observation sub-window is compressed, the upgrade trigger time is moved forward, and the reset prohibition sub-window is extended.
[0016] In one embodiment, when the residual hazardous energy index meets the dynamic safety threshold and the command process response deviation index meets the dynamic deviation threshold, the high-risk industrial object is determined to have reached the empirical isolation state; when the high-risk industrial object has not reached the empirical isolation state, a safety upgrade level is generated, and safety redundancy actions are dynamically triggered according to the safety upgrade level; wherein, the safety redundancy actions include at least one of backup cut-off, upstream isolation, pump stop, pressure relief, venting, inerting, ventilation, fire linkage, and reset locking.
[0017] Compared with the prior art, the present invention has the following beneficial effects: This invention acquires time-series sensing data after a high-risk industrial object receives a safety redundancy action command, and incorporates process status parameters, isolation topology parameters, hazardous medium property parameters, operating condition stage parameters, final actuator feedback parameters, and process safety time into the same safety judgment chain. This makes safety status judgment no longer limited to single actuator feedback or single-point process parameters, and can more completely reflect the real risk changes of high-risk industrial objects during the execution of safety redundancy actions, thereby improving the accuracy of safety redundancy control status identification and process adaptability. Based on time-series perception data, a hazardous energy state space, a safety target state, a set of expected response trajectories, and a dynamic threshold group are generated. Furthermore, a hazardous energy residual index and a command process response deviation index are generated. This allows for the quantitative expression of whether hazardous energy converges to the safety target state, whether the actual response of safety redundant action commands conforms to the residual index change benchmark, response time limit benchmark, and topological sequence benchmark. This is beneficial for identifying risks such as hazardous energy residue, response lag, abnormal topological sequence, and inconsistency between execution feedback and actual process state. A dynamic safety window is generated based on the residual hazardous energy index, command process response deviation index, time-series perception data, dynamic threshold groups, and safety target state. Within the dynamic safety window, safety-level control is implemented, enabling the safety control of high-risk industrial objects to be dynamically adjusted according to the degree of residual hazardous energy, the degree of command process response deviation, and the proximity of the safety target state. This improves the hierarchy, targeting, and coordination of safety redundancy action triggering, and enhances the reliability of safety control in high-risk scenarios. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the overall structure of a high-risk scenario industrial automation safety redundancy control system according to the present invention; Figure 2 This is a schematic diagram of the workflow of a high-risk scenario industrial automation safety redundancy control system according to the present invention; Figure 3 This is a schematic diagram illustrating the generation of the safety target state, expected response trajectory set, and dynamic threshold group of the present invention. Detailed Implementation
[0019] Reference Figures 1 to 3 A high-risk scenario industrial automation safety redundancy control system, comprising: The time-series sensing acquisition module is used to acquire time-series sensing data of high-risk industrial objects after they receive a safety redundancy action command. This time-series sensing data includes process state parameters, isolation topology parameters, hazardous medium property parameters, operating condition stage parameters, feedback parameters from the final actuator, and process safety time. It collects continuous data related to changes in safety status based on the actual response process of the high-risk industrial object after receiving the safety redundancy action command. After the safety redundancy action command is issued, changes in process states such as internal pressure, temperature, flow rate, liquid level, inter-valve pressure, and downstream pressure of the high-risk industrial object, combined with isolation topology information such as isolation boundaries, equipment volume, pipe section volume, buffer cavities, energy storage units, transmission paths, and safety action nodes, form a time-series sensing basis. Hazardous medium property parameters reflect the flammability, explosiveness, toxicity, corrosiveness, enthalpy, or phase change characteristics of the medium itself; operating condition stage parameters reflect the differences between different stages such as start-up, shutdown, interlocking actions, abnormal handling, and accident isolation; actuator feedback parameters reflect the action feedback of field actuators such as valves, shut-off devices, pressure relief devices, and pump shutdown devices; process safety time reflects the time constraint that high-risk industrial objects are allowed to complete safety control actions under hazardous conditions. This module provides data sources for the system to identify hazardous energy residues, action response deviations, and dynamic safety windows.
[0020] A unified timing baseline is established at the moment when a high-risk industrial object receives a safety redundancy action command. The receiving time, command type, command target, and command target of the safety redundancy action command are recorded, and the timing perception data of the high-risk industrial object is continuously acquired around this timing baseline. The general limit operator, positive part function, and decision function are defined as follows:
[0021]
[0022]
[0023] in, This represents the value to be processed. Indicates the lower limit. Indicates the upper limit, and ; Indicate the judgment condition; Indicate the judgment condition The function that takes the value of . (The functions mentioned in this article) All follow the above definition. Represents the sample set Arrange in ascending order and then take quantiles, and When the denominator of the formula is a dimensionless quantity, the smallest positive number is denoted as . ,and When the denominator of the formula is a dimensional physical quantity. When, the smallest positive number is denoted as Its value is taken from physical quantity The measurement resolution or computational resolution and The larger value in the reference order. (The values appearing in this article...) All are determined according to the above rules.
[0024] The time-series sensing data includes process status parameters, isolation topology parameters, hazardous medium property parameters, operating condition stage parameters, final actuator feedback parameters, and process safety time. Among them, the process status parameters include at least one of pressure, temperature, flow rate, liquid level, intervalve pressure, and downstream pressure, and the isolation topology parameters include at least one of isolation boundary, equipment volume, pipe segment volume, buffer cavity, energy storage unit, transmission path, and safety action node. The moment when a high-risk industrial object receives a safety redundancy action command is recorded as follows: The sampling period is denoted as , No. The sampling times are:
[0025] Time-aware data is denoted as:
[0026] in, Indicates the sampling time Time-series sensing data, Indicates pressure, Indicates temperature. Indicates flow rate. Indicates liquid level. Indicates the pressure between valves. Indicates downstream pressure. Indicates the isolation topology parameters, This represents the set of feedback parameters for the actuator. Indicates the property parameters of hazardous media. Indicates parameters for operating conditions. This represents the process safety time. The sampling period satisfies:
[0027] in, This represents the minimum number of samples required within the process safety time. Process safety time. The hazard development time is determined according to the safety instrumented function design document, hazard and operability analysis, layer of protection analysis, or process safety analysis document. When a directly given value is unavailable, it is determined using the following formula:
[0028] in, This indicates the time it takes for a dangerous condition to develop from its initial triggering state to unacceptable consequences. This indicates the time it takes for the detection element to identify hazardous operating conditions. This indicates the communication transmission time of the safety redundancy action command. Indicates the time it takes for the actuator to complete the predetermined action. Indicates a safety margin time; when the same safety redundancy action command involves multiple safety action nodes, Take the maximum value among the predetermined action times for each safety action node.
[0029] Taking the emergency shut-off scenario of a liquefied hydrocarbon pipeline as an example, after a high-risk industrial object receives a safety redundancy action command, it continuously samples the upstream pressure, downstream pressure, inter-valve pressure, pipe section temperature, pipe flow rate, and buffer tank level. At the same time, it reads the feedback parameters of the final actuators such as shut-off valves, pressure relief valves, and pump shutdown circuits, and records whether it is in the abnormal isolation stage or the shutdown and pressure relief stage. Combined with the saturated vapor pressure, flash characteristics, and flammability and explosion hazards of liquefied hydrocarbons, it forms hazardous medium attribute parameters. The various types of data obtained are organized according to sampling time, equipment location, isolation boundary and safety action node, and a time-series sensing data sequence under the same safety redundancy action command is established. The equipment volume, pipe section volume, buffer cavity, energy storage unit and transmission path are included in the same isolation topology. The safety action node that has taken action feedback is distinguished from the safety action node that has not reached the predetermined feedback state. The process safety time is combined to determine whether each process state parameter is within the allowable observation range. For example, when the shut-off valve has already been closed but the intervalve pressure continues to rise, the downstream pressure drops slowly, and the pipe section temperature is close to the sensitive range of medium flash evaporation, the time-series sensing data not only records the shut-off valve feedback results, but also simultaneously retains the time correspondence between the intervalve pressure, downstream pressure, residual flow, and pressure relief path status. This forms a data foundation that can reflect the actual changes of high-risk industrial objects after the safety redundancy action command.
[0030] The state-space configuration module is used to generate a hazardous energy state space, a safety target state, a set of expected response trajectories, and a dynamic threshold set based on time-series sensing data. The set of expected response trajectories includes a residual exponential change benchmark, a response time limit benchmark, and a topological order benchmark. The dynamic threshold set includes dynamic safety thresholds and dynamic deviation thresholds. The time-series sensing data is organized into a structured state space that reflects the distribution, transmission, and convergence relationships of hazardous energy in high-risk industrial objects. Based on process state parameters, isolation topology parameters, hazardous medium property parameters, and operating condition stage parameters, a hazardous energy state space is established, and within this state space, the safety target state, the set of expected response trajectories, and the dynamic threshold set are determined. The hazardous energy state space reflects the distribution of hazardous energy in equipment, pipe sections, buffer cavities, energy storage units, and transmission paths; the safety target state reflects the energy convergence state that high-risk industrial objects should achieve under the action of safety redundancy action commands; the expected response trajectory set includes residual exponential change benchmark, response time limit benchmark, and topological sequence benchmark, reflecting the reasonable response law of safety actions in terms of time, energy change, and topological transmission; the dynamic threshold set includes dynamic safety threshold and dynamic deviation threshold, reflecting the changes in safety judgment scale under different operating conditions and hazardous media conditions. The dangerous energy state space is denoted as:
[0031] in, Represents the dangerous energy state space. Represents a set of state nodes. Indicates the first One state node, Indicates the number of state nodes. Represents the set of coupling edges. Indicates the state node Pointing to the state node The transmission, release, pressure transfer, or heat transfer relationships, This represents the number of coupling edges. The set of safety action nodes is denoted as:
[0032] in, Represents the set of safety action nodes. Indicates the first Each security action node, Indicates the number of safety action nodes. Each state node at the sampling time The node process state is denoted as:
[0033] in, State node The set of node process states, Indicates pressure, Indicates temperature. Indicates flow rate. Indicates liquid level. Indicates the pressure between valves. This indicates downstream pressure.
[0034] Based on the time-series perception data of high-risk industrial objects after the safety redundancy action command, process state parameters, isolation topology parameters, hazardous medium attribute parameters and operating condition stage parameters are mapped to hazardous energy dimensions. The hazardous energy dimensions include inventory residual dimension, pressure energy storage dimension, enthalpy residual dimension and residual flow dimension. State nodes and coupling edges are established according to isolation boundaries, equipment volume, pipe section volume, buffer cavity, energy storage unit, transmission path and safety action node to form a hazardous energy state space. For example, in the emergency shut-off scenario of liquefied hydrocarbon pipeline, the pressure before the shut-off valve, the pressure after the shut-off valve, the pressure between valves, the pipe section temperature, the residual flow rate, and the buffer tank level are respectively classified into the corresponding dangerous energy dimensions. The upstream pump outlet, shut-off valve group, inter-valve pipe section, pressure relief branch, and downstream buffer tank are set as state nodes, and the medium flow direction, pressure transmission direction, relief path, and isolation boundary relationship are set as coupling edges. The target energy convergence interval is determined based on the safety redundancy action command and the dangerous energy state space, and the safety target state is generated based on this target energy convergence interval. In the emergency shut-off scenario of liquefied hydrocarbon pipeline, the safety target state includes the pressure difference on both sides of the shut-off valve entering the allowable range, the inter-valve pressure entering the release stability range, the downstream pressure dropping to the safe acceptance range, and the residual flow dropping to the process allowable range. In combination with the flammability and explosion hazard of liquefied hydrocarbons, the current shutdown isolation stage, and the process safety time, the dynamic safety threshold and dynamic deviation threshold are determined. Using the safety target state as the convergence endpoint and the process safety time as the constraint, the topological sequence of safety action nodes is determined based on the isolation topological parameters, and the residual exponent change benchmark, response time limit benchmark, and topological sequence benchmark are generated by combining the operating condition stage parameters. For example, the pump stop, upstream isolation, inter-valve pressure relief, downstream isolation, and reset lockout are arranged according to the transmission path and isolation boundary relationship. The residual exponential change benchmark is set with the pressure storage decreasing segment by segment, the residual flow gradually decaying, and the residual enthalpy entering the stable range. Corresponding response time limit benchmarks are configured for each safety action node. If the shut-off valve has been feedback closed but the inter-valve pressure has not decreased according to the residual exponential change benchmark, or the pressure relief branch action is later than the topological sequence benchmark, it can be determined that the actual response deviates from the expected response trajectory set.
[0035] The residual index generation module generates a hazardous energy residual index based on time-series sensing data and the hazardous energy state space. It quantifies the degree of residual hazardous energy remaining in high-risk industrial objects after safety redundancy actions, based on the same data. By combining process state parameters, isolation topology parameters, hazardous medium property parameters, and feedback parameters from the final actuators, it incorporates inventory residuals, pressure stored energy, enthalpy residuals, and residual flow rates into a unified calculation relationship, fusing them according to state nodes and coupling edges in the hazardous energy state space. Actuator feedback parameters are used to correct the residual results, avoiding reliance solely on the command issuance status while ignoring the actual actions of the on-site actuators. The hazardous energy residual index reflects the level of hazardous energy remaining in high-risk industrial objects after safety redundancy actions such as isolation, disconnection, depressurization, pump shutdown, venting, inerting, or ventilation.
[0036] Based on the time-series perception data and hazardous energy state space of high-risk industrial objects after the safety redundancy action command, hazardous energy is decomposed into process state parameters, isolation topology parameters, and hazardous medium attribute parameters. The amount of hazardous medium that has not been emptied or isolated in the equipment volume, pipe section volume, and buffer cavity is determined as the inventory residual quantity. Pressure, inter-valve pressure, downstream pressure, and pressure difference on both sides of the isolation boundary are converted into pressure energy storage. Temperature, specific heat of medium, latent heat of vaporization, phase change range, and thermal hazard characteristics corresponding to the operating condition stage are converted into enthalpy residual quantity. Flow rate, residual discharge rate, transmission path on / off status, and the positional relationship of safety action nodes are converted into residual flow quantity. No. Each state node at the sampling time The remaining inventory, pressure storage capacity, enthalpy residue, and residual flow rate are determined by the following formula:
[0037]
[0038]
[0039]
[0040] in, Indicates the remaining inventory level. Indicates that pressure stores energy. This indicates the residual enthalpy. Indicates residual flow; Indicates the first Density of hazardous media within each state node Indicates the first Each status node corresponds to the effective volume of a device, pipe section, or buffer cavity; Indicates the first state under the safe objective state The maximum allowable pressure for each state node; This indicates the specific heat capacity at constant pressure of a hazardous medium. Indicates the first state under the safe objective state The maximum allowable temperature for each state node; This indicates the latent heat of vaporization of a hazardous medium.
[0041] The residual inventory occupancy factor, pressure storage conversion factor, phase change or flash evaporation participation factor, and transmission path connectivity factor are determined by the following formula:
[0042]
[0043]
[0044]
[0045] in, Indicates the first Within each state node, the hazardous medium occupies an effective volume; Indicates the first The equivalent bulk elastic modulus of the hazardous medium within each state node; Indicates the hazardous medium under pressure The saturation temperature below; Indicates the first Temperature reference upper limit for each status node; Represents the state node The relevant set of transmission paths; express One of the transmission paths in; Indicates the transmission path Safety action nodes on; Indicates safety action node At sampling time The flow state; Taking the pipeline from the liquefied hydrocarbon storage tank to the downstream reaction unit as an example, after receiving the safety redundancy action command, if the upstream shut-off valve is closed, the downstream shut-off valve is not fully in place, the intervalve pressure is still higher than the set range for venting, and the pipe section temperature is close to the sensitive range for liquefied hydrocarbon flashing, then the medium in the intervalve pipe section is included in the inventory residual quantity, the pressure difference between the intervalve pressure and the downstream pressure is included in the pressure storage energy, the heat released by the flashing of the medium and the heat storage effect of the pipe wall are included in the enthalpy residual quantity, and the residual flow in the pressure relief branch is included in the residual flow quantity. No. Each state node at the sampling time The normalized values of residual inventory, pressure storage capacity, residual enthalpy, and residual flow are as follows:
[0046]
[0047]
[0048]
[0049] in, These represent the normalized values of residual inventory, pressure storage capacity, residual enthalpy, and residual flow, respectively. They represent the first state under the safe target state. The maximum allowable inventory residual quantity, pressure storage capacity, enthalpy residual quantity, and residual flow quantity for each state node; They represent the first The reference upper limit for each state node during the accident isolation phase or the shutdown and depressurization phase. For any residual quantity... , , ,in, This represents the upper limit of the target corresponding to the safe target state. Indicates the upper limit of the process. This indicates the reference value corresponding to the interlock trigger or alarm trigger. This indicates the upper limit of the reference range given in the process design documents or equipment design documents. This represents the 95th percentile of the corresponding residual in the historical safety action sample; when there is no historical safety action sample... Pick .
[0050] Coupled edge At sampling time Normalized transmission risk Determine using the following formula:
[0051]
[0052]
[0053]
[0054]
[0055] in, This represents the normalized value of the pressure difference. This represents the normalized edge flow. This represents the normalized value of the temperature difference. Indicates the connected state of the coupled edges; Representing the coupling edges respectively The upper limit of the pressure difference reference, the upper limit of the flow rate reference, and the upper limit of the temperature difference reference; Indicates the state node To the state node The set of transmission paths; These represent the weights of pressure difference, side flow rate, temperature difference, and connectivity, respectively. . By coupling edge The flow meter directly collects data; coupled edge No flow timer is set; it is determined by the status node. With state nodes The flow rate, pressure difference, valve opening, and pipe section resistance parameters are estimated using a process piping network calculation model. Based on the state nodes and coupling edges in the hazardous energy state space, the inventory residual quantity, pressure stored energy, enthalpy residual quantity and residual flow quantity are weighted and integrated. The weights are determined according to the position of the state node, the transmission direction of the coupling edge, the hazardous medium property parameters and the current operating stage. Any weight vector All are determined according to the calibrated contribution:
[0056]
[0057] in, Indicates the first Each weight item Indicates the number of weighted items. Indicates the first The calibrated contribution of each weighted item Indicates the first A sample set of calibration indicators for each weight item. Indicates the weighted quantile. Indicates the number of calibration samples. This represents the project risk score. State node weights. Coupled edge weights and residual component weights Risk is calibrated based on state node risk score, coupled edge risk score, and residual inventory, pressure storage, residual enthalpy, and residual flow contribution from historical samples; risk weights are transferred through coupled edges. Calibrated based on the contributions of pressure difference, side flow rate, temperature difference, and connectivity; response deviation weighting. The historical consequence level is calibrated based on the contribution of residual exponential trajectory deviation, response time deviation, and topological order deviation to the historical consequence level.
[0058] The risk scores for state nodes and coupling edges are determined by the following formula:
[0059]
[0060]
[0061]
[0062] in, State node Node risk score, Indicates coupling edge Edge risk score, Indicates a positive base score; These represent the scores for distance to personnel work areas, distance to ignition sources, distance to high-temperature equipment, and isolation boundaries, respectively. These represent the scores for pressure transmission capacity at the coupling edge, flow transmission capacity, and connectivity design state, respectively. All were obtained according to the aforementioned weighting rules. The distances from the status node to the personnel work area, ignition source, and high-temperature equipment were obtained by normalizing the distances based on proximity (higher for near-field, lower for far-field) and distance (lower for far-field). The value is zero or one depending on whether the status node is located within or near the isolation boundary. The limits were obtained based on the ratios of the design pressure transmission capacity, the design flow capacity, and the corresponding benchmark magnitude, respectively. Take zero or one according to the designed connectivity state. When When empty, the weight term of the coupled edge and the summation term of the coupled edge are counted as zero.
[0063] Hazardous medium property scores and operating condition stage scores are normalized using the following formula:
[0064]
[0065] The correction factors for hazardous medium properties, operating condition stages, threshold values, and coupling side effects are determined by the following formula:
[0066]
[0067]
[0068]
[0069]
[0070]
[0071] in, Indicates the first Hazardous media property level score, and These represent the lower and upper limits of the attribute's rating score, respectively. Indicates the first Risk level score for each working condition stage and These represent the lower and upper limits of the risk level score for each working condition stage, respectively. These represent the normalized scores for flammability, toxicity, corrosivity, and volatility or flash evaporation risk, respectively. These represent the weights of the corresponding hazardous medium attribute scores, and the sum of the four is one. Indicates the first Risk scoring for each working condition stage Indicates the number of scoring items in the operating condition stage. Indicates the first The weight of risk scores for each working condition stage, and ; This represents the correction factor for the hazardous medium properties. This represents the correction factor for the operating condition stage. and These represent the lower limits of the corresponding threshold correction coefficients. This represents the threshold correction factor for hazardous media properties. This represents the threshold correction coefficient for the operating condition stage. Indicates the influence coefficient of the coupling edge; Status nodes located within the isolation boundary and adjacent to personnel work areas, ignition source areas, or high-temperature equipment are given higher weights. Coupled edges that may have pressure feedback, medium backflow, or heat accumulation are given additional weights, and the fusion result is corrected in combination with the feedback parameters of the final actuator. Safety Action Node The feedback compliance status, flow status, number of safety action nodes that have reached the predetermined feedback status, feedback anomaly correction coefficient, and actuator feedback correction coefficient are determined by the following formula:
[0072]
[0073]
[0074]
[0075]
[0076] in, Indicates the first Each safety action node at the sampling time Feedback on compliance status; Indicates the first Each safety action node at the sampling time The flow state; Indicates the first The actual feedback volume of each safety action node; Indicates the first The predetermined safety feedback quantity for each safety action node; Indicates safety action node Feedback quantity when in a state of reliable isolation; Indicates safety action node Feedback quantity when in full flow state; Indicates the first The allowable deviation in feedback from each safety action node; Indicates the sampling time The number of safety action nodes that have reached the predetermined feedback state; This indicates the number of times the actuators reported abnormalities in historical interlock tests or historical safety action samples. This indicates the number of safety action commands in historical interlock tests or historical safety action samples. This represents the feedback anomaly correction coefficient; This represents the feedback correction coefficient for the actuator.
[0077] The hazardous energy residual index is denoted as The formula for its calculation is:
[0078] in, Indicates the sampling time Dangerous residual energy index; These represent the respective weights of residual inventory, pressure storage capacity, residual enthalpy, and residual flow. Coupled edge set When empty, Count as zero.
[0079] The response deviation generation module generates a command process response deviation index based on safety redundancy action commands, time-series sensing data, hazardous energy residual index, and the expected response trajectory set. It identifies and quantifies the difference between the safety redundancy action commands and the actual responses of high-risk industrial objects. Using the safety redundancy action commands as the response trigger benchmark, and combining the process state parameters, operating stage parameters, hazardous medium property parameters, and hazardous energy residual index change trajectories from the time-series sensing data, the actual change trajectory is compared with the residual index change benchmark, response time limit benchmark, and topology sequence benchmark in the expected response trajectory set. The command process response deviation index reflects whether the actual response of the high-risk industrial object after receiving the safety redundancy action command exhibits lag, deviation, reverse change, partial lack of isolation, abnormal topology sequence, or inconsistent execution feedback.
[0080] The moment when a high-risk industrial object receives a safety redundancy action command is used as the response trigger benchmark. This moment is recorded on the same timeline, and the change trajectory of the residual hazardous energy index is continuously extracted according to the time-series perception data. The change trajectory includes the initial amplitude of the residual hazardous energy index, the decrease per unit time, the plateau stagnation interval, the reverse rise interval, and the change segment corresponding to the feedback status of the safety action node. Taking the emergency shut-off scenario of a liquefied hydrocarbon pipeline as an example, after receiving the upstream isolation, pump stop and pressure relief linkage command, the pressure between valves, downstream pressure, residual flow, pipeline temperature, feedback status of shut-off valve and pressure relief valve are collected, and the residual dangerous energy index at each sampling time is connected into a change trajectory. If the residual flow drops rapidly after the pump stop feedback is completed, and the pressure between valves remains high after the pressure relief valve opens, a pressure energy storage stagnation section is formed in the change trajectory. No. The original risk association score, normalized risk association score, reference action duration, and response time weights for each safety action node are determined by the following formula:
[0081]
[0082]
[0083]
[0084]
[0085] in, Indicates the first A set of state nodes associated with each security action node. Indicates the first The set of coupling edges associated with each safety action node. Indicates the first The original risk correlation score for each security action node and These represent the lower and upper limits of the original risk-related score for each safety action node, respectively. Indicates the first Normalized risk correlation score for each safety action node; Indicates the first The historical action duration set of each security action node Indicates the first Number of historical action duration samples for each security action node Indicates the quantiles of action duration. This indicates the duration of the action obtained from the interlocking test. Indicates the first The reference action duration for each safety action node. Indicates the first The response time weight of each security action node. When When empty, Count as zero; when When empty, Count as zero; when hour, .
[0086] Residual index target upper limit Residual exponential base decay coefficient Residual index change benchmark Response time limit benchmark The topological order criterion is determined by the following formula:
[0087]
[0088]
[0089]
[0090]
[0091] in, This represents the upper limit of the residual exponential target corresponding to the safe target state; The index representing the residual hazardous energy at the moment the safety redundancy action command is received; Indicates the residual index baseline decay coefficient; Indicates the sampling time The benchmark for residual index changes; Indicates the first in the topological order Each safety action node; Indicates safety action node The response time benchmark; when hour, ; This indicates the topological sequence constraints between safety action nodes, taken from interlocking logic files, safety instrumented function design files, or safety action sequence tables. This represents the set of safe action node pairs with sequential constraints. Indicates the number of action node pairs.
[0092] Safety Action Node The actual feedback completion time is recorded as Safety Action Nodes At sampling time The calculation feedback time is:
[0093] Command process response deviation index is denoted as The formula for its calculation is:
[0094]
[0095]
[0096]
[0097] in, These represent the residual exponential trajectory deviation, response time deviation, and topological order deviation, respectively. These represent the weights of the three types of bias, calibrated according to the contribution of the corresponding bias to the consequence level in historical samples, and... .
[0098] During the shutdown isolation phase, if the liquefied hydrocarbons are highly volatile and have a risk of combustion and explosion, higher weights are assigned to the pressure storage retention section, the residual flow rebound section, and the pressure relief action hysteresis section. During the accident isolation phase, if the safety action nodes do not complete the feedback according to the topological sequence of pump shutdown, upstream isolation, inter-valve pressure relief, and downstream isolation, the proportion of the topological sequence deviation is increased. The command process response deviation index is obtained through weighted fusion. This command process response deviation index reflects the degree of deviation of the actual dangerous energy convergence process from the residual index change benchmark, response time limit benchmark, and topological sequence benchmark after the safety redundancy action command is issued.
[0099] The dynamic time window generation module generates a dynamic safety window based on the residual hazardous energy index, command process response deviation index, time-series sensing data, dynamic threshold groups, and safety target state. It also forms a dynamic safety window that matches the current hazardous state based on these parameters. It focuses on the safety confirmation period, transition observation period, escalation trigger time, and reset prohibition period for high-risk industrial objects after a safety redundancy action command. The dynamic safety window is not a fixed time period but adjusts according to changes in the residual hazardous energy index, command process response deviation index, process safety time, hazardous medium properties, and operating condition stage. When the residual hazardous energy is high, the response deviation is large, or the process safety time is shortened, the dynamic safety window tends to tighten to ensure that safety confirmation, escalation triggering, and reset restrictions match the level of on-site hazard.
[0100] The safe sample set and the unsafe sample set are denoted as follows: ,in, and Let these represent the set of residual hazardous energy indices and the set of command-process response deviation indices, respectively, in the historical samples that have reached the empirical isolation state. and Let represent the set of residual hazardous energy indices and the set of command-process response deviation indices in historical samples that did not reach the empirical isolation state, respectively. The basic safety threshold, the basic deviation threshold, and the upper and lower limits of the thresholds are determined by the following formula:
[0101]
[0102]
[0103]
[0104]
[0105]
[0106] in, Indicates the number of safe samples. Indicates the number of unsafe samples. This indicates the minimum number of samples required to enable historical sample quantile calculation; Let represent the base quantile, lower limit quantile, and upper limit quantile of the safe sample, respectively. 1; These represent the basic safety threshold, basic deviation threshold, lower limit of safety threshold, lower limit of deviation threshold, upper limit of safety threshold, and upper limit of deviation threshold, respectively, given by engineering verification. This indicates the calculation resolution of the hazardous energy residual index. This indicates the calculation resolution of the command procedure response deviation index. and These represent the minimum output resolution of the corresponding index in the control system, calculation module, or historical sample validation, respectively. If the sample distribution leads to... or Then according to and Correct to .
[0107] The dynamic threshold group includes dynamic security thresholds. and dynamic deviation threshold The remaining safe time for the process is recorded as:
[0108] The time correction factor is denoted as:
[0109] The dynamic safety threshold and the dynamic deviation threshold are respectively:
[0110]
[0111] in, Indicates the sampling time The remaining time for the process safety This represents the time correction factor. The hazardous energy residual index satisfying the dynamic safety threshold means... The command process response deviation index meets the dynamic deviation threshold, which means... .
[0112] Based on the residual hazardous energy index, command process response deviation index, time-series perception data, dynamic threshold group, and safety target state of high-risk industrial objects after a safety redundancy action command, a time constraint interval matching the current hazardous state is established; the dynamic safety threshold is compared with the residual hazardous energy index, the dynamic deviation threshold is compared with the command process response deviation index, and the process safety time, the target energy convergence interval in the safety target state, hazardous medium attribute parameters, and operating condition stage parameters are incorporated into the same judgment relationship, dividing the sub-window into safety confirmation, transition observation, upgrade trigger time, and reset prohibition. Taking the emergency shut-off scenario of a liquefied hydrocarbon pipeline as an example, after the upstream isolation, pump stop and pressure relief linkage command is issued, if the intervalve pressure, downstream pressure, residual flow and pipeline temperature all converge toward the safe target state, and the residual danger energy index is lower than the dynamic safety threshold and the command process response deviation index is lower than the dynamic deviation threshold, then the safety confirmation sub-window remains relatively complete, and the transition observation sub-window covers the observation period when the intervalve pressure is stable, the residual flow decays and the pressure relief path is stable; The dynamic security window is referred to as:
[0113] in, Indicates the length of the safety confirmation sub-window. Indicates the length of the transition observation sub-window. Indicates the time when the upgrade is triggered. This indicates the length of the reset-disabled subwindow. The base times for safety confirmation, transient observation, escalation triggering, and reset disabling are denoted as follows: Its value is taken from the quantile of historical time samples; if the historical time samples are insufficient, the verification time of the interlocking test is used. The corresponding lower limit and upper limit are denoted as . .in, exist At each time, according to the first Window-like historical time sample set The baseline quantile, lower limit quantile, and upper limit quantile are determined; when the sample size is insufficient... At that time, the base time, lower limit time and upper limit time obtained from the interlocking test verification are taken respectively.
[0114] The critical compressibility factor is denoted as:
[0115] The sub-windows of the dynamic security window are determined by the following formula:
[0116]
[0117]
[0118]
[0119] in, This represents the dynamic safety window compression factor. It is applied when the residual hazardous energy index increases, the command process response deviation index increases, or the remaining process safety time decreases. Increase.
[0120] The dynamic safety window is adjusted in real time based on the changes in the residual hazardous energy index and the command process response deviation index. When the residual hazardous energy index increases, the command process response deviation index increases, or the process safety time decreases, the safety confirmation sub-window is shortened, the transition observation sub-window is compressed, the upgrade trigger time is moved forward, and the reset prohibition sub-window is extended. For example, if the intervalve pressure does not decrease according to the safety target state after the shut-off valve feedback closure, the pressure relief valve opening feedback is insufficient, the residual flow rebounds, and the liquefied hydrocarbon is in an accident isolation stage with high volatility and high risk of combustion and explosion, then the upgrade trigger time is set in advance, the original transition observation sub-window is compressed, the reset prohibition sub-window is extended, manual reset and interlock bypass release are prohibited within this time range, and safety redundancy actions such as standby shut-off, upstream isolation, forced pressure relief, inerting or ventilation are included in the upgrade control scope.
[0121] The safety classification and control module is used to perform safety classification and control of high-risk industrial objects within a dynamic safety window, based on the residual hazardous energy index, command process response deviation index, and dynamic threshold group. Within the dynamic safety window, graded safety control is implemented for high-risk industrial objects according to these indices. This module determines whether a high-risk industrial object has reached a verified isolation state using dynamic safety thresholds and dynamic deviation thresholds. If it has not reached this state, a safety upgrade level is generated based on the degree of residual hazardous energy and command process response deviation, and corresponding safety redundancy actions are triggered accordingly. Safety redundancy actions include at least one of the following: backup cutoff, upstream isolation, pump shutdown, pressure relief, venting, inerting, ventilation, fire alarm linkage, and reset locking. It emphasizes the closed-loop relationship between the actual on-site state and safety control actions, avoiding confirmation that a high-risk industrial object is safe based solely on a single action command or a single execution feedback.
[0122] Within the dynamic safety window, the residual hazardous energy index, command process response deviation index, dynamic safety threshold, and dynamic deviation threshold are read, and a hierarchical judgment relationship is established by combining the safety confirmation sub-window, transition observation sub-window, upgrade trigger time, and reset prohibition sub-window. The set of process state parameters and the allowable range of safety target states are determined by the following formula:
[0123]
[0124] in, Represents the set of process state parameters. Indicates the permissible range of the safety target state; These represent the allowable boundaries of the corresponding process state parameters.
[0125] The exponential over-limit state and the duration of continuous over-limit are determined by the following formula:
[0126]
[0127] in, Indicates the sampling time The index is out of limit. Indicates the time up to the sampling point The duration of continuous overruns.
[0128] The empirical isolation state determination quantity is denoted as Determine using the following formula:
[0129] in, This indicates that high-risk industrial sites have reached a state of empirical isolation. This indicates that high-risk industrial entities have not reached a state of empirical isolation.
[0130] The security upgrade determination quantity is recorded as:
[0131] The sample sets with slight deviation, moderate deviation, and severe deviation are denoted as follows: The safety upgrade threshold is determined by the following formula:
[0132]
[0133]
[0134] in, Indicates the sampling time Security upgrade judgment quantity This indicates the dividing line between slight and moderate deviation. This indicates the dividing line between moderate and severe deviation. The smallest distinguishing factor representing the security upgrade determination. These represent the number of samples in the slightly deviated sample set, the moderately deviated sample set, and the severely deviated sample set, respectively.
[0135] The condition for continuous increase is determined by the following formula:
[0136]
[0137] when and If a slight deviation is detected, it triggers backup disconnection, reset locking, or extended transition observation; when and When the deviation is deemed moderate, it triggers upstream isolation, pump shutdown, pressure relief, or venting; when and If the residual hazardous energy index and the command process response deviation index meet the above conditions of continuous increase, it is judged as a severe deviation, triggering inerting, ventilation, and fire protection linkage and maintaining reset lock.
[0138] For example, if the shut-off valve is closed but the inter-valve pressure continues to rise, the pressure relief valve is not open enough and the residual flow rebounds, the safety upgrade level is increased, and the standby shut-off and forced pressure relief are linked. If the liquefied hydrocarbon release area is close to an ignition source or high-temperature equipment, the inerting, ventilation and fire protection linkage are activated simultaneously until the hazardous energy residual index and the command process response deviation index meet the dynamic threshold requirements again.
[0139] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A high-risk scenario industrial automation safety redundancy control system, characterized in that, include: The timing awareness acquisition module is used to acquire timing awareness data of high-risk industrial objects after they receive a safety redundancy action command. The timing awareness data includes process status parameters, isolation topology parameters, hazardous medium property parameters, operating condition stage parameters, feedback parameters of the final actuator, and process safety time. The state space configuration module is used to generate a hazardous energy state space, a safety target state, a set of expected response trajectories, and a set of dynamic thresholds based on time-series sensing data. The set of expected response trajectories includes a residual exponential change benchmark, a response time limit benchmark, and a topological order benchmark. The set of dynamic thresholds includes dynamic safety thresholds and dynamic deviation thresholds. The residual index generation module is used to generate the hazardous energy residual index based on time-series sensing data and the hazardous energy state space; The response deviation generation module is used to generate a command process response deviation index based on safety redundancy action commands, time-series perception data, hazardous energy residual index, and expected response trajectory set. The dynamic time window generation module is used to generate a dynamic safety window based on the residual hazardous energy index, command process response deviation index, time-series perception data, dynamic threshold group, and safety target state. The safety classification and control module is used to perform safety classification and control of high-risk industrial objects within a dynamic safety window, based on the hazardous energy residual index, command process response deviation index, and dynamic threshold group.
2. The high-risk scenario industrial automation safety redundancy control system according to claim 1, characterized in that, Process status parameters include at least one of pressure, temperature, flow rate, liquid level, intervalve pressure, and downstream pressure; isolation topology parameters include at least one of isolation boundary, equipment volume, pipe segment volume, buffer cavity, energy storage unit, transmission path, and safety action node.
3. The high-risk scenario industrial automation safety redundancy control system according to claim 2, characterized in that, The state space configuration module is used to map process state parameters, isolation topology parameters, hazardous medium property parameters, and operating condition stage parameters into hazardous energy dimensions, and establish state nodes and coupling edges according to isolation boundaries and transmission paths to form a hazardous energy state space.
4. A high-risk scenario industrial automation safety redundancy control system according to claim 3, characterized in that, The state space configuration module is also used to determine the target energy convergence interval based on the safety redundancy action command and the dangerous energy state space, so as to generate the safety target state, and generate the expected response trajectory set and dynamic threshold group based on the safety target state, process safety time, isolation topology parameters and operating condition stage parameters.
5. A high-risk scenario industrial automation safety redundancy control system according to claim 4, characterized in that, Using the safety target state as the convergence endpoint and the process safety time as the constraint, the topological sequence of safety action nodes is determined based on the isolation topological parameters. The residual exponent change benchmark, response time limit benchmark, and topological sequence benchmark are generated by combining the operating condition stage parameters.
6. A high-risk scenario industrial automation safety redundancy control system according to claim 1, characterized in that, The generation of the hazardous energy residual index involves mapping process state parameters, isolation topology parameters, and hazardous medium property parameters to inventory residual quantity, pressure stored energy, enthalpy residual quantity, and residual flow quantity. The index is then weighted and fused according to the state nodes and coupling edges in the hazardous energy state space, and the fusion result is corrected by combining the feedback parameters of the final actuator, thereby generating the hazardous energy residual index.
7. A high-risk scenario industrial automation safety redundancy control system according to claim 6, characterized in that, The generation of the command process response deviation index includes: using the safety redundancy action command as the response trigger benchmark, obtaining the change trajectory of the hazardous energy residual index based on the time-series perception data, comparing the change trajectory with the residual index change benchmark, the response time limit benchmark, and the topology sequence benchmark respectively, and combining the working condition stage parameters and hazardous medium property parameters for weighted fusion to generate the command process response deviation index.
8. A high-risk scenario industrial automation safety redundancy control system according to claim 7, characterized in that, The dynamic security window includes a security confirmation sub-window, a transition observation sub-window, an upgrade trigger time, and a reset prohibition sub-window.
9. A high-risk scenario industrial automation safety redundancy control system according to any one of claims 1-8, characterized in that, When the residual hazardous energy index increases, the command process response deviation index increases, or the process safety time decreases, the safety confirmation sub-window is shortened, the transition observation sub-window is compressed, the upgrade trigger time is moved forward, and the reset prohibition sub-window is extended.
10. A high-risk scenario industrial automation safety redundancy control system according to claim 9, characterized in that, When the residual hazardous energy index meets the dynamic safety threshold and the command process response deviation index meets the dynamic deviation threshold, the high-risk industrial object is determined to have reached the empirical isolation state; when the high-risk industrial object has not reached the empirical isolation state, a safety upgrade level is generated, and safety redundancy actions are dynamically triggered according to the safety upgrade level; among them, safety redundancy actions include at least one of the following: backup cut-off, upstream isolation, pump stop, pressure relief, venting, inerting, ventilation, fire linkage, and reset locking.