Method and system for safety integrity assessment of underwater blowout preventer electric control system

CN122615263APending Publication Date: 2026-08-21CHINA NAT OFFSHORE OIL CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610754261.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-28
Publication Date
2026-08-21

AI Technical Summary

Technical Problem

传统评估方法还存在着考虑影响因素不够全面、缺乏灵活性和空间状态爆炸等问题,进一步增加了安全完整性评估的难度

Benefits of technology

[0014] According to the technical solution provided in this application, by evaluating the parameters of the equipment, when the specific failure parameters are unknown, they are represented as distributed data, thus completing a reasonable estimate of the distribution of unknown data. This achieves the preprocessing of failure parameter data and solves the problem of excessive uncertainty caused by insufficient data. Based on the network topology of the underwater blowout preventer's electronic control system, Bayesian network models for each stage are established, thereby constructing a multi-stage dynamic Bayesian network model. This model can simulate the state of the underwater blowout preventer's electronic control system during its operating cycle. Compared with the calculation method using traditional models, this application utilizes the flexibility and accuracy of the multi-stage dynamic Bayesian network model. This approach addresses the shortcomings of traditional models, such as insufficient consideration of influencing factors, lack of flexibility, and spatial state explosion. It fully utilizes the uncertainty and randomness handling capabilities of Monte Carlo simulation. Based on Monte Carlo simulation calculations, the evaluated parameter distribution data is introduced into a multi-stage dynamic Bayesian network model. Through multiple Monte Carlo simulations, the health status indicators of the underwater blowout preventer's electronic control system are calculated, and its safety integrity level is evaluated. This effectively improves the accuracy of safety integrity assessment under unknown parameter conditions, achieves precise assessment of the safety integrity of the offshore oil and gas underwater blowout preventer's electronic control system, and optimizes the safety integrity assessment method.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122615263A_ABST
    Figure CN122615263A_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a kind of safety integrity assessment methods and systems of underwater blowout preventer electric control system, wherein the method comprises: obtaining the parameter distribution data obtained by evaluation;According to the network topology of underwater blowout preventer electric control system, the bayesian network model of each stage is established, and the multi-stage dynamic bayesian network model is constructed according to the bayesian network model of each stage;According to parameter distribution data, multiple monte carlo simulation sampling is carried out, and the sampling parameter data is input into the multi-stage dynamic bayesian network model for parameter modeling and calculation, to obtain the health status index of underwater blowout preventer electric control system corresponding to multiple monte carlo simulation simulation calculation;According to the health status index of underwater blowout preventer electric control system corresponding to multiple monte carlo simulation simulation calculation, the safety integrity level of underwater blowout preventer electric control system is evaluated.The application effectively improves the accuracy of safety integrity assessment under unknown parameter condition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of petroleum engineering technology, specifically to a method and system for assessing the safety integrity of an electronic control system for a marine oil subsea blowout preventer. Background Technology

[0002] The subsea blowout preventer (BOP) electronic control system is an electronic control network used in oil and gas drilling to remotely control the operation of the subsea BOP assembly from the surface. In emergencies such as well kicks or blowouts, the platform operator can instantly issue relevant commands through the subsea BOP electronic control system to prevent disaster. Safety Integrity (SIL) assessment of the subsea BOP electronic control system is a core step in ensuring drilling operation safety and preventing runaway blowouts. Traditional assessment methods suffer from insufficient consideration of influencing factors, lack of flexibility, and the potential for spatial explosion, further increasing the difficulty of SIL assessment. Furthermore, subsea BOP electronic control systems are large-scale, with complex and diverse system components, making it difficult to obtain complete failure parameters. The SIL assessment process often introduces many uncertainties, and these uncertainties can lead to deviations in the SIL assessment results, affecting their accuracy and increasing the risk to the controlled equipment. Summary of the Invention

[0003] In view of the above problems, the present invention is proposed to provide a method and system for safety integrity assessment of an underwater blowout preventer electronic control system that overcomes or at least partially solves the above problems.

[0004] According to one aspect of the embodiments of this application, a method for safety integrity assessment of an underwater blowout preventer electronic control system is provided, comprising: Obtain the evaluated parameter distribution data; Based on the network topology of the underwater blowout preventer electronic control system, Bayesian network models for each stage are established, and a multi-stage dynamic Bayesian network model is constructed based on the Bayesian network models for each stage. Based on the parameter distribution data, multiple Monte Carlo simulations are performed. The sampled parameter data is then input into a multi-stage dynamic Bayesian network model for parameter modeling and calculation, resulting in the health status indicators of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulation calculations. Based on the health status indicators of the underwater blowout preventer's electronic control system calculated through multiple Monte Carlo simulations, the safety integrity level of the underwater blowout preventer's electronic control system is assessed.

[0005] Furthermore, obtaining the evaluated parameter distribution data further includes: For equipment that does not provide a range of failure parameters, the parameter range of the equipment is evaluated multiple times, and a triangular fuzzy number is constructed for each evaluation value as each evaluation result; The arithmetic mean of multiple evaluation results is obtained by integrating them using an ordered weighted average algorithm. Calculate the distance measure between each evaluation result and the arithmetic mean, and calculate the similarity between each evaluation result and the arithmetic mean based on the distance measure; The weight coefficient of each evaluation result is calculated based on the similarity. The multiple evaluation results are then weighted according to the weight coefficient to obtain the parameter distribution data.

[0006] Furthermore, based on the network topology of the underwater blowout preventer's electronic control system, the Bayesian network models for each stage are established, including: The composition and redundancy configuration of each subsystem and unit within each subsystem of the underwater blowout preventer electronic control system are analyzed to obtain the network topology of the underwater blowout preventer electronic control system. Determine the system runtime and the multiple periodic functional verification test intervals and functional verification test phases included in the system runtime; Based on the network topology, establish Bayesian network models for the functional verification test interval and the functional verification test phase.

[0007] Furthermore, the network topology includes: a failure factor node layer, a redundant channel status node layer, a redundant unit status node layer, and a system status node layer. The nodes in the failure factor node layer include: independent failure impact nodes that cause channel failure and common failure impact nodes that cause common cause failure of the unit; The nodes in the redundant channel state node layer are used to represent the state of each channel in the redundant structure under the influence of failure factors in the underwater blowout preventer's electronic control system. The nodes in the redundant unit state node layer are used to represent the state of each redundant unit under the combination and cooperation of each channel in the redundant channel state node layer. The nodes in the system state node layer are used to represent the state and probability of each subsystem under the influence of each redundant unit in the redundant unit state node layer.

[0008] Furthermore, based on the Bayesian network models at each stage, a multi-stage dynamic Bayesian network model is constructed, which further includes: Establish the Bayesian network model for the functional verification test interval and the conditional probabilities within each time slice of the Bayesian network model for the functional verification test. By alternately connecting the Bayesian network model in the functional verification test interval stage and the Bayesian network model in the functional verification test stage, and determining the transition conditional probabilities between each time slice, a multi-stage dynamic Bayesian network model is constructed.

[0009] Furthermore, health status indicators include: probability of failure upon request; Based on multiple Monte Carlo simulations, the health status indicators of the underwater blowout preventer's electronic control system are used to assess its safety integrity level. Further assessments include: Based on multiple Monte Carlo simulations, the required failure probability of the underwater blowout preventer electronic control system was calculated, and the average failure probability was also calculated. Assess the safety integrity level of the underwater blowout preventer's electronic control system based on the required average failure probability.

[0010] According to another aspect of the embodiments of this application, a safety integrity assessment system for an underwater blowout preventer electronic control system is provided, comprising: The parameter distribution evaluation module is suitable for acquiring the evaluated parameter distribution data. The Bayesian network model building module is suitable for building Bayesian network models at various stages based on the network topology of the underwater blowout preventer electronic control system, and constructing a multi-stage dynamic Bayesian network model based on the Bayesian network models at each stage. The Monte Carlo simulation module is suitable for performing multiple Monte Carlo simulations based on parameter distribution data. The sampled parameter data is input into a multi-stage dynamic Bayesian network model for parameter modeling and calculation, resulting in the health status indicators of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulations. Based on the health status indicators of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulations, the safety integrity level of the underwater blowout preventer electronic control system is evaluated.

[0011] According to another aspect of the embodiments of this application, a computing device is provided, including: a processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other through the communication bus; The memory is used to store at least one executable instruction, which causes the processor to perform the operation corresponding to the safety integrity assessment method of the above-mentioned underwater blowout preventer electronic control system.

[0012] According to another aspect of the embodiments of this application, a computer storage medium is provided, the storage medium storing at least one executable instruction, the executable instruction causing a processor to perform operations corresponding to the safety integrity assessment method of the underwater blowout preventer electronic control system described above.

[0013] According to another aspect of the embodiments of this application, a computer program product is provided, including at least one executable instruction, which causes a processor to perform operations corresponding to the safety integrity assessment method of the underwater blowout preventer electronic control system described above.

[0014] According to the technical solution provided in this application, by evaluating the parameters of the equipment, when the specific failure parameters are unknown, they are represented as distributed data, thus completing a reasonable estimate of the distribution of unknown data. This achieves the preprocessing of failure parameter data and solves the problem of excessive uncertainty caused by insufficient data. Based on the network topology of the underwater blowout preventer's electronic control system, Bayesian network models for each stage are established, thereby constructing a multi-stage dynamic Bayesian network model. This model can simulate the state of the underwater blowout preventer's electronic control system during its operating cycle. Compared with the calculation method using traditional models, this application utilizes the flexibility and accuracy of the multi-stage dynamic Bayesian network model. This approach addresses the shortcomings of traditional models, such as insufficient consideration of influencing factors, lack of flexibility, and spatial state explosion. It fully utilizes the uncertainty and randomness handling capabilities of Monte Carlo simulation. Based on Monte Carlo simulation calculations, the evaluated parameter distribution data is introduced into a multi-stage dynamic Bayesian network model. Through multiple Monte Carlo simulations, the health status indicators of the underwater blowout preventer's electronic control system are calculated, and its safety integrity level is evaluated. This effectively improves the accuracy of safety integrity assessment under unknown parameter conditions, achieves precise assessment of the safety integrity of the offshore oil and gas underwater blowout preventer's electronic control system, and optimizes the safety integrity assessment method.

[0015] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more obvious and understandable, specific implementation methods of the embodiments of this application are described below. Attached Figure Description

[0016] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the embodiments of this application. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 A flowchart illustrating a method for assessing the safety integrity of an underwater blowout preventer electronic control system according to an embodiment of this application is shown. Figure 2 A schematic diagram illustrating the principle of a safety integrity assessment method for an underwater blowout preventer electronic control system according to an embodiment of this application is shown. Figure 3A flowchart is shown to establish the inter-chip transition conditional probability of independent failure-affected nodes during the functional verification and testing interval of the underwater blowout preventer's electronic control system. Figure 4 A flowchart is shown to establish the inter-chip transition conditional probability of nodes affected by common cause failures during the functional verification and testing interval of the underwater blowout preventer's electronic control system. Figure 5 The state transition diagram of the failure factor nodes during the functional verification and testing phase of the underwater blowout preventer's electronic control system is shown. Figure 6 A structural block diagram of a safety integrity assessment system for an underwater blowout preventer electronic control system according to an embodiment of this application is shown; Figure 7 A schematic diagram of the structure of a computing device according to an embodiment of this application is shown. Detailed Implementation

[0017] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0018] Figure 1 A flowchart illustrating a safety integrity assessment method for an underwater blowout preventer electronic control system according to an embodiment of this application is shown, as follows: Figure 1 As shown, the method includes the following steps: Step S101: Obtain the parameter distribution data obtained after evaluation.

[0019] By evaluating the parameters of the equipment and representing them as distributed data when specific failure parameters are unknown, a reasonable estimate of the distribution of unknown data is achieved. Here, "equipment" refers to the components within the underwater blowout preventer's electronic control system. Specifically, the parameter distribution data refers to the evaluation results of the distribution of failure parameters for each module within the equipment.

[0020] For equipment that does not provide a failure parameter range, the parameter range can be evaluated multiple times, constructing a triangular fuzzy number for each evaluation value as each evaluation result. In one optional implementation, the parameter range can be evaluated based on expert assessments, using multiple experts to provide the evaluation parameter range, which serves as each expert's evaluation value. In another optional implementation, the parameter range can also be evaluated based on different data models trained using historical failure parameter ranges of underwater blowout preventer electronic control systems.

[0021] In this application, the evaluation parameter range is based on the theory of triangular fuzzy numbers, the basic form of which is:

[0022] in, ; This represents the lower limit of the fuzzy interval for a fuzzy number. This represents the upper limit of the fuzzy interval of the fuzzy number; This represents the median of the fuzzy number. When or ,and The greater the numerical difference, the stronger the ambiguity of the data being described. When At that point, the data becomes an accurate value. Membership function The fuzziness of parameter x is described as follows:

[0023] After constructing the triangular fuzzy numbers for multiple evaluation values, multiple evaluation results are obtained. An ordered weighted average algorithm is then used to integrate these results, yielding the arithmetic mean of the multiple evaluation results. For example, if n experts evaluate the parameters of a device, n evaluation values ​​are obtained; where the triangular fuzzy number of the k-th evaluation value is... , This represents the lower limit of the fuzzy interval in the k-th evaluation result. This represents the median of the fuzzy numbers in the k-th evaluation result. This represents the upper limit of the fuzzy interval in the k-th evaluation result; the DOUWA (Ordered Weighted Average Based on Uncertainty) operator is used to integrate the evaluation results of n experts. The DOUWA operator is characterized by weights that depend on the distribution of the data itself; data closer to the group mean has a larger weight, making it suitable for multi-attribute group decision-making under uncertain environments. Specifically, the integration process is as follows: calculate the arithmetic mean of multiple evaluation results. ,in:

[0024] After calculating the arithmetic mean, the distance measure and similarity between each evaluation result and the arithmetic mean can be calculated, and then the weight coefficient of each evaluation result can be determined for merging multiple evaluation results.

[0025] Specifically, the distance measure between each evaluation result and the arithmetic mean is calculated using the following formula:

[0026] in, This represents the sum of the k-th evaluation result and the arithmetic mean. Distance measure between.

[0027] Next, the similarity between each evaluation result and the arithmetic mean is calculated based on the distance measure. The formula for calculating the similarity is:

[0028] in, This represents the sum of the k-th evaluation result and the arithmetic mean. The similarity between them.

[0029] Then, a weight coefficient is calculated for each evaluation result based on similarity. Multiple evaluation results are then weighted according to these weight coefficients to obtain parameter distribution data, which is the final evaluation result. The parameter distribution data is calculated as follows:

[0030] in, This represents the parameter distribution data obtained after evaluation; This represents the lower limit of a fuzzy interval for parameter distribution data; The median of the fuzzy numbers representing the parameter distribution data; This represents the upper limit of a fuzzy interval for parameter distribution data; This represents the weight coefficient of the k-th evaluation result.

[0031] Figure 2 A schematic diagram illustrating the principle of a safety integrity assessment method for an underwater blowout preventer electronic control system according to an embodiment of this application is shown, such as... Figure 2 As shown, this method can be mainly divided into three parts: obtaining parameter distribution data based on evaluation, establishing a multi-stage dynamic Bayesian network model, and performing Monte Carlo simulation calculations. Specifically, in the process of obtaining parameter distribution data based on evaluation, the parameter range of the device is evaluated, and a triangular fuzzy number is constructed for each evaluation value as each evaluation result. Then, the arithmetic mean of multiple evaluation results is calculated, along with the distance measure and similarity between each evaluation result and the arithmetic mean. Finally, the weight coefficient of each evaluation result is calculated, and multiple evaluation results are weighted according to the weight coefficients to obtain the final parameter distribution data.

[0032] Step S102: Based on the network topology of the underwater blowout preventer electronic control system, establish Bayesian network models for each stage, and construct a multi-stage dynamic Bayesian network model based on the Bayesian network models for each stage.

[0033] This paper analyzes the composition and redundancy configuration of each subsystem and unit within the underwater blowout preventer (BOP) electronic control system to obtain the network topology of the system. Specifically, it analyzes the composition of each subsystem and the redundancy configuration between them, establishing the topological relationship between each subsystem node (S node) and the entire system; it analyzes the composition of each unit within each subsystem, establishing the topological relationship between each unit node (U node) and the subsystem node; it analyzes the redundancy configuration within each unit, establishing the topological relationship between each channel node (CH node) and the unit; it analyzes the failure factors affecting each channel, constructing independent failure factor nodes (IF nodes) and common failure factor nodes (CF nodes), connecting them to the channel nodes according to redundancy relationships; and finally, it obtains the network topology of the underwater BOP electronic control system based on redundancy configuration and logical relationships.

[0034] The network topology of the underwater blowout preventer (BOP) electronic control system includes: the topological relationship between each subsystem node and the entire system; the topological relationship between each unit node within a subsystem and the subsystem node; the topological relationship between each channel node and the unit; and the topological relationship between each independent failure factor node and common failure factor node and its corresponding channel. The network topology of the underwater BOP electronic control system can be divided into four layers from top to bottom: the failure factor node layer, the redundant channel status node layer, the redundant unit status node layer, and the system status node layer.

[0035] The failure factor node layer is the first layer. The nodes in this layer represent the factors influencing the failure of the submersible blowout preventer's electronic control system. The nodes in this layer include: independent failure impact nodes (IF nodes) that cause channel failure and common cause failure impact nodes (CF nodes) that cause common cause failure of the unit. Each node in the failure factor node layer contains five states: normal state (NS), system-detected safe failure state (SD), system-undetected safe failure state (SU), system-detected dangerous failure state (DD), and system-undetected dangerous failure state (DU).

[0036] The redundant channel state node layer is the second layer. The nodes in this layer (referred to as CN nodes, i.e., channel state nodes) represent the state of each channel in the redundant structure under the influence of failure factors in the underwater blowout preventer's electronic control system. Each node in the redundant channel state node layer contains five states: Normal (NS), Detected Safe Failure (SD), Undetected Safe Failure (SU), Detected Dangerous Failure (DD), and Undetected Dangerous Failure (DU).

[0037] The redundant unit state node layer is the third layer. The nodes in the redundant unit state node layer (referred to as U nodes, i.e., unit state nodes) are used to represent the state of each redundant unit under the combination and cooperation of various channels in the redundant channel state node layer. The nodes in the redundant unit state node layer contain four states: normal state (NS), safe failure state (SS), dangerous failure state detected by the system (DD), and dangerous failure state not detected by the system (DU).

[0038] The system state node layer is the fourth layer. The nodes in the system state node layer (referred to as S-nodes, i.e., system state nodes) represent the state and probability of each subsystem under the influence of each redundant unit in the redundant unit state node layer. The nodes in the system state node layer contain four states: normal state (NS), safe failure state (SS), system-detected dangerous failure state (DD), and system-undetected dangerous failure state (DU).

[0039] In step S102, it is also necessary to determine the system runtime (TS) and the multiple periodic functional verification and testing intervals (TI) and functional verification and testing phases (TST) included within the system runtime. The system runtime can be set according to the actual application scenario. Multiple periodically arranged functional verification and testing intervals and functional verification and testing phases are cyclically nested throughout the entire operation of the underwater blowout preventer's electronic control system. These two phases are sequentially connected and alternately carried out according to a preset safety control sequence. The functional verification and testing interval phase belongs to the safety integrity level design and quantitative assessment phase. Based on the system's service environment conditions and latent fault detection capabilities, the maximum time interval for safety functional verification and testing is determined. The functional verification and testing phase belongs to the in-service operation safety verification and implementation phase of the underwater blowout preventer's electronic control system. According to the cycle determined by the functional verification and testing interval phase, complete or partial functional verification and testing are periodically performed on the underwater blowout preventer's electronic control system to identify and repair latent dangerous failures.

[0040] Based on the network topology, Bayesian network models are established for the functional verification and testing interval phase and the functional verification and testing phase, thus representing different phases through two different Bayesian network models. In the functional verification and testing interval phase, the system's time-varying behavior can be represented by a dynamic Bayesian network model containing multiple time slices, used to describe self-diagnosis, failures, and maintenance issues in each self-diagnosis cycle within the functional verification and testing interval phase. In the functional verification and testing phase, the system's time-varying behavior can be represented by a dynamic Bayesian network model based on the actual situation, used to describe the verification and testing, failures, and maintenance during the functional verification and testing phase.

[0041] After establishing the Bayesian network model for the functional testing interval and the Bayesian network model for the functional testing phase, the conditional probabilities within each time slice in the Bayesian network model for the functional testing interval and the Bayesian network model for the functional testing phase are established.

[0042] The process of establishing the conditional probabilities within each time slice specifically includes: (1) The state of the nodes (CN nodes) in the redundant channel state node layer is jointly determined by the independent failure-affected nodes (IF nodes) and the common-cause failure-affected nodes (CF nodes). For a 1oo1 structure (i.e., a one-to-one structure or a single-channel structure), the state of the CN node depends only on the independent failure-affected nodes (IF nodes) of the single channel. The process and establishment rules for conditional probability modeling of CN nodes are as follows: When the IF node and CF node are in the same state, the CN node is also in the same state as them. When the states of the IF node and the CF node are different, if the state of the IF node is the normal state NS, then the state of the CN node is the same as the state of the CF node. When the states of the IF node and the CF node are different, if the state of the CF node is the normal state NS, then the state of the CN node is the same as the state of the IF node. When the states of the IF node and the CF node are different, if neither the IF node nor the CF node is in the normal state NS, and the common cause weight parameter is defined as w (w=1 by default), then the probability that the CN node is in the CF node state is w, and the probability that it is in the IF node state is 1-w.

[0043] (2) The state of the nodes (U nodes) in the redundant unit state node layer is determined by the CN nodes of all individual channels. The process and rules for establishing the conditional probability modeling of U nodes are as follows: When the number of channels that fail security in a redundant unit (referred to as nS) is greater than the security fault margin (referred to as SFT), the unit fails security, that is, node U is in the security failure state SS. When the number of channels with undetected dangerous failures (nDU) in a redundant unit is greater than the hardware failure margin (HFT), the unit is considered to have experienced a dangerous failure. If the unit contains at least one detected safe failure or a detected dangerous failure, then a detected dangerous failure occurs, i.e., node U is in the system-detected dangerous failure state DD. Otherwise, the unit is considered to have experienced an undetected dangerous failure, i.e., node U is in the system-undetected dangerous failure state DU.

[0044] (3) The state of the nodes (S nodes) in the system state node layer is determined by all the constituent U nodes, and the conditional probability of the S nodes depends on the actual connection relationship of each redundant unit.

[0045] After establishing the conditional probabilities for each time slice, the Bayesian network models for the functional test interval phase and the functional test phase are alternately linked, and the transition conditional probabilities between each time slice are determined. This constructs a multi-stage dynamic Bayesian network model (MDBN model) for safety integrity assessment. The MDBN model can simulate the state of the underwater blowout preventer's electronic control system during its operating cycle. Specifically, it simulates the system state during the multiple periodic functional test interval phases (TI) and functional test phases (TST) included in the system's runtime (TS). By determining the transition conditional probabilities between each time slice, an inter-time slice transition conditional probability table can be formed. The inter-time slice transition conditional probability table is a statistical table representing the conditional probability of the system transitioning from the state of the previous time slice to the operating state of the next time slice, using equally divided time segments (i.e., time slices) as units.

[0046] Figure 3 The flowchart illustrates the establishment of inter-chip transition condition probabilities for independent failure-affected nodes during the functional verification and testing interval of the underwater blowout preventer's electronic control system. Figure 3 As shown, the degradation, self-diagnosis, and repair process of an independently affected node (IF node) during the functional verification test interval is simulated, based on... Figure 3 The process of establishing inter-component transfer conditional probability tables can be used for modeling and analysis of issues such as specific component degradation and maintenance patterns. The establishment process is as follows: (1) When node IF is in the NS state, IF will degenerate into the SD, SU, DD or DU state according to the exponential law.

[0047] (2) When node IF is in SD or DD state, if it causes the controlled system SS to fail, then IF will be in μ SR Transform into NS state according to the exponential distribution law; otherwise, IF uses μ. TR It transitions to the NS state according to the exponential distribution pattern.

[0048] (3) When node IF is in SU state, if its parent node causes system SS failure, then IF will be in μ state. SR The IF transitions to the NS state according to an exponential distribution; if its parent node contains at least one detected failure, then the IF transitions to the NS state with an exponential distribution of μ. TR If the exponential distribution pattern is followed, the state transitions to NS; otherwise, the IF state remains unchanged at SU.

[0049] (4) When node IF is in DU state, if its parent node causes system SS failure, then IF will be in μ state. SR The IF transitions to the NS state according to an exponential distribution; if its parent node contains at least one detected failure, then the IF transitions to the NS state with an exponential distribution of μ. TR The IF state transitions to the NS state according to the exponential distribution pattern; otherwise, the IF state remains unchanged at DU.

[0050] Figure 3 In this context, a, b, and k are used for counting and have no practical meaning; n is the number of node state combinations of the parent node of the IF node; nSD is the count of detectable safety failure states; nSU is the count of undetected safety failure states; nDD is the count of detectable dangerous failure states; nDU is the count of undetected dangerous failure states; IFbk is the state of the parent node of the IF node; μ is the maintenance rate; μ TR For failure repair rate; μ SR For restart recovery rate; IFak t The current node state; P(IFak) t+1 =NS) represents the probability that the current node will transform into the corresponding state (NS state) at the next time step; Δt is the time step; λ N Non-common cause failure rate; λ SDN For detectable non-common-cause safety failure rate; λ SUN For undetected non-common-cause safety failure rate; λ DDN For detectable non-common cause hazard failure rate; λ DUN For undetected non-common cause hazard failure rate.

[0051] Figure 4 The flowchart illustrates the establishment of inter-chip transition conditional probabilities for nodes affected by common-cause failures during the functional verification and testing interval of the underwater blowout preventer's electronic control system. Figure 4 As shown, this process represents the degradation, self-diagnosis, and repair process of the common-cause failure affected node (CF node) during the functional verification test interval, based on... Figure 4 The process of establishing inter-chip transition conditional probability tables can also be used for modeling and analyzing complex degradation processes and the impact of common-cause failures. The establishment process is as follows: (1) When CF is in the NS state, it degenerates into the SD, SU, DD or DU state according to the exponential distribution law.

[0052] (2) When CF is in SD or SU state, it will cause the system SS to fail, and CF will be in μ SR The system transitions to the NS state according to an exponential distribution.

[0053] (3) When CF is in DD state, it will cause the system DD to fail, and CF will be in μ TR The system transitions to the NS state according to an exponential distribution.

[0054] (4) When CF is in DU state, it will cause the system DU to fail. However, the self-diagnostic function cannot detect the system DU failure. Therefore, CF will maintain the DU state before the test.

[0055] Figure 4 In this context, k is used for counting and has no practical meaning; μ TR For failure repair rate; μ SR For restart recovery rate; MOON is for N-to-M voting redundancy; CFx t The current node state; P(CFx) t+1 =NS) represents the probability that the current node will transform into the corresponding state (NS state) at the next time step; Δt is the time step; λ C For common-cause failure rate; λ SDC For detectable common-cause safety failure rate; λ SUC For undetected common-cause safety failure rate; λ DDC For detectable common-cause hazard failure rate; λ DUC The failure rate is the rate of failure due to undetected common causes.

[0056] Figure 5 The diagram shows the state transition of failure factor nodes during the functional verification and testing phase of the underwater blowout preventer's electronic control system, as follows: Figure 5 As shown, this process applies to all failure factor nodes (TF nodes) during the functional verification and testing phase, including independent failure factor nodes (IF nodes) and common cause failure factor nodes (CF nodes). Each failure factor node contains five states: NS, SD, SU, DD, and DU. The state transition process of the failure factor node is as follows: (1) When node TF is in the NS state, TF will degenerate into the SD, SU, DD or DU state with the corresponding probability.

[0057] (2) When node TF is in SD or DD state, TF will be transformed into NS state with the corresponding maintenance probability.

[0058] (3) When node TF is in SU state, TF will be transformed into NS state with the corresponding maintenance probability, or will remain in the original SU state or be transformed into SD state with the corresponding probability due to the influence of the inspection and testing coverage rate.

[0059] (4) When node TF is in DU state, TF will be transformed into NS state with the corresponding maintenance probability, or will remain in the original DU state or be transformed into DD state with the corresponding probability due to the influence of the inspection and testing coverage rate.

[0060] Figure 5 In the middle, TFx t The current node state; P(TFx) t+1 =NS) represents the probability that the current node will transition to the corresponding state (NS state) at the next time step; γ represents the total failure probability; γ SD γ represents the probability of a detectable safety failure. SU The probability of an undetected safety failure; γ DD γ represents the detectable probability of dangerous failure. DU The probability of an undetected hazardous failure; μ SD The probability of repairing a detected safety failure; μ SU The probability of repairing an undetected safety failure; μ DD The probability of repairing a detected hazardous failure; μ DU ε represents the probability of repairing undetected hazardous failures; ε represents the inspection and testing coverage.

[0061] like Figure 2 As shown, in the process of establishing a multi-stage dynamic Bayesian network model, the network topology of the underwater blowout preventer electronic control system is analyzed, Bayesian network models for each stage are established, the conditional probabilities within each time slice and the transition conditional probabilities between each time slice are determined, and finally, a multi-stage dynamic Bayesian network model is constructed.

[0062] Step S103: Perform multiple Monte Carlo simulations based on the parameter distribution data, input the sampled parameter data into a multi-stage dynamic Bayesian network model for parameter modeling and calculation, and obtain the health status indicators of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulation calculations.

[0063] Monte Carlo simulation sampling is performed based on the parameter distribution data obtained from the evaluation. Each sampling yields a set of failure parameter data, i.e., a set of sampling parameter data. This set of sampling parameter data is then introduced into the transition conditional probability table between time slices of a multi-stage dynamic Bayesian network model. In other words, the sampling parameter data from each sampling is input into the multi-stage dynamic Bayesian network model for parameter modeling, resulting in the MDBN evaluation model of the electronic control system corresponding to each sampling parameter data. The MDBN evaluation model is run and inferred, and calculations are performed to obtain the health status index of the underwater blowout preventer electronic control system corresponding to one Monte Carlo simulation calculation. A preset number of sampling times is determined, and the above sampling simulation calculation process is repeated to obtain the health status index of the underwater blowout preventer electronic control system corresponding to multiple Monte Carlo simulation calculations.

[0064] Step S104: Based on the health status indicators of the underwater blowout preventer electronic control system calculated through multiple Monte Carlo simulations, assess the safety integrity level of the underwater blowout preventer electronic control system.

[0065] Specifically, health status indicators may include the probability of failure at demand (PFD). The probability of failure at demand refers to the probability that the electronic control system will fail to operate normally at the moment when a safety risk is triggered and a safety function is required to be performed. Based on the probability of failure at demand for the corresponding underwater blowout preventer electronic control system calculated through multiple Monte Carlo simulations, the average probability of failure at demand (PFDavg) is calculated using the following formula:

[0066] Where T represents the total running time of the system; Indicates the number of time slices within a single functional test interval; Indicates the number of functional test intervals; TI represents the functional test interval. This represents the failure probability of the required time slice corresponding to the i-th time slice within the j-th functional test interval; This represents the failure probability of the required time slice corresponding to the (i+1)th time slice within the j-th functional test interval.

[0067] like Figure 2 As shown, in the Monte Carlo simulation calculation process, a set of sampling parameter data is obtained through Monte Carlo simulation sampling. The sampling parameter data is input into the MDBN model for parameter modeling, and the MDBN evaluation model of the electronic control system corresponding to each sampling parameter data is obtained. The failure probability of the underwater blowout preventer electronic control system under the required time is calculated under the set of sampling parameter data. It is then determined whether the sampling of the preset number of samplings has been completed. If so, the average failure probability under the required time is calculated. If not, the Monte Carlo simulation sampling continues.

[0068] After calculating the required mean time failure probability (MTBF), the safety integrity level of the underwater blowout preventer's electronic control system is assessed based on the MTBF. In practical applications, the corresponding safety integrity level can be defined by the numerical range of the MTBF. Therefore, the safety integrity level is determined based on the calculated MTBF's numerical range, thus completing the assessment of the safety integrity level of the underwater blowout preventer's electronic control system. Taking safety integrity levels from level one to level four as an example, the correspondence between the MTBF and the safety integrity level is shown in Table 1: Table 1. Correspondence between required mean failure probability and safety integrity level

[0069] The safety integrity assessment method for an underwater blowout preventer (BOP) electronic control system provided in this application evaluates the equipment parameters and represents them as distributed data when specific failure parameters are unknown. This achieves a reasonable estimate of the distribution of unknown data, realizes the preprocessing of failure parameter data, and solves the problem of excessive uncertainty caused by insufficient data. Based on the network topology of the underwater BOP electronic control system, Bayesian network models for each stage are established, thereby constructing a multi-stage dynamic Bayesian network model. This model can simulate the state of the underwater BOP electronic control system during its operating cycle. Compared with the calculation method using traditional models, this application utilizes a multi-stage dynamic Bayesian network model. The system improves flexibility and accuracy, addressing the shortcomings of traditional models such as insufficient consideration of influencing factors, lack of flexibility, and spatial state explosion. It fully utilizes the ability of Monte Carlo simulation to handle uncertainty and randomness, and incorporates the evaluated parameter distribution data into a multi-stage dynamic Bayesian network model based on Monte Carlo simulation calculations. Through multiple Monte Carlo simulations, the health status indicators of the underwater blowout preventer's electronic control system are calculated, and its safety integrity level is evaluated. This effectively improves the accuracy of safety integrity assessment under unknown parameter conditions, achieves precise assessment of the safety integrity of the offshore oil and gas underwater blowout preventer's electronic control system, and optimizes the safety integrity assessment method.

[0070] Figure 6 A structural block diagram of a safety integrity assessment system for an underwater blowout preventer electronic control system according to an embodiment of this application is shown, as follows: Figure 6 As shown, the device includes: a parameter distribution evaluation module 610, a Bayesian network model building module 620, and a Monte Carlo simulation calculation module 630.

[0071] The parameter distribution evaluation module 610 is suitable for: acquiring the evaluated parameter distribution data.

[0072] The Bayesian network model building module 620 is suitable for: establishing Bayesian network models for each stage based on the network topology of the underwater blowout preventer electronic control system, and constructing a multi-stage dynamic Bayesian network model based on the Bayesian network models for each stage.

[0073] The Monte Carlo simulation calculation module 630 is suitable for: performing multiple Monte Carlo simulations based on parameter distribution data, inputting the sampled parameter data into a multi-stage dynamic Bayesian network model for parameter modeling and calculation, obtaining the health status indicators of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulation calculations; and evaluating the safety integrity level of the underwater blowout preventer electronic control system based on the health status indicators of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulation calculations.

[0074] Optionally, the parameter distribution evaluation module 610 is further adapted to: for devices that do not provide a range of failure parameters, evaluate the parameter range of the device multiple times, construct a triangular fuzzy number for each evaluation value as each evaluation result; integrate multiple evaluation results through an ordered weighted average algorithm to obtain the arithmetic mean of multiple evaluation results; calculate the distance measure between each evaluation result and the arithmetic mean, and calculate the similarity between each evaluation result and the arithmetic mean based on the distance measure; calculate the weight coefficient of each evaluation result based on the similarity, and perform a weighted operation on multiple evaluation results based on the weight coefficient to obtain parameter distribution data.

[0075] Optionally, the Bayesian network model building module 620 is further adapted to: analyze the composition and redundancy configuration of each subsystem and each unit within the underwater blowout preventer electronic control system to obtain the network topology of the underwater blowout preventer electronic control system; determine the system runtime and the multiple periodic functional verification test intervals and functional verification test phases contained within the system runtime; and establish Bayesian network models for the functional verification test intervals and functional verification test phases based on the network topology.

[0076] Optionally, the network topology includes: a failure factor node layer, a redundant channel state node layer, a redundant unit state node layer, and a system state node layer; the nodes in the failure factor node layer include: independent failure-affecting nodes that cause channel failure and common-cause failure-affecting nodes that cause common-cause failure of units; the nodes in the redundant channel state node layer are used to represent the state of each channel in the redundant structure under the influence of failure factors in the underwater blowout preventer's electronic control system; the nodes in the redundant unit state node layer are used to represent the state of each redundant unit under the combination and cooperation of each channel in the redundant channel state node layer; the nodes in the system state node layer are used to represent the state and probability of each subsystem under the influence of each redundant unit in the redundant unit state node layer.

[0077] Optionally, the Bayesian network model building module 620 is further adapted to: establish the conditional probabilities in each time slice of the Bayesian network model in the functional testing interval stage and the Bayesian network model in the functional testing stage; alternately connect the Bayesian network model in the functional testing interval stage and the Bayesian network model in the functional testing stage, and determine the transition conditional probabilities between each time slice to construct a multi-stage dynamic Bayesian network model.

[0078] Optionally, the health status indicators include: the probability of failure at the required time; the Monte Carlo simulation calculation module 630 is further adapted to: calculate the average probability of failure at the required time based on the probability of failure at the required time of the corresponding underwater blowout preventer electronic control system based on multiple Monte Carlo simulation calculations; and assess the safety integrity level of the underwater blowout preventer electronic control system based on the average probability of failure at the required time.

[0079] The descriptions of the above modules refer to the corresponding descriptions in the method embodiments, and will not be repeated here.

[0080] The safety integrity assessment system for an underwater blowout preventer (BOP) electronic control system provided in this application evaluates the equipment parameters and represents them as distributed data when specific failure parameters are unknown. This allows for a reasonable estimation of the distribution of unknown data, achieving preprocessing of failure parameter data and solving the problem of excessive uncertainty caused by insufficient data. Based on the network topology of the underwater BOP electronic control system, Bayesian network models for each stage are established, thereby constructing a multi-stage dynamic Bayesian network model. This model can simulate the state of the underwater BOP electronic control system during its operating cycle. Compared with the calculation method using traditional models, this application utilizes a multi-stage dynamic Bayesian network model. The system improves flexibility and accuracy, addressing the shortcomings of traditional models such as insufficient consideration of influencing factors, lack of flexibility, and spatial state explosion. It fully utilizes the ability of Monte Carlo simulation to handle uncertainty and randomness, and incorporates the evaluated parameter distribution data into a multi-stage dynamic Bayesian network model based on Monte Carlo simulation calculations. Through multiple Monte Carlo simulations, the health status indicators of the underwater blowout preventer's electronic control system are calculated, and its safety integrity level is evaluated. This effectively improves the accuracy of safety integrity assessment under unknown parameter conditions, achieves precise assessment of the safety integrity of the offshore oil and gas underwater blowout preventer's electronic control system, and optimizes the safety integrity assessment method.

[0081] This application provides a non-volatile computer storage medium storing at least one executable instruction or computer program that enables a processor to perform the operation corresponding to the safety integrity assessment method of the underwater blowout preventer electronic control system in any of the above method embodiments.

[0082] This application provides a computer program product, which includes at least one executable instruction or computer program that enables a processor to perform the operation corresponding to the safety integrity assessment method of the underwater blowout preventer electronic control system in any of the above method embodiments.

[0083] Figure 7 The diagram shows a structural schematic of a computing device according to one embodiment of the present application. The specific embodiments of the present application do not limit the specific implementation of the computing device.

[0084] like Figure 7 As shown, the computing device may include: a processor 702, a communications interface 704, a memory 706, and a communications bus 708.

[0085] The processor 702, communication interface 704, and memory 706 communicate with each other via communication bus 708. Communication interface 704 is used to communicate with other network elements, such as clients or other servers. Processor 702 executes program 710, specifically performing the relevant steps in the embodiment of the safety integrity assessment method for the underwater blowout preventer electronic control system of the computing device described above.

[0086] Specifically, program 710 may include program code that includes computer operation instructions.

[0087] The processor 702 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application. The computing device includes one or more processors, which may be processors of the same type, such as one or more CPUs; or processors of different types, such as one or more CPUs and one or more ASICs.

[0088] Memory 706 is used to store program 710. Memory 706 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.

[0089] Specifically, program 710 can be used to cause processor 702 to execute the safety integrity assessment method for the underwater blowout preventer electronic control system in any of the above method embodiments. The specific implementation of each step in program 710 can be found in the corresponding descriptions of the steps and units in the above embodiments of the safety integrity assessment of the underwater blowout preventer electronic control system, and will not be repeated here. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the devices and modules described above can be referred to the corresponding process descriptions in the foregoing method embodiments, and will not be repeated here.

[0090] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The required structure for constructing such systems is apparent from the above description. Furthermore, the embodiments of this application are not directed to any particular programming language. It should be understood that the contents of the embodiments of this application described herein can be implemented using various programming languages, and the above description of specific languages ​​is for the purpose of disclosing the best implementation of the embodiments of this application.

[0091] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this application may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.

[0092] Similarly, it should be understood that, in order to simplify this disclosure and aid in understanding one or more of the various inventive aspects, in the foregoing description of exemplary embodiments of the present application, various features of the present application embodiments are sometimes grouped together into a single embodiment, figure, or description thereof. However, this approach to disclosure should not be construed as reflecting an intention that the claimed embodiments of the present application require more features than expressly recited in each claim. Rather, as reflected in the following claims, inventive aspects lie in fewer than all features of a single foregoing disclosed embodiment. Therefore, the claims following the detailed description are hereby expressly incorporated into that detailed description, wherein each claim itself is a separate embodiment of the present application.

[0093] Those skilled in the art will understand that modules in the device of the embodiments can be adaptively changed and placed in one or more devices different from that embodiment. Modules, units, or components in the embodiments can be combined into a single module, unit, or component, and further, they can be divided into multiple sub-modules, sub-units, or sub-components. Except where at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all processes or units of any method or device so disclosed. Unless expressly stated otherwise, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) may be replaced by an alternative feature that serves the same, equivalent, or similar purpose.

[0094] Furthermore, those skilled in the art will understand that although some embodiments described herein include certain features but not others included in other embodiments, combinations of features from different embodiments are meant to be within the scope of the embodiments of this application and form different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.

[0095] The various component embodiments of this application can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components according to the embodiments of this application. The embodiments of this application can also be implemented as device or apparatus programs (e.g., computer programs and computer program products) for performing part or all of the methods described herein. Such programs implementing the embodiments of this application can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.

[0096] It should be noted that the above embodiments are illustrative of the embodiments of this application and not limiting of the embodiments of this application, and those skilled in the art can devise alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. Embodiments of this application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names.

Claims

1. A method for safety integrity assessment of an underwater blowout preventer electronic control system, characterized in that, include: Obtain the evaluated parameter distribution data; Based on the network topology of the underwater blowout preventer electronic control system, Bayesian network models for each stage are established, and a multi-stage dynamic Bayesian network model is constructed based on the Bayesian network models for each stage. Based on the parameter distribution data, multiple Monte Carlo simulations are performed, and the sampled parameter data is input into a multi-stage dynamic Bayesian network model for parameter modeling and calculation, so as to obtain the health status index of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulation calculations. Based on the health status indicators of the underwater blowout preventer's electronic control system calculated through multiple Monte Carlo simulations, the safety integrity level of the underwater blowout preventer's electronic control system is assessed.

2. The method according to claim 1, characterized in that, The acquisition of the evaluated parameter distribution data further includes: For devices that do not provide a range of failure parameters, the parameter range of the device is evaluated multiple times, and a triangular fuzzy number is constructed for each evaluation value as each evaluation result. The arithmetic mean of multiple evaluation results is obtained by integrating them using an ordered weighted average algorithm. Calculate the distance measure between each evaluation result and the arithmetic mean, and calculate the similarity between each evaluation result and the arithmetic mean based on the distance measure; The weight coefficient of each evaluation result is calculated based on the similarity, and the multiple evaluation results are weighted according to the weight coefficient to obtain parameter distribution data.

3. The method according to claim 1, characterized in that, The establishment of Bayesian network models for each stage based on the network topology of the underwater blowout preventer's electronic control system further includes: The network topology of the underwater blowout preventer electronic control system is obtained by analyzing the composition and redundancy configuration of each subsystem and each unit within each subsystem. Determine the system runtime and the multiple periodic functional verification test intervals and functional verification test phases included in the system runtime; Based on the network topology, establish a Bayesian network model for the functional verification test interval and a Bayesian network model for the functional verification test phase.

4. The method according to claim 3, characterized in that, The network topology includes: a failure factor node layer, a redundant channel status node layer, a redundant unit status node layer, and a system status node layer. The nodes in the failure factor node layer include: independent failure impact nodes that cause channel failure and common failure impact nodes that cause unit common cause failure; The nodes in the redundant channel state node layer are used to represent the state of each channel of the redundant structure under the influence of failure factors in the underwater blowout preventer's electronic control system. The nodes in the redundant unit state node layer are used to represent the state of each redundant unit under the combination and cooperation of each channel in the redundant channel state node layer. The nodes in the system state node layer are used to represent the state and probability of each subsystem under the influence of each redundant unit in the redundant unit state node layer.

5. The method according to claim 3, characterized in that, The construction of a multi-stage dynamic Bayesian network model based on the Bayesian network models at each stage further includes: Establish the Bayesian network model for the functional verification test interval and the conditional probabilities within each time slice of the Bayesian network model for the functional verification test. By alternately connecting the Bayesian network model in the functional verification test interval stage and the Bayesian network model in the functional verification test stage, and determining the transition conditional probabilities between each time slice, a multi-stage dynamic Bayesian network model is constructed.

6. The method according to any one of claims 1-5, characterized in that, The health status indicators include: probability of failure upon request; The assessment of the safety integrity level of the underwater blowout preventer's electronic control system, based on health status indicators calculated through multiple Monte Carlo simulations, further includes: Based on multiple Monte Carlo simulations, the required failure probability of the underwater blowout preventer electronic control system was calculated, and the required average failure probability was also calculated. The safety integrity level of the underwater blowout preventer's electronic control system is assessed based on the average failure probability required.

7. A safety integrity assessment system for an underwater blowout preventer electronic control system, characterized in that, include: The parameter distribution evaluation module is suitable for acquiring the evaluated parameter distribution data. The Bayesian network model building module is suitable for building Bayesian network models at various stages based on the network topology of the underwater blowout preventer electronic control system, and constructing a multi-stage dynamic Bayesian network model based on the Bayesian network models at each stage. The Monte Carlo simulation module is suitable for performing multiple Monte Carlo simulations based on the parameter distribution data, inputting the sampled parameter data into a multi-stage dynamic Bayesian network model for parameter modeling and calculation, and obtaining the health status index of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulations; based on the health status index of the underwater blowout preventer electronic control system corresponding to the multiple Monte Carlo simulations, the safety integrity level of the underwater blowout preventer electronic control system is evaluated.

8. A computing device, comprising: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable instruction that causes the processor to perform the operation corresponding to the safety integrity assessment method of the underwater blowout preventer electronic control system as described in any one of claims 1-6.

9. A computer storage medium storing at least one executable instruction that causes a processor to perform an operation corresponding to the safety integrity assessment method for an underwater blowout preventer electronic control system as described in any one of claims 1-6.

10. A computer program product comprising at least one executable instruction that causes a processor to perform an operation corresponding to the safety integrity assessment method for an underwater blowout preventer electronic control system as described in any one of claims 1-6.