Method for carrying out automatic process risk analyses and computer-readable storage medium
The automated method for process risk analysis in the oil and gas industry addresses the time-consuming nature of manual HazOp studies by dividing plants into nodes and traversing P&ID graphs, resulting in reduced project timelines and enhanced analysis accuracy.
Patent Information
- Application Number
- PCT/BR2024/050565
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-05
- Filing Date
- 2024-12-04
- Publication Date
- 2025-06-12
AI Technical Summary
The manual process of performing HazOp studies in the oil and gas industry is time-consuming and labor-intensive, often leading to project delays due to the need for extensive reanalyses and corrections.
An automated method for performing process risk analysis that divides an industrial plant into nodes based on shutdown valves and traverses P&ID graphs to identify deviations, causative objects, affected objects, detection, and safeguard modes, generating a spreadsheet with recommendations for process security vulnerabilities.
The automated method significantly reduces the time required for HazOp studies, allowing for more efficient project timelines, and provides detailed, standardized results with a safeguard score, enhancing the accuracy and completeness of process risk analysis.
Smart Images

Figure BR2024050565_12062025_PF_FP_ABST
Abstract
Description
[0001] Field of the invention
[0001] The present invention falls within the technical field of process safety in industry, more specifically in the oil and gas industry. In particular, the present invention relates to a method for performing automatic process risk analysis and computer-readable storage media. Background of the invention
[0002] The design phases of industrial units include process risk analysis events. Among these, we can mention the risk and operability study, known as HazOp (Hazard and Operability Study).
[0003] HazOp is widely used in the oil and gas industry as a qualitative risk analysis. It is an inductive and structured technique for identifying process hazards and potential operational problems by systematically associating a set of guide words with process variables. For each identified deviation, its causes, consequences, detection methods, and existing safeguards are listed, recommending additional measures when necessary. HazOp can be applied in different phases of an industrial facility's life cycle, primarily: basic design, detailed design, commissioning / pre-operation, and operation.
[0004] HazOp studies involve multidisciplinary teamwork and significant project hours. The results obtained from HazOp studies can impact project delivery times when the recommendations resulting from the study require excessive rework.
[0005] Traditionally, HazOp is performed manually by a multidisciplinary team, completing and analyzing spreadsheets and analyzing project documents. In practice, much of the HazOp study is developed manually by the group, except for the use of commercial software that organizes the report and assists in recording scenarios. This software does not anticipate scenarios, hazards, safeguards, or other factors.
[0006] Specifically, when preparing a HazOp study, printed engineering and instrumentation drawings of the entire industrial plant are used, such as the Process Flow Diagram (PFD), Piping and Instrumentation Diagram (P&ID), and cause-and-effect matrix. The plant must be divided into small sections to avoid compromising the quality of the team's analysis. Furthermore, some information may not be present in the printed drawings, requiring consultation with other engineering documents, resulting in longer analysis times.
[0007] In this sense, there is a risk that the HazOp study preparation process will impact the project delivery deadline, as the number of reanalyses and corrections required to be carried out in the project will only be known at the end of the HazOp study, through its results, which can take a few months.
[0008] However, HazOp is important for ensuring an intrinsically safe project. Therefore, reducing HazOp duration is a major concern in the oil and gas industry, as it would shorten the project schedule and allow the team to work on other analyses that cannot be automated. Prior art
[0009] In the state of the art, there are some solutions that facilitate filling out spreadsheets, but all documentation continues to be printed and the search for information is carried out by a professional or multidisciplinary team.
[0010] Document US8639646B1 discloses a system for building, managing, and analyzing a computer-generated risk assessment model and performing a layer of protection analysis. The system uses a computer-generated safety instrumented system model to manage a process safety lifecycle for a safety instrumented system in a facility. However, the proposed system does not use as input a database with industrial plant information, nor graphs or algorithms to traverse a Piping and Instrumentation Diagram (P&ID).
[0011] The document Johannes I. Single, Jürgen Schmidt, Jens Denecke, Ontology-based computer aid for the automation of HazOp studies, Journal of Loss Prevention in the Process Industries, Volume 68, 2020, 104321, ISSN 0950-4230, https: / / doi.org / 10.1016 / j.jlp.2020.104321 describes HazOp studies focusing on the representation of semantic relationships between relevant HazOp concepts, taking into account the degree of abstraction, through an ontological model to identify hazardous scenarios and operability problems. This proposed system is not based on rules that define the system's behavior, which simplifies the adaptation and maintenance of the computerized model method. Brief description of the invention
[0012] According to a preferred embodiment of the present invention, a method is defined for performing automatic process risk analysis, comprising the steps of: • dividing an industrial plant into nodes including dividing the industrial plant into portions smaller than the objects of the Piping and Instrumentation Diagram, P&ID; in which each node includes a set of deviations, in which a deviation is defined by a pair of process variable and a modifier; • defining at least one causative object for each deviation and recording a causative-deviation pair; in which the event that occurs in a causative object or for a causative object is the cause; • defining at least one affected object for each causative-deviation pair, which comprises defining at least one equipment that suffers the consequence of the deviation, due to the cause in the causative object; • defining at least one set of detection and safeguard mode, which comprises defining at least one set of detection and safeguard mode for each consequence;• define at least one additional safeguard recommendation, including defining at least one additional safeguard recommendation if a pre-established number of safeguards is not defined in the previous step. ;
[0013] Furthermore, according to a preferred embodiment of the present invention, the step of dividing an industrial plant into nodes comprises dividing the industrial plant into nodes based on a shutdown valve (SDV).
[0014] According to a preferred embodiment of the present invention, the step of dividing an industrial plant into nodes comprises: (i) identifying the objects of the well P&IDs and making them belong to a node for each well type; (ii) identifying all the objects of the systems P&IDs missing SDV and making them belong to a node for each system; (iii) searching for SDVs; (iv) for each SDV, searching for objects downstream, following the correct flow direction; (v) stopping the search if any of these objects are found: a offline instruments b open drain lines c closed drain lines d flare lines e utility connectors f another SDV (vi) defining that all objects reached by each SDV belong to a new node; (vii) for each instrument, checking if each object connected to it belongs to a node. If not, searching for objects without a node from this connected object and assigning them to the same node as the initial instrument;(viii) for each connector, check if the object connected to the connector pair belongs to a node. If not, look for nodeless objects from this object and assign them to the node before the connector; (ix) for each node N without equipment, list all neighboring nodes En with equipment that belong to the same predominant system and make node N part of the largest neighboring node En; (x) repeat the previous step until the number of nodes remains unchanged. ;
[0015] Additionally, according to another preferred embodiment of the present invention, the set of deviations, the process variable pair and the modifier are related as follows:
[0016] According to another complementary preferred embodiment of the present invention, the pre-established number of safeguards are two safeguards, from a mechanical safeguard or an interlocking safeguard or any combination thereof; or the pre-established number of safeguards is one safeguard.
[0017] According to another additional preferred embodiment of the present invention, the method comprises traversing the graph defined by the characteristics and connections of the Piping and Instrumentation Diagram (P&ID) objects and generating a table including: - Tag_Pipe: includes the identification tag for the piping line; - Rep_ID: includes the identification number for the piping line; - Pipe_Type: includes the type of piping line: primary, secondary, any type of signal line, or a "relation line" if it is a dummy line representing a relationship between two directly connected instruments; - Diam_Self: includes the diameter of the piping line; - Drawing: includes the drawing where the connection between the piping line and the object is represented; - Tag_Other: includes the identification tag for the object; - Rep_Other_ID: includes the identification number for the object;- Position: includes the position reference of the object in relation to the line, which can be: "from" if it is upstream of the line; "to" if it is downstream of the line. If the object is another line, the position can also be "inside" or "outside," indicating the direction of the object's flow in relation to the line; - Type: includes the type of object, which can be any equipment, instrument, or in-line component; - Info: includes additional information about the object, which can be the symbol name, the valve opening action, the nozzle location, the equipment type and family, the description of the instrument type, and whether the connection is the maximum inlet or maximum outlet nozzle.
[0018] According to a further preferred embodiment of the present invention, the step of defining at least one affected object for each causative-deviation pair comprises: (i) starting from the causative, checking the search direction according to the consequence table, wherein the search direction is one of: downstream, upstream, or any; (ii) searching for connected objects; (iii) stopping if the object is: a) offline instrument b) open drain line c) closed drain line d) flare line e) utility connector f) closed stuck valve g) closed paddle h) assigned to a node that is not neighboring the causative node (iv) specific cases: a) if the cause mentions "hot side", the affected object must be on the cold side; b) if the cause mentions "cold side", the affected object must be on the hot side; c) if the cause mentions "pipe rupture", the affected object must be on the lower pressure side;d) if the trigger is a heat exchanger or an electric heater, the affected object may be the trigger itself; e) if the cause mentions "closing", "closing", or "blocking", the trigger itself acts as the stopping criterion; f) if the trigger is a vessel or a tank: - if the cause mentions "high level", the affected object must be reached from the top of the trigger; - if the cause mentions "low level", the affected object must be reached from the bottom of the trigger; g) if the trigger is a vessel: - if the cause mentions "low temperature (top)", the affected object must be reached from the top of the trigger; - if the cause mentions "low temperature (bottom)", the affected object must be reached from the bottom of the trigger; h) if the trigger is an electrostatic precipitator: - if the cause mentions "low temperature (bottom)", the affected object must be reached from the bottom of the trigger; (v) Restrict the affected objects to equipment. ;
[0019] Additionally, according to a preferred embodiment of the present invention, the step of defining at least one set of detection and safeguard mode comprises: (i) Consulting the safeguard table and obeying the search limit and direction; a) trigger-affected object: starts at the trigger and the affected object is a stopping criterion; b) affected object: starts at the affected object; c) affected object to pressure: starts at the affected object and adds some stopping criteria for pressure safeguards; d) affected object to PSV / PSE: starts at the affected object and adds some stopping criteria for PSV and PSE; e) affected object to level: starts at the affected object and adds some stopping criteria for level safeguards and restricts the safeguard to the affected object node; (ii) searching for connected objects;(iii) stop if the object is any of: a) offline instrument b) open drain line c) closed drain line d) flare line e) utility connector f) stuck-closed valve g) closed paddle h) AND and OR i) assigned to a node that is not neighboring the inflictor node (iv) specific cases: a) if a control valve fails, all instruments in its loop are stop criteria and cannot be safeguards; b) stop criteria for affected object for pressure: SDV, XV, HV, FV, LV, PV, TV and normally closed valve; if there is safeguard and detection, the stop criteria are: normally open valves and valve without opening action information; c) still for pressure safeguards: normally open valves between the inflictor and the affected object are discarded from the stop criteria; or d) other distinct process variables are stop criteria for a given variable. ;
[0020] Still, according to another preferred embodiment of the present invention, there is defined a computer-readable storage medium comprising, stored therein, a set of computer-readable instructions, which when executed by a computer, executes the method for performing automatic process risk analysis of the present invention. Brief description of the figures
[0021] In order to complement the present description and obtain a better understanding of the characteristics of the present invention, and in accordance with a preferred embodiment thereof, a set of figures is presented in the annex, where in an exemplified, although not limitative, manner its preferred embodiment is represented.
[0022] Figure 1 shows an example of a Piping and Instrumentation Diagram (P&ID).
[0023] Figure 2 illustrates the P&ID graph from Figure 1.
[0024] Figure 3 shows another practical example of a segment of a P&ID with the application of part of the method of the present invention.
[0025] Figure 4 presents an additional practical example of a segment of a P&ID with the application of part of the method of the present invention.
[0026] Figure 5 represents a complementary practical example of a segment of a P&ID with the application of part of the method of the present invention.
[0027] Figure 6 illustrates an example of information resulting from the method of the present invention.
[0028] Figure 7 presents an additional example of information resulting from the method of the present invention. Detailed description of the invention
[0029] The method for performing automatic process risk analysis, according to a preferred embodiment of the present invention, is described in detail below, based on the attached figures.
[0030] In particular, the objective of the proposed method is to automatically divide the plant P&IDs into nodes, perform a cause-consequence-safeguard analysis, and generate a spreadsheet where, for each node, there will be a complete description of the node's content and a list of recommendations addressing process security vulnerabilities.
[0031] Specifically, the method for performing automatic process risk analysis comprises the steps described in detail below. Step 1 - Divide an industrial plant into nodes
[0032] Specifically, the method for performing automatic process risk analysis comprises the step of dividing an industrial plant into nodes, which includes dividing the plant into portions smaller than the connected Piping and Instrumentation Diagram, P&ID, objects.
[0033] More specifically, each node includes a set of deviations, where a deviation is defined by a pair of process variable and a modifier, as defined in Table 1 below. Table 1: Definition of process variable, modifier, and deviation
[0034] According to Table 1 above, the set of deviations, the pair of process variable and modifier are related as follows: - if the process variable is flow and the modifier is no flow, then there is no deviation; - if the process variable is flow and the modifier is also flow, then the deviation is also flow; - if the process variable is flow and the modifier is less flow, then the deviation is less flow; - if the process variable is flow and the modifier is greater flow, then the deviation is greater flow; - if the process variable is flow and the modifier is reverse flow, then the deviation is reverse flow; - if the process variable is level and the modifier is less level, then the deviation is less level; - if the process variable is level and the modifier is greater level, then the deviation is greater level; - if the process variable is temperature and the modifier is greater temperature, then the deviation is lower temperature;- if the process variable is temperature and the modifier is reverse temperature, then the deviation is lower temperature; - if the process variable is pressure and the modifier is higher pressure, then the deviation is lower pressure; - if the process variable is pressure and the modifier is reverse pressure, then the deviation is higher pressure. Step 2 – Define at least one causative object for each deviation;
[0035] The step of defining at least one causative object involves defining, for each deviation, at least one causative object that can cause that deviation; and recording a causative-deviation pair. The causative object can henceforth be referred to simply as the causative object.
[0036] Furthermore, the event that occurs in or to a causative object that triggers the deviation is called the cause. Step 3 – Define at least one affected object for each causative-deviation pair.
[0037] The step of defining at least one affected object for each causer-deviation pair comprises defining at least one piece of equipment that suffers the effects of the deviation, due to the cause in the causer, given a certain influence limit (possibly limited to adjacent nodes).
[0038] Specifically, the effects of a deviation can henceforth be called consequences. Step 4 – Define at least one set of detection and safeguard modes
[0039] The step of defining at least one set of detection and safeguard modes comprises defining at least one set of detection and safeguard modes for each consequence (effect of the deviation). Step 5 – Define at least one safeguard recommendation
[0040] The step of defining at least one additional safeguard recommendation comprises defining at least one additional safeguard recommendation if a pre-established number of safeguards is not defined in the previous step.
[0041] Specifically, depending on the characteristics of the scenario, for example, the nature of the deviation, the frequency and severity of the consequence, and the reasonable safeguards available for the process disruption under analysis, the pre-established number of safeguards required may vary. Generally, the pre-established number of safeguards is two (2) safeguards of different types, mechanical and / or interlocking. In some cases, the pre-established number of safeguards is one (1) safeguard.
[0042] More specifically, the proposed method is based on an algorithm capable of traversing the graph defined by the characteristics and connections of the P&IDs objects.
[0043] A graph is formed by a set of vertices and a set of edges, where each edge connects a pair of vertices.
[0044] According to the method of the present invention, the graph is implemented as a table, where each row represents a relationship between a row and another object.
[0045] A simple example of P&ID representation is provided in Figure 1.
[0046] According to Figure 2, all objects in the example P&ID in Figure 1 can be seen as vertices of a graph, such as the vertices named EQP-001, VALV-001, EQP-002, EQP-003, and INSTR-001. Furthermore, all piping lines and instrument signals can be seen as edges of this graph, such as the lines named PIPE-001, PIPE-002, PIPE-003, and COM-001.
[0047] However, a more appropriate structure for using the information provided by the graph is a table. All the information represented in Figure 2 can be represented in tabular form, as illustrated in Table 2 below. Table 2: Tabular form of the graph presented in Figure 2 Table 2: Tabular form of the graph shown in Figure 2
[0048] The format illustrated in Table 2 is a simplified form of the one actually used in the method of the present invention, which is more practical, mainly due to extra information that allows more filtering and searching possibilities.
[0049] Specifically, the method of the present invention provides the following information, in at least 10 columns of its graph table, in which the name of the columns and the detail of the information contained in each of them is given below: - 1st column: Tag_Pipe: includes the identification tag for the line; - 2nd column: Rep_ID: includes the identification number for the line; - 3rd column: Pipe_Type: includes the type of the line, which can be primary, secondary, any type of signal line or a "relation line" if it is a dummy line that represents a relationship between two directly connected instruments; - 4th column: Diam_Self: includes the diameter of the line; - 5th column: Drawing: includes the drawing where the connection between the line and the object is represented; - 6th column: Tag_Other: includes the identification tag for the object; - 7th column: Rep_Other_ID: includes the identification number for the object;- 8th column: Position: includes the reference to the object's position in relation to the line, which can be: "from" if it is upstream of the line; "to" if it is downstream of the line. If the object is another line, the position can also be "inside" or "outside," indicating the direction of the object's flow in relation to the line; - 9th column: Type: includes the type of object, which can be equipment, an instrument, an in-line component, etc.; - Info: includes additional information about the; object, which may be the symbol name, the valve opening action, the nozzle location, the equipment type and family, the instrument type description, whether the connection is the maximum inlet or maximum outlet nozzle, etc.
[0050] According to an exemplary application of the present invention, steps 2, 3 and 4 of the method of the present invention are modeled according to at least 4 rule tables of: causes, consequences, safeguards and checks.
[0051] Hypothetically, in an application of the method of the present invention, considering that the current deviation to be analyzed is "no flow".
[0052] This means that the cause table must be filtered so that the process variable and modifier (first two columns) indicate "flow" and "none", respectively, resulting in the rows shown in Table 3 below. Table 3 – Example of a cause table
[0053] For example, if there is a compressor within the current node, then the compressor's "stop" event should be investigated. The effects of this event should be considered for objects downstream of the trigger (which are "ahead" of the flow direction) or upstream of the trigger (which are "behind" the flow direction). For both configurations, the compressor's stoppage should be considered a primary cause, since, as shown in Table 3, in the last column, there is no secondary cause.
[0054] As mentioned earlier, the effects of the cause must be taken into account to estimate the consequences.
[0055] Therefore, it is necessary to consult the consequences table. This table should be filtered by process variable, modifier, flow direction, and cause, based on the information already known.
[0056] Once this is done, the result is the rows shown in Table 4. Table 4 - Example of a consequences table
[0057] According to Table 4, it can be seen that if a piece of equipment is found downstream of this compressor (i.e., "ahead" of the flow direction), the consequence would be "low pressure." On the other hand, if a piece of equipment is found upstream of this compressor (i.e., "behind" the flow direction), the consequence would be "high pressure."
[0058] The next step is to look for safeguards and detections (both are generally referred to as safeguards), and the safeguards table should be consulted.
[0059] This table should be filtered by process variable, modifier, consequence, and affected object, based on what is already known. Once this is done, the result is expressed in Table 5. Table 5 – Example of a cause table
[0060] The safeguard column shows the possible safeguard that should be sought to ensure that the analyzed scenario is safe.
[0061] According to Table 5, the "Flow Direction" and "Limit" columns indicate how to search for them. If the "Limit" column is "Affected for PSV / PSE," it means the search should begin at the affected object and follow specific rules for PSV and PSE. Furthermore, the "Flow Direction" column indicates that the algorithm performed by the method of the present invention should follow forward or backward relative to the flow direction of the pipeline. If the "Flow Direction" is "any," it means no restrictions are imposed.
[0062] Then, perform any additional checks, if applicable. For example, a relief valve (PSV) may be found, but within an invalid context. To determine if an additional check is necessary, consult the check table, an example of which is shown in Table 6. Table 6 – Example of a check table
[0063] This table should be filtered by the process variable, modifier, cause, consequence, and safeguard columns, based on what is already known. Once this is done, the result is the rows shown in Table 6 above.
[0064] The "Check" column indicates which check must be performed to consider the safeguard as correctly applied. If this check fails, it means that this safeguard must be considered non-existent or poorly adjusted. For this check in Table 6, "EQP_PRESS_PIPE_PRESS_PSV_SETPOINT" indicates that the following check must be performed: (i) - List all objects that are returned when searching for safeguards. (ii) - Consider E as the minimum design pressure for all equipment. (iii) - Consider P as the minimum design pressure for all pipelines. (iv) - Consider S as the minimum setpoint for all PSVs. (v) - If E is greater than P, then if S is less than P, the check passes; otherwise, it fails.
[0065] Figure 3 illustrates another practical example of a segment of a P&ID, where a manual valve VALV-12310009 is illustrated, in which the arrow coming from such valve indicates that, in a "no flow" scenario, caused by the inadvertent closing of this valve, the consequence must be sought by going back in relation to the direction of the flow.
[0066] Furthermore, according to figure 3, following the page connector, which is in the left corner of such figure (number 03391), the algorithm performed by the method of the present invention would reach the next P&ID, shown in Figure 4.
[0067] It is worth noting that figure 4 serves to illustrate the path taken by the method of the present invention, through the arrow illustrated therein, and the texts present in figure 4 are not relevant to understanding the method of the present invention.
[0068] According to figure 4, as shown by the arrow, the algorithm performed by the method of the present invention travels back through the pipe 26"-PC-C30-0380-PP, passing through valves VALV-12311631 and VALV-12310590, arriving at vessel V-1231001, causing the pressure to increase.
[0069] Once it was established that vessel V-1231001 could be subjected to higher pressure, some safeguards would need to be found, as illustrated in Figure 5, such as PSV, PSHH, and PAH. These safeguards were found by following the solid lines and arrows, marked with solid circles. Specifically for the very high pressure switch PSHH, the algorithm must still search for interlocks. The path to the interlocks found is marked by dashed lines. A shutdown valve (SDV) and an emergency shutdown signal were found, both marked with dashed circles.
[0070] It is worth noting that figure 5 serves to illustrate the path taken by the method of the present invention, through the arrow illustrated therein, and the texts present in figure 4 are not relevant to understanding the method of the present invention.
[0071] In this way, the method would group all the triggers that presented the same cause and the same consequence, constructing the resulting spreadsheet from which a row is displayed in Figure 6, where all the results are summarized. Division of the industrial plant by nodes
[0072] The algorithm performed by the method of the present invention performs the step of dividing the industrial plant by nodes based on the shutdown valve, SDV, and obeys the following steps: (ii) identify the objects of the well P&IDs and make them belong to a node for each well type; (ii) identify all the objects of the P&IDs of the systems missing SDV and make them belong to a node for each system; (iii) search for SDVs; (iv) for each SDV, search for objects downstream, following the correct flow direction; (v) stop the search if any of these objects are found: a) offline instruments b) open drain lines c) closed drain lines d) flare lines e) utility connectors f) another SDV (vi) define that all objects reached by each SDV belong to a new node;(vii) for each instrument, check if each object connected to it belongs to a node If not, look for nodeless objects from this connected object and assign them to the same node as the initial instrument; (viii) for each connector, check if the object connected to the pair of connectors belongs to a node If not, look for nodeless objects from this object and assign them to the node before the connector; (ix) for each node N without equipment, list all neighboring nodes En with equipment that belong to the same predominant system and make node N part of the largest neighboring node En; (x) repeat the previous step until the number of nodes remains unchanged. ;
[0073] Additionally, the algorithm can perform its analysis on a database that has been manually split into nodes or whose nodes have been automatically split and then manually adjusted. Search for affected objects
[0074] The search for affected objects is performed by following the steps below: (i) Starting from the initiator, check the search direction according to the consequence table (as described in Table 4), which can be "downstream", "upstream", or "Any"; (ii) Search for connected objects; (iii) Stop if the object is: a) Instrument offline b) Drain line open c) Drain line closed d) Flare line e) Utility connector f) Valve stuck closed g) Racket closed h) Assigned to a node that is not neighboring the initiator node (iv) Specific cases: a) If the cause mentions "hot side" (meaning that the initiator is a heat exchanger), the affected object must be on the cold side; b) If the cause mentions "cold side", the affected object must be on the hot side; c) If the cause mentions "pipe rupture", the affected object must be on the lower pressure side;d) If the trigger is a heat exchanger or an electric heater, the affected object may be the trigger itself; e) If the cause mentions "closing", "closing", or "blocking", the trigger itself acts as the stopping criterion; f) If the trigger is a vessel or a tank: - If the cause mentions "high level", the affected object must be reached from the top of the trigger; - If the cause mentions "low level", the affected object must be reached from the bottom of the trigger; g) If the trigger is a vessel: - If the cause mentions "low temperature (top)", the affected object must be reached from the top of the trigger; - If the cause mentions "low temperature (bottom)", the affected object must be reached from the bottom of the trigger; h) If the trigger is an electrostatic precipitator: - If the cause mentions "low temperature (bottom)", the affected object must be reached from the bottom of the trigger; (v) Restrict the affected objects to the equipment.
[0075] In the initial experiments to develop the method of this invention, the affected objects were not restricted to equipment and could be pipes to more closely resemble a real HazOp result. However, since pipes can be considered as equipment connections and this system can search for all equipment, pipes can be discarded. Furthermore, this would lead to a saving in processing time. Safeguard Search
[0076] The safeguard search is performed by following the steps below. (i) Consult the safeguard table (as described in Table 5) to determine the search limit and direction. The limit indicates the search scope: a) trigger-affected object: starts at the trigger, and the affected object is a stopping criterion; b) affected object: starts at the affected object; c) affected object to pressure: starts at the affected object and adds some stopping criteria for pressure safeguards; d) affected object to PSV / PSE: starts at the affected object and adds some stopping criteria for PSV and PSE; e) affected object to level: starts at the affected object and adds some stopping criteria for level safeguards and restricts the safeguard to the affected object node; (ii) search for connected objects;(iii) stop if the object is any of: a) offline instrument b) open drain line c) closed drain line d) flare line e) utility connector f) stuck-closed valve g) closed paddle h) AND and OR i) assigned to a node that is not neighboring the trigger node (iv) specific cases: a) if a control valve fails, all instruments in its loop are stop criteria and cannot be safeguards; b) stop criteria for "pressure affected object": SDV, XV, HV, FV, LV, PV, TV, and normally closed valve. If the safeguard is S (safeguard and not just detection), there are also some additional stop criteria: normally open valves and valve without opening action information; c) Still for pressure safeguards: normally open valves between the trigger and the affected object should be discarded from the stop criteria, as they should be considered as if the affected object were subjected to the effects of the trigger;d) All other process variables are stopping criteria for a given variable. For example: if the process variable is P (Pressure), the following process variables act as stopping criteria: F (Flow), L (Level), T (Temperature), PD (Differential Pressure). ;
[0077] In particular, if a "too high or too low switch" is detected, the interlocks and emergency shutdown signals that are triggered by it should be listed along with the appropriate action.
[0078] The method of the present invention identifies both the primary consequence and also consequences derived from it, that is, a secondary consequence.
[0079] As can be seen in Figure 7, which illustrates an example of information resulting from the method of the present invention, an oil separator may be subjected to a high level (which would be a primary consequence), but this may lead to liquid carryover with possible damage to another vessel, which is modeled as a secondary cause. For the aforementioned example, a high level is not an event that should be considered a primary cause. However, if this is imposed on an oil separator as a consequence of a primary cause from another object, this "high level" can then be considered a secondary cause. If this is the case, the consequence of a secondary cause is a secondary consequence, and potential safeguards should be related to the primary consequence.
[0080] In particular, the method of the present invention is highly flexible, as all knowledge is represented through tables of rules of causes, consequences, safeguards and checks and can be updated, modified or even customized to meet the demands of a specific project or team.
[0081] Complementarily, the present invention relates to a computer-readable storage medium, which comprises, stored therein, a set of computer-readable instructions, in which when the set of computer-readable instructions is executed by one or more processors, the one or more processors implement the method for performing automatic process risk analysis of the present invention, as described above.
[0082] In particular, computer-readable storage media may be memory, which may be non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or volatile memory, such as random-access memory (RAM). Computer-readable storage media may be any other medium or media that can transport, store, or record the expected program code in the form of an instruction, a data structure, or a set of instructions, and can be accessed by, but is not limited to, one or more computers or one or more processors. Alternatively, computer-readable storage media may be a circuit or any other device that can implement a storage, transport, or recording function.
[0083] Specifically, the set of computer-readable instructions represents the algorithm or computer program code or a data structure that performs the method for performing automatic process risk analysis of the present invention described above.
[0084] The processor may be a general-purpose processor, which may be a microprocessor or any conventional processor, or the like. Implementation of the algorithm performed by the method of the present invention
[0085] The method of the present invention can be implemented in C# and SQL, with the rule tables formatted in XML (generated from an Excel spreadsheet, which would facilitate management). The P&ID database is built based on Smart P&ID and stored in Oracle databases. The user interface contains: - Instructions on how to use it; - Checkboxes to define how the program will behave; - Log window to inform the user of what the program is currently doing; - Progress bars; - Performance statistics; - Calculation of the safeguard score.
[0086] The nature of the problem itself leads to a large number of database queries, many of which are redundant. This means, for example, that a particular trigger X could affect an object Y, imposing a safeguard search (with all those searches being performed by database queries).
[0087] But if a trigger Z also affects the same object Y, these safeguards have already been sought, and the time for that query to execute can be saved. This data reuse mechanism can save over 50% of the total processing time.
[0088] The algorithm's computational cost is extremely high. As the testing scope grew, so did the demand for memory, constantly leading to memory overloads. The system architecture was changed to 64-bit. This allowed the program to utilize a larger portion of the available memory.
[0089] Even so, data processing was still very slow. However, dividing the data into nodes helped create a very favorable environment for parallel processing. Each node can be analyzed independently, and this can save hours. However, this approach has its own limitation: if a node or a small group of nodes is much larger than the others, the system will exhaust the smaller nodes and become stuck with one or a few nodes that cannot be processed in parallel, compromising performance.
[0090] The solution to this problem was to subdivide the nodes into smaller chunks of 10 objects, ensuring that no single subdivision was significantly larger than another. This ensured effective parallelism throughout the processing.
[0091] Because this algorithm performs a large number of database queries over a long period of time, the system has its own safeguards, without which performance would be seriously compromised: - Each query is executed with a time limit. This means that if the query takes more than a few minutes to complete, the query is canceled, the system waits a few minutes, and then tries again; - If the database connection fails, perhaps due to database failures or general unavailability, the system waits a few minutes and then resumes processing. Results of the present invention
[0092] One of the main differences between the method of the present invention and standard HazOp is that the system performs a comprehensive search, meaning all objects are searched and analyzed. Thus, the number of scenarios and recommendations tends to be very large.
[0093] To reduce the number of objects to be searched, some exclusions were considered. These cases are analyzed in other scenarios. For example, valves that block or drain a control valve produce the same effects as the control valve in question. Some exclusions are: • Spare equipment; • Valve connected to a "process connection" line; • Valve connected to a signal line; • Valves in the standard: valve - pipeline - paddle - pipeline - valve - pipeline; • Valve connected to a paddle or closed figure 8; • Valve connected to a blind flange; • Valve in a line containing a sampler; • Valve connected to spare equipment; • Valves in the standard: valve (globe or needle) - pipeline - valve (globe or needle) - pipeline; • Valve that blocks or drains a control valve; • Valves with a diameter less than 1 inch; • Check valves.
[0094] After some experimentation, it was concluded that the original node splitting algorithm leads to a large number of small nodes, sometimes unrelated to the purpose of a given node. Therefore, the best node splitting approach would be to define each system as a node. Larger nodes tend to lead to shorter processing times. Recent HazOp meetings tend to link the node splitting approach to a specific operation or service, such as oil treatment, main compression, etc.
[0095] Another benefit of the method of the present invention is obtaining detailed information regarding the analyzed objects. For example, all objects are presented along with their tag and the P&ID in which they are represented. Furthermore, all nodes are described in detail, along with: • Equipment; • Valves; • Pipes; • Pressure, temperature, and capacity for each piece of equipment; • P&IDs.
[0096] One of the main benefits of this automated approach is the ability to calculate a safeguard score, which is calculated by the ratio of the number of safe scenarios to the total number of scenarios. A scenario is considered safe if there are a minimum number of safeguards in place to protect the affected object in question.
[0097] One of the biggest limitations of this system is its reliance on proper P&ID modeling. All connections must be made correctly for the search algorithm to work properly. Sometimes an analysis is flawed, but the P&ID appears correct. A more detailed analysis of the P&ID reveals unconnected objects.
[0098] Similar to the connection issue (mentioned above), the search for interlocks and emergency shutdown signals suffers from incorrect modeling. Some instrumentation signals lack the arrow indicating their direction, allowing the search algorithm to follow the wrong path. This can lead to incorrect results regarding interlocks.
[0099] The method of the present invention was designed to generate a list of interlocks and emergency shutdown signals (ESDs) for each too-high or too-low switch, providing a solution to a problem that requires several hours of work from the HazOp team. This would serve as input for the construction of a cause-and-effect matrix.
[0100] The method of the present invention exports as a result a spreadsheet that comprises a list of scenarios with their respective recommendations, project name, node control equipment and valves, system process data (informing equipment process data and capacity), P&IDs involved, etc. Assessment of the accuracy of the method of the present invention
[0101] Assessing system accuracy can be one of the most difficult questions to answer. The first attempt was to have the process team analyze each scenario listed by the system and verify that the cause, consequence, safeguards, detections, interlocks, and emergency shutdown signals were correct.
[0102] However, this approach was highly inefficient, taking a significant amount of time to verify, correct, and test a single scenario. The approach to assessing accuracy involved applying the present invention's method to a project's engineering database for which a HazOp spreadsheet was available. Thus, the challenge is how to compare the results of a primarily human process with the results of a computational process. However, this comparison proved to be the best method for listing all the scenarios that were not found by the present invention's method. The missed scenarios were classified into three classes: - Incorrect modeling: the actual database content contains errors (such as incorrect connections). No adjustments to the algorithm would help improve accuracy. This is the "dead end" class. - Incorrect comparison: the scenario was actually found by the automated system, but the comparison algorithm needs to be adjusted to correctly flag it.This is mainly due to the difficulty of comparing human and computational results. - Incorrect rules / algorithm: If the database content is correct and the comparison is correct, then the rule tables or the algorithm itself should be adjusted and another test should be done.
[0103] The method proposed in the present invention provides standardized and rapid results, following strict rules and complemented by complete and consistent information extracted directly from engineering databases. Alternatively, the results of the method of the present invention can be used as an initial estimate for the actual standard HazOp or can be used before the HazOp itself, so that some of its recommendations are already addressed to speed up the process as a whole. Furthermore, the results can also be used through safeguard scoring. If the system performs its analyses before and after implementing the recommendations, the safeguard score value can be compared before and after to verify whether these recommendations were implemented.
[0104] Those skilled in the art will appreciate the knowledge presented herein and will be able to reproduce the invention in the presented embodiments and in other variants, covered by the scope of the attached claims.
Claims
CLAIMS 1. A method for performing automatic process risk analysis, comprising the steps of: • dividing an industrial plant into nodes including dividing the industrial plant into portions smaller than the objects of the Piping and Instrumentation Diagram, P&ID; in which each node includes a set of deviations, in which a deviation is defined by a pair of process variable and a modifier; • defining at least one causative object for each deviation and recording a causative-deviation pair; in which the event that occurs in a causative object or to a causative object is the cause; • defining at least one affected object for each causative-deviation pair, which comprises defining at least one equipment that suffers the consequence of the deviation, due to the cause in the causative; • defining at least one set of detection and safeguard mode, which comprises defining at least one set of detection and safeguard mode for each consequence;• defining at least one additional safeguard recommendation, including defining at least one additional safeguard recommendation if a pre-established number of safeguards is not defined in the previous step.
2. Method, according to claim 1, characterized by the fact that the step of dividing an industrial plant into nodes comprises dividing the industrial plant by nodes based on a shutdown valve (SDV).
3. Method, according to claim 1 or 2, characterized by the fact that the step of dividing a plant; industrial node-based search comprises: (i) identifying objects from well P&IDs and assigning them to a node for each well type; (ii) identifying all objects from systems P&IDs missing SDV and assigning them to a node for each system; (iii) searching for SDVs; (iv) for each SDV, searching for objects downstream, following the correct flow direction; (v) stopping the search if any of the following objects are found: a offline instruments b open drain lines c closed drain lines d flare lines e utility connectors f another SDV (vi) defining that all objects reached by each SDV belong to a new node; (vii) for each instrument, checking whether each object connected to it belongs to a node. If not, searching for objects with no node from this connected object and assigning them to the same node as the initial instrument;(viii) for each connector, check whether the object connected to the connector pair belongs to a node. If not, look for non-node objects from this object and assign them to the node before the connector; (ix) for each node N without equipment, list all neighboring nodes En with equipment that belong to the same predominant system and make node N part of the largest node; neighbor En; (x) repeat the previous step until the number of nodes remains unchanged.
4. Method, according to claim 1, characterized by the fact that the set of deviations, the pair of process variable and the modifier are related as follows: - if the process variable is flow and the modifier is no flow, then there is no deviation; - if the process variable is flow and the modifier is also flow, then the deviation is also flow; - if the process variable is flow and the modifier is less flow, then the deviation is less flow; - - if the process variable is flow and the modifier is greater flow, then the deviation is greater flow; - if the process variable is flow and the modifier is reverse flow, then the deviation is reverse flow; - if the process variable is level and the modifier is less level, then the deviation is less level; - if the process variable is level and the modifier is greater level, then the deviation is greater level;- if the process variable is temperature and the modifier is higher temperature, then the deviation is lower temperature; - if the process variable is temperature and the modifier is reverse temperature, then the deviation is lower temperature; - if the process variable is pressure and the modifier is higher pressure, then the deviation is lower pressure; - if the process variable is pressure and the modifier; for reverse pressure, then the deviation is greater pressure.
5. Method, according to claim 1, characterized by the fact that the pre-established number of safeguards are two safeguards, among mechanical safeguard or interlocking safeguard or any combination thereof; or the pre-established number of safeguards is one safeguard.
6. Method, according to claim 1, characterized by the fact that it comprises traversing the graph defined by the characteristics and connections of the objects of the Piping and Instrumentation Diagram (P&ID) and generating a table including: - Tag_Pipe: includes the identification tag for the pipe line; - Rep_ID: includes the identification number for the pipe line; - Pipe_Type: includes the type of the pipe line: primary, secondary, any type of signal line or a "relation line" if it is a false line that represents a relationship between two directly connected instruments;- Diam_Self: includes the diameter of the pipe line; - Drawing: includes the drawing where the connection between the pipe line and the object is represented; - Tag_Other: includes the identification tag for the object; - Rep_Other_ID: includes the identification number for the object; - Position: includes the reference of the position of where the object is positioned in relation to the line, which can be: “from” if it is upstream of the line; “to” if; is downstream of the line; if the object is another line, the position can also be “in” or “out”, indicating the direction of flow of the object in relation to the line; - Type: includes the type of object, which can be any equipment, instrument or component in the line; - Info: includes extra information about the object, which can be the name of the symbol, the valve opening action, the location of the nozzle, the type and family of the equipment, the description of the instrument type, whether the connection is the maximum inlet or maximum outlet nozzle. 7.The method of claim 1, wherein the step of defining at least one affected object for each causative-deviation pair comprises: (i) starting from the causative, checking the search direction according to the consequence table, wherein the search direction is one of: downstream, upstream or any; (ii) searching for connected objects; (iii) stopping if the object is: a) offline instrument b) open drain line c) closed drain line d) flare line e) utility connector f) closed locked valve g) closed paddle h) assigned to a node that is not neighboring the causative node (iv) specific cases: a) if the cause mentions "hot side", the affected object must be on the cold side; b) if the cause mentions "cold side", the affected object must be on the hot side; c) if the cause mentions "pipe rupture", the affected object must be on the lower pressure side; d) if the trigger is a heat exchanger or an electric heater, the affected object may be the trigger itself; e) if the cause mentions "closing", "closure" or "blockage", the trigger itself acts as the stopping criterion; f) if the trigger is a vessel or a tank: - if the cause mentions "high level", the affected object must be reached from the top of the trigger; - if the cause mentions "low level", the affected object must be reached from the bottom of the trigger; g) if the trigger is a vessel: - if the cause mentions "low temperature (top)", the affected object must be reached from the top of the trigger; - if the cause mentions "low temperature (bottom)", the affected object must be reached from the bottom of the trigger;h) if the trigger is an electrostatic precipitator: - If the cause mentions "low temperature (bottom)", the affected object must be reached from the bottom of the trigger; (v) restricting the affected objects to the equipment.
8. Method, according to claim 1, characterized by the fact that the step of defining at least one set of detection and safeguard mode comprises:; (i) consult the safeguard table and obey the search limit and direction; a) causer-affected object: start at the causer and the affected object is a stopping criterion; b) affected object: start at the affected object; c) affected object to pressure: start at the affected object and add some stopping criteria for pressure safeguards; d) affected object to PSV / PSE: start at the affected object and add some stopping criteria for PSV and PSE; e) affected object to level: start at the affected object and add some stopping criteria for level safeguards and restrict the safeguard to the affected object node; (ii) search for connected objects;(iii) stop if the object is any of: a) offline instrument b) open drain line c) closed drain line d) flare line e) utility connector f) stuck closed valve g) closed paddle h) AND and OR i) assigned to a node that is not neighboring the initiator node (iv) specific cases: a) if a control valve fails, all instruments in its loop are stop criteria and not; may be safeguards; b) stopping criteria for affected object for pressure: SDV, XV, HV, FV, LV, PV, TV and normally closed valve; if there is safeguard and detection, the stopping criteria are: normally open valves and valve without opening action information; c) still for pressure safeguards: normally open valves between the causer and the affected object are discarded from the stopping criteria; or d) other distinct process variables are stopping criteria for a given variable.
9. Computer-readable storage media, characterized by comprising, stored therein, a set of computer-readable instructions, which when executed by a computer, executes the method as defined in any one of claims 1 to 8.
Citation Information
Patent Citations
Danger and operability analysis method based on discontinuous chemical production device
CN111553053A
Computer-aided chemical process safety analysis method based on first principle modeling
CN113836670A
Oil and gas pipeline transportation analysis method
CN116957187A
Safety management method for plant facility
JP2009122737A