Field Device Safe State Override via Hardware-Software Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In safety instrumented systems, field devices can fail, leading to dangerous operational states, and existing technologies lack effective methods to reliably bring these devices to a safe state, impacting the safety integrity level and probability of failure on demand.
Innovation Solution
A control system and method that combines a Type A classified hardware module with a Type B classified software module to redundantly ensure a field device is brought to a safe state, with the hardware module independently overriding normal control and the software module monitoring and verifying the override, ensuring the device is placed in a safe state even if the hardware fails.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant equipment is implemented to improve safety, then the safe failure fraction increases, but the device complexity and cost increase
Solution Approach 1:
The patent merges Type A hardware-based safety control with Type B software-based monitoring into a single integrated field device architecture. This combination achieves the benefits of redundant classification (improving safe failure fraction) while avoiding the complexity of completely separate redundant systems, as both modules operate within the same device framework with coordinated functions.
Solution Approach 2:
The field device is designed with multi-functionality, where the same device performs both normal control operations and safety-critical override functions through its dual-module architecture. This universality eliminates the need for entirely separate redundant equipment, reducing overall system complexity while maintaining high safe failure fraction through the combined Type A and Type B classifications.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A diagnostic system and method for a field device implemented in a safety instrumented system includes detecting an occurrence of a safety event associated with the field device, overriding normal control of the field device to cause the field device to enter a safe state in response to the detected occurrence of the safety event, verifying the override of normal control of the field device, and transmitting a control signal to cause the field device to enter the safe state.