Redundant Safety System Dormant Failure Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multiple redundant safety systems, dormant failures in inactive units can go undetected, potentially affecting the safety of a plant or complex, as existing systems do not adequately prevent failed units from interfering or assuming control before repair.
Innovation Solution
A safety assurance system with a unit active line (UAL) and safety verification line (SVL) communicates status indications between safety units, using vital supervision cards and power buses to ensure only the active/master unit is controlling the system, with switchable connections preventing simultaneous energization of both UAL and SVL, and periodic verification to detect potential safety issues.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple redundant safety units are used with active/master and passive/slave states, then system reliability is improved through redundancy, but dormant failures in inactive units can go undetected and potentially interfere with system safety
Solution Approach 1:
The patent implements a feedback mechanism where the active safety unit continuously monitors the passive units through a verification line (VSL). When a passive unit experiences a dormant failure, the monitoring detects the abnormal state and sends feedback signals to terminate the failed unit's power supply, preventing it from interfering with system safety. This closed-loop feedback system ensures that redundant units remain safe even when not actively controlling the plant.
Solution Approach 2:
The patent introduces an intermediary monitoring system consisting of the verification line and supervision card that mediates between the active and passive safety units. This intermediary mechanism allows the active unit to verify the safe state of passive units without direct control intervention, enabling detection and isolation of dormant failures while maintaining the redundancy architecture.
2Reliability
If failed units are disconnected prior to repair, then control safety is maintained, but subsequent dormant failures can occur that remain undetectable
Solution Approach 1:
The patent applies preliminary action by continuously monitoring and verifying the state of passive safety units before they can potentially cause harm. The verification line actively checks the readiness and safe state of standby units in advance, ensuring that any dormant failures are detected and the units are terminated before they could interfere with system safety or assume control unexpectedly.
Solution Approach 2:
The monitoring system provides continuous feedback on the state of disconnected/terminated units. Even after a unit is disconnected following a detected failure, the system maintains verification capabilities to ensure the unit remains in a safe state and does not develop undetectable dormant failures that could later compromise system safety.
3Reliability
If continuous verification of UAL and SVL status is performed, then dormant failures are detected preventing safety issues, but system complexity increases
Solution Approach 1:
The patent merges the verification function with the existing control architecture by integrating the verification line and supervision card into the redundant safety system structure. The monitoring and verification capabilities are combined with the control signal transmission functions, allowing continuous safety verification without adding completely separate complex monitoring systems.
Solution Approach 2:
The verification line and supervision card perform multiple functions: they monitor the state of passive units, verify signal integrity, detect dormant failures, and coordinate termination decisions. This multi-functional approach reduces overall system complexity compared to having separate dedicated monitoring systems for each safety function.
Data Source
AI summary
A system, method, and safety unit provide safety assurance for a multiple redundant system controlling a plant or complex. A unit active line (UAL) status indicates the presence of at least one redundant active unit within the system. A safety verification line (SVL) status verifies the powered down status of all redundant units not active within the system. A safety unit is associated with a vital supervision card (VSC) and vital power bus and the safety unit controls switchable connections from the vital power bus to the UAL and the SVL. Based on verification of UAL and SVL status, system control includes energizing the UAL.


