Redundant Safety System Dormant Failure Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multiple redundant safety systems, dormant failures in inactive units can go undetected, potentially affecting the safety of a plant or complex, as existing systems do not adequately prevent failed units from interfering or assuming control before repair.

Innovation Solution

A safety assurance system with a unit active line (UAL) and safety verification line (SVL) communicates status indications between safety units, using vital supervision cards and power buses to ensure only the active/master unit is controlling the system, with switchable connections preventing simultaneous energization of both UAL and SVL, and periodic verification to detect potential safety issues.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple redundant safety units are used with active/master and passive/slave states, then system reliability is improved through redundancy, but dormant failures in inactive units can go undetected and potentially interfere with system safety

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddormant failures interference
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the active safety unit continuously monitors the passive units through a verification line (VSL). When a passive unit experiences a dormant failure, the monitoring detects the abnormal state and sends feedback signals to terminate the failed unit's power supply, preventing it from interfering with system safety. This closed-loop feedback system ensures that redundant units remain safe even when not actively controlling the plant.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary monitoring system consisting of the verification line and supervision card that mediates between the active and passive safety units. This intermediary mechanism allows the active unit to verify the safe state of passive units without direct control intervention, enabling detection and isolation of dormant failures while maintaining the redundancy architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If failed units are disconnected prior to repair, then control safety is maintained, but subsequent dormant failures can occur that remain undetectable

Engineering Contradiction:
Improvecontrol safetyVSAvoiddormant failure detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by continuously monitoring and verifying the state of passive safety units before they can potentially cause harm. The verification line actively checks the readiness and safe state of standby units in advance, ensuring that any dormant failures are detected and the units are terminated before they could interfere with system safety or assume control unexpectedly.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system provides continuous feedback on the state of disconnected/terminated units. Even after a unit is disconnected following a detected failure, the system maintains verification capabilities to ensure the unit remains in a safe state and does not develop undetectable dormant failures that could later compromise system safety.

Inventive Principle:
Principle #23Feedback

3Reliability

If continuous verification of UAL and SVL status is performed, then dormant failures are detected preventing safety issues, but system complexity increases

Engineering Contradiction:
Improvesafety assuranceVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the verification function with the existing control architecture by integrating the verification line and supervision card into the redundant safety system structure. The monitoring and verification capabilities are combined with the control signal transmission functions, allowing continuous safety verification without adding completely separate complex monitoring systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The verification line and supervision card perform multiple functions: they monitor the state of passive units, verify signal integrity, detect dormant failures, and coordinate termination decisions. This multi-functional approach reduces overall system complexity compared to having separate dedicated monitoring systems for each safety function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9618909B2Safety assurance of multiple redundant systems
Publication Date: 2017.04.11 HITACHI RAIL GTS CANADA INC
  • US9618909B2 patent drawing
  • US9618909B2 patent drawing
  • US9618909B2 patent drawing

AI summary

A system, method, and safety unit provide safety assurance for a multiple redundant system controlling a plant or complex. A unit active line (UAL) status indicates the presence of at least one redundant active unit within the system. A safety verification line (SVL) status verifies the powered down status of all redundant units not active within the system. A safety unit is associated with a vital supervision card (VSC) and vital power bus and the safety unit controls switchable connections from the vital power bus to the UAL and the SVL. Based on verification of UAL and SVL status, system control includes energizing the UAL.