Configurable SIS Voting Logic for Multi-SIL Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing safety instrumented systems (SIS) are inflexible and require multiple systems to implement different Safety Integrity Levels (SIL), leading to inefficiency and high costs, as they can only operate with a single SIL value.
Innovation Solution
A protection system with multiple processing channels and configurable voting logic, allowing it to operate in various SIL configurations by altering the number of processing channels and voting logic, enabling flexible operation across multiple SIL values such as SIL 2 and SIL 3.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate safety instrumented systems are used to implement different SIL values, then each system can maintain its dedicated safety configuration, but the overall system complexity and cost increase significantly
Solution Approach 1:
The safety instrumented system is designed to perform multiple SIL functions within a single unified platform. The controller can be reconfigured to implement different voting logic (e.g., 2-out-of-3, 1-out-of-2) and safety architectures, allowing one system to replace multiple dedicated systems while maintaining appropriate SIL certifications for each configuration mode.
Solution Approach 2:
The system incorporates dynamic reconfigurability where the safety architecture and voting logic can be changed during operation or maintenance cycles. This allows the system to adapt between different SIL requirements without physical hardware changes, transitioning between configurations such as SIL 3 (2-out-of-3 voting) and SIL 2 (1-out-of-2 voting) as needed.
2Device complexity
If a single safety instrumented system is used for multiple SIL values, then cost and complexity are reduced, but the system must support multiple configurations which increases software and hardware complexity
Solution Approach 1:
The system is pre-designed with the capability to support multiple voting logic configurations and safety architectures built into the hardware and software architecture. This preliminary preparation allows rapid reconfiguration between different SIL modes without requiring extensive redesign or additional components, as the multi-configurability is embedded from the outset.
Solution Approach 2:
The system achieves different SIL configurations by changing operational parameters such as voting logic rules, channel activation states, and safety architecture modes rather than requiring physical hardware modifications. This parameter-based reconfiguration allows the same physical system to meet different SIL requirements through software and configuration adjustments.
3Ease of manufacture
If the system is designed with fixed hardware architecture, then manufacturing and certification are simplified, but the system cannot adapt to changing risk levels and SIL requirements
Solution Approach 1:
The hardware architecture incorporates dynamic elements such as reconfigurable logic, programmable controllers, and selectable circuit paths that allow the system to change its functional configuration. This dynamic capability enables the same hardware platform to be certified for multiple SIL levels by activating different configuration modes, combining manufacturing simplicity with operational flexibility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method includes selecting one of a first safety architecture and a second safety architecture of a protection system configured to monitor a protection system. The protection system includes an input base, a controller base and an output base. The selecting includes selecting one of a first voting logic associated with the first safety architecture and a second voting logic associated with the second architecture. The controller base is configured to execute the selected voting logic. The method also includes configuring the protection system including a plurality of processing channels to operate in one of a first configuration associated with the first safety architecture and a second configuration associated with the second safety architecture. The configuring includes altering the number of processing channels releasably coupled to the protection system and hardware relay output in the protection system. Each processing channel of the plurality of processing channels includes an input circuit coupled to the input base, a controller coupled to the controller base and an output circuit coupled to the output base.