Beruflich Dokumente
Kultur Dokumente
06 1
0 6
TM
10year
Y
N
R
N
I V A
E R S
A supplement to PLANT
ControlENGINEERING
Engineering
and Control Engineering magazines
PLANT ENGINEERING magazines
✓
GET IT DONE
for less...
...with Do more ®
orePLC
o-m s
1
D
Made in
YEAR USA
NEW!
Value Line Linear Actuator Compact Linear Actuator Twin Round Shaft Actuator
Low-cost, versatile linear slide Self-contained linear slide actuator Continuously-supported round
actuator with hard-coated designed for light loads in harsh rail slide with ball screw actuation
aluminum guide shafts. Unit or wet conditions in a very small provides a very robust precision
can be mounted horizontally, package. linear motion.
vertically, or inverted without
• Compact design • High-accuracy ball screw
loss of load capacity.
• Stainless steel lead screw • Continuously-supported guide rails
• Max load capacity: 110 lb
• Max load capacity: 125 lb • Max load capacity: 920 lb
• Max speed: 15 in/sec
• Max speed: 20 in/sec • Max speed: 6 in/sec
• Travel: 6, 12, 18, 24 inches
• Travel: 6, 12, 24, 36 inches • Travel: 12, 24 inches
• Ready for NEMA 17 motor
• Ready for NEMA 17 motor • Ready for NEMA 23 motor
4. Manufacturing machines
5. Ensuring productivity
With increasing engineering tasks and ever shorter time frames, it’s
good to know you have a drive and automation specialist at your side
who can make many of these tasks easy for you. We work with you
through the entire development process of your machine – from initial
ideas all the way to after-sales, from the control system all the way to
the drive shaft. Come discover the future of engineering with us, and
you will find more freedom to explore what really counts – your ideas.
To learn more, visit www.Lenze.com or come see us at:
PACK EXPO in Chicago, November 6-9, 2016 at Booth N-5125 As easy as that.
Contents
A6 Wireless remote monitoring improves
performance, reliability
Wireless monitoring is helping users solve problems by integrating
new and existing technologies across a common infrastructure to
get data into the hands of those who need it—securely.
A19
C OMMENT
Of wireless technology, process safety, and VFD software
S
ince the early 2000s, wireless technology procedures. He writes, “The validation process
has been working its way into industrial puts the SIF under a microscope, dissects it, and
facilities. And during the last decade, the looks for all the ways in which it could fail. Each
use of industrial wireless sensor networks of those possibilities must be examined and
has been growing rapidly in the process indus- tested, one by one, element by element. Proof
tries, which is the topic of the cover story tests are conducted at prescribed intervals
in this issue of AppliedAutomation. - 20 to detect undetected dangerous failures
06 1
0 6
According to the author, “Many that could prevent the SIF from
2
Jack Smith
N
R
N
ON THE COVER New types of measurement devices, such as acoustic monitors, allows companies to identify the source and quantity of material being
sent to flares. Courtesy: Emerson Process Management
T
The cost of wireless sensing networks is
he use of industrial wireless sensor networks significantly less than wired infrastructure due
has been growing rapidly in the process indus- to reduced cost of wiring, cable trays, input/output (I/O)
tries during the past decade. During this time, equipment, and associated design, installation, and main-
many stories have been told of successful tenance labor. This reduced cost makes it possible to
implementations in process, reliability, and implement new applications that previously weren’t finan-
energy industries as well as in health, safety, cially justified. For example, tank farm automation projects
security, and environmental monitoring applications. Many are now possible because of cost savings of up to 70%
users across these industries have found that wireless from reduced infrastructure, design, and labor required for
monitoring technologies provide new ways to improve the installation and commissioning (see Figure 1). Wireless
performance and reliability of their operations. level, temperature, and pressure measurements can be
installed to monitor the materials stored in these tanks,
improving the capability of operations.
Wireless sensing technologies make it possible to
measure processes that could not be measured before.
New sensors, combined with analytics software are being
applied to applications, such as process emissions, steam
trap health, relief valve status, and equipment corrosion
monitoring. Previously, these applications required manual
inspection using handheld equipment or other manual
techniques. With manual inspection, identifying the source
of process gases that are being sent to a flare can be very
difficult. Now, wireless acoustic monitoring allows compa-
nies to identify the source and quantity of material being
sent to flares (see Figure 2).
An electricity and natural gas utility company imple-
mented a wireless network to enable remote monitoring
of outlet gas pressures from four district regulators. The
company required quick installation and the cost of install-
ing wires was prohibitive. By attaching WirelessHART
interface adapters to existing pressure transmitters, it was
able to replace paper chart recorders with digital informa-
tion displayed on screens in the control room and logged
Figure 1: Once difficult and expensive to monitor, wireless sensor in the historical database. The entire installation was com-
technology makes tank farm operations easier by making monitor- pleted, tested, and tuned in three days.
ing more cost-effective and easier to implement. All graphics cour- WirelessHART networks also can enable access to smart
tesy: Emerson Process Management field device diagnostics that are stranded by legacy sys-
tems. Most legacy control systems don’t have I/O hardware
that is capable of HART digital communications with smart Integrating wired and wireless data into ana-
field devices. Rich diagnostics and sensor data is trapped
in these smart devices with no way for monitoring systems lytics and visualization applications increases
to connect to them. Previously, end users have dealt with
this by wiring multiplexers, but this approach is complex users’ ability to do more with the data.
and costly to implement. Instead, WirelessHART networks
enable access to diagnostic information through the use of actionable information. Subject matter experts have a
wireless transmitters installed on smart devices (see Figure more holistic view of data and can make recommendations
3). For example, control valve diagnostic information can be based on their education and experience. Purpose-built
accessed remotely by technicians for online diagnostics and software tools can be used to apply physics principles or
troubleshooting. empirical models to deepen the level of analysis.
For example, software with first-principle thermodynamic
Integrate data across information silos models can be integrated with a data historian to detect
Wireless data shouldn’t stand by itself. equipment performance degradation as an early indica-
Integrating wired and wireless data into ana- tion of mechanical problems. An existing heat exchanger
lytics and visualization applications increases might have flow and process temperature measure-
users’ ability to do more with the data. Wireless ments that are used by for temperature control, but would
data can be integrated into control systems, data histo- require additional temperature and pressure sensors to be
rians, and software applications where data from other installed for performance monitoring. Existing measure-
sources also are available. Before adding wireless mea- ments can be combined with new wireless measurements,
surements, engineers should take inventory of sensor data where mechanical gauges are replaced with wireless
that is already installed and add new points to complement transmitters. By expanding the data set to include all of the
existing measurements. available measurements, the thermodynamic models can
When the data is integrated, flexible analytics and visu- be used by experts to more accurately detect problems
alization platforms enable experts to derive insights and and proactively recommend actions to be taken.
Networks such as a wireless mesh network perature, must be secured for availability, integrity, and
confidentiality. However, if these monitoring networks
can be expanded easily by adding new measure- connect to critical control equipment, such as control
ments online while increasing the reliability valves, gas analyzers, or flowmeters, the security
needs will be much higher. Even in this case, secu-
and performance of the overall network. rity technologies, such as data diodes can be used
to ensure separation of the monitoring network from
historians or stand-alone application software focused on external threats.
solutions such as energy management, environmental
monitoring, and regulatory compliance reporting. Untethering data
For more specialized applications, it is becoming com- In this time of digital transformation, the companies that
mon for vendors to offer connected services based on use technology in new ways are the ones that gain a com-
wireless sensing networks. In this case, the wireless petitive advantage. Merely adding measurement points
monitoring networks are owned and operated by the ser- through wireless monitoring won’t reset users’ expecta-
vice provider and the user pays only a monthly service tions to achieve new business goals. When users begin
subscription fee. Vendors provide services based on strategically using wireless technology to complement
drop-in monitoring networks that are owned, installed, and their wired infrastructure to address previously unsolvable
operated by the service provider (see Figure 4). These are issues, they can start to advance the performance and reli-
connected securely through the user’s existing IT network, ability of their entire operation.
or installed with Internet connectivity via a cellular router.
Appropriate security measures are applied by the vendor, Mike Boudreaux is the director of connected ser-
including firewalls, data encryption, and even physical vices at Emerson Process Management, Round Rock,
security to prevent tampering. Texas. He has a BS in chemical engineering from the
Stand-alone wireless networks that are used for only University Houston and an MBA from the Kellogg School
measurements, such as acoustics, vibration, and tem- of Management at Northwestern University.
Engineering is personal.
So is the way you use information.
CFE Media delivers a world of knowledge to you.
Personally.
CFE Media is home to four of the most trusted names in the business:
Visit us in Chicago at
Pack Expo International
Booth S-2179
For more info:
November 6 - November 9
http://budurl.me/YAI949
Scott Hayes, PE may be other mechanisms that are capable of solving the
M a v e r i c k Te c h n o l o g i e s problem, so the degree of risk reduction would be less.
A
(See editor’s note.)
Safety specialists design the SIFs and then oversee
process safety system comprises many their installation and maintenance for as long as the plant
individual safety instrumented functions is in operation. This safety lifecycle (SLC) concept ties
(SIFs) designed to move a plant or process together all the steps in implementing a complete safety
unit to a safe state when something goes system, or one SIF. It follows three main phases: analy-
wrong. These functions should happen sis, realization, and maintenance. It begins with the initial
automatically—following a specific plan— analysis of the process and hazard identification, and then
when an undesired condition arises. moves to developing a mechanism to protect against the
For example, a steam-heated reactor will be equipped event, including installation and ongoing support.
with a pressure sensor able to determine if it has moved The role of the safety specialist in this context cannot
beyond its safe operating range. The SIF will have a trip be overemphasized. The suggestions for designing and
point where the controller (the SIF’s logic solver), will do implementing safety functions offered here should be
something specific to remediate the situation. In this case, left to qualified safety specialists. While it is important to
it opens a relief valve to keep pressure in the reactor understand how these things work, implementing them
from going any higher and might cut off steam flow. This yourself if you don’t have the proper training is not a good
action, or perhaps actions, happen automatically when idea and could potentially be disastrous. To apply a com-
the pressure reaches the prescribed setpoint following the mon expression, don’t try this at home.
plan designed by safety engineers to avoid any possibil-
ity of the reactor or its associated piping exploding (see Will it work?
“Designing a SIF”). After a SIF is installed, it must be validated to verify its
While a process is being designed, particularly one operation. Validation must follow specific procedures to
where products are flammable or toxic, safety specialists ensure it is trustworthy, with all steps documented. The
study it carefully to determine all the areas where things validation process puts the SIF under a microscope, dis-
could go wrong. For example, what if this valve sticks? sects it, and looks for all the ways in which it could fail.
What if the reactor gets too hot? Could this tank overflow? Each of those possibilities must be examined and tested,
Then, safety specialists imagine what kinds of havoc or one by one, element by element. Proof tests are con-
damage these situations could cause if realized, and the ducted at prescribed intervals to detect undetected dan-
likelihood of a problem actually developing. gerous failures that could prevent the SIF from working in
If they believe the consequences of the specific problem the future. Sensors, logic solvers, and final elements can
occurring are beyond what the company is willing to risk, be tested seperatly at different intervals, or the entire SIF
safety specialists design a remedy and create a SIF to can be proof tested at once. Eventually, the specific SIF
carry it out. In a complex unit, there can be hundreds of or the complete safety system may be decommissioned
individual SIFs. The hazards they cover may overlap, cre- with a given process unit or entire plant, bringing an end
ating multiple layers of protection. Therefore, if one fails or to its lifecycle.
proves to be inadequate, another remains to avoid a more The term “validation” is critical. There are many kinds
drastic escalation. of tests and checks performed when a unit is being con-
Each SIF is assigned a safety integrity level (SIL), structed or upgraded. Terms such as software verification,
which in basic terms is its importance in the larger risk- loop checks, proof tests, factory acceptance test, and
reduction picture. Every SIF is important, but some are others can be used for other things. But a safety system
more so. Those with high SIL ratings are especially criti- validation must follow a specific approach spelled out in an
cal, and the remedy has to provide a major reduction in applicable standard and must be documented in a specific
the probability that the event will happen. Those with low way. Other tests also may be just as specific, but typically
SIL ratings may have smaller consequences, or there they may have different objectives.
n Pressure instrument location 3. Create the testing process and put it in writing.
Because the test must be documented, it must follow a spe-
n Valve response time after trip cific procedure. IEC 61511 and ISA 84 specify the general
steps the test must include, so make sure it follows those
n Pipe and valve sizes sufficient for pressure relief recommendations. Each step should indicate the desired
outcome, following the potential failure modes identified
n Trip pressure setting by the system designers. The SIL rating may come into
play because a SIF with a high SIL rating may need more
n Self-resetting versus non-self-resetting loop extensive testing than one with a low SIL. The procedure
also must be practical within the plant context, so it must be
n The information that should be sent to the BPCS. selected carefully. In most companies, a basic procedural
template can be set up and adjusted for each situation, so it 7. Communicate instructions for return-to-service after
won’t be necessary to start from scratch for every SIF. the test is complete.
4. Determine and document advance preparations of 8. This test may be performed only once, but because
the equipment necessary to perform the test, along with there is potential for the SIF to be updated or otherwise
any unusual equipment to have on hand, such as a stop- modified, the procedure should include a revision history.
watch. If a pipe must be drained or the liquid in a tank
moved to a specific level, these requirements must be Simulating danger
noted. If step 2 was executed correctly, this will be easier. SIFs are designed to respond to problems, often poten-
tially major incidents. When a safety function is activated,
5. Communicate the testing instructions. Be specific as it is because the BPCS can’t cope with a malfunction or
to who needs to be where, what they need to be doing, other upset—these are not trivial matters. Validating a
and when their activities must take place. Again, coopera- SIF should involve, as closely as possible, creating the
tion and success in this step depends on step 2. Some problem so there is no doubt that the SIF can respond
tests will address the SIF as a unit, while others will exam- appropriately. Nonetheless, there will always be push-
ine individual components. back from operations to the suggestion of over-pressuriz-
ing a massive reactor or overheating a tank of product to
6. Specify in detail which variables must be recorded make sure a safety sensor reads the problem correctly.
during the tests. What value did the pressure instrument In the real world, even when working with something
actually display? How long did it take for the actuator as critical as a safety system, some allowance will need
to respond to the signal? Did it respond as quickly as to be made in the name of practicality. Here, in order
it needs to in actual service? This where the stopwatch from best to still acceptable, are the typical ways in which
might come in handy. If the response time is too fast for a SIFs are validated:
stopwatch, some other mechanism might need to be used,
such as an event or alarm log on a software program con- 1. Manipulate the process safely and carefully to create
nected to the process. the hazardous conditions. Obviously, this provides the most
conclusive test. But it generally involves the most drastic
process disruptions, with some manipulations worse than
Designing a SIF
A
safety-instrumented function (SIF) is a simple pro- depending on help from a human operator or any other
cess, sometimes called a safety loop, designed to part of the control system. The question one might ask is
perform a single function. It consists of three ele- why this complex system can’t be replaced with a much
ments: a sensor, logic solver, and actuator. Conceptually, cheaper level switch wired in series with the pump. The
it is a control loop, but it has a discrete on-off function. answer is it can, but the level switch does not provide
For example, consider an oil terminal that transfers the same assurances of functionality. If it gets jammed or
petroleum products from a pipeline to a storage tank. The moving parts rust or corrode, it might not operate during
control system is supposed to stop operators from over- an emergency. Yes, it can be tested, but this requires an
filling the tank, but if it does not function properly, liquid operator to perform the test, and it might not give a clear
can get too high and flow out of the tank vents. Given indication of its condition.
the hazards that a situation such as this creates, a SIF is The more elaborate safety loop approach is able to send
added as a layer of protection (see Figure 2). There is a information to the control system to indicate it is functioning
level sensor sending its data to a logic solver, a safety- correctly. It can send its level measurement to show it has
rated controller capable of reading the level variable from a correct reading and also verify the logic solver is working.
the sensor, which is programmed to trip and open a relay The trip point can also be changed, but this should be done
to shut down the pump motor when it reaches a specific only according to procedures for modifying a SIF. If the sen-
value. In this case, the actuator stops the oil flow before it sor goes dead or any other component fails, the logic solver
spills. It might also close the inlet valve for the tank. This can send an alarm to the control system. The logic solver
loop is not designed to regulate level. It just stops the also can be programmed to test itself at prescribed inter-
transfer when the level reaches its programmed trip point. vals, opening the valve to verify it is not stuck. These diag-
The most critical aspect of the SIF is its ability to func- nostic functions provide a much higher level of confidence
tion independently. It must be entirely self-contained, not and assures the SIF’s ability to do its job when called upon.
3. Use a simulated sensor. Uncouple the actual sen- Figure 2: The logic solver is the brain of the safety loop, and it has a
sor from the transmitter and use a simulator to provide a very simple function. It reads the process value from the sensor (LT), and
dummy input to the safety instrument(s). The most com- when the value crosses the threshold, it executes its task. Normally it is
mon example of this is disconnecting a thermocouple and
a discrete on-off function, opening or closing a valve, starting or stop-
using a thermocouple simulator.
ping some piece of equipment. Depending on the nature of the process,
4. Use a calibrator. Put the transmitter into simulation it may have a delay built in, waiting for some period of time between
mode and generate a trip signal. This is the least real- the value crossing the threshold and responding, to avoid tripping when
istic, but it is certainly the easiest. As a result, it is also the change is a brief transient. Some safety loops are self-resetting,
unfortunately the most common approach. resuming normal operation automatically when the variable returns to
its normal range. Courtesy: Maverick Technologies
Regardless of which approach is selected, it should be
written into the procedure.
The tests described so far are aimed primarily at the to a valve actuator can be disabled so it will not move,
sensor. In most cases, SIFs are looking for excursions although the actuator can still be verified.
into undesirable temperature or pressure, but level also is Having said that, no test is complete without seeing the
common to avoid overflows and spills. final operation work fully at least once. If there must be
The other parts of the SIF—the logic solver and final intermediate tests, a good procedure is to make the final
control element (FCE) or actuator—are just as important operation happen on the first and last tests. If doing it twice
and must be checked individually and thoroughly. During is too many, then it should be done on the final test. This
the actual field validation, it is important to include a allows the final element to be left as it is tested instead of
series of individual checks for these devices as well. For relying on the reconnection of such a critical device.
the logic solver: A SIF designed well and tested thoroughly should perform
reliably in an emergency and not cause nuisance trips. The
n Confirm all inputs and outputs are functional validation process is a critical step in the larger SLC. When
executed by a qualified and experienced safety engineer, a
n Confirm programming and other software to ensure all plant should be confident of its ability to operate safely to pro-
setpoints and other configurations are correct tect plant personnel, the environment, and the equipment.
n If a voting scheme is used, connections to all the sen- Scott Hayes is a control systems engineer at Maverick
sors must be verified, although checking every possible Technologies. Maverick Technologies is a CFE Media
combination is probably not necessary. content partner, CSIA Level 1 member, the Control
Engineering System Integrator of the Year in 2011,
Just as it may be necessary to avoid disrupting the pro- and was inducted into the Control Engineering System
cess to test the sensor, testing the FCE can also cause Integrator Hall of Fame in 2012.
disruptions. Opening a relief valve or repeatedly shutting
down a major piece of machinery, such as a pump or com- Editor’s notE: The process of determining SIL ratings is
pressor, as part of the validation is not a good idea. As complex and beyond the scope of this discussion. For more
with checking the sensor, some allowance may have to be information about SIL ratings, safety instrumented systems,
made for the sake of practicality. and safety instrumented functions, read Control Engineering
For large equipment, it is likely possible to disconnect or Magazine’s “Real World Engineering” blog at
bypass where the FCE interfaces with the equipment so www.controleng.com/blogs/real-world-engineering, written
that it is possible to see it operate without actually shut- by engineers at Maverick Technologies.—JS
ting down the device. Similarly, the compressed air supply
W
ithin a process manufacturing context, safety to equipment. When the problem is fixed, the unit can
incidents can take many forms. Some are be restarted, but critical time has been lost.
small and an occurrence could create a minor Now, imagine the same situation where a unit tripped
chemical spill. Others are huge and could result in a and went into shutdown mode because there was a
fire or explosion with thousands of gallons of petroleum malfunction in one of the safety sensors. The SIF went
products. In the same way, the actions a specific safety into action because the pressure sensor mistakenly
instrumented function (SIF) takes reported a problem when none
to correct a problem and avoid To avoid nuisance trips with actually existed. If it’s a small
escalation can take various forms. problem with a small result, such
critical SIFs, some plants install
A relief valve may be opened to situations are called nuisance
release pressure in a tank for a redundant sensors to prevent a trips. However, if it’s a big event,
small problem. However, for a seri- critical system from going into the result is almost as disruptive
ous situation, the action the SIF as an actual emergency.
takes can be hugely disruptive. If shutdown unnecessarily. These Obviously, a plant wants its
a major incident is underway, a approaches use voting schemes SIFs to do their jobs. Reliable
drastic action may be appropriate, SIFs need to act when an actual
such as effectively shutting down to force the redundant problem is developing—but only
an entire process unit. To avoid sensors to act as a group. when an actual problem is devel-
a catastrophe, such actions are oping. To avoid nuisance trips
absolutely necessary, but they cost enormous amounts with critical SIFs, some plants install redundant sensors
of money and disrupt production even if the process to prevent a critical system from going into shutdown
shuts down exactly as it is supposed to with no damage unnecessarily. These approaches use voting schemes
1oo1 1oo2
SIS
SIS SIS
2oo2
VOTING
2oo3 SIS
2oo3 voting
Figure 3: If a sensor malfunctions and/or opens, there is still a path for power to reach the intended equipment. In addition, two sensors
must report the same problem simultaneously for the SIF to act. This 2oo3 scheme reduces the likelihood of a nuisance trip. However,
there are other voting schemes used in various applications. It should be noted that other arrangements, such as 1oo2, won’t work
because the failure of one device still trips the system. Also, 2oo2 has its quirks for the opposite reason. If one sensor fails “on,” the
SIF can’t perform its function. Both kinds of failures are possible. When a system can’t do its function, it’s called “failure on demand.”
Courtesy: CFE Media
Subscribe today at
www.PlantEngineering.com/subscribe
VFD programming
V
defaults. When working with more than one device on
a daily basis, any tool that will eliminate the need for
ariable frequency drives (VFDs) have been remembering these functions, parameters, and values
around for decades now. During their infan- makes a big difference.
cy, programming involved moving jumper VFD software allows users to search through all
blocks and adjusting potentiometers. As time parameters and monitors with an active search func-
passed, technology evolved (see Figure 1). tion. Instead of remembering that parameter “C1-01” is
Although seven-segment light-emitting diode the acceleration time and hunting through the keypad or
(LED) keypads began to emerge, programming and moni- technical manual to find this, searching for “acceleration”
toring was easier but still somewhat cryptic. Eventually, in the search bar will display the matching parameter.
full-text liquid-crystal display (LCD) keypads became the Changing the aforementioned acceleration time is equally
norm. These keypads feature multiple lines of text that easy. Simply clicking on the parameter, entering the new
can be displayed in many languages. Navigation is intui- value, and then clicking “Write” changes the parameter
tive and the display can be customized to display the nearly instantaneously. There is no more need for multiple
most useful parameters. Although VFD manufacturers keystrokes on the keypad. This function is great for chang-
have made many advances in terms of ease of use, some ing one parameter at a time. But what about changing
users still find programming and monitoring with a 2-inch multiple parameters at once to make commissioning and
display tedious. This is where VFD programming and startups as efficient as possible?
monitoring software comes into play. VFD startup can be streamlined by using what some
software programs call an “application wizard,” which
Making programming easier takes the guesswork out of VFD application program-
The benefits of using VFD software can make start- ming. Typically, the wizard asks for information, such as
ups, programming, monitoring, and even troubleshooting control method, duty, motor data, and control sources.
2S
Selects accel/decal time range
Switch
Accel/ (0.2 to 1,800 seconds)
decel
time ACC DEC
setting Accel/decal times independently
Potentiometer adjustable within the time range
selected by 2S
a VFD to a PC is with
(USB) connection.
Be prepared
Preparation is one of the most impor-
tant steps to take when operating in the
field. For example, if a system integrator Figure 3: A monitor panel can display user-selected signals, such as analog gauges,
is contracted to provide VFDs with other sliding scale, trend, or an LED-style panel. Signal levels are displayed in real time.
seweurodrive.com | 864-439-7537
Less means more!