Beruflich Dokumente
Kultur Dokumente
TRICONEX
1
Definizioni
Safety (Sicurezza) Si definisce Sicurezza la libert da un rischio inaccettabile, per il Personale, la Collettivit, lAmbiente.
TRICONEX Systems
Goal : Strategy : Measurement: Method: Safety Fail Operationnal Reliability Fault Tolerance
Applications Areas
Safety
Safety/ Availability
Availability
Industries ...
Oil & Gas Pulp & Paper Textile Food Hydrocarbon Processing Marine Rubber and Plastics Pharmaceutical Utility Nuclear Cement Metals
Applications ...
Safety/ESD Equipment Fire & Gas Burner Management Automotive Presses Rotating Critical Control 4
Gas Turbine Control Steam Turbine Control Integrated Turbine Compressor/Anti-Surge Integrated Turbine Generator/Voltage Regulation
Safety/Emergency Shutdown Critical Control Burner Management Fire & Gas Detection New applications Nuclear & Transportation 5
Markets Served
11% 26% 23% 24% 8% 3% 5%
Chemical Manufacturing Petroleum Refining Oil & Gas Production Electric Power Utilities Marine Pulp & Paper Other
Our TMR Products are designed to meet the highest levels of safety certification - IEC 1508 class 3, DIN VDE 0801, 19250 level 6 (TV clas 6), FM Class 1 Div. 2 We continually certify our products to International standards - DIN, CSA, FM, IEC, UL, CE Mark, ABS
June, 1997 7
" Fail Safe" strategy: A failure inside a subsystem must shutdown the safety system "Fail operationnal" strategy: A failure inside a subsystem do not lead to a shutdown
Startup phase
"FAIL OPERATIONNAL"
Spurious trips
MTTF
t == 100years
= To avoid spurious trips = To decrease downtime = To decrease production costs = To control failures
Process lifecycle
10
Support failures
-Electronic component failures -Mechanical component failures -No single point of failure -Redundancy -On line replacement
11
Dual Architectures
PLC
Process
12
A B
B C
A C
Safety Availability
13
TMR Architecture
Input
A
Sensors
Processor
B V O T I N G A B C
Output
A B C
Voter
B C
Actuators
TriBus
Main Processor
A Output Leg B
Sensors
Input Leg B
Voter
Actuators
B TriBus
Main Processor
Input Leg C
C I/O Bus
Input Termination
NO C NC L N
2
RC
NO C NC
POWER
A
RUN
MP
COM
1
A
REMOTE
PROGRAM
PASS PASS FAULT ACTIVE MAINT1 MAINT2
PASS FAULT
PASS
PASS
FAULT
STOP LOCAL
FAULT
ACTIVE
ACTIVE
1 2
NET 1
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32
4TX 4RX
3TX 3RX
115/230 VAC
1 2 3 4 5 6 7 8
1 2 3 4 5 6
1TX 1RX
3 4 5
6 7 8 9 10 11 12 13
2TX
7 8
2RX
NET 2
14 15 16
17 18 19 20
115/230 VAC
21 22 23
COM RX COM TX I/O RX I/O TX
COMM TX RX
24 25 26 27 28 29 30 31
9 10 11 12 13 14 15 16
9 10 11 12 13 14 15 16
PRT
I/O TX
EMP 3006
EMP 3006
EMP 3006
NCM 4329
32
EICM 4119
18
Chassis - Architecture
ELCO Connectors for I/O Termination
Terminal Strip 1 Terminal Strip 2
TRIBUS
Power Supply 1
Communication Module * Either the left module or right module functions as the active or hot spare at any particular time
19
TRIBUS Hardware
Three Independent Serial Links Transmit Data From Each Main Processor to the Other Two Main Processors Serial Links Operate at 4 MBits/Second Utilizes a Fault-tolerant Clock (Tri-Clock) Consisting of Three Independent Clocks and Associated Selection Circuitry
20
TRIBUS Functions
Synchronizes MPs at the Beginning of Each Scan Votes DI Data Between MPs and Flags Disagreements Transfers AI Data Between MPs Compares DO and AO Between MPs and Flags Disagreements Transfers Diagnostic and Program Data Between MPs Transfers Incoming Communication Messages Between MPs Communication Bus for Automatic Re-education of MP
21
Diagnostics - Hardware
MPs Inspect the Chassis Layout for Proper Cards and Installed Cards Any Download Commands Will Create a System Inspection Query Application Program File Compared with Installed I/O Boards Firmware If a Board is Missing or Improperly Installed, The MPs Flag a System Alarm During Downloads, TRISTATION Displays all Disagreements
23
Vcc
Status Indicators Main Processor NS32GX32 Floating Point Processor NS32381 Internal System Bus
Timing Generator
Interrupt Controller
24
Power Regulators are Toggled Off to Test the Redundant Power Regulator If Fault is Detected by MPs 2oo3 Vote, Power Supply Fault Light is Energized and a System Alarm is Generated
26
R E G
A
Vdc
Filter
Rectifier
Converter DC/DC
NO C NC
R E G
Fault Detection
R E G
B
Vdc
Power supply #2
+
R E G
Filter
Rectifier
Converter DC/DC
NO C NC
Fault Detection
Fault
R E G R E G
C
Vdc
+V Bus 2 +V Bus 1 OV
27
28
If Circuitry is Found to be Stuck-On, MPs Vote to Activate DI Module Fault LED and Generate a System Alarm.
29
Mux. Optoisolator
Miicroprocessor
Bus
Xcvr
Mux. Optoisolator
Miicroprocessor
Bus
Xcvr
30
32
Signal Conditionning
Amp
ADC
Mux.
+ -
Amp
ADC
Miicroprocessor
Bus Xcvr
Mux.
Amp
ADC
Miicroprocessor
Bus Xcvr
Mux.
33
Both Tests Are Performed on All Output Circuits Regardless of Power Status. (NE or ND)
Output Switches are Closed then Opened, Voltage Loopback Verifies Proper Operation
If Switch is Found Faulty, MPs Vote to Activate DO Module Fault Light and Generate a System Alarm
35
Field Circuitry
Output Drive Circuitry
*
+V
A
*
Bus Xcvr
Microprociessor
Point Register
A.B
Bus Xcvr
Miicroprocessor
Point Register
C
* *
A et B
Load
Output Drive Circuitry
-V
36
Diagnostics - Supervised DO
Stuck-On and Stuck-Off Tests are Performed Continuously Both Tests Occur on All Output Circuits Regardless of Power Status (NE or ND)
Output Circuits are Toggled, Voltage Loopback Circuits Verify Proper Operation Field Load Monitored by Use of Voltage Loopback Circuits
If Output Switch is Found Faulty, MPs Vote to Energize Fault LED and Generate a System Alarm If Load is Missing, MPs Vote to Energize Load LED - Field Device Failure, NOT TMR System Fault
38
Field circuitry
Voltage Sensor
Point Register
+V (secondary) +V (primary) A
*
A or B
Point Register Output Drive Circuitry
C
Voltage/ Current Sensor
Bus Xcvr
Miicro Processor
Dual Ported RAM
Bus Xcvr
Miicro Processor
Dual Ported RAM
Point Register
B
* *
A or B Load
-V
39
Typical Architecture
Main Chassis
P.S 1 CPU P.S 2 I/O or COM I/O or COM I/O or COM I/O or COM P.S 2 P.S 1 I/O or COM I/O or COM I/O or COM I/O or COM I/O or COM P.S 2
Expansion Chassis
RXM Chassis
P.S 1 RXM Prim. I/O I/O I/O I/O
Room 1
30 m max
RXM Chassis
P.S 1 RXM Rem. P.S 2 I/O I/O I/O I/O P.S 2 P.S 1
Expansion Chassis
Remote Room
I/O
I/O
I/O
I/O
I/O
43
Communication Capabilities
MODBUS Master MODBUS Master
ETHERNET 802.3
C PU P.S 2
I/O
I/O
C PU
EICM NCM
P.S 2
I/O
I/O
P.S 1
P.S 1
C PU P.S 2
I/O
I/O
EICM
NCM
C PU P.S 2
I/O
I/O
EICM
NCM
45
Supports Two IEEE 802.3 Ports Four Isolated RS-232/ 422 Serial Ports (One Port Used for TriStation and Others Typically Used for MODBUS Communication to DCSs and Other Computer or SubSystems) One Parallel Printer Port Connects to TDC 3000 Universal Control Network (UCN) Connects to Foxboro I/A Series Nodebus Supports Additional 802.3 Port and Two RS-232/ 422 Serial Ports
46
Printer
TCP/IP 802.3 Network
CPU P.S 2
CPU P.S 2
CPU P.S 2
CPU P.S 2
SOE - Features
All the variables are recorded and time stamped in the memory of the TRICON Accuracy : scan time SOE block are setting up within Tristation (maximun of 14 SOE The control program manages event collection by means of functions that the user includes in his program All the informations can be retrieved through the different communication modules SOE Data Retrieval utility program is available through the Network Communication Module NCM.
48
Raffineria di Priolo
Configurazione di rete Ethernet ridondante, con connessioni rame-fibra ottica e Bridge per ottimizzazione del traffico di rete
NCM-2 Node 6 NCM-1 Node 5 CAVO IN RAME CAVO COASSIALE IN RAME FIBRA OTTICA
FO
FO
FIBRA OTTICA
B
BRIDGE
C
COAX
C
COAX
B
BRIDGE
FO
FIBRA OTTICA
FO
Printer1_1
FO
FO
Printer2_1
FO
PR1_2
P1
PR1_1
SG10_1 P2
SG10_2
49