Download as pdf or txt
Download as pdf or txt
You are on page 1of 27

DeltaV Safety Instrumented

System (SIS) Overview

EMERSON Process Management Educational Services Copyrighted Material / Reproduction Restricted


Objectives
Upon completion of this module, you will be able to define
 Safety Instrumented Function
 Safety Instrumented System
 The DeltaV SIS Hardware Architecture
 The DeltaV SIS Software Architecture
 The DeltaV SIS Capacities

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-2
Basic Process Control System – BPCS
A Basic Process Control System (BPCS) compares process inputs to operator-entered
setpoints and continuously regulates final control elements to maintain those setpoints.
The DeltaV automation system is a BPCS and is shown below in a flow control
application.

PS MD AI AO

FY
FT

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-3
Safety Instrumented Function
A Safety Instrumented Function (SIF) is a combination of sensors, Logic Solver and final
elements with a specified safety integrity level that detects an out of limit condition and
brings the process to a functionally safe state. SIF1, shown below, monitors a high
pressure condition and closes the solenoid valve to stop catalyst flow to avoid a hazardous
event.
Logic Solver

SIF1

BPCS

PT

Reactor
FY
FT XV

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-4
Safety Integrity Level
Each SIF is designed to meet a Safety Integrity Level (SIL). A SIL is determined by a
target risk reduction shown in the right column of the table below. Various qualitative or
quantitative methods can be used to calculate the target risk reduction which is a
combination of likelihood and consequence of an event.

Target average Probability of


Safety Integrity Level Failure on Demand
(SIL) (Demand Mode of Operation) Target Risk Reduction

4 > 10-5 to <10-4 >10,000 to <100,000

3 > 10-4 to <10-3 >1,000 to <10,000

2 > 10-3 to <10-2 >100 to <1,000

1 > 10-2 to <10-1 >10 to <100

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-5
Safety Integrity Level
To ensure a SIF will perform on demand, the combination of the sensors, Logic Solver
and final elements together must meet a Probability of Failure on Demand (PFD).
Assuming that a target risk reduction of SIL 3 is required, then the failure rates of the
instruments and Logic Solver combined must fall within the PFD of > 10-4 to <10-3.

Target average Probability of


Safety Integrity Level Failure on Demand
(SIL) (Demand Mode of Operation) Target Risk Reduction

4 > 10-5 to <10-4 >10,000 to <100,000

3 > 10-4 to <10-3 >1,000 to <10,000

2 > 10-3 to <10-2 >100 to <1,000

1 > 10-2 to <10-1 >10 to <100

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-6
Safety Instrumented Systems (SIS)
A Safety Instrumented System (SIS) consists of sensors, Logic Solvers executing SIFs and
final control elements. A SIS will typically execute multiple SIFs. The example below
consists of a SIS executing SIF1 for high pressure and SIF2 for high temperature.

SIS

PS CPU Output Module Input Module


SIF1
SIF2

BPCS

SV
TT PT

Reactor
FY
FT XV

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-7
BPCS – SIS Integration
Data is often passed between a BPCS and the SIS for coordination and interlocking. The
BPCS and SIS are typically from different vendors which can make the integration effort
extensive.

Server

PS MD AI AO
PS CPU Output Module Input Module

PT

Reactor
FY
FT XV

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-8
DeltaV SIS Hardware
DeltaV combines the BPCS and the SIS. The DeltaV Logic Solver SLS 1508 is plugged
into the same backplane as the BPCS; thus the phrase integrated but separate. For
integration purposes the MD controller can read SLS data and the SLS can read MD
control data. The MD and SLS use separate power and communications.

SLS 1508

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1-9
DeltaV SIS Hardware
Each Logic Solver can execute up to four modules, each module typically performs a SIF.
There may be as many as 32 Logic Solvers per controller.

SLS 1508 SLS 1508

SLS 1508 SLS 1508 SLS 1508 SLS 1508

SLS 1508 SLS 1508 SLS 1508 SLS 1508

….
EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 10
I/O
Each Logic Solver has 16 I/O channels. The channels can be any mixture of:
 Analog Inputs
 HART Analog Inputs
 HART Two-state Outputs
 Discrete Inputs
 Discrete Outputs

SLS 1508 SLS 1508


SIF1 SIFX

+ +
- -
- -
Ch1…....…Ch16 Ch1…....Ch16

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 11
I/O
Logic Solvers can read input channels from any Logic Solver under the same controller.
They can only write to their own output channels.

SLS 1508 SLS 1508


SIF1 SIFX

+ +
- -
- -
Ch1…....…Ch16 Ch1…....Ch16

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 12
Secure Parameters
DeltaV Logic Solvers communicate with each other using peer to peer communications
through secure parameters and secure parameter references. All Logic Solvers under the
same controller can read any secure parameters on the Local Peer to Peer.

SLS 1508 SLS 1508


SIF1 SIFX

Local Peer to Peer

Secure Parameter Reference

Secure Parameter

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 13
SISNet Repeaters
SISNet Repeaters provide communication between Logic Solvers that are attached to
different controllers for Remote Peer to Peer communications. Only Boolean data can be
transferred between SIS modules on different controllers and a total of eight Booleans can
be broadcast by a Logic Solver.
SLS 1508 SLS 1508

Remote Peer to Peer

SLS 1508 SLS 1508

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 14
SIS Network
The SIS Network is a separate category and contains the Logic Solvers and their
associated configuration.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 15
Library Items
The Library contains SIS Function Block Templates, SIS Composite Templates, and SIS
Module Templates.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 16
SIS Function Blocks
The SIS Function Blocks are designed specifically for SIS applications.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 17
SIS Locks
SIS parameters are write protected by SIS locks. Only users with the appropriate SIS keys
can change specific SIS parameters. The SIS Engineer would, most likely, have all the
SIS keys and the SIS Operator may only have the SIS Control key.

SIS Engineer

SIS Restricted Control

SIS Control

SIS Operator

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 18
User Manager
The DeltaV User Manager application allows you to define users and their respective
keys and privileges.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 19
Secure Write Mechanism
A Secure Write Mechanism allows you to change the value of a writeable parameter in a
Logic Solver. This significantly reduces the risk of an unintentional change to the Logic
Solver by the following means:
 Does not accept the type of change message that is sent to a Control Module.
 Only accepts a new pair of change messages, command and confirm
 Only accepts configuration changes if unlocked
 Integrity checks include, checking for error corruption and a two minute timeout
between the command and confirm

SLS 1508
Secure Write Bypass
Mechanism

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 20
Secure Write
The command and confirm of the Secure Write Mechanism is shown below in DeltaV
Operate.
Command

Confirm

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 21
SIS Data Entry Expert
The SIS Data Entry Expert allows you to create data entry using the Secure Write
Mechanism.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 22
SIS Alerts
Traditional safety systems relied on PLCs and non-intelligent field devices and, without
additional testing, you did not know the state of the equipment. The DeltaV SIS, along
with the Rosemount SIS instruments and Fisher SIS digital valve controllers, incorporate
HART technology to alert you if the system has an integrity problem.

AMS

HART
HART

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 23
SIS Alerts
The Rosemount 3144P and 3051S diagnostics detect failures. You are alerted of possible
failures through SIS Alerts.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 24
SIS Alerts
The SIS Alert indicates an alarm on a safety device TT-1 in the illustration below. The
operator can view the problem by clicking the device alarm.

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 25
Partial Stroke Testing
While a BPCS is dynamic with outputs continually moving, a SIS is static. On-line testing
can reveal undetected failures of a final element, such as a stuck valve, by partial stroke
testing. Partial Stroke testing can be initiated manually or scheduled with the DVC block.

Control Studio DeltaV Operate

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 26
Summary
You should now be able to define
 Safety Instrumented Function
 A Safety Instrumented System
 The DeltaV SIS Hardware Architecture
 The DeltaV SIS Software Architecture
 The DeltaV SIS Capacities

EMERSON Process Management – Educational Services Course 7305 – Rev 1 – 5/10/05 Copyrighted Material / Duplication Prohibited
1 - 27

You might also like