TIL 1556 - Security Measures Against Logic Forcing

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 7

Abstract

This knowledge article is to inform Customers of the applicability of TIL 1556 to units serviced by Baker Hughes.

Serviceable Technology
Heavy Duty Gas Turbines serviced by Baker Hughes (see “APPLICATION” of TIL 1556).

Classification
KS SAFETY

Nuovo Pignone Tecnologie S.r.l. con socio unico (Registro Imprese di Firenze, Codice Fiscale 06593380485 e Partita IVA di Gru ppo 06872660482)
Capitale Sociale ϭ 100.000.000,00 i.v. - Società soggetta a direzione e coordinamento di Baker Hughes Company

Nuovo Pignone Tecnologie S.r.l. Proprietary Information


The information published in this Technical Bulletin is offered to you by Baker Hughes in consideration of its ongoing sales and service relationship with your organization. However, since the operation
of your plant involves factors not within our knowledge, and since operation of the plant is within your control and responsibility for its continuing successful operation rests with you, Baker Hughes
disclaims responsibility or liability for damage of any type, including but not limited to direct, consequential or special damages that may be alleged to have occurred as a result of applying this
information, regardless of whether it is claimed that Baker Hughes is strictly liable, in breach of contract, in breach of warranty, negligent, or is in any other respect responsible for any alleged injury
or damage sustained by your organization as a result of applying this information. The information contained in this Technical Bulletin is confidential and proprietary. This Bulletin and the information
contained in it are protected by copyright and/or other intellectual property rights. This Bulletin and information are provided for authorized use only, and may not be used by or disclosed to others
without the prior express written consent of Nuovo Pignone Tecnologie S.r.l.
Contacts
For units under warranty or covered under a Contractual Service Agreement (CSA) please refer to your BH
Project Manager.

For technical questions or application and commercial requests please contact:


Baker Hughes Company
Customer Service Center
Via Felice Matteucci, 2
50127 Florence, Italy
e-Mail: customer.service.center@bakerhughes.com
Phone: +39 055 427 2500
Fax: +39 055 423 2800
Please specify the Unit Serial Number and Technical Bulletin associated with the request and whether the
request is technical or commercial.
To directly access and download BH Technical Bulletins published for your fleet or to subscribe to Technical
Bulletin e-mail notification service, please visit the Technical Enhancements & Notifications Platform:
https://www.bakerhughes.com/customer-resources

This online tool is available only to registered BH Customers.

Expense Policy
The recommendations contained in this Technical Bulletin are for information only. Unless otherwise indicated
in a Contractual Service Agreement (CSA) in force between the parties, a specific Purchase Order must be
agreed, and all costs associated with the implementation of the recommendations shall be paid by the
Customer.

2/2
Nuovo Pignone Tecnologie S.r.l. Proprietary Information
The information contained in this Technical Bulletin is confidential and proprietary. This Bulletin and the information contained in it are protected by copyright and/or other
intellectual property rights. This Bulletin and information are provided for authorized use only, and may not be used by or disclosed to others without the prior express written
consent of Nuovo Pignone Tecnologie S.r.l.
ENERGY SERVICES ENGINEERING TIL 1556
PRODUCT SERVICE 20 DECEMBER 2006
Compliance Category – A S
Timing Code - 4

TECHNICAL INFORMATION LETTER


SECURITY MEASURES AGAINST LOGIC FORCING

APPLICATION
All gas turbines, generators, and steam turbines with digital controls.

PURPOSE
To advise users to protect GE digital controls from unauthorized logic forcing while the unit is in operation.

Compliance Category

O - Optional Identifies changes that may be beneficial to some, but not necessarily all,
operators. Accomplishment is at customer's discretion.

M - Maintenance Identifies maintenance guidelines or best practices for reliable equipment


operation.

C - Compliance Required Identifies the need for action to correct a condition that, if left uncorrected,
may result in reduced equipment reliability or efficiency. Compliance may be
required within a specific operating time.

A - Alert Failure to comply with the TIL could result in equipment damage or facility
damage. Compliance is mandated within a specific operating time.

S – Safety Failure to comply with this TIL could result in personal injury. Compliance is
mandated within a specific operating time.

Timing Code

1 Prior to Unit Startup / Prior to Continued Operation (forced outage condition)

2 At First Opportunity (next shutdown)

3 Prior to Operation of Affected System

4 At First Exposure of Component

5 At Scheduled Component Part Repair or Replacement

6 Next Scheduled Outage

7 Optional

COPYRIGHT 2006 GE
The information published in this Technical Information Letter is offered to you by GE in consideration of its ongoing sales and service relationship
with your organization. However, since the operation of your plant involves many factors not within our knowledge, and since operation of the plant
is in your control and ultimate responsibility for its continuing successful operation rests with you, GE specifically disclaims any responsibility for
liability based on claims for damage of any type, i.e. direct, consequential or special that may be alleged to have been incurred as result of applying
this information regardless of whether it is claimed that GE is strictly liable, in breach of contract, in breach of warranty, negligent, or is in other
respects responsible for any alleged injury or damage sustained by your organization as a result of applying this information.
TIL 1556
BACKGROUND DISCUSSION Turbine Controllers older than Mk VI
Within digital control systems a logic point is a binary These controllers do not have the ability to provide
bit used to note the state of some information or to software control limited access to the controller. Users
take one of two actions, such as the turbine is either are responsible for limiting access to the equipment by
tripped or reset or a solenoid is either energized or de- administrative procedures to only approved and
energized. GE digital control systems have allowed a qualified personnel.
user a method to make a particular logic point be a
specific state, regardless of what it should be in normal Turbine Controllers MARK VI / MARK VIE
operation. This is called “forcing”, and is used primarily The Mark VI and Mark VIE Toolboxes provide various
when the unit is off line to troubleshoot a given privilege level access.
condition or calibrate a given device. • For Mark VI, reference GEH 6403
The forcing of any point was never intended to be an • For Mark VIE, reference GEH 6700
operational feature.
Generator Exciter Controllers older than EX2000
GE Energy has recently become aware of unauthorized These controllers do not have the ability to provide
access and modifications, i.e. forcing logic signals, to software control limited access to the controller. Users
controller systems. These situations have created are responsible for limiting access to the equipment by
hazardous conditions for personnel and equipment. administrative procedures to only approved and
qualified personnel.
In one instance, a logic point was forced in a MK V in
order to start a second vent fan in a gas turbine Generator Controllers EX2000, EX2100, LCI, LS2100
enclosure. This resulted in two hazardous conditions:
These Toolboxes provide various privilege level access.
• Abnormal operation of ventilation system
• For EX2000, reference GEH 6404
compromising the ability of the hazardous gas
• For EX2100, reference GEH 6414
protection system to detect a leak (the
relationship between gas pocket size and • For LCI, reference GEH 6402
detector reading is a function of airflow) • For LS2100, reference GEH 6415
• Unintentionally disabled the tripping function
The end user is responsible for password-protecting
of the hazardous gas protection system
privilege levels or access rights within the Toolboxes to
limit access to control settings and logic forcing to
RECOMMENDATIONS qualified personnel only.
GE recommends that users review the security
measures related to software changes, including logic /
analog forcing, to ensure the establishment of
administrative procedures and / or password
procedures that will prevent unauthorized
modifications (forcing, control constant changes,
sequence changes) to the control system. Included
should be the education of pertinent personnel to
ensure compliance. Users should also be aware that
any modifications done to the control system without
GE approval are at the users own risk.

It is intended that logic forcing only be used for off-line


software checkout, or troubleshooting procedures,
while the unit is shut down, and in conjunction with
proper lockout / tag-out procedures. Forcing should
never be used to replace lockout / tag-out procedures.
Customer personnel should not force logic signals to
circumvent control and protection functions. Forcing
logic while the unit is in operations should only be done
for troubleshooting, and then only after a thorough
study is made to ensure that it can be done safely.

2 of 5
TIL 1556
PLANNING INFORMATION Reference Documents
N/A
Compliance
• Compliance Category: A S Previous Modifications
• Timing Code: 4 N/A

Manpower Skills Scope of Work


Management and / or controls technician. N/A

Parts Contact your local GE I&FS Service Manager or


None Contract Performance Manager for assistance or for
additional information.
Special Tooling
N/A NOTE: If you would like to receive future TILs by email,
contact your local GE I&FS Service Manager or Contract
Performance Manager for assistance.

3 of 5
TIL 1556

TIL COMPLIANCE RECORD


Compliance with this TIL must be entered in local records. GE requests that the customer notify GE upon compliance of
this TIL.

Complete the following TIL Compliance Record and FAX it to:

TIL Compliance
FAX: (678) 844-3451
Toll free FAX: 1-888-896-TILS (1-888-896-8457)

TIL COMPLIANCE RECORD For Internal Records Only #


Site Name: Customer Name:
Customer Contact Information GE Contact Information
Contact Name: Contact Name:
Address: Address:

Email: Email:
Phone: Phone:
FAX: FAX:
Turbine Serial Number(s):

INSTALLED EQUIPMENT TIL Completed Date:


100% TIL Completed:
Description:

Unit Numbers: Part Description: Part Number MLI Number

Comments:

NOTE: If there are any redlined drawings that pertain to this TIL implementation, please FAX the drawings along with
this TIL Compliance Record.

FAX this form to: TIL Compliance


FAX: (678) 844-3451
Toll free FAX: 1-888-896-TILS (1-888-896-8457)

4 of 5
TIL 1556

USER SATISFACTION SURVEY


GE values your opinions and comments.

GE requests that you complete the User Satisfaction Survey below to help us better serve you with accurate and timely
information on your equipment.

Complete the following TIL Compliance Record and FAX it to:

TIL Survey
GE Product Service
FAX: (678) 844-6737
Toll free FAX: 1-866-604-2668

USER SATISFACTION SURVEY


Serial Number: Date:

1. How many days after TIL issue date did you receive this TIL?

1 - 5 days 6 - 10 days + 10 days


NOTE: If you would like to receive future TILs by email, contact your local GE Energy Services representative for assistance.
Rate the following based on a scale of 1 to 5, where 1 is Excellent and 5 is Poor.

2. Please rate how well this document informed you of the technical issue.

1 2 3 4 5

3. Please rate the overall effectiveness of this TIL.

1 2 3 4 5

Comments / Suggestions:

FAX this form to: TIL Survey


GE Product Service
FAX: (678) 844-6737
Toll free FAX: 1-866-604-2668

5 of 5

You might also like