Practical Process Engineering
Kanalga Telegramāda oātish
Please invite your friends to follow this channel if they are interested in Process Engineering like you. Thank you in advance!
Ko'proq ko'rsatishMamlakat belgilanmaganToif belgilanmagan
2 467
Obunachilar
+1324 soatlar
+607 kunlar
+22630 kunlar
Postlar arxiv
Based on the examples of CCF's in above post, you can tell me one of them may happen in our example; PLUGGAGE. If any dusts or wax flows in the line, both of them can be plugged. It means a common cause is able to fail both. Therefore, these XV's are not independent. Actually, we do not need two XV's and one is enough. Instead, we may need to resize the PSV for a higher relief scenario.
Now you are familiarized with voting and IPL's. Here is a question for you? Two XV's are installed on the feed line? Are they independent?
We are one step away to answer this question?
This step is "COMMON CAUSE FAILURE"
A common cause failure (CCF) occurs when a single failure results in the failure of multiple devices. ASME Code Case 2211 requires that sufficient independence be demonstrated to ensure reliability of the HIPPS performance. To minimize common cause failures, the initiating causes of each scenario identified during the hazard analysis should be examined. Then, the HIPPS hardware and software should be designed to function independently from these initiating causes. For example, if a control transmitter is listed as an initiating cause to the scenario, the control transmitter cannot be the sole means for detecting the potential incident. At least one additional transmitter will be required for the HIPPS. Once independence of the HIPPS devices is demonstrated, common cause failures (CCF) related to the design must be examined. The following are often cited as examples of common cause faults:
⢠Miscalibration of sensors
⢠Fabrication flaws
⢠Pluggage of common process taps for redundant sensors
⢠Incorrect maintenance
⢠Improper bypassing
⢠Environmental stress on the field device
⢠Process fluid or contaminant prevents valve closure
The most critical failure is that the SRS is incorrect at the beginning of the design process and the HIPPS cannot effectively detect or prevent the potential incident. Improper system specification can compromise the entire HIPPS. Industrial standards and corporate engineering guidelines and standards can be utilized to reduce the potential for CCF. The proposed or installed HIPPS design can be compared to these standards. Deviation from the standards can be corrected through design revision or documented to justify why this specific application has different requirements. Checklists can also be used to reduce potential CCFs. A checklist analysis will identify specific hazards, deviations from standards, design deficiencies and potential incidents through comparison
of the design to known expectations, which have been expressed as checklist questions. In some cases, it may be necessary to consider the impact of potential common cause failures when verifying whether the HIPPS can achieve the target SIL. In such cases, the potential common cause failures will need to be considered in the quantitative performance evaluation.
Some protection layers are protective/preventive; prevent the undesirable event from occuring in the first place such as process design, basic proces control system (BPCS like DCS or FCS system are used in control rooms), critical alarms and human intervention and safety instrumented function (SIF).
On the other hand, some protection layers are mitigative; they mitigate the event after it occurs. Physical protections like rupture disks or safety relief valves imlying some degree of spillage, or contamination in the surrounding environment, which makes this physical/mechanical protection layer mitigative, rather than protective/preventive. Above this layer, all further layers are mitigative.
Since prevention is always better than a cure, it is best to employ prevention rather than mitigation. Now, you know why some concepts such as SIS's like HIPPS or inherently safe designs are very important. Moreover, these protection layers should be independent (IPL)
#Independent_Protection_Layers_(IPL)
Every piece of hardware may fail at one time or another. Failure requires repair or replacement. However, control and safety functions provided within the same hardware show that system failures and repair leave the process unprotected, which is unacceptable in most operations. There's also the need to spread risk. Like financial investors who diversify their investments, designers and operators of control and safety systems need to prevent one system's failure from causing devastating effects.
Broadly speaking, risks can be classified into 3 categories:
*Negligible risks - risks broadly accepted by most people as they go about their everyday lives.
**Tolerable risk - we would rather not have the risk but it is tolerable in view of the benefits obtained by accepting it. This would apply to traveling in a car, we accept that accidents happen but we do our best to minimize our chances of disaster.
***Unacceptable risk - the risk level is so high that we are not prepared to tolerate it. The losses far outweigh any possible benefits in the situation.
There is no single method that can totally eliminate all risks. Therefore, several methods must be implemented to reduce the risk of an accident. The concept of protection layers applies to the use of a number of safety measures all designed to reduce risk by reducing either the likelihood of potential incidents resulting in an impact on people, environment or property, or by reducing the magnitude of the impact should an incident occur.
Multiple, independent protection layers (IPL), also known as the "defense-in-depth" approach, generally consists of the following independent layers.
In all these examples we see a 2oo3 structure. It means if two of these three pressure transmitters fails or send a high pressure signal to the HIPPS logic solver, it sends CLOSED signal to the XV's on thr feed line.
So far so good. But, the designer installed two XV's on the same line to increase the reliability. Is there and error in this layout? I say YES.
Let's talk a little bit about Independent Protection Layers or IPL's.
***VOTING***
What does VOTING mean in SIS (safety instrumented system)?
voting specifies the impact of redundancy on the fault tolerance. "m oo n" (means m out of n) is a structure of elements that is functioning when m-out-of-n channels are functioning, and which fails when n-m+1 or more of its elements fail.
Voting elements are usually accomplished by taking the sensor signals and comparing them in the CPU executing the application logic. The actuator signals are then directed to the outputs where the signal for the actuator is either electrically or logically solved, or both.
For simple dual voted configurations, two votes are available. The logic can be voted either 1oo2 (one-out-of-two) or 2oo2 (two-out-of-two) from the state of the signals.
1oo2 voting requires additional field taps, PLC or DCS input boards, system loading, and higher cable costs. The two transmitters should be wired into separate input boards in architecture.
Voting a dual system 2oo2, where both signals are required to be present for operation, will increase reliability (where the safe state is off or non-operational). This is desirable for the safe operation of critical processes and machines. However, system availability which might otherwise be compromised because of the potential for a single loss of a component causing the system to shut down, are prevented with fault degradation capability.
2oo2 is not considered fail-safe because there are many conditions when one transmitter may be out of service and unable to trip. Therefore, even if the other transmitter votes a trip, a trip cannot occur. This architecture is not normally used in process or personal safety protective systems; it is most often used in rotating equipment (e.g. vibration probes for shaft shutdowns) where space limitations make it difficult to install three sensors.
***Standards for HIPPS:
The international standard, IEC 61508, āFunctional Safety of Electrical / Electronic / Programmable
Electronic Safety Related Systems,ā establishes a framework for the design of instrumented systems that
are used to mitigate safety-related risks. The United States standard, ANSI/ISA S84.01-1996, āApplication
of Safety Instrumented Systems (SIS) for the Process Industry,ā and international standard, IEC 51611,
āFunctional Safety: Safety Instrumented Systems for the Process Sector,ā are intended to address the
application of SISs in the process industries.
The objective of these standards is to define the assessment, design, validation, and
documentation requirements for SISs. While these design standards are not prescriptive in nature, the
design processes mandated by these standards cover all aspects of design including: risk assessment,
conceptual design, detailed design, operation, maintenance, and testing. Since HIPPS is a type of SIS, the
requirements of these standards, as pertaining to each specific HIPPS application, must be investigated
and applied thoroughly.
#HIPPS
šš¼šš¼Why do we need HIPPS (High Integrity Pressure Protection System)?šš¼šš¼
Conventional pressure relief system design, including relief header and flare sizing, does not
examine the reduction in potential loading due to hazard mitigation provided by operator response to
alarms or to the initiation of instrumented systems, including basic process control systems (BPCS) or
safety instrumented systems (SIS). In fact, until 1996, the American Society of Mechanical Engineers
(ASME) codes mandated the use of pressure relief devices for protection of pressure vessels.
However, in some applications, the use of pressure relief devices is impractical. Typical cases
include:
⢠Chemical reactions so fast the pressure propagation rate could result in loss of containment prior to the
relief device opening. Examples are āhot spots,ā decompositions, and internal detonation/fires;
⢠Chemical reactions so fast the lowest possible relieving rate yields impractically large vent areas;
⢠Exothermic reactions occurring at uncontrollable rates, resulting in a very high propagation rate for the
process pressure. (The pressure propagation rate for these reactions is often poorly understood.);
⢠Plugging, polymerization, or deposition formed during normal operation, which have historically partially
or completely blocked pressure relief devices;
⢠Reactive process chemicals relieved into lateral headers with polymerization and thus plugging,
rendering the relief device useless;
⢠Multi-phase venting, where actual vent rate is difficult to predict; and
⢠Pressure relief device installation creates additional hazards, due to its vent location.
In such applications, the installation of the pressure relief device provides minimum risk reduction.
Consequently, other methods of preventing overpressure must be utilized to achieve measurable risk
reduction.
Adding to the complexity, in many countries around the world, there is increased pressure from
community and regulatory authorities to reduce venting and combustion of gases. In these countries, it is
now unacceptable to flare large volumes of gas. The need to balance safety requirements and
environmental requirements has resulted in increased focus on using an alternative approach to pressure
protection.
Fortunately, API 521 and Code Case 2211 of ASME Section VIII, Division 1 and 2, provide an
alternative to pressure relief devices ā the use of an instrumented system to protect against overpressure.
When used, this instrumented system must meet or exceed the protection provided by the pressure relief
device. These instrumented systems are safety instrumented systems (SIS), since their failure can result in
the release of hazardous chemicals and/or the creation of unsafe working conditions. As SISs, they must
be designed according to the United States standard ANSI/ISA S84.01-1996 or the international standard
IEC 61511. The risk typically involved with overpressure protection results in the need for high SIS
integrity; therefore, these systems are often called High Integrity Pressure Protection Systems (HIPPS) or
High Integrity Protection Shutdowns (HIPS).
