Professional Documents
Culture Documents
TRICONEX
1
Definizioni
Safety
(Sicurezza)
2
TRICONEX Systems
Goal : Safety
Measurement: Reliability
3
Applications Areas
Safety/
Safety Availability
Availability
Industries ...
Oil & Gas Hydrocarbon Processing Utility
Pulp & Paper Marine Nuclear
Textile Rubber and Plastics Cement
Food Pharmaceutical Metals
Applications ...
Safety/ESD Burner Management Rotating
Equipment
Fire & Gas Automotive Presses Critical Control
4
Expertise in Major Safety and
Critical Control Areas:
TRI-SEN SYSTEMS TRICON TMR SYSTEMS
5
Markets Served
Chemical Manufacturing
11% 8% 3%
5% Petroleum Refining
Oil & Gas Production
26%
23%
Electric Power Utilities
24% Marine
Pulp & Paper
Other
6
Technology and Quality
TRICON TMR (Triplicated Modular Redundant) system
is viewed as the standard for safety and critical control
Triconex is the leading supplier of fault tolerant control
systems worldwide:
- Over 2 500 TMR and 4 200 Turbine Solutions installed worlwide
and over 500 in Europe and Africa
-62% market share (1996 Frost Sullican PLC study)
8
Safety Application Lifecycle
"FAIL SAFE"
MTTF MTTR
Spurious trips
t== few years
Startup phase
10
Strategy to become reliable
Avoid Failure
-Internal failures of the system (quality plan)
-Exploitation failures (Programming tools, diagnostics,
maintenance, training)
Support failures
-Electronic component failures
-Mechanical component failures
-No single point of failure
-Redundancy
-On line replacement
11
Dual Architectures
PLC
Process
Safety
Safety
Availability
Availability
12
23D Voting system
A B A Safety
B C C Availability
Majority state
13
TMR Architecture
No propagation
14
TRICON - TMR Fault Tolerant Controller
15
Triconex TMR vs. All Other PLC Technologies
1.1.No
NoSingle
SinglePoint
Pointof
ofFailure
Failure
2.2. Diagnostics
Diagnostics
3.3. On
On--Line
LineRepair
Repair
The Difference Between Long Term and Short Term
Availability and Reliability ---- Diagnostics
16
Fully Triplicated Architecture
Main TriBus
Input Output
Leg Processor I/O Bus Voter Actuators
Sensors Leg
B B
B
Main
TriBus
Processor
Input C Output
Leg I/O Bus Leg
C C
Output
Input Termination
Termination
- No propagation
- Supports 2 faults of different ranks
- Diagnostics are easy to manage 17
Version 9 High Density Main Chassis
L
N
1
NO
C
NC
L
N
2
NO
RC C
NC
POWER A MP B C COM L 2 R L 3 R L 4 R L 5 R L 6 R L 7 R
REMOTE
1 RUN
PROGRAM
A STOP
PASS PASS PASS
PASS
FAULT
PASS PASS
PASS PASS PASS
FAULT 4 4
5 5
ALARM
6 6 5 5
TEMP TX
RX 6 6
BATT LOW 7 7
B 8 8 7 7
2TX
2RX
9 9 8 8
10 10
11 11
12 12
13 13 3TX
NET 2 14 14 3RX
POWER MODULE 15 15
MODEL 8310
16 16
TX 17 17
RX
18 18
19 19 4TX
115/230 VAC
20 20 4RX
21 21
PASS
22 22
FAULT
ALARM 23 23
COM RX COM RX COM RX
TEMP 24 24
COM TX COM TX COM TX COMM
BATT LOW 9 9
TX 25 25
I/O RX I/O RX I/O RX
10 10 PRT
RX
C I/O TX I/O TX I/O TX 26 26
11 11
27 27
12 12
28 28
13 13
29 29
14 14
30 30
15 15
31 31
16 16
POWER MODULE EMP EMP EMP NCM 32 32 EICM
DIGITAL DIGITAL DIGITAL DIGITAL
MODEL 8310 3006 3006 3006 4329 INPUT INPUT OUTPUT OUTPUT 4119
3501E 3501E 3603B 3603B
D E F G H I J K L M N O P Q R S
18
Chassis - Architecture
ELCO Connectors for I/O Termination
Terminal
Strip Power
1 Terminal Strip
Terminal 1 2 3 4 5 6
Strip
2
TRIBUS
Power
Supply
1
DUAL
POWER
RAIL
Power
Supply Leg A
Leg B Comm
2 Bus
Leg C
Leg A
Leg B I/O
Leg C Bus
19
TRIBUS Hardware
20
TRIBUS Functions
Synchronizes MPs at the Beginning of Each Scan
21
Main Processor Module
32 Bit Microprocessor Operating at 25 MHz
Floating Point Co-Processor
1800 Kbytes of User Memory
I/O and Communication Co-Processors
Fault Tolerant Interprocessor Bus (TRIBUS)
Hardware Voting and Comparison Circuits
Supports the Collection of Sequence of Events (SOE) Data
Extensive Background Diagnostics
On-Line Replacement
22
Diagnostics - Hardware
Dual Failure
Power Vcc Detect Status Indicators
Regulators Circuitry
Main Processor
NS32GX32
512K EPROM Timing Interrupt Floating Point Processor
2MB SRAM Generator Controller NS32381
Internal System Bus
24
Fault Tolerant Power Subsystem
25
Diagnostics - Power Subsystem
Power supply #1
R A
E
- + G
Filter Converter Vdc
R
Rectifier
DC/DC E
G
NO
C Fault
NC Detection
R B
E
G
Power supply #2 R
Vdc
E
- + G
Filter Converter
DC/DC C
Rectifier R
E
NO G
C Fault
Detection Vdc
NC R
E
G
Fault
+V Bus 2
+V Bus 1
OV
27
Enhanced TMR Digital Input Module
28
Diagnostics - TMR EDI Module
29
EDI Module - Architecture
Input cicuit Individual opto-isolator Intelligent I/O CONTROLLERS Triplicated I/O BUS
Threshold
Detect Mux. Miicro- Bus A
Opto-isolator processor Xcvr
Opto-
short-circuit detection isolator
Dual
Port
RAM
Threshold
Detect Mux. Miicro- Bus B
Opto-isolator processor Xcvr
Opto-
isolator
Dual
Port
RAM
Threshold
Detect Mux. Miicro- Bus C
Opto-isolator processor Xcvr
Opto-
isolator
Dual
Port
RAM
30
TMR Analog Input Module
Triplicated A/D Converters and Multiplexors
On-Line Replacement
31
Diagnostics - TMR AI Module
32
TMR AI Module - Architecture
Mux.
+ Miicro- B
Amp ADC Bus Xcvr
- processor
Mux.
+ Miicro-
Amp ADC Bus Xcvr C
- processor
Mux.
33
TMR Enhanced Digital Output Module
Fault Tolerant Hardware Voter for Each Output Point
On-Line Replacement
34
Diagnostics - TMR EDO Module
35
TMR EDO Module : Architecture
B C
Output A et B
Drive
Circuitry * *
C Point
Bus Xcvr Miicro-
processor Register Load
C
Output
Drive
Circuitry Voltage
Loopback
* All output switches are opto-isolated detector -V
36
Supervised Digital Output Module
Fault Tolerant Hardware Voter for Each Output Point
Series / Parallel Quad Output Circuits
24 VDC Version Uses Smart FETs That Require No Fusing
No Single Point of Failure
Field Loopback Sensing
Latent Fault Detection
Fully Isolated Output Channels
Blown Fuse Detection
Line Monitoring of Field Load (Open or Short)
On-Line Replacement
37
Diagnostics - Supervised DO
Stuck-On and Stuck-Off Tests are Performed
Continuously
Both Tests Occur on All Output Circuits
Regardless of Power Status (NE or ND)
Output Circuits are Toggled, Voltage Loopback
Circuits Verify Proper Operation
Field Load Monitored by Use of Voltage Loopback
Circuits
If Output Switch is Found Faulty, MPs Vote to Energize Fault
LED and Generate a System Alarm
If Load is Missing, MPs Vote to Energize Load LED - Field
Device Failure, NOT TMR System Fault
38
SDO Module -Architecture
Triplicated Intelligent I/O Field circuitry
I/O Bus Controllers
Voltage
A Sensor
Dual
Ported B
RAM Output B A or B
Drive
* *
Miicro Circuitry
C Point Load
Bus Xcvr Processor Register
C
Dual Output
Ported
RAM
Drive
Circuitry
Voltage
Sensor -V
* All output switches are galvanically isolated
39
TMR Analog Output Module
Triplicated D/A Converters for Each of the 8 Output Points
2oo3 Selection Circuit Selects Correctly Operating DAC for
Each Point and Periodically Selects Each DAC to Check Its
Correct Operation
Loopback Checking of All Analog Output Channels
Automatic Calibration Using Built-in Reference Voltages
0.15% Full Scale Accuracy
No Single Point of Failure
On-Line Replacement
40
TMR Pulse Input Module
On-Line Replacement
41
TMR Thermocouple Input Module
On-Line Replacement
42
Typical Architecture
30 m max
RXM Chassis Expansion Chassis
Remote Room
P.S
1
P.S
1
up to 12 Kms
I/O I/O I/O I/O I/O I/O I/O I/O I/O
through Triplicated Fiber Optic
RXM
Rem.
P.S P.S
2 2
43
Communication Capabilities
ETHERNET 802.3
44
Communication Capabilities (cont..)
P.S P.S
1 1
NCM C PU
... Up to 10 Tricon systems
C PU I/O I/O EICM I/O I/O EICM NCM
P.S P.S
2 2
45
Triconex Communication Modules
Network Communication Module (NCM)
Supports Two IEEE 802.3 Ports
Intelligent Communications Module (EICM)
Four Isolated RS-232/ 422 Serial Ports (One Port Used for TriStation and
Others Typically Used for MODBUS Communication to DCSs and Other
Computer or SubSystems)
One Parallel Printer Port
Safety Manager Module (SMM)- Honeywell TDC 3000
Connects to TDC 3000 Universal Control Network (UCN)
Advanced Communication Module (ACM)- Foxboro I/A Series
Connects to Foxboro I/A Series Nodebus
Supports Additional 802.3 Port and Two RS-232/ 422 Serial Ports
46
Sequence of Events : SOE
SOE Utility through the
NCM Module
Printer
48
Raffineria di Priolo
Configurazione di rete Ethernet
ridondante, con connessioni rame-fibra CAVO IN RAME
ottica e Bridge per ottimizzazione del
traffico di rete CAVO COASSIALE IN
RAME
Node 6 Node 5
C FO
FO B C C B FO
Printer1_1 Printer2_1
C FO FO C C FO FO C
49