Professional Documents
Culture Documents
R&M Division
MOL Group
TECHNICAL SPECIFICATION
INSTRUMENTATION
MGS-S-REF-I-28
Rev 1.01.00
This document is property of MOL Group. The use is only allowed with the written permission of MOL Group.
SLOVNAFT a.s. MGS-S-REF-I-28
R&M Division
TECHNICAL SPECIFICATION - INSTRUMENTATION Rev.: 1.01.00
28 Requirements for Field-Installed Bus Systems Date: 01.05.2016
Page/Pages: 2/4
Release list
This document is property of MOL Group. The use is only allowed with the written permission of MOL Group
SLOVNAFT a.s. MGS-S-REF-I-28
R&M Division
Contents
Book breakdown
MOL Group
TECHNICAL SPECIFICATION
INSTRUMENTATION
MGS-S-REF-I-28.1
Rev 1.00.00
This document is property of MOL Group. The use is only allowed with the written permission of MOL Group.
SLOVNAFT a.s. MGS-S-REF-I-28.1
R&M Division
TECHNICAL SPECIFICATION - INSTRUMENTATION Rev.: 1.00.00
28 Requirements for Field-Installed Bus Systems Date: 30.11.2011
1 Requirements for Foundation Fieldbus Systems Page/Pages: 2/14
Release list
This document is property of MOL Group. The use is only allowed with the written permission of MOL Group
SLOVNAFT a.s. MGS-S-REF-I-28.1
R&M Division
Contents
1 General
In addition to systematizing bus-based field communication networks, this specification sets forth the basic design
requirements applicable to the field-installed bus network Foundation Fieldbus, to be observed during the
development of the functional specification. The technical implements of field bus networks are being developed at
a fast rate, requiring frequent revisions of this documentation.
In addition to observing this specification, system engineers shall also use the necessary reference books and
standards for design work.
1.1 Deviations
The applicable Project Specification may contain deviations from or changes to this document.
Deviations from the contents of this specification and the Project Specification shall be permissible only on the
basis of prior written approval by MOL Group.
The specified solutions shall be in conformance with the specification system, standards and requirements of the
applicable project documentation.
Point-to-point connection
Each segment contains only two devices. A safe and conservative, but uneconomic solution.
Spur topology
Individual spur lines connected to a trunk line. A topology used for installations in low density and lightly
congested units
Tree structure
Spur groups branch off from the trunk cable of the segment in junction boxes.
This design is recommended in cases of Retrofit installations, High density of fieldbus devices in a
particular area and High Speed Ethernet (HSE) is being used
„Daisy chain” topology
The segment (trunk) cable is connected in loops from device to device, not allowing on-line maintenance. A
design not applicable in refineries.
FFB coupler
A FOUNDATION fieldbus device coupler or isolated device coupler (where applicable) is located where the
trunk (home run) is connected to the various device spurs. It is typically the location of one of the
terminators (associated with a segment), and the location of spur short circuit protection.
Basic diagnostics
Failures caused by any field device, communication or controller (host) shall be brought to the attention of
the operator at the operator station and – upon its existence – facilities shall be available for forcing the
controller into manual mode in a configurable manner.
Advanced diagnostics
This shall provide for the on-line determination of device performances – such as accuracy of valve
positions, number of valve strokes, hysteresis, friction of valve stem seal gland, etc. – without the removal
of field devices.
Technological diagnostics
This is to monitor on-line the functioning of individual devices directly connected to process system.
Network/Segment Shorting: A shorted network/segment or power supply failure shall send valves to their
designated failure position, regardless of the device hosting the PID algorithm.
Transmitter Assignment: In normal practice the same segment shall include the transmitter of primary
process variable and its associated valve.
Multiple Process Variables: Multiple measurements used to provide a calculated differential shall be
assigned to a common segment with the differential calculation performed in one of the transmitters as they
typically have a lower „load‟ than an output device.
Redundant uninterrupted power supply of segments, suppression of electrical noises and over-voltages,
recovery of correct signal shapes by means of repeaters and termination elements.
Provision of redundant communication between the controller and the host system in order to ensure high
availability for operator control & intervention.
Short-circuit protection of segments and individual circuits.
Additional redundancy requirements (field application of LAS, use of redundant controllers, etc.) will be
defined in the applicable project specification.
Design philosophy of control function location shall be specified by designer in a Functional Design Study
or Project specification and shall be approved by Client.
The system shall provide for the simultaneous link-up and use of more than one engineering workstations.
The in-house program languages of suppliers shall not be used for the execution of control functions.
Data import & export: The host device & database shall provide configuration capabilities for importing and
exporting the data of function blocks and modules. The applicable import and export file format are: Microsoft
Excel, text, Microsoft Access, SQL.
The host device shall be capable of downloading data (function, scheduling, initialization) in the function block of
the respective FF element.
For safety reasons, the maintenance workstation and functions must be installed on separate servers but
made accessible from operator stations.
It shall indicate which elements are FF-based as well as the FF types implemented, software versions and
function blocks.
Descriptions of standard control functions
These shall include applicable parameters, descriptions of block operations, conditions of controlling
detected errors, failures and malfunctions.
The system of numbering cables (the cable schedule) will change, several devices will be connected by a
single cable, therefore segments numbers or segments descriptions should be used preferably for cable
identification.
c. Network/segment verification
Verify uniformity of software/firmware versions in host and FF devices.
Verify correctness & uniformity of software versions in H1 cards.
Check communication and macro-cycle periods of all segments.
Check correct functioning of segment elements (H1 cards, power supply units, signal conditioners, etc.)
and whether eventual failed elements are reported in the error log of the system.
Verify system recovery after segment shorting.
Measure current consumption of segments.
Verify operation of back-up LAS function.
MOL Group
TECHNICAL SPECIFICATION
INSTRUMENTATION
MGS-S-REF-I-28.2
Rev 1.00.00
This document is property of MOL Group. The use is only allowed with the written permission of MOL Group.
SLOVNAFT a. s. MGS-M-REF-I-28.2
R&M Division
TECHNICAL SPECIFICATION - INSTRUMENTATION Rev.: Rev 1.00.00
28 Requirements for Field-Installed Bus System Date: 01.05.2016
2 Wireless communication between field device and control system Page/Pages: 2/20
Release list
This document is property of MOL Group. The use is only allowed with the written permission of MOL Group.
SLOVNAFT a. s. MGS-M-REF-I-28.2
R&M Division
Contents
1 Overview
This specification addresses the design principles and best practices regarding the designing, secure
implementation, testing and operation of wireless industrial field communication networks based on the
industrial standards. This specification details the decision to use wireless field communication versus to
use traditional hard wired system. The wireless field device shall be only used for indication of process
variables on Integrated Control System (ICS) and to connect devices to Field Instrumentation
Maintenance System (FIMS) by using wireless connection. The wireless field device shall not be used
for control purpose and as any part of Safety Instrumented System.
The scope of this specification are wireless field devices based on ISA100, Wireless HART wireless field
communications and connected wireless network elements (Access Point, repeater, Gateways etc.) in
order to connect them to Integrated Control System (ICS). Other wireless technologies and application
exist (e.g. Mobile Worker, wireless remote video monitoring, wireless personnel tracking, asset tracking
etc.) that may be integrated into the ICS, but they are out of scope of this specification.
In addition to systematizing wireless field communication, this specification sets forth the basic design
requirements applicable to the wireless field-communications, to be observed during the development of
the functional specification.
2 Deviations
The applicable Project Specification may contain deviations from or changes to this document.
Deviations from the contents of this specification and the Project Specification shall be permissible only
on the basis of prior written approval by MOL PLC.
The specified solutions shall be in conformance with the specification system, standards and
requirements of the applicable project documentation.
4 Abbreviation
• AP: Access Point
• BER: Bit Error Rate
• CF: Capability File
• DD: Device Description
• EIRP: Equivalent Isotropic Radiated Power. Computed quantity which cannot be measured
directly. It is equal to the product of the total radiated antenna power multiplied by the antenna
gain.
• FIMS: Field device Maintenance System
• ICS: Integrated Control System
• ISA100.11a: ISA100.11a is a wireless sensor network protocol standard developed by the
International Society of Automation.
• ISM band: industrial, scientific and medical bands: 2.4 GHz band: 2.4000–2.4835 GHz and 5.8
GHz band: 5.725 to 5.875 GHz are supported range
• LOS: Line of Sight
• LR-WPAN: Low Rate-Wireless Personal Area Network
• PER: Packet Error Rate, PER (%) = Number of lost packets/Number of transmitted packets × 100
• QoS. Quality of Service
• RF: Radio Frequency
• RSS/RSSI: Received Signal Strength indicator is a measurement of the power present in a
received radio signal
• RSQI: Receive Signal Quality Index
• SNR: Signal-to-Noise Ratio (SNR = Received Power - Chanel Noise)
• TCO: Total Cost of Ownership
• Update Rate: The user specified interval at which a wireless field device (sensor, transmitter) will
detect a measurement and transmit the measurement to the Gateway (i.e. sample rate).
• Wi-Fi: Wireless Fidelity refers to wireless networks that use the IEEE 802.11 standard and
operates 2,4 GHz and 5 GHz bands.
• WISN: Wireless Industrial Sensor Network
• WLAN: Wireless Local Area Network
• WPN: Wireless Plant Network
Wireless communications
Wireless communication is the transfer of information over a distance without the use of electrical and/or
optical conductors (wires or fiber optic cables).
The industrial wireless communications shall support the one of the following ISM bands (applicable to
the wireless field network and wireless field devices):
2.4 GHz ISM (2.4 GHz radio band: 2.4000–2.4835 GHz supported range)
5 GHz ISM (5.8 GHz radio band: 5.725 to 5.875 GHz supported range)
Within the ISM band, 2.4GHz band and the 5 GHz band communications are used in the following
standards and supported in MOL Group Refineries:
Wireless Industrial Sensor Network (WISN): IEEE 802.15.4 is a selforganizing, selfhealing
mesh used in Low Power and Low Rate (250 kb/s).
The following standard and specification are supported in MOL Group Refineries:
• IEC/PAS-62734 (ISA 100.11a or ISA100 Wireless)
• IEC/PAS-62591(WirelessHART)
Wireless Plant Network (WPN): IEEE 802.11b/g/n (2,4 GHz WiFi) and IEEE 802.11a/na (5 GHz
WLAN) are used for a with higher transmission power level and with a higher data
communication rate.
Preconditions to use wireless field communication for connection of wireless field devices
Wireless field devices are not allowed to use for control purpose (closed control loop, PID
controller) and in a Safety Instrumented System.
The decision to use the wireless field device versus the traditional wired solution shall be based
on lifecycle cost analysis as results of Total Cost of Ownership (TCO) consideration with regard
to the applicability constrains.
TCO generally should consist the following of three life cycle phases for time period of 15 years:
• Procurement (C0: engineering & design, investment, deployment as implementation,
installation, integration, FAT, commissioning, SAT, documentation, training, initial spares etc.)
• Operations (Ki: general maintenance, repair, software/hardware upgrade, management of
change (MoC), backup, parts replacement (cards, battery), spare parts, HVAC (heating,
ventilating, and air conditioning), audit, training, cost of downtime, etc.)
Note: The wired solution should be calculated with 200 m multi-cable and 60 m individual cable.
The built in spare parts shall be 10 % and extendibility shall be 20 %.
TCO calculation form:
Where:
Cost of procurement
Cost of operation
n Last year of lifecycle
r Weighted Average Cost of Capital (WACC)
The Vendor shall attached the TCO calculation of wireless field communication solution and the
traditional wired solution in order to prove the proposed solution is reasonable.
Deviations from applying of TCO calculation for wireless field communication shall be permissible
only on the basis of prior written approval by MOL PLC or special requirements of Project
Specification.
The industrial wireless system consists wireless field device using WISN and WPN which can be:
• Wireless field device (wireless sensor, transmitter, adapter, repeater)
• Wireless network component (wireless Access Point/ Gateway)
The WISN shall be a self-configuring and self-healing mesh network.
The WISN shall support a mix of wireless field device types and update rates.
The WISN and WPN architecture shall be capable of supporting both wireless and wired media to
connect the wireless network to the wired network (e.g. Process Control Network).
The industrial wireless network architecture shall have an IP-compatible network layer and
support for tunneling, i.e., transporting other protocols through the wireless network
The industrial wireless network architecture shall support the system management of all wired
and wireless communication devices
The infrastructure of industrial wireless network shall be scalable and support the following
topologies:
• Point to Point
• Star
• Redundant Star
• Mesh
• Star-Mesh (combination of star and mesh wireless segment)
• Infrastructure Mesh (combination of the WISN and WPN as backbone/backhaul network to
provide a plant-wide coverage.)
The infrastructure of industrial wireless network to be deployed shall support at minimum the
following wireless networks:
• Wireless Industrial Sensor Network based on:
ISA 100.11a or ISA 100 Wireless
WirelessHART)
• Wireless Plant Network based on:
IEEE 802.11b/g/n (2,4 GHz WLAN)
IEEE 802.11a/na (5 GHz WLAN)
The infrastructure of industrial wireless network shall be easily extensible: a new wireless device
can automatically join the network. Automatic device joining and network formation enables
system configuration with minimal need for personnel with specialized radio frequency (RF) skills
or tools.
Self-organizing network shall support the redundant communications from wireless field device to
Host system (ICS with redundant Process Control Network connection) via redundant Access
Point and redundant Gateway.
The industrial wireless network shall support a minimum of 2000 industrial wireless devices
operating at a minimum average update rate of 10 seconds using sufficient number of Access
Points and Gateways to connect to Host System.
The industrial wireless network shall support wireless devices (wireless sensor, transmitters)
operating at update rates of 1 second as minimum, but as additional feature of configuring the
same at update rates from1, 5, 10, 30 or 60 seconds to one hour shall also be available.
The industrial wireless network architecture shall be secure, including data integrity, encryption,
data authenticity, replay protection, and delay protection
8 Security requirements
Mechanisms for protecting the industrial wireless network shall be implemented.
• Encryption: Data communicator shall have least 128-bit encryption.
• Authentication: Only wireless field devices authenticated by the System Manager and/or
Security Manager can join and exchange data.
• Integrity: End-to-end basis data integrity and transport security shall be provided.
Key Management: All wireless devices shall have a join key that acts as a password that the
device uses to authenticate it to the network.
Wireless (RF) Site Survey’s with spectrum scans shall be performed before RF design of wireless
network in order to reveal problems such as interference (e.g. by radar), obstructions.
The RF bands with the assigned channel (frequency channel hopping pattern) to be used shall be
verified and approved by the MOL.
The new industrial wireless networks shall be designed to coexist with other existing wireless
networks. Strong interference sources must be addressed (removed, avoided, or minimized)
before the installation.
To determine RF power level settings according to the location of deployment with regards
allowed maximum EIRP according to NCA’s regulations.
Coexisting capability (e.g. channel-hopping, DSSS: direct-sequence, spread spectrum, low
transmit power) with other RF sources using ISM radio band shall be taken into account.
Where surge protection is deemed necessary (e.g. location of AP with areas of high lightning
incidence, or where large inductive loads are started and stopped), surge protection should be
provided.
Online download of a software upgrade to a wireless field device from a Host System (ICS) shall
be supported.
If the wireless field device is located in a hazardous area, the wireless field device shall have the
appropriate approvals (e.g. ATEX: Class I, Zone 2; Ex nA IIC T4 or Ex ia IIC T4 ).
The wireless field devices shall be housed in a rugged aluminum-alloy casing that meets IP 66
and certification.
The wireless field device shall be rated to operate under the following conditions:
• Operating Temperature: -40° to +75°C
• Transportation and Storage Temperature: -40° to +7 5° C
• Operating Humidity: 0-100% non-condensing
The participation of the representatives of the Client shall not in any way release the system
Vendor from their guarantee responsibilities regarding material quality, installation, production
and operability.
The vendor shall remove or disable all software artifacts that are not required for the operation
and maintenance of the device prior to the Factory Acceptance Test (FAT).
The Vendor shall ensure that the systems have had a minimum of a 48-hour burn-in.
The Vendor shall perform an interference rejection test and supply the results with an explanation
of the results.
The vendor shall verify compatibility of the wireless field device with other devices with which the
device must interface.
To add one of each type of wireless field device to the network and verify proper connectivity.
To perform sensitivity test: The wireless field device should be separated in which the received
signal strength (RSS) at the receiver is at its minimum while packet error rate (PER) remains at
0%. The IEEE 802.15.4 standard specifies that a compliant device shall be capable of achieving
a sensitivity of -85 dBm or better.
To verify connectivity between the wireless Gateway and the host system (ICS) application and
an integration test shall be carried out.
To test in dense highly radio reflective environments in order to prove the wireless connectivity
the reliability and immunity to reflection.
To perform coexistence test operating on the unlicensed 2.4 GHz ISM band in a coexistence
environment with several kind of wireless devices (eg. cell phones, Wireless handheld
computers, Wireless local area networks (802.11.a/b/g/ac), 802.15.1 (Bluetooth), Zigbee, RF
Identification (RFID) bar code readers etc.
16 Appendix:
Appendix A.: Check list of SAT
NOT
Item Description OK Note
OK
1. Check the Wireless Gateway
1.1 Identification Check:
Wireless Gateway Tag:
Description:
Wireless Network ID:
Join key (x-x-x-x):Type:
NOT
Item Description OK Note
OK
SNR: dB or
RSQI: No/Poor/Fair/Good/Excellent
Transmit Fail Ratio (TxFailRatio):
Bit Error Rate (BER):
Packet Error Rate (PER):
RF Chanel Configuration Check:
Routing: (Enabled/Disabled)
Maximum Hops:
Enabled Channel:
11 / 12 / 13 / 14 / 15 / 16 / 17 / 18 / 19 / 20 / 21 / 22 / 23 / 24 / 25
NOT
Item Description OK Note
OK
• OP Low limit:
• OP Rate of Change limit:
3.6 Commissioning of wireless field device to AP and Gateway
3.7 Connectivity Status Check: on-line
Antenna Type (Omnidirection/High Gain/Directional)
Operating Frequency (GHz):
Connection Type (Direct/Routed):
If Routed, Number of Available Neighbors:
RSSI: dBm
SNR: dB or
RSQI: No/Poor/Fair/Good/Excellent
Transmit Fail Ratio (TxFailRatio):
Bit Error Rate (BER):
Packet Error Rate (PER):
RSSI threshold: dBm
High PER threshold: %
Low Battery threshold: days
3.8 Channel status Check: on-line
Offline/Inactive/OOS/Auto/Manual
Update Rate (sec/min):
3.9 I/O Check: on-line
Type:
Number of Leads (2/3/4/-wire):
Engineering Unit:
Scale Low:
Scale High:
PV 0%: EU
PV 50% EU
PV100% EU
AO 0% mA
AO 50% mA
AO 100% mA
3.10 Process Alarm Check: on-line
PV LoLo: Deadband: Priority:
PV Lo: Deadband: Priority:
PV Hi: Deadband: Priority:
PV HiHi: Deadband: Priority:
3.11 Security Check:
Setup and/or review the Write Protect setting
4. Check the HMI and Faceplate
4.1 Check the existence of the primary associated HMI display. on-line
Call the primary associated HMI display.
Name of the primary associated HMI display:
4.2 Dynamo indication check: on-line
Check the dynamo on the operator interface related to wireless field
device.
Check the dynamo field on the graphic HMI display
Check the alarm coding of dynamo on graphic HMI display
4.3 Faceplate indication check on-line
Check that information on the faceplate matches the wireless
module data detailed in the FDS
Call the faceplate from the related Dynamo element
Check the displayed information of faceplate
• Tagname
• Description
• PV
• PV Scale
• Alarm indication
• Unit name
NOT
Item Description OK Note
OK
Check the operation with the faceplate
Check the Navigation from the faceplate
• Primary associated HMI display
• Detail display
• Alarm display + alarm acknowledgement function
• Trend display
Detail display check on-line
Call the faceplate and navigate to the related Detail picture
On the Detail picture change the high and low alarm limits and
enable or disable alarms
Module functionality check on-line
Check the module properties and functions according to the FDS
requirements
• Simulate PV and check the actions
• Simulate BAD_PV and check the actions