Method and apparatus for configuring a blackout period for scheduled diagnostic checks of a field device in a process plant.
Abstract
A diagnostic system and method for a field device in a process plant is provided. The diagnostic apparatus includes a processor operatively connected to the field device and a calendar having a proscribed period stored in memory. A diagnostic check is executed on the field device if an occurrence of a diagnostic event is detected and execution of the diagnostic check does not coincide with the proscribed period.

Term
6.6 yearsleft in the term
Expires 9 May 2033.
- Priority
- Filed
- Granted
- Today
- Expires
17 claims: 3 independent, 14 dependent
- 1CLAIMS REIVINDICACIONES IMPI IMPI INSTTTIITO MEXICAN ·. □ Ε the ranneoAP INtWSTUIAl. INSTTTIITO MEXICAN·. □Ε la ranneoAP INtWSTUIAl. 1. Un método para controlar un aparato de campo en un sistema de control, caracterizado porque comprende:one. A method of controlling a field apparatus in a control system, characterized in that it comprises: proporcionar un dispositivo de memoria que incluye al menos un período establecido;providing a memory device that includes at least one set period;supervisar, a través de un procesador, el dispositivo de campo;supervise, through a processor, the field device;detectar, a través de un procesador, la ocurrencia de un evento de diagnóstico asociado con el dispositivo de campo;detecting, through a processor, the occurrence of a diagnostic event associated with the field device;formular, a través de un procesador, una comprobación de diagnóstico del dispositivo de campo en respuesta a la ocurrencia del evento de diagnóstico;formulating, through a processor, a diagnostic check of the field device in response to the occurrence of the diagnostic event;determinar, a través de un procesador, si la ejecución de la comprobación de diagnóstico se producirá durante el al menos un período establecido;determine, through a processor, whether the diagnostic check will run for at least a set period;ejecutar, a través de un procesador, la comprobación de diagnóstico si no se producirá la comprobación de diagnóstico durante el al menos un periodo establecido;y reprogramar, a través de un procesador, la ejecución de la comprobación de diagnóstico si se producirá la comprobación de diagnóstico durante el al menos un periodo establecido. run, through a processor, the diagnostic check if the diagnostic check will not occur for at least a set period;and reprogramming, through a processor, the execution of the diagnostic check if the diagnostic check will occur during the at least a set period.
- 7A diagnostic apparatus for a qqe control system has a controller operatively connected to a field device, characterized in that it comprises:7. Un aparato de diagnóstico para un sistema de control qqe tiene un controlador conectado operativamente a un dispositivo de campo, caracterizado porque comprende: a processor operatively connected to the field device to detect the occurrence of a diagnostic event;un procesador conectado operativamente al dispositivo de campo para detectar la ocurrencia de un evento de diagnóstico;a memory operatively connected to the processor;a calendar stored in memory, the calendar includes a set period when running a diagnostic check is prohibited;and, _____ a diagnostic module stored in memory, while processor j controls the diagnostic module if it is detected una memoria conectada operativamente al procesador;un calendario almacenado en la memoria, el calendario incluye un período establecido cuando se prohíbe la ejecución de una comprobación de diagnóstico;y, _____ un módulo de diagnóstico almacenado en la memoria, en tanto el procesador j cuta el módulo de diagnóstico si se detecta ΙΜΡΙ ^> ΙΜΡΙ^> instituto mexicano mexican institute I HEARD THE RROFUDají industrial the occurrence of the diagnostic event and the execution of the diagnostic module does not coincide with the established period, and the processor reprograms the execution of the diagnostic module if the occurrence of the diagnostic event is detected and the OÍ LA RROFUDají industrial la ocurrencia del evento de diagnóstico y la ejecución del módulo de diagnóstico no coincide con el período establecido, y el procesador reprograma la ejecución del módulo de diagnóstico si la ocurrencia del evento de diagnóstico es detectado y la 5 Execution of the diagnostic module coincides with the established period. 5 ejecución del módulo de diagnóstico coincide con el periodo establecido.
- 16A computer-readable medium whose contents cause a computer system to monitor an occurrence of a diagnostic event and reprogram an action in response to the occurrence of the diagnostic event using a method that comprises the steps of:16. Un medio legible por computadora cwyos contenidos ocasionan que un sistema de computadora supervise una ocurrencia de un evento de diagnóstico y reprograme una acción en respuesta a la ocurrencia del evento de diagnóstico por medio de un método que comprende los pasos de: monitor an occurrence of a diagnostic event associated with a field device;supervisar una ocurrencia de un evento de diagnóstico asociado a un dispositivo de campo;detect the occurrence of the diagnostic event;detectar la ocurrencia del evento de diagnóstico;formular una acción de respuesta a la ocurrencia del evento de diagnóstico;formulate a response action to the occurrence of the diagnostic event;determinar si la ejecución de la acción tendrá lugar durante un período establecido;determine if the execution of the action will take place during a set period;ejecutar la acción si la ejecución de la acción no ocurre durante el periodo establecido;y reprogramar la acción si la ejecución de la acción ocurre durante el periodo establecido. execute the action if the execution of the action does not occur during the established period;and reschedule the action if the execution of the action occurs during the established period.
Independent claims3
162 paragraphs in 28 sections, as filed
(54) Title: METHOD AND APPARATUS FOR CONFIGURING A PROHIBITION PERIOD FOR SCHEDULED DIAGNOSTIC CONTROLS OF A FIELD DEVICE IN A PROCESSING PLANT.
(54) Title: METHOD AND APPARATUS FOR CONFIGURING A BLACKOUT PERIOD FOR SCHEDULED DIAGNOSTIC CHECKS OF A FIELD DEVICE IN A PROCESS PLANT.
(57) Summary
A diagnostic system and method is provided for a field device in a processing plant. The diagnostic apparatus includes a processor operatively connected to the field device and a calendar that has a prohibited period stored in memory. A diagnostic check runs on the field device if the occurrence of a diagnostic event is detected and the execution of the diagnostic check does not match the prohibited period.
(57) Abstract
A diagnostic system and method for a field device in a process plant is provided. The diagnostic apparatus ineludes a processor operatively connected to the field device and a calendar having a proscribed period stored in memory. A diagnostic check is executed on the field device if an occurrence of a diagnostic event is detected and execution of the diagnostic check does not coincide with the proscribed period.
'Κ
I KNOW
Institute
Mexican Property
Industrial
StCRETARU Ot ΗΧΜΟΜί *
PATENT TITLE NO. 338959
Headlines):
Home:
Denomination:
FISHER CONTROLS INTERNATIONAL LLC
205 South Center Street, Marshalltown, Iowa, 50158, USA
METHOD AND APPARATUS FOR CONFIGURING A PROHIBITION PERIOD FOR SCHEDULED DIAGNOSTIC CONTROLS OF A FIELD DEVICE IN A PROCESSING PLANT.
Classification: lnt.CI.8: G05B15 / 02; G05B23 / 00; G05B9 / 02
V, 'Y<sup>-</sup>
FFR
<img file="MX338959B_D0001.tif" />
<img file="MX338959B_D0002.tif" />
Number:
MX / a / 2014 / 013f35
<img file="MX338959B_D0003.tif" />
icia: Twenty-one i Date of Vene ηίβηφ: 9 i Reference patent if Jtorga cotefundame.
In accordance with article 23 of | starting from the date of the rights.
Luien subscribes to the present | Industrial Property (Diari> / 01/2004, 06/16/2005, 2
ICITUD Presentation date intemactMMh May 9, 2013
PRIORITY
Date:
May 2012
13 / 467,651 i P ntaclón Law of *
<img file="MX338959B_D0004.tif" />
or of 2033 articles 1st, 2nd fraction V, 6th fraction III, and 58 of the Irüdustrlal Property Law.
The present patent has a valid term of twenty years, and will be subject to the payment of the fee to keep the BCEs with funding from the Federation (D.CT 6/05 / 2009,06 / 01/2010,
Iciso a), sub clause iii) 4φ 12 ° tragones I and lll of the Regulation «formed on 07/01/2002, 'and 7 ° bis 2 of the law of 1/1996, 12/26/1997, 1W05 / 1999 , i / 2012); articles 1, 3 lacclón V 'industrial integrity (DOF 1 | / action V Clause a), sub clause iii), 16 fraction
112/1999, ilyllly
107/2004,
3 ° and t> 'subsection a) and antepenultimate paragraph of the Agreement that delegates powers to the Assistant General Directors, Coordinator, Divisional Directors, Head of the Regional Offices, Divisional Deputy Directors, Departmental Coordinators and other subordinates of the Mexican Institute of Industrial Property. (DOF 12/15/1999, amended on 02/04/2000, 07/29/2004, 08/04/2004 and 09/13/2007). ·>.
'07 / 2004> 07/08/2004 and 09/07/2007); articles 1, 3<sup>to</sup>?
»<sup>the</sup> subsection a) and antepenultimate kennel of the Agreement that delegates facültade
Issue Date: May 6, 2016
DIVISIONAL DEPUTY DIRECTOR OF EXAMINATION OF PATENT FUND, MECHANICAL, ELECTRICAL AREA AND REGISTRY OF INDUSTRIAL DESIGNS AND
<img file="MX338959B_D0005.tif" />
Arenal No. 550, Floor 1<sub>;</sub> 'oi. Pueblo Santa María Tepepan,
XOChirTilCO, CP 15020,
Mexico City
Tei (55) 53 34 07 00 www.impiqop.mx
<img file="MX338959B_D0006.tif" />
<img file="MX338959B_D0007.tif" />
MX / 2016Z35027
-/ 3
IMPÍAS I instituted υ Msxrozíi · in the rROPinvtL 'NOVSWal
METHOD AND APPARATUS TO CONFIGURE A PERIOD OF
PROHIBITION FOR PROGRAMMED CONTROLS OF
DIAGNOSIS OF A FIELD DEVICE IN A
PROCESSING PLANT
Field of the Invention
The present invention relates generally to diagnostic controls of field devices in a processing plant, and more particularly to a method and apparatus for prohibiting the execution of automatically scheduled diagnostic checks on field devices during prohibited periods.
Background of the Invention
Process control systems and safety instrumented systems (SIS) typically include one or more controllers connected to one or more field devices via a communication bus. Controllers in each of these systems use field devices to perform a variety of control functions in the control environment. For example, field devices can be used to open or close valves, increase or decrease fluid flow, and parameters of the measurement process, such as temperature, pressure, the rate of fluid flow. The maintenance of the process control system and the SIS of a processing plant is a continuous process that included the control of the
<img file="MX338959B_D0008.tif" />
<sup>2</sup> IMPI
MEXICAN INSTITUTE
I heard LA MOHEDA ·
INDIVIDUAL Operation of field devices, periodically test field devices, and repair or replace field devices as necessary. To maintain the performance of the field device, plant personnel may periodically perform a diagnostic check on the field device. The diagnostic check can also be automatically scheduled or executed by the process control system, SIS, or field device in response to the occurrence of a predetermined diagnostic event that is used as a trigger event. The predetermined diagnostic event is typically associated with the field device and may comprise the field device reaching a predetermined time limit of operational use, or the inability of a component of the field device to reach a specified position, for example.
A particular field device used in a SIS to maintain the safe operation of a process control system is the closure of an emergency valve (ESD). In an implementation example, the ESD valve is an actuated valve designed to stop the flow of a fluid in detecting a hazardous event. Because the ESD valve is normally in the open position, the accumulation of foreign substances can cause it to stick or the actuation mechanism of the ESD valve to stop working, preventing the ESD valve from operating properly in a
IMPI Mexican INSTITUTE OF LA mOFIlDAÍ,
INDUSTRIAL emergency situation. However, initialization of the ESD valve completely to check its overall operability is not feasible since complete closure of the valve will essentially involve shutting down the process control system.
A partial stroke test (PST) is a standard automated diagnostic check commonly used by plant personnel to test a percentage of possible ESD valve failure modes without having to completely close the valve. To carry out the PST, an actuator is activated to partially close the ESD valve, typically moving the valve approximately 30% of a full stroke. Thereafter, the ESD valve is returned to its fully open state. By moving the ESD valve as far as the process would safely allow, the PST can diagnose ESD valve performance problems without interrupting the control process. Regular use of the gen ral PST provides for longer intervals between full stroke tests (which require plant deactivation), reducing plant downtime. Therefore, the PST is considered a sufficient test to exercise the ESD valve during use, thus guaranteeing its correct operation.
There are, however, some valid concerns with using automated PST. A major concern is the time at which I PST is eventually met, about
<img file="MX338959B_D0009.tif" />
<img file="MX338959B_D0010.tif" />
everything in what r sp cta
IMPI
MEXICAN INSTITUTE Γ>! LA ΜΟΜΒΟΑΓ INDUSTRIAL automatically scheduled events, such as in response to the occurrence of a diagnostic event. The diagnostic event can correspond to a time or an event. For example, the diagnostic event may refer to a certain time, for example, every Monday at 3:00 p.m., or the diagnostic event may refer to a particular event, such as reaching a preset limit of operating hours or reaching a preset amount of time since the last ESD valve PST was performed. Therefore, because the timing of a diagnostic event may not always be known, the timing of a PST running in response to the occurrence of a diagnostic event may not be known. This lack of certainty can present a problem to plant personnel if the PST is performed during a time when plant personnel are unable to attend the test or cannot respond to an adverse PST result. For example, if a problem arises during an automatic PST off-shift or on a holiday, fewer plant staff may be available to respond if necessary, which can have a serious negative impact on plant productivity and staff safety.
There may also be times when the occurrence of a diagnostic event may not be relevant and therefore a response action may be incessant. For example, the
<img file="MX338959B_D0011.tif" />
ΙΜΡΙ
Detection of the position of a valve outside of a desired range can usually be reported to plant personnel in accordance with defined protocols. However, if such variation occurs during plant startup when the control system is incompletely configured, automatically reporting the variation in this case can be a distraction for plant personnel. It is during commissioning operations, for example, that disabling the reporting of a fact from a diagnostic event might be convenient and beneficial for plant personnel.
While there are benefits to automatically running a diagnostic check in response to detecting the occurrence of a diagnostic event, it is possible that the automated diagnostic check may adversely affect the operation of the control system. Because automated diagnostic controls can occur at undetermined times and perhaps without much notice, which can negatively affect the sense of staff control over the management of the plant control system, plant personnel can therefore prefer not to use diagnostic controls and automated tests in some cases.
Brief Description of the Invention
Apparatus and methods are described to improve the operational control of a plant. In an implemented dj mplo method
<img file="MX338959B_D0012.tif" />
IMPI
INSTITUTO MEXICA NO Oí LA RRORIEJAL) provides a period-prohibited device, monitors the occurrence of an event on a computer, the memory method that includes at least one field device, and detects diagnosis associated with the field device. The method formulates a diagnostic check of the field device in response to the occurrence of the diagnostic event and determines whether running the diagnostic check will occur for at least a prohibited period. The method includes executing a first command if the diagnostic check will not occur during the at least one prohibited period, and executing a second command if the diagnostic check will occur during the at least one prohibited period.
If desired, commands executed by the example method may include: running a diagnostic check of the field device, rescheduling the running of the diagnostic check, and / or circumventing the running of a diagnostic check. The method may further include transmitting an alert associated with the first command to a workstation and / or receiving a calendar including the at least one prohibited period on the memory device.
In a further exemplary embodiment relating to a diagnostic apparatus for a control system having a controller operatively connected to a field device,
<img file="MX338959B_D0013.tif" />
<sup>7</sup> IMPI
Mexican INSTITUTE
OF INDUSTRIAL PROPERTY
The diagnostic apparatus includes a processor operatively attached to the field device to detect the occurrence of a diagnostic event. The apparatus includes a memory operatively connected to the processor and a calendar stored in the memory. The calendar includes a prohibited period when the execution of a diagnostic check is prohibited. The apparatus includes a diagnostic module stored in memory, in which the processor executes the diagnostic module if the occurrence of the diagnostic event is detected and the execution of the diagnostic module does not coincide with the prohibited period.
In another embodiment, a tangible non-transient computer-readable medium includes stored instructions that, when executed by one or more processors, cause one or more processors to monitor an occurrence of a diagnostic event associated with a field device, detect the occurrence of the diagnostic event, formulate a response action to the occurrence of the diagnostic event, determine whether the action will take place during a prohibited period, and issue a command in response to determining whether the action will take place during the prohibited period.
Brief Description of Drawings
Figure 1 is a block diagram of an example of a processing plant that has a process control system and a
IMPI
MEXICAN INSTITUTE OF THE KROPltDAL · INDUSTRIAL
<img file="MX338959B_D0014.tif" />
execution of a module action or flow diagram of additional itrol to the security system system;
Figure 2 is an illustration of you have prohibited response periods.
Figure 3 illustrates an example of a process to provide a control that is illustrated in Figure 1.
Figure 4 illustrates an example of a process flow diagram or module to provide additional control to the control system illustrated in Figure 1.
Detailed description of the invention
Referring now to Figure 1, a processing plant 10 includes a process control system 12 integrated with a security system 14 (shown in dotted lines 15) that generally operates as a security instrumented system (SIS). The security system 14 controls the operation of the process control system 12 to ensure the safe operation of the processing plant 10. If necessary, the security system 14 can override the control of the process control system 12.
Processing plant 10 also includes one or more host workstations 16 or computing devices that have a user interface (can be any type of personal computer, workstation, etc.) that are accessible by plant personnel. . In the illustrated example n
ΙΜΡΪ
BMSTITUTO MEXICANO Pí LA RkOPlíQAD INOOSWAL
<img file="MX338959B_D0015.tif" />
Figure 1 shows two workstations 16 connected to a process control / safety control node 18 and a memory device 20 through a common communication line or bus 22. Communication bus 22 can be implemented using any desired bus-based or non-bus-based hardware, using any desired wired or wireless communication structure, and using any desired or suitable communication protocol, such as an Ethernet protocol.
In general, the processing plant 10 includes both the process control system devices and the security system devices operatively connected to each other through the bus structure that can be provided on a printed circuit board 26 where connect the different process controllers and input / output devices. The processing plant 10 illustrated in Figure 1 includes at least one process controller 24, as well as one or more input / output (I / O) devices of the process control system 28, 30, 32. Each of the process control system I / O devices 28, 30, 32 is connected to a set of field devices related to process control, which is illustrated in Figure 1 as the field devices 40, 42. Process controller 24, I / O devices 28, 30, 32, and field devices of controller 40, 42 generally constitute the control system 12 of Figure 1.
IMPI
INSTITUTO MÍX4CANO OF LA PROfft £> A¿>
INDUSTRIAL
<img file="MX338959B_D0016.tif" />
Process controller 24, which may be, by way of example only, a DeltaV ™ controller marketed by Emerson Process Management or any other desired type of process controller, is programmed to provide process control functionality using E devices. / S 28, 30, 32 and field devices 40, 42. In particular, controller 24 implements or monitors one or more process control modules or routines stored in memory therein or otherwise associated therewith and communicates with field devices 40 and 42 and workstations 16 for controlling the processing plant 10 or a portion of the processing plant 10 in any desired manner.
Control routines 46, which can be control modules or any part of a control procedure such as a subroutine, parts of a subroutine (such as lines of code), etc., can be implemented in any desired software format, such as using ladder logic, sequential function graphs, control routine diagrams, object-oriented programming, or any other software programming language or design paradigm. Similarly, the control routines described in this document may be encoded in, for example, one or more EPROM memories, EEPROMs, Application Specific Integrated Circuits (ASICs), PLCs, or any other hardware or firmware item. The
ΙΜΡΙ
MEXICAN INSTITUTE DS THE PROPERTY
INDUSTRIAL
<img file="MX338959B_D0017.tif" />
Control routines can be designed using design tools, including graphic design tools or any other type of programming in software / hardware / firmware or design tools.
Controller 24 may be configured to implement a control routine or control strategy in any desired manner. For example, controller 24 can implement a control strategy using what is commonly known as function blocks, where each function block is a part or object of a general control routine and operates in conjunction with other function blocks. (through communications called links) to implement process control loops in the process control system 12. Function blocks typically carry out: an input function such as that associated with a transmitter, sensor, or other process parameter measurement device;
a control function such as that associated with a control routine that executes PID, fuzzy logic, etc. of control; or, an output function that controls the operation of some device such as a valve to perform some physical function within the process control system 12. There may also be hybrids of these function blocks, as well as other types of function blocks. Although the description of the control system is provided in this document with the use of a function block control strategy that incorporates
IΜ ΡI
MSXICAN INSTITUTE
OR LA RRORIEDAO <sup>62</sup>
..., INDUSTRIAL _ an object-oriented programming paradigm, the control strategy or control routines or control loops or er control modules could also be implemented or designed using other conventions, such as ladder logic, graphs of sequential functions, etc., or through any other programming language or paradigm that is desired.
Function blocks and control routines can be stored and executed in controller 24, which is typically the case when these function blocks are used for, or associated with, standard 4-20 ma devices and some types of smart field, such as HART devices. Function blocks and control routines can also be stored and executed by the field devices themselves, which may be the case with Fieldbus devices.
For the purposes of this description, the terms control strategy, control routine, control module, control function block, security module, security logic module, and control loop essentially denote a control program executed to control the process and these terms can be used interchangeably in this document. However, for the purposes of the following discussion, the term module will be used. Furthermore, it should be noted that the module described in this document may have its parts implemented or executed by different controllers or other devices if so provided.
IMPI
MEXICAN INSTITUTE OF LA, PRÜPIE »AD INDUSTRIAL
<img file="MX338959B_D0018.tif" />
Furthermore, the modules described in this memory to be executed in the process control system 12 and the security system 14 can take any form, including software, firmware, hardware, and any combination thereof.
Field devices 40, 42 can be of any desired type, such as sensors, valves, transmitters, positioners, etc., and can conform to open, proprietary, or other communication or programming protocol, including, for example, the HART or 4-20 ma protocol (as indicated in field devices 40), any bus protocol such as the Foundation Fleldbus ® protocol (as indicated in field devices 42), or CAN protocols, Profibus and AS-Interface, to name a few. Similarly, each of the I / O devices 28, 30, 32 can be any known type of I / O process control device using any appropriate communication protocol.
Processing plant 10 also includes one or more security system logic solvers 50, 52. Each of the logic solvers 50, 52 is a security controller (also called an I / O device) having a processor 54 running the security logic modules stored in the memory 58 and is connected to provide control signals and / or receive the signals from the field devices of the security system 60, 62. The
<img file="MX338959B_D0019.tif" />
<sup>INST</sup>'TJJTO maid <sup>1</sup><sup>O |</sup>·. the «ο,<sub>Ι £</sub>„<sub>Αυ</sub> > ^ * "GSá3" J industrial safety controllers 50, 52 and field devices of the safety system 60, 62 generally constitute the safety system 14 of Figure 1.
Security field devices 60, 62 can be any desired type of field device that adapts to or uses any known or desired communication protocol, such as those mentioned above. In particular, the field devices 60, 62 may be safety related field devices of the type conventionally controlled by an independent dedicated safety related control system, such as an emergency stop valve (ESD). In the processing plant 10 qu illustrated in Figure 1, the security field devices 60 are represented with the use of a dedicated or point-to-point communication protocol, such as the HART protocol or the 4-20 ma protocol, while security field devices 62 are illustrated with the use of a bus communication protocol, such as a Fieldbus protocol. In general, safety devices (both controllers 50, 52 and field devices of safety system 60, 62) that are used as part of safety system 14 are classified as safety devices, which generally means that these Devices must go through a classification procedure to be classified by an appropriate body as a safety device.
IMPI
INSTITUTO MEXICAN »i OE LA rftOMEUAJ
INDUSTRIAL
<img file="MX338959B_D0020.tif" />
Printed circuit board 26 (indicated by a broken line through process controller 24, I / O devices 28, 30, 32, and safety controllers 50, 52) is used to connect the process controller 24 to process control I / O cards 28, 30, 32, as well as safety controllers 50, 52. Process controller 24 is also connected to bus 22 and operates as a bus arbiter to allow each of I / O devices 28, 30, 32 and safety controllers 50, 52 to communicate with either station. 16 through bus 22. The printed circuit board 26 allows the security controllers 50, 52 to communicate with each other and coordinate the security functions implemented by each of these devices, to communicate data with each other, or to perform other integrated functions.
Each of the workstations 16 includes a workstation processor 34 and a memory 36 that can store applications or modules adapted to be run by any of the processors 24, 34, 50, 52 within the processing plant 10.
A display application 44 is illustrated in an enlarged view of Figure 1 as stored in memory 36 of one of the workstations 16. However, if desired, display application 44 can be stored and run on one station working different than 16 or on another device
IMPI
MEXICAN INSTITUTE OF PROPERTY
INDUSTRIAL
<img file="MX338959B_D0021.tif" />
computer associated with the processing plant 10. The display application 44 can be any type of interface that, for example, allows a user to manipulate the data values (for example, read or write) in order to thereby alter operation. of control modules 46 or security 58 within control system 12 and / or security system 14. Therefore, if a write operation is specified in the control module 46 associated with the control system 12 or in one of the field devices 42, for example, the display application 44 that allows writing. On the other hand, if the write operation is specified in the security logic module 58 associated with the security system 14 or in one of the field devices 62, for example, the display application 44 that allows writing, is Una Diagnostic application 38 may include one or more diagnostic modules. The diagnostic modules can also be stored in the memory of the workstation 16 for later use by plant personnel in the control 12 or security 14 systems. Generally speaking, when executed by the respective processors 24, 50, 52 in the control 12 or security 14 systems, the diagnostic application 38 is capable of checking or testing the operating status of the field devices 40, 42, 60, 62 used. For example, a control loop tuner (which can, for example, be used in either the control loop of the
<img file="MX338959B_D0022.tif" />
<sup>17</sup> IMPI
INSTTTUT · MÍJUCUMl oc (jtnurituAu
IWMJSTWAl · process control system 12 or I control loop d I security system 14) can be a particular module within diagnostic application 38, control module 46, or security logic module 58 capable of being executed by the processors 24, 50, 52. The user can select to run this particular module when diagnostic data on the control loop indicates that a control loop is poorly adjusted or does not operate within the desired tolerances.
In addition, other modules of diagnostic application 38 can be programmed to execute from a specific condition, for example at a certain time or upon the occurrence of a particular event. For example, a diagnostic module 38 executed by the process controller 24 of the control system 12 may periodically monitor the occurrence of a predetermined diagnostic event, for example, the position of a valve out of range. In response to detecting the occurrence of the diagnostic event, the process controller 24 and / or field device can automatically capture data and report the occurrence to plant personnel and / or adjust the valve accordingly, if necessary. Similarly, a diagnostic module 38 executed by security controller 50, 52 of security system 14 can monitor the occurrence of another pre-terminated diagnostic event, for example, the number of
<img file="MX338959B_D0023.tif" />
LMpr hours that an emergency shutoff valve (ESD) has operated?
and automatically initiate a partial stroke test (ΡίΓ to test the mechanical components of the ESD valve, in response to detection of the occurrence of the diagnostic event.
The results of an executed diagnostic module can be communicated and / or displayed to plant personnel at workstation 16 through display application 44 and / or field devices 40, 42, 60, or 62. io For example, an alert can be generated on field device 40, 42, 60, 62 and sent to display application 44 for display on workstation 16. If desired, plant personnel can respond by acknowledging or disabling the control and / or security alarms displayed on workstation 16.
Because a diagnostic check can be run automatically in response to the detection of a diagnostic event, the automated diagnostic check can occur at an unknown and / or inconvenient time. Therefore, plant personnel could ensure that when a diagnostic check is run automatically, that it is executed in a timely manner when sufficient plant personnel are available. One way to ensure that a diagnostic check is run during a convenient time is to use a calendar
IMPI
MEXICAN INSTITUTE I heard THE INDUSTRIAL PROPERTY with moments when a diagnostic check did not
<img file="MX338959B_D0024.tif" />
It may automatically run in response to detection of the occurrence of a predetermined diagnostic event. Figure 2 illustrates an example of calendar 48 that includes one or more prohibited periods in which diagnostic testing is prohibited. Prohibited periods or blackout can be displayed in hours, days, weeks, or years. Also, prohibited periods can be shown in a list view or any other view, and they don't have to be limited to the example shown in Figure 2.
Calendar 48 can be entered into any of the memory locations within the processing plant 10 through any known means, including, but not limited to, inserting, downloading, or uploading from a wired or wireless handheld device, workstation 16, remote control device, remote controller etc. Calendar 48 can be edited by plant personnel and be exclusively associated with a single field device 40, 42, 60, 62, or generally associated with multiple field devices. In cases where one calendar is associated with a particular field device, another calendar may be associated with another field device. Additional calendars can also be associated with a particular type of field device or a particular type of diagnostic check and are stored in memory throughout the plant.
MEXICAN INSTITUTE OR £ LA FXOFIEDMJ INDUSTRIAL
<img file="MX338959B_D0025.tif" />
processing 10.
The periods of prohibition to carry out a diagnostic check can be designated in calendar 48 by plant personnel in an isolated or periodic (repetitive) way, such as holidays, weekends, Fridays, out of shifts, departures from service etc. This additional functionality provided in part by Calendar 48 offers plant personnel 48 greater flexibility in managing the control system, particularly with regard to executing scheduled automated diagnostic tests. All formulations, comparisons, and determinations involving the diagnostic event, schedule 48, and response action and their execution can be resolved through the cooperation of process controller 12, safety controller 50, 52, and the controller of the workstation 54 together with the memory locations of the processing plant 10.
FIG. 3 depicts a flowchart 300 of an exemplary method of an embodiment of the invention in which the occurrence of a diagnostic event associated with a field device is monitored (block 302). The diagnostic event may be a recognition of a component of the field device located outside a desired range, for example a valve. In response to detecting the occurrence of a diagnostic event associated with the device
<img file="MX338959B_D0026.tif" />
IMPI '^ ηΤΙ / ΐν MEXICANO,' E LA FRoMeuap, friDIISriilAL field (block 304), an action d respifesTa (block 306) is formulated. The processor performs a calculation to determine if the execution of the response action will occur during a prohibited period (block 308) that may have been previously designated by plant personnel in calendar 48. That is, the time of execution of the response action is compared to the prohibited period (s) of calendar 48 to determine whether the response action would occur during a prohibited period. If the response action will not run during the prohibited period, a first command is executed (block 310). Some examples of first commands that can be run include performing a diagnostic check, transmitting an alert or report to the workstation, and adjusting the field device. However, if the execution of the response action will occur during the ban period, a second command is executed (block 312). Some examples of second commands include reprogramming the response action to run at a time that does not coincide with the prohibited period, or ignoring and not reporting the diagnostic event. For example, plant personnel may designate that specific diagnostic controls, such as checking the position of a valve on a specific field device, be disregarded during commissioning or a prescribed maintenance period. Therefore, diagnostic events
IMPI
R'STITUTl I MÍXICANO Oí LA LA FROFIkOAO INDUSTRIAL
<img file="MX338959B_D0027.tif" />
Associates that occur during this signed period can be ignored.
In addition to postponing or delaying an action in response to the occurrence of a diagnostic event, or ignoring the occurrence of a diagnostic event entirely, it may sometimes be preferable to initiate an action in response to the occurrence of the diagnostic event before the expected. By anticipating that a diagnostic event is likely to occur during a future prohibited period and rescheduling the response action or diagnostic check before that time, potential consequences associated with delayed response action beyond a period will be avoided. of established time.
Figure 4 depicts a flow diagram 400 describing another example of the method for applying the described technique in a control system where a diagnostic event associated with a field device is controlled. In particular, a PST interval is used to detect the occurrence of the next scheduled PST (block 402). The PST interval is a typically referenced period in hours of operation, and designates how much an associated ESD valve can operate before requiring a PST. In one example, the field device will track ESD valve usage and monitor the remaining run time until a PST is initiated. The next occurrence of the PST can be detected or determined by projecting when the hours of the PST interval will end.
<img file="MX338959B_D0028.tif" />
INSTITUT · MEXICANO US THE INIWJSTRIAl PROPERTY
The conclusion of the remaining hours of operation of the ESD valve can be checked against the period or periods prohibited in the calendar (block 406). If the PST interval end time does not overlap or coincide with any of the designated prohibited periods in the calendar, a PST command can be run as scheduled at the PST interval end time (block 408). If the end time of the PST interval is however expected to overlap or coincide with any part of the prohibited periods in the calendar, an alternative time that does not conflict with the prohibited periods in the PST execution schedule may be programmed for the PST. When it comes to reprogramming the PST, to avoid circumventing security measures, it is preferred to reprogram the PST before the end of the PST interval, instead of delaying the PST to a later time beyond the end of the PST interval. . For example, the execution of the PST may be advanced to ensure that it is executed before the prescribed deadlines or limits.
It is evident from the description above that the sense of control perceived by plant personnel and the actual level of control in managing a control system can be increased by using a calendar that has designated periods when prohibition is prohibited. run an automatic diagnostic check in response to the occurrence of a diagnostic event. The set of periods
<img file="MX338959B_D0029.tif" />
<sup>24</sup> IMPIg
INSTITUTO MEXICANO \ ^ ¡• E LA, prohibited industrial PROPERTY reduces the likelihood that a diagnostic check will be run automatically when plant personnel are not trained to do so.
Despite the fact that certain examples of methods, apparatus and devices have been described, the scope of this is not limited to them. Rather, the present invention covers all methods, apparatus, and devices that fall within the scope of the Claims either literally or under the doctrine of equivalents.
Contents28
32 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32
20 members in 10 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 13467651 | United States of America | – | |
| 201213467651 | United States of America | A | |
| 2013040354 | United States of America | W | |
| 13467651 | – | – | – |
| US1340354 | – | – | – |
| US201213467651 | – | – | – |
| WO2013US40354 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| CN103389724A | China | A | |
| CA2872913A1 | Canada | A1 | |
| US2013304238A1 | United States of America | A1 | |
| WO2013170033A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CN203324809U | China | U | |
| US8744604B2 | United States of America | B2 | |
| MX2014013635A | Mexico | A | |
| WO2013170033A3 | World Intellectual Property Organization (WIPO) | A3 | |
| AR093210A1 | Argentina | A1 | |
| JP2015519657A | Japan | A | |
| EP2909679A2 | European Patent Office (EPO) | A2 | |
| MX338959BThis record | Mexico | B | |
| RU2014148180A | Russian Federation | A | |
| EP2909679A4 | European Patent Office (EPO) | A4 | |
| BR112014027749A2 | Brazil | A2 | |
| CN103389724B | China | B | |
| RU2642208C2 | Russian Federation | C2 | |
| EP2909679B1 | European Patent Office (EPO) | B1 | |
| JP6574700B2 | Japan | B2 | |
| CA2872913C | Canada | C |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 338959
- Publication, DOCDB
- 338959
- Publication, EPODOC
- MX338959
- Application
- 2014013635
- Application, DOCDB
- 2014013635
- Application, EPODOC
- MX20140013635
Titles2
- Spanish
- METODO Y APARATO PARA CONFIGURAR UN PERIODO DE PROHIBICION PARA CONTROLES PROGRAMADOS DE DIAGNOSTICO DE UN DISPOSITIVO DE CAMPO EN UNA PLANTA DE PROCESAMIENTO.
- English
- METHOD AND APPARATUS FOR CONFIGURING A BLACKOUT PERIOD FOR SCHEDULED DIAGNOSTIC CHECKS OF A FIELD DEVICE IN A PROCESS PLANT.
Classification
- CPC, 2
- G05B19/0428
- G05B2219/33331