Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Triguard 2
TMR Safety Products
ABB
TMR Safety and Control
August Systems, founded in 1978, was the worldwide pioneer in the development of Triple Modular Redundant
(TMR) processing for real time, fault tolerant control. August Systems became an ABB company in 1997 adding
TMR technology to the well established Dual Redundant Safety systems developed within ABB. The new
business group of ABB Safety has been established to offer a broad range of safety solutions to industry.
The Triguard SC300E products are available as engineered systems from ABB or products for integration by
third party system integrators and OEMs, enabling the technology to be made available to a wide range of
customers and applications.
TRIGUARD SC300E
ADNOC McDermott
AGIP Pacific Gas & Electric
AMEC Pemex
Arabian Industrial Fibers Petrobras
Azot – Russia Petrokemya
Bechtel Petromin
BP/AMOCO Petronas Gas
British Nuclear Fuels Qatar Gas
Cegelec QGPC
Chiyoda Ralph M Parsons
Conoco Saipem
Crescent Petroleum SARAS – Italy
Dow Sarawak Shell
Ecopetrol Saudi Aramco
Elf Enterprise Snamprogetti
EPA – Taiwan Southern Petrochemical
Exxon/Mobil Technip
Foster Wheeler Technipgeoproduction
Gas Authority India Tecnimont
Gazprom Thai Aromatics
Hanwha Chemical Torch Energy
Huntsman Chemicals Total
Hyundai Petrochemical Toyo Engineering Co
IOCL – India UK Atomic Energy
KBR US Steel
KNPC Westlake Group
Madras Refinery
2
Contents International Standards 16
Tr i g u a r d S C 3 0 0 E
The ABB Triguard SC300E is the • Safety Shutdown
evolution of 20 years of combined • Electrical Stability and Load Control
vendor and customer experience • Process Shutdown
integrated into the design of the • Reactor Control
ultimate TMR product. Building on a • Emergency Shutdown
proven platform, the Triguard SC300E • Critical Batch Processing
combines features that will maintain • Sequence and Interlock Control
excellence well into the future. • Fire & Gas Protection and Detection
• Critical Process Control
Today ABB is a global supplier with • Burner Management and Control
key operating bases in North America, • Turbine and Compressor Control
Europe, Middle East and Asia Pacific. • Wellhead/Sub-Sea Control
The Company has successfully • Unmanned Installations
supplied TMR products and systems to • FPSOs
meet an ever increasing diverse range
of applications, including:
3
Product Family
The ABB Triguard SC300E TMR product family gives unrivalled performance in areas of reliability, availability, test coverage,
diagnostics and simplicity of operation. Advances in technology and improved production methods add cost benefits that
give significant price/performance advantages.
TRIGUARD SC300E
MICRO MICRO
PROCESSOR
CONTROLLER CONTROLLER
A
A A
FIELD FIELD
TERMINATION READ ONLY LINKS READ ONLY LINKS READ ONLY LINKS TERMINATION
4
SC300E Chassis
High speed of response benefits the TriBuildTM and TriCommandTM Server Importance of Transient
customer application which specifies can be used with Windows NTTM. Immunity
Sequence of Events recording (SoE) Features include: Comprehensive physical and electrical
without the cost of additional isolation combined with asynchronous
equipment. It also enables TMR to be • True multitasking capability processors and software voting
used for applications requiring high • Strategies can be saved on-line ensures the Triguard SC300E is
speed advanced control. without halting the system operation immune to transient errors.
• Ability to upload the configuration
Fault Tolerant Hardware and • Changes can be made on-line Smallest Footprint Size
Software without halting the system operation The Triguard SC300E TMR offers our
The system is designed to continue to • Bumpless changeover of hot repair customers the best utilisation of
operate correctly with the presence of modules available space. ABB have developed
a major component fault and is • Comprehensive diagnostic displays “plug and play” cabinet layout
capable of tolerating multiple, non for ease of maintenance configurations that offer pre-designed
concurrent faults. hardware for system applications.
Fault Tolerance and
Easy to Use Software – Selective Redundancy Plug and socketed system cables make
WindowsTM Improvements in the system to keep a marshalling and termination
TriBuildTM configuration and process plant running safely without interconnection quick and easy to
application programming and the nuisance of false trips have been implement.
TriCommandTM Server achieved by full diagnostic coverage
(WONDERWARE© MMI interface of all modules and selective
software) are WindowsTM compliant, redundancy.
making the system easier to use for
the engineer and the operator. For Processors 3–2–1–0
customers with existing ABB equipment
“backward compatibility” is provided Input/Output Circuits 3–2–1–0 or
making upgrading or adding new 3–2–0
facilities economic to implement.
5
Product Hardware and Software
Description
The ABB Triguard SC300E TMR Each processor correlates and of the customer application.
product has a fully triplicated system corrects its memory image of the Extension chassis are always
architecture from input module to current state of the system using a complete with two power supply
output module. Each system software vote, logging any units and three bus extender
comprises one or more identical discrepancies in the diagnostic table. modules.
chassis housing the power supplies, Each processor then executes its
processors, I/O and communications programmed application logic and • A Remote Master Chassis
modules as required by the sets its respective outputs to the Always equipped with two power
application. required state. supply units and three fibre optic
TRIGUARD SC300E
A single system may be as small as Commanded output status from the master bus extender modules. The
one chassis or as large as 15, giving a processors are received by an output master chassis can service up to four
maximum of 9,500 I/O. module which, using a 2oo3 hardware remote chassis.
voter, sets the outputs to the field.
The system is designed to achieve the Any discrepancy is detected by the • A Remote Chassis
highest possible reliability, safety and micro-controllers and reported to the Always equipped with two power
availability and still provide economic processors. supply units and three fibre optic
advantage. System availabilities in slave bus extender modules.
excess of 99.999% can readily be All input and output modules can be A remote chassis can be sited up to
realised, maximising the potential optionally configured with a hot spare 2km away from a remote master.
uptime for a customers process plant. partner module. This allows repairs to
be carried out without affecting the
All SC300E input and output modules operation of the system.
interface to three isolated I/O
communication buses, each being Triguard SC300E Chassis
controlled by one of the three System
processor modules. There are four basic types of chassis, all
using the same mechanics, each
Field input signals are filtered and providing 10 slot positions for I/O
split, via isolating circuits on the input modules and redundant power supplies.
modules, into three identical signal
processing paths. Each path is • The Main Chassis
controlled by a micro-controller to co- One per system is required and is
ordinate processing, testing and status always complete with two power
reporting to the respective processor. supply units, three processor
modules, the chassis backplane with
Each processor communicates with triple bus systems and plug/socket
its two neighbours via isolated, read system module connectors.
only, high speed links to
synchronise input, output and • An Extension Chassis
diagnostic status information at least Up to 14 chassis can be connected
once every scan. to a main chassis to suit the capacity
6
Processor Key features of the processor modules:
Each Triguard SC300E TMR system • Intel processor
contains three processors. Each • Battery backed static RAM for
processor operates asynchronously in application logic
parallel with the other two processor • RAM Battery backup supply for six
modules and receives power from the months
redundant power supply units in the • 1 Mbyte of EPROM
main chassis. A triplicated bus system • Real time clock for data logging to
on the chassis backplane connects 10ms resolution Processor Module
each of the three processors to the The Triguard SC300E has an operating Input/Output Modules
I/O and communications modules. system known as the Real Time Task All I/O module types share an
Supervisor (RTTS), which is installed element of common design, providing
in each of the three processors. The component rationalisation and
operating system has been proven by implementing distributed processing.
well over 10 million operational hours.
RTTS is transparent to the user, it The three isolated TMR signal paths of
controls the off-line/start-up and all input/output modules are
on-line continuous diagnostic and supervised by a micro-controllers
voting functions, and provides a single which:
environment for the application
programming. • Provides fault isolation
• Co-ordinate signal processing
On power up, comprehensive • Provides diagnostics
diagnostic routines check and validate • Provides on-line to off-line
the correct operating parameters of switching (hot repair)
each processor. • Provides data validation routines
• Provides data to the processor
The Triguard SC300E operating • Provides latent fault detection
system, RTTS, will permit the
processors to operate in a 3–2–1 A fault in one signal path cannot be
format allowing a system to continue passed to another. I/O modules can
to function with one healthy be fitted in any of the 10 slots in any
processor. A replaced processor will chassis. “Hot Repair” is a customer
automatically acquire the data it configurable option on a per module
requires to become operational from basis. All modules are “keyed” to
the on-line processor before going prevent improper installation.
on-line.
7
Product Hardware and Software
Description
Digital Input Modules Digital Output Modules All TMR digital output modules are
The types of digital input modules The types of digital output modules equipped with:
available are: available are:
• Line monitoring circuits to confirm
• 32 channel isolated • 32 channel – supervised 24Vdc energised field loop integrity
24Vdc\120Vdc\120Vac TMR TMR* • Six element voting circuits for
• 64 channel isolated 24Vdc Simplex • 16 channel – supervised maximum safety and availability
120Vdc\120Vac TMR* • Automatic latent fault testing and
All TMR digital input modules are diagnostics with 100% coverage (TMR)
TRIGUARD SC300E
availability.
DRIVER A A B C
MICRO
CONTROLLER
Each signal path conditions signals A V/I
MONITOR
independently and provides full
optical isolation between the field and MICRO
DRIVER B C A B
CONTROLLE
RC OUTPUT
V/I MONITOR STATUS LED
Line monitored inputs can be
implemented using analogue input SUPPLY –
modules with line monitor termination
Typical Digital Output Circuit
cards.
TEST
ISOLATOR
INPUT SIGNAL
FILTER ISOLATOR PROCESSING MICRO Each of the three micro-controllers
CONTROLLE
RA operate two isolated switches per
ISOLATOR
TEST channel which together form a six
INPUT
FILTER SIGNAL element voting network.
ISOLATOR PROCESSING MICRO
CONTROLLER
B
TEST
ISOLATOR
INPUT SIGNAL
FILTER ISOLATOR PROCESSING MICRO
CONTROLLER
C
DRIVER
SIGNAL
STATUS LED
* Line monitoring of de-energised field
Typical Digital Input Circuit
loops may be achieved using alternative
termination cards.
8
The output voting, testing, feedback Thermocouple Inputs
and diagnostics are co-ordinated by the Thermocouple and resistance
Triguard SC300E operating system. All thermometer inputs are provided by
modules provide 2oo3 voted outputs. the use of third party transmitters or
converters mounted in the field or
Selective redundancy operating in within the marshalling cabinets. Inputs
3–2–1 or 3–2–0 modes is available, from these devices are then handled
with selectable fall back to fail safe or by the standard TMR analogue input
retain last value states. modules.
• Isolation
• Noise Filtering VREF 1 VREF 2
SELECT
• Multiplexing RANGE NOISE FILTER
1
MICRO
MUX
• Amplification 32 AMP A/D
CONTROLLER B
VREF 1 VREF 2
and each of the three circuits is SELECT
1
supervised by a micro-controller. RANGE NOISE FILTER MICRO
MUX CONTROLLER
32 AMP A/D C
The three circuits synchronously
measure the input signals, vote the
data and transmit the data to the
Typical Analogue Input Circuit
processors.
Analogue Output Modules Each micro-controller controls a digital Feedback to each of the three
• 4 channel – 12 bit resolution to analogue converter which drives micro-controllers provides continuous
4–20mA TMR two elements of the six element checking for correctness. Diagnostics
output voting network. Each element declare any fault to the processors for
Each of the three Triguard SC300E of the six element voter is an isolated maintenance information and action.
processors sends voted output voltage field effect transistor operated within
data to the analogue output modules. its linear range. The final output of
The commands are received via the field device is selected as the
the bus system by the three mid-value from the three circuits of
micro-controllers on each module. output data.
TRIGUARD SC300E
V REF
D/A CONVERTER A A B C
MICRO
CONTROLLER A
V MONITOR
D/A CONVERTER B C A B
MICRO
CONTROLLER B
V MONITOR
D/A CONVERTER C
10
INDICATORS
WATCHDOG
MICROCONTROLLER
0–20mA TMR I/O BUS B
O/P B
O/P’s INTERFACE
DRIVERS
(ANALOGUE)
WATCHDOG
MICROCONTROLLER
Pulse Input Analogue Output C I/O BUS C
a gear wheel for example, and Communications Module High speed network
accumulates this data to an accuracy A four channel serial communications connectivity feature (to be
of +_0.01% over 20Hz to 20KHz. module is always fitted to a Triguard released)
SC300E TMR system to allow Triguard may be interfaced to standard
Output values to 12 bit resolution can communications to the engineering communications networks such as
provide voted and validated data to workstation and is installed in I/O slot Ethernet/TCP/IP using approved
field devices for control (see analogue number 10 of the main chassis. All gateway products.
output module for output circuit four channels operate RS232\423 up
operation). to 19.2 kbits/sec and all four DCS connectivity includes:
communication ports are fully isolated. • Yokogawa Electric, Elsag-Bailey,
Fisher Rosemount, ABB, Honeywell
The four channel communications and Foxboro
module is directly addressed by the
three Triguard SC300E processors and
contains a micro-computer that
controls the four programmable
multi-protocol ports. Data received
from the three processors is voted
2oo3 providing correct data for
onward transmission.
Hot Repair Facility All I/O modules can be programmed Field Termination Cards
A quick repair procedure, once any for a hot repair facility. A wrong or The types of termination cards
fault is revealed, is important in the faulty module in an allocated hot available:
total fault tolerant product strategy. repair I/O slot will not be accepted.
Hot repair slots are selected to be • 16 channel – digital input
The hot repair facility achieves a quick next to the system I/O resident • 32 channel – digital input
and easy repair by the user and this is module. • 16 channel – digital output
TRIGUARD SC300E
done bumplessly without interrupting There are three ways to replace an • 16 channel – analogue input
the normal operation of the system on-line I/O module: • 4 channel – analogue output
and process. • 16 channel – digital output with line
• Module with no additional hot monitoring
The operating system, RTTS, routinely repair slot – single slot hot repair • 4 channel – pulse input
executes a hot repair task, checking • Module has an unpopulated hot
and validating that all configuration repair partner slot – manual hot DIN rail mounted termination cards
data is correct, eg. correct I/O repair for field wiring can be supplied as an
module, on-line/off-line hot repair • Module with a populated hot repair easy to fit method to route field cables
functions. partner slot – hot repair to the Triguard SC300E system I/O
modules, and distribute field wetting
current to each I/O point.
Triguard SC300E
MAIN CHASSIS
EXTENSION CHASSIS
13
Software
The Triguard SC300E supports three The TriBuild Workstation is connected TriBuildTM software provides:
main application software packages, to a Triguard SC300E TMR system via • A comprehensive library of
all are Windows compatible: the communications module. programming elements, eg logic,
• TriBuildTM for developing and arithmetic, data conversion, timers,
programming application logic TriBuild provides on and off-line counters, block elements, bit shift,
• TriCommandTM a display and configuration, programming, comparators, mid value select,
control system workstation documentation and testing functions. NooM voting blocks
(WONDERWARE©) Programming uses both conventional • An environment for users to
• TriLogTM simple PC based ladder logic displays, function block develop special functions, function
alarm/event logger programming and structured networks. blocks, custom programs for
TRIGUARD SC300E
TriBuildTM These can be developed quickly and advanced fault tolerant control
TriBuild is an easy to use, menu effectively with the assistance of applications
driven, software package running search and replace, cut and paste and • Application specific control
under Windows NTTM. It is used for a standard library of logic symbols and functions, eg auto-test routines, gas
the creation of system application programming functions. Completed detection calibration tables,
logic of the Triguard SC300E control programs can be loaded into a advanced control
control system. Triguard SC300E system and the • System interrogation
execution of the control program can • Control and user changes with date
Key features of TriBuild: be monitored on-line with the TriBuild and time
workstation. • Off-line configuration, simulation
• System Configurator – easy guide and applications testing of the
for system build control programs
• Ladder Annotator – adds notes to
the ladder logic
• Network Editor – on-line/off-line
editing of logic functions
• On-Line Help – reduces need to
refer to printed manual
DCS AND
• Ladder Simulator – allows testing CPU/CPU
FIELD I/O
INTERFACE 3rd PARTY
during program development COMMUNICATIONS
14
TriBuild provides a secure
environment to make program
changes on-line and without
interrupting the normal process
operations.
TriCommandTM
TriCommand is a PC-based operator
workstation, utilising Wonderware’s
InTouchTM products. TriCommand TRIBUILD Windows Workstation
provides real time system control and Key features of TriCommand: The Graphical User Interface for
monitoring facilities. It can operate as • A real time database of up to 32,000 operators, engineers and managers is
part of a Triguard SC300E system in a points that can be mapped to field a multiple Windows display on a
single station configuration or as or virtual I/O points single screen. Displays can however
multiple TriCommand stations for • Dynamic Data Exchange (DDE) be locked on full screen making the
distributed applications. TriCommand allowing TriCommand to pass data Windows feature unavailable.
workstations can be connected to other Windows applications, eg
to a Triguard SC300E system via peer ExcelTM Operators can choose different means
to peer, single, or dual serial • Supports a comprehensive range of of navigating and interacting with the
communication links, networked via industry standard protocols, such as system, from full keyboard to a
single or dual redundant LANs. TCP/IP via the DDE server library restricted pushbutton selection pad.
• Can display an almost unlimited Engineers can develop graphical
TriCommand is Windows NTTM number of mimic pages displays using a powerful display
compliant. Standard off-the-shelf • Extensive alarm handling builder which can be tailored to the
hardware makes customer ownership capabilities, including accept, reset, needs of the process operation.
and support easy to achieve. cross functions (for multiple
TriCommand workstations may be systems), zone hierarchy, first out, TriLogTM
installed in the control room for status, prioritising, displays, TriLog is a message logger, it is
operator display and control or at a summaries designed to monitor up to four
remote location where there may be a • Data logging, data archiving, data Triguard SC300E systems accepting
need for local information and control. trending and storing sequence of event and
• Event status, event history, event alarm messages from each system. It
TriCommand allows a user to start display, event printing uses a dedicated PC with Windows
small and expand into an integrated • Fault diagnostics – communication, NTTM compliance. Windows are
environment providing a single systems allocated to display time and date
seamless network. Expansion is simple • Advanced control – digital, analogue together with current and archived
and cost effective. • Multi-level security access information from each system.
15
International Standards
Quality
ABB quality system meets International Standards and is certified to the requirements of BS EN ISO 9001
1994, Certificate Number FM 1353 for safety systems and products. The certification for Quality Assurance at
ABB, covers all aspects of design, manufacturing, testing, software verification, software validation and
service activities.
TRIGUARD SC300E
16
Global Support
Description Model
SC300E Extension I/O Chassis, complete with 3 bus extender modules and 2 PSUs
TRIGUARD SC300E
SC300E Remote I/O Chassis, complete with 3 fibre optic bus extender modules and 2 PSUs
4 Channel pulse input/4 channel analogue output module (PIANO), 4/20mA MHB 44 IND
18
General Product Specifications
Overall Sizes
All Chassis Types 19” Rack Mounted x 398mm height x 474mm depth
All I/O Module Types 365.8mm high x 28mm width x 394mm depth
All Termination Cards Types DIN Rail mounted 162mm high x 110mm width x 56mm depth
All Power Supply Types 198mm high x 67mm width x 417mm depth
Approximate Weights
Main Chassis with two PSU’s and three Processors 16.8kg (37.0lb)
Extension/Remote Chassis with two PSU’s and
Three Extender Modules 17.1kg (37.7lb)
Power Supply Module 2.3kg ( 5.1lb)
Fabrication and Paint Finish Aluminium Chassis with Dusty Grey, Front Panel
Finish (RAL 7037)
Environment Specifications
Operating Temperature 0–60˚C
Storage Temperature with Battery –30˚C to +75˚C
Relative Humidity 5 to 95% Non-Condensing
Vibration 1g at 5 to 500 Hz Sinusoidal
Shock 20G for 12ms
Electro-static Discharge 8kV (IEC 801-4, level 3)
EMC
Immunity EN50082-2
Emissions EN50081-2
19
ABB is a global electrical engineering group which is active in many
areas associated with the generation, transmission, distribution and
use of electrical power. The ABB Group comprises 1,000 companies
in 140 countries.
Email: info@triguard.co.uk
008-5185-02(12/01)