Reliability and Availability Modeling of Subsea Autonomous High Integrity Pressure Protection System With Partial Stroke Test by Dynamic Bayesian
Reliability and Availability Modeling of Subsea Autonomous High Integrity Pressure Protection System With Partial Stroke Test by Dynamic Bayesian
Reliability and Availability Modeling of Subsea Autonomous High Integrity Pressure Protection System With Partial Stroke Test by Dynamic Bayesian
Chuan Wang1 , Yupeng Liu1, Wen Hou2, Chao Yu3, Guorong Wang1 and
Yuyan Zheng1
Abstract
Subsea Autonomous High Integrity Pressure Protection System is used in the subsea production process to lower
the pressure level of downstream equipment and pipelines and to protect low-pressure pipelines and equipment. Once
fail- ure occurs, it will cause serious environmental damage and huge economic losses. In this article, a method of
Dynamic Bayesian networks is proposed based on different failure types detected by different test methods. The
reliability and availability of HIPPS with different detection methods were analyzed quantitatively. The results show
that the perfor- mance of the system is improved significantly after inspection and maintenance. Compared with
traditional methods, the performance of HIPPS is improved after the partial stroke test is introduced. Through sensitivity
analysis, it is found that failure rates have a greater impact on the reliability of HIPPS valves. Increasing partial stroke test
coverage can improve HIPPS performance. To improve the reliability of HIPPS, it is necessary to improve the reliability of
the execution unit, especially the HIPPS valves. The analysis of the PST strategy can provide a theoretical basis for
selecting the frequency of partial stroke test and functional test interval in actual projects.
Keywords
Dynamic Bayesian networks, High Integrity Pressure Protection System, reliability, availability, partial stroke test, func-
tional test
Figure 4. DBN of (a) 3/3(G), (b) 1/3(G), and (c) 2/3(G) systems with three components.
modeling of HIPPS.’’ Failure rate and repair rate of An important factor to consider in the reliability
the parent nodes are denoted by l and m, respec- evaluation of equipment is incomplete coverage.29 This
tively.26 Assume the current time is t and the time inter- article considers this important problem by defining a
val between two-time slices is Dt. It is known that the coverage factor c, which can be expressed as c = P
state NO means the node is in normal working state, (sys- tem recovers|fault occurs).30 It reflects the ability
and the state YES means the node is in a failure state. of the system to automatically recover from the
Then, the transition probability of the nodes with tem- occurrence of a fault. The DBN model of the system
poral links between two-time slices is given by27: composed of three components is proposed in this
article. When the system is in series, when any
PðXi ðt + DtÞ = NOjXi ðtÞ = NOÞ = e—lDt ð4Þ
component fails, the sys- tem cannot be restored. For
PðXi ðt + DtÞ = YESjXi ðtÞ = NOÞ = 1 — e—lDt parallel system, when one or two components fail, the
system can be restored. In the case of a 2oo3 voting
ð5Þ PðXiðt + DtÞ = NOjXiðtÞ = YESÞ =1 — e—mDt system, the system can be restored only if a component
ð6Þ fails. Therefore, the imperfect coverage affects both
parallel and 2oo3 vot-
PðX ðt + DtÞ = YESjX ðtÞ = YESÞ = e—mDt
ð7Þ
i i ing systems. In a system with a given coverage factor c,
the conditional probability table (CPT) of the state of
node D is shown in Tables 1–3. For the three systems,
Conditional probability table the coverage factor c is 0.9.31
For a DBN with n parent nodes and m states for each
parent nodes, it requires mn independent parameters to
Partial stroke testing
completely specify the CPT. 28 It can be seen that when
n increases, the parameters need to be determined grow Concept. Partial stroke test (PST) as a supplement to
exponentially. Obviously, it is not feasible to determine functional test (FT), is widely used in the final elements
so many parameters to determine CPT. In order to of SISs.9 Partial stroke test refers to the partial opera-
solve this problem, noisy OR-gate and noisy AND-gate tion of the valve, which can not only meet the require-
models are used for series and parallel systems, ments of valve movement but also reveal a part of the
respectively. specific dangerous faults through small movement.
Wang et 5
is 100%;
Table 4. Failure rates and MTTR of components. 3. PST shall be conducted once a month and func-
tional test shall be conducted once a year.
Component lDU lD MTTR (h)
ð9Þ
lD = lDD + lDU
ð10Þ
lDD = uDC 3 lD
ð11Þ
lDU, PST = ð1 — uDCÞ 3 uPST 3 lD
ð12Þ
lDU, FT = ð1 — uDCÞ 3 ð1 — uPSTÞ 3 lD
ð13Þ
Failure rates of each component are found accord-
ing to OREDA and the literature32 as shown in Table
4. Failure rates lDD can be calculated according to
Table 4. Therefore, in this article, the diagnostic cover-
age is no longer selected. Meanwhile, the following
hypothesis is given:
NO NO 1 0
NO YES 0 1
YES NO 0 1
YES YES 0 1
incomplete coverage, this article sets the coverage fac- the values should be always greater than the one
tor as 0.9. from the set of x — yðy 2 xÞ attributes;
Take the child node of L1 in Figure 8 as an example
Validation of the method and model to verify the correctness of DBN model. When the state
NO of node HV1 is set to 80 from 100, the reliability of
Model validation is one key issue of the proposed
the system is reduced from 99.87 to 97.83 in the second
DBNs because of that it can provide a reasonable
time slice. When the state of node SV1 is set from 100
amount of confidence in the results of the model. In the
to 80, the reliability of the system is reduced to 96.202
present study, a three-axiom-based validation method
in the second time slice. Similarly, change the state of
is used for partial validation of the developed DBNs.
the HV1 child nodes in Figure 9. When the state of
The three axioms33–35 are as follows:
HV1DD NO is set from 100 to 80, the reliability of the
system is reduced from 99.87 to 99.36 in the second
(1) Increasing/decreasing the prior probabilities of time slice. When the status of node HV1DU is set from
parent nodes slightly will lead to the relative 100 to 80, the reliability of the system is reduced to
increase/decrease of the posterior probabilities of 97.96 in the second time slice. The state NO of child
the corresponding child nodes; node HV1DUPST and HV1DUOUT in figure 10 is set
(2) The influence degree to the child node caused by to 80 in turn, and the reliable line in the second time
the change of probability distributions of parent
slice is reduced from 99.87 to 99.39 and 99.29, respec-
nodes should be consistent;
tively. By changing the states of multiple parent nodes,
(3) The total influence magnitudes of the combination
it can be found that the reliability of the system has
of the probability variations from x attributes on
changed, thus verifying the rationality of the model.
10 Proc IMechE Part O: J Risk and Reliability 00(0)
Figure 10. DBNs of HIPPS with self-diagnosis, partial stroke test, and function test.
so it can significantly improve the performance of PTs. inspection and maintenance methods. The most effec-
The reliability of the PTs dropped to 0.93 in the 120th tive way to improve performance is the combination of
month. self-diagnosis, partial stroke test and functional test
Through comparative analysis, it is found that the (SDPSFT).
performance of HIPPS is improved by using different
12 Proc IMechE Part O: J Risk and Reliability 00(0)
Sensitivity analysis
As the parameters of the DBN are calculated according
to the failure rates, repair rates, coverage factor, and
PST coverage, sensitivity analysis is carried out for the
two commonly used methods in practical engineering.
Figure 16. Effects of failure rates on the availability of HIPPS (a) with SDFT and (b) with SDPSFT.
14. Summers A and Zachary B. Partial-stroke testing of preventers in presence of imperfect repair. Expert Syst
safety block valves. Control Eng 2000; 47: 87–89. Appl 2013; 40: 7544–7554.
15. Innal F, Lundteigen MA, Liu Y, et al. PFDavg general- 29. Kim SJ, Seong PH, Lee JS, et al. A method for evaluat-
ized formulas for SIS subject to partial and full periodic ing fault coverage using simulated fault injection for digi-
tests based on multi-phase Markov models. Reliab Eng talized systems in nuclear power plants. Reliab Eng Syst
Syst Safe 2016; 150: 160–170. Safe 2006; 91: 614–623.
16. Jin H and Rausand M. Reliability of safety-instrumented 30. Dugan JB and Trivedi KS. Coverage modeling for
systems subject to partial testing and common-cause fail- dependability analysis of fault-tolerant systems. IEEE T
ures. Reliab Eng Syst Safe 2014; 121: 146–151. Comput 1989; 38(6): 775–787.
17. Brissaud F, Barros A and Be´renguer C. 31. Cai B, Liu Y, Fan Q, et al. Performance evaluation of
Probability of failure on demand of safety systems: subsea BOP control systems using dynamic Bayesian net-
impact of partial test distribution. Proc IMechE, Part O: works with imperfect repair and preventive maintenance.
J Risk and Reliability 2012; 226(4): 426–436. Eng Appl Artif Intel 2013; 26(10): 2661–2672.
18. Pascual R, Louit D and Jardine AKS. Optimal inspec- 32. Tor O. Reliability data for safety instrumented systems –
tion intervals for safety systems with partial inspections. PDS data handbook, 2010 edition. Trondheim: SINTEF
J Oper Res Soc 2011; 62: 2051–2062. Technology and Society, 2014.
19. Nelson-Bridgewater S, Hiez M, Caudin J, et al. High 33. Cai B, Liu Y, Zhang Y, et al. A dynamic Bayesian net-
Integrity Pressure Protection System for ESP activated works modeling of human factors on offshore blowouts.
wells. In: SPE international conference on health, safety, J Loss Prev Process Ind 2013; 26(4): 639–649.
and environment, Long Beach, California, USA, 17–19 34. Cai B, Liu Y, Zhang Y, et al. Dynamic Bayesian net-
March 2014, p.10. Long Beach, CA: Society of Petro- works based performance evaluation of subsea blowout
leum Engineers. preventers in presence of imperfect repair. Expert Syst
20. Langvik S and Aarebrot E. High Integrity Pressure Pro- Appl 2013; 40(18): 7544–7554.
tection Systems for production applications. Vol. 4. SPE 35. Jones B, Jenkinson I, Yang Z, et al. The use of Bayesian
Advanced Technology Series. Society of Petroleum network modelling for maintenance planning in a manu-
Engi- neers, 1996, pp. 155–159. facturing industry. Reliab Eng Syst Safe 2010; 95(3):
21. Hutchings V. Is the Subsea High Integrity Pressure Pro- 267– 277.
tection System (HIPPS) coming of age? In: Subsea Con-
trol and Data Acquisition (SCADA) conference,
Newcastle, UK, 2–3 June 2010, p.8. Newcastle: Society Appendix 1
of Underwater Technology.
22. Hu J, Zhang L, Ma L, et al. An integrated safety prog- Notation
nosis model for complex system based on dynamic Baye-
sian network and ant colony algorithm. Expert Syst Appl HIPPS High Integrity Pressure Protection System
2011; 38(3): 1431–1446. DBNs Dynamic Bayesian networks
23. Murphy KP. Dynamic bayesian networks: FT Functional test
representation, inference and learning. Doctoral PST Partial stroke test
Dissertation, University of California, Berkeley, 2002. SD Self-diagnosis
24. Yuan L and Cui Z. Reliability analysis for the consecu- SDFT Self-diagnosis and functional test
tive-k-out-of-n: F system with repairmen taking multiple SDPSFT Self-diagnosis, partial stroke test, and
vacations. Applied Math Modell 2013; 37(7): 4685–4697.
functional test
25. O’Connor PDT. An introduction to reliability and main-
tainability engineering, Charles E. Ebeling, McGraw- DD Self-diagnostic testing reveals
Hill, 1997. Number of pages: 489. Price: £22.99. Qual fault patterns
Reliab Eng Int 1998; 14: 295. DU Self-diagnostic tests cannot reveal
26. Liu Z, Liu Y, Cai B, et al. Dynamic Bayesian network fault patterns
modeling of reliability of subsea blowout preventer stack DU, PST Partial stroke test reveals fault patterns
in presence of common cause failures. J Loss Prev Pro- DU, FT Functional test reveals fault patterns
cess Ind 2015; 38: 58–66. DU, OUT Partial stroke test cannot reveals fault
27. Kohda T and Cui W. Risk-based reconfiguration of patterns
safety monitoring system using dynamic Bayesian net- PFDavg The average probability of on-demand
work. Reliab Eng Syst Safe 2007; 92(12): 1716–1723.
failure in low-demand mode
28. Cai B, Liu Y, Zhang Y, et al. Dynamic Bayesian net-
works based performance evaluation of subsea blowout