This simulator models a functional ESD (emergency shutdown) logic trainer — three independent pressure transmitters are voted, a shutdown logic cabinet latches a trip decision after a configurable persistence delay, a de-energize-to-trip solenoid drops out, the feed pump stops, and a spring-return isolation valve closes with a closure-proof deadline that can reveal a failed final element.
• A real-time 3D cutaway of the protected vessel and pressure taps, three independent pressure transmitters, the shutdown logic cabinet, a manual emergency trip station, the de-energize-to-trip solenoid, the spring-return isolation valve with limit switch, the feed pump and motor contactor, and a trip/closure-proof annunciator, with home view, focus-selected-part, toggleable full enclosure, exploded view, auto-rotate, expand and label controls plus tappable numbered components. • Thirteen live controls: imposed vessel pressure, high-pressure trip setting, a voting-logic selector (two-out-of-three / one-out-of-three), independent sensor A/B/C bias adjustments, a sensor-A fault selector (healthy / stuck low at 0 bar / stuck high at 12 bar), pressure-demand persistence delay, full valve travel time, closure-proof deadline, a shutdown-control-power-available toggle, and an isolation-valve-mechanically-stuck toggle. • Play/pause, single-step (0.1 s) and larger-step (1 s) time controls, plus a playback-speed selector from 10× slow motion to 1-minute-per-second. • Dedicated shutdown-sequence actions: press manual trip, release manual trip, reset trip latch, and restart process, alongside start/stop trial controls. • Ten live metrics: pressure sensors A, B and C, high-pressure vote count, continuous pressure-demand time, trip latch state, isolation valve opening percentage, pump run command, solenoid energized state, and the failure-to-close alarm. • A Curves & measurements tab with two charts (all three sensor readings, and valve opening over time), the full voting/latching/proof equations, and snapshot measurements. • An Experiments tab with four guided scenarios (high-pressure shutdown, single stuck-high channel, stuck isolation valve, loss of control power), a model-verification bench of independent automated checks, and a timestamped event log with a copyable trial report. • A Learn & assess tab with guided lessons (voting and timing the demand, latching shutdown, proving the response, resetting without automatic restart), a knowledge-check quiz and a written scope/reference statement.
A pressure channel casts a high-pressure vote whenever its reading meets or exceeds the trip setting. The selected voting architecture (two-out-of-three or one-out-of-three) determines how many simultaneous votes are required, and that required vote count must persist continuously for the configured pressure-demand delay before a trip is declared — a momentary spike that clears before the delay elapses does not trip the system. A manual trip or a loss of shutdown control power instead bypasses this timing entirely and latches shutdown immediately.
Once latched, the trip removes the pump run command and de-energizes the solenoid, which is a de-energize-to-trip design — losing energization commands the spring-return isolation valve to close. Critically, the latch does not reset on its own: releasing a manual trip button clears the demand but leaves the latch set, and even after resetting the latch, restart requires a separate explicit restart command rather than happening automatically.
Commanding the isolation valve to close and confirming it actually closed are treated as two separate facts. The valve travels toward closed over the configured full-travel time, and the closure-proof alarm activates if the proof deadline elapses while opening is still above 5% — exactly the situation demonstrated in the stuck-isolation-valve experiment, where the pump stops correctly but the mechanically jammed valve produces a failure-to-close alarm.
This is a functional logic trainer, not a certified safety-instrumented system, SIL calculation or operating procedure — it includes no common-cause failure modeling, no diagnostic-coverage or probability-of-failure calculations, and the three sensor channels share one imposed vessel pressure rather than independent process physics. Pump stop is modeled as immediate, without motor coastdown or pressure decay dynamics, and the closure-proof check monitors modeled travel rather than actual seat leakage.
No. Releasing the manual trip clears the trip demand but the shutdown latch itself remains set. A full reset requires clearing all sensor votes, releasing the manual trip, restoring control power and bringing imposed pressure below 7 bar, and even after the latch resets, the process needs a separate explicit restart command — it never restarts automatically.
It detects whether the isolation valve reached its expected closed position (5% opening or less) before the configured proof deadline elapsed. Commanding closure and confirming closure are separate events in this model — the stuck-isolation-valve experiment shows the pump stopping correctly while a mechanically jammed valve still triggers the failure-to-close alarm.
With the default two-out-of-three voting architecture, at least two of the three pressure channels must agree on a high-pressure condition before a vote count is reached. A single sensor stuck high at 12 bar casts only one vote, which is insufficient under 2oo3 voting at otherwise normal process pressure — switching to one-out-of-three voting would trip on that single channel instead.
It is a functional logic trainer, not a certified safety-instrumented system or SIL/PFD calculation. It has no common-cause-failure or diagnostic-coverage modeling, the three sensor channels share one imposed physical pressure rather than independent process dynamics, pump stop is immediate with no motor coastdown, and closure proof monitors modeled valve travel rather than actual seat leakage.