Refinery and Ethylene Complex — 42,358 I/O Delivered Across 17 Field Auxiliary Rooms

A 22 million t/y refinery revamp and 1 million t/y ethylene complex on a single Yokogawa CENTUM VP control system, spanning four central control rooms and seventeen field auxiliary rooms. Our engineers delivered the control cabinet integration and manufacture, and the system configuration and commissioning.

IndustryRefining and petrochemicals — refinery, ethylene, coal gasification hydrogen, utilities
RegionSouthern China, coastal petrochemical zone
Scale22 million t/y refinery expansion plus 1 million t/y ethylene; 60+ process and utility units
Control platformYokogawa CENTUM VP (Vnet/IP), with expansion of an existing legacy Foxboro DCS
Total I/O42,358 points
Our scopeControl cabinet integration and manufacture · system configuration, FAT/SAT support and commissioning
Client identityWithheld — described by industry, region and scale

Project Context

The plant is a brownfield expansion on an operating site. Phase 1 was already running from an existing control room; Phase 2 added the refinery revamp and ethylene complex alongside it, plus coal gasification hydrogen production, a power island and a large utilities scope.

That produced an unusually distributed architecture. Three new central control rooms were built alongside the existing one, with operations split by production department:

Control roomOperating scope
CCR-1 (existing)Phase 2 utilities; refinery tank farm via expansion of the legacy Foxboro DCS
CCR-2 (new)Refinery process units and feedstock tank farms, five operating departments
CCR-3 (new)Chemical product tank farms and power island — gas turbines, HRSGs, boilers, STGs
CCR-4 (new)Coal gasification, hydrogen production and associated units

Field control stations and marshalling cabinets sit in 17 field auxiliary rooms (FARs) next to the process units, each connected back to its control room over redundant single-mode fibre.

The Engineering Problem

The availability target was 99.99999 % with a mean time to repair of one hour or less, which pushes redundancy decisions down to card and power-feed level. But at this scale the real difficulty is holding tens of thousands of such decisions consistent across seventeen buildings, dozens of contractors and a schedule that does not wait.

  • Volume. 42,358 I/O points over more than 60 units, each with its own design institute package, instrument index and delivery date.
  • Brownfield coexistence. New CENTUM VP stations had to run alongside a live legacy Foxboro DCS, with part of the Phase 2 scope delivered as an expansion of that older system.
  • Distribution. Field rooms sit far beyond the 100 m limit of copper Ethernet, so the whole control network depends on a fibre plant that must survive construction traffic and rodents.
  • Segregation discipline. IS and non-IS signals, gas detection and electrical circuits all had to stay on separate cards and in separate cabinet types — easy to state, easy to violate under schedule pressure.

I/O Scope and Distribution

The I/O count drives controller sizing, network load, domain allocation and cabinet quantity. It was held as a single controlled register across the whole project:

ScopeI/O points
New CENTUM VP — CCR-2 and CCR-1 groups26,518
New CENTUM VP — CCR-4 group (gasification and hydrogen)13,292
Expansion of the existing legacy DCS — CCR-2 scope2,548
Total42,358

The register tracked every unit against every signal type on the project — HART and conventional two-wire analogue input, thermocouple and RTD, externally powered gas detection, analogue output with and without HART, FOUNDATION Fieldbus segments, pulse input, volt-free and relay-isolated digital input, solenoid and 220 V electrical digital output, and RS-485 serial links — so card and barrier counts fell out of it directly instead of being estimated.

Control System Architecture

Every control station was built to the same redundant pattern, so spare parts, drawings and maintenance procedures stayed identical across all seventeen field rooms.

ElementConfiguration
Field control unitAFV30D-S41261, 19-inch rack, duplexed, redundant 220 VAC supplies, G3 coating
Node unitANB10D-427/CU2N and /CU2T, redundant ESB bus and 220 VAC supplies, G3 coating
CPUCPU451 pair-and-spare — two independent MPUs per card compared every scan, two cards in hot standby
MemoryECC RAM with battery backup; data retained 72 hours after total power loss, automatic restart
ESB busRedundant EC401/EC402 coupler in the FCU, SB401 in each node; bump-free changeover with alarm
Node powerDual PW482 modules per nest, fed from two independent UPS systems
I/O redundancyRedundant cards on control and critical loops, in adjacent odd/even slots on the same unit

I/O Card Types

ModelDescriptionChannels
AAI143-H53Analogue input, 4–20 mA with HART, G3 coating16
AAI543-H51Analogue output, 4–20 mA with HART, G3 coating16
ADV151-P53Digital input, G3 coating32
ADV551-P53Digital output, G3 coating32
AAP135-S53Pulse input, G3 coating8
ALR121-S51RS-485 serial communication, G3 coating2 ports

All cards are hot-swappable and all field wiring uses crimped terminations. G3 coating was specified throughout because of the coastal, sulphur-bearing atmosphere.

Network Design

The control network is redundant Vnet/IP; the plant information network is separate Gigabit Ethernet. Vnet/IP runs at 100 Mbps, star topology, full duplex, peer-to-peer between stations, up to 16 domains of 64 stations, certified under IEC/PAS 62405.

Between buildings it runs on rodent-resistant armoured single-mode fibre. Every FAR-to-CCR link uses two independent cable routes — one on overhead tray, one buried — with core allocation fixed project-wide so a single cable strike can never take down both control buses:

NetworkCable routeFibre cores
Vnet/IP Bus 1Overhead tray1 and 2
Vnet/IP Bus 2Buried1 and 2
Plant Ethernet (PCN)Buried3 and 4

Bus 1 and Bus 2 run on physically separate Hirschmann switches fed from separate UPS sources. The network is layered to the Purdue model and ISA-99 from Level 0 to Level 4, with a DMZ at Level 3.5, and a GPS clock gives a common time source across DCS, SIS and packaged systems.

Control cabinet integration workshop with rows of assembled system cabinets
Cabinet integration hall — every cabinet built to the same standard before it ships. Illustration treatment applied to the original project photograph.

Cabinet Design and Integration

Cabinets were standardised on Rittal TS8, 800 × 800 × 2100 mm including plinth (servers 1000 mm deep), RAL 7035. Seven types covered the project:

TypeContents
Power distribution (PDP)Incoming breakers, distribution busbars, MCBs, transfer terminals
System — intrinsically safeDCS nests, cards, 24 VDC supplies, IS barriers
System — non-ISDCS nests, cards, surge protection, isolating relays, terminals
System — relayDCS nests, cards, interposing relays, power supplies
FOUNDATION Fieldbus (FF)Power conditioner motherboards, surge protection, 24 VDC supplies
Network (NET)Layer 2 and 3 switches, GPS clock, firewall, fibre patch panels
Server (SVR)Drawer-mounted servers, integrated KVM, power distribution units

The same integration details were applied to every cabinet built for the project:

  • Dual UPS feeds. Two 220 VAC UPS supplies enter through separate isolators and are distributed independently to nests, 24 VDC supplies, fans and lighting.
  • Thermal management. Bottom-in, top-out airflow — filtered vents 150 mm above the plinth on both doors, four extract fans in the roof.
  • Self-monitoring. Cabinet thermostat and every 24 VDC supply failure contact are hardwired to DI channels, so cabinet health is alarmed on the operator station rather than found on a walk-round.
  • Electrical isolation. An insulating board between body and plinth isolates the enclosure from site steelwork; separate clean-earth and protective-earth busbars inside.
  • Layout discipline. FCU at the top, node units below, maximum five nests per cabinet front, barriers and isolators on the rear mounting plate.

Signal isolators and IS barriers were Pepperl+Fuchs KCD and KC slim-line series, chosen so barrier count matched the channel derating rule below without widening the cabinet.

I/O Allocation Rules

Allocation rules turn a correct parts list into a plant that can be maintained while running. These were fixed before the first card was assigned and applied without exception:

  • I/O from different control groups is placed in different controllers.
  • Signals from redundant or parallel equipment go to different I/O cards, so no single card failure can take out both trains.
  • All I/O for one control loop stays inside one control station.
  • Communication I/O for a unit sits in that unit’s own control station.
  • IS and non-IS signals never share a card.
  • Gas detection signals never share a card with other signal types.

Channel usage was deliberately derated to leave working spares in place from day one:

Card sizeChannels usedIS barriers fitted
32 channel2828
16 channel1414
8 channel77

Third-Party System Integration

SIS, motor control and the packaged systems supplied with major process units all had to appear on the same operator screens.

  • Serial integration. ALR121 RS-485 cards running Modbus RTU, simplex or redundant, connect the DCS to SIS, MCS and package PLCs.
  • Hardwired critical signals. Safety- or availability-critical subsystem signals are hardwired to a DCS I/O card in addition to the serial link, subject to design approval.
  • Instrument asset management. A PRM server on Vnet/IP collects HART data from smart instruments through the AAI143-H and AAI543-H cards.

Spare Capacity Policy

Spare capacity is a commercial decision, not a technical one — it sets what the next revamp costs. These figures were fixed in the hardware specification and held through detailed design:

ItemReserve
Spare I/O channels20 %
Spare cabinet mounting space20 %
Controller load ceiling60 % of total processing capacity
Network spare capacityNot less than 60 % of total capacity
Power supply margin40 %

Testing and Handover

Hardware acceptance ran in three stages, each with an approved procedure and signed records: an internal 100 % test of the integrated system against the project specification before the client was invited; a factory acceptance test witnessed by the design institute and the owner; and a site acceptance test after cabinets were set and field wiring terminated.


What This Project Demonstrates

Most plants are not 42,000 points. But what was hard here is what is hard on a 2,000-point revamp:

  • A controlled I/O register is the backbone. Controller sizing, cabinet count, barrier count, network load and domain allocation all derive from it. If it is not controlled, nothing downstream is.
  • Segregation rules must be set before allocation starts. Retrofitting IS/non-IS and gas-detection separation after cards are assigned means rebuilding cabinets.
  • Redundancy has to be traced end to end. Redundant CPUs are worthless if both fibre routes share a trench, or both node supplies come off the same UPS.
  • Spare capacity is cheapest at design stage. 20 % spare channels and mounting space cost little while the cabinet is being built, and a great deal afterwards.

The cabinet integration and the system configuration and commissioning described on this page were performed by members of the neoDrive engineering team. Design authority for the control system rested with the project’s main automation vendor. The client has not authorised disclosure of its identity, so the project is described by industry, region and scale.


Discuss a Control System Project

Planning a DCS revamp, a greenfield control system, or cabinet integration for a package? Tell us the plant, the approximate I/O count and the platform. We will arrange a technical discussion with an engineer rather than a sales call.

Related pages: DCS Engineering and Configuration · Control Cabinet Design and Integration

Engineering Configuration Enquiry
Scroll to Top