.1 For equipment class 1, the DP-control system
need not be redundant.
.2 For equipment class 2, the DP-control system
should consist of at least two independent computer systems. Common
facilities such as self-checking routines, data transfer arrangements,
and plant interfaces should not be capable of causing the failure
of both/all systems.
.3 For equipment class 3, the DP-control system
should consist of at least two independent computer systems with self-checking
and alignment facilities. Common facilities such as self checking
routines, data transfer arrangements and plant interfaces should not
be capable of causing failure at both/all systems. In addition, one
back-up DP-control system should be arranged, see 3.4.2.6. An alarm
should be initiated if any computer fails or is not ready to take
control.
.4 For equipment classes 2 and 3, the DP-control
system should include a software function, normally know as `consequence
analysis', which continuously verifies that the vessel will remain
in position even if the worst case failure occurs. This analysis should
verify that the thrusters remaining in operation after the worst case
failure can generate the same resultant thruster force and moment
as required before the failure. The consequence analysis should provide
an alarm if the occurrence of worst case failure would lead to a loss
of position due to insufficient thrust for the prevailing environmental
conditions. For operations which will take a long time to safely terminate,
the consequence analysis should include a function which simulates
the thrust and power remaining after the worse case failure, based
on manual input of weather trend.
.5 Redundant computer systems should be arranged
with automatic transfer of control after a detected failure in one
of the computer systems. The automatic transfer of control from one
computer system to another should be smooth, and within the acceptable
limitations of the operation.
.6 For equipment class 3, the back-up DP-control
system should be in a room separated by A.60 class division from the
main DP-control station. During DP-operation this back-up control
system should be continuously updated by input from the sensors, position
reference system, thruster feedback, etc., and be ready to take over
control. The switch-over of control to the back-up system should be
manual, situated on the back-up computer and should not be affected
by failure of the main DP-control system.
.7 An uninterruptable power supply (UPS) should
be provided for each DP-computer system to ensure that any power failure
will not affect more than one computer. UPS battery capacity should
provide a minimum of 30 minutes operation following a mains supply
failure.