BTT-304  |  Control-to-Protection InterfacesModule 17 of 48 · Track 3 — Governor & Control Systems
≡ Course Index
EHC CONTROL SYSTEM (MODULES 3.1–3.3) INDEPENDENT TRIP/PROTECTION SYSTEM TRIP SOLENOID / DUMP VALVE PERMISSIVE INTERLOCKS WHY SEPARATION MATTERS
Select a component
Tap any element in the steam path
Click any component above to see how control and protection stay separate but interface where it matters.

Control-to-Protection Interfaces

Track 3 · Module 4 — Governor & Control Systems

Two Systems, Not One

Modules 3.1 through 3.3 covered the EHC control system in depth — the system that handles normal, everyday speed and load control. This module introduces a critical design principle: the control system is deliberately kept separate from the protection system that handles genuinely dangerous conditions. Understanding how these two systems interface — without being the same system — is essential before this course covers trip and protection logic in depth in a later track.

Different Jobs, Different Systems

The EHC control system is built to keep the turbine operating smoothly within normal bounds — modulating governor valves to track speed and load reference through everyday conditions. The trip/protection system has a completely different job: detecting genuinely dangerous conditions (overspeed, low lube oil pressure, high vibration, thrust bearing failure, and others) and rapidly shutting off steam entirely by closing the stop valves — the same fast-acting stop valve first introduced in Module 1.1, distinct from the modulating governor valve.

These aren't just different logical functions within one system — they're deliberately separate systems, often with different sensors, different logic paths, and sometimes different power supplies entirely. This separation exists so that a fault in the control system (a software bug, a sensor failure, a servo valve malfunction) can't simultaneously disable the protection system's ability to trip the unit when it genuinely needs to.

Key Relationship

The control system optimizes normal operation; the protection system exists purely to stop the turbine when normal operation isn't safe anymore. Keeping them independent means a failure in the "optimize" function can't compromise the "stop it" function.

How a Trip Actually Closes the Valves

When the protection system detects a trip condition, it acts through a trip solenoid (or dump valve) that rapidly releases hydraulic pressure from the stop valve actuating system. Rather than actively driving the valve closed the way a governor valve modulates position, this mechanism removes the force holding the stop valve open, allowing spring force or an equivalent fail-safe mechanism to slam it shut.

This is a fundamentally different mechanism than normal control modulation, and it's deliberately designed that way: the system fails toward the safe (closed) state. If hydraulic pressure or electrical power is lost entirely — the worst-case failure scenario — the stop valves close rather than staying open. Trip systems are described as "fail-safe" by design, not by coincidence.

Why This Matters On Shift

A trip isn't the control system "deciding" to close the valve through its normal logic — it's an entirely separate physical mechanism removing the force that holds the valve open. Understanding this distinction matters when troubleshooting: a control system malfunction and a genuine protection trip look very different in cause, even if the immediate symptom (valve closing) looks similar.

Permissive Interlocks — Where the Two Systems Actually Talk

The protection system doesn't only act reactively through trips — it also provides permissive interlocks to the control system: conditions that must be satisfied before the control system is allowed to take certain actions in the first place. Module 2.6's turning gear engagement interlock is a direct example of this in action — the protection/interlock logic prevents the control system from admitting steam while turning gear is engaged, and prevents turning gear engagement while steam conditions aren't appropriate. This is the legitimate, designed interface point between the two systems: permissions granted or withheld, rather than the protection system's trip logic being folded into normal control.

Glossary

Module Quiz

6 questions · 80% required to pass
0%
Your Score