CTRL Tunnel Ventilation Control

//CTRL Tunnel Ventilation Control
CTRL Tunnel Ventilation Control 2017-11-15T15:04:22+00:00


Project Date: 2004 – 2007

End User: Network Rail (HS1)

Client: Network Rail (HS1)


SCADA: Mitsubishi Citect MX4

PLC: Mitsubishi Q Series


Site Surveys

System Architecture Design

Network Infrastructure Design

Software Development

SCADA Systems Integration

CAD Drawings

Containment Systems Design


Electrical Services

Testing and Commissioning

Network Rail: CTRL Tunnel Ventilation Control

Ematics provided specialist software engineering and systems assurance for implementation of the Ventilation Control System for the three Channel Tunnel Rail Link (CTRL) tunnels.

The primary function of the tunnel VCS is to supply air or extract air from the tunnels in the event of an incident as well as perform tunnel ventilation during normal train operations. The system was deemed to be safety critical, thus system development had to follow strict software assurance guidelines and was subject to regular audits to ensure that the system met the required operational safety criteria.

The following systems and services have been designed and installed:

  • Mitsubishi PLC Control System
  • Citect SCADA System.
  • Remote Monitoring.
  • SIL 2 & 3 Development.
  • High Availability Systems.
  • Project Design
  • Installation, Testing, Commissioning.
  • Audit and Obsolescence Study .
  • Integrated Central Database.
  • Training
The system architecture comprised redundant PLC’s at the plant control level and Citect MX4 SCADA system to provide the overall operator monitoring and control functionality. All PLC and SCADA software was developed in accordance with the systematic requirements of BSEN51028 SIL3 requirements employing approved configuration management systems and procedures.The systems were connected in duty standby arrangement and provided control and monitoring from a number of vent shaft and portal locations across the tunnel sections.

SCADA System

The SCADA system was designed and developed in accordance with SIL 2 and provides the supervisory layer of the architecture and is designed to ensurectrl_vcs_scada01 optimal availability by operating on a dual-redundant basis. The SCADA servers handle all the core SCADA tasks such as communications (master PLCs, RCCS and EMMIS), alarm and event logging, data logging, trending and Archiving and provide this data to the client workstations over the network.

The SCADA Servers communicate with the Clients via a dedicated SCADA Ethernet LAN, configured to provide dual network connections to each workstation in order to provide greater resilliance during a network failure.Each client and server will reside in a network segregated SCADA VLAN top provide a level of storm protection for the SCADA communications.
Three dedicated SCADA Client workstations are installed to provide operator functionality such as Supervisor, Controller and Maintenance however any workstation can be used for any operator task in the event of a workstation failure. Each Client workstation has its own local configuration for graphics, alarm viewing and database browsing depending on the operator function desired. 


The SCADA is also used to monitor the network and the availability of each of the PLC & SCADA systems and will provide alarms indocating when the minimum required operating availability to achive a safe haven are being reached in order to prevent any unplanned tunnel closures.







PLC System

Designed and developed in accordance with SIL 3, a duty/standby pair of Mitsubishi “Q” series PLC’s have been installed perform supervisory contol and toctrl_vcs_plc01-2 accept pushbutton requests for safe haven control in the event of the unavailability SCADA system.These “Master” PLCs will distribute control commands to a number of PLC tunnel outstations PLCs and gather and co-ordinate status information for display by the SCADA.
Two manual override “Pushbutton Stations” are provided in the main control room, each consisting of a number ctrl_vcs_plc03of pushbuttons and lamps and wired in duplex for redundency.
These will be used to initiate and monitor safe haven control in the event of an incident in the unlicky event that the SCADA system is unavailable.These panels are located on the operator control desk and only designed for use during a main SCADA system failure.
A number of Forward Incident Control Panels (FICPs) have been installed at each of the tunnel portals and provide a mimic depicting the current ventilationctrl_vcs_plc02 status for their respective tunnel bores.Each FICP has is driven by a Mitsubishi Q series PLC with the appropriate I/O cards to drive the LEDs on the mimic as weel as an Ethernet communications adapter to enable communications to the Master PLC’s.