{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp11_mechanism_context_external20_20260804","research_id":"eoa_inverse_innovation_exp11_external_scrutiny_20260804","cell_id":"deadweight_loss_reduction__systems_cybernetics","opaque_id":"deadweight_loss_reduction__systems_cybernetics__B","search_lanes":{"direct_problem":{"queries":["safety instrumented system nuisance trips dynamic trip setpoint state dependent interlock redundant sensors","adaptive protection system nuisance trip operating condition trip logic","nuisance trip decision management multiple sensors allow avoid tripping"],"source_ids":["SRC1","SRC4","SRC5"],"no_result_note":null},"closest_prior_art":{"queries":["dynamic trip setpoints process safety instrumented system operating mode","adaptive protection systems setting groups operating state primary research nuisance tripping","Simplex architecture safety controller advanced controller runtime assurance operating envelope"],"source_ids":["SRC1","SRC4","SRC5","SRC6","SRC8"],"no_result_note":null},"historical_terminology":{"queries":["operational permissive circuit reactor protection spurious trip redundant signal voting","1990s Simplex architecture dependable process-control safety region","older terminology spurious trip coincidence logic operating inhibit protection system"],"source_ids":["SRC1","SRC6","SRC8"],"no_result_note":null},"products_practices_standards":{"queries":["IEC 61511 nuisance trip voting architecture bypass override safety instrumented system","site:iec.ch IEC 61511 safety instrumented systems process industry official","motor protection configurable operating modes trip timeout custom logic"],"source_ids":["SRC1","SRC2","SRC3","SRC7"],"no_result_note":null},"non_english_regional":{"queries":["déclenchements intempestifs système de protection logique de vote signaux redondants permissif","Fehlauslösung Sicherheitsabschaltung redundante Sensoren 2oo3 Voting Störabschaltung","disparo espurio sistema instrumentado seguridad votación 2oo3 sensores redundantes","误动 自适应保护 运行方式 定值组 继电保护"],"source_ids":["SRC1","SRC3"],"no_result_note":"A French IAEA safety guide was retained because it directly addresses spurious trips, redundant-signal voting, parameter validation, and operational permissives. Other regional-language results were not retained under the eight-source limit."},"composition_subproblems":{"queries":["redundant sensor voting plus operational permissive hard safety limits","state monitoring adaptive protection setting group validation","runtime assurance certified baseline controller safety invariant rollback","shadow testing adaptive protection nuisance trips"],"source_ids":["SRC1","SRC3","SRC5","SRC6","SRC7","SRC8"],"no_result_note":null}},"sources":[{"source_id":"SRC1","title":"Systèmes d’instrumentation et de contrôle-commande importants pour la sûreté des centrales nucléaires — Guide de sûreté NS-G-1.3","url":"https://nucleus.iaea.org/sites/committees/Policy%20Documents/Complete%20Collections%20of%20Safety%20Standards/Complete%20collection%20French/Superseded%20Standards%20French/NS-G-1.3.pdf","publisher":"International Atomic Energy Agency","date_or_year":"2002","source_type":"OFFICIAL_GUIDANCE","language":"French","claims_supported":["Spurious protective trips can cause unnecessary equipment stress, additional safety actions, loss of operator confidence, and lost generating capacity.","Recommended countermeasures include online signal filtering, parameter validation, and voting logic over redundant signals.","Operational permissives are an established protection-system mechanism for inhibiting unnecessary protective actions during authorized operating-state transitions.","Permissive conditions must be enforced automatically and the permissive remains part of the protection system and its safety requirements.","Safety documentation should specify thresholds for each applicable operating mode and authorized bypass conditions."]},{"source_id":"SRC2","title":"IEC 61511-1:2016 — Functional safety: Safety instrumented systems for the process industry sector, Part 1","url":"https://webstore.iec.ch/en/publication/24241","publisher":"International Electrotechnical Commission","date_or_year":"2016; amended 2017","source_type":"OFFICIAL_STANDARD","language":"English/French","claims_supported":["IEC 61511-1 supplies lifecycle requirements for specification, design, installation, operation, and maintenance of process-industry safety instrumented systems.","A modified state-conditioned safety function must remain within formal functional-safety lifecycle and assurance requirements rather than being treated as an ordinary control optimization."]},{"source_id":"SRC3","title":"Common Inspection Criteria: Safety Instrumented Functions","url":"https://minerva.jrc.ec.europa.eu/en/shorturl/technical_working_group_2_seveso_inspections/cic_safety_instrumented_functions","publisher":"European Commission Joint Research Centre, MINERVA","date_or_year":"2023","source_type":"OFFICIAL_GUIDANCE","language":"English; German version also offered","claims_supported":["Operators are identifiable owners of SIF identification, documentation, effectiveness, and testing duties.","SIF logic may include sensor and final-element voting, fault tolerance, redundant elements, and online diagnostics comparing sensor readings.","Sensor independence and common-component failure are explicit safety concerns.","Modifications require management of change, testing, documentation updates, and assessment of reliability, effectiveness, and newly introduced risks.","Temporary deactivation requires formal line-management permission and compensating measures."]},{"source_id":"SRC4","title":"Nuisance trip decision management using data analytics in electrical protection system — U.S. Patent 12,088,089","url":"https://patents.justia.com/patent/12088089","publisher":"ABB Schweiz AG; patent text hosted by Justia","date_or_year":"priority 2020; filed 2021; issued 2024","source_type":"OTHER","language":"English","claims_supported":["The disclosed system uses multiple sensors, stored nuisance-trip history, neighboring-system data, and hybrid machine learning to classify nuisance-trip conditions.","A protection microcontroller conditionally allows or avoids tripping while defaulting to trip for unconfirmed nuisance conditions.","The patent describes state evidence including thermal data, voltage, frequency, load characterization, power-flow direction, and upstream/downstream protection context.","This is a close collision with the proposed generic lever of corroborated state evidence deciding whether a trip should be admitted."]},{"source_id":"SRC5","title":"Facilitating the Validation of Adaptive Power System Protection through Formal Scheme Modelling and Performance Verification","url":"https://strathprints.strath.ac.uk/45538/1/T13511.pdf","publisher":"University of Strathclyde","date_or_year":"2013","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Adaptive protection dynamically changes active settings using protection-system state and primary-system state.","The studied logic monitors plant status, loading, breaker status, and operating mode and activates an appropriate settings group.","Validation difficulty, poorly understood benefit-risk tradeoffs, and industry conservatism are documented barriers.","The work supports formal modeling and performance verification as bounded evidence steps before adoption."]},{"source_id":"SRC6","title":"An Architectural Description of the Simplex Architecture","url":"https://www.sei.cmu.edu/library/an-architectural-description-of-the-simplex-architecture/","publisher":"Software Engineering Institute, Carnegie Mellon University","date_or_year":"1996","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["Simplex is a longstanding architecture for dependable, evolvable process-control systems.","It provides historical prior art for pairing higher-performance control with a high-assurance safety subsystem and formally analyzing safety and liveness."]},{"source_id":"SRC7","title":"TeSys T LTMR Motor Management Controller User Guide — Motor Protection Functions","url":"https://productinfo.se.com/tesys_t_user_guides/doca0127-tesys-t-ltmr-motor-management-controller-user-guide/English/BM_TeSys%20T%20LTMR%20User%20Guide_53457272_T001010654.xml/$/CHP_MotorProtectionFunctions_53457272_T001010712","publisher":"Schneider Electric","date_or_year":"2024","source_type":"FIRST_PARTY_PRODUCT","language":"English","claims_supported":["A commercial motor-management controller monitors several electrical and thermal parameters and records trips by protection function.","The product supports predefined and customized operating modes, configurable trip responses, thresholds, delays, inverse trip curves, hysteresis, and state-dependent startup deferral.","The guide demonstrates that protection behavior conditioned on operating mode, thermal state, and transient duration is implemented in commercial equipment.","The guide warns that emergency restart or altered protection settings can cause injury or equipment damage, underscoring the need for controlled authority."]},{"source_id":"SRC8","title":"A Component-Based Simplex Architecture for High-Assurance Cyber-Physical Systems","url":"https://arxiv.org/abs/1704.04759","publisher":"arXiv; authors from academic and aerospace research institutions","date_or_year":"2017","source_type":"PRIMARY_RESEARCH","language":"English","claims_supported":["A monitored state-dependent decision module can permit a high-performance controller while a pre-certified baseline controller keeps the plant inside a prescribed safety region.","The architecture switches to the baseline controller when the state is near leaving the safe region and supports formally proved global invariants.","This supplies close compositional prior art for state-conditioned operation with a certified fallback and hard safety properties."]}],"problem_evidence":{"status":"SUPPORTED","finding":"The problem exists. IAEA guidance explicitly identifies spurious protection trips as a cause of equipment stress, extra safety actions, lost operator confidence, and lost production, and recommends minimizing them without weakening protection. Commercial motor protection records trips and incorporates transient-aware delays and state-dependent protection behavior. Adaptive-protection research likewise documents shortcomings of fixed protection under changing operating states.","source_ids":["SRC1","SRC5","SRC7"],"uncertainty":"The sources establish the general problem across nuclear, electrical-power, and motor-control contexts, but do not establish its frequency, economic magnitude, or causal mix for any particular candidate unit. Some apparent nuisance events may correctly anticipate hazards or arise from sensor faults better addressed by calibration."},"adopter_evidence":{"status":"SUPPORTED","finding":"An identifiable adopter and authorizer exist: the operating organization and accountable SIF/protection owner, with line-management, functional-safety, regulatory, or independent-review approval as applicable. European Commission guidance assigns operators explicit duties for documentation, testing, modification control, and formal permission for deactivation.","source_ids":["SRC2","SRC3","SRC5","SRC7"],"uncertainty":"The exact legal authorizer varies by sector and jurisdiction; a specific facility, regulator, and safety case were not supplied."},"implementation_evidence":{"status":"SUPPORTED","finding":"The principal implementation mechanisms are already demonstrated or prescribed: redundant-signal voting, parameter validation, operational permissives tied to operating modes, adaptive protection settings, commercial custom trip logic, and certified fallback architectures. The evidence supports technical feasibility and real practice, but not the performance of an unspecified new envelope on a particular asset.","source_ids":["SRC1","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"],"uncertainty":"No retained source validates the proposal's exact 30-day shadow protocol, its unspecified state variables, independence model, adjudication procedure, or noninferiority margins on a named unit."},"prior_art":{"disposition":"ESTABLISHED_PRACTICE","closest_analogues":[{"name":"IAEA redundant voting, parameter validation, and operating permissives for reactor protection","source_ids":["SRC1"],"same_problem":true,"same_causal_lever":true,"overlap":"The guide addresses unwanted protective trips, their availability and behavioral costs, corroboration through redundant-signal voting and validation, and state/mode-conditioned permissive circuits that inhibit unnecessary actions while remaining inside the protection system.","remaining_difference":"The proposal adds a particular shadow-first, rollback-oriented evaluation wrapper and extends the framing beyond nuclear plants, but it does not specify a new permissive logic, state estimator, or independence proof."},{"name":"ABB nuisance-trip decision management using contextual data analytics","source_ids":["SRC4"],"same_problem":true,"same_causal_lever":true,"overlap":"It directly classifies valid versus nuisance trip conditions from multiple and neighboring measurements and conditionally allows or avoids tripping, with a conservative response to uncertainty.","remaining_difference":"The proposal emphasizes independent hard limits, non-actuating shadow evaluation, burden monitoring, and automatic rollback; those exact governance constraints are not the patent's central claim."},{"name":"Adaptive power-system protection with dynamic setting groups","source_ids":["SRC5"],"same_problem":true,"same_causal_lever":true,"overlap":"Protection logic monitors operating and protection state, then dynamically selects settings to preserve protection performance under changing conditions; formal modeling and validation address adoption risk.","remaining_difference":"The thesis concerns power-system relay settings rather than a generic industrial interlock and reports that adaptive protection was not then a universal industry policy."},{"name":"Simplex and Component-Based Simplex runtime assurance","source_ids":["SRC6","SRC8"],"same_problem":false,"same_causal_lever":true,"overlap":"State monitoring permits higher-performance operation while a certified baseline controller and proved safety region preserve hard invariants and provide fallback.","remaining_difference":"Simplex primarily addresses assurance of advanced controllers, not adjudicated nuisance trips from coarse static interlocks."},{"name":"Commercial configurable, mode- and transient-aware motor protection","source_ids":["SRC7"],"same_problem":false,"same_causal_lever":true,"overlap":"The product conditions trip behavior on multiple measurements, operating modes, thermal state, timing, hysteresis, and customized logic while retaining defined protection functions.","remaining_difference":"The guide does not claim the full governance package or quantify reductions in retrospectively adjudicated nuisance trips."}],"contrastive_claim_remaining":"Only a context-specific incremental claim remains credible: for one named unit and a preregistered set of benign transients, a specified new evidence-fusion envelope using demonstrably independent inputs will reduce blinded-adjudicated false trips relative to the certified baseline while meeting a preregistered noninferiority margin for hazardous-state detection, detection margin, operator burden, and protected-party risk. The generic mechanism—state/mode-conditioned permissives using redundant evidence with retained safety protection—is not distinct.","contrastive_claim_falsifier":"Falsify the remaining claim if blinded replay finds negligible recoverable false trips; if the new envelope does not reduce false trips; if any hazardous event accepted by the new envelope would have tripped the baseline; if input failures are materially correlated; if detection margin or operator burden breaches its bound; or if the claimed safe states cannot be justified under the applicable safety lifecycle and authorization regime.","confidence":"HIGH","search_limitations":"This was a bounded eight-source search. The full paid text of IEC 61511 was not reviewed beyond the official IEC description; patent-family and citation searching was not exhaustive; regional searching retained one directly probative French source; and no facility-specific trip logs, safety case, regulatory license, or product configuration were available. Results cannot establish world novelty, patentability, freedom to operate, market size, routine prevalence in every safety-critical sector, or realized impact."},"researchability_gates":{"externally_supported_problem":{"status":"PASS","rationale":"Official IAEA guidance directly recognizes spurious trips and their equipment, behavioral, and production consequences; adaptive-protection research and commercial protection documentation corroborate the underlying setting/transient problem.","source_ids":["SRC1","SRC5","SRC7"]},"identifiable_adopter_or_authorizer":{"status":"PASS","rationale":"The operating organization and accountable protection/SIF owner are identifiable, and official guidance locates modification, testing, and temporary-deactivation authority in documented management and safety processes.","source_ids":["SRC2","SRC3"]},"distinct_testable_incremental_claim":{"status":"PASS","rationale":"Although the generic intervention is established, a narrow site-specific performance claim remains testable if it names the unit, eligible transients, evidence inputs, independence assumptions, and noninferiority bounds. It should not be represented as a novel generic mechanism.","source_ids":["SRC1","SRC4","SRC5","SRC8"]},"bounded_next_evidence_step":{"status":"PASS","rationale":"A one-unit, non-actuating shadow replay is bounded and consistent with the strong external emphasis on formal validation, full-function testing, documentation, and management of change. It can be halted without changing certified actuation.","source_ids":["SRC3","SRC5"]},"no_unresolved_safety_or_authority_stop":{"status":"PASS","rationale":"There is no evident stop for a read-only shadow evaluation if approved data handling and safety governance are followed. Live logic modification would require a safety lifecycle, management of change, proof of input independence, full testing, and appropriate authorization; bypassing hard limits remains excluded.","source_ids":["SRC1","SRC2","SRC3","SRC7","SRC8"]},"adequate_search_evidence":{"status":"PASS","rationale":"All six lanes were searched adversarially using direct, historical, standards/product, regional-language, and component-combination terminology. Exactly eight opened sources span IAEA, IEC, the European Commission, ABB, Schneider Electric, two universities, and SEI, with multiple official, primary, and first-party sources.","source_ids":["SRC1","SRC2","SRC3","SRC4","SRC5","SRC6","SRC7","SRC8"]}},"strict_success":false,"screen_survival":false,"remaining_research_value":"MODERATE","recommended_next_step":"Reframe the work as site-specific validation rather than invention of the generic mechanism. Select one named unit and transient class; obtain accountable safety-owner approval; freeze the certified interlock; preregister blinded trip adjudication, input-independence checks, hazardous-detection noninferiority margins, workload and protected-party bounds, and halt criteria; then run a non-actuating replay/shadow comparison. Do not proceed to live permission unless the change completes the applicable safety lifecycle and management-of-change process.","world_novelty_boundary":"The search supports an established-practice finding for the broad problem–intervention package, not a universal claim that every implementation detail is old. It cannot establish world novelty, patentability, freedom to operate, market size, realized impact, or absence of undiscovered prior art. Any defensible novelty boundary would have to lie in a fully specified asset-specific envelope, independence argument, validation method, or governance implementation—not in the generic idea of reducing nuisance trips through redundant, state-conditioned permissives while retaining certified safety protection."}