On a ship that handles dry bulk cargo, the dust collection plant is classified as protective equipment. It protects lungs, it protects machinery and navigational aids, and it protects the accommodation. Follow what it physically does, however, and a different picture emerges: it takes combustible dust that was dispersed across holds and decks and gathers it into a single sealed enclosure.

IEC 60079-10-2 classifies areas by how often an explosive dust cloud is present. Its example of Zone 20 — the most severe class, where a dust cloud is present continuously, for long periods, or frequently — is the inside of a dust collector hopper. A dust explosion needs five things: fuel, oxygen, an ignition source, dispersion, and confinement. This system supplies the confinement and concentrates the fuel.

Of six component typologies, only three are cyber-relevant. The fan, the ducting and the rotary airlock have no interfaces, no firmware and no accounts. Yet the fan holds no authority at all while touching the physical process directly. That asymmetry is the key to reading this system.

1. Why this system exists

Grain, cement, coal, ore concentrates, fertiliser — dry bulk cargo generates dust whenever it is moved. Dust rises when a grab releases its load, when a conveyor hands cargo across a transfer point, when a pneumatic line blows product into a tank. That dust does damage along three paths.

        Cargo handling (grab / conveyor / pneumatic transfer)
                         |
                    Dust generation
                         |
        +----------------+----------------+
        |                |                |
   Human airway     Machinery &      Accommodation &
   exposure         nav equipment    interior spaces
        |                |                |
   Chronic /        Bearing wear,     Habitability,
   acute health     sensor fouling    contamination
   effects
        |
   (if concentration and ignition source coincide)
        |
   Dust explosion  -> IMSBC Code 3.4.1
Operational context diagram: a transfer point above a cargo hold generating dust, with a dust collection system capturing it at source on the left and the accommodation protected under IMSBC 2.2.5 on the right, plus the three damage paths if dust is not captured.
Figure 1. Dust is generated at the transfer point. IMSBC 2.2.5 closes the accommodation off; this system extracts at the source instead.

The IMSBC Code addresses each path in a different clause. Section 3.3, Health hazards due to dust, requires a high standard of personal hygiene together with appropriate breathing protection, protective clothing, washing and laundering, to reduce the chronic and acute risks of exposure. Section 3.4.1, Flammable atmosphere, goes further: the dust of some solid bulk cargoes may constitute an explosion hazard, particularly during loading, unloading and cleaning. The measures it names are ventilation to prevent a dust-laden atmosphere forming, and hosing down rather than sweeping. Section 2.2.6 asks that consideration be given to minimising the extent to which dust reaches the moving parts of deck machinery and external navigational aids. Verified

The third path — ingress into living spaces — reveals what kind of system this is. Section 2.2.5 requires that, as far as practicable, ventilation systems be shut down or screened and air conditioning placed on recirculation during loading or discharge, to minimise dust entering the accommodation and other interior spaces.

That is a defensive measure. It closes doors. The dust collection plant stands on the opposite side of the same problem: it extracts at the source. The two clauses have to be read as a pair before the system's place becomes visible. Where 2.2.5 says keep it out, this plant says stop it spreading in the first place — and the better it succeeds, the less work 2.2.5 has to do.

2. What the system actually does

"Dust collection" sounds like a single action. At system level it is five processes in series.

  Dust source
       |
  [1] Capture        Hood / pickup point at the transfer point
       |
  [2] Conveyance     Ducting under negative pressure, fan-driven
       |
  [3] Separation     Cyclone -- coarse particles fall out first
       |
  [4] Filtration     Bag / cartridge element -- fine particles retained
       |
  [5] Discharge      Rotary airlock -> collected dust back to cargo or to a bin
       |
  Clean air out

Each stage fails differently, and each has a different degree of cyber relevance.

Capture is pure fluid mechanics. If the hood covers the source and the face velocity is adequate, the dust is caught. There is no electronic element in this stage at all.

Conveyance happens through the negative pressure the fan creates. Ducting is only a path, but when velocity falls, dust settles inside the duct — and that deposit becomes a problem later.

Separation is the cyclone dropping coarse particles out by centrifugal action before they reach the filter. It is a pre-stage that reduces the load on the filter media, with no moving parts and no signals.

Filtration is the heart of the system. As a dust layer — the filter cake — builds on the media, filtration efficiency actually improves, but pressure loss rises with it. So the cake must periodically be shaken off. Deciding when to do that is the only substantive control judgement this system makes.

Discharge is the rotary airlock's job. Its purpose is not merely to move dust out; it is to move dust out while preventing air from flowing back in. Rotating vanes always keep one side closed, so the system's negative pressure is maintained. If the airlock seizes, the hopper fills; when the hopper fills, it drowns the lower filter area.

3. Core functions and operating modes

This system is subordinate to cargo work. No cargo movement, no dust.

Mode Fan Cleaning Airlock Governing condition
IdleStoppedOffStoppedNo cargo operation
HandlingRunningOnline periodicRunningLoading or discharge in progress
CleaningRunning or stoppedPulse firingRunningΔP threshold reached, or timer
MaintenanceStopped, isolatedManualStoppedElement replacement, inspection

What matters here is that cleaning exists as a mode of its own. It comes in two forms. Online cleaning pulses the elements in sequence while the fan keeps running; offline cleaning shuts the plant down first. Online cleaning avoids interrupting cargo work, but some of the dislodged dust is drawn straight back onto the media — re-entrainment — which costs efficiency.

That looks like a purely engineering trade-off. It becomes a security question later, because the cleaning method and its intervals are settable parameters.

4. How the result is produced

This system has a single governing variable: the differential pressure across the filter element.

  Filter cake thickness  (physical, unobservable directly)
             |
             v
  Differential pressure across the element  (the only observable)
             |
      4-20 mA / switch contact
             |
             v
  Control panel comparison against threshold
             |
      +------+------+
      |             |
  below         above
      |             |
  keep running  trigger pulse-jet cleaning
                     |
                  compressed air valve fires
                     |
                  cake dislodged -> hopper -> rotary airlock
                     |
                  Delta-P falls -> cycle ends

ΔP expresses two things at once: filtration performance (how blocked the media is) and accumulation (how much has built up). These are two faces of the same physical quantity, which is why one number tells you the state of the plant — and why, if that one number is wrong, you do not know the state of the plant at all.

5. What the system is made of

The brief resolves the composition into six typology rows.

Typology Equipment kind Component Purdue CBS (E26) Evidence
TYP-C04Fan / blowerDust extraction fansL0 — physical processNTYPICAL
TYP-A08Filter / strainerBag filter / cyclone separatorL0 — physical processY — within parent CBSTYPICAL
TYP-A01Piping, ducting and fittingsExtraction ducts and hoodsL0 — physical processNTYPICAL
TYP-A05Mechanical machine / toolRotary airlock / dust discharge unitL0 — physical processNTYPICAL
TYP-B02Process transmitter / sensorDifferential-pressure sensorsL1 — sensingY — within parent CBSINFERRED
TYP-B08HMI / operator console / panelDust-control panelL2 — supervisoryY — list separatelyTYPICAL

Four of the six rows sit at Purdue L0 — the physical process itself. One is L1 sensing, one is L2 supervisory. Only three are CBS candidates.

The distribution says something plainly: most of this system is not a cyber object. The fan is a machine turned by a motor. The ducting is a path air travels through. The rotary airlock is a valve rotated by an electric motor. None of the three has firmware, an account, or a communication port.

6. Typology profiles — why component count is not the measure

TYP-C04, fan / blower. The final element that creates negative pressure. Per the cached doctrine, fans and blowers are not programmable electronic devices and therefore do not satisfy the CBS definition in IACS UR E26 §2. Speed selection, reversal and interlocks belong to the starter panel or control panel, not to the fan. The fan exercises no operational authority over anything (A0). Where a variable-speed fan is driven by a VFD, that drive is the programmable element — and that is a different typology's problem.

TYP-A08, filter / strainer. The cache treats this typology as a SPLIT. A manual strainer is a wholly passive pressure part, so A0. But a unit with an automatic cleaning control box exercises genuine closed-loop CONTROL (A5) over its own actuators, because the box starts, sustains and ends the cleaning cycle itself on a differential-pressure threshold or a timer. Pulse-jet cleaning in a dust collector is exactly this structure. The SPLIT must not be averaged away: under one name sit items whose authority is A0 and items whose authority is A5.

TYP-A01, piping and ducting. Carrying fluid is mass transfer, not data transfer. E26 §1.3.2 a) defines in-scope OT as CBSs using data to control or monitor physical processes, and §2 defines a CBS as a programmable electronic device. Ducting has neither data nor a programmable element, so it exercises no authority in any direction. Where a duct run appears to be instrumented, the intelligence belongs to the transmitter attached to it.

TYP-A05, mechanical machine. The rotary airlock belongs here. Start and stop commands arrive from a parent starter panel or PLC (A4 inbound), while the local operator holds the local starter and the emergency stop. IEC 60204-1 stop category 0 is an uncontrolled stop by immediate removal of power from the actuators, and the safety function acts directly on the power-removal path, bypassing the drive or motion controller — typically implemented with hardwired electromechanical components such as contactors, with restart possible only after a manual reset. The final stopping path in this family therefore does not pass through software by design.

TYP-B02, process transmitter. The differential-pressure sensor. It sits at Purdue L1, observes only, and exerts no force on the process (A1); it provides its value to the panel (A2). Inbound, however, range and span changes through a HART handheld or a service laptop constitute A3, and depending on the model, firmware replacement constitutes A7. The evidence grade for this typology is INFERRED Inferred — its register is unpopulated and the doctrine is inherited from sibling typologies, so nothing derived from it can be stated more strongly than an inference.

TYP-B08, HMI / control panel. The dust-control panel. Purdue L2, supervisory, and the only element in this system classified as a separately listed CBS. It directs the cleaning programme and sequence (A4) and sets parameters and alarm limits (A3). The closed loop is closed by the controller beneath it, so it is not A5.

7. Where the supply boundary falls

The most consequential register value for this system is Typical supply: "Either". The same nominal equipment becomes two quite different things depending on the project.

Owner-specified and yard-integrated, the fan, ducting, filter and airlock are ordered as individual items and integrated into the ship's switchboards and automation. Control becomes part of the ship's IAS or cargo control system, and configuration management stays with the integrator.

Delivered as a package, the vendor supplies a skid complete with its own control cubicle. In that case the parameters, firmware and diagnostic ports inside that cubicle belong to the vendor, and maintenance access opens along a vendor path.

That difference is a trust boundary that has nothing to do with where a firewall sits. Administrative ownership, privilege and update path all change at that line.

There is a familiar trap. The control cubicle can be absorbed into the parent package and appear in no component row at all. If the BOM records only "dust collection unit, 1 set", the programmable panel inside it disappears from the inventory. This system's six rows are organised by function, and no control cubicle is captured explicitly — which makes it something to confirm in any real project.

Describing vendor maintenance access as "remote access" stops the analysis. It has to be modelled as inbound authority: changing parameters (A3), changing accounts and security settings (A6), and replacing executable code (A7) are different authorities demanding different controls.

8. Architecture patterns

Real topology varies by project and is not resolved by this brief. Three conceptual patterns, and how the attack surface differs across them.

Pattern A — standalone local panel

  Delta-P switch -> Local control box -> Pulse valve manifold
                          |
                    Relay contact -> Lamp / horn (local only)

A self-contained differential-pressure switch and relay alarms, with no connection to ship networks. The attack surface is limited to physical access — keypad parameters, wiring, compressed air.

Pattern B — monitored by the IAS

  Delta-P transmitter (4-20 mA) -> Local panel -> Pulse valve manifold
                                       |
                              Status / alarm relay -> Remote I/O -> IAS alarm page

Status and alarms travel upward while commands stay local; the information path is outbound only. The IAS alarm path is added to the attack surface — suppress the alarm and the degradation becomes invisible.

Pattern C — integrated into the cargo handling sequence

  Cargo handling sequencer / IAS
          |  (start, stop, mode)
          v
  Dust-control panel  <->  Delta-P transmitter
          |
          +-> Fan starter / VFD
          +-> Pulse valve manifold
          +-> Rotary airlock starter

Interlocked with conveyor and unloader start-up, allowing remote start and stop. The widest attack surface — stopping the fan and defeating the cleaning cycle are both reachable from upstream.

9. What information and commands flow through it

Mixing information with commands destroys the analysis. Here they separate cleanly.

  INFORMATION FLOW (upward)
  Delta-P element -> Transmitter -> Control panel -> [status, alarm] -> IAS / operator

  COMMAND FLOW (downward)
  Operator / sequencer -> Control panel -> +-> Fan starter -> Fan
                                           +-> Pulse valve -> Compressed air -> Filter element
                                           +-> Airlock starter -> Rotary airlock

  AUTONOMOUS LOOP (no human in path)
  Delta-P above threshold -> Control panel logic -> Pulse valve fires -> Delta-P falls

The third path is what characterises this system. Cleaning triggered by a differential-pressure threshold has no person in it. People only supervise whether that cycle appears to be turning.

10. What authority each connection carries

Source → Destination Observe Provide info Configure Command Control Admin Update exec
Panel → Fan starterNONONOYESNONONO
Panel → Pulse valveNONOYESYESNONONO
Panel → Airlock starterNONONOYESNONONO
Panel → IASNOYESNONONONONO
ΔP transmitter → PanelYESYESNONONONONO
Filter logic → own pulse valveNONONOYESYESNONO
Fan → any other systemNONONONONONONO
Duct / hood → any other systemNONONONONONONO
Rotary airlock → any other systemNONONONONONONO
Operator → PanelNONOYESYESNOCONDNO
Local keypad → panel parametersNONOYESNONONONO
Vendor service tool → PanelYESNOYESNONOYESYES
Cargo sequencer → Panel (Pattern C)NOYESCONDYESNONONO

11. Can the system affect the physical process

Interaction Authority Physical effect Human gate Security significance
Panel → fan startA4 COMMANDP4 DIRECTEXECUTIONWhether capture happens at all
Fan → air movementA0 NONEP4 DIRECTPhysical contact without authority
Filter logic → pulse valveA5 CONTROLP4 DIRECTNONEAutomatic physical action, no person
ΔP sensor → panelA1 / A2P1 INDIRECT DECISIONSUPERVISIONThe sole input to the judgement
Panel → airlockA4 COMMANDP4 DIRECTEXECUTIONWhether the hopper empties
Ducting and hoodsA0 NONEP0 NONENONENot captured on this axis
Vendor tool → panelA3 / A6 / A7P3 INDIRECT PHYSICALREVIEWReplacement of the cleaning logic itself
Table comparing six typologies by Purdue level, outbound authority, physical effect and CBS status, highlighting that fan and rotary airlock hold A0 authority yet have P4 direct physical effect.
Figure 3. Authority against physical effect across the six typologies. Fan, ducting and airlock hold no authority at all; two of them still touch the process directly.

Three points deserve attention.

First, the fan's A0 + P4 asymmetry. The fan exercises no authority over anything, yet its physical effect is P4, direct physical control — because the fan is the final element that actually moves the air. Having no signal input means the authority lies upstream, not that there is no physical contact. This asymmetry is normal rather than an error, and it recurs throughout actuator families.

Second, the filter control logic's P4 has no human gate. When differential pressure crosses the threshold, the panel opens the compressed air valve by itself. That is a supervised automatic action, not an action a person executes.

Third, P0 on the ducting does not mean harmless. P0 means there is no path to the physical process through a CBS. A blocked or ruptured duct certainly produces physical consequences, but those consequences cannot be reached through the control system. Physical effect and severity are separate axes, and this typology is the cleanest illustration of that principle.

12. Where the human sits in the architecture

Two gates of different character coexist in one system.

Action Human gate Basis
Fan start / stopEXECUTIONOperated by a person as part of the cargo procedure
Airlock start / stopEXECUTIONLocal starter and E-stop are hardwired
Element replacement, inspectionEXECUTIONPhysical work after isolation
Automatic pulse cleaning cycleSUPERVISIONRepeats autonomously on threshold; people only watch
Parameter changeREVIEW (or none)Local keypad reached by physical access alone, without authentication

That the cleaning cycle has no human gate is the premise of section 13. What people see is the result of the cycle turning — differential pressure falling — not the reason it ought to turn, which is the actual accumulation. The only bridge between those two is the ΔP signal.

The gate on the parameter path is weaker still. A local keypad is a CONFIGURE path reached by physical access alone, with no authentication, and the values changed there alter how the cycle behaves.

13. Authority escalation and propagation

The differential-pressure sensor holds only A1 and A2. It has no control authority. And yet this one sensor can increase physical hazard.

  False low Delta-P  (signal fixed, re-ranged, or wiring manipulated)
            |
            v
  Panel logic sees "filter is clean"
            |
            v
  Pulse cleaning never triggers          <-- no human gate here
            |
            v
  Filter cake grows unchecked
            |
      +-----+------------------------+
      |                              |
  Airflow falls                 Fuel accumulates inside
      |                         a Zone 20 enclosure
  Capture efficiency drops           |
      |                              |
  Dust escapes at source        Explosion pentagon:
  (health, machinery)           confinement + fuel supplied
                                by the protective system itself
Dust explosion pentagon with vertices fuel, oxygen, dispersion, ignition and confinement, showing that the collector supplies confinement and fuel, and that fuel layer thickness and dispersion are governed by the differential-pressure and cleaning control path.
Figure 2. The dust explosion pentagon. This system supplies confinement and concentrates the fuel — and two elements are reachable through the control path.

This is propagation that does not pass through a person. The sensor gained no CONTROL authority, and no attacker opened a valve. Simply causing the automatic logic to conclude "no cleaning required" is enough for a physical consequence to follow.

It is worth distinguishing this from direct control. Direct control is immediate and usually observed. This path is slow, looks normal, and generates no alarm — differential pressure is low, so no differential-pressure alarm is raised.

14. Trust boundaries and dependencies

  +------------------ Owner / integrator domain -------------------+
  |                                                                |
  |   Cargo sequencer / IAS      Ship power        Compressed air  |
  |          |                       |                   |         |
  +----------|-----------------------|-------------------|---------+
             |                       |                   |
  +----------v-----------------------v-------------------v---------+
  |                    Dust collection package                     |
  |   +--------------------------------------------------------+   |
  |   |  Vendor control cubicle  (parameters, firmware, ports)  |   |
  |   +--------------------------------------------------------+   |
  |   Fan   Ducting   Cyclone   Filter   Airlock   Delta-P sensor  |
  +----------------------------------------------------------------+
             ^
             |
     Vendor service laptop  (A3 / A6 / A7)  -- crosses the boundary

There are three boundaries.

The supply boundary, as section 7 described: where a vendor cubicle exists, everything inside it belongs to a different administrative owner.

Compressed air. This is the system's hidden single dependency. Pulse-jet cleaning is impossible without compressed air. The air system lies outside this plant, is shared with other consumers, and when its pressure falls the cleaning quietly stops — the panel commanded the valve, the valve opened, and there was no air to do the work. This is a place where the command succeeds and the physical action fails, and failures of that shape are invisible to any status indication derived from the command.

Power and the upstream sequence. In Pattern C, an upstream cargo sequencer holds start and stop authority.

15. What happens when it fails — before cyber

Before discussing attack, it is worth knowing how this plant breaks on its own.

Filter element rupture. When media tears, dust passes straight through to the clean-air side. Differential pressure falls rather than rises, because the resistance is gone. In industry practice a sudden drop in differential pressure is a recognised indication of element leakage or rupture; if the reading falls below the clean-filter baseline and heads toward zero, a system failure is suspected. Typical

Rotary airlock seizure. When discharge stops, the hopper fills, and when the hopper fills it submerges the lower filter area. Effective filtration area shrinks, differential pressure climbs, cleaning fires more often — and since nothing is being discharged, the situation only worsens.

Pulse valve failure. A valve that will not open means no cleaning. A valve that sticks open bleeds compressed air continuously and drops system pressure, defeating the cleaning of the other elements as well.

ΔP measurement failure. A blocked impulse line or a stuck transmitter freezes the reading. Frozen high, cleaning repeats endlessly and element life collapses. Frozen low, nothing happens at all — and that is the dangerous one.

Loss of compressed air. The path from section 14: command normal, physical action absent.

  FAILURE CHAIN -- the dangerous one

  Delta-P transmitter fails low
        -> no alarm (low is "good")
        -> cleaning never triggers
        -> cake grows
        -> airflow falls gradually
        -> capture efficiency degrades at the hood
        -> dust escapes where it was supposed to be captured
        -> AND fuel accumulates inside the Zone 20 enclosure

16. Attack surface and credible threat scenarios

Class What it is here Exists when
Local physicalKeypad parameters, sensor wiring, impulse linesAlways
Removable mediaPanel firmware and settings transferPackaged supply
Connected OTIAS alarm path, cargo sequencer interlockPatterns B and C
Ship–shore(no evidence of a shore path specific to this system)
VendorService laptop, remote diagnostic gatewayPackaged supply
Supply chainPanel configuration, default parameter valuesAlways

The ship–shore row is deliberately empty. Unlike liquid cargo systems, there is no evidence of a path by which this system sends data ashore. The cached material on custody transfer and metering computers belongs to sibling components and is not imported here.

Scenario 1 — pinning the differential-pressure signal

Entry Interaction    : Physical access to the 4-20 mA wiring or HART segment
Initial Authority    : A3 CONFIGURE (range / span change) or signal injection
Mechanism            : Hold the indicated value at a point below threshold
Authority Gained     : None -- no escalation occurs
Affected Interaction : The panel's threshold comparison
Physical Effect      : P4 (the cleaning valve never opens -- physical result by omission)
Consequence          : Cake growth, falling capture efficiency, fuel accumulating
                       inside a Zone 20 enclosure. No alarm.

What distinguishes this scenario is that no escalation happens at all. The attacker touches only a sensor path carrying A1/A2, and a physical consequence follows. It is the propagation structure of section 13 realised directly.

Scenario 2 — changing parameters at the local keypad

Entry Interaction    : Local panel keypad (no authentication, physical access only)
Initial Authority    : A3 CONFIGURE
Mechanism            : Shorten pulse duration, raise the Delta-P threshold, extend delay
Authority Gained     : None
Affected Interaction : The cleaning cycle itself
Physical Effect      : P4 (cleaning performed only nominally)
Consequence          : The cycle "runs" and is logged, but nothing is shaken off.
                       Differential pressure climbs slowly, yet the threshold has
                       risen with it, so no alarm is raised.

This is the silent failure path the cached TYP-A08 doctrine identifies, made considerably heavier by the dust context. In fuel filtration the result of this manipulation is a load limit on the main engine. In dust collection it is fuel accumulation inside a confined enclosure.

Scenario 3 — stopping the fan while holding the status indication

Entry Interaction    : Cargo sequencer or panel (remotely reachable only in Pattern C)
Initial Authority    : A4 COMMAND
Mechanism            : Stop command to the fan, with status held at "running"
Authority Gained     : None
Affected Interaction : The entire capture stage
Physical Effect      : P4 (air movement ceases)
Consequence          : Cargo work continues with no capture. Dust disperses across
                       deck and holds while the operator believes extraction is
                       working. IMSBC 3.3 exposure and 3.4.1 dust-cloud formation
                       occur together.

The cached TYP-C04 doctrine identifies this structure — if the fan has actually stopped but is indicated as running, people enter a hazardous space. That doctrine arose in a pump-room gas context, but the structure carries over to dust. Here, though, what rests on the false indication is not an entry decision but a decision to keep working cargo.

17. Security architecture and standards

Controls are derived from the threats first; standards are mapped afterwards.

Threat Control derived
ΔP signal pinned (Scenario 1)Plausibility checking of differential pressure — with the fan running, a reading pinned below the clean baseline is itself an anomaly, since healthy, ruptured and falsified states share that value. Cross-check against airflow and fan current rather than trusting a single signal
Diagnostic ambiguity of low ΔPDetection on the discharge side, independent of ΔP — triboelectric particulate detection or equivalent, watching clean-air dust concentration directly. Leakage is then caught even when the pressure path is lying
Parameter change (Scenario 2)Lock levels and change records on panel parameters; default passwords changed at handover; parameter values placed under configuration management
Fan status spoofing (Scenario 3)Derive the running indication from actual airflow or pressure, not the starter auxiliary contact; separate command success from physical-action success
Vendor access (A3 / A6 / A7)Separate access by authority; log sessions; verify media before transfer
Loss of compressed airConfirm cleaning execution by observing the pressure drop, not merely that a command was issued
Clause What it means here
IACS UR E26 §1.3.2 a)In-scope OT is CBSs using data to control or monitor physical processes — the panel and the ΔP sensor
IACS UR E26 §2CBS = programmable electronic device. The basis for excluding the fan, ducting, cyclone and airlock
IACS UR E26 §6Documented risk assessment for exclusion. Separate row by row so that automatic variants are not excluded alongside manual ones sharing a name
IACS UR E26 §4.1.1.3Asset inventory. Ducting is not the object; the transmitter on it is
IACS UR E26 §4.2.1.1 / §4.2.1.3Security zone grouping and explicitly permitted traffic; separation of cargo systems from navigation and communication zones
IACS UR E26 §4.2.4.3.4Removable media policy — the route by which panel settings and firmware arrive
IACS UR E26 §4.2.4.4.1Authentication exemption for HMIs needing immediate access, conditional on physical access control. Whether the dust panel qualifies must be specified
IACS UR E27 §4.1 Table 1 item 1 (SR 1.1)Identification and authentication of human users
IACS UR E27 §4.1 Table 1 item 12 (SR 2.5)Session lock after configurable inactivity
IACS UR E27 §4.1 Table 1 item 18 (SR 3.2)Prevention, detection and mitigation of malicious and unauthorised software
IACS UR E27 §4.1 Table 1 item 20 (SR 3.6)Deterministic output when normal operation cannot be maintained. Directly determines what state the pulse valve and airlock are left in when the panel fails
IMSBC Code 3.3Dust as a health hazard — reason for existence 1
IMSBC Code 3.4.1Dust explosion hazard; ventilation to prevent a dust-laden atmosphere — reason 2
IMSBC Code 2.2.5 / 2.2.6Keeping dust out of interior spaces; protecting deck machinery and navigational aids — reason 3
IEC 60079-10-2Combustible dust zones 20 / 21 / 22, EPL Da / Db / Dc, enclosure IP6X (20 and 21), IP5X (22)

18. Open questions, takeaways and references

Questions to ask first in a real project

  1. Does the dust-control panel appear as its own line in the BOM, or is it absorbed into "dust collection unit, 1 set"?
  2. Is the supply boundary owner-specified or packaged — is there a vendor control cubicle?
  3. Is the cleaning trigger a differential-pressure switch or a transmitter? (A switch fixes the threshold in hardware.)
  4. Do the ΔP threshold, pulse duration and delay parameters have lock levels? Are defaults changed at handover?
  5. Are cleaning cycles logged, and can the log be read on board?
  6. Does the fan "running" indication come from a starter auxiliary contact, or from actual airflow or pressure?
  7. Is a fall in compressed air pressure alarmed as a cleaning failure, or is only the command recorded as successful?
  8. Is there any means of detecting element rupture, given that it lowers differential pressure?
  9. Is the plant interlocked with the cargo handling sequence — is this Pattern C?
  10. Is there a vendor remote diagnostic gateway, and if so, which zone does it sit in?
  11. Is the dust panel specified as exempt under E26 §4.2.4.4.1?
  12. Are dust hazardous areas classified as Zone 20 / 21 / 22 and shown on drawings?
  13. Is equipment in those areas selected to the D series EPL rather than the G series?
  14. Is the fail state of the pulse valve and airlock defined for panel failure (E27 item 20)?

Open questions

  • This system's BOM rows were populated by an engineering gap audit, so component identification has not been vendor-confirmed. The six-typology mapping is itself open to revision.
  • TYP-B02, the differential-pressure sensor, carries evidence grade INFERRED. Its register is empty and the doctrine is inherited from sibling typologies; vendor datasheet research must come first before it can be raised to TYPICAL.
  • The actual communication method — 4-20 mA alone, or HART or Modbus in addition — is unresolved.
  • Whether the control cubicle is separately listed as a CBS or absorbed into the parent package is unconfirmed.
  • Ship type (cement carrier, self-unloader, grain, general bulk) drives plant scale and integration level considerably, and this analysis does not fix a ship type.
  • Whether a dust explosion hazard genuinely exists depends on cargo-specific dust properties — combustibility, minimum ignition energy, Kst value — and this article holds no measured values for them. Not every dry bulk cargo produces an explosible dust.

Engineering takeaways

  FINAL CHAIN

  IMSBC 3.3 / 3.4.1 / 2.2.5  (why the system exists)
        |
  Capture -> Convey -> Separate -> Filter -> Discharge   (what it does)
        |
  6 typologies, 4 at Purdue L0, 3 CBS candidates          (what it is)
        |
  Delta-P : the single governing observable               (how it decides)
        |
  Panel A4/A3 . Sensor A1/A2 . Fan A0+P4 . Filter logic A5+P4   (authority)
        |
  Cleaning cycle has NO human gate                        (where people are)
        |
  False Delta-P -> no cleaning -> cake grows              (propagation)
        |
  Fuel + confinement inside a Zone 20 enclosure           (physical consequence)
        |
  Control the judgement chain, not just the executable    (what to protect)
  1. Most of this system's physical bulk is not a cyber object. Three of six rows are CBSs and only one is separately listed. Document the removal under E26 §6.
  2. Do not read the fan's A0 + P4 asymmetry as an error. Authority upstream and physical contact downstream is the normal structure of actuator families.
  3. What must be protected is the judgement chain, not the executable. Five segments from ΔP signal to pulse valve, with different owners.
  4. A silent failure here is accumulating hazard, not degraded performance. The same manipulation in fuel filtration produces an engine load limit; here it produces combustible material inside a Zone 20 enclosure.
  5. Separate command success from physical-action success. Without compressed air, the valve opens and nothing is cleaned.

Sources

  • IMO, International Maritime Solid Bulk Cargoes (IMSBC) Code — 2.2.5, 2.2.6, 3.3, 3.4.1, 3.4.2
  • IACS, UR E26 Rev.1 — §1.3.2, §2, §4.1.1.3, §4.2.1.1, §4.2.1.3, §4.2.4.3.4, §4.2.4.4.1, §6
  • IACS, UR E27 Rev.1 — §4.1 Table 1 items 1, 12, 18, 20
  • IEC 60079-10-2:2015, Explosive atmospheres — Classification of areas: combustible dust atmospheres
  • IEC 60204-1, Safety of machinery — Electrical equipment of machines (stop category 0)
  • NFPA 652, Standard on the Fundamentals of Combustible Dust — shore-based; cited only to explain the physical phenomenon
  • OSHA Technical Manual, Section IV Chapter 6, Combustible Dusts — as above