Normal opening
The full open stroke under nominal conditions.
Digital Twin Engine
A digital twin is a high-fidelity software model of a physical system — accurate enough that running the model tells you what the real hardware would do. Drive-Drive Power maintains a full engineering digital twin of its technology, built across a complementary toolchain: MATLAB, Simulink, and Simscape Fluids for system-level dynamics, controls, and closed-loop hydraulic behaviour; ANSYS CFD for internal flow, pressure-drop, and accumulator-discharge analysis; and ANSYS Mechanical for structural, fatigue, and stress validation of pump, actuator, and valve components. Together these are the same simulation tools used across aerospace, automotive, and energy industries to certify designs before metal is cut.
What the twin models
Every performance figure on this page is model-derived from physics, not assumed. The digital twins are Simscape, ANSYS CFD, Mechanical, Motion, and Twin Builder physical networks: pressures, flows, forces, and torques satisfy mass and momentum conservation and fluid compressibility by construction — the solvers enforce the governing equations rather than replaying assumed behaviour. And every parameter — cylinder geometry, spring preload and rate, pump displacement, motor ratings, valve areas — traces to an engineering source document or a commercial component class.
The reference application is a large emergency shutdown valve (ESDV): a 36-inch, fail-close, trunnion-mounted ball valve of the kind that isolates a pipeline in an emergency. It is driven by an electro-hydrostatic actuator — a self-contained electric-pump-plus-cylinder unit — through a mechanical linkage, and held closed by a powerful spring so that, on any loss of power, the valve fails safely shut.
The entire model is generated from text — a written recipe rebuilds it identically every time — so the design is fully transparent and reproducible. There are no hidden tuning knobs.
The twin captures
How it is tested
The twin is exercised through a suite of eighteen pass/fail checkpoints covering every duty the valve must perform and every failure it must survive. Each checkpoint has a hard numerical target; the test suite passes only if every single one is met.
The full open stroke under nominal conditions.
The periodic proof test that safety certification depends on.
Spring-driven fail-close with the motors switched off.
Confirming the valve fails safely shut.
Performance under reduced fluid availability.
A deliberately punishing cold, thick oil plus elevated friction.
Unique to Drive-Drive: a motor lost during operation.
Same valve, same hydraulics, same safety logic — only the drive changes.
To make the comparison fair and honest, the Simplex and Drive-Drive systems are tested on an identical valve, identical hydraulics, and identical safety logic. The only thing that changes between them is the drive — one motor versus two. Both systems pass all eighteen checkpoints. The closing (safety) numbers are identical to the hundredth of a second, because closing is done by the spring with the motors switched off.
Verification result
Both architectures: 18 / 18 checkpoints PASS , in both an open-circuit and a sealed closed-circuit hydraulic configuration.
Emergency-closure performance is identical between them — the safety case is independent of the drive.
Verification scenarios
Every scenario below is run on two architectures built on the identical valve, hydraulics, and safety logic — changing only the drive: the Drive-Drive (two synchronised motors) and the Simplex baseline (one motor of the same total power). The scenarios fall into three groups: normal duty (does the valve open, hold, and partial-stroke correctly?), fail-safe closure (does it close safely under every fault?), and redundancy under motor failure (does it keep working when a motor is lost?).
The result is a clean split. On normal duty and on fail-safe closure the two architectures are indistinguishable — the same numbers to the hundredth of a second — because the valve and the closing spring are identical. It is only when a motor fails that they diverge: the Drive-Drive keeps the valve operable; the single-motor Simplex cannot.
Result at a glance
Normal duty & fail-safe closure: Drive-Drive and Simplex are identical — opens in ≈ 42 s, closes safely in ≈ 22.9 s (target ≤ 25 s), surge ≈ 31 bar (limit 174 bar).
Motor-failure scenarios: Drive-Drive keeps opening on the surviving motor (worst case, inside its continuous rating). Simplex has no second motor — the valve stalls part-open and cannot complete its stroke.
Two motors do not change the certified fail-close function — the spring closes the valve either way. What they eliminate is the failure-to-open mode, and that is itself a safety issue: a stalled part-open valve can leave a section blocked in with no relief path, escalate under fire toward vessel rupture, choke relief routes and force backflow, or — on fail-open flare and vent duty — keep toxic or flammable gas from venting safely away from personnel.
Every checkpoint on both architectures, side by side. The two columns match through S8, then diverge completely from S9 on — the moment a motor failure enters the picture.
Through S8 the columns match because the valve, the hydraulics, and the fail-close spring are identical and the total drive power is the same. From S9 the single-motor system has no answer: losing its one motor is losing its drive.
Before any failure is considered, the twin proves the valve does its everyday job: open on demand, hold open, and accept the periodic proof test that safety certification requires. Drive-Drive and Simplex are identical here.
Commanded open from the fully seated position, the actuator strokes the valve to 99% open in about 42 seconds. On the Drive-Drive the two motors share the load exactly equally — each carrying half, and each working far below its rating. On the Simplex one motor of the same total power does the same work in the same time. This is the baseline against which every other scenario is read.
Safety regulations require an ESDV to be exercised periodically without fully closing it — a proof test that confirms the valve is free to move. The twin commands a partial stroke: the valve dips to about 85% open and then recovers cleanly to fully open. Both architectures pass identically; the dual-motor architecture later makes this even safer (see S9–S12).
The core safety duty: on any emergency or fault, the valve must close, quickly and without over-pressure. Closure is performed by a powerful mechanical spring with the motors de-energised — the drive is not involved — which is why these results are robust to every electrical and hydraulic fault and identical between Drive-Drive and Simplex. They confirm the dual-motor architecture removes the failure-to-open exposure without disturbing the certified fail-close function.
On an ESD signal both dump valves de-energise, the cylinder vents, and the spring drives the valve shut in 22.9 seconds — comfortably inside the 25-second target. A two-stage dump profile vents fast and then cushions the final seating to avoid slamming.
Both motors and all electrical power are cut simultaneously. The valve closes in exactly the same 22.9 seconds: closure draws on stored spring energy, not electricity. Loss of power is a fail-safe event, not a failure.
With the hydraulic supply degraded to its minimum (130 bar), the valve still closes in 22.9 seconds — closure does not depend on supply pressure.
The punishing case: cold, thick oil (1.5× viscosity) combined with 40% elevated friction. The valve still closes in 22.9 seconds. The spring's energy margin absorbs the worst conditions the valve is likely to meet.
One of the two dump valves drops out unexpectedly. The 1-out-of-2 voting logic detects the resulting drift and completes the closure on the remaining valve in 23.7 seconds — still within budget. Redundancy in the final-element path, proven.
Rapid closure can cause a damaging pressure surge (water-hammer). The twin measures the peak at 31.3 bar against a 174-bar limit (120% of maximum allowable operating pressure) — a comfortable five-fold margin, thanks to the cushioned two-stage dump.
This is where the two architectures part ways. The scenarios below inject a motor failure and ask the simplest possible question: does the valve still do its job? For the Drive-Drive the answer is yes — the surviving motor carries on. For the single-motor Simplex, losing the motor is losing the drive, and the valve is stranded. The contrast is simulated on both, not asserted.
The difference in one picture
Both systems are commanded open; ten seconds in, a motor fails. The Drive-Drive's surviving motor opens the valve fully (100%, ≈ 42 s). The single-motor Simplex stalls at about 22% open and stops there — the stroke never completes and the pipeline cannot be restored without intervention.
Same fault, two outcomes. A motor fails 10 s into opening: the Drive-Drive reaches fully open; the single-motor Simplex stalls part-open and stops.
Ten seconds into the opening stroke, one motor fails outright. On the Drive-Drive its torque collapses to zero within 50 milliseconds as the drive isolates it, the surviving motor instantly takes the full load, and the valve keeps opening with no measurable disturbance — reaching fully open on time in 42.0 seconds. On the Simplex, that same motor is the only motor: the drive goes dead, the valve coasts to a halt at about 22% open, and there it stays. For an emergency shutdown valve this is the difference between a logged maintenance item and a stranded, part-open valve that forces a trip.
The hardest version of the redundancy test: one motor is already failed before the valve even begins to move, so the surviving motor must break the valve off its seat — the highest-force moment of the whole cycle — entirely on its own. The Drive-Drive does it, opening fully in 42.0 seconds, the same as with both motors: single-motor operation costs no speed. The Simplex cannot even start — with its one motor unavailable there is no drive to break the valve off the seat, and the valve stays shut. A dual system can still restore the line on a single motor; a single-motor system, once its motor is down, cannot.
The two motors are commanded to share the load 70/30 instead of equally — a deliberate capability used for thermal management (steer work toward the cooler motor) or staged fault recovery. The measured torque ratio tracks the command exactly (2.33 against a commanded 2.33), with no effect on stroke time. This real-time load-steering lever has no equivalent in a single-motor drive.
The decisive checkpoint. It combines the two hardest conditions — a single surviving motor AND the worst-case cold-oil, high-friction environment — and requires the survivor to open the valve while staying inside its continuous rating, not by briefly overloading. It does: the surviving motor's sustained load is 78.8 N·m against its 150 N·m continuous rating — a 1.9× margin, the same comfortable margin a single-motor system is designed to — and it spends just 0.07 seconds momentarily above continuous (the normal control transient at the start of the stroke). This is what turns “redundant” from a marketing word into a guarantee backed by a hard test.
Why S12 is the headline
One motor, worst-case conditions, valve opened fully — with the survivor running at 78.8 N·m against a 150 N·m continuous rating (1.9× margin).
Redundancy here is sized and proven, not hoped for.
Run side by side on the identical valve, the scenarios tell a clean, two-part story:
Through S1–S8 the Drive-Drive and the single-motor Simplex are identical — same opening time, same proof test, same fail-safe closure to the hundredth of a second, same surge. Adding a second motor does not disturb the certified safety function.
From S9 on, the single-motor system has no answer: a motor failure strands the valve part-open or prevents it opening at all. The Drive-Drive carries on — full-speed opening on the surviving motor, with a proven 1.9× thermal margin even in the worst case.
That is the case for two motors in one sentence: the same safety, the same performance, but a valve that keeps working when a single-motor system would be stranded. Every number here is reproducible from a fully text-generated Simulink / Simscape model — transparent, repeatable, and verified, not asserted.
Beyond pass/fail — four deeper studies
Four further studies establish why, and by how much, Drive-Drive is better — and confirm the twin can be trusted.
The simplified one-pump drive model was checked against a rigorous two-pump model in which each motor drives its own half-size pump element. The two agreed exactly — identical motion, pressure, and timing to the resolution of the simulation. The same study showed that when a motor fails the per-gear flow split stays balanced, so single-motor failure costs no flow capability at all; only the force budget halves.
A winding-temperature model, calibrated so that each motor's rated load sits exactly at its insulation limit, shows how hot the motors actually run. In normal two-motor operation each frame runs cool with a large margin; even a lone surviving motor handling the entire worst-case load stays comfortably within its temperature limit. Heat is no longer a constraint on the redundancy.
A runtime instrumentation layer logs torque, current, power, efficiency, flow, pressure ripple, and per-motor heat at high rate across a full duty cycle — giving a complete energy-and-thermal picture of both systems on the same basis.
A transparent, fully parametric cost model carries the comparison through to dollars over a 25-year service life — purchase, spares, maintenance, energy, and the cost of unplanned downtime — with every price an explicit, adjustable assumption.
We'll take you through the 18-checkpoint suite, the four deeper studies, and the reproducible model recipe.