Nuclear power plant external event configuration risk management assessment method, system, medium and equipment
By using a risk management assessment method for external events in nuclear power plants, configuration change information is obtained and evaluated, and risk management strategies are generated. This solves the problem that existing technologies cannot effectively assess the impact of external events, thereby improving safety and economic benefits.
Patent Information
- Application Number
- CN202511106617.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-07
- Publication Date
- 2025-12-05
AI Technical Summary
In existing technologies, nuclear power plants only consider configuration risk management for internal events and fail to effectively assess the impact of external events on nuclear power plants, which may lead to the neglect of important risks or overly conservative risk management.
A method for assessing configuration risk management of external events in nuclear power plants is provided, including obtaining configuration change information, conducting qualitative and quantitative assessments, generating risk management action strategies, and assessing the risk impact of external events through screening tables and envelope quantitative assessment methods or risk monitor quantitative assessment methods.
By incorporating external events into risk management, significant risks are avoided, and safety and economic benefits are achieved. This addresses the inadequacy of existing technologies in assessing the impact of external events and supports the rational management of safety mitigation equipment.
Smart Images

Figure CN121073192A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of nuclear power plant configuration risk management, and more particularly to a nuclear power plant external event configuration risk management evaluation method, system, medium and device. BACKGROUND
[0002] With the development of probabilistic safety assessment (PSA) technology, nuclear power plants continue to expand the scope of probabilistic risk assessment and develop standards for the development and maintenance of PSA models. External events are events that occur outside the boundaries of a specific power plant system and usually affect multiple systems within a given spatial area. External event PSA includes internal fire, internal flooding, seismic events, strong winds, etc. Each type of external event may produce a specific external event risk for a specific power plant configuration.
[0003] Current nuclear power plant configuration risk management only considers the risk of internal events, i.e., configuration risk due to unavailability of nuclear power plant internal equipment due to maintenance or random failure, and does not analyze the configuration risk of the power plant that may be caused by internal fires, earthquakes, etc. There is no corresponding evaluation method for the impact of external events. SUMMARY
[0004] The technical problem to be solved by the present application is to provide a nuclear power plant external event configuration risk management evaluation method, system, medium and device to solve the problems in the prior art.
[0005] The technical solution adopted by the present application to solve the technical problem is: a nuclear power plant external event configuration risk management evaluation method is constructed, comprising the following steps:
[0006] Obtain configuration change information of the nuclear power plant;
[0007] Analyze the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant;
[0008] If yes, then perform qualitative screening evaluation on the current configuration change to obtain the external event risk impact of all current configuration changes;
[0009] Perform quantitative evaluation on the external event risk impact of all current configuration changes to obtain a quantitative evaluation result;
[0010] Generate a risk management action strategy based on the quantitative evaluation result.
[0011] In the nuclear power plant external event configuration risk management evaluation method described in the present application, the analysis of the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant comprises:
[0012] determining whether the current configuration change only produces internal event risk according to the configuration change information;
[0013] if yes, determining that the current configuration change does not produce external event risk influence;
[0014] if no, determining whether the current configuration change does not affect external event scenarios and the unavailable equipment is used to mitigate internal events and external events;
[0015] if the current configuration change does not affect external event scenarios and the unavailable equipment is used to mitigate internal events, determining that the current configuration change produces external event risk influence;
[0016] if the current configuration change does not affect internal event risk and affects external event risk, determining that the current configuration change produces external event risk influence.
[0017] In the nuclear power plant external event configuration risk management evaluation method, the qualitative screening evaluation of the current configuration change includes:
[0018] screening all external event risk influences produced by the current configuration change based on a screening table to obtain a preliminary screening result;
[0019] secondary evaluating the preliminary screening result to obtain external event risk influences of all current configuration changes.
[0020] In the nuclear power plant external event configuration risk management evaluation method, the quantitative evaluation of the external event risk influences of all current configuration changes includes:
[0021] quantitatively evaluating the external event risk influences of all current configuration changes by using an envelope quantitative evaluation method to obtain a quantitative evaluation result;
[0022] or, quantitatively evaluating the external event risk influences of all current configuration changes by using a risk monitor quantitative evaluation method to obtain a quantitative evaluation result.
[0023] In the nuclear power plant external event configuration risk management evaluation method, the quantitative evaluation of the external event risk influences of all current configuration changes by using an envelope quantitative evaluation method includes:
[0024] determining an external event type;
[0025] calculating a core damage frequency according to the external event type;
[0026] quantitatively evaluating the external event risk influences of all current configuration changes based on the core damage frequency.
[0027] In the nuclear power plant external event configuration risk management evaluation method, the quantitative evaluation of the influence of the current all configuration changes on the external event risk by using the risk monitor quantitative evaluation method comprises:
[0028] obtaining a reference external event PSA model;
[0029] reconstructing the reference external PSA model to obtain a real-time risk model;
[0030] quantitatively evaluating the influence of the current all configuration changes on the external event risk based on the real-time risk model.
[0031] In the nuclear power plant external event configuration risk management evaluation method, the reconstruction of the reference external PSA model to obtain a real-time risk model comprises:
[0032] performing real-time model conversion of the reference external PSA model by using a risk monitor to obtain the real-time risk model.
[0033] The application further provides a nuclear power plant external event configuration risk management evaluation system, comprising:
[0034] a change information acquisition unit configured to acquire configuration change information of a nuclear power plant;
[0035] a risk influence analysis unit configured to analyze the configuration change information to determine whether the current configuration change has an influence on the external event risk of the nuclear power plant;
[0036] a qualitative screening unit configured to perform qualitative screening evaluation on the current configuration change to obtain the influence of the current all configuration changes on the external event risk;
[0037] a quantitative evaluation unit configured to quantitatively evaluate the influence of the current all configuration changes on the external event risk to obtain a quantitative evaluation result;
[0038] a management strategy generation unit configured to generate a risk management action strategy based on the quantitative evaluation result.
[0039] The application further provides a storage medium storing a computer program, wherein the computer program is suitable for being loaded by a processor to execute the steps of the nuclear power plant external event configuration risk management evaluation method.
[0040] The application further provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the steps of the nuclear power plant external event configuration risk management evaluation method by calling the computer program stored in the memory.
[0041] The nuclear power plant external event configuration risk management evaluation method, system, medium and device provided by the present application have the following beneficial effects: including the following steps: obtaining configuration change information of a nuclear power plant; analyzing the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant; if yes, performing qualitative screening evaluation on the current configuration change to obtain the external event risk impact of all current configuration changes; performing quantitative evaluation on the external event risk impact of all current configuration changes to obtain a quantitative evaluation result; and generating a risk management action strategy based on the quantitative evaluation result. The present application solves the problems existing in the current nuclear power plant internal event risk evaluation management by including the external event in the configuration risk management range, avoids the situation of ignoring important risks or overly conservative risk management, and supports the realization of additional safety and economic benefits. BRIEF DESCRIPTION OF DRAWINGS
[0042] The present application will be further described below in combination with the drawings and embodiments, and the drawings are as follows:
[0043] Figure 1 FIG. 1 is a flowchart of a nuclear power plant external event configuration risk management evaluation method provided by an embodiment of the present application;
[0044] Figure 2 is a configuration risk considering the influence of external events;
[0045] Figure 3 FIG. 5 is a configuration risk influence evaluation flowchart provided by an embodiment of the present application;
[0046] Figure 4 FIG. 6 is a logic block diagram of a nuclear power plant external event configuration risk management evaluation system provided by an embodiment of the present application. DETAILED DESCRIPTION
[0047] The technical solutions in the embodiments of the present application will be clearly and completely described below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.
[0048] In order to solve the problem that the current nuclear power plant only considers the influence of internal events on configuration risk management, without considering the overall risk influence, and without forming a complete evaluation method for the influence of external events, the application provides a nuclear power plant external event configuration risk management evaluation method, which can evaluate and manage the potential influence of external events, cope with the configuration risk caused by external events, support the realization of additional safety and economic benefits, and has low cost and high benefit.
[0049] Specifically, the nuclear power plant external event configuration risk management evaluation method expands the evaluation range of the configuration risk of the nuclear power plant. After considering the configuration risk management (CRM) of external events, the power plant can include the external event related system equipment (such as fire detection system, fire extinguishing system, etc.) into the management range, can better solve the problem of unavailable risk evaluation of these equipment, especially the superimposed risk, which cannot be covered by the existing national standard. At the same time, the risk management of the unavailable safety mitigation equipment of the external event with high risk can also appropriately relax the risk threshold which is too conservative when only internal events are used for configuration evaluation, thereby supporting the realization of additional safety and economic benefits.
[0050] Reference Figure 1 , Figure 1 An embodiment of the nuclear power plant external event configuration risk management evaluation method provided by the application is shown.
[0051] As shown in Figure 1 , in this embodiment, the nuclear power plant external event configuration risk management evaluation method comprises the following steps:
[0052] Step S101: Obtain the configuration change information of the nuclear power plant.
[0053] Specifically, when the configuration of the nuclear power plant is changed, the corresponding configuration change information can be automatically generated. The configuration change information includes but is not limited to: change items, change range, change object, change time, etc.
[0054] Step S102: Analyze the configuration change information to determine whether the current configuration change has an influence on the external event risk of the nuclear power plant.
[0055] In the embodiment of the present application, the analysis of the configuration change information to determine whether the current configuration change has an impact on the external event risk of the nuclear power plant comprises: determining whether the current configuration change only produces internal event risk according to the configuration change information; if yes, determining that the current configuration change does not produce external event risk impact; if no, determining whether the current configuration change does not affect the external event scenario and the unavailable equipment is used to mitigate internal events and external events; if the current configuration change does not affect the external event scenario and the unavailable equipment is used to mitigate internal events, determining that the current configuration change produces external event risk impact; if the current configuration change does not affect internal event risk and affects external event risk, determining that the current configuration change produces external event risk impact.
[0056] Specifically, the external event refers to an event occurring outside the boundary of a specific power plant system, which usually affects multiple systems in a given spatial area. The external event generally includes but is not limited to internal fire, internal flooding, earthquake event, strong wind, etc. Each type of external event has configuration-specific risk factors that lead to the risk of a specific external event.
[0057] Optionally, for any specific configuration change of the power plant, the external event risk impact is generally divided into the following cases in the embodiment of the present application:
[0058] 1) The configuration change only affects the internal event risk and does not affect the external event (such as detection and mitigation). For such configuration change risk, the internal event configuration risk (CRM) tool can be directly analyzed, and the external event risk impact does not need to be considered.
[0059] 2) The configuration change does not directly affect any external event scenario (such as detection and mitigation), but the unavailable equipment will be used to support the mitigation of internal events and external events. For example, the turbine-driven auxiliary feedwater pump of the pressurized water reactor nuclear power plant may be important for mitigating internal events, but it may also be a key factor in mitigation in various external event situations, so including the external event impact will result in a higher configuration-specific risk "peak", as shown in Figure 2 . For such configuration change, the impact of external event configuration risk needs to be considered.
[0060] 3) The configuration change does not affect the internal event risk but affects the external event risk. For example, the configuration change may involve damage to the barrier (such as removal of the fire barrier), activities that increase the frequency of external events (such as maintenance activities that increase temporary ignition sources), or damage to detection equipment (such as unavailable fire detection). The new risk "peak" is only the result of the impact of external event-related scenarios, as shown in Figure 2 . For such configuration change, the impact of external event configuration risk also needs to be considered.
[0061] Step S103: If yes, qualitative screening assessment is performed on the current configuration change to obtain the external event risk impact of all current configuration changes.
[0062] In the embodiment of the present application, the qualitative screening assessment is performed on the current configuration change to obtain the external event risk impact of all current configuration changes, which includes: screening all external event risk impacts caused by the current configuration change based on the screening table to obtain a preliminary screening result; and performing secondary assessment on the preliminary screening result to obtain the external event risk impact of all current configuration changes.
[0063] Specifically, after confirming that the configuration change will have an impact on the external event risk, all external event risk impacts of the configuration change need to be screened out. That is, through qualitative screening, the external event risk impacts of all configuration changes in the current configuration change are quickly assessed. In the embodiment of the present application, the screening table is used to determine whether the configuration change has an external event risk impact. That is, a series of questions are asked to determine whether the work activity will damage the protection function of other nuclear power plant equipment (i.e. equipment that is not unavailable due to the configuration change). If the external event protection function is damaged, but a compensatory measure is taken, the damage can be considered to have no further impact.
[0064] Specifically, the preliminary screening of the external event impact can be based on the following factors:
[0065] The specific configuration change does not affect the external event protection function.
[0066] The configuration change affects the external event protection function (such as a barrier or a detection system), but due to the maintenance activity, the barrier damage only affects the equipment that is already unavailable. For example, due to preventive maintenance on the pump itself, the fire / water flood door of the pump room can be opened without causing other impacts on other nuclear power plant equipment.
[0067] The configuration change affects the external event protection function, but sufficient compensatory measures have been taken to offset the risk impact of the damage (such as using a temporary barrier to replace the damaged barrier, using continuous personnel on duty to compensate for the unavailability of the detection equipment, and suppressing the equipment or barrier).
[0068] The power plant can determine the time limit of the configuration change, and the change with a duration shorter than the time limit cannot generate sufficient additional risk. For example, if a single configuration change cannot result in more than 1E-7CCDP, the risk it generates is very low compared to the internal event risk.
[0069] Further, after obtaining all external event impacts caused by all configuration changes through the preliminary screening assessment using the screening table, secondary assessment is also needed. Specifically, the secondary assessment includes:
[0070] If the configuration change has no such impact (i.e. the configuration change resulting from the required preventive maintenance work does not affect any external event protection measure), no further assessment of the configuration change is required, i.e. no assessment of the external event risk impact is required.
[0071] If the configuration change has one or more impacts on external event protection functions, it is necessary to determine whether it only impacts currently unavailable equipment. If it only impacts currently unavailable equipment and does not impact other equipment, no further assessment of the configuration change is required. If other nuclear power plant equipment is also impacted, further assessment is required. It is noted that if a power plant has only one column of power plant equipment available for protection from external events and this column of equipment is impacted by the configuration change, further assessment of the configuration change is required.
[0072] If the power plant specifies a minimum configuration time to consider the external event risk impact and the duration of the proposed configuration change is shorter than the minimum configuration time, no further assessment is required. If the duration of the proposed configuration change is longer (or the equipment is not restored to availability within the minimum configuration time), further assessment of the configuration change is required.
[0073] It is determined whether compensatory measures are being used to offset the impact on external event protection measures. If appropriate compensatory measures are in place, no additional significant risk is expected to be added by the external event. If plant-specific procedures are in place that specify which compensatory measures should be used in specific situations, these are considered. If no compensatory measures are in place, further assessment of the configuration change risk is required.
[0074] If acceptable compensatory measures are in place, it is considered whether the configuration change impacts multiple external events or multiple protection measures for a single external event (e.g. the configuration impacts both fire detection and fire extinguishing systems). If multiple impacts are expected, additional assessment of the potential synergistic impact of the damage is required (even if all impacts are considered to be offset by compensatory measures). If no multiple impacts are expected, the external event risk impact of the configuration change is limited to an acceptable range by the use of compensatory measures and no further assessment is required.
[0075] Step S104: quantitatively assessing the external event risk impact of all the current configuration changes to obtain a quantitative assessment result.
[0076] In the embodiment of the present application, the quantitatively assessing the external event risk impact of all the current configuration changes to obtain a quantitative assessment result comprises: quantitatively assessing the external event risk impact of all the current configuration changes by using an envelope quantitative assessment method to obtain a quantitative assessment result. Alternatively, the external event risk impact of all the current configuration changes is quantitatively assessed by using a risk monitor quantitative assessment method to obtain a quantitative assessment result.
[0077] Wherein, the quantitative evaluation of the risk influence of the current all configuration changes of external events includes: determining the type of external events; calculating the core damage frequency according to the type of external events; and quantitatively evaluating the risk influence of the current all configuration changes of external events based on the core damage frequency. Specifically, as known from the foregoing, the external events include but are not limited to: internal fire, internal flooding, earthquake event, strong wind and the like, thus, when quantitatively evaluating, the type is determined first, then the corresponding core damage frequency is calculated according to the type, and then the risk influence of the current all configuration changes of external events is evaluated according to the calculated core damage frequency.
[0078] Next, the internal fire is taken as an example for illustration.
[0079] Specifically, the maintenance activities that may cause the risk influence of internal fire are as follows:
[0080] 1) Maintenance activities that may cause fire (such as welding, use of cutting and grinding tools, instantaneous flammable materials, etc.);
[0081] 2) Fire detection or fire extinguishing system is unavailable;
[0082] 3) Removing or damaging fireproof barriers (for example, opening fireproof doors for maintenance, removing protective barriers on cable slots or conduits, etc.);
[0083] 4) Maintenance or unavailability of core damage mitigation equipment.
[0084] Since the above three risk influences can be managed by the fire prevention outline of each power plant, in the present application, the risk of unavailability of core damage mitigation equipment is focused on evaluation and management.
[0085] Specifically, the core damage frequency (CDF) of the fire scenario can be calculated by the following formula:
[0086] CDF i =IEF i ×SP i ×CCDP i (3-1);
[0087] CDF 总 =∑CDF i (3-2);
[0088] Wherein, CDF i is the core damage frequency of scenario i; IEF i is the scenario i initiating event frequency; SP i is the scenario i fire extinguishing failure probability; CCDP i is the scenario i conditional core damage probability; CDF总 This represents the core damage frequency of the total fire.
[0089] In this embodiment of the invention, the principle of envelope quantitative analysis is as follows:
[0090] The typical fire initiation event frequency for a single scenario is typically 1E-3 per year. For envelope design baseline events, the frequency can be lower than 1E-3. Generally, electrical maintenance activities for most high-risk equipment last less than one week (7 days). Assuming that maintenance results in no mitigation path under a given condition (i.e., CCDP set to 1.0), the fire ICDP can be 1E-5. If any mitigation path (CCDP < 1.0) and / or fire suppression system is available, the ICDP will decrease.
[0091] The calculation is performed using equation (3-1). If the maintenance activity lasts for one week, the initiating event frequency (IEF) is 1E-3 / year, and the SP... i =1 (assuming no fire extinguishing), CCDP i =1.0 (assuming no mitigation path), CDF i =IEF i ×SP i ×CCDP i =1E-03 / year; T = 1 week (0.02 years), ICDP i =CDF i ×T=2E-5 / year.
[0092] Based on the examples above, it can be seen that reducing the duration to approximately three days (72 hours, the typical duration of the equipment in the technical specifications) will reduce the ICDP to less than or equal to approximately 1E-5. If the mitigation equipment remains unchanged or the fire suppression system is available, the ICDP will continue to decrease. Even a single-success path with a conservative failure probability of 0.1 will result in an ICDP less than 1E-6 over a three-day maintenance duration. The results shown in Table 3-1 are based on Equation (3-1) and general rules for taking conservative values for relevant variables. These general rules are:
[0093] The frequency of initiation events is approximately 1E-3 / year.
[0094] The duration can be divided into periods of less than 3 days (0.01 years), 3-30 days (0.1 years), or more than 30 days.
[0095] The fire suppression system reduces the likelihood or impact of a fire by a factor of 10 (i.e., taking the probability of fire suppression failure SP = 0.1).
[0096] The failure probability of a single safe shutdown train is less than 0.1, and the failure probability of two or more safe shutdown trains is less than 0.01.
[0097] Table 3-1 Quantitative Summary Table
[0098]
[0099] Using the threshold criteria in Table 3-2, the numerical results in Table 3-1 can be converted to colors that represent the relative risk and acceptability of the various scenarios. These results are shown in Table 3-3.
[0100] Table 3-2 Configuration Risk Thresholds
[0101]
[0102]
[0103] Table 3-3 Risk Management Categories
[0104]
[0105] In Table 3-3, the three levels of risk management actions are described as follows:
[0106] 1) Normal Control:
[0107] Normal control means that the maintenance activity follows the normal work control process for the plant and no additional actions are required to address risk management issues.
[0108] 2) Risk Management Actions - Enhanced Control:
[0109] For configurations that result in minimal increases in the plant baseline risk, risk management actions should be considered. These actions are intended to increase the risk awareness of the appropriate plant personnel, more rigorously plan and control the activity, and take actions to control the duration and extent of the increased risk. Examples of risk management actions include:
[0110] Enhance risk awareness and risk control.
[0111] Shorten the duration of the maintenance activity.
[0112] Minimize the extent of the increased risk (e.g., reduce the likelihood of initiating events, protect redundant equipment (fire protection systems and alternate success paths), establish alternate success paths, etc.).
[0113] 3) Avoid Configuration or Further Evaluation:
[0114] Establish a final action threshold to ensure that significant risk configurations are not entered voluntarily in general. Since this method is only a quantitative envelope analysis, it is allowed for the user to use more rigorous tools or methods to determine if the significant conservatism can be eliminated, and acceptable results are obtained within the threshold range that allows these configurations to be performed.
[0115] Based on the above principles, the fire configuration risk of the maintenance activity can be specifically referred to Figure 3 .
[0116] Specifically, as shown in Figure 3 , first, it is judged whether the activity duration is less than 8 hours, if less than 8 hours, normal control is executed, if greater than 8 hours, it is identified whether the affected SSC supports the fire scenario after the safe shutdown of the fire, if not, normal control is executed, if yes, it is judged whether there are 2 or more safe shutdown paths, if yes, it is judged whether there is a fire extinguishing system, if yes, normal control is executed, if no, it is judged whether the activity duration is less than 30 days, if yes, normal control is executed, otherwise, risk management five is performed.
[0117] If there are not 2 or more safe shutdown paths available, it is judged whether there is only 1 safe shutdown path, if yes, it is further judged whether there is a fire extinguishing system, if yes, it is judged whether the activity duration is less than 30 days, if yes, normal control is executed, otherwise, risk management four is performed. If there is no fire extinguishing system, it is judged whether the activity duration is less than 3 days, if yes, normal control is executed, if greater than 3 days, it is judged whether the activity duration is less than 30 days, if yes, risk management three is performed, if greater than 30 days, it is avoided to enter or detailed assessment is performed.
[0118] If there is not only 1 safe shutdown path, it is judged whether there is a fire extinguishing system, if yes, it is judged whether the activity duration is less than 3 days, if yes, normal control is executed, if greater than 3 days, it is judged whether the activity duration is less than 30 days, if yes, risk management two is performed, if greater than 30 days, it is avoided to enter or detailed assessment is performed, if there is no fire extinguishing system, it is judged whether the activity duration is less than 3 days, if yes, risk management one is performed, if greater than 3 days, it is avoided to enter or detailed assessment is performed.
[0119] In the embodiment of the present application, the quantitative evaluation of the influence of the external event risk of all configuration changes by the risk monitor quantitative evaluation method (i.e. the risk monitor detailed quantitative evaluation method) comprises: obtaining a reference external event PSA model; reconstructing the reference external PSA model to obtain a real-time risk model; and quantitatively evaluating the influence of the external event risk of all configuration changes based on the real-time risk model. The reconstruction of the reference external PSA model to obtain the real-time risk model comprises: converting the reference external PSA model into a real-time risk model by a risk monitor.
[0120] Currently, the tool used in nuclear power plant for risk management is Risk Monitor, which is mainly used for internal event risk assessment. The risk monitor of nuclear power plant is used to provide instantaneous risk information of the plant in various operating states (including full power operation, low power operation and shutdown condition) and different configuration states, which reflects the actual risk information of the plant, rather than the average estimate of the baseline PSA model. Therefore, the external baseline PSA model cannot be directly applied in the Risk Monitor system, and it is necessary to establish a real-time fire risk model suitable for the application of Risk Monitor based on the baseline PSA model and model transformation, so as to reflect the influence of the change of plant configuration state on the fire risk analysis logic and analysis results in real time. Based on the above principle, the present application carries out Risk Monitor real-time model transformation based on the baseline external event PSA model, realizes the reconstruction of the baseline external event model, and obtains the real-time risk model.
[0121] For example, the external event is internal fire, and correspondingly, the baseline external event PSA model is defined as the baseline fire model, and the real-time risk model is defined as the fire real-time risk model. The present application carries out Risk Monitor real-time model transformation based on the baseline fire PSA model, and obtains the fire real-time risk model. For the reconstruction of the baseline fire PSA model, it is based on the reconstruction of the internal event PSA model, in addition to the specific lumped initiation event splitting, operation / standby column modeling and ignition frequency correction of fire, when carrying out the transformation of the baseline fire PSA model, the reconstruction of the remaining internal event PSA technical elements (such as maintenance event modeling, removed initiation event modeling, development event modeling, common cause improvement, etc.) is not needed, and the current internal event PSA model reconstruction method of nuclear power plant can be used.
[0122] Specifically, taking operation standby column modeling as an example, there are a large number of normal operating systems in nuclear power plant, and usually these systems have corresponding redundant standby columns, and the operation / standby relationship between the redundant columns in these systems is determined by the actual operation state of the plant at that time. In the baseline fire PSA model, considering the symmetry relationship between the redundant columns of the system, it is necessary to assume that there is a specific operation / standby relationship between the redundant columns in the average risk analysis. However, such assumption cannot reflect the actual operation state of the plant, especially when the operation / standby configuration relationship is asymmetric due to the exit of a device in a column. Unlike internal events, the reconstruction of fire real-time risk model also needs to consider the following factors:
[0123] (1) Fire will not cause damage to high melting point metals such as steel, therefore, non-active mechanical devices such as manual valves, stop valves, filters, heat exchangers, tanks, etc. do not need to be included in the list of fire PSA devices; it is necessary to screen whether the device to which the added basic event belongs is a fire PSA device.
[0124] (2) If it belongs to a fire PSA device, it is necessary to further screen the cables related to the fire PSA device, including power supply, control, display and instrument cables, etc., and determine the laying path of the cables.
[0125] (3) In the fire real-time risk model, corresponding fire failure events and fire failure agent events need to be established for the added basic events.
[0126] Therefore, according to the requirements of Risk Monitor, on the basis of the benchmark fire PSA model, a fire real-time risk model suitable for Risk Monitor application is established through model transformation to reflect the influence of power plant configuration state changes on fire risk analysis logic and analysis results in real time.
[0127] Step S105: generating a risk management action strategy based on the quantitative evaluation results.
[0128] Specifically, after quantitatively evaluating the influence of all configuration changes on external event risks in step S104 by using the envelope quantitative evaluation method or the Risk Monitor detailed quantitative evaluation method, a corresponding risk management action strategy can be generated based on the quantitative evaluation results. For example, in the envelope quantitative evaluation method, taking internal fire as an example, the corresponding risk management action strategy is shown in the fire risk management action matrix in Table 3-4.
[0129] Table 3-4 Fire risk management action matrix
[0130]
[0131] Specifically, in Table 3-4:
[0132] (1) Fire monitoring can reduce the likelihood of a fire. Fire monitors should also be aware of important equipment in the area. If a fire occurs, it must be prevented from affecting these critical devices.
[0133] (2) Fire monitoring is important to prevent challenges to the plant (i.e., to prevent fires that cause the plant to trip off). The importance of protecting equipment in the fire area is reduced (but still important) because there is still a way to succeed.
[0134] (3) Fire monitoring It is important to prevent challenges to the plant, such as (2). However, since the risk of this configuration is relatively low (at least two successful paths are available), it can be able to provide sufficient coverage by patrol or intermittent fire monitoring.
[0135] (4) If the fire extinguishing system is restored (i.e., available), this configuration will become the configuration of "Risk Management Two".
[0136] (5) The fire extinguishing system is available, so there is not much to improve. However, in the case of concern, it will be prudent to protect the fire extinguishing (and related detection) system.
[0137] (6) If the area has a fire detection system, consider protecting the detection system, and it can be possible to set up continuous fire monitoring.
[0138] (7) At least two successful paths are available in this configuration. If the successful path is reliable, it can not be beneficial to establish a backup successful path.
[0139] The present application can make the nuclear power plant include the system equipment related to the external event (such as the fire detection system, the fire extinguishing system, etc.) into the management range after the configuration risk assessment of the external event, can well solve the problem of the unavailability risk assessment of the equipment, especially the superimposed risk, which is not covered by the current nuclear power plant system specification management. The total sum of the contributions of the internal and external event risks is considered in the nuclear power plant risk management technical specification (RMTS), thereby avoiding the situation of ignoring important risks or overly conservative risk management, and the risk management of the unavailability of the safety mitigation equipment with significant external event risk can also appropriately relax the situation of overly conservative risk threshold when only the internal event is configured and evaluated, thereby supporting the realization of additional safety and economic benefits.
[0140] Reference Figure 4 The present application also provides a nuclear power plant external event configuration risk management evaluation system.
[0141] As Figure 4 shown, the nuclear power plant external event configuration risk management evaluation system comprises:
[0142] A change information acquisition unit 401 is configured to acquire configuration change information of the nuclear power plant.
[0143] A risk impact analysis unit 402 is configured to analyze the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant.
[0144] A qualitative screening unit 403 is configured to perform qualitative screening evaluation on the current configuration change to obtain the external event risk impact of all current configuration changes.
[0145] The quantitative evaluation unit 404 is configured to quantitatively evaluate the influence of the current all-configuration-changed external event risk, and obtain a quantitative evaluation result.
[0146] The management strategy generation unit 405 is configured to generate a risk management action strategy based on the quantitative evaluation result.
[0147] Specifically, the specific cooperation operation process between the units in the nuclear power plant external event configuration risk management evaluation system can refer to the above-mentioned nuclear power plant external event configuration risk management evaluation method, and will not be described here.
[0148] In addition, the electronic device of the present application includes a memory and a processor; the memory is used to store a computer program; the processor is used to execute the computer program to realize the nuclear power plant external event configuration risk management evaluation method of any one of the above. Specifically, according to the embodiments of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments of the present application include a computer program product, which includes a computer program carried on a computer readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such embodiments, the computer program can be downloaded and installed by the electronic device and executed to perform the above-mentioned functions defined in the method of the embodiments of the present application. The electronic device in the present application can be a notebook, a desktop, a tablet computer, a smart phone, etc. terminal, or a server.
[0149] In addition, the present application also provides a storage medium storing a computer program, which is executed by a processor to implement the method for configuring risk management evaluation of external events of a nuclear power plant according to any one of the above. Specifically, it should be noted that the storage medium of the present application can be a computer readable signal medium or a computer readable storage medium, or any combination of the two. The computer readable storage medium may, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or apparatus. In the present application, the computer readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer readable program code. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium other than the computer readable storage medium, which can send, propagate or transmit a program for use by or in conjunction with an instruction execution system, device or apparatus. The program code contained in the computer readable medium can be transmitted by any suitable medium, including but not limited to a wire, a cable, an RF (radio frequency) or the like, or any suitable combination of the above.
[0150] The above computer readable medium can be included in the above electronic device; or can exist separately and not be assembled into the electronic device.
[0151] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method part.
[0152] Those skilled in the art will further realize that the mere conception of the examples described herein is not inducing the patentable subject matter recited in each claim. The combinations and / or sequences of various example elements, steps, operations, actions, and / or functions described in each example are not necessarily the only possible combinations and / or sequences for practicing the claimed subject matter. Those skilled in the art will further realize that the mechanisms of the various examples described herein are for implementing the several embodiments and are not meant to be limiting as to the scope of the claimed subject matter. That is, the protection afforded to the claimed subject matter is not limited to the mechanisms of practicing the described examples. Therefore, the claimed subject matter should be understood to encompass a variety of subject matter, and equally obvious to those in the art, including but not limited to the following:
[0153] The steps of a method or algorithm described in connection with the examples disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM, flash memory, ROM, electrically programmable ROM (EPROM or EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, the storage medium can be integral to the processor. The processor and the storage medium can reside in an ASIC.
[0154] The examples described herein are only intended to illustrate the technical concepts and features of the present application, and the purpose is to enable those skilled in the art to understand the content of the present application and to implement it accordingly, and cannot limit the protection scope of the present application. Any equivalent changes and modifications made within the scope of the claims of the present application shall be included in the scope of the claims of the present application.
Claims
1. A method of external event configuration risk management assessment for a nuclear power plant, characterized by, The method comprises the following steps: obtaining configuration change information of a nuclear power plant; analyzing the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant; if yes, performing a qualitative screening evaluation on the current configuration change to obtain the external event risk impact of all current configuration changes; performing a quantitative evaluation on the external event risk impact of all current configuration changes to obtain a quantitative evaluation result; generating a risk management action strategy based on the quantitative evaluation result.
2. The nuclear power plant external event configuration risk management assessment method of claim 1, wherein, The analysis of the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant comprises: determining whether the current configuration change only has an internal event risk according to the configuration change information; if yes, determining that the current configuration change does not have an external event risk impact; if no, determining whether the current configuration change does not affect an external event scenario and an unavailable device is used to mitigate internal events and external events; if the current configuration change does not affect an external event scenario and an unavailable device is used to mitigate internal events, determining that the current configuration change has an external event risk impact; if the current configuration change does not affect an internal event risk and affects an external event risk, determining that the current configuration change has an external event risk impact.
3. The nuclear power plant external event configuration risk management assessment method of claim 1, wherein, The qualitative screening evaluation of the current configuration change to obtain the external event risk impact of all current configuration changes comprises: screening all external event risk impacts caused by the current configuration change based on a screening table to obtain a preliminary screening result; performing a secondary evaluation on the preliminary screening result to obtain the external event risk impact of all current configuration changes.
4. The nuclear power plant external event configuration risk management assessment method of claim 1, wherein, The quantitative evaluation of the external event risk impact of all current configuration changes to obtain a quantitative evaluation result comprises: using an envelope quantitative evaluation method to quantitatively evaluate the external event risk impact of all current configuration changes to obtain a quantitative evaluation result; or, using a risk monitor quantitative evaluation method to quantitatively evaluate the external event risk impact of all current configuration changes to obtain a quantitative evaluation result.
5. The nuclear power plant external event configuration risk management assessment method according to claim 4, characterized in that, The quantitative evaluation of the external event risk impact of all current configuration changes using the envelope quantitative evaluation method comprises: determining an external event type; calculating a core damage frequency according to the external event type; quantitatively evaluating the external event risk impact of all current configuration changes based on the core damage frequency.
6. The nuclear power plant external event configuration risk management assessment method of claim 4, wherein, The quantitative evaluation of the external event risk impact of all current configuration changes using the risk monitor quantitative evaluation method comprises: obtaining a baseline external event PSA model; performing model reconstruction on the baseline external PSA model to obtain a real-time risk model; quantitatively evaluating the external event risk impact of all current configuration changes based on the real-time risk model.
7. The nuclear power plant external event configuration risk management assessment method according to claim 6, characterized in that, The model reconstruction of the baseline external PSA model to obtain a real-time risk model comprises: performing a risk monitor real-time model conversion on the baseline external PSA model to obtain the real-time risk model.
8. A nuclear power plant external event configuration risk management assessment system, characterized by, comprises: a change information acquisition unit configured to obtain configuration change information of a nuclear power plant; a risk impact analysis unit configured to analyze the configuration change information to determine whether the current configuration change has an external event risk impact on the nuclear power plant; a qualitative screening unit configured to perform a qualitative screening evaluation on the current configuration change to obtain external event risk impacts of all current configuration changes; a quantitative evaluation unit configured to perform a quantitative evaluation on the external event risk impacts of all current configuration changes to obtain a quantitative evaluation result; a management strategy generation unit configured to generate a risk management action strategy based on the quantitative evaluation result.
9. A storage medium, characterized by The storage medium stores a computer program adapted to be loaded by the processor to execute the steps of the nuclear power plant external event configuration risk management evaluation method according to any one of claims 1 to 7.
10. An electronic device, comprising: The device comprises a memory and a processor, wherein the memory stores a computer program, and the processor executes the steps of the nuclear power plant external event configuration risk management evaluation method according to any one of claims 1 to 7 by invoking the computer program stored in the memory. The device comprises a memory and a processor, wherein the memory stores a computer program, and the processor executes the steps of the nuclear power plant external event configuration risk management evaluation method according to any one of claims 1 to 7 by invoking the computer program stored in the memory.