Reactor backup safety shutdown method and system
By introducing hardware switches and logic circuits into the reactor control system of nuclear power plants, the risk of reactor shutdown caused by digital chip network attacks has been resolved, and reliable shutdown and residual heat removal have been achieved in the event of network attacks or system crashes, thereby improving the safety and reliability of the system.
Patent Information
- Application Number
- CN202511417671.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-02-06
AI Technical Summary
In existing nuclear power plant reactor control systems, digital chips are vulnerable to cyberattacks, which could prevent reactors from shutting down and removing residual heat as required, posing a serious safety hazard.
The reactor backup channel is constructed using pure hardware switches and logic circuits. The shutdown command is generated and transmitted through hardware switches and logic circuits to ensure normal operation in the event of digital system failure or network attack, avoiding reliance on software and network communication of the preferred module.
This ensures that the reactor can be reliably shut down in the event of a reactor main control system failure or a cyberattack, reducing the probability of system failure, improving safety and reliability, preventing misoperation, and simplifying the operation process.
Smart Images

Figure CN121483672A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of nuclear reactor shutdown technology, and in particular to a reactor backup safe shutdown method, system, equipment and medium. Background Technology
[0002] Nuclear power plants generate electricity by controlling the reactivity of the nuclear reactor, regulating the reactor's output thermal power, and driving the turbine. Generally, during normal operation, the Nuclear Power Plant Control and Monitoring System (PSAS) and the Reactor Power Control System (RPCS) regulate the reactor's operating status to maintain it under normal operating conditions; this is the first layer of defense in the nuclear power plant's instrumentation and control system. When an abnormal situation occurs, the Reactor Shutdown Protection System (RPS) generates a protection signal. After logical processing such as "two out of four," the signal generates a reactor shutdown command. The shutdown circuit breaker opens, the control rod actuators lose power, and the control rods quickly fall into the reactor core under gravity, thus shutting down the reactor; this is the second layer of defense in the nuclear power plant's instrumentation and control system. When the Reactor Shutdown Protection System (RPS) software fails due to a common cause compounded by a design basis accident, the KDOS (Knowledge, Diversity, and Safety) system can automatically or manually initiate a shutdown command, activating selected dedicated safety facilities (emergency feedwater, main feedwater isolation, main steam isolation, safety injection, etc.). This is the third layer of defense in the nuclear power plant's instrumentation and control system. In the event of a plant-wide power outage similar to the Fukushima accident, the Severe Accident Control and Instrumentation (KDA) system monitors and manually controls necessary monitoring instruments and field equipment to prevent and mitigate severe accidents. This is the fourth layer of defense in the nuclear power plant's instrumentation and control system.
[0003] However, all of the aforementioned protective actions require logical judgment by the Optimization Module (CIM) before proceeding with safety actions such as reactor shutdown. Currently, the CIMs used in domestic nuclear power plants employ FPGA or CPLD processing chips, which are digital technologies and are all imported. These chips have closed-source architectures, posing a risk of cyberattacks. Even if the probability of such a risk is very low, it could result in the reactor failing to shut down and remove residual heat as required, with potentially severe or even catastrophic consequences. Therefore, a safe reactor shutdown method that avoids the risk of cyberattacks is urgently needed. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a reactor backup safe shutdown method and system to address the risks of being unable to enter and maintain a shutdown state and remove residual heat due to digital chip failure, as well as the risks of cyberattacks.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] In a first aspect, the present invention provides a reactor backup safe shutdown method, comprising:
[0008] When the system optimization module is unable to issue an instruction, the first hardware switch closes, issuing the first closing instruction.
[0009] In response to the first closing instruction, the second hardware switch closes, a second closing instruction is issued, and a first safety control instruction is generated through AND logic;
[0010] The first safety control command is transmitted to the corresponding safety device via OR logic to directly ignore the preferred module, and a reactor shutdown operation is performed.
[0011] As a preferred embodiment of the reactor backup safety shutdown method described in this invention, wherein: when the preferred module is operating normally, the first hardware switch and the second hardware switch do not perform closing actions;
[0012] The preferred module issues a second safety control command, which is transmitted to the corresponding safety device via OR logic to perform a reactor shutdown operation.
[0013] As a preferred embodiment of the reactor backup safe shutdown method described in this invention, the OR logic is set after the preferred module for judgment;
[0014] The first security control command and the second security control command are determined by an OR logic. If the first security control command exists, it is transmitted to the corresponding security device.
[0015] As a preferred embodiment of the reactor backup safety shutdown method described in this invention, wherein: the AND logic is set before the OR logic judgment;
[0016] If either the first hardware switch or the second hardware switch is in a closed state and the other switch is in an open state, the first safety control command will not be generated through AND logic.
[0017] In a second aspect, the present invention provides a reactor backup safety shutdown system, comprising:
[0018] The hardware control module includes a first hardware switch and a second hardware switch, which are used to manually operate the switches to close and issue corresponding closing commands.
[0019] The first judgment module is used to generate the first security control instruction through AND logic;
[0020] The second judgment module is used to judge and transmit the first security control command and the second security control command through OR logic.
[0021] As a preferred embodiment of the reactor backup safety shutdown system described in this invention, it further includes: a selection module, used to perform logical judgment on all shutdown signals set before the selection module, and to issue them after judgment.
[0022] As a preferred embodiment of the reactor backup safety shutdown system described in this invention, it further includes: a reactor protection and safety monitoring module, used to generate a shutdown signal when an abnormal situation occurs in the nuclear power plant, the shutdown signal is sent to the preferred module, and after logical processing, a reactor shutdown command is generated.
[0023] As a preferred embodiment of the reactor backup safety shutdown system described in this invention, it further includes: a diversified protection module, used to automatically or manually initiate a shutdown signal when a design baseline accident occurs due to a common cause failure, send the signal to the preferred module, and generate a reactor shutdown command after logical processing, thereby activating the selected dedicated safety facilities.
[0024] As a preferred embodiment of the reactor backup safety shutdown system described in this invention, it further includes: a severe accident instrumentation and control module, used to monitor and manually control monitoring instruments and field equipment in the event of a plant-wide power outage, generate a shutdown signal, and send the shutdown signal to the preferred module, which generates a reactor shutdown command after logic processing.
[0025] As a preferred embodiment of the reactor backup safety shutdown system described in this invention, it further includes: a non-safety-grade DCS control module, used to process conventional control signals and generate equipment operation instructions during normal operation or non-emergency situations of the nuclear power plant, so as to realize the daily operation control and parameter adjustment of the reactor.
[0026] Compared with existing technologies, the beneficial effects of this invention are as follows: The method of this invention constructs the entire reactor backup channel purely in hardware, independent of the software, processor, power supply, or communication network of the preferred modules. Even in the event of a complete collapse, system crash, virus attack, or common software failure in the reactor main control digital system, it can still function normally, ensuring the absolute availability of the safe shutdown function. Hardware switches and logic circuits reduce the probability of simultaneous failure of the main control system and the backup system due to the same cause, thereby significantly improving the overall reliability of the entire system. Setting two hardware switches to be closed simultaneously to trigger shutdown prevents accidental shutdowns caused by single switch failure, accidental human contact, or signal interference, improving the backup system's protection against accidental activation. Furthermore, through OR logic circuits, as long as the hardware loop is triggered, the shutdown command will be executed unconditionally, ensuring the mandatory execution of safety actions. The entire solution is simple, highly operable, and extremely safe. Attached Figure Description
[0027] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 This is a schematic diagram of the overall process of a reactor backup safe shutdown method according to an embodiment of the present invention.
[0029] Figure 2 This is a schematic diagram of a specific architecture of a reactor backup safety shutdown system according to an embodiment of the present invention.
[0030] Figure 3 This is a schematic diagram of the overall architecture of a reactor backup safety shutdown system according to an embodiment of the present invention. Detailed Implementation
[0031] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0032] Example 1, referring to Figures 1-2 As an embodiment of the present invention, a reactor backup safe shutdown method is provided, comprising:
[0033] S100: When the system optimization module is unable to issue an instruction, the first hardware switch closes and issues the first closing instruction;
[0034] S200: In response to the first closing instruction, the second hardware switch closes, a second closing instruction is issued, and a first safety control instruction is generated through AND logic;
[0035] S300: The first safety control instruction is transmitted to the corresponding safety device through the OR logic to directly ignore the preferred module, and a reactor shutdown operation is performed.
[0036] In one alternative implementation, such as Figure 2 As shown, the first hardware switch is the push-button switch in the main control room, and the second hardware switch is the key switch for the shift supervisor. By adding a new switch connected by a cable, the judgment operation of pure software logic is avoided, and complete simulation is achieved by combining AND-OR circuit logic.
[0037] In another alternative implementation, the first and second hardware switches can also be toggle switches, mechanical switches that switch the circuit state by toggling a lever. They can be designed to be monostable or bistable, replacing push-button switches for initial signal triggering, or replacing key switches for shift leader confirmation; or they can be rotary switches replacing key switches for shift leader hierarchical authorization confirmation, rotated to a specific position to activate a reactor stop command.
[0038] It should be noted that the present invention preferably uses push-button switches and key switches, because they are usually physical mechanical or electronic switching devices that do not rely on network communication and are immune to network attacks. Furthermore, key switches are controlled by administrators, making them safer. Both switches are simple to operate and can ensure reliable operation in emergency situations.
[0039] The specific process is as follows: when the optimization module CIM fails to issue instructions due to a network attack, the main control operator can press the button switch in an emergency and then ask the shift leader to operate the key switch. After the shift leader opens the key switch, the safety control instructions can bypass the optimization module and directly operate the selected safety equipment to achieve the function of safe reactor shutdown and continuous discharge of residual heat.
[0040] In this embodiment of the application, when the preferred module is operating normally, the first hardware switch and the second hardware switch do not close.
[0041] The preferred module issues a second safety control command, which is transmitted to the corresponding safety device via OR logic to perform a reactor shutdown operation.
[0042] For example, this step is the shutdown process in a nuclear power plant under normal operating conditions. The preferred module, as a safety-level control system, is responsible for monitoring the reactor status and generating a second safety control command when an anomaly is detected, such as power over-limit. This command drives safety devices, such as control rod insertion or boric acid injection, via OR logic to achieve rapid shutdown and residual heat removal.
[0043] In another alternative implementation, real-time feedback, such as a control room display screen or indicator light, can be added when the preferred module is operating normally to confirm that the second safety control command has been successfully transmitted to the safety equipment, thereby increasing the operator's confidence in the system.
[0044] It should be noted that the implementation steps of this application are automated shutdown command transmission. The preferred module directly transmits the second safety control command to the safety equipment through OR logic. The logic path is clear, reducing intermediate links and reducing failure points. At the same time, the OR logic can be executed quickly after anomaly detection, meeting the high timeliness requirements of nuclear power plants for emergency shutdown.
[0045] In this embodiment of the application, the OR logic is set to be judged after the preferred module;
[0046] The first security control command and the second security control command are determined by an OR logic. If the first security control command exists, it is transmitted to the corresponding security device.
[0047] It should be noted that the "OR logic" setting after the selection module is the core design of the entire scheme. Its placement allows shutdown commands to be output from either the selection module (i.e., normal mode) or the hardware switch (i.e., backup mode). During normal operation, the selection module transmits commands via OR logic, while in the event of a CIM failure, the hardware switch takes over command transmission via the same OR logic. This step, by explicitly stating that the hardware switch does not activate during normal operation, separates the software-controlled primary shutdown from the hardware-controlled backup shutdown, forming a hierarchical safety strategy. This ensures the system can reliably drive safety devices in both modes, enhancing the overall system's robustness and resilience against failures.
[0048] Meanwhile, the OR logic circuit design is simple and easy to integrate into existing nuclear power plant control systems. It is suitable for various reactor types, and through standardized logic interfaces, implementation costs and adaptation difficulties can be reduced.
[0049] In an alternative implementation, based on the above implementation, the response time of the "OR logic" circuit can also be set, for example, the response time needs to be less than 100 milliseconds, to ensure that the overall solution's response meets nuclear safety standards.
[0050] In another alternative implementation, parallel logic circuits can be added to the "OR logic" of the above implementation to further reduce the failure risk of a single logic path.
[0051] In this embodiment of the application, the AND logic is set before the OR logic judgment;
[0052] If either the first hardware switch or the second hardware switch is in a closed state and the other switch is in an open state, the first safety control command will not be generated through AND logic.
[0053] It should be noted that by setting an AND logic before the OR logic, both the first and second hardware switches must be closed to generate the first safety control command, thus preventing accidental reactor shutdown. Nuclear power plant shutdown operations involve significant safety and economic consequences; misoperation can lead to unnecessary downtime or risks. The AND logic implements hierarchical authorization, thereby reducing the risk of accidental or unauthorized operation by a single operator, ensuring that backup shutdowns are only performed when necessary and confirmed, and enhancing system controllability and reliability.
[0054] Meanwhile, the overall logic, acting as the control point for generating backup mode instructions, ensures that a shutdown is only triggered after double confirmation, forming a unified control architecture for primary and backup modes together with the OR logic. Furthermore, because it is based on the physical state judgment of a pure hardware switch, it does not rely on the network or software, making it immune to network attacks and ensuring the reliable execution of the backup shutdown function, thus addressing the pain points caused by network security threats.
[0055] In an alternative implementation, based on the above implementation, the response time of the "AND logic" circuit can also be set. For example, the response time needs to be less than 50 milliseconds to ensure that instruction generation in backup mode is fast enough to match the timeliness requirements of emergency shutdown.
[0056] In another alternative implementation, based on the above implementation, a time window limit can be set before the logic, for example, the two switches need to be closed within a specific time to reduce the possibility of operator accidental touch and further reduce the risk of misoperation.
[0057] Example 2, refer to Figures 2-3 This is one embodiment of the present invention. Based on the above embodiment, a system for applying a reactor backup safe shutdown method is provided.
[0058] In the embodiments of this application, such as Figure 2 and 3 As shown, a reactor backup safety shutdown system includes:
[0059] The hardware control module includes a first hardware switch and a second hardware switch, which are used to manually operate the switches to close and issue corresponding closing commands.
[0060] The first judgment module is used to generate the first security control instruction through AND logic;
[0061] The second judgment module is used to judge and transmit the first security control command and the second security control command through OR logic.
[0062] For example, the hardware switch in the hardware control module can be any hardware switch, such as: push button switch, key switch, toggle switch, rotary switch, push-pull switch, mechanical limit switch, etc. One switch is controlled by the main control room, and the other is controlled by the shift supervisor's station in open loop, forming a double confirmation.
[0063] The first judgment module is an AND logic circuit, which receives a closing instruction from the hardware control module. The closing signal is in binary state and is transmitted to the input terminal of the AND logic circuit through physical circuitry. The AND logic circuit performs logical operations on the closing signals of the first and second hardware switches. Only when both switches are in the closed state, i.e., both inputs are 1, does it output 1, generating the first safety control instruction.
[0064] The first safety control command is an electrical signal, such as a relay closing or a digital pulse, which is transmitted through physical lines to the second judgment module, i.e., an OR logic circuit, for subsequent driving of safety devices.
[0065] The circuits of the first and second decision modules are independent of the network system of the preferred module (CIM), which can protect against network attacks and ensure that the backup shutdown function can be reliably executed when the CIM fails.
[0066] In this embodiment of the application, a reactor backup safety shutdown system further includes: an optimization module, used to perform logical judgment on all shutdown signals set before the optimization module, and to issue them after judgment.
[0067] It should be noted that the optimization module is a core component of the nuclear power plant's safety-grade control system. It is responsible for monitoring the reactor's operating status in real time and generating safety control commands in case of abnormalities. During normal operation, the CIM can automatically handle abnormalities without manual intervention. The CIM is usually integrated into the digital control system and may communicate via network. Currently, the optimization modules used in domestic nuclear power plants all adopt FPGA or CPLD processing chips, which are digital technologies and are all imported chips. The design architecture of these chips is not open source, which poses a risk of network attacks. Even if the probability of such a risk is very low, the result is that the reactor cannot be shut down and residual heat removed as required, which would have very serious consequences.
[0068] In this embodiment of the application, a reactor backup safety shutdown system further includes: a reactor protection and safety monitoring module, used to generate a shutdown signal when an abnormal situation occurs in the nuclear power plant, the shutdown signal is sent to the optimization module, and after logical processing, a reactor shutdown command is generated.
[0069] It should be noted that the reactor protection and safety monitoring module is a key component in the nuclear power plant's safety-level control system. It can collect key reactor parameters in real time through sensors, such as neutron flux, temperature, and pressure, and then detect abnormal situations. When an abnormality is detected and reaches a safety threshold, a shutdown signal is generated and sent to the optimization module.
[0070] In this application embodiment, a reactor backup safety shutdown system further includes: a diversified protection module, used to automatically or manually initiate a shutdown signal when a design basis accident occurs due to a common cause failure, send it to the preferred module, and generate a reactor shutdown command after logical processing to activate the selected dedicated safety facility.
[0071] It should be noted that the diversified protection module is a redundant component in the safety-level control system of a nuclear power plant. It is designed to deal with the failure of the main protection system due to the superposition of common cause failure and design basis accident, and to identify the common cause failure superposition of design basis accident, such as earthquake, power loss, etc. It generally adopts different technologies from the main protection system, such as hardware or logic architecture.
[0072] In this embodiment of the application, a reactor backup safety shutdown system further includes: a severe accident instrumentation and control module, used to monitor and manually control monitoring instruments and field equipment in the event of a plant-wide power outage, generate a shutdown signal, and send the shutdown signal to the optimization module, which generates a reactor shutdown command after logic processing.
[0073] It should be noted that the severe accident instrumentation and control module is a dedicated component in the safety-level control system of a nuclear power plant, designed to ensure reactor safety under extreme conditions. In the event of a plant-wide power outage, it monitors key reactor parameters through an independent power supply or passive sensors, and can generate a shutdown signal through manual control or automatic detection, which is then sent to the optimization module.
[0074] In this application embodiment, a reactor backup safety shutdown system further includes: a non-safety-grade DCS control module, used to process conventional control signals and generate equipment operation instructions during normal operation or non-emergency situations of the nuclear power plant, so as to realize the daily operation control and parameter adjustment of the reactor.
[0075] It should be noted that the non-safety-grade DCS control module is a non-safety-grade component in the nuclear power plant control system. It is responsible for daily operation and management. Under normal operation or non-emergency conditions of the nuclear power plant, it collects and processes routine control signals. It usually communicates through the network and may also be affected by network attacks or failures. If the network or system fails, it may be unable to perform effective actions.
[0076] like Figure 3 As shown, in addition to the main modules mentioned above, the entire system also includes: Auxiliary Control Panel (ACP), Non-Safety Operator Station (OWP), Emergency Operation Panel (ECP), Diversity Control Panel (DHP), Severe Incident Control Panel (SAP), Gateway (GWP), Safety System Bus, M-net, S-net, Signal Isolation Distribution Cabinet, Safety-grade Instruments and Actuators, Non-Safety-grade Instruments and Actuators, Logic and Relays, and Logic OR Relays.
[0077] In summary, nuclear power is a conservative industry, and cyberattacks have only begun to appear in recent years. Currently, it has become a very strong system composed of various control modules. The reactor control system generally uses multi-layered safety design, such as reactor protection and safety monitoring modules, and diversified protection modules, to ensure that rapid shutdown and residual heat removal can still be achieved under design basis accidents or extreme conditions.
[0078] However, these modules increasingly rely on software algorithms and network communication, which, while improving automation and operational efficiency, also introduces potential risks of cyberattacks. In recent years, cyberattacks, such as malware intrusions, have posed a growing threat to industrial control systems, with nuclear power plants, as critical infrastructure, becoming prime targets. If core modules like the CIM (Center for Isolation and Mobility) fail due to a cyberattack, reactor shutdown signals may fail to be generated, jeopardizing reactor safety.
[0079] Therefore, this invention, through a simple yet ingenious design, employs pure hardware switches and logic circuits, completely independent of the network system, thus thoroughly avoiding the risk of CIM and other modules failing due to network attacks. Hardware switches, such as buttons or key switches, generate signals through physical actions, combining AND and OR logic to ensure the reliability of instruction generation and transmission.
[0080] The logic circuit requires dual confirmation from both the operator and the shift supervisor to prevent single-point misoperation while keeping the operation process simple; or the logic circuit serves as a unified interface for normal and backup modes, ensuring consistent instruction transmission paths in both modes, reducing system complexity and maintenance costs; moreover, the hardware switches and logic circuits are simple to design, easy to integrate into existing nuclear power plant control systems, applicable to various reactor types, with low implementation costs and convenient maintenance.
[0081] The above is a schematic scheme of a reactor backup safe shutdown method. It should be noted that the technical solution of this reactor backup safe shutdown system and the technical solution of the reactor backup safe shutdown method described above belong to the same concept. For details not described in detail in the technical solution of the reactor backup safe shutdown system in this embodiment, please refer to the description of the technical solution of the reactor backup safe shutdown method described above.
[0082] Based on the above description of the implementation methods, those skilled in the art will clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.
[0083] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A reactor backup safe shutdown method, characterized in that, include: When the system optimization module is unable to issue an instruction, the first hardware switch closes, issuing the first closing instruction. In response to the first closing instruction, the second hardware switch closes, a second closing instruction is issued, and a first safety control instruction is generated through AND logic; The first safety control command is transmitted to the corresponding safety device via OR logic to directly ignore the preferred module, and a reactor shutdown operation is performed.
2. The reactor backup safe shutdown method as described in claim 1, characterized in that, When the optimization module is operating normally, the first hardware switch and the second hardware switch do not close. The preferred module issues a second safety control command, which is transmitted to the corresponding safety device via OR logic to perform a reactor shutdown operation.
3. A reactor backup safe shutdown method as described in claim 2, characterized in that, The OR logic is set after the optimization module for judgment; The first security control command and the second security control command are determined by an OR logic. If the first security control command exists, it is transmitted to the corresponding security device.
4. A reactor backup safe shutdown method as described in claim 3, characterized in that, The AND logic is set before the OR logic judgment; If either the first hardware switch or the second hardware switch is in a closed state and the other switch is in an open state, the first safety control command will not be generated through AND logic.
5. A reactor backup safety shutdown system, employing the method described in any one of claims 1-4, characterized in that, include: The hardware control module includes a first hardware switch and a second hardware switch, which are used to manually operate the switches to close and issue corresponding closing commands. The first judgment module is used to generate the first security control instruction through AND logic; The second judgment module is used to judge and transmit the first security control command and the second security control command through OR logic.
6. A reactor backup safety shutdown system as described in claim 5, characterized in that, Also includes: The selection module is used to perform logical judgments on all shutdown signals set before the selection module, and then send them out after the judgment.
7. A reactor backup safety shutdown system as described in claim 6, characterized in that, Also includes: The reactor protection and safety monitoring module is used to generate a shutdown signal when an abnormal situation occurs in the nuclear power plant. The shutdown signal is sent to the optimization module, which generates a reactor shutdown command after logical processing.
8. A reactor backup safety shutdown system as described in claim 7, characterized in that, Also includes: The diversified protection module is used to automatically or manually initiate a shutdown signal when a design baseline accident occurs due to a common cause failure. The signal is sent to the optimization module, which processes the signal logically to generate a reactor shutdown command and activate the selected dedicated safety facilities.
9. A reactor backup safety shutdown system as described in claim 8, characterized in that, Also includes: The severe accident instrumentation and control module is used to monitor and manually control the monitoring instruments and field equipment in the event of a plant-wide power outage, generate a shutdown signal, and send the shutdown signal to the optimization module. After logic processing, a reactor shutdown command is generated.
10. A reactor backup safety shutdown system as described in claim 9, characterized in that, Also includes: Non-safety grade DCS control modules are used in normal operation or non-emergency situations of nuclear power plants to process routine control signals and generate equipment operation instructions to achieve daily operation control and parameter adjustment of the reactor.