Emergency status classification method, device, computer equipment and storage medium
By obtaining and analyzing the operating status, system failure and disaster information of nuclear power plant units and determining the level of emergency operations, the problem of incomplete emergency status grading in the existing technology has been solved, and more accurate and efficient emergency response has been achieved.
Patent Information
- Application Number
- CN202110758745.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-05
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2041-07-05
AI Technical Summary
The existing technology relies on the relationship between barriers and accident handling procedures in the emergency status grading of nuclear accidents, and fails to fully consider the operating status, system failure and disaster information, resulting in the incomplete classification of emergency status.
By obtaining the operation information during the unit operation, including operating status information, system failure information and disaster information, determine whether the initial conditions for emergency action level are triggered, the emergency action level is determined based on the triggering conditions of each emergency action level is determined, and the highest emergency level is selected as the emergency state level.
This method takes into account more aspects of operation information, improves the perfection and accuracy of emergency status grading, and ensures that emergency response can be carried out quickly and effectively in nuclear accidents.
Smart Images

Figure CN113537743B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a method and device for classifying emergency states, a computer device, and a storage medium. Background Art
[0002] A nuclear accident is different from other accidents, as it may lead to an unacceptable release of radioactive substances. In order to quickly and effectively control an accident and mitigate its consequences in the event of an accident, a nuclear power plant should have a thorough nuclear accident emergency plan and sufficient emergency preparedness. In the emergency plan of the operating unit and the corresponding emergency response procedures, the classification of emergency states and the emergency action levels are very important parts. The main purpose of classifying emergency states is to classify the emergency states according to the severity of the accident and determine the corresponding emergency action levels.
[0003] Nuclear power plants are generally equipped with a system of operating procedures to monitor and control the unit under various operating conditions to achieve real-time monitoring of the safety state of the unit. In the related art, the classification of emergency states is only determined based on the relationship between the barrier type and the accident handling procedures, and this method of classifying emergency states is not perfect enough. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide a method and device for classifying emergency states, a computer device, and a storage medium with a more perfect perspective.
[0005] An emergency state classification method, the method comprising:
[0006] Obtaining operation information during the operation of the unit; the operation information includes at least one of operation status information, system failure information, and disaster information;
[0007] Based on various types of the operation information, determining whether to trigger the initial conditions of the corresponding emergency action levels, and obtaining the triggering situation of the initial conditions of the emergency action levels;
[0008] According to the triggering situation of each of the initial conditions of the emergency action levels, determining the corresponding emergency action levels;
[0009] Selecting the highest emergency level among the emergency action levels and determining it as the emergency state level.
[0010] An emergency state classification device, the device comprising:
[0011] An obtaining module, configured to obtain operation information during the operation of the unit; the operation information includes at least one of operation status information, system failure information, and disaster information;
[0012] A condition judgment module, configured to determine whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information, and obtain the triggering situation of the initial conditions of the emergency action level;
[0013] An emergency action level determination module, configured to determine the corresponding emergency action level for each according to the triggering situation of the initial conditions of each emergency action level;
[0014] A status classification module, configured to determine the emergency status level in combination with each of the emergency action levels.
[0015] A computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0016] Obtain the operation information during the operation of the unit; the operation information includes at least one of operation status information, system fault information, and disaster information;
[0017] Determine whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information, and obtain the triggering situation of the initial conditions of the emergency action level;
[0018] Determine the corresponding emergency action level for each according to the triggering situation of the initial conditions of each emergency action level;
[0019] Select the highest emergency level among each of the emergency action levels and determine it as the emergency status level.
[0020] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0021] Obtain the operation information during the operation of the unit; the operation information includes at least one of operation status information, system fault information, and disaster information;
[0022] Determine whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information, and obtain the triggering situation of the initial conditions of the emergency action level;
[0023] Determine the corresponding emergency action level for each according to the triggering situation of the initial conditions of each emergency action level;
[0024] Select the highest emergency level among each of the emergency action levels and determine it as the emergency status level.
[0025] The above emergency state classification method, device, computer equipment and storage medium obtain operation information such as operation status information, system fault information and disaster information during the operation of the unit, determine whether to trigger the initial conditions of the corresponding emergency action level based on the operation information, determine the corresponding triggered emergency action level in combination with the triggering situations of the initial conditions of each emergency action level, and finally select the highest emergency level among each emergency action level as the emergency state level. The above method considers various aspects of operation information such as operation status information, system fault information and disaster information, and considers more aspects of information when classifying the emergency state, which is more perfect. Description of the Drawings
[0026] Figure 1 It is a schematic flow chart of the emergency state classification method in an embodiment;
[0027] Figure 2 It is a schematic flow chart of determining whether to trigger the initial conditions of the corresponding emergency action level based on various types of operation information in an embodiment to obtain the triggering situation of the initial conditions of the emergency action level;
[0028] Figure 3 It is a schematic diagram of classifying the emergency state according to the technical specification in a specific embodiment;
[0029] Figure 4 It is a schematic flow chart of determining whether to trigger the initial conditions of the corresponding emergency action level based on various types of operation information in another embodiment to obtain the triggering situation of the initial conditions of the emergency action level;
[0030] Figure 5 It is a schematic diagram of classifying the emergency state according to the alarm card in a specific embodiment;
[0031] Figure 6 It is a schematic step flow chart of confirming the abnormal leakage of the primary loop in a specific embodiment;
[0032] Figure 7 It is a schematic diagram of classifying the emergency state according to the abnormal confirmation information in the abnormal operation program in a specific embodiment;
[0033] Figure 8(a) is the trigger logic corresponding to the potential loss of the fuel cladding barrier in a specific embodiment;
[0034] Figure 8(b) is the trigger logic corresponding to the loss of the fuel cladding barrier in a specific embodiment;
[0035] Figure 9(a) is the trigger logic corresponding to the potential loss of the pressure barrier at the primary loop boundary in a specific embodiment;
[0036] Figure 9(b) is the trigger logic corresponding to the loss of the pressure barrier at the primary loop boundary in a specific embodiment;
[0037] Figure 10(a) shows the trigger logic corresponding to the potential loss of the containment barrier in a specific embodiment;
[0038] Figure 10(b) shows the trigger logic corresponding to the loss of the containment barrier in a specific embodiment;
[0039] Figure 11 It is the trigger logic for the emergency action level of the barrier type in a specific embodiment;
[0040] Figure 12 It is the trigger logic for the emergency action level of the fault type in a specific embodiment;
[0041] Figure 13 It is the trigger logic for the emergency action level of the disaster type in a specific embodiment;
[0042] Figure 14 It is a schematic diagram for determining the emergency state level according to each emergency action level in the accident handling procedure in a specific embodiment;
[0043] Figure 15 It is a schematic diagram for obtaining accident handling procedure data from the DCS for emergency state classification in a specific embodiment;
[0044] Figure 16 It is a structural block diagram of an emergency state classification device in an embodiment;
[0045] Figure 17 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0046] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0047] In one embodiment, as Figure 1 shown, a method for emergency state classification is provided. In this embodiment, the method is exemplified by being applied to a terminal. It can be understood that the method can also be applied to a server, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. Emergency refers to a state that requires immediate actions beyond normal working procedures to avoid the occurrence of an accident or mitigate the consequences of an accident. Sometimes it is also called an emergency state.
[0048] In this embodiment, the method includes steps S110 to S140.
[0049] Step S110, obtain the operation information during the operation of the unit; the operation information includes at least one of operation status information, system failure information, and disaster information.
[0050] In this embodiment, the unit refers to the unit of a nuclear power plant. The operation status information refers to the information indicating the operation status during the operation of the unit; in a specific embodiment, the operation status information includes the level of the spent fuel pool, the gamma dose rate of the primary coolant, etc. The system failure information refers to the information related to the failures that occur in the system; in a specific embodiment, the system failure information includes the loss of off-site AC power; the single power supply of the emergency AC bus and the loss of which will lead to the loss of power of the whole plant; the loss of all AC power of the emergency AC bus, etc. The disaster information refers to the information such as natural disasters that occur; in a specific embodiment, the disaster information includes fire information, etc.; further, in an embodiment, the disaster information may also include the information about the impact of the occurring disaster on the unit, for example, whether a fire affects the safety function.
[0051] In an embodiment, the operation information of the unit can be obtained through various different methods; for example, it can be obtained automatically, manually, etc.
[0052] Among them, automatically obtaining information means directly obtaining relevant information from the system. In an embodiment, automatically obtaining the operation information of the unit includes directly provided by the digital accident handling procedure, such as: the degradation degree of the status function can be directly provided by the digital accident handling procedure, and there is no need to repeatedly judge whether the status function is degraded. For nuclear power units adopting the digital instrument and control system DCS, the monitoring screen of the supporting digital accident handling procedure can automatically monitor the degradation degree of the status function, the operation status of the system function, the status of the support function, etc. in real time after an accident.
[0053] Among them, the status function is defined in the status-oriented accident handling procedure and is used to characterize the functional parameters of the reactor safety state. For example, it includes subcriticality, the water inventory of the primary loop, residual heat removal, the water inventory of the steam generator, the integrity of the steam generator, the integrity of the containment, etc. The combination of these status function parameters can characterize the physical state of the reactor and provide a basis for determining the accident handling strategy.
[0054] Manually obtain information that requires manual intervention and on-site confirmation; in one embodiment, for information related to operator intervention, since such information involves the intervention operations of the operator, it is considered to set corresponding confirmation interfaces in the digital accident handling procedure to achieve the purpose of information provision through the confirmation interfaces. In a specific embodiment, when a high radioactivity alarm of the steam generator occurs, it is necessary to identify the radioactive steam generator, and the operator isolates the radioactive steam generator, and then the operator confirms the isolation intervention result of the radioactive steam generator and reports it. In another embodiment, the operator confirms the loss of AC power and reports relevant information.
[0055] In one embodiment, obtain the operation information during the operation of the unit, including: during the operation of the unit, obtain the operation information based on a preset interface.
[0056] Among them, the preset interface refers to the interface set for manually obtaining information. In one embodiment, the preset interface includes the intervention result confirmation interface corresponding to the operator's intervention, such as the preset interfaces corresponding to the failure of isolating the radioactive steam generator, the failure of isolating the containment, etc.; in another embodiment, the preset interface includes some diagnostic confirmations of the operator on the operation state of the unit, such as the preset interfaces corresponding to the primary loop leakage, the primary loop break, etc.; in another embodiment, the preset interface includes the interface corresponding to the operator's diagnosis of faults during the execution of function monitoring, such as the preset interface corresponding to the confirmation of power failure faults.
[0057] In this embodiment, preset interfaces are set at some positions, and the information manually confirmed by the operator can be obtained through the preset interfaces. Thus, when the emergency level needs to be divided, it is not necessary for emergency personnel to repeatedly confirm the relevant information, reducing the on-site confirmation steps, ensuring that the emergency action level can be judged timely, accurately and conveniently, and providing important support for the classification of the emergency state.
[0058] Step S120, determine whether to trigger the initial conditions of the corresponding emergency action level based on various operation information, and obtain the triggering situation of the initial conditions of the emergency action level.
[0059] Among them, the initial conditions of the emergency action level refer to the conditions for judging whether to trigger the emergency action level. The emergency action level is a pre-determined and observable parameter or criterion used to establish, identify and determine the emergency level and start implementing the corresponding emergency measures. In one embodiment, the initial conditions of the emergency action level corresponding to various operation information can all be set according to the actual situation.
[0060] For the obtained operation information, analysis can be carried out to determine whether the initial conditions of the corresponding emergency action level are triggered. The triggering situation of the initial conditions of the emergency action level indicates whether the initial conditions of the emergency action level are triggered. For example, for the operation status information, it is judged whether the corresponding initial conditions of the emergency action level are triggered; for the system fault information, it is judged whether the corresponding initial conditions of the emergency action level are triggered; for the disaster information, it is judged whether the corresponding initial conditions of the emergency action level are triggered.
[0061] Among them, based on various operation information to determine whether the corresponding initial conditions of the emergency action level are triggered, the specific implementation of obtaining the triggering situation of the initial conditions of the emergency action level will be described in detail in the subsequent embodiments and will not be elaborated here.
[0062] Step S130, determine the corresponding emergency action level according to the triggering situation of each initial condition of the emergency action level.
[0063] The emergency action level represents the emergency action level that needs to be executed for the currently triggered emergency state. For example, in a specific embodiment, the emergency action levels include: emergency standby, plant emergency, site emergency, off-site emergency, etc. Among them, the specific emergency measures for each emergency action level can be set according to the actual situation.
[0064] After determining whether various operation information triggers the corresponding initial conditions of the emergency action level, the emergency action level that needs to be started can be determined; for each triggering situation of the initial conditions of the emergency action level corresponding to various operation information, a corresponding emergency action level can be determined.
[0065] Step S140, select the highest emergency level among each emergency action level and determine it as the emergency state level.
[0066] After determining the corresponding emergency action level according to various operation information, since various operation information are all operation information at the same time, it can be known that after determining the emergency action levels from different operation information, select one of the highest-level emergency action levels as the emergency state level, which can ensure that the plant can obtain the fastest and most effective emergency protection measures.
[0067] For the above emergency state classification method, during the operation of the unit, operation information such as operation status information, system fault information, and disaster information is obtained, and based on the operation information, it is determined whether the corresponding initial conditions of the emergency action level are triggered. Combining the triggering situations of the initial conditions of each emergency action level, the corresponding triggered emergency action level is determined. Finally, the highest emergency level among each emergency action level is selected as the emergency state level. The above method considers various aspects of operation information such as operation status information, system fault information, and disaster information, and considers more aspects of information when classifying the emergency state, which is more perfect.
[0068] In one embodiment, as Figure 2 shown, based on various operation information, it is determined whether to trigger the initial conditions of the corresponding emergency action level, and the triggering situation of the initial conditions of the emergency action level is obtained, including steps S210 to S230.
[0069] Step S210: Read the parameter limit conditions in the technical specification.
[0070] Among them, the technical specification, also known as the operation technical specification, is used to monitor whether the operation information of the unit exceeds the safety limit and the operation status of the safety system during normal operation; the technical specification defines a series of operation limit conditions, stipulates a series of operation limits as the boundary of normal operation, which are recorded as the parameter limit conditions of each operation information in this embodiment. During the operation of the unit, the corresponding parameters need to be within the limit range of the parameter limit conditions in the technical specification.
[0071] In one embodiment, the technical specification can be stored in the terminal or the server. When performing emergency status classification, the technical specification is obtained from the terminal or the server, and each parameter limit condition is read from it.
[0072] Step S220: Judge the first operation information of the operation information based on each parameter limit condition.
[0073] Among them, the first operation information is the operation information corresponding to the parameter limit condition. In one embodiment, the first operation information can be any one of operation status information, system fault information, and disaster information. It should be noted that the "first", "second", etc. involved in this application are only used for distinguishing names and do not represent actual meanings.
[0074] After obtaining the parameter limit conditions in the technical specification, the operation information (i.e., the first operation information) associated with the parameter limit conditions in the obtained operation information can be analyzed and judged to determine whether the first operation information exceeds the parameter limit conditions, and then it can be determined whether to trigger the initial conditions of the corresponding emergency action level.
[0075] Step S230: If the first operation information does not meet the parameter limit conditions, determine to trigger the initial conditions of the emergency action level corresponding to the technical specification.
[0076] In one embodiment, the initial conditions of the emergency action level are set based on the parameter limit conditions in the technical specifications. For example, in a specific embodiment, taking the first operating information, the level of the spent fuel pool, as an example, the parameter limit conditions corresponding to the level of the spent fuel pool are set in the technical specifications, such as PTR3 (the level of the spent fuel pool is lower than 19.3 m). In this embodiment, the initial conditions of the emergency action level are set such that when the level of the spent fuel pool in the first operating information does not meet the corresponding parameter limit conditions, it is determined that the initial conditions of the emergency action level are triggered. In a specific embodiment, as shown in Table 1, the correlation between the parameter limit conditions corresponding to the level of the spent fuel pool and the initial conditions of the emergency action level is presented.
[0077]
[0078] Table 1
[0079] Furthermore, in this embodiment, it is determined whether to trigger the initial conditions of the initial emergency action level based on the parameter limit conditions. Specifically, when the parameter limit conditions are exceeded, it is determined that the corresponding initial conditions of the emergency action level are triggered. Among them, the technical specifications are procedures applicable during normal operation, generally only involving initial conditions of system failures and disasters, and it is considered to directly use whether the operating limit conditions are violated as the initial conditions of the emergency action level. Taking the level of the spent fuel pool as an example, the level of the spent fuel pool being lower than the limit value in the technical specifications is used as the initial condition for starting emergency standby, rather than formulating the initial conditions based on instrument parameters and thresholds.
[0080] In this embodiment, the corresponding initial conditions of the emergency action level are set through the parameter limit conditions in the technical specifications, and for the first operating information in the obtained operating information for which parameter limit conditions are set in the technical specifications, it is judged whether the parameter limit conditions are met, and then it is determined whether to trigger the corresponding initial conditions of the emergency action level. By using the limit conditions in the technical specifications as one of the judgment conditions for the emergency state, it can assist in effectively and quickly determining whether to trigger the initial conditions of the emergency action level.
[0081] Furthermore, in a specific embodiment, the corresponding emergency action levels are determined according to the triggering situations of the initial conditions of each emergency action level, including: if it is judged that the first operating information exceeds the normal operating boundary specified by the parameter limit conditions in the technical specifications, the initial conditions of the emergency action level corresponding to the technical specifications are triggered; if none of the other initial conditions of the emergency action level are triggered, it is determined that the emergency action level of emergency standby is triggered. Taking the level of the spent fuel pool as an example, after confirming based on the technical specifications that the level of the spent fuel pool is lower than the limit value in the technical specifications, the activated emergency action level is emergency standby. In a specific embodiment, as Figure 3 shown, it is a schematic diagram for classifying the emergency state according to the technical specifications.
[0082] In another embodiment, as Figure 4 shown, based on various operation information, it is determined whether to trigger the initial conditions of the corresponding emergency action level, and the triggering situation of the initial conditions of the emergency action level is obtained, including step S410 and step S420.
[0083] Step S410, read the parameter alarm reason in the alarm card.
[0084] Among them, the alarm card is used to trigger an alarm when the system operation is abnormal due to equipment or component failure and the monitored parameters do not meet the corresponding alarm thresholds, reminding relevant personnel to repair the failure in time. The possible reasons for alarm triggering and the intervention actions required to eliminate the failure are listed in the alarm card.
[0085] In one embodiment, the alarm card can be stored in the terminal or the server. When performing emergency status classification, the alarm card is obtained from the terminal or the server and the key information in it is read for analysis and judgment. Further, in one embodiment, reading the parameter alarm reason in the alarm card means that after the parameter alarm reason has been determined from the alarm card, the parameter alarm reason therein will be read.
[0086] Step S420, determine to trigger the initial conditions of the corresponding emergency action level based on the parameter alarm reason.
[0087] After obtaining the parameter alarm reason in the alarm card, it can be determined whether to trigger the initial conditions of the corresponding emergency action level according to the parameter alarm reason.
[0088] For example, in a specific embodiment, taking the 2-level alarm KRT046KA of the primary coolant γ dose rate in the alarm card as an example, if the alarm reason has been confirmed, read the alarm reason: the activity of the primary coolant increases (fuel cladding failure); further, set the initial conditions of the emergency action level to fuel cladding failure, then it is determined that the initial conditions of the emergency action level are triggered. As shown in Table 2, the correlation between the parameter alarm reason of the 2-level alarm KRT046KA of the primary coolant γ dose rate and the initial conditions of the emergency action level is shown.
[0089]
[0090]
[0091] Table 2
[0092] Furthermore, similar to the technical specification, the alarm card generally only involves the initial conditions of system failures and disasters. It is considered to directly use the physical meaning represented by the alarm as the initial condition of the emergency action level. Taking the high-2 alarm of the primary coolant γ dose rate as an example, the rupture of the fuel cladding is used as the initial condition to start emergency standby, rather than formulating the initial condition based on instrument parameters and thresholds.
[0093] In this embodiment, the initial conditions of the emergency action level are set corresponding to the parameter alarm reasons of the alarm card, and the parameter alarm reasons in the alarm card are read, and then it is determined whether to trigger the corresponding initial conditions of the emergency action level. The parameter alarm reasons in the alarm card are used as one of the judgment conditions for the emergency state, which can assist in effectively and quickly determining whether to trigger the initial conditions of the emergency action level.
[0094] Furthermore, if it is determined that the parameter alarm reason in the alarm card is confirmed, the emergency action level corresponding to the alarm card is determined according to the physical meaning corresponding to the alarm, which involves the emergency action levels of emergency standby, plant emergency, site emergency, and off-site emergency. In a specific embodiment, taking the high-2 alarm of the primary coolant γ dose rate as an example, the corresponding emergency action level is determined according to the triggering situation of the initial conditions of each emergency action level, including: after it is confirmed in the alarm card that the fuel cladding is damaged, if none of the other initial conditions of the emergency action level are triggered, the triggered emergency action level is determined to be emergency standby. In other embodiments, if other parameter alarm reasons are involved, other emergency action levels can be correspondingly set. In a specific embodiment, as Figure 5 shown, it is a schematic diagram of classifying the emergency state based on the alarm card.
[0095] In one embodiment, based on various operation information, it is determined whether to trigger the corresponding initial conditions of the emergency action level, and the triggering situation of the initial conditions of the emergency action level is obtained, including: when the unit enters the abnormal operation program, if it is detected that the operation information contains the abnormal confirmation information in the abnormal operation program, it is determined to trigger the corresponding initial conditions of the emergency action level of the abnormal operation program.
[0096] Among them, the abnormal operation program is used to handle system or unit-level faults that are relatively minor, more complex in response to the unit compared to the alarm card, and do not require entering the accident handling program. The abnormal operation program will diagnose and confirm the fault and define the intervention actions required to eliminate the fault.
[0097] The abnormal confirmation information is the abnormal information manually confirmed by humans. In a specific embodiment, taking the primary loop leakage anomaly as an example, in the primary loop leakage abnormal operation program, if the relevant personnel confirm through the leakage balance test that the primary loop leakage rate exceeds the limit value (such as 2300 L / h), the primary loop leakage anomaly is confirmed, and an interface is set to confirm the primary loop leakage anomaly. As Figure 6The figure shows a schematic diagram of the step flow for confirming abnormal primary loop leakage in a specific embodiment.
[0098] In this embodiment, for the abnormal information obtained through manual confirmation in the abnormal operation program, corresponding initial conditions for the emergency action level are established, and based on the abnormal confirmation information, it is confirmed to trigger the corresponding initial conditions for the emergency action level as one of the judgment conditions for the emergency state, which can assist in effectively and quickly determining whether to trigger the initial conditions for the emergency action level.
[0099] Furthermore, the emergency action level corresponding to the abnormal operation program is determined according to the severity of the faults addressed by the abnormal operation program, and it can involve emergency standby and emergency action levels at the plant emergency level. In a specific embodiment, taking the abnormal primary loop leakage as an example, according to the triggering situation of each initial condition for the emergency action level, the corresponding emergency action level is determined, including: if the operation information contains the confirmation information of abnormal primary loop leakage, and if none of the other initial conditions for the emergency action level are triggered, the grading result of the emergency state is emergency standby. In other embodiments, if other parameter alarm reasons are involved, other emergency action levels can be correspondingly set to be triggered. In a specific embodiment, as Figure 7 The figure shows a schematic diagram of grading the emergency state based on the abnormal confirmation information in the abnormal operation program.
[0100] In one embodiment, based on various types of operation information, it is determined whether to trigger the corresponding initial conditions for the emergency action level, and the triggering situation of the initial conditions for the emergency action level is obtained, including: based on the operation status information, it is determined whether to trigger the initial conditions for the emergency action level of the barrier function.
[0101] Among them, the initial conditions for the emergency action level of the barrier function are the initial conditions for the emergency action level corresponding to the function of the barrier. In one embodiment, the barrier represents the fission product barrier; in a specific embodiment, the fission product barrier represents the closed outer shell that contains radioactive products between the nuclear fuel and the public, and from the inside to the outside, it includes: the fuel cladding, the primary loop pressure boundary, and the containment.
[0102] Among them, the fuel cladding refers to the metal outer shell that encapsulates the fuel core.
[0103] The pressure boundary of the reactor coolant system (pressure boundary) is the boundary that contains the reactor coolant at the operating temperature and pressure and is also used to contain radioactive substances. Due to the huge heat energy generated by nuclear fuel fission in the reactor core, the water pumped into the core by the main pump is heated into high-temperature and high-pressure water at 327 degrees and 155 atmospheres. The high-temperature and high-pressure water flows through the heat transfer U-tubes in the steam generator, and the heat energy is transferred to the secondary loop cooling water outside the U-tubes through the tube wall. After releasing the heat, it is pumped back into the core by the main pump to be reheated and then enters the steam generator again. The water circulates continuously in the closed loop like this, which is called the primary loop.
[0104] The containment is the nuclear reactor containment, also known as the reactor containment, containment building or enclosure, safety building, or safety shelter. It is the outermost building of a pressurized water reactor, referring to the outer shell building that houses most of the systems and equipment of the nuclear steam supply system. It is used to accommodate the reactor pressure vessel and some safety systems (including the primary circuit main system and equipment, and the shutdown cooling system), and completely isolates them from the external environment, expecting to achieve the function of a safety protection barrier.
[0105] In one embodiment, the initial conditions of the emergency action level for the barrier function include at least one of the following: potential loss of the fuel cladding barrier, loss of the fuel cladding barrier, potential loss of the primary circuit pressure boundary barrier, loss of the primary circuit pressure boundary barrier, potential loss of the containment barrier, and loss of the containment barrier.
[0106] In this embodiment, it is determined whether the function of the barrier category triggers the corresponding initial conditions of the emergency action level according to the operating status information; that is, it is determined whether there are functional problems with the fuel cladding, the primary circuit pressure boundary, or the containment according to the operating status information, and the barrier integrity is judged based on the degree of state function degradation supplemented by some key parameter information; specifically, it includes two situations: potential loss of function and loss of function. Among them, loss of function means that the function is damaged and cannot play its corresponding role; while potential loss of function means that the function is affected and there is a possibility of loss or is about to be lost.
[0107] Furthermore, in one embodiment, the potential loss of the fuel cladding barrier includes: degradation of the primary coolant inventory, degradation of the residual heat removal state function, or degradation of the steam generator coolant inventory.
[0108] In one embodiment, the potential loss of the fuel cladding barrier includes a severe degradation of the primary coolant inventory; a severe degradation of the state function of the primary coolant inventory means that the pressure vessel water level has started to be lower than the top of the core, and the fuel assemblies start to be exposed, which indicates the potential loss of the fuel cladding barrier.
[0109] In one embodiment, the potential loss of the fuel cladding barrier includes a severe degradation of the residual heat removal state function; a severe degradation of the state function of the residual heat removal means that the coolant at the core outlet starts to overheat (superheated steam), and this phenomenon only occurs when the core fuel assemblies start to be exposed, which also indicates the potential loss of the fuel cladding barrier.
[0110] In one embodiment, the potential loss of the fuel cladding barrier includes a severe degradation of the steam generator water inventory; a severe degradation of the status function of the steam generator water inventory, indicating that the steam generator loses its heat transfer capacity due to a severe deterioration of the secondary side water level, and the core heat cannot be removed in time, which will eventually lead to overheating and damage of the fuel assembly, indicating the potential loss of the fuel cladding barrier. As shown in Figure 8(a), it is the trigger logic corresponding to the potential loss of the fuel cladding barrier in a specific embodiment.
[0111] In other embodiments, the potential loss of the fuel cladding barrier may also include specific conditions set for other parameters.
[0112] In one embodiment, the loss of the fuel cladding barrier includes: the core outlet temperature is greater than the temperature threshold, or the status function of the containment integrity degrades.
[0113] The core of a nuclear reactor is also called the reactor active zone, which is composed of fuel assemblies placed in a core grid with a certain grid. The fuel assemblies are assembled by fuel elements made into a certain shape (plate, rod, tube) through various components according to a certain grid layout to meet the requirements of physics and thermal hydraulics. Among them, the temperature threshold can be set according to the actual situation. In a specific embodiment, the temperature threshold is set to 650 °C; when the core outlet temperature reaches 650 °C, it means that most of the core fuel assemblies are exposed, and the fuel assemblies begin to melt and break, which characterizes the loss of the fuel cladding barrier.
[0114] In one embodiment, the loss of the fuel cladding barrier includes a severe degradation of the status function of the containment integrity; for the status function of the containment integrity, if its severe degradation is caused by a high dose rate inside the containment, it means that a certain proportion of the fuel cladding has been damaged, and the radioactive substances (including inert gases, etc.) in the cladding gap are released into the containment along with the primary coolant, which also characterizes the loss of the fuel cladding barrier. As shown in Figure 8(b), it is the trigger logic corresponding to the loss of the fuel cladding barrier in a specific embodiment.
[0115] In one embodiment, the potential loss of the primary circuit pressure boundary barrier includes at least one of the following: the status function degradation of residual heat removal, the status function degradation of residual heat discharge, the degradation of the steam generator water inventory, the existence of a primary circuit leak and an automatic reactor trip signal, and the degradation of the steam generator integrity and the existence of an automatic reactor trip signal.
[0116] The degradation of the status function of residual heat removal caused by primary circuit subcooling indicates that there is a severe pressurized thermal shock in the reactor pressure vessel, and there is a risk of brittle fracture of the pressure vessel, indicating the potential loss of the primary circuit pressure boundary barrier.
[0117] For the working condition where the residual heat removal system is connected, the safety valve setting value (such as 4.5MPa) on the residual heat removal system pipeline is taken as the criterion. If the pressure exceeds the safety valve setting pressure, it means that there is a cold overpressure risk in the primary circuit. Among them, the residual heat removal system is a system used to remove the residual heat of the core during cold shutdown, also known as the shutdown cooling system, and is one of the primary circuit auxiliary systems.
[0118] Steam generator is a device for producing steam. In one embodiment, the potential loss of the primary circuit pressure boundary barrier includes serious degradation of the water content of the steam generator; the serious degradation of the water content of the state function steam generator indicates that the steam generator has lost its heat conduction capacity due to serious deterioration of the secondary side water level, the core heat cannot be discharged in time, and the continuous temperature rise of the primary circuit coolant will eventually cause the primary circuit pressure to exceed its design pressure, indicating the potential loss of the primary circuit pressure boundary.
[0119] If there is a leak in the primary circuit and the automatic shutdown signal exists, it means that the leakage in the primary circuit has triggered the action of the reactor protection system. This situation can be considered as a potential loss of the primary circuit pressure boundary barrier. Similarly, if a steam generator is radioactive due to a leak in the U-tube, resulting in a serious degradation of the steam generator integrity status function, and the automatic shutdown signal exists, this situation can also be considered as a potential loss of the primary circuit pressure boundary barrier. As shown in Figure 9 (a), the trigger logic corresponding to the potential loss of the primary circuit boundary pressure barrier in a specific embodiment is shown.
[0120] In one embodiment, the loss of the primary circuit pressure boundary barrier includes: the containment integrity status function is degraded, or there is a breach in the primary circuit and a safety injection signal exists.
[0121] In one embodiment, the loss of the primary pressure boundary barrier includes a slight degradation of the containment integrity status function; for the status function containment integrity, if the high dose rate in the containment causes it to be slightly degraded, it indicates that there is a release of primary coolant into the containment, which indicates the loss of the primary pressure boundary barrier.
[0122] If it is determined that there is a breach in the primary circuit and the safety injection signal exists, it means that the leakage in the primary circuit has triggered the action of the dedicated safety facility. This situation can be considered as the loss of the primary circuit pressure boundary barrier. Similarly, if a steam generator is radioactive due to damage to the U-tube, resulting in a serious degradation of the steam generator integrity status function, and the safety injection signal exists, this situation can also be considered as the loss of the primary circuit pressure boundary barrier. As shown in Figure 9(b), the trigger logic corresponding to the loss of the primary circuit boundary pressure barrier in a specific embodiment is shown.
[0123] In one embodiment, the potential loss of the containment barrier includes: the functional degradation of the containment integrity status and the failure of the containment spray system, the containment pressure exceeding the design limit pressure, or the achievement of severe accident entry conditions.
[0124] Among them, the severe accident entry conditions can be set according to the actual situation or in accordance with relevant regulations. For the potential loss of the containment barrier: If the functional degradation of the containment integrity status is caused by too high pressure inside the containment, it indicates that a large amount of mass-energy is released inside the containment, and it is necessary to start the containment spray system as soon as possible to reduce the pressure of the containment. If the start of the containment spray system fails, it indicates the potential loss of the containment barrier function.
[0125] If the containment pressure directly exceeds its design limit pressure (such as 0.52 MPa), this will directly challenge the integrity of the containment, indicating the potential loss of the containment barrier function.
[0126] The satisfaction of the severe accident entry conditions means that most of the core fuel assemblies are exposed, and almost all of the primary coolant is released into the containment, indicating the potential loss of the containment barrier function. Or there is hydrogen in the containment that has accumulated beyond the minimum explosion concentration, and there is a risk of hydrogen deflagration in the containment, indicating the potential loss of the containment barrier function. As shown in Figure 10(a), it is the trigger logic corresponding to the potential loss of the containment barrier in a specific embodiment.
[0127] In one embodiment, the loss of the containment barrier includes: the failure of the steam generator isolation and the functional degradation of the steam generator integrity status, or the failure of the containment isolation and the triggering of the containment isolation signal.
[0128] If a steam generator is radioactive, resulting in the functional degradation of the steam generator integrity status, and at the same time the isolation of the radioactive steam generator fails, it indicates that there is a path for the release of radioactive substances in the primary circuit to the outside of the containment through the damaged steam generator. This situation can be regarded as a typical example of the loss of the containment barrier.
[0129] If the containment isolation signal is triggered, it indicates that a break accident has occurred inside the containment, and there is a large amount of mass-energy released inside the containment. It is necessary to close the containment isolation valve as soon as possible to isolate the containment. If the operator judges that the containment isolation fails (such as: not all of the containment isolation valves are closed), it means that the containment is bypassed and the containment barrier function is lost. As shown in Figure 10(b), it is the trigger logic corresponding to the potential loss of the containment barrier in a specific embodiment.
[0130] In this embodiment, corresponding detailed initial conditions are respectively set for various barriers such as fuel cladding, primary circuit pressure boundary, and containment. When it is detected that the above-mentioned operating status information reaches the corresponding conditions, the initial conditions for triggering the corresponding emergency action levels can be determined, providing important support for the classification of emergency states.
[0131] Further, in one embodiment, for the initial conditions of the emergency action levels of the barriers, when it is judged according to the operating status information that the corresponding requirements are met, it is judged that the initial conditions of the emergency action levels of the barriers are triggered; for example, the degradation of the primary circuit water inventory indicates the potential loss of the fuel cladding, thereby determining that the initial conditions of the emergency action levels of the barriers are triggered; similarly, if it is judged that the containment isolation fails and the containment isolation signal is triggered, it means that the containment barrier is lost, thereby the initial conditions of the emergency action levels of the barriers can be determined, and so on.
[0132] Furthermore, after determining the triggering situation of the initial conditions of the emergency action levels of the barriers, the emergency action levels of the barriers can be determined.
[0133] In a specific embodiment, the corresponding emergency action levels are determined according to the triggering situations of the initial conditions of each emergency action level, including: the emergency action level that can be triggered by the loss or potential loss of the fuel cladding or the primary circuit pressure boundary barrier is "plant emergency", and the emergency action level that can be triggered when two barriers are simultaneously threatened is "site emergency". Confirming the loss of the two barriers of the fuel cladding and the primary circuit pressure boundary, and at the same time the containment barrier is threatened (lost or potentially lost) can trigger "off-site emergency". The triggering logic for the emergency action levels of the barriers is as Figure 11 shown.
[0134] In this embodiment, a specific method for determining the emergency action level according to the triggering situation of the initial conditions of the emergency action levels of the barriers is illustrated. According to the set triggering logic of the emergency action levels, a rapid response can be made during the classification of emergency states, and a relatively perfect triggering logic is established, taking into account more real situations, conforming to the actual situation, and having high practicability.
[0135] In one embodiment, based on various operating information, it is determined whether to trigger the corresponding initial conditions of the emergency action levels, and the triggering situations of the initial conditions of the emergency action levels are obtained, including: determining whether to trigger the initial conditions of the emergency action levels of the fault type based on the system fault information.
[0136] System fault information is information used to indicate fault conditions. During the execution of the accident handling procedure, functional monitoring will monitor the operating status of important systems and equipment. Taking AC power supply as an example, functional monitoring will monitor the operating status of the power supply outside the factory and the emergency AC power supply inside the factory. After the power failure alarm is detected, the operator will use other information means (such as switchboard voltage, load operating status, etc.) to confirm the power failure during the functional monitoring period.
[0137] For the initial conditions of the fault-type emergency action level, it is necessary to exclude the possible disturbance-induced false triggering of the fault signal, and the emergency response needs to be initiated only after the fault is confirmed. In one embodiment, a preset confirmation interface is set in the function monitoring part of the accident handling program. After the operator confirms that the fault has indeed occurred, the corresponding fault-type initial conditions are triggered through the preset confirmation interface, and the emergency personnel no longer need to repeat the judgment.
[0138] Furthermore, in one embodiment, the initial condition of the emergency action level of the fault-type function includes at least one of the following: loss of off-site AC power supply, single emergency AC bus power supply, and loss of all AC power supply of the emergency AC bus.
[0139] In this embodiment, the AC power supply is used as an example for explanation. When the operator executes the functional monitoring part of the digital accident handling procedure, the operator sets the corresponding preset confirmation interface according to the monitored AC power loss situation, including: loss of AC power outside the factory; the emergency AC busbar has a single power supply, and loss will cause power loss to the entire factory; the emergency AC busbar loses all AC power, etc. These preset confirmation interfaces directly correspond to the initial conditions for losing AC power supply: loss of AC power outside the factory; the emergency AC busbar has a single power supply, and loss will cause power loss to the entire factory; the emergency AC busbar loses all AC power. It should be noted that in other embodiments, the system fault information may also include other parameter information, and accordingly, the initial conditions of the fault-type emergency action level may also be set to other conditions.
[0140] In this embodiment, an example is given to illustrate the specific setting of the initial conditions of the fault-type emergency action level. When the emergency state is subsequently classified, it can be quickly determined whether to trigger the initial conditions of the fault-type emergency action level based on the obtained system fault information.
[0141] Furthermore, in one embodiment, for the initial conditions of the emergency action level of the fault type, when it is determined that the corresponding requirements are met based on the system fault information, it is determined that the initial conditions of the emergency action level of the fault type are triggered; for example, when the loss of the AC power supply outside the factory is confirmed, it is determined that the initial conditions of the emergency action level of the fault type are triggered; similarly, if it is confirmed that the emergency AC bus power supply is single and its loss will cause power outages in the entire factory, it can be determined that the emergency action level of the fault type is triggered, and so on.
[0142] Furthermore, after determining the triggering situation of the initial conditions of the emergency action level for the failure category, the emergency action level for the barrier category can be determined.
[0143] The emergency action level for the failure category is determined based on the degree of decline in the safety level of the nuclear power plant caused by the failure. The emergency action level can be directly triggered by the operator's confirmation action, or can be triggered when the operator's confirmation action meets other conditions at the same time. Taking the loss of AC power supply as an example, as Figure 12 shown is the triggering logic of the emergency action level for the failure category.
[0144] In the example shown in the figure, according to the triggering situation of the initial conditions of each emergency action level, the corresponding emergency action level is determined, including: (a) If it is confirmed through the preset interface that off-site AC power supply is lost, the emergency action level triggered directly by the initial condition of loss of off-site AC power supply and starting is emergency standby. (b) If it is confirmed through the preset interface that the emergency AC bus power supply is single and the loss will cause the whole plant to lose power, the emergency action level triggered directly by the corresponding initial condition and starting is plant emergency. (c) If it is confirmed through the preset interface that the emergency AC bus loses all AC power, the emergency action level triggered directly by the corresponding initial condition and starting is site emergency. (d) If it is confirmed through the preset interface that the emergency AC bus loses all AC power, and the status function of the steam generator water inventory degrades or overheats, resulting in the degradation of the residual heat removal function, the emergency action level that needs to be started due to the initial condition of the emergency AC bus losing all AC power and the mitigation measures failing is off-site emergency.
[0145] In this embodiment, a specific method for determining the emergency action level according to the triggering situation of the initial conditions of the emergency action level for the failure category is illustrated. According to the set triggering logic of the emergency action level, during the emergency state classification, a quick response can be made, and a relatively complete triggering logic is established, taking into account more realistic situations, conforming to the actual situation, and having high practicability.
[0146] In one embodiment, based on various operation information, it is determined whether to trigger the corresponding initial conditions of the emergency action level, and the triggering situation of the initial conditions of the emergency action level is obtained, including: determining whether to trigger the initial conditions of the emergency action level for the disaster category based on the disaster information.
[0147] During the execution of the accident handling procedure, the function monitoring will monitor the disaster. Taking a fire as an example, the function monitoring will monitor the fire in the nuclear island plant. After detecting the alarm trigger of a certain fire compartment, during the function monitoring, the operator will use other information means (such as fire first-level intervention, etc.) to confirm the fire situation.
[0148] For the initial conditions of disaster types, it is necessary to confirm that the disaster has actually occurred before starting the emergency response. Therefore, a confirmation interface is set in the function monitoring part of the accident handling procedure. After the operator confirms that the disaster has indeed occurred, the corresponding initial conditions of the fault type are triggered through the confirmation interface, and there is no need for emergency personnel to repeatedly judge.
[0149] Furthermore, in one embodiment, the initial conditions for the emergency action level of the disaster type function include: a disaster occurs and affects the safety function, or a fire occurs and does not affect the safety function.
[0150] In this embodiment, the fire is taken as an example for illustration. As Figure 13 shown, when the operator executes the function monitoring part of the digital accident handling procedure, if a fire in a fire compartment is confirmed, corresponding confirmation interfaces are set according to whether the fire affects the safety equipment. These confirmation interfaces can directly correspond to the corresponding initial conditions. It can be understood that in other embodiments, the disaster information can also include other disaster information, and correspondingly, the initial conditions for the emergency action level of the disaster type can also be set as the corresponding conditions.
[0151] In a specific embodiment, the safety functions include system functions such as the emergency core cooling system ECCS (safety injection system) required to ensure the safe operation, withdrawal, and / or maintenance of the power plant in the cold shutdown condition. These system functions are generally safety-class functions.
[0152] In this embodiment, the specific setting of the initial conditions for the emergency action level of the disaster type is illustrated. Subsequently, when grading the emergency state, it is possible to quickly determine whether to trigger the initial conditions for the emergency action level of the disaster type based on the obtained disaster information.
[0153] Furthermore, the emergency action level of the disaster type is determined according to the degree of decline in the safety level of the nuclear power plant caused by the fault. The emergency action level can be directly triggered by the operator's confirmation action, or triggered when the operator's confirmation action meets other conditions at the same time. Taking the fire as an example for illustration, the trigger logic corresponding to the emergency action level of the fire is shown in the figure. In this embodiment, if it is determined that a disaster has occurred but has not caused the loss of safety functions, it means that the initial conditions for the emergency action level of the disaster type are triggered, and the emergency action level of the disaster type is determined to be emergency standby. If it is confirmed that a disaster has occurred and has caused a series of safety function losses, it means that the initial conditions for the emergency action level of the disaster type are triggered, and the emergency action level of the disaster type is determined to be plant emergency.
[0154] In this embodiment, the specific method of determining the emergency action level according to the trigger situation of the initial conditions for the emergency action level of the disaster type is illustrated. According to the set trigger logic of the emergency action level, a quick response can be made when grading the emergency state, and a relatively perfect trigger logic is established, taking into account more real situations, conforming to the actual situation, and having high practicality.
[0155] After determining the triggered emergency action level based on various operation information, the highest-level emergency action level can be selected from each emergency action level and determined as the emergency state level, and then relevant personnel are instructed to respond based on the emergency state level. Among them, the emergencies of the emergency action levels are arranged from high to low, including off-site emergency, on-site emergency, plant emergency, and emergency standby. The classification result of the emergency state depends on the comprehensive judgment of each identified emergency action level. Considering conservatively, the classification result of the emergency state should be the highest of the emergency action levels corresponding to each identified category. As Figure 14 shown is a schematic diagram of determining the emergency state level according to each emergency action level in the accident handling procedure.
[0156] In a specific embodiment, as shown in the figure, for a nuclear power unit adopting a digital instrument control system DCS (Distributed Control System), the supporting digital accident handling procedure monitoring screen can automatically monitor the degradation degree of the state function, the operation state of the system function, the support function state, etc. in real time after an accident. The logic criteria involved in this technical solution can be integrated into the existing DCS of the nuclear power plant, or obtain relevant data from the DCS as a third-party system, so as to achieve the purpose of automatically classifying the emergency state in real time during the execution of the accident handling procedure. Figure 15 shown is a schematic diagram of classifying the emergency state by obtaining accident handling procedure data from the DCS in a specific embodiment. In Figure 15 it, the data during the execution of the accident handling procedure is collected and processed by the information acquisition module of the system after passing through the firewall, and then compared with the initial condition threshold criteria of each identified category based on the obtained data, and the trigger logic of the emergency action level is automatically judged, and the corresponding emergency state classification is determined. The system also provides a man-machine interface to provide necessary information display, personnel intervention interface, etc.
[0157] In a specific embodiment, the overall process of the above emergency state classification method is as shown in the figure. During the operation of the unit, the obtained information involves the operation information corresponding to the parameters included in the technical specifications (the above first operation information), the operation information in the alarm card, the operation information in the abnormal operation procedure, and the operation information in the accident handling procedure. The means of obtaining information include manual acquisition or automatic acquisition.
[0158] Determine whether to trigger the initial conditions of the corresponding emergency action level according to various operation information, and obtain the initial condition trigger situation. Among them, the trigger logic for judging whether to trigger the initial conditions of the emergency action level based on the operation information obtained from the technical specifications, alarm card, abnormal operation procedure, or accident operation procedure has been described in detail in the above embodiments, and will not be elaborated here.
[0159] Determine the triggered emergency action level based on the initial condition triggering situation. For example, after determining the initial condition for triggering the emergency action level for the operation information containing parameters in the technical specification, determine the corresponding emergency action level according to the initial condition triggering situation corresponding to the technical specification; specifically, it can be triggering the initial condition of the emergency action level corresponding to the technical specification and determining the emergency action level as emergency standby. In other embodiments, the specific method for determining the initial condition triggering situation for other types of operation information and then determining the emergency action level has been described in detail in the above embodiments and will not be elaborated here.
[0160] After determining the emergency action level according to various types of operation information, select the emergency action level with the highest rank among them as the emergency status level according to the rank sorting order of off-site emergency > on-site area emergency > plant building emergency > emergency standby.
[0161] The above emergency status classification method classifies the emergency status based on the operation procedures, which involves setting the initial conditions of the emergency action level by using the information related to the technical specification, alarm card, abnormal operation procedure, and accident operation procedure, and judging whether the operation information obtained during the unit operation triggers the corresponding initial conditions of the emergency action level. Then, determine the respective corresponding emergency form levels according to the triggering situation of the initial conditions, and finally obtain the emergency status level by integrating each emergency action level. The above method realizes the intelligence of emergency status classification. During the unit operation, abnormal working conditions, and accident conditions, the emergency action level can be automatically judged. It can effectively avoid human errors under accident conditions. Ensure that the emergency action level can be judged timely, accurately, and conveniently, providing important support for emergency status classification. In addition, the above method can establish network communication interfaces with local emergency command centers and national nuclear emergency command centers through the DCS network, and send relevant data information to local emergency command centers and national nuclear emergency command centers in real time to make the emergency responses at all levels coordinated.
[0162] It should be understood that although each step in the flowcharts involved in the above embodiments is shown in sequence according to the indication of the arrow, these steps do not necessarily need to be executed in the order indicated by the arrow. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps in other steps.
[0163] In one embodiment, as Figure 16As shown in the figure, an emergency state classification device is provided, including: an acquisition module 100, a condition judgment module 200, an emergency action level determination module 300, and a state classification module 400, where:
[0164] The acquisition module 100 is used to acquire operation information during the operation of the unit; the operation information includes at least one of operation status information, system fault information, and disaster information;
[0165] The condition judgment module 200 is used to determine whether to trigger the initial conditions of the corresponding emergency action levels based on various operation information, and obtain the triggering situation of the initial conditions of the emergency action levels;
[0166] The emergency action level determination module 300 is used to determine the corresponding emergency action levels according to the triggering situations of the initial conditions of each emergency action level;
[0167] The state classification module 400 is used to determine the emergency state level in combination with each emergency action level.
[0168] In the above emergency state classification device, during the operation of the unit, operation information such as operation status information, system fault information, and disaster information is acquired, and it is determined whether to trigger the initial conditions of the corresponding emergency action levels based on the operation information. The corresponding triggered emergency action levels are determined in combination with the triggering situations of the initial conditions of each emergency action level, and finally the highest emergency level among each emergency action level is selected as the emergency state level. The above method considers various aspects of operation information such as operation status information, system fault information, and disaster information, and more aspects of information are considered when classifying the emergency state, which is more perfect.
[0169] In one embodiment, the acquisition module 100 of the above device is further used to: acquire operation information based on a preset interface during the operation of the unit.
[0170] In one embodiment, the condition judgment module 200 of the above device includes: a limit condition reading sub-module, used to read each parameter limit condition in the technical specification; a judgment sub-module, used to judge the first operation information of the operation information based on each parameter limit condition; the first operation information is the operation information corresponding to the parameter limit condition; a condition trigger determination sub-module, used to determine to trigger the initial conditions of the emergency action level corresponding to the technical specification if the first operation information does not meet the parameter limit condition.
[0171] In one embodiment, the condition judgment module 200 of the above device includes: an alarm reason reading sub-module, used to read the parameter alarm reason in the alarm card; a condition trigger determination sub-module, used to determine to trigger the initial conditions of the corresponding emergency action level based on the parameter alarm reason.
[0172] In one embodiment, the condition judgment module 200 of the above device includes: a condition trigger determination sub-module, configured to, when the unit enters an abnormal operation program, if it detects that the operation information contains the abnormal confirmation information in the abnormal operation program, determine to trigger the initial conditions of the emergency action level corresponding to the abnormal operation program.
[0173] In one embodiment, the condition judgment module 200 of the above device is further configured to: determine whether to trigger the initial conditions of the emergency action level of the barrier function based on the operation status information; or determine whether to trigger the initial conditions of the emergency action level of the fault type based on the system fault information; or determine whether to trigger the initial conditions of the emergency action level of the disaster type based on the disaster information.
[0174] In one embodiment, the initial conditions of the emergency action level of the barrier function in the above device include at least one of the following: potential loss of the fuel cladding barrier, loss of the fuel cladding barrier, potential loss of the primary circuit pressure boundary barrier, loss of the primary circuit pressure boundary barrier, potential loss of the containment barrier, and loss of the containment barrier.
[0175] In one embodiment, the potential loss of the fuel cladding barrier in the above device includes: degradation of the primary coolant inventory, degradation of the residual heat removal status function, or degradation of the steam generator coolant inventory.
[0176] In one embodiment, the loss of the fuel cladding barrier in the above device includes: the core outlet temperature is greater than the temperature threshold, or the function of the containment integrity status degrades.
[0177] In one embodiment, the potential loss of the primary circuit pressure boundary barrier in the above device includes at least one of the following: degradation of the residual heat removal status function, degradation of the residual heat discharge status function, degradation of the steam generator coolant inventory, primary circuit leakage and the presence of an automatic reactor trip signal, and degradation of the steam generator integrity and the presence of an automatic reactor trip signal.
[0178] In one embodiment, the loss of the primary circuit pressure boundary barrier in the above device includes: degradation of the containment integrity status function, or there is a break in the primary circuit and the safety injection signal is present.
[0179] In one embodiment, the potential loss of the containment barrier in the above device includes: degradation of the containment integrity status function and failure of the containment spray system, the containment pressure exceeds the design limit pressure, or the severe accident entry condition is reached.
[0180] In one embodiment, the loss of the containment barrier in the above device includes: failure of the steam generator isolation and degradation of the steam generator integrity status function, or failure of the containment isolation and triggering of the containment isolation signal.
[0181] In one embodiment, the initial conditions for the emergency action level of the fault class functions in the above device include at least one of the following: loss of off-site AC power, single power supply to the emergency AC bus, and loss of all AC power to the emergency AC bus.
[0182] In one embodiment, the initial conditions for the emergency action level of the disaster class functions in the above device include: a fire occurs and affects the safety function, or a fire occurs and does not affect the safety function.
[0183] For specific embodiments of the emergency status classification device, reference may be made to the embodiments of the emergency status classification method described above, which will not be elaborated here. Each module in the above emergency status classification device can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or be stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above respective modules.
[0184] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 17 shown. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements an emergency status classification method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, a touchpad, or a mouse, etc.
[0185] Those skilled in the art can understand that Figure 17 the structure shown in
[0186] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements. In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:
[0187] Obtain the operation information during the operation of the unit; the operation information includes at least one of operation status information, system fault information, and disaster information; determine whether to trigger the initial conditions of the corresponding emergency action level based on various operation information, and obtain the triggering situation of the initial conditions of the emergency action level; determine the corresponding emergency action level for each triggering situation of the initial conditions of the emergency action level; select the highest emergency level among each emergency action level and determine it as the emergency status level.
[0188] In one embodiment, when the processor executes the computer program, the following steps are further implemented: during the operation of the unit, obtain the operation information based on a preset interface.
[0189] In one embodiment, when the processor executes the computer program, the following steps are further implemented: read the parameter limit conditions in the technical specification; judge the first operation information of the operation information based on each parameter limit condition; the first operation information is the operation information corresponding to the parameter limit condition; if the first operation information does not meet the parameter limit condition, determine to trigger the initial conditions of the emergency action level corresponding to the technical specification.
[0190] In one embodiment, when the processor executes the computer program, the following steps are further implemented: when the unit enters the abnormal operation program, if it is detected that the operation information contains the abnormal confirmation information in the abnormal operation program, determine to trigger the initial conditions of the emergency action level corresponding to the abnormal operation program.
[0191] In one embodiment, when the processor executes the computer program, the following steps are further implemented: read the parameter alarm reason in the alarm card; determine to trigger the corresponding initial conditions of the emergency action level based on the parameter alarm reason.
[0192] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine whether to trigger the initial conditions of the emergency action level of the barrier function based on the operation status information.
[0193] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine whether to trigger the initial conditions of the emergency action level of the fault type based on the system fault information.
[0194] In one embodiment, when the processor executes the computer program, the following steps are further implemented: determine whether to trigger the initial conditions of the emergency action level of the disaster type based on the disaster information.
[0195] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0196] Obtain the operation information during the operation of the unit; the operation information includes at least one of operation status information, system fault information, and disaster information; determine whether to trigger the initial conditions of the corresponding emergency action level based on various operation information to obtain the triggering situation of the initial conditions of the emergency action level; determine the corresponding emergency action level for each triggering situation of the initial conditions of the emergency action level; select the highest emergency level among each emergency action level and determine it as the emergency status level.
[0197] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: during the operation of the unit, obtain the operation information based on a preset interface.
[0198] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: read the parameter limit conditions in the technical specification; judge the first operation information of the operation information based on each parameter limit condition; the first operation information is the operation information corresponding to the parameter limit condition; if the first operation information does not meet the parameter limit condition, determine to trigger the initial conditions of the emergency action level corresponding to the technical specification.
[0199] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: read the parameter alarm reasons in the alarm card; determine to trigger the initial conditions of the corresponding emergency action level based on the parameter alarm reasons.
[0200] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: when the unit enters the abnormal operation program, if it is detected that the operation information contains the abnormal confirmation information in the abnormal operation program, determine to trigger the initial conditions of the emergency action level corresponding to the abnormal operation program.
[0201] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: determine whether to trigger the initial conditions of the emergency action level of the barrier function based on the operation status information.
[0202] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: determine whether to trigger the initial conditions of the emergency action level of the fault type based on the system fault information.
[0203] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: determine whether to trigger the initial conditions of the emergency action level of the disaster type based on the disaster information.
[0204] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above various methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.
[0205] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0206] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. An emergency state classification method, characterized in that, the method includes: During the operation of the unit, obtain operation information based on a preset interface; the operation information includes at least one of operation status information, system failure information, and disaster information; the preset interface is an interface set for manually obtaining information; the preset interface includes an interface for confirming the intervention result corresponding to the operator's intervention, the operator's diagnosis and confirmation of the unit operation status, and an interface corresponding to the operator's diagnosis of a fault during the execution of function monitoring; Based on various types of the operation information, determine whether to trigger the initial conditions of the corresponding emergency action level, and obtain the triggering situation of the initial conditions of the emergency action level; the initial conditions of the emergency action level are conditions for judging whether to trigger the setting of the emergency action level; According to the triggering situation of each initial condition of the emergency action level, determine the corresponding emergency action level for each; Select the highest emergency level among each of the emergency action levels and determine it as the emergency state level.
2. The emergency state classification method according to claim 1, characterized in that, The determining whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information and obtaining the triggering situation of the initial conditions of the emergency action level includes: Read the parameter limit conditions in the technical specifications; Based on each of the parameter limit conditions, judge the first operation information of the operation information; the first operation information is the operation information corresponding to the parameter limit condition; If the first operation information does not meet the parameter limit condition, determine to trigger the initial conditions of the emergency action level corresponding to the technical specifications.
3. The emergency state classification method according to claim 1, characterized in that, The determining whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information and obtaining the triggering situation of the initial conditions of the emergency action level includes: Read the parameter alarm reasons in the alarm card; Based on the parameter alarm reasons, determine to trigger the initial conditions of the corresponding emergency action level.
4. The emergency state classification method according to claim 1, characterized in that, The determining whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information and obtaining the triggering situation of the initial conditions of the emergency action level includes: When the unit enters the abnormal operation program, if it is detected that the operation information contains the abnormal confirmation information in the abnormal operation program, determine to trigger the initial conditions of the emergency action level corresponding to the abnormal operation program.
5. The emergency state classification method according to claim 1, characterized in that, The determining whether to trigger the initial conditions of the corresponding emergency action level based on various types of the operation information and obtaining the triggering situation of the initial conditions of the emergency action level includes at least one of the following: The first item, based on the operation status information, determine whether to trigger the initial conditions of the emergency action level of the barrier function; The second item, based on the system failure information, determine whether to trigger the initial conditions of the emergency action level of the fault type; The third item, based on the disaster information, determine whether to trigger the initial conditions of the emergency action level of the disaster type.
6. The emergency state classification method according to claim 5, It is characterized in that the initial conditions of the emergency action level for the barrier functions include at least one of the following: potential loss of the fuel cladding barrier, loss of the fuel cladding barrier, potential loss of the primary circuit pressure boundary barrier, loss of the primary circuit pressure boundary barrier, potential loss of the containment barrier, and loss of the containment barrier.
7. The emergency state classification method according to claim 6, characterized in that: the potential loss of the fuel cladding barrier includes: degradation of the primary coolant inventory, degradation of the residual heat removal function, or degradation of the steam generator coolant inventory; the loss of the fuel cladding barrier includes: the core outlet temperature is greater than the temperature threshold, or degradation of the containment integrity function; the potential loss of the primary circuit pressure boundary barrier includes at least one of the following: degradation of the residual heat removal function, degradation of the residual heat discharge function, degradation of the steam generator coolant inventory, a primary circuit leak with an automatic reactor trip signal present, and degradation of the steam generator integrity with an automatic reactor trip signal present; the loss of the primary circuit pressure boundary barrier includes: degradation of the containment integrity function, or a primary circuit break with an emergency injection signal present; the potential loss of the containment barrier includes: degradation of the containment integrity function and a failure of the containment spray system, the containment pressure exceeding the design limit pressure, or reaching the severe accident entry conditions; the loss of the containment barrier includes: failure of the steam generator isolation and degradation of the steam generator integrity function, or failure of the containment isolation and triggering of the containment isolation signal.
8. The emergency state classification method according to claim 5, characterized in that, the initial conditions of the emergency action level for the failure functions include at least one of the following: loss of off-site AC power, single power supply to the emergency AC bus, and loss of all AC power to the emergency AC bus.
9. The emergency state classification method according to claim 5, characterized in that, the initial conditions of the emergency action level for the disaster functions include: a fire occurs and affects the safety function, or a fire occurs and does not affect the safety function.
10. An emergency state classification device, characterized in that, the device includes: an acquisition module, configured to obtain operation information based on a preset interface during the operation of the unit; the operation information includes at least one of operation status information, system fault information, and disaster information; the preset interface is an interface set for manually obtaining information; the preset interface includes an interface for confirming the intervention result when the operator intervenes, the operator's diagnosis and confirmation of the unit operation status, and an interface corresponding to the operator's diagnosis of a fault during the execution of function monitoring; a condition judgment module, configured to determine whether to trigger the corresponding initial conditions of the emergency action level based on various types of the operation information, and obtain the triggering situation of the initial conditions of the emergency action level; the initial conditions of the emergency action level are conditions for judging whether to trigger the emergency action level setting; an emergency action level determination module, configured to determine the corresponding emergency action level for each of the triggering situations of the initial conditions of the emergency action level; a state classification module, configured to determine the emergency state level in combination with each of the emergency action levels.
11. A computer device, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, when the processor executes the computer program, the steps of the method according to any one of claims 1 to 9 are implemented.
12. A computer-readable storage medium, on which a computer program is stored, characterized in that, when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Nuclear power plant emergency state diagnosis system and diagnosis method
CN104916339A