A Configuration Risk Assessment Method Based on PSA Model and Modeling Software
Through the configuration risk evaluation method based on PSA model and modeling software, the problem of the gap in the configuration risk control of new nuclear power plants before the development of risk monitors is solved, and the configuration risk control of the power plant before the risk monitor is launched is realized, which improves the nuclear safety level of the power plant.
Patent Information
- Application Number
- CN202210436733.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-25
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-04-25
AI Technical Summary
A new nuclear power plant will undergo a gap in configuration risk control before the risk monitor is developed, resulting in the safety of the power plant being unable to be guaranteed during this period and the operational risk is relatively high.
A configuration risk assessment method based on PSA model and modeling software is proposed. By obtaining the differences between the PSA model in the design stage and the real-time risk model, the impact of maintenance/test unavailability events in the PSA model in the design stage is eliminated, and the risk increment value is calculated based on the actual operation of the power plant, so as to realize the early implementation of configuration risk management and control work.
This method can use the design stage PSA model to perform configuration risk assessment before the risk monitor is launched, make up for the lack of risk control in power plant configuration before the risk monitor is launched, improve the overall nuclear safety level of the power plant, and create a good nuclear safety atmosphere.
Smart Images

Figure CN114722628B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of nuclear power plant safety analysis, and particularly to a configuration risk assessment method based on a PSA model and modeling software. Background Art
[0002] Since the rapid development and application of the Probabilistic Risk Assessment (PSA) method to nuclear power in the 1970s, countries around the world have carried out a large number of studies on PSA and applied PSA to the operation management and safety supervision of nuclear power plants. The US NRC issued the Maintenance Rule (10 CFR 50.65) in 1991, requiring nuclear power plant owners to develop appropriate management and index systems to effectively evaluate the maintenance activities of SSCs. In 1999, the NRC revised the Maintenance Rule, requiring owners to evaluate and manage the risks caused by maintenance activities before their implementation. To meet regulatory requirements, the vast majority of nuclear power plants in the United States have established a configuration risk management system to assess and manage the risks introduced by equipment outages. In the 1990s, China also began to explore and study the use of risk monitors to evaluate the configuration risks of power plants and gave relevant safety recommendations. Practice has proved that the configuration risk control of nuclear power at home and abroad has effectively improved the operation safety of power plants.
[0003] At present, nuclear power plants at home and abroad all use risk monitors to conduct configuration risk management based on probabilistic safety analysis for power plants. A risk monitor is a tool that encapsulates a real-time risk model and provides a friendly user interface for non-PSA professionals to use. However, the development of a risk monitor requires two steps of model conversion. The first step is to convert the PSA model in the design stage into the PSA model in the operation stage, and the second step is to convert the PSA model in the operation stage into a real-time risk model.
[0004] Generally speaking, a power plant has a PSA model in the design stage. The PSA model in the operation stage is a secondary development of the PSA model in the design stage on the basis of comprehensively considering factors such as power plant design changes and operation characteristics, reflecting the risk characteristics of the power plant during operation. Therefore, the development work of the PSA model in the operation stage can only be carried out after the power plant is put into operation, and then the conversion of the real-time risk model can be completed to realize the development of the risk monitor. According to this characteristic, it generally takes 2-3 years after the formal commercial operation of a new unit of a power plant to complete the development of the risk monitor. Therefore, all newly built power plants will experience a blank period of configuration risk control in the operation stage before the development of the risk monitor is completed. The power plant needs to experience a period of lack of risk control, and the safety of the power plant cannot be guaranteed during this period. The risk of power plant operation is relatively high. Therefore, doing a good job in the configuration risk control of the power plant at this stage is of great significance for improving the operation safety of the power plant.
[0005] Chinese Patent CN103400246B, with the publication date of July 6, 2016, discloses a risk monitoring system and method for nuclear power plants based on a cloud architecture. The system includes eight major functional modules. The system is architected based on a cloud platform, constructing a virtual machine cluster from the idle physical machines of the nuclear power plant through the Internet. This system can automatically migrate faulty nodes to ensure its reliable, stable, and continuous operation. At the same time, it can utilize the advantages of combining cloud computing and distributed computing to solve the problem of dynamically allocating computing resources according to the number of status points of the maintenance plan when using the maintenance plan management module of the risk monitoring system for large-scale maintenance plans, thus saving computing resources to the greatest extent while solving the problem that the computing speed is too slow to meet the actual production management requirements. The system in the above patent conducts risk monitoring on the power plant after the risk monitor of the power plant is developed, that is, for power plants that have been in formal commercial operation for 2 - 3 years. Since the risk monitor of newly built power plants in the risk control blank period has not been developed, the above system cannot conduct risk control on newly built power plants in the risk control blank period. Summary of the Invention
[0006] The purpose of the present invention is to propose a configuration risk assessment method based on the PSA model and modeling software in view of the deficiencies of the above-mentioned prior art.
[0007] The present invention proposes a configuration risk assessment method based on the PSA model and modeling software, including the following steps:
[0008] S1: Based on the PSA model and real-time risk model in the design stage of the power plant, obtain the differences between the PSA model and real-time risk model in the design stage. The differences include four aspects: maintenance / test unavailability events, operation / standby columns, lumped initiating events, and unmodeled equipment.
[0009] S2: Eliminate the influence of maintenance / test unavailability events in the PSA model in the design stage through modeling software to form a modified model.
[0010] S3: According to the actual operation situation of the power plant, calculate and set to eliminate the influence of one or more of the operation / standby columns, unmodeled equipment, and lumped initiating events on the calculation results, obtain the power plant risk increment value, and control the power plant risk according to the power plant risk increment value.
[0011] Further, specifically eliminating the influence of maintenance / test unavailability events in the PSA model in the design stage in step S2 includes: setting the failure probability value of the corresponding basic event in the PSA model in the design stage to 0, or setting the status of the corresponding basic event in the PSA model in the design stage to FALSE, or directly deleting the corresponding basic event in the PSA model in the design stage.
[0012] Further, the elimination of the influence of the operating / standby column in step S3 specifically includes: adjusting the equipment status in the modified model according to the actual operating conditions of the power plant and the system configuration in the modified model.
[0013] Further, the elimination of the influence of the lumped initiating event in step S3 specifically includes: obtaining the corresponding risk increment of the power plant by reasonably setting the modified model and appropriately correcting the risk calculation results.
[0014] Further, the elimination of the influence of unmodeled equipment in step S3 specifically includes: obtaining the failed equipment in the actual operation of the power plant. If the failed equipment is an unmodeled equipment in the modified model, analyzing the failure influence of the unmodeled equipment, obtaining a modeled equipment with the same failure influence as that of the unmodeled equipment, and replacing the failure of the unmodeled equipment with the failure of the modeled equipment.
[0015] Further, if the configuration in the model is consistent with the actual operation configuration of the power plant and all columns in the actual operation of the power plant are in only one of the operating and standby states, when maintenance occurs in the first preset column in the actual operation of the power plant, set the equipment in the first preset column in the model to failed.
[0016] Further, if all columns in the actual operation of the power plant include standby columns in the standby state and operating columns in the operating state: when maintenance occurs in the operating columns of the power plant, if the operating condition of the power plant does not change at this time, set the equipment in the operating columns in the model to failed; if the operating condition of the power plant changes at this time, set the equipment in the standby columns in the model to failed; when maintenance occurs in the standby columns of the power plant, set the equipment in the standby columns in the model to failed.
[0017] Further, if the failed equipment belongs to the mitigation equipment of a preset lumped initiating event, respectively obtain the first risk value caused by other initiating events after removing the preset lumped initiating event in the power plant and the second risk value caused by the preset lumped initiating event in the power plant, and add the first risk value and the second risk value to obtain the CDF of the power plant.
[0018] Further, the obtaining of the first risk value specifically includes: assuming that there are two pipelines, A and B, in the power plant system, and only pipeline A is included in the model. When the equipment in pipeline A fails in the actual operation of the power plant, set the equipment in pipeline A in the model to failed, calculate the overall CDF1 of the power plant using the modeling software and calculate the CDF2 caused by this lumped initiating event separately, and calculate the first risk value according to the formula CDF1 - CDF2; when the equipment in pipeline B fails in the actual operation of the power plant, there is no need to set the model, calculate the overall CDF1 of the power plant using the modeling software and calculate the CDF2 caused by this lumped initiating event separately, and calculate the first risk value according to the formula CDF1 - CDF2.
[0019] Further, obtaining the second risk value specifically includes: According to the calculation formula of the second risk value == 0.5 * the frequency of the lumped initiating event * the failure probability mitigated by column A * the failure probability of other mitigation systems + 0.5 * the frequency of the lumped initiating event * the failure probability mitigated by column B * the failure probability of other mitigation systems; Assume that the power plant system includes two pipelines, column A and column B, and the model only includes the pipeline of column A. When the equipment in column A or column B fails during the actual operation of the power plant, first change the frequency of the lumped initiating event to half of the original, use the modeling software to calculate the risk value CDF3 caused by the lumped initiating event, and then based on the model with the modified initiating event frequency, set the equipment on the pipeline of column A in the model to fail. If the equipment on the pipeline of column B actually fails in the power plant, also set the equipment on the pipeline of column A in the model to fail, use the modeling software to calculate the risk value CDF4 caused by the lumped initiating event, and calculate the second risk value according to the formula CDF3 + CDF4.
[0020] A configuration risk assessment method based on a PSA model and modeling software of the present invention has the following beneficial effects:
[0021] Based on the characteristics of the PSA model in the power plant design stage and the modeling software, the power plant can modify the PSA model in the design stage independently to carry out the configuration risk control work in advance, which can make up for the lack of probabilistic safety configuration risk control in the power plant before the risk monitor is put into operation, solve the problem of the configuration risk control blank in the newly built nuclear power plant before the risk monitor is developed, improve the overall nuclear safety level of the power plant, and create a good nuclear safety atmosphere; This method can help power plant personnel better optimize the maintenance plan and assist in controlling the overall risk of the power plant; This method has strong versatility and can be applied to various types of units; The implementation of this method can be completed by the power plant itself, with high feasibility and no additional practical costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings incorporated into the specification and constituting a part of the specification illustrate embodiments of the present invention and, together with the description, are used to explain the principles of the present invention. In these drawings, like reference numerals are used to represent like elements. The drawings in the following description are some embodiments of the present invention, not all embodiments. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0023] Figure 1 It is a flowchart of a configuration risk assessment method based on a PSA model and modeling software of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other arbitrarily.
[0025] Please refer to Figure 1 . A configuration risk assessment method based on a PSA model and modeling software in an embodiment of the present invention includes the following steps:
[0026] S1: Based on the PSA model and real-time risk model in the design stage of the power plant, obtain the differences between the PSA model and the real-time risk model in the design stage. The differences include four aspects: maintenance / test unavailability events, operation / standby columns, lumped initiating events, and unmodeled equipment;
[0027] S2: Eliminate the influence of maintenance / test unavailability events in the PSA model in the design stage through the modeling software to form a modified model;
[0028] S3: According to the actual operation situation of the power plant, eliminate the influence of one or more of the operation / standby columns, unmodeled equipment, and lumped initiating events on the calculation result by calculation settings, obtain the power plant risk increment value, and control the power plant risk according to the power plant risk increment value.
[0029] On the basis of fully analyzing the design characteristics of the PSA model in the design stage of the power plant, develop appropriate model modification methods and calculation methods to guide the power plant staff to carry out configuration risk control work using the PSA model in the design stage and the modeling software before the completion of the risk monitor development, so as to improve the overall nuclear safety level of the power plant. By comparing the real-time model and the PSA model in the design stage, the differences in the analysis results of the two are mainly reflected in maintenance / test unavailability events, operation / standby columns, lumped initiating events, and unmodeled equipment. First, eliminate the influence of maintenance / test unavailability events in the PSA model in the design stage to form a modified model, and then according to the actual operation situation of the power plant, eliminate the influence of one or more of the operation / standby columns, unmodeled equipment, and lumped initiating events on the calculation result by calculation settings, so as to realize the configuration risk assessment using the PSA model in the design stage before the risk monitor goes online.
[0030] Generally, a power plant first has a PSA model in the design stage. After 2-3 years, based on the PSA model in the design stage, a operation PSA model is developed by combining the design changes of the power plant in recent years. Then, a real-time model is developed based on the operation PSA model. Therefore, it is generally impossible for a power plant to develop an accurate real-time model immediately after the PSA model in the design stage is developed. So in this application, the PSA model in the design stage of the power plant can be simply modified directly. That is, the impact of maintenance / test unavailable events in the PSA model in the design stage is eliminated through modeling software. Then, using the modified model, a risk value is calculated using a specific calculation method. That is, the impact of one or more of the operation / standby columns, unmodeled equipment, and lumped initiating events on the calculation result is eliminated through calculation settings. Then, appropriate corrections are made according to the calculation situation, and then a risk increment value that can reflect the power plant is obtained to control the risk of the power plant. There is a risk threshold in the actual operation of the power plant, and the power plant personnel conduct risk control based on the risk threshold and the configured risk assessment results. In this application, it is necessary to eliminate the impact of maintenance / test unavailable events in the PSA model in the design stage. The elimination of the impact of the operation / standby column, unmodeled equipment, and lumped initiating events can be selected according to different calculation situations. According to the actual calculation situation, if the impact of the operation / standby column is encountered, the impact of the operation / standby column is eliminated. If the impact of unmodeled equipment is encountered, the impact of unmodeled equipment is eliminated.
[0031] The elimination of the impact of maintenance / test unavailable events in the PSA model in the design stage in step S2 specifically includes: setting the failure probability value of the corresponding basic event in the PSA model in the design stage to 0, or setting the status of the corresponding basic event in the PSA model in the design stage to FALSE, or directly deleting the corresponding basic event in the PSA model in the design stage. The PSA model in the design stage usually uses a basic event to model the test / maintenance unavailable event. However, the power plant configuration in the real-time risk model is determined and the test / maintenance unavailable event does not need to be considered. Therefore, it is necessary to eliminate the impact of maintenance / test unavailable events in the PSA model in the design stage.
[0032] The elimination of the impact of the operation / standby column in step S3 specifically includes: adjusting the equipment status in the modified model according to the actual operation situation of the power plant and the system configuration situation in the modified model. The real-time risk model establishes corresponding fault tree models according to different configurations of the power plant, while the model in the design stage only assumes a specific configuration and models it. For example, in the power plant, it is assumed that there are two columns A and B. In the real-time risk model, the configuration of A operating and B standby is modeled, and the configuration of A standby and B operating is also modeled. However, in the PSA model in the design stage, only the configuration of A operating and B standby is modeled. Therefore, it is necessary to eliminate the impact of the operation / standby column. For this problem, it can be solved by reasonable settings of the model during the evaluation process, and there is no need to complete the model according to the actual situation of the power plant.
[0033] If the configuration in the model is consistent with the actual operation configuration of the power plant and all columns in the actual operation of the power plant are in only one of the operating and standby states, then when maintenance occurs in the first preset column in the actual operation of the power plant, the equipment in the first preset column in the model is set to failed.
[0034] Scenario 1 - The actual operation status of the power plant is that all columns are in the operating state, and the configuration in the model is consistent with the power plant, also all columns are in the operating state. Then:
[0035] 1) If maintenance occurs in Column A, then the equipment in Column A in the model is set to failed.
[0036] 2) If maintenance occurs in Column B, then the equipment in Column B in the model is set to failed.
[0037] Scenario 2 - The actual operation status of the power plant is that all columns are in the standby state (usually Columns A and B), and the configuration in the model is consistent with the power plant, also all columns are in the standby state. Then:
[0038] 1) If maintenance occurs in Column A, then the equipment in Column A in the model is set to failed.
[0039] 2) If maintenance occurs in Column B, then the equipment in Column B in the model is set to failed.
[0040] If all columns in the actual operation of the power plant include standby columns in the standby state and operating columns in the operating state: When maintenance occurs in the operating columns of the power plant, if the operating status of the power plant has not changed at this time, then the equipment in the operating columns in the model is set to failed; if the operating status of the power plant has changed at this time, then the equipment in the standby columns in the model is set to failed; when maintenance occurs in the standby columns of the power plant, then the equipment in the standby columns in the model is set to failed.
[0041] Scenario 3 - The actual operation status of the power plant is one in use and one in standby or two in use and one in standby. The configuration in the model may or may not be consistent with the actual operation status of the power plant. Then:
[0042] 1) Maintenance occurs in the operating column. If the operating status of the power plant has not changed at this time (the operating column has not exited operation and the standby column has not been put into operation), then the equipment in the operating column in the model is set to failed. If the operating status of the power plant has changed at this time (the operating column exits operation and the standby column is put into operation simultaneously), then the equipment in the standby column in the model fails.
[0043] 2) If maintenance occurs in the standby column, then the equipment in the standby column in the model is set to failed.
[0044] The modeling methods of the spare train and the operating train are different. When maintenance occurs in the operating train or spare train, the corresponding train in the model is set to fail, which can make the state in the model closer to the actual situation, thereby obtaining accurate calculation results. Scenarios 1, 2, and 3 are three situations under this step of eliminating the impact of the operating / spare train.
[0045] Eliminating the impact of the lumped initiating events in step S3 specifically includes: obtaining the corresponding risk increment of the power plant by reasonably setting and modifying the model and appropriately correcting the risk calculation results. In the design stage, the PSA model generally makes some lumped assumptions about the initiating events according to the process of the accident, the success criteria, etc. For example, in the PSA model in the design stage, for the initiating events such as SGTR and DVI pipeline rupture, the rupture is considered to occur in column B, so column B is not modeled in the mitigation system after the accident. However, in the real-time risk model, if this assumption is still maintained, it may not be able to reflect the risk level of the actual configuration of the power plant. Therefore, these initiating events will be balanced in the real-time model. For example, for the SGTR and DVI pipeline rupture accidents, the rupture of the pipeline in column A and the rupture of the pipeline in column B will be modeled separately, and the frequency of the initiating events will be half of each. As far as this problem is concerned, it can be solved by reasonably setting the model and appropriately correcting the results, without completing the model according to the actual situation of the power plant.
[0046] If the failed device is a mitigation device for a preset collective initiating event, obtain a first risk value of the power plant caused by other initiating events after removing the preset collective initiating event and a second risk value of the power plant caused by the preset collective initiating event, and add the first risk value and the second risk value to obtain the CDF of the power plant.
[0047] Obtaining the first risk value specifically includes: assuming that the power plant system includes two columns of pipelines A and B, and the model only includes column A pipelines. When the equipment in column A fails during the actual operation of the power plant, the equipment in column A in the model is set to fail, and the modeling software is used to calculate the overall CDF1 of the power plant and the CDF2 caused by the aggregate initiating event, and the first risk value is calculated according to the formula CDF1-CDF2. When the equipment in column B fails during the actual operation of the power plant, there is no need to set up the model, and the modeling software is used to calculate the overall CDF1 of the power plant and the CDF2 caused by the aggregate initiating event, and the first risk value is calculated according to the formula CDF1-CDF2. The CDF2 here is an inaccurate risk value calculated by the software, and the first risk value is the risk value caused by other initiating events of the power plant after the aggregate initiating event is calculated by the modeling software.
[0048] Obtaining the second risk value specifically includes: According to the calculation formula of the second risk value == 0.5 * the frequency of the lumped initiating event * the failure probability mitigated by column A * the failure probability of other mitigation systems + 0.5 * the frequency of the lumped initiating event * the failure probability mitigated by column B * the failure probability of other mitigation systems. Assume that the power plant system contains two pipelines, column A and column B, and only column A pipeline is included in the model. When equipment in column A or column B fails during the actual operation of the power plant, first change the frequency of the lumped initiating event to half of the original, use the modeling software to calculate the risk value CDF3 caused by the lumped initiating event, and then based on the model with the modified initiating event frequency, set the equipment on column A in the model to fail (if the equipment on column B actually fails in the power plant, also set the equipment on column A in the model to fail. For example, if 1-XXX-XX-01B actually fails in the power plant, then set 1-XXX-XX-01A on column A in the model to fail), use the modeling software to calculate the risk value CDF4 caused by the lumped initiating event, and calculate the second risk value according to the formula CDF3 + CDF4.
[0049] Then the accurate total CDF of the power plant = CDF1 - CDF2 + CDF3 + CDF4, which can better identify risks and conduct control.
[0050] Eliminating the influence of unmodeled equipment in step S3 specifically includes: Obtain the failed equipment during the actual operation of the power plant. If the failed equipment is an unmodeled equipment in the modified model, analyze the failure influence of the unmodeled equipment, obtain the modeled equipment with the same failure influence as the unmodeled equipment, and replace the failure of the unmodeled equipment with the failure of the modeled equipment. Since generally only a specific configuration is assumed in the PSA model during the design stage, some equipment is not modeled in the model, which is appropriate in the design stage model but cannot reflect the actual configuration of the power plant. For this problem, it can be avoided through model settings without adding each unmodeled equipment in the model one by one. If unmodeled equipment is found during the risk assessment process, first analyze its failure influence, and then replace the failure of the unmodeled equipment with the failure of the modeled equipment. For example, equipment A and equipment B are on the same series branch, but only equipment A is modeled in the PSA model during the design stage. Since the failure influence of equipment B is the same as that of equipment A, if equipment B actually fails in the actual power plant configuration, equipment A can be set to fail in the model.
[0051] The content described above can be implemented alone or in various combinations, and these variant ways are all within the protection scope of the present invention.
[0052] It should be noted that in the description of this application, the terms "upper end", "lower end", and "bottom end" indicating the orientation or positional relationship are based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of this application is usually placed during use. These are only for the convenience of describing this application and simplifying the description, rather than indicating or implying that the device referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to this application. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
[0053] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A configuration risk assessment method based on a PSA model and modeling software, characterized in that, it includes the following steps: S1: Based on the PSA model and real-time risk model in the design stage of the power plant, obtain the differences between the PSA model and the real-time risk model in the design stage, and the differences include four aspects: maintenance / test unavailability events, operation / standby columns, lumped initiating events, and unmodeled equipment; S2: Eliminate the influence of maintenance / test unavailability events in the PSA model in the design stage through modeling software to form a modified model; S3: According to the actual operation situation of the power plant, calculate and set to eliminate the influence of one or more of the operation / standby columns, unmodeled equipment, and lumped initiating events on the calculation result, obtain the power plant risk increment value, and control the power plant risk according to the power plant risk increment value; In step S3, eliminating the influence of the operation / standby column specifically includes: adjusting the equipment status in the modified model according to the actual operation situation of the power plant and the system configuration situation in the modified model; If the configuration in the model is consistent with the actual operation configuration of the power plant and all columns in the actual operation of the power plant are in only one of the operation and standby states, when maintenance occurs in the first preset column in the actual operation of the power plant, set the equipment in the first preset column in the model to failed; If all columns in the actual operation of the power plant include standby columns in the standby state and operation columns in the operation state: when maintenance occurs in the operation column of the power plant, if the operation status of the power plant has not changed at this time, set the equipment in the operation column in the model to failed, if the operation status of the power plant has changed at this time, set the equipment in the standby column in the model to failed; when maintenance occurs in the standby column of the power plant, set the equipment in the standby column in the model to failed.
2. A configuration risk assessment method based on a PSA model and modeling software as described in claim 1, characterized in that, In step S2, eliminating the influence of maintenance / test unavailability events in the PSA model in the design stage specifically includes: setting the failure probability value of the corresponding basic event in the PSA model in the design stage to 0, or setting the status of the corresponding basic event in the PSA model in the design stage to FALSE, or directly deleting the corresponding basic event in the PSA model in the design stage.
3. A configuration risk assessment method based on a PSA model and modeling software as described in claim 1 or 2, characterized in that, In step S3, eliminating the influence of lumped initiating events specifically includes: setting the modified model and correcting the risk calculation result to obtain the corresponding risk increment of the power plant.
4. A configuration risk assessment method based on a PSA model and modeling software as described in claim 1 or 2, characterized in that, In step S3, eliminating the influence of unmodeled equipment specifically includes: obtaining the failed equipment in the actual operation of the power plant, if the failed equipment is an unmodeled equipment in the modified model, analyzing the failure influence of the unmodeled equipment, obtaining a modeled equipment whose failure influence is consistent with that of the unmodeled equipment, and replacing the failure of the unmodeled equipment with the failure of the modeled equipment.
5. A configuration risk assessment method based on a PSA model and modeling software as described in claim 3, characterized in that: If the failed device belongs to the mitigation device of a preset lumped initiating event, respectively obtain the first risk value caused by other initiating events in the power plant after removing the preset lumped initiating event and the second risk value caused by the preset lumped initiating event in the power plant, and add the first risk value and the second risk value to obtain the CDF of the power plant.
6. A configuration risk assessment method based on a PSA model and modeling software as claimed in claim 5, characterized in that The specific steps for obtaining the first risk value include: There are two pipelines, namely Pipeline A and Pipeline B, in the power plant system, and only Pipeline A is included in the model. When the equipment in Pipeline A fails during the actual operation of the power plant, set the equipment in Pipeline A in the model to be failed, and use the modeling software to calculate the overall CDF1 of the power plant and the CDF2 caused by this lumped initiating event calculated separately. Calculate the first risk value according to the formula CDF1 - CDF2; when the equipment in Pipeline B fails during the actual operation of the power plant, there is no need to set the model, use the modeling software to calculate the overall CDF1 of the power plant and the CDF2 caused by this lumped initiating event calculated separately, and calculate the first risk value according to the formula CDF1 - CDF2.
7. A configuration risk assessment method based on a PSA model and modeling software as claimed in claim 5, characterized in that The specific steps for obtaining the second risk value include: According to the calculation formula of the second risk value == 0.5 * the frequency of this lumped initiating event * the failure probability mitigated by Pipeline A * the failure probability of other mitigation systems + 0.5 * the frequency of this lumped initiating event * the failure probability mitigated by Pipeline B * the failure probability of other mitigation systems; there are two pipelines, namely Pipeline A and Pipeline B, in the power plant system, and only Pipeline A is included in the model. When the equipment in Pipeline A or Pipeline B fails during the actual operation of the power plant, first change the frequency of this lumped initiating event to half of the original, use the modeling software to calculate the risk value CDF3 caused by this lumped initiating event, and then based on the model with the modified initiating event frequency, set the equipment on Pipeline A in the model to be failed. If the equipment on Pipeline B actually fails in the power plant, also set the equipment on Pipeline A in the model to be failed, use the modeling software to calculate the risk value CDF4 caused by this lumped initiating event, and calculate the second risk value according to the formula CDF3 + CDF4.
Citation Information
Patent Citations
A risk monitoring system and method for nuclear power plants based on cloud architecture
CN103400246B
Method and device for evaluating risk of nuclear power station
CN101710400A