A digital protection system for nuclear power plants based on FPGA

By adopting a dual FPGA architecture in the safety-level digital control system of nuclear power plants, separating safety functions and auxiliary functions, and executing different dedicated safety facilities driving signals in parallel, the problems of insufficient independence and security of the existing system are solved, and efficient and reliable safety control is achieved.

CN116598032BActive Publication Date: 2025-07-25CHINA NUCLEAR CONTROL SYST ENG
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310566294.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-18
Publication Date
2025-07-25
Estimated Expiration
2043-05-18

AI Technical Summary

Technical Problem

The existing nuclear power plant safety-level digital control systems cannot operate in parallel due to the use of microprocessor (CPU) technology, resulting in low system independence and security.

Method used

Using a dual FPGA architecture, one FPGA is used to perform security functions and the other FPGA is used to perform auxiliary functions, separate auxiliary functions that are not closely related to safety functions, and divide the functional components in the dedicated safety facility drive system into two categories, respectively, generating dedicated safety facility drive signals with diverse grouping requirements and without diversified grouping requirements, realizing parallel, high-speed, and independent functional execution.

Benefits of technology

It improves the independence and security of the system, reduces the refusal rate, improves the system processing efficiency and reliability, and ensures that the safety functions are not affected when auxiliary functions fail.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116598032B_ABST
    Figure CN116598032B_ABST
Patent Text Reader

Abstract

The present invention discloses a digital protection system for nuclear power plants based on FPGA, belonging to the field of nuclear power plant safety protection. A dual-FPGA architecture is adopted, where one FPGA architecture is used to execute safety functions, and the other FPGA architecture is used to execute functions other than safety functions. Auxiliary functions that have little association with safety functions are separated from safety functions, so that the execution of safety functions will not be blocked when the auxiliary functions fail, thereby improving the system independence and security. Moreover, the functional groups in the dedicated safety facility drive system are divided into two categories. One category generates dedicated safety facility drive signals with diversity grouping requirements, and the other category generates dedicated safety facility drive signals without diversity grouping requirements, and executes the required functions in parallel, at high speed, and independently, improving the processing efficiency of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of nuclear power plant safety protection, and particularly to a digital protection system for nuclear power plants based on FPGA. Background Art

[0002] The function of the safety-class protection system of a nuclear power plant is to execute protection actions according to the monitoring of abnormal states and the degree of harm of abnormal changes when the nuclear parameters or process parameters of the power plant change abnormally or the operating personnel make misoperations, prevent the core fuel from burning out and the diffusion of excessive radioactive substances, and ensure the safety of the power plant and the surrounding residents.

[0003] At present, the safety-class digital control system has become the mainstream technology adopted by nuclear power plants. The safety-class digital control system mainly adopts the technology based on a microprocessor (CPU). However, the CPU has a von Neumann architecture and serially executes a series of instructions, unable to perform parallel operations, and the independence and security of the system are relatively low. Summary of the Invention

[0004] The purpose of the present invention is to provide a digital protection system for nuclear power plants based on FPGA, which can improve the independence and security of the system.

[0005] To achieve the above purpose, the present invention provides the following solutions:

[0006] A digital protection system for nuclear power plants based on FPGA includes: an emergency shutdown system and a dedicated safety facility drive system;

[0007] Both the emergency shutdown system and the dedicated safety facility drive system adopt a dual-FPGA architecture. One FPGA architecture is used to execute safety functions, and the other FPGA architecture is used to execute functions other than safety functions;

[0008] The emergency shutdown system is respectively connected to the dedicated safety facility drive system and the shutdown circuit breaker; the emergency shutdown system is used to collect reactor safety parameters, generate a channel-level local trip signal and an emergency shutdown signal according to the collected reactor safety parameters, send the channel-level local trip signal to the dedicated safety facility drive system, and send the emergency shutdown signal to the shutdown circuit breaker;

[0009] The dedicated safety facility drive system includes a first functional group, a second functional group, and a preferred drive system;

[0010] The first functional group is respectively connected to the emergency shutdown system and the preferred drive system. The first functional group is used to generate dedicated safety facility drive signals with diversity grouping requirements according to the channel-level local trip signal, and then control the safety actuator through the preferred drive system;

[0011] The second functional group is respectively connected to the emergency shutdown system and the preferred drive system. The second functional group is used to generate a dedicated safety facility drive signal without diversity grouping requirements according to the channel-level local trip signal, and then control the safety actuator through the preferred drive system.

[0012] According to the specific embodiments provided by the present invention, the following technical effects are disclosed by the present invention:

[0013] The present invention discloses a digital protection system for nuclear power plants based on FPGA, adopting a dual-FPGA architecture. One FPGA architecture is used to execute safety functions, and the other FPGA architecture is used to execute functions other than safety functions. The auxiliary functions that have little association with safety functions are separated from the safety functions. When the auxiliary functions fail, the execution of safety functions will not be blocked, thereby improving the independence and safety of the system. And the functional groups in the dedicated safety facility drive system are divided into two categories. One category generates dedicated safety facility drive signals with diversity grouping requirements, and the other category generates dedicated safety facility drive signals without diversity grouping requirements, and executes the required functions in parallel, at high speed, and independently, improving the processing efficiency of the system. Brief Description of the Drawings

[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0015] Figure 1 It is a structural diagram of a digital protection system for nuclear power plants based on FPGA provided by an embodiment of the present invention. Detailed Embodiments

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0017] The purpose of the present invention is to provide a digital protection system for nuclear power plants based on FPGA, which can improve the independence and safety of the system.

[0018] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.

[0019] Such asFigure 1 As shown in Figure 1 , an embodiment of the present invention provides a digital protection system for nuclear power plants based on FPGA, including: an emergency shutdown system and a dedicated safety facility drive system.

[0020] Both the emergency shutdown system and the dedicated safety facility drive system adopt a dual-FPGA architecture. One FPGA architecture is used to execute safety functions, and the other FPGA architecture is used to execute functions other than safety functions. The emergency shutdown system is respectively connected to the dedicated safety facility drive system and the shutdown circuit breaker; the emergency shutdown system is used to collect reactor safety parameters, and generate channel-level local trip signals and emergency shutdown signals according to the collected reactor safety parameters, send the channel-level local trip signals to the dedicated safety facility drive system, and send the emergency shutdown signals to the shutdown circuit breaker.

[0021] The dedicated safety facility drive system includes a first functional group, a second functional group, and a preferred drive system. The first functional group is respectively connected to the emergency shutdown system and the preferred drive system. The first functional group is used to generate dedicated safety facility drive signals with diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred drive system. The second functional group is respectively connected to the emergency shutdown system and the preferred drive system. The second functional group is used to generate dedicated safety facility drive signals without diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred drive system.

[0022] All modules adopt a dual-FPGA architecture, that is, it includes one processing FPGA (PFPGA) and one diagnostic FPGA (DFPGA). In addition, the controller uses one proprietary algorithm FPGA (AFPGA) for specific arithmetic logic. This dual-core FPGA architecture technology has been used in different ways in other industries, such as the rail transit field, and can be regarded as a hardware checker (IEC 61508). This method is used in 8000N to ensure the integrity, safety, and reliability of the execution of safety functions. The FPGA can execute multiple tasks in parallel without interference. The multi-bus cooperation technology makes full use of the characteristic that the FPGA can work in parallel.

[0023] The controller module has three FPGAs, namely the processing FPGA (PFPGA), the diagnostic FPGA (DFPGA), and the algorithm FPGA1 (AFPGA1). The PFPGA is the core device of the controller, performing functions such as control, communication, data processing, and maintenance of the controller module. The AFPGA1 is the algorithm execution device of the controller, mainly completing the configuration calculation function. The DFPGA mainly monitors whether the communication, PFPGA, and peripheral devices are working properly and returns the diagnostic information to the PFPGA; when a serious fault is diagnosed, it will cut off the communication bus of the PFPGA and the NP811 will enter the safe state.

[0024] The present invention adopts a safety-class DCS system architecture based on FPGA technology and uses a multiple redundancy technology for the protection groups. The redundancy technology improves the safety of the system, that is, reduces the refusal operation rate, but at the same time increases the misoperation rate. Therefore, in order to reduce the probability of accidental reactor trip, while using the redundancy technology, logic should also be used to improve the reliability of the system. The architecture of the present invention is based on the optimal system architecture model obtained after reliability calculation.

[0025] The FPGA-based digital protection system for nuclear power plants belongs to the reactor protection system and adopts a structure of four protection groups (IP, IIP, IIIP, and IVP) and two safety trains (TrainA, TrainB), where the reactor trip signal is generated in the protection group and the signal to start the engineered safety features is generated in the safety train.

[0026] Among them, the emergency reactor trip system includes: four protection groups. All four protection groups are connected to the engineered safety features actuation system; the four protection groups are connected to each other. Each protection group is used to collect the reactor safety parameters, generate a local trip signal according to the collected reactor safety parameters, and receive the local trip signals of the other three protection groups, and perform a logical vote on all the local trip signals to generate the emergency reactor trip signal of this channel and the channel-level local trip signal.

[0027] Each protection group includes: a protection signal preprocessing unit PIP, a functional subgroup PRC-Sub1, and a functional subgroup PRC-Sub2. The protection signal preprocessing unit PIP is respectively connected to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2.

[0028] The protection signal preprocessing unit PIP is used to collect reactor safety parameters. After conditioning the reactor safety parameters into standard signals, they are isolated and distributed to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2. That is, each protection group contains a PIPx (x = 1 to 4), which is used to collect signals from on-site sensors or transmitters. After signal conditioning (converting analog signals into 4 to 20 mA signals), according to functional requirements, the signals are isolated and distributed to each control station, non-safety-class system, and / or BUP, etc. in the protection group.

[0029] The functions of PIP include: conditioning (if necessary) the analog signals sent by sensors into standard signals, and isolating and distributing them to two diverse subsystems or other external systems (such as DAS or NC DCS).

[0030] The functional subgroup PRC-Sub1 is respectively connected to the engineered safety feature actuation system and the reactor trip breaker. The functional subgroup PRC-Sub1 is used to generate local trip signals according to the standard signals, and receive local trip signals from the other 3 protection groups, perform logical voting on all local trip signals, generate the emergency reactor trip signal and channel-level local trip signal of this channel, send the emergency reactor trip signal of this channel to the reactor trip breaker, and send the channel-level local trip signal to the engineered safety feature actuation system.

[0031] The functional subgroup PRC-Sub2 is respectively connected to the engineered safety feature actuation system and the reactor trip breaker. The functional subgroup PRC-Sub2 is used to generate local trip signals according to the standard signals, and receive local trip signals from the other 3 protection groups, perform logical voting on all local trip signals, generate the emergency reactor trip signal and channel-level local trip signal of this channel, send the emergency reactor trip signal of this channel to the reactor trip breaker, and send the channel-level local trip signal to the engineered safety feature actuation system.

[0032] Each protection group contains two functional subgroups Sub11 and Sub12 (Sub21 and Sub22, Sub31 and Sub32, Sub41 and Sub42), where Sub11, Sub21, Sub31, and Sub41 belong to the functional subgroup Sub1, and Sub12, Sub22, Sub32, and Sub42 belong to the functional subgroup Sub2, which is used to achieve functional diversity and complete functions such as signal acquisition (signals come from PIP), engineering quantity value conversion of signals, threshold comparison, and voting logic of the protection system. The reactor trip signals generated by the two control stations are sent to the reactor trip breaker through a hardware logic "OR".

[0033] Figure 1The RPC-sub11 / sub12 / sub31 / sub32 / sub21 / sub22 / sub41 / sub42 in it constitutes the Reactor Trip System (RTS) and performs the following tasks:

[0034] a) Collect signals sent from the PIP, nuclear instrumentation, and other devices in this protection group, and generate a "local trip" signal after calculation and processing. The "local trip" signal is a digital quantity and is generated by comparing the collected signals with the protection set values. These comparisons involve I&C functions such as whether to trigger an emergency reactor trip, turbine trip, actuate the drive safety facilities, or support system functions. The "local trip" signals generated by each protection group need to be sent to the other three protection groups. In each protection group, logical voting is performed on these "local trip" signals to generate the emergency reactor trip signal for this channel and the channel-level "local trip" signal for ESFAS drive. The ESFAS channel-level "local trip" signal is transmitted to the ESFAC through a point-to-point fiber optic network. One protection group corresponds to one channel.

[0035] Among them, the calculation and processing process of the "local trip" signal is as follows: The PIP collects standard 4-20 mA signals, and the controller receives the analog signals from the PIP and performs threshold comparison in the controller. After comparison, a local trip signal is generated.

[0036] b) Each protection group outputs an emergency reactor trip signal to the reactor trip breaker corresponding to this protection group, and outputs a turbine brake signal to the TPCS system.

[0037] Send signals to the main control room ( Figure 1 not shown in the figure) through hardwiring or communication interfaces for monitoring, recording, and alarming, etc.

[0038] Engineered Safety Feature Actuation System (ESFAS): The engineered drive functions implemented in the RPC and ESFAC are also divided into two diverse subsystems. Each series of ESFAC receives the "local trip" signals from the corresponding subsystems of the RPC. ESFAC-A11 / A21 / B11 / B21 correspond to Subsystem 1 in the protection train, and ESFAC-A12 / A22 / B12 / B22 correspond to Subsystem 2 in the protection train.

[0039] The main functions of the ESFAS are as follows:

[0040] a) Receive the channel-level "local trip" signals from the RTS, perform 2 / 4 calculation and corresponding logical processing on the system-level engineered drive, and decompose them into component-level engineered drive signals and send them to the Preferred Logic Module (PLM) through hardwiring.

[0041] b) The control or interlock signals generated by the RPC for other systems are first sent to the ESFAC through a point-to-point optical fiber network, and then sent out from the ESFAC after 2 / 4 logic calculation.

[0042] ESFAC-A11 / 12 and ESFAC-A21 / 22 are independent of each other, and the failure of a certain subsystem shall not prevent the execution of the functions of another subsystem. The dedicated drive signals output by each subsystem are first sent to the Priority Management Module (PLM), and after an "OR" operation inside the PLM, they are sent to the dedicated driver. The same applies to ESFAC-B11 / 12 and ESFAC-B21 / 22.

[0043] Functions without diversity grouping requirements are implemented in ESFAC-AC / BC, so as to reduce the complexity of ESFAC-A11 / 12 / 21 / 22 and ESFAC-B11 / 12 / 21 / 22 as much as possible and improve their reliability. If it is necessary to receive signals from ESFAC-A11 / 12 / 21 / 22 or ESFAC-B11 / 12 / 21 / 22 for interlock operation, the signals in ESFAC-A11 / 12 / 21 / 22 (or ESFAC-B11 / 12 / 21 / 22) are transmitted to ESFAC-AC / BC through a multi-node optical fiber network.

[0044] The 1E-level functions also need to receive signals from the RPC. For example, the VCL system needs to receive IRM system signals from the RPC in the protection group for its logic processing. In this case, the RPC directly connects through a point-to-point optical fiber and transmits the signals directly to ESFAC-AC / BC.

[0045] The drive signals output by ESFAC-AC / BC are first sent to the PLM, and then to the field driver.

[0046] ESFAC-AC and ESFAC-BC are preferably connected through a point-to-point optical fiber network to exchange the signals that need to be exchanged between protection column A and protection column B. It is also possible to design a hard-wired decoupling circuit for signal interaction between columns A and B. If a hard-wired connection is adopted, a decoupling power supply needs to be designed for decoupling.

[0047] The first functional group of the dedicated safety facility drive system includes: functional subgroup ESFAC-SubA1, functional subgroup ESFAC-SubA2, functional subgroup ESFAC-SubB1, and functional subgroup ESFAC-SubB2.

[0048] The functional subgroup ESFAC-SubA1 is connected to the functional subgroup PRC-Sub1 of two protection groups, and the functional subgroup ESFAC-SubA2 is connected to the functional subgroup PRC-Sub2 of two protection groups. The functional subgroup ESFAC-SubB1 is connected to the functional subgroup PRC-Sub1 of another two protection groups, and the functional subgroup ESFAC-SubB2 is connected to the functional subgroup PRC-Sub2 of another two protection groups. The functional subgroup ESFAC-SubA1, the functional subgroup ESFAC-SubA2, the functional subgroup ESFAC-SubB1, and the functional subgroup ESFAC-SubB2 are all connected to the preferred drive system.

[0049] The functional subgroup ESFAC-SubA1 is used to receive the channel-level local trip signal of the functional subgroup PRC-Sub1 of two protection groups. According to the channel-level local trip signal, it generates a dedicated safety facility drive signal with diversity grouping requirements, and then controls the safety actuator through the preferred drive system. The functional subgroup ESFAC-SubA2 is used to receive the channel-level local trip signal of the functional subgroup PRC-Sub2 of two protection groups. According to the channel-level local trip signal, it generates a dedicated safety facility drive signal with diversity grouping requirements, and then controls the safety actuator through the preferred drive system. The functional subgroup ESFAC-SubB1 is used to receive the channel-level local trip signal of the functional subgroup PRC-Sub1 of another two protection groups. According to the channel-level local trip signal, it generates a dedicated safety facility drive signal with diversity grouping requirements, and then controls the safety actuator through the preferred drive system. The functional subgroup ESFAC-SubB2 is used to receive the channel-level local trip signal of the functional subgroup PRC-Sub2 of another two protection groups. According to the channel-level local trip signal, it generates a dedicated safety facility drive signal with diversity grouping requirements, and then controls the safety actuator through the preferred drive system.

[0050] The second functional group includes: functional subgroup ESFAC-SubA3, functional subgroup ESFSC2-A, functional subgroup ESFAC-SubB3, and functional subgroup ESFSC2-B. The functional subgroup ESFAC-SubA3 is connected to the functional subgroups PRC-Sub1 and PRC-Sub2 of two protection groups. The functional subgroup ESFSC2-A is connected to the functional subgroups PRC-Sub1 and PRC-Sub2 of two protection groups. The functional subgroup ESFAC-SubB3 is connected to the functional subgroups PRC-Sub1 and PRC-Sub2 of another two protection groups. The functional subgroup ESFSC2-B is connected to the functional subgroups PRC-Sub1 and PRC-Sub2 of another two protection groups. The functional subgroup ESFAC-SubA3, the functional subgroup ESFSC2-A, the functional subgroup ESFAC-SubB3, and the functional subgroup ESFSC2-B are all connected to the preferred drive system.

[0051] The functional subgroup ESFAC-SubA3 is used to receive the channel-level local trip signals of the functional subgroups PRC-Sub1 and PRC-Sub2 of two protection groups, generate a dedicated safety facility drive signal without diversity grouping requirements based on the channel-level local trip signals, and then control the safety actuator through the preferred drive system.

[0052] The functional subgroup ESFSC2-A is used to receive the channel-level local trip signals of the functional subgroups PRC-Sub1 and PRC-Sub2 of two protection groups, generate a dedicated safety facility drive signal without diversity grouping requirements based on the channel-level local trip signals, and then control the safety actuator through the preferred drive system.

[0053] The functional subgroup ESFAC-SubB3 is used to receive the channel-level local trip signals of the functional subgroups PRC-Sub1 and PRC-Sub2 of another two protection groups, generate a dedicated safety facility drive signal without diversity grouping requirements based on the channel-level local trip signals, and then control the safety actuator through the preferred drive system.

[0054] The functional subgroup ESFSC2-B is used to receive the channel-level local trip signals of the functional subgroups PRC-Sub1 and PRC-Sub2 of another two protection groups, generate a dedicated safety facility drive signal without diversity grouping requirements based on the channel-level local trip signals, and then control the safety actuator through the preferred drive system.

[0055] Exemplarily, the preferred drive system includes: a first priority management module, a second priority management module, a third priority management module, and a fourth priority management module. The functional subgroup ESFAC-SubA1, the functional subgroup ESFAC-SubA2, and the functional subgroup ESFAC-SubA3 are all connected to the first priority management module. The functional subgroup ESFSC2-A is connected to the second priority management module. The functional subgroup ESFAC-SubB1, the functional subgroup ESFAC-SubB2, and the functional subgroup ESFAC-SubB3 are all connected to the third priority management module. The functional subgroup ESFSC2-B is connected to the fourth priority management module.

[0056] The preferred drive system (hereinafter referred to as "PLM") provides an interface for the RPS system and in-situ equipment, mainly for the preference of drive commands of different safety levels, and sends the preferred result to the field drive (or intermediate relay cabinet).

[0057] For drive commands, their priorities are generally from high to low as follows:

[0058] a) Special drive commands from ESFAC-A11 / 12 / 21 / 22 (or ESFAC-B11 / 12 / 21 / 22), and drive commands from ESFAC-AC (or ESFAC-BC);

[0059] b) System-level manual commands from ECP hard logic;

[0060] c) Special drive commands from DAS;

[0061] d) Drive signals from PSAS.

[0062] Refer to Figure 1, the dedicated safety facility drive system includes: safety train A and safety train B. Safety train A includes: functional subgroup ESFAC-SubA1, functional subgroup ESFAC-SubA2, functional subgroup ESFAC-SubA3, functional subgroup ESFSC2-A, the first priority management module, and the second priority management module. Safety train B includes: functional subgroup ESFAC-SubB1, functional subgroup ESFAC-SubB2, functional subgroup ESFAC-SubB3, functional subgroup ESFSC2-B, the third priority management module, and the fourth priority management module. That is, each safety train also contains two diverse functional subgroups SubA1 and SubA2 (SubB1 and SubB2), which perform logical voting and logical operations to generate a signal for driving the dedicated safety facilities. This signal is output to the PLM or the field actuator (safety actuator) through the DO card; each safety train also contains two functional subgroups SubA3 (SubB3) and ESFSC2-A (ESFSC2-B). SubA3 (SubB3) is used to execute the F-SC1 level functions that do not require diversity grouping, and ESFSC2-A (ESFSC2-B) is used to execute the F-SC2 level functions that do not require diversity grouping. The two output control signals to the field actuator through the PLM or the DO card.

[0063] Furthermore, safety train A also includes: a transmission control station and a safety display unit. The safety display unit is located in the area of the operator workstation. The transmission control station is respectively connected to the safety display unit, the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of the two protection groups. The transmission control station is used to monitor the fault status of the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 in the digital protection system of the nuclear power plant, and generate an I&C fault alarm signal when a device fault is detected; transmit various information in the digital protection system of the nuclear power plant to the gateway; receive a part of the PAMS parameters collected by the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2, and transmit them to the safety display unit. The safety display unit is used to display and record the PAMS parameters, protect the system display and lockout reset, reset the reactor trip breaker, conduct the T3 periodic test, and comprehensively alarm the health status of the I&C system.

[0064] The safety display unit (SVDU) is located in the area of the operator workstation. As a safety-level digital human-machine interface, the SVDU mainly completes functions such as the display of PAMS parameters, the reset and (or) locking of protection actions, digital BUP display and control, periodic tests, and the setting of parameter set values. It mainly performs the following functions:

[0065] a) Display and recording of PAMS parameters. The PAMS parameters are collected by the RPC control station and sent to the SVDU through the TU / PI station. According to the typical functions selected for the mock-up, the SVDU is mainly used to display the PAMS parameters of typical type signals such as water level, flow rate, pressure, temperature, concentration, etc.

[0066] b) Display of the protection system and lockout reset. According to the typical functions selected for the mock-up, this part of the SVDU function mainly includes source range manual lockout / reset, intermediate range manual lockout, power range manual lockout, manual lockout of steam line safety injection, manual lockout / reset of pressurizer safety injection, lockout / reset of hot leg loop water level safety injection.

[0067] c) Reset of the reactor trip breaker. According to the typical functions selected for the mock-up, this part of the SVDU function mainly completes the reset test of the reactor trip breakers of protection groups IP and IIIP.

[0068] d) T3 periodic tests: mainly including PLM output lockout test, reactor trip breaker drive test, and signal connection test for output to external systems. According to the typical functions selected for the mock-up, the PLM input lockout test mainly completes the group test of the PLM by the control stations (ESFAC1 / ESFAC2 control stations). Since the signals output from the PLM to the actuators are locked out, the real actions of the actuators will not be triggered; the reactor trip breaker drive test mainly verifies whether the signal circuits between the mock-up protection groups IP and IIIP and the corresponding reactor trip breakers are normal; the signal connection test for output to external systems mainly completes whether the emergency diesel engine start command is normal.

[0069] e) Integrated alarm function for the health status of the I&C system (including mock-up control stations, gateway stations, SVDU safety display stations, and I&C alarm information of the panel cabinets).

[0070] Each protection train contains 2 TU control stations, which perform the following functions:

[0071] a) Monitor or collect the fault status of RPS system equipment and generate necessary I&C fault alarm signals;

[0072] b) Transmit the information of the RPS system to the gateway;

[0073] c) Provide an interface with the SVDU and participate in relevant periodic tests.

[0074] TUA1 and TUB1 are connected to NC-GWA, and TUA2 and TUB2 are connected to NC-GWB.

[0075] The RPC-SubX and ESFAC-SubX control stations send the above signals to the TU control station through two (redundant) multi-node communication networks. The TUA1 / TUB1 control station receives signals from one of the multi-node communication networks, and the TUA2 / TUB2 control station receives signals from the other multi-node communication network. This is used for the necessary signal exchange between protection column A and protection column B.

[0076] The safety column A also includes: a panel interface unit and a gateway. The panel interface unit is respectively connected to the safety display unit, the gateway, the functional subgroups PRC-Sub1 and PRC-Sub2 of the two protection groups. The panel interface unit is used to send another part of the PAMS parameters collected by the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 to the safety display unit and the BUP for display, and send another part of the PAMS parameters to the gateway; display the protection action execution status; send the manual reset and / or locking commands on the safety display unit and the BUP to the protection group or the protection column control station through multi-node communication. The gateway is used to encapsulate another part of the PAMS parameters according to the non-safety-level side communication protocol and send them to the non-safety-level control system.

[0077] Each protection column contains 1 PI control station, which performs the following functions:

[0078] a) The manual reset and (or) locking commands on the SVDU and the BUP are sent to the protection group or the protection column control station through multi-node communication via the PI control station.

[0079] b) The PAMS parameters need to be displayed on the BUP and the SVDU. One part of the PAMS parameters is directly sent to the BUP for display after being allocated by the PIP. For the other part of the PAMS parameters, the RPS system displays them on the BUP and the SVDU through the PI control station: after the control station RPC-SubX in the protection group collects the on-site instrument signals, it sends the signals to the PI control station in the corresponding protection column through multi-node communication (IP and IIIP correspond to PIA, and IIP and IVP correspond to PIB), and each PI control station sends the PAMS parameters sent by the protection group to the SVDU and the BUP for display.

[0080] c) Display the protection action execution status: This status needs to be displayed on the ECP (Emergency Control Panel) and the SVDU. The status signal is generated in the ESFAC-SubX control station of the protection column, sent to the PI control station of this protection column through multi-node communication, and finally displayed. The ECP outputs a reactor trip signal (switching quantity signal) to each protection group through the emergency reactor trip panel and the manual button.

[0081] Each sequence contains a gateway (NC-GWA / NC-GWB), which is the interface between the RPS system and the NC DCS, and realizes data transfer with the NC DCS. The GW parses the communication protocol on the safety level side, obtains the transmitted data content, and encapsulates the data according to the communication protocol on the non-safety level side and sends it to the NC DCS.

[0082] TUA1 / B1 and TUA2 / B2 respectively send information to NC-GWA and NC-GWB simultaneously; both NC-GWA and NC-GWB contain the data of all protection groups and protection columns sent to the NC DCS.

[0083] NC-GWA and NC-GWB are redundant structures with respect to each other, and each contains the data that all protection groups and protection columns need to send out. NC-GWA and NC-GWB are at the NC level, but their functions need to be verified. Among them, the communication between TU and the gateway and between the gateway and the non-safety level system is one-way.

[0084] The structure of safety column B is the same as that of safety column A.

[0085] The present invention proposes an implementation method for the digitalization of the reactor protection system through a safety-level digital control system based on FPGA technology and a multi-redundancy system architecture based on this platform.

[0086] Through comparative analysis, the safety-level digital control system architecture based on FPGA technology has obvious advantages compared with the safety-level digital system architecture based on microprocessor technology, which are mainly reflected in:

[0087] The safety-level digital control system based on FPGA technology can separate auxiliary functions (monitoring, self-diagnosis, etc.) that have little to do with safety functions from safety functions. When the auxiliary functions fail, it will not prevent the execution of safety functions, thereby improving the system independence and safety. According to the system structure calculation, the failure rate of the reactor trip system is ≤1.0E -7 , and the failure rate of the dedicated safety facility drive system is ≤1.0E -5 , and the system availability is ≥99.99%.

[0088] The safety-level digital control system based on FPGA technology can execute the required functions in parallel, at high speed, and independently, meeting the strict requirements of the safety level for response time;

[0089] The safety-level digital control system based on FPGA technology executes "hard logic". Since it does not use an operating system, the system has stronger stability and fundamentally simplifies the design of the I&C system;

[0090] The safety-class digital control system based on FPGA technology can ensure the reliability design and safety integrity level of the system throughout its life cycle. It can detect faults through high-coverage self-diagnosis technology and trigger fault handling and alarm mechanisms to avoid fault spread and ensure that the safety functions of the system are not lost in the fault state. It can improve the reliability, availability, and safety of the system and reduce the system usage and maintenance costs;

[0091] For the system architecture, considering the influencing factors such as system reliability, safety, and cost, it is made more suitable for the nuclear power safety-class digital control system.

[0092] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.

[0093] In this article, specific examples are used to elaborate on the principles and implementation methods of the present invention. The descriptions of the above embodiments are only used to help understand the method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A digital protection system for nuclear power plants based on FPGA, characterized in that, Comprising: Emergency shutdown system and engineered safety feature actuation system; Both the emergency shutdown system and the engineered safety feature actuation system adopt a dual-FPGA architecture. One FPGA architecture is used to execute safety functions, and the other FPGA architecture is used to execute functions other than safety functions; The emergency shutdown system is respectively connected to the engineered safety feature actuation system and the shutdown breaker; the emergency shutdown system is used to collect reactor safety parameters, and generate channel-level local trip signals and emergency shutdown signals according to the collected reactor safety parameters, send the channel-level local trip signals to the engineered safety feature actuation system, and send the emergency shutdown signals to the shutdown breaker; The emergency shutdown system includes: 4 protection groups; The engineered safety feature actuation system includes a first functional group, a second functional group and a preferred actuation system; The first functional group is respectively connected to the emergency shutdown system and the preferred actuation system. The first functional group is used to generate engineered safety feature actuation signals with diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred actuation system; the first functional group includes: functional subgroup ESFAC-SubA1 and functional subgroup ESFAC-SubA2; the functional subgroup ESFAC-SubA1 is used to receive the channel-level local trip signals of the functional subgroup PRC-Sub1 of two protection groups, and generate engineered safety feature actuation signals with diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred actuation system; the functional subgroup ESFAC-SubA2 is used to receive the channel-level local trip signals of the functional subgroup PRC-Sub2 of two protection groups, and generate engineered safety feature actuation signals with diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred actuation system; The second functional group is respectively connected to the emergency shutdown system and the preferred actuation system. The second functional group is used to generate engineered safety feature actuation signals without diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred actuation system; the second functional group includes: functional subgroup ESFAC-SubA3 and functional subgroup ESFSC2-A; the functional subgroup ESFAC-SubA3 is used to receive the channel-level local trip signals of the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of two protection groups, and generate engineered safety feature actuation signals without diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred actuation system; the functional subgroup ESFSC2-A is used to receive the channel-level local trip signals of the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of two protection groups, and generate engineered safety feature actuation signals without diversity grouping requirements according to the channel-level local trip signals, and then control the safety actuator through the preferred actuation system; The preferred drive system includes: a first priority management module and a second priority management module; the functional subgroup ESFAC-SubA1, the functional subgroup ESFAC-SubA2, and the functional subgroup ESFAC-SubA3 are all connected to the first priority management module; the functional subgroup ESFSC2-A is connected to the second priority management module; The dedicated safety facility drive system includes: safety column A and safety column B; each protection column contains 1 PI control station, which performs the following functions: The manual reset and / or locking commands on the SVDU and BUP are sent to the protection group or protection column control station through the PI control station by multi-node communication; Each PI control station sends the PAMS parameters sent by the protection group to the SVDU and BUP for display; Display of the protection action execution status.

2. The digital protection system for nuclear power plants based on FPGA according to claim 1, characterized in that, The 4 protection groups are all connected to the dedicated safety facility drive system; the 4 protection groups are connected to each other; Each protection group is used to collect reactor safety parameters, generate local trip signals according to the collected reactor safety parameters, receive the local trip signals of the other 3 protection groups, perform logical voting on all the local trip signals, and generate the emergency shutdown signal and channel-level local trip signal of this channel.

3. The digital protection system for nuclear power plants based on FPGA according to claim 2, characterized in that, The protection group includes: a protection signal preprocessing unit PIP, a functional subgroup PRC-Sub1, and a functional subgroup PRC-Sub2; The protection signal preprocessing unit PIP is respectively connected to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2; the protection signal preprocessing unit PIP is used to collect reactor safety parameters, condition the reactor safety parameters into standard signals, and then isolate and distribute them to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2; The functional subgroup PRC-Sub1 is respectively connected to the dedicated safety facility drive system and the shutdown breaker. The functional subgroup PRC-Sub1 is used to generate local trip signals according to the standard signals, receive the local trip signals of the other 3 protection groups, perform logical voting on all the local trip signals, generate the emergency shutdown signal and channel-level local trip signal of this channel, send the emergency shutdown signal of this channel to the shutdown breaker, and send the channel-level local trip signal to the dedicated safety facility drive system; The functional subgroup PRC-Sub2 is respectively connected to the dedicated safety facility drive system and the shutdown breaker. The functional subgroup PRC-Sub2 is used to generate local trip signals according to the standard signals, receive the local trip signals of the other 3 protection groups, perform logical voting on all the local trip signals, generate the emergency shutdown signal and channel-level local trip signal of this channel, send the emergency shutdown signal of this channel to the shutdown breaker, and send the channel-level local trip signal to the dedicated safety facility drive system.

4. The digital protection system for nuclear power plants based on FPGA according to claim 3, wherein The first functional group further includes: a functional subgroup ESFAC-SubB1 and a functional subgroup ESFAC-SubB2; The functional subgroup ESFAC-SubA1 is connected to the functional subgroup PRC-Sub1 of two protection groups, and the functional subgroup ESFAC-SubA2 is connected to the functional subgroup PRC-Sub2 of two protection groups; The functional subgroup ESFAC-SubB1 is connected to the functional subgroup PRC-Sub1 of another two protection groups, and the functional subgroup ESFAC-SubB2 is connected to the functional subgroup PRC-Sub2 of another two protection groups; The functional subgroup ESFAC-SubA1, the functional subgroup ESFAC-SubA2, the functional subgroup ESFAC-SubB1, and the functional subgroup ESFAC-SubB2 are all connected to the preferred drive system; The functional subgroup ESFAC-SubB1 is used to receive the channel-level local trip signal of the functional subgroup PRC-Sub1 of another two protection groups. According to the channel-level local trip signal, it generates a dedicated safety facility drive signal with diversity grouping requirements, and then controls the safety actuator through the preferred drive system; The functional subgroup ESFAC-SubB2 is used to receive the channel-level local trip signal of the functional subgroup PRC-Sub2 of another two protection groups. According to the channel-level local trip signal, it generates a dedicated safety facility drive signal with diversity grouping requirements, and then controls the safety actuator through the preferred drive system.

5. The digital protection system for nuclear power plants based on FPGA according to claim 4, wherein, The second functional group further includes: the functional subgroup ESFAC-SubB3 and the functional subgroup ESFSC2-B; The functional subgroup ESFAC-SubA3 is connected to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of two protection groups, and the functional subgroup ESFSC2-A is connected to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of two protection groups; The functional subgroup ESFAC-SubB3 is connected to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of another two protection groups, and the functional subgroup ESFSC2-B is connected to the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of another two protection groups; The functional subgroup ESFAC-SubA3, the functional subgroup ESFSC2-A, the functional subgroup ESFAC-SubB3, and the functional subgroup ESFSC2-B are all connected to the preferred drive system; The functional subgroup ESFAC-SubB3 is used to receive the channel-level local trip signals of the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of another two protection groups. According to the channel-level local trip signals, it generates a dedicated safety facility drive signal without diversity grouping requirements, and then controls the safety actuator through the preferred drive system; The functional subgroup ESFSC2-B is used to receive the channel-level local trip signals of the functional subgroup PRC-Sub1 and the functional subgroup PRC-Sub2 of another two protection groups. According to the channel-level local trip signals, it generates a dedicated safety facility drive signal without diversity grouping requirements, and then controls the safety actuator through the preferred drive system.

6. The digital protection system for nuclear power plants based on FPGA according to claim 5, characterized in that The preferred drive system further includes: a third priority management module and a fourth priority management module; The functional subgroups ESFAC-SubB1, ESFAC-SubB2, and ESFAC-SubB3 are all connected to the third priority management module; The functional subgroup ESFSC2-B is connected to the fourth priority management module.

7. The digital protection system for nuclear power plants based on FPGA according to claim 6, characterized in that Safety column A includes: functional subgroups ESFAC-SubA1, ESFAC-SubA2, ESFAC-SubA3, functional subgroup ESFSC2-A, a first priority management module, and a second priority management module; Safety column B includes: functional subgroups ESFAC-SubB1, ESFAC-SubB2, ESFAC-SubB3, functional subgroup ESFSC2-B, a third priority management module, and a fourth priority management module.

8. The digital protection system for nuclear power plants based on FPGA according to claim 7, characterized in that The safety column A further includes: a transmission control station and a safety display unit; The safety display unit is located in the area of the operator workstation; The transmission control station is respectively connected to the safety display unit, the functional subgroups PRC-Sub1 and PRC-Sub2 of the two protection groups; The transmission control station is used to monitor the fault status of the functional subgroups PRC-Sub1 and PRC-Sub2 in the digital protection system of the nuclear power plant, and generate an I&C fault alarm signal when a device fault is detected; transmit various information in the digital protection system of the nuclear power plant to the gateway; receive a part of the PAMS parameters collected by the functional subgroups PRC-Sub1 and PRC-Sub2, and transmit them to the safety display unit; The safety display unit is used to display and record the PAMS parameters, display and lock reset of the protection system, reset the reactor trip breaker, conduct the T3 periodic test, and comprehensively alarm the health status of the I&C system.

9. The digital protection system for nuclear power plants based on FPGA according to claim 8, characterized in that The safety column A further includes: a console interface unit and a gateway; The console interface unit is respectively connected to the safety display unit, the gateway, the functional subgroups PRC-Sub1 and PRC-Sub2 of the two protection groups; The console interface unit is used to send another part of the PAMS parameters collected by the functional subgroups PRC-Sub1 and PRC-Sub2 to the safety display unit and the BUP for display, and send the other part of the PAMS parameters to the gateway; display the protection action execution status; send the manual reset and / or lock commands on the safety display unit and the BUP to the protection group or the protection column control station through multi-node communication; The gateway is used to encapsulate the other part of the PAMS parameters according to the non-safety-level side communication protocol and send them to the non-safety-level control system.

10. The digital protection system for nuclear power plants based on FPGA according to claim 9, characterized in that, The safety column B has the same structure as that included in the safety column A.

Citation Information

Patent Citations

  • Security level DCS dual-FPGA diversity architecture

    CN106527295A

  • Optimized digital reactor protection system

    CN110444305A