A method and system for robustness analysis of an emergency operating procedure

By constructing a robustness analysis method for accident operation procedures, the reliability of information is assessed and optimized, solving the problem of inappropriate actions caused by information loss or failure in existing technologies. This achieves full-range robustness analysis of nuclear power plant accident operation procedures, thereby improving the safety and stability of nuclear power plants.

CN117012424BActive Publication Date: 2026-05-26CHINA NUCLEAR POWER DESIGN COMPANY +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA NUCLEAR POWER DESIGN COMPANY
Filing Date
2023-07-21
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing technologies cannot achieve robustness analysis of the entire range of nuclear power plant accident operation procedures information, which may lead to operators performing inappropriate actions when information is lost or invalid, thus failing to improve the robustness of nuclear power plant accident operation procedures.

Method used

A robustness analysis method for accident operation procedures is constructed. By acquiring all information, judging its reliability, performing secondary analysis, and optimizing the procedures, the method ensures that information is available in the event of loss of a single power source, accident conditions, and before the accident occurs, thus avoiding inappropriate consequences caused by information failure.

Benefits of technology

It enables a full-range robustness analysis of accident operation procedures, ensuring the reliability and fault tolerance of information and improving the safety and stability of nuclear power plant reactors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117012424B_ABST
    Figure CN117012424B_ABST
Patent Text Reader

Abstract

This invention relates to a robustness analysis method and system for accident operation procedures, comprising the following steps: acquiring all information used by the accident operation procedures in handling accident conditions; performing the following operations on each piece of information: determining whether the information to be analyzed is reliable; if reliable, determining that the information to be analyzed is robust; if unreliable, performing a secondary analysis on the information to be analyzed. This invention achieves full-range robustness analysis of the accident operation procedures by extracting and robustly analyzing all information used by the accident operation procedures in handling accident conditions, avoiding problems caused by information loss or failure, ensuring the fault tolerance of the reliability of the accident operation procedures, and further improving the safety and stability of nuclear power plant reactors.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of nuclear power plant accident operation procedures, and more specifically, to a robustness analysis method and system for accident operation procedures. Background Technology

[0002] Robustness analysis of accident operation procedure information primarily involves analyzing the hypothetical consequences of information failure in the designed accident operation procedures. This ensures that operators will not perform inappropriate actions or be guided to inappropriate accident handling strategies due to information failure. In reality, given the sheer volume of information in accident operation procedures, which makes analysis difficult, it is often only possible to analyze information related to the guidance of the accident operation procedures and some safety-related information. A comprehensive analysis and verification of the robustness of accident operation procedure information cannot be achieved.

[0003] The patent "An Automatic Evaluation System and Method for the Implementation of Nuclear Power Plant Operating Procedures" discloses an automatic evaluation system and method for the implementation of nuclear power plant operating procedures. This system and method can, to some extent, avoid omissions in operational steps or errors, reducing the workload of operators. However, this solution only confirms and evaluates the operator's actions, ensuring that the operator accurately executes the operational steps of the nuclear power plant operating procedures based on unit status information; it does not improve the robustness of nuclear power plant accident operating procedures. In the event of information loss or failure, this solution does not reduce the risk of operators adopting inappropriate accident handling strategies or executing unsuitable control actions. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a robustness analysis method and system for accident operation procedures.

[0005] The technical solution adopted by this invention to solve its technical problem is: to construct a robustness analysis method for accident operation procedures, including the following steps:

[0006] Obtain all information used by the accident operation procedures in handling accident conditions;

[0007] Perform the following operations on each of the aforementioned pieces of information:

[0008] Determine whether the information to be analyzed is reliable;

[0009] If reliable, the information to be analyzed is determined to be robust;

[0010] If the information is unreliable, a second analysis will be performed on the information to be analyzed.

[0011] In the robustness analysis method for accident operation procedures described in this invention, the step of determining whether the information to be analyzed is reliable includes:

[0012] Determine whether the information to be analyzed meets the preset conditions;

[0013] If the preset conditions are met, the information to be analyzed is determined to be reliable;

[0014] If the preset conditions are not met, the information to be analyzed is determined to be unreliable;

[0015] The preset conditions are: usable when a single power source is lost, usable during accident conditions, and usable before an accident occurs.

[0016] In the robustness analysis method for accident operation procedures described in this invention, the method further includes: determining whether the information to be analyzed was available before the accident occurred based on the following steps:

[0017] Determine whether the information to be analyzed is information used in the initial state of the unit before the accident occurred;

[0018] If so, it is determined that the information to be analyzed was available before the accident occurred;

[0019] If not, determine whether the availability and performance of the information to be analyzed meet the requirements of the technical specifications; the technical specifications include: technical specifications and / or technical requirements manual;

[0020] If the availability and performance of the information to be analyzed do not meet the requirements of the technical specifications, then the information to be analyzed is determined to be unavailable before the accident occurred.

[0021] If the availability and performance of the information to be analyzed meet the requirements of the technical specifications, then determine whether the information to be analyzed has a corrective action under the state corresponding to the technical specifications;

[0022] If a corrective action is taken, it is determined that the information to be analyzed was available before the accident occurred;

[0023] If no corrective action is taken, the information to be analyzed is determined to have been unavailable before the accident occurred.

[0024] In the robustness analysis method for accident operation procedures described in this invention, the secondary analysis of the information to be analyzed includes:

[0025] Determine whether the loss or invalidation of the information to be analyzed would lead to a predetermined consequence;

[0026] If not, then the information to be analyzed is determined to be robust;

[0027] If so, then perform procedural analysis on the information to be analyzed.

[0028] In the robustness analysis method for accident operation procedures described in this invention, the procedure analysis of the information to be analyzed includes:

[0029] Determine whether the information to be analyzed requires optimization of the accident operation procedures;

[0030] If it is necessary to optimize the accident operation procedure, the information to be analyzed is determined to be non-robust and the accident operation procedure corresponding to the information to be analyzed is optimized.

[0031] If there is no need to optimize the accident operation procedure, then determine whether the loss or failure of the information to be analyzed would lead to serious consequences;

[0032] If it leads to serious consequences, the information to be analyzed is determined to be non-robust and operational management is performed on the information to be analyzed.

[0033] If it will not lead to serious consequences, the information to be analyzed is determined to be non-robust and no management is performed on the information to be analyzed.

[0034] In the robustness analysis method for accident operation procedures described in this invention, determining whether the loss or failure of the information to be analyzed would lead to a preset consequence includes:

[0035] Determine whether the loss or failure of the information to be analyzed will lead to any of the following: a preset operation, a redirection to another accident condition procedure, a redirection to a strategy with a different target priority, an impact on the integrity of the containment, or a preset action of the dedicated system and its supporting systems.

[0036] If so, it is determined that the loss or invalidation of the information to be analyzed will lead to a preset consequence.

[0037] In the robustness analysis method for accident operation procedures described in this invention, determining whether the loss or failure of the information to be analyzed would lead to serious consequences includes:

[0038] Determine whether the loss or failure of the information to be analyzed would lead to any one of the following: increased risk of core meltdown, damage to pressure vessel integrity, damage to reactor coolant system integrity, or severe damage to containment integrity.

[0039] If so, it is determined that the loss or invalidation of the information to be analyzed would lead to serious consequences.

[0040] In the robustness analysis method for accident operation procedures described in this invention, obtaining all information used by the accident operation procedures in handling accident conditions includes:

[0041] Build an information database;

[0042] The information in the database is transformed to obtain digitized accident operation procedures;

[0043] The system is initialized based on preset accident conditions. After initialization, the preset accident conditions are processed according to the digitized accident operation procedures. All information used during the accident condition processing is generated and saved.

[0044] This invention also provides a robustness analysis system for accident operation procedures, comprising:

[0045] The information acquisition unit is used to acquire all information used by the accident operation procedures in handling accident conditions.

[0046] A robustness diagnostic module, which performs the following operations on each piece of information:

[0047] Determine whether the information to be analyzed is reliable;

[0048] If reliable, the information to be analyzed is determined to be robust;

[0049] If the information is unreliable, a second analysis will be performed on the information to be analyzed.

[0050] The robustness analysis system for accident operation procedures described in this invention also includes:

[0051] An information database is used to store information on accident operation procedures and related data.

[0052] An accident operation procedure compilation module is used to convert the information of the accident operation procedures in the information database into information symbols and generate digital accident operation procedures.

[0053] The accident operation procedure execution module is used to initialize based on preset accident conditions, and after the initialization is completed, to process the preset accident conditions based on the digitized accident operation procedure, and to generate and save all the information used during the accident condition processing.

[0054] The robustness analysis method and system for accident operation procedures of the present invention have the following beneficial effects: It includes the following steps: acquiring all information used by the accident operation procedures in handling accident conditions; performing the following operations on each piece of information: determining whether the information to be analyzed is reliable; if reliable, determining that the information to be analyzed is robust; if unreliable, performing a secondary analysis on the information to be analyzed. By extracting and robustly analyzing all information used by the accident operation procedures in handling accident conditions, the present invention achieves full-range robustness analysis of the accident operation procedures, avoiding problems caused by information loss or failure, ensuring the fault tolerance of the reliability of the accident operation procedures, and further improving the safety and stability of nuclear power plant reactors. Attached Figure Description

[0055] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings:

[0056] Figure 1 This is a flowchart illustrating the robustness analysis method for accident operation procedures provided by the present invention.

[0057] Figure 2 This is a flowchart of the information reliability analysis provided by the present invention;

[0058] Figure 3 This invention provides an analysis flowchart to determine whether the information provided is available before an accident occurs.

[0059] Figure 4 This is a flowchart illustrating the robustness analysis of the accident operation procedure provided by the present invention.

[0060] Figure 5 It is a logical relationship diagram of complex information and its constituent information;

[0061] Figure 6 This is a logical structure diagram of the robustness analysis system for accident operation procedures provided by the present invention. Detailed Implementation

[0062] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0063] Figure 1 The flowchart illustrates the robustness analysis method for accident operation procedures provided by this invention. Specifically, as shown... Figure 1 As shown, the robustness analysis method for this accident operation procedure includes the following steps:

[0064] Step S10: Obtain all information used by the accident operation procedure in handling the accident situation, and perform the operations of steps S20 to S40 for each piece of information obtained.

[0065] In this embodiment, obtaining all the information used by the accident operation procedure in handling accident conditions includes: constructing an information database 11; converting the information in the information database 11 to obtain a digitized accident operation procedure; initializing based on a preset accident condition, and after the initialization is completed, handling the preset accident condition based on the digitized accident operation procedure, and generating and saving all the information used in handling the accident condition.

[0066] Specifically, the information used in the accident operation procedures can be organized according to the requirements of digital procedure compilation and robustness analysis, and the attributes of various types of information can be completed. For simple information, a mapping relationship needs to be established: information-simulation model information-sensor-safety classification-environmental assessment conditions, or a mapping relationship needs to be established: information-simulation model information-manually assigned values, and then stored in the information database 11. For complex information, it needs to be decomposed into simple information and logical operation relationships, and the mapping relationships of simple information and logical operation relationships need to be combined to form the mapping relationships of complex information.

[0067] For example, simple information is: medium-pressure safety injection system flow (Q MHSI), and its mapping relationship is as follows:

[0068]

[0069] The complex message is: "Column A MHSI is running." The logical relationship between this complex message and its constituent messages "QMHSI" and "MHSIp" is as follows: Figure 5 As shown. The simple functional mapping relationship of the complex information-based pressure injection system during operation is as follows:

[0070]

[0071] In this embodiment, the safety classification includes four categories: Functional Safety Category 1 (FC1), Functional Safety Category 2 (FC2), Functional Safety Category 3 (FC3), and Non-Safe (NC). The safety classification refers to the fact that the safety of a nuclear power plant relies on the performance of safety functions by its structures, systems, and components. The purpose of the classification is to ensure that the design, manufacture, construction, commissioning, and operation of items meet appropriate requirements to ensure adequate quality assurance under all anticipated operating conditions and to ensure the realization of safety functions.

[0072] In this embodiment, the accident operation procedure is a set of procedural documents designed by the nuclear power plant to respond to design basis accidents and design extended operating conditions, which guides nuclear power plant operators to perform necessary accident operations and is an important component of the nuclear power plant's defense-in-depth concept.

[0073] Robustness refers to the characteristic of a control system to maintain certain other performances under certain parameter perturbations (structure, size). In this article, it refers to the characteristic that the operator's operation will not be interrupted or misled when accidental operating procedure information is lost or becomes invalid.

[0074] Step S20: Determine whether the information to be analyzed is reliable.

[0075] Specifically, in this embodiment, determining whether the information to be analyzed is reliable includes: determining whether the information to be analyzed meets preset conditions; if the preset conditions are met, the information to be analyzed is determined to be reliable; if the preset conditions are not met, the information to be analyzed is determined to be unreliable. The preset conditions are: usable in the event of a single power supply failure, usable under accident conditions, and usable before the accident occurs.

[0076] Specifically, such as Figure 2 As shown, information is considered reliable if it simultaneously possesses the following characteristics: it is available in the event of a single power source loss, it is available under accident conditions, and it was available before the accident occurred. Conversely, if any one or more of these three characteristics are not met, the information is unreliable.

[0077] In this embodiment, the information is usable even in the event of a power loss, meaning that the sensors that make up the information are powered by a redundant power supply. For example, the pressure information (PSG) of the steam generator is composed of four sensors VVP 1811 / 1812 / 1813 / 1814MP of the main steam system (VVP). Each of the four sensors is powered by a different power supply, so the PSG information is still available even in the event of a single power failure.

[0078] In this embodiment, the availability of information under accident conditions is related to the environmental assessment condition classification of the sensors. This classification specifies the relevant environmental conditions and uptime requirements for information reliability. For example, the environmental condition classification for the four sensors providing pressure information from the steam generator is C. BSX (It can operate for a long time under conditions of degraded thermal-hydraulic conditions). Therefore, it has a qualified rating, meaning it can be used under accident conditions.

[0079] In this embodiment, whether the information was available before the incident can be determined based on... Figure 3 The method is used to make the judgment. Specifically, such as... Figure 3As shown, determining whether the information to be analyzed was available before the accident includes: determining whether the information to be analyzed was used in the initial state of the unit before the accident; if so, the information to be analyzed was available before the accident; if not, determining whether the availability and performance of the information to be analyzed met the requirements of the technical specifications; the technical specifications include: technical specifications and / or technical requirements manuals; if the availability and performance of the information to be analyzed did not meet the requirements of the technical specifications, the information to be analyzed was deemed unavailable before the accident; if the availability and performance of the information to be analyzed met the requirements of the technical specifications, determining whether the information to be analyzed had corrective actions in the state corresponding to the technical specifications; if corrective actions were performed, the information to be analyzed was deemed available before the accident; if no corrective actions were performed, the information to be analyzed was deemed unavailable before the accident.

[0080] Specifically, such as Figure 3 As shown, information is considered available prior to an accident if it meets any of the following conditions: the information is used in the initial state of the unit prior to the accident; or, the availability and performance of the information meet the requirements of the corresponding state in the technical specifications and / or technical requirements manual, and there is a corrective action in the corresponding state in the technical specifications and / or technical requirements manual.

[0081] Step S30: If reliable, the information to be analyzed is determined to be robust.

[0082] Step S40: If unreliable, perform a second analysis on the information to be analyzed.

[0083] In this embodiment, the secondary analysis of the information to be analyzed includes: determining whether the loss or failure of the information to be analyzed would lead to a preset consequence (i.e., an inappropriate consequence); if not, then determining that the information to be analyzed is robust; if so, then performing a procedure analysis on the information to be analyzed.

[0084] The process analysis of the information to be analyzed includes: determining whether the information to be analyzed needs to optimize the accident operation procedures; if optimization is required, then the information to be analyzed is determined to be unrobust and the corresponding accident operation procedures are optimized; if optimization is not required, then it is determined whether the loss or failure of the information to be analyzed would lead to serious consequences; if serious consequences would lead to serious consequences, then the information to be analyzed is determined to be unrobust and operational management is implemented for the information to be analyzed; if serious consequences would not lead to serious consequences, then the information to be analyzed is determined to be unrobust and no management is implemented for the information to be analyzed.

[0085] Furthermore, in this embodiment, determining whether the loss or failure of the information to be analyzed will lead to a preset consequence includes: determining whether the loss or failure of the information to be analyzed will lead to any one of the following: a preset operation (i.e., an inappropriate operation), a redirection to another accident condition procedure, a redirection to a strategy with a different target priority, an impact on the integrity of the containment, or a preset action (i.e., an inappropriate action) of the dedicated system and its supporting systems; if so, it is determined that the loss or failure of the information to be analyzed will lead to a preset consequence.

[0086] Specifically, in this embodiment, inappropriate operation, such as mistakenly activating the safety injection system in the dedicated system to inject water into the primary circuit when there is no loss of primary coolant, may cause the dedicated system and its supporting systems to perform preset actions, such as starting the emergency diesel engine to supply power to the emergency bus when there is no loss of external power.

[0087] This can lead to procedures for other accident conditions, such as incorrectly directing the emergency operation procedure for controlling reactivity when reactivity has not degraded. It can also lead to strategies with different objective priorities, such as prioritizing the recovery water system and waste heat removal before implementing reactivity control when reactivity has degraded but other state parameters have not.

[0088] This can affect the integrity of the containment, for example, by mistakenly opening an unnecessary containment isolation valve when a containment isolation signal is available, or by bypassing containment cooling and depressurization operations when the containment temperature or pressure is high.

[0089] In this embodiment, determining whether the loss or failure of the information to be analyzed will lead to serious consequences includes: determining whether the loss or failure of the information to be analyzed will lead to any one of the following: increased risk of core meltdown, damage to the integrity of the pressure vessel, damage to the integrity of the reactor coolant system, or serious damage to the integrity of the containment; if so, it is determined that the loss or failure of the information to be analyzed will lead to serious consequences.

[0090] In this embodiment, the increased risk of core meltdown means that the core frequency (CDF) caused by the accident sequence of information failure calculated using probabilistic safety analysis does not increase significantly.

[0091] Pressure vessel integrity failure: For example, the state point of the primary coolant pressure-temperature curve exceeds the pressure vessel brittle fracture curve.

[0092] Disruption of reactor coolant system integrity: For example, the reactor coolant system boundary valves are opened incorrectly; or the primary loop pressure exceeds the reactor coolant system design pressure.

[0093] The integrity of the containment is severely compromised: causing the temperature or pressure of the containment to exceed design limits under accident conditions.

[0094] Specifically, such as Figure 4 As shown, when performing robustness analysis on the information to be analyzed, the first step is to assess the reliability of the information. If the information is reliable, it is determined to be robust. Reliable information meets extremely high reliability standards and the single-failure criterion in all stages of information acquisition, transmission, and logical processing (i.e., a combination of devices that meets the single-failure criterion can maintain its intended safety functions even if any component experiences a single random failure). Robustness analysis only assumes a single failure (a failure that prevents a component from performing its intended safety functions, and all secondary failures originating from this single failure are considered integral parts of it). Therefore, within the scope of robustness analysis, reliable information will not be lost or invalidated; that is, the robustness analysis result is that the information is robust.

[0095] Secondly, if the information to be analyzed is determined to be unreliable, then it is determined whether the loss or failure of the information would lead to inappropriate consequences (i.e., the pre-set consequences). If the loss or failure of the information would not lead to inappropriate consequences, then the information to be analyzed can be considered robust. Although this information does not meet the reliability standard, the consequences of its failure are controllable and will not have a serious negative impact on unit safety, equipment operation, and accident handling strategies. For this type of information, the robustness analysis result is also robust.

[0096] After the above analysis, if it is determined that the information to be analyzed lacks robustness, further analysis can be performed on the information. Specifically:

[0097] Determine whether the lack of robustness in the information requires optimization of the incident operation procedure. If optimization is needed, then optimize the incident operation procedure. If optimization is not needed, determine whether the loss or failure of the lack of robustness in the information would lead to serious consequences. If serious consequences would lead to serious consequences, then determine that the information to be analyzed is not robust and implement operational management for the information to be analyzed; otherwise, if serious consequences would not lead to serious consequences, then determine that the information to be analyzed is not robust and do not implement management for the information to be analyzed.

[0098] Based on the above analysis, the following types of information can be obtained after the robustness analysis of the embodiments of the present invention:

[0099] a. Robust information.

[0100] For reliable information, it meets extremely high reliability standards and single-failure criteria in all stages, including information acquisition, transmission, and logical processing. Robustness analysis only assumes a single failure; therefore, within the scope of robustness analysis, reliable information will not be lost or invalidated, meaning its robustness analysis result is robust.

[0101] If the loss or failure of information does not lead to inappropriate consequences, then such information can be considered robust. Although it does not meet the reliability standard, the consequences of its failure are controllable and will not have a serious negative impact on unit safety, equipment operation and accident handling strategies. For such information, the robustness analysis results are also robust.

[0102] b. Information that lacks robustness and requires optimization of procedures.

[0103] For information that lacks robustness, its loss or failure will not lead to inappropriate consequences, but inappropriate consequences can be avoided by optimizing the accident operation procedures without making the optimized accident operation procedures too complicated. In this case, the robustness analysis result of such information is that it lacks robustness and the procedures need to be optimized.

[0104] c. Information that lacks robustness and requires operational management.

[0105] If the loss or invalidation of information would lead to serious consequences, and the optimized accident operation procedures are overly complex, then optimization of the accident operation procedures is not the optimal approach; instead, nuclear power plant operation and management methods should be used. Robustness analysis for this type of information indicates a lack of robustness and the need for operation and management. Operation and management can prevent serious consequences through the following measures:

[0106] - Use management methods other than accident operation procedures (emergency response organizations, etc.);

[0107] - Replace the equipment.

[0108] d. Information that is not robust and does not require management.

[0109] If the optimized procedures are excessively complex, and the failure of such information would lead to inappropriate but not serious consequences, it indicates that the current procedures are not optimal for accident management, but are effective nonetheless. Based on existing engineering experience, there is no need to incur significant costs to modify the design for this type of information. The robustness analysis for this type of information indicates that it is not robust but does not require management.

[0110] like Figure 6 As shown, this invention provides a robustness analysis system for accident operation procedures. This robustness analysis system for accident operation procedures includes:

[0111] The information acquisition unit 14 is used to acquire all the information used by the accident operation procedure when handling accident conditions.

[0112] The robustness diagnosis module 15 is used to perform the following operations on each piece of information: determine whether the information to be analyzed is reliable; if it is reliable, determine that the information to be analyzed is robust; if it is unreliable, perform a second analysis on the information to be analyzed.

[0113] Furthermore, such as Figure 6 As shown, the robustness analysis system for this accident operation procedure also includes:

[0114] Information database 11 is used to store information on accident operation procedures and related data.

[0115] The accident operation procedure compilation module 12 is used to convert the information of the accident operation procedure in the information database 11 into information symbols and generate digital accident operation procedures.

[0116] Specifically, in this embodiment, the accident operation procedure compilation module 12 can use an existing or newly developed accident operation compilation platform to realize the information in the information database 11 as a graphic symbol, and digitally edit, combine, and connect the graphic information according to the content of the paper accident operation procedure, thereby realizing the digitization of the accident operation procedure, that is, generating a digital accident operation procedure.

[0117] The accident operation procedure execution module 13 is used to initialize based on preset accident conditions, and after the initialization is completed, to process the preset accident conditions based on the digital accident operation procedure, and to generate and save all the information used during the accident condition processing.

[0118] Specifically, in this embodiment, the accident operation procedure execution module 13 can set a preset accident operation condition list based on the nuclear power plant design baseline operating condition and design extended operating condition list (wherein the preset accident operation condition list includes simulation model information such as initial conditions and initiating events for each operating condition), and select each preset accident operation condition in the preset accident operation condition list for initialization during initialization (wherein initialization can be performed through the nuclear power plant's simulation simulator). After completing the initialization of each preset accident operation condition, the corresponding accident operation procedure can be used to bring the accident to a safe shutdown state through a preset safety analysis action sequence or manual accident intervention. During the process of handling the accident operation condition using the accident operation procedure, the processing path and all information used during the handling of the accident operation condition are generated and saved according to parameter changes and operation content, and all information used and corresponding procedure execution operations are stored.

[0119] It should be noted that the specific coordination and operation processes between the units in the robustness analysis system of the accident operation procedure here can be referred to the robustness analysis method of the accident operation procedure mentioned above, and will not be repeated here.

[0120] This invention establishes a robustness method and system for accident operation procedures, defining a set of methods and theories for robustness analysis of nuclear power plants, and logicalizing and digitizing the robustness analysis process. A digital database of accident operation procedures is established using a digital platform. Based on this database and a digital operation procedure compilation platform, digital accident operation procedures are compiled. By combining a simulator with the digital accident operation procedures, automatic execution and path saving functions of the accident operation procedures are achieved under accident conditions. The robustness diagnostic module 15 extracts and performs robustness analysis on all path information. This completes a full-range robustness analysis of the accident operation procedures, ensuring their reliability and fault tolerance, and further improving the safety and stability of the nuclear power plant reactor.

[0121] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0122] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0123] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0124] The above embodiments are only for illustrating the technical concept and features of the present invention, and are intended to enable those skilled in the art to understand the content of the present invention and implement it accordingly. They do not limit the scope of protection of the present invention. All equivalent changes and modifications made within the scope of the claims of the present invention should fall within the scope of the claims of the present invention.

Claims

1. A robustness analysis method for accident operation procedures, characterized in that, Includes the following steps: Obtain all information used by the accident operation procedures in handling accident conditions, including: Construct an information database; transform the information in the information database to obtain digitized accident operation procedures; initialize based on preset accident conditions, and after initialization, process the preset accident conditions based on the digitized accident operation procedures, and generate and save all information used during the accident condition processing. Perform the following operations on each of the aforementioned pieces of information: Determining whether the information to be analyzed is reliable includes: Determine whether the information to be analyzed meets preset conditions, which are: available when a single power source is lost, available during an accident, and available before the accident occurs; If the preset conditions are met, the information to be analyzed is determined to be robust; If the preset conditions are not met, a secondary analysis is performed on the information to be analyzed. The secondary analysis is as follows: it is determined whether the loss or failure of the information to be analyzed will lead to a preset consequence; if not, it is determined that the information to be analyzed has robustness; if so, a procedural analysis is performed on the information to be analyzed.

2. The robustness analysis method for accident operation procedures according to claim 1, characterized in that, The method further includes: determining whether the information to be analyzed was available before the accident occurred based on the following steps: Determine whether the information to be analyzed is information used in the initial state of the unit before the accident occurred; If so, it is determined that the information to be analyzed was available before the accident occurred; If not, determine whether the availability and performance of the information to be analyzed meet the requirements of the technical specifications; the technical specifications include: technical specifications and / or technical requirements manual; If the availability and performance of the information to be analyzed do not meet the requirements of the technical specifications, then the information to be analyzed is determined to be unavailable before the accident occurred. If the availability and performance of the information to be analyzed meet the requirements of the technical specifications, then determine whether the information to be analyzed has a corrective action under the state corresponding to the technical specifications; If a corrective action is taken, it is determined that the information to be analyzed was available before the accident occurred; If no corrective action is taken, the information to be analyzed is determined to have been unavailable before the accident occurred.

3. The robustness analysis method for accident operation procedures according to claim 1, characterized in that, The secondary analysis of the information to be analyzed includes: Determine whether the loss or failure of the information to be analyzed will lead to a preset consequence. The preset consequence is any one of the following: causing preset improper operation, leading to other accident condition procedures, leading to strategies with different target priorities, affecting the integrity of the containment, or causing improper actions of the dedicated system and its support system. If not, then the information to be analyzed is determined to be robust; If so, then perform procedure analysis on the information to be analyzed. The procedure analysis is as follows: determine whether the information to be analyzed needs to optimize the accident operation procedure. If the accident operation procedure needs to be optimized, then determine that the information to be analyzed is not robust and optimize the accident operation procedure corresponding to the information to be analyzed. If the accident operation procedure does not need to be optimized, then determine whether the loss or failure of the information to be analyzed will lead to serious consequences.

4. The robustness analysis method for accident operation procedures according to claim 3, characterized in that, The procedure analysis of the information to be analyzed includes: Determine whether the information to be analyzed requires optimization of the accident operation procedures; If it is necessary to optimize the accident operation procedure, the information to be analyzed is determined to be non-robust and the accident operation procedure corresponding to the information to be analyzed is optimized. If there is no need to optimize the accident operation procedure, then determine whether the loss or failure of the information to be analyzed would lead to serious consequences; If it leads to serious consequences, the information to be analyzed is determined to be non-robust and operational management is performed on the information to be analyzed. If it will not lead to serious consequences, the information to be analyzed is determined to be non-robust and no management is performed on the information to be analyzed.

5. The robustness analysis method for accident operation procedures according to claim 3, characterized in that, The determination of whether the loss or invalidation of the information to be analyzed will lead to a preset consequence includes: Determine whether the loss or failure of the information to be analyzed will lead to any of the following: a preset operation, a redirection to another accident condition procedure, a redirection to a strategy with a different target priority, an impact on the integrity of the containment, or a preset action of the dedicated system and its supporting systems. If so, it is determined that the loss or invalidation of the information to be analyzed will lead to a preset consequence.

6. The robustness analysis method for accident operation procedures according to claim 4, characterized in that, The determination of whether the loss or invalidation of the information to be analyzed would lead to serious consequences includes: Determine whether the loss or failure of the information to be analyzed would lead to any one of the following: increased risk of core meltdown, damage to pressure vessel integrity, damage to reactor coolant system integrity, or severe damage to containment integrity. If so, it is determined that the loss or invalidation of the information to be analyzed would lead to serious consequences.

7. A robustness analysis system for accident operation procedures, characterized in that, include: The information acquisition unit is used to build an information database; The information in the database is transformed to obtain digitized accident operation procedures; Initialization is performed based on preset accident conditions. After initialization is completed, the preset accident conditions are processed based on the digitized accident operation procedures. All information used is generated and saved during the accident condition processing. A robustness diagnostic module, which performs the following operations on each piece of information: Determine whether the information to be analyzed meets preset conditions, which are: available when a single power source is lost, available during an accident, and available before the accident occurs; If the preset conditions are met, the information to be analyzed is determined to be robust; If the preset conditions are not met, a second analysis is performed on the information to be analyzed. The second analysis is to determine whether the loss or failure of the information to be analyzed will lead to a preset consequence. If not, the information to be analyzed is determined to be robust; if so, procedural analysis is performed on the information to be analyzed.

8. The robustness analysis system for accident operation procedures according to claim 7, characterized in that, Also includes: An information database is used to store information on accident operation procedures and related data. An accident operation procedure compilation module is used to convert the information of the accident operation procedures in the information database into information symbols and generate digital accident operation procedures. The accident operation procedure execution module is used to initialize based on preset accident conditions, and after the initialization is completed, to process the preset accident conditions based on the digitized accident operation procedure, and to generate and save all the information used during the accident condition processing.