Emergency shutdown methods and systems for nuclear fuel reprocessing plants and nuclear fuel reprocessing plants
By adopting a switching mechanism between non-safe and safe systems in nuclear fuel reprocessing plants, the problem of the lack of emergency shutdown strategies in reprocessing plants has been solved, enabling safe shutdown in accident situations, avoiding the harm and losses caused by accidents, and improving the safety and economy of operation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-05
- Publication Date
- 2026-04-03
AI Technical Summary
The lack of standardized emergency shutdown strategies for nuclear fuel reprocessing plants in the current technology leads to more serious accident consequences, and the shutdown strategies of nuclear power plants are not applicable to reprocessing plants.
The plant-wide process and auxiliary system equipment is monitored and controlled using both non-safety level (NC) and safety level (RS) systems. Under normal conditions, the non-safety level system monitors the equipment operation, and when an accident occurs, it switches to the safety level system to shut down the equipment. This ensures that the redundant safety level equipment sequence is consistent with the operating unit sequence, shields the control signals of the non-safety level system, and achieves shutdown through the safety level system.
Effectively prevent the consequences of accidents from becoming more severe, avoid personal injury, environmental damage and economic losses, improve the safety and economy of reprocessing plant operation, ensure that the negative pressure gradient is not disordered, and prevent the leakage of radioactive materials.
Smart Images

Figure CN118335371B_ABST
Abstract
Description
Technical Field
[0001] This invention specifically relates to an emergency shutdown method, system, and nuclear fuel reprocessing plant for nuclear fuel reprocessing. Background Technology
[0002] Currently, with the rapid development of nuclear power projects, nuclear fuel reprocessing technology has also become an important technology that must be developed rapidly. The main means of preventing accidents at nuclear power plants and mitigating their consequences is to apply the concept of defense in depth. Therefore, nuclear power plants have complete and mature emergency shutdown strategies. However, nuclear fuel reprocessing technology is still in its early stages, and reprocessing plants under construction or planned have not yet developed standardized emergency shutdown strategies.
[0003] The core equipment of a nuclear power plant is the nuclear reactor, and the main focus is on the stable operation of the reactor and the safe and reliable operation of other equipment such as generator sets and cooling systems. Nuclear power plants inherently possess a high level of safety, and their safety control systems are mostly passive systems—systems that automatically activate in the event of abnormal conditions. These include reactor protection systems, emergency shutdown systems, and cooling systems. The plant layout is primarily centered around the nuclear island, and mainly includes the nuclear island, steam generator building, turbine building, auxiliary equipment buildings, and waste treatment facilities; the plant buildings are arranged in a relatively concentrated manner.
[0004] However, reprocessing plants are primarily responsible for the reprocessing and disposal of nuclear waste, and their accident safety functions are mainly focused on preventing the leakage and spread of radioactive materials. They mainly handle more hazardous materials such as high-level radioactive waste, and their safety control systems generally employ active systems, meaning safety is ensured through real-time monitoring and manual operation. Safety control equipment is relatively limited, with monitoring and alarm systems being the most prevalent. The various sub-buildings within a reprocessing plant are set up relatively independently.
[0005] The reprocessing plant and the nuclear power plant have significant differences in safety functions, types of safety equipment, safety control systems and plant layout, as mentioned above. It is clear that the shutdown strategy of the nuclear power plant is not applicable to the reprocessing plant. Summary of the Invention
[0006] The technical problem to be solved by this invention is to address the aforementioned shortcomings in the existing technology by providing an emergency shutdown method for a nuclear fuel reprocessing plant. This method is clear and reasonable in its approach, easy to implement, specifically designed for reprocessing plants, and can shut down the plant in a timely manner, effectively preventing the escalation of accident consequences. This invention also provides an emergency shutdown system for a nuclear fuel reprocessing plant and a nuclear fuel reprocessing plant itself.
[0007] An emergency shutdown method for a nuclear fuel reprocessing plant includes the following steps:
[0008] Acquire monitoring data from the equipment;
[0009] Determine whether an accident state has been entered based on the monitoring data:
[0010] If the system is determined to be in an accident state, it will then determine whether the currently running redundant safety-level device sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level device sequence is inconsistent with the current operating unit sequence, the running redundant safety-level device sequence will be switched to be consistent with the current operating unit sequence.
[0011] The nuclear fuel reprocessing plant was shut down using a safety-grade system.
[0012] Furthermore, if it is determined that the system will not enter an accident state, it will operate as a non-safety-level system monitoring device.
[0013] Furthermore, the shutdown of the nuclear fuel reprocessing plant controlled by the safety-level system specifically includes: operating the first redundant safety-level equipment through the first operating unit of the safety-level system or operating the second redundant safety-level equipment through the second operating unit of the safety-level system to achieve the shutdown operation;
[0014] The step of determining whether the currently running redundant security-level device sequence is consistent with the current operating unit sequence of the security-level system, and switching the running redundant security-level device sequence to be consistent with the current operating unit sequence when they are inconsistent, specifically includes:
[0015] If the current operating unit is the first operating unit, determine whether the currently running redundant security level device is the first redundant security level device, and if the currently running redundant security level device is not the first redundant security level device, switch the running redundant security level device to the first redundant security level device.
[0016] If the current operating unit is the second operating unit, determine whether the currently running redundant security level device is the second redundant security level device, and if the currently running redundant security level device is not the second redundant security level device, switch the running redundant security level device to the second redundant security level device.
[0017] Furthermore, the step of performing the parking operation by operating the first redundant safety-level device through the first operating unit of the safety-level system or by operating the second redundant safety-level device through the second operating unit of the safety-level system specifically includes: determining whether the first operating unit is valid.
[0018] When the first operating unit is determined to be valid, the control signal from the non-safety level system to the safety level system is shielded by the first operating unit to prevent the non-safety level system control equipment from operating, and the parking operation is realized by the first operating unit.
[0019] When the first operating unit is determined to be invalid, the control signal from the non-safety level system to the safety level system and the first operating unit are blocked by the second operating unit to prevent the first operating unit and the non-safety level system control equipment from operating, and the parking operation is achieved through the second operating unit.
[0020] Furthermore, when it is determined that no accident state is entered, the first operating unit and the second operating unit are in a disabled state; when it is determined that an accident state is entered, the first operating unit and the second operating unit are in an enabled state.
[0021] Furthermore, the step of determining whether an accident state has been entered based on monitoring data specifically includes:
[0022] Determine whether an anomaly has occurred based on the monitoring data:
[0023] If no abnormalities are found in the monitoring data, it is determined that the accident state will not be entered.
[0024] If the monitoring data is abnormal, further investigation will be conducted to determine whether the safety function signals have been triggered:
[0025] If not triggered, the repair operation will be performed and the system will be determined not to enter an accident state.
[0026] If it has been triggered, it is determined that an accident state has been entered.
[0027] Furthermore, acquiring the monitoring data of the equipment includes: simultaneously acquiring the monitoring data of the equipment using two sets of monitoring instruments; and determining whether an abnormality has occurred based on the monitoring data specifically includes:
[0028] Determine whether there is an instrument malfunction based on the monitoring data obtained from the two sets of monitoring instruments.
[0029] An anomaly is determined to have occurred when an instrument malfunctions and / or when the monitoring data from any set of monitoring instruments does not meet the first set conditions.
[0030] Furthermore, the monitoring data acquired simultaneously by two sets of monitoring instruments is the first monitoring data, and the two sets of monitoring instruments belong to a first monitoring unit. A second monitoring unit is also used to acquire the second monitoring data of the equipment. The step of determining whether an abnormality has occurred based on the monitoring data further includes:
[0031] If the second monitoring data does not meet the second set conditions, an anomaly is determined to have occurred.
[0032] This invention also provides an emergency shutdown system for a nuclear fuel reprocessing plant, comprising: a monitoring unit for acquiring monitoring data from equipment; a first judgment unit electrically connected to the monitoring unit for determining whether an accident state has been entered based on the monitoring data; a second judgment unit electrically connected to the first judgment unit, which, when the first judgment unit determines that an accident state has been entered, determines whether the currently operating redundant safety-level equipment sequence is consistent with the current operating unit sequence of the safety-level system, and switches the operating redundant safety-level equipment sequence to be consistent with the current operating unit sequence when the redundant safety-level equipment sequence is inconsistent with the current operating unit sequence; and a safety-level system for controlling the shutdown of the nuclear fuel reprocessing plant.
[0033] Furthermore, the nuclear fuel reprocessing plant emergency shutdown system also includes a non-safety level system, which is electrically connected to the first judgment unit and is used to monitor equipment operation when the first judgment unit determines that an accident state has not been entered.
[0034] Furthermore, the operating unit of the safety-level system includes a first operating unit and a second operating unit, which are separately located in different positions. When the monitoring unit determines that an accident state is not being entered, the first and second operating units are disabled. When the monitoring unit determines that an accident state is being entered, the first and second operating units are enabled. The first operating unit is used to shield the control signals from the non-safety-level system to the safety-level system when an accident state is entered, so as to prevent the non-safety-level system control equipment from operating and to achieve a shutdown operation. The second operating unit is used to shield the control signals from the non-safety-level system to the safety-level system and the first operating unit when the first operating unit fails, so as to prevent the first operating unit and the non-safety-level system control equipment from operating and to achieve a shutdown operation.
[0035] Furthermore, both the non-safety level system and the safety level system include control units. The control unit of the non-safety level system is a non-safety level control unit, and the control unit of the safety level system includes a first control unit and a second control unit. The equipment includes a non-safety level device, a non-redundant safety level device, a first redundant safety level device, and a second redundant safety level device. The non-redundant safety level device automatically enters a stopped state when it loses its power source. The first control unit provides power and control commands to the non-redundant safety level device and the first redundant safety level device. The second control unit provides power and control commands to the second redundant safety level device. The non-safety level system is used to monitor the operation of the non-safety level device through the non-safety level control unit, and to monitor the operation of the first redundant safety level device and the non-redundant safety level device through the first control unit / monitor the operation of the second redundant safety level device through the second control unit. The safety level system is used to monitor the first redundant safety level device and the second redundant safety level device through the first control unit and the second control unit, so that only one of the first redundant safety level device and the second redundant safety level device is in an operating state at any given time.
[0036] The present invention also provides a nuclear fuel reprocessing plant, including an equipment area, a habitable area, and the aforementioned nuclear fuel reprocessing plant emergency shutdown system. The habitable area includes an in-plant habitable area and an off-plant habitable area. The nuclear fuel reprocessing plant emergency shutdown system is located in the in-plant habitable area and is used to monitor and control the equipment in the equipment area. The off-plant habitable area is communicatively connected to the in-plant habitable area and is used to collect signals from the nuclear fuel reprocessing plant emergency shutdown system and provide technical support to the in-plant habitable area.
[0037] This invention provides an emergency shutdown method specifically designed for nuclear fuel reprocessing plants. Within the field of nuclear fuel reprocessing plant operation control technology, it is specifically designed for accident conditions at nuclear fuel reprocessing plants. It employs both non-safety-grade (NC) and safety-grade (RS) systems for monitoring and controlling the entire plant's process and auxiliary equipment. Specifically, under normal conditions, the NC system monitors equipment operation. However, in the event of an accident, since the NC system is unreliable or unavailable, the safety-grade system is used to shut down the nuclear fuel reprocessing plant. This addresses the uncontrollable situations caused by the failure of the NC system during an accident, avoiding personnel hazards, environmental damage, and economic losses, thereby improving the safety and economy of reprocessing plant operation.
[0038] Since the various sub-projects of the reprocessing plant perform slow chemical reactions, their core safety function is to contain radioactive materials. This is mainly reflected in the need to maintain the negative pressure gradient between different areas within the sub-project facilities, which is a "dynamic seal." Therefore, when switching system operations, the method of this invention must first determine whether the currently operating redundant safety-level equipment sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level equipment sequence is inconsistent with the current operating unit sequence, the operating redundant safety-level equipment sequence is switched to be consistent with the current operating unit sequence. Then, the safety-level system controls the nuclear fuel reprocessing plant to shut down, thereby avoiding the disruption of the negative pressure gradient and the leakage of radioactive materials. Because of this judgment process, even reprocessing plants can use system switching to conduct emergency shutdowns, ensuring applicability to reprocessing plants. Attached Figure Description
[0039] Figure 1 This is a schematic flowchart of the emergency shutdown method for a nuclear fuel reprocessing plant in Embodiment 1 of the present invention;
[0040] Figure 2 This is a schematic diagram of the nuclear fuel reprocessing plant emergency shutdown system in Embodiment 2 of the present invention;
[0041] Figure 3 This is a simplified schematic diagram of the equipment in the nuclear fuel reprocessing plant in Embodiment 3 of the present invention;
[0042] Figure 4 This is a schematic diagram of the layout of the habitable area of the nuclear fuel reprocessing plant in Embodiment 3 of the present invention. Detailed Implementation
[0043] The technical solutions of the invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the invention, not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without creative effort are within the scope of the invention.
[0044] In the description of this invention, it should be noted that the terms "upper" and "lower" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience and simplification of the description and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this invention.
[0045] In the description of this invention, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.
[0046] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "connection," "setting," "installation," "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0047] Example 1
[0048] The emergency shutdown method for the nuclear fuel reprocessing plant in this embodiment includes the following steps:
[0049] Acquire equipment monitoring data;
[0050] Determine whether an accident state has been entered based on monitoring data:
[0051] If the system is determined to be in an accident state, it will then determine whether the currently running redundant safety-level device sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level device sequence is inconsistent with the current operating unit sequence, the running redundant safety-level device sequence will be switched to be consistent with the current operating unit sequence.
[0052] The nuclear fuel reprocessing plant was shut down using a safety-grade system.
[0053] If it is determined that the system will not enter an accident state, it will operate as a non-safety-level system monitoring device.
[0054] The method in this embodiment, within the field of nuclear fuel reprocessing plant operation control technology, is specifically designed for nuclear fuel reprocessing plant accident conditions. It employs both non-safety-grade (NC) and safety-grade (RS) systems for monitoring and controlling the entire plant's process and auxiliary equipment. Specifically, under normal conditions, the NC system monitors equipment operation. However, in the event of an accident, since the NC system is no longer reliable or available, the safety-grade system controls the reprocessing plant shutdown. This addresses the uncontrollable situations caused by the failure of the NC system during an accident, preventing personnel hazards, environmental damage, and economic losses, thereby improving the safety and economy of the reprocessing plant operation.
[0055] Since the various sub-projects of the reprocessing plant perform slow chemical reactions, their core safety function is to contain radioactive materials. This is mainly reflected in maintaining the negative pressure gradient between different areas within the sub-project facility, which is a form of "dynamic sealing." Specifically, it involves maintaining the negative pressure gradient between the red, orange, green, and white areas within the sub-project facility. Therefore, even redundant equipment cannot be mixed; otherwise, it will lead to a disruption of the negative pressure gradient and cause radioactive material leakage. Thus, when switching system operations, the method in this embodiment first determines whether the currently operating redundant safety-level equipment sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level equipment sequence is inconsistent with the current operating unit sequence, the operating redundant safety-level equipment sequence is switched to be consistent with the current operating unit sequence, thereby avoiding a disruption of the negative pressure gradient and causing radioactive material leakage. Because of this judgment process, even reprocessing plants can use system switching for emergency shutdowns, ensuring applicability to reprocessing plants.
[0056] In this embodiment, the operating unit of the safety-level system includes a first operating unit and a second operating unit. The safety-level system controls the shutdown of the nuclear fuel reprocessing plant. Specifically, the shutdown operation is achieved by operating the first redundant safety-level equipment through the first operating unit of the safety-level system or by operating the second redundant safety-level equipment through the second operating unit of the safety-level system.
[0057] Determine whether the currently running redundant security-level device sequence is consistent with the current operating unit sequence of the security-level system, and if the redundant security-level device sequence is inconsistent with the current operating unit sequence, switch the running redundant security-level device sequence to be consistent with the current operating unit sequence, specifically including:
[0058] If the current operating unit is the first operating unit, determine whether the currently running redundant security level device is the first redundant security level device, and if the currently running redundant security level device is not the first redundant security level device, switch the running redundant security level device to the first redundant security level device.
[0059] If the current operating unit is the second operating unit, determine whether the currently running redundant security level device is the second redundant security level device, and if the currently running redundant security level device is not the second redundant security level device, switch the running redundant security level device to the second redundant security level device.
[0060] Therefore, before the shutdown operation, it is essential to ensure that the sequence (first, second) of the currently operating redundant safety-level devices completely corresponds to the sequence (first, second) of the operating unit. This avoids the possibility of restarting another set of redundant safety-level devices when one set is already in operation, which could lead to consequences such as negative pressure gradient confusion. This process ensures the strict operation of redundantly configured devices.
[0061] In this embodiment, the parking operation is achieved by operating the first redundant safety-level device through the first operating unit of the safety-level system or by operating the second redundant safety-level device through the second operating unit of the safety-level system. Specifically, this includes: determining whether the first operating unit is valid.
[0062] When the first operating unit is determined to be valid, the control signal from the non-safety level system to the safety level system is shielded by the first operating unit to prevent the non-safety level system control equipment from operating, and the parking operation is realized by the first operating unit.
[0063] When the first operating unit is determined to be invalid, the control signal from the non-safety level system to the safety level system and the first operating unit are blocked by the second operating unit to prevent the first operating unit and the non-safety level system control equipment from operating, and the parking operation is achieved through the second operating unit.
[0064] Since the after-treatment plant has entered an accident state when the equipment needs to be stopped using the safety-level system, the non-safety-level system is unreliable or unusable at this time. Therefore, the non-safety-level system is shielded by the first and second operating units to avoid conflicting operating commands caused by abnormal operation of the non-safety-level system. This redundant setup of two operating units ensures the effectiveness of the shutdown operation and prevents serious accidents such as the failure of a single operating unit due to emergencies such as fire, which could ultimately lead to the inability to stop the equipment. In this embodiment, the first and second operating units are ECP1 and ECP2, respectively, located in the central control room (MCR) and the emergency monitoring room. In the event of an inoperable situation such as a fire in the central control room, the first operating unit, ECP1, is deemed invalid, and the safety-level system's operating units consist only of the first and second operating units, with the second operating unit serving as a backup for the first operating unit.
[0065] In this embodiment, when it is determined that no accident state will be entered, the first and second operation units are disabled; only when an accident state is determined to be entered are the first and second operation units enabled. This configuration can avoid situations such as conflicting instructions caused by accidental operation.
[0066] In this embodiment, determining whether an accident state has been entered based on monitoring data specifically includes:
[0067] Determine whether an anomaly has occurred based on the monitoring data:
[0068] If no abnormalities are found in the monitoring data, it is determined that the accident state will not be entered.
[0069] If the monitoring data is abnormal, further investigation will be conducted to determine whether the safety function signals have been triggered:
[0070] If not triggered, the repair operation will be performed and the system will be determined not to enter an accident state.
[0071] If it has been triggered, it is determined that an accident state has been entered.
[0072] In this embodiment, when critical safety function signals are triggered, manual judgment can be made on whether to enter an accident state and execute an emergency stop, thereby adding another layer of protection.
[0073] In this embodiment, acquiring the equipment monitoring data includes: simultaneously acquiring the equipment monitoring data using two sets of monitoring instruments.
[0074] Determining whether an anomaly has occurred based on monitoring data specifically includes: determining whether there is an instrument malfunction based on monitoring data obtained from two sets of monitoring instruments.
[0075] An anomaly is determined to have occurred when an instrument malfunctions and / or when the monitoring data from any set of monitoring instruments does not meet the first set conditions.
[0076] In other words, by using two sets of monitoring instruments to perform monitoring simultaneously—a redundant setup—the data from both sets of instruments can be cross-referenced. Therefore, if a single instrument is unavailable or its reading is unreliable, an anomaly should not be concluded and an accident should not be declared due to the failure of a single instrument. In this case, the readings of instruments with the same measurement function as the faulty instrument should be obtained periodically to determine whether the problem is an instrument malfunction or an actual equipment malfunction.
[0077] Furthermore, in this embodiment, it is also necessary to determine whether the faulty instrument participates in the automatic control logic. If the faulty instrument participates in the control logic, the equipment and / or control unit (i.e., the cabinet mentioned later) controlled by the faulty instrument in the control logic are switched to manual control mode or local operation mode.
[0078] In this embodiment, the monitoring data acquired simultaneously by two sets of monitoring instruments is the first monitoring data, and the two sets of monitoring instruments belong to the first monitoring unit; a second monitoring unit is also used to acquire the second monitoring data of the equipment; judging whether an anomaly has occurred based on the monitoring data also includes: if the second monitoring data does not meet a second set condition, then an anomaly is determined to have occurred. That is, in this embodiment, the determination of whether an anomaly has occurred is made through two aspects of numerical monitoring, and the judgment result is more comprehensive and reliable, avoiding the delay in the detection of accidents.
[0079] In this embodiment, the first monitoring unit is mainly used to monitor abnormalities in critical safety parameters of the process system, such as spent fuel assembly drops, failure of the iodine filter in the headend dissolved exhaust system, etc.; as well as abnormal radiation monitoring data, such as nuclear criticality in the process equipment room (or hot chamber), abnormal aerosol signals in the process tail gas; and seismic instrument alarm signals. The first set condition is the normal operating range of the aforementioned critical safety parameters of the process system. When the values do not meet this range, it indicates that there is an abnormality in the critical safety parameters of the process system. The first set condition can be selected according to specific circumstances.
[0080] The second monitoring unit is located in the emergency command center within the habitable area outside the plant. It is a dedicated emergency response facility for the nuclear fuel reprocessing plant, responsible for the overall command and coordination of all emergency response actions within the plant during an accident emergency. This includes the emergency command center and operations support center. Its main tasks are to monitor critical safety parameters of the reprocessing plant's process systems, radiation monitoring data, environmental and meteorological data, accident consequence assessment results, etc., compare these with the reprocessing plant's emergency response level, provide recommendations on the accident status level, and offer decision support to emergency command personnel. The second set condition refers to the normal operating range of the aforementioned parameters. When these ranges are not met, it indicates an anomaly in a critical parameter. The second set condition can be selected based on specific circumstances.
[0081] The emergency shutdown method for the nuclear fuel reprocessing plant in this embodiment can adopt the emergency shutdown system of Embodiment 2, such as... Figure 1 As shown, the method generally includes the following steps:
[0082] The first monitoring unit / second monitoring unit acquires monitoring data from the equipment. The first judgment unit determines whether an anomaly has occurred (i.e., whether there is a situation where the monitoring data does not match the set conditions and an alarm is issued). In this embodiment, the two sets of monitoring instruments of the first monitoring unit simultaneously acquire the first monitoring data of the first redundant safety-level equipment and the non-redundant safety-level equipment, and send it to the first control unit. The first control unit then sends it to the non-safety-level operation unit, the first operation unit, and the second operation unit (wherein, the first monitoring data sent to the second operation unit is only the first monitoring data of the non-redundant safety-level equipment). The two sets of monitoring instruments of the first monitoring unit simultaneously acquire the first monitoring data of the second redundant safety-level equipment, and send it to the second control unit. The second control unit then sends it to the non-safety-level operation unit and the second operation unit. The first monitoring unit also acquires the first monitoring data of the non-safety-level equipment and sends it to the non-safety-level control unit. The non-safety-level control unit then sends it to the non-safety-level operation unit. Here, the determination of whether the first and second monitoring data are abnormal can be made manually or by setting up automatic judgment devices such as the first judgment unit in the central control room, emergency monitoring room, or emergency command center.
[0083] If no abnormality occurs, it is determined that the accident state will not be entered;
[0084] If an anomaly occurs, determine whether the safety function signal has been triggered:
[0085] If not triggered, the repair operation will be performed and the system will be determined not to enter an accident state.
[0086] If triggered, it is determined that an accident state has been entered. In this embodiment, when safety function signals such as criticality are triggered, it can be further determined manually or by the first judgment unit based on other preset conditions whether it is necessary to enter an accident state and execute an emergency stop, thereby adding another layer of protection.
[0087] If it is determined that the system will not enter an accident state, then the non-safety level system control equipment will operate, which is the normal operating state;
[0088] If an accident state is determined, the second judgment unit first determines whether the currently operating redundant safety-level equipment sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level equipment sequence is inconsistent with the current operating unit sequence, the operating redundant safety-level equipment sequence is switched to be consistent with the current operating unit sequence. Then, the safety-level system controls the shutdown of the nuclear fuel reprocessing plant. Specifically:
[0089] Determine if the first operating unit is effective (i.e., determine manually or through automated monitoring equipment whether a fire has occurred and whether the central control room is available):
[0090] When the first operating unit, namely ECP1, is active, the control signal from the non-safety level system to the safety level system is shielded through the first operating unit to prevent the non-safety level system control equipment from operating, and the shutdown operation is achieved through the first operating unit.
[0091] When the first operating unit is invalid, the second operating unit, namely ECP2, shields the control signals from the non-safety level system to the safety level system and the first operating unit to prevent the first operating unit and the non-safety level system control equipment from operating and to achieve the stop operation through the second operating unit.
[0092] After the parking operation is completed, determine whether the accident has been resolved:
[0093] If the situation has been resolved, it indicates that a design-based accident has occurred, and the reprocessing plant is now in a safe shutdown state.
[0094] If the situation is not resolved, it indicates that a serious accident has occurred. A serious accident is an accident whose consequences exceed the severity of the design baseline accident. Such accidents are extremely unlikely to occur. The design of the reprocessing plant cannot prevent the loss of sealing caused by such accidents, nor can it mitigate the consequences of such accidents, such as the red oil explosion accident in the high-level radioactive waste evaporator (red zone purification failure) and the hydrogen explosion accident in the high-level radioactive waste storage tank (red zone purification failure).
[0095] The purpose of this method is to propose an emergency shutdown scheme for the control system of a nuclear fuel reprocessing plant to address the problem of emergency shutdown under accident emergency conditions. According to HAF102-2016, "Safety Regulations for Nuclear Power Plant Design," the main means of preventing nuclear power plant accidents and mitigating their consequences is the application of the defense-in-depth concept. Defense-in-depth primarily prevents harm to personnel and the environment through a combination of a series of continuous and independent defense layers. Defense-in-depth consists of five layers; if the protection of one layer fails, the next layer provides protection. The independent effectiveness of each layer is a necessary component of defense-in-depth. The emergency shutdown strategy of this method is the fifth layer. This final layer of defense aims to mitigate the radioactive consequences of potential releases caused by accident conditions. This layer requires appropriate emergency facilities and the development of emergency plans and procedures for both on-site and off-site emergency responses. The system in Example 2 can effectively achieve this objective.
[0096] Referring to HAF102-2016, "Safety Regulations for Nuclear Power Plant Design," the commonly used accident analysis methods for nuclear facilities are determinism and probability. Determinism is primarily used in the safety analysis of reprocessing plants. From a conservative and safety perspective, determinism is irreplaceable. It assumes an accident has occurred, adopts reasonable or conservative assumptions as required, and analyzes and calculates the corresponding consequences of the entire nuclear facility system until the radioactive consequences of the accident are determined. This type of accident consequence presupposition analysis involves specifying typical hypothetical nuclear accidents and analyzing their resulting event evolution to verify the effectiveness of various safety measures, with a focus on the design basis accident. This method utilizes the fifth level of the defense-in-depth concept, aiming to mitigate the radioactive consequences of potential radioactive releases caused by accident conditions and to bring the reprocessing plant to a safe shutdown state under a design basis accident.
[0097] Overall, this method implements the defense-in-depth concept and combines physical isolation and redundant design. By adopting this method, the operation of the aftertreatment plant can be guaranteed to be safe and controllable, the ability to prevent human error can be improved, the risks caused by OWPS failure under accident conditions in the aftertreatment plant can be resolved, and the aftertreatment plant can be brought to a safe shutdown state under design baseline accident conditions, avoiding personnel hazards, environmental hazards and economic losses caused by the accident, thereby improving the safety and economy of the aftertreatment plant operation.
[0098] Example 2
[0099] The nuclear fuel reprocessing plant emergency shutdown system of this embodiment includes: a monitoring unit for acquiring monitoring data from the equipment; a first judgment unit electrically connected to the monitoring unit for determining whether an accident state has been entered based on the monitoring data; a second judgment unit electrically connected to the first judgment unit, which, when the first judgment unit determines that an accident state has been entered, determines whether the currently operating redundant safety-level equipment sequence is consistent with the current operating unit sequence of the safety-level system, and switches the operating redundant safety-level equipment sequence to be consistent with the current operating unit sequence when the redundant safety-level equipment sequence is inconsistent with the current operating unit sequence; and a safety-level system for controlling the shutdown of the nuclear fuel reprocessing plant.
[0100] In this embodiment, the nuclear fuel reprocessing plant emergency shutdown system also includes a non-safety level system, which is electrically connected to the first judgment unit and is used to monitor equipment operation when the first judgment unit determines that an accident state has not been entered.
[0101] The monitoring unit comprises a first monitoring unit and a second monitoring unit. The first monitoring unit includes two sets of safety-grade monitoring instruments, redundantly configured, used to monitor for anomalies in critical safety parameters of the equipment's process systems, such as spent fuel assembly drops or iodine filter failures in the head-end dissolved exhaust system; as well as anomalies in radiation monitoring data, such as nuclear criticality in the process equipment room (or hot chamber) or aerosol signals in the process tail gas; and seismic instrument alarm signals. The second monitoring unit is located in the emergency command center within the habitable zone outside the plant. It is a dedicated emergency response facility for the nuclear fuel reprocessing plant, responsible for the overall command and coordination of all emergency response actions within the plant during an accident emergency, including the emergency command center and operations support center. Its main tasks include monitoring critical safety parameters of the reprocessing plant's process systems, radiation monitoring data, environmental and meteorological data, accident consequence assessment results, comparing these with the reprocessing plant's emergency response level, providing accident status level recommendations, and offering decision support to emergency command personnel.
[0102] Therefore, the monitoring data obtained by the first and second monitoring units can determine whether an accident state needs to be entered from different perspectives, and the judgment results are more comprehensive and reliable, avoiding the delay in accident detection.
[0103] In this embodiment, the judgment can be made by operators in the central control room, emergency monitoring room, or emergency command center to determine whether the data is abnormal. Alternatively, automatic judgment devices / systems such as a first judgment unit and a second judgment unit can be set up to determine whether the data is abnormal.
[0104] In this embodiment, the non-safety level (NC) system is a DCS system, which also includes an operator station (OWPS) as the non-safety level operating unit of the non-safety level system. Under normal circumstances, the non-safety level operating unit (OWPS) controls the operation of the equipment. When an accident occurs, the system becomes unavailable or unreliable, so it switches to the safety level system to perform a shutdown operation.
[0105] In this embodiment, the operating unit of the safety-level system includes a first operating unit and a second operating unit, which are separately disposed in different locations. When the monitoring unit determines that no accident state has been entered, the first and second operating units are disabled. When the monitoring unit determines that an accident state has been entered, the first and second operating units are enabled. The first operating unit is used to shield the control signals from the non-safety-level system to the safety-level system when an accident state is entered, so as to prevent the non-safety-level system control equipment from operating and to achieve a shutdown operation. The second operating unit is used to shield the control signals from the non-safety-level system to the safety-level system and the first operating unit when the first operating unit fails, so as to prevent the first operating unit and the non-safety-level system control equipment from operating and to achieve a shutdown operation.
[0106] Specifically, the safety-grade system has two emergency operation platforms: the first operation unit (ECP1) and the second operation unit (ECP2). The first operation unit (ECP1) and the non-safety-grade system operation unit (OWPS) are both located in the central control room (MCR), while the second operation unit (ECP2) is located in the emergency monitoring room. Both the MCR and the emergency monitoring room are located within the habitable zone of the nuclear power plant. ECP1 and ECP2 are both located within the habitable zone, specifically in the MCR and emergency monitoring room, respectively. These two rooms must be located in different fire compartments within the habitable zone to ensure a smooth shutdown of the reprocessing plant in the event of a fire or other accident.
[0107] The control system of the post-treatment plant is isolated according to sub-items (initial stage, decontamination and separation, final stage, wastewater treatment, etc.). Each sub-item has two redundant control units: ECP1 in the central control room and ECP2 in the emergency monitoring room. Each sub-item has a switching knob in both ECP1 and ECP2. The two switching knobs make a binary decision: if both knobs are set to "Central Control Room Operation," then it is central control room operation; if either or both knobs are set to "Emergency Monitoring Room Operation," then it is emergency monitoring room operation. The advantage is that the binary decision logic avoids the situation where a single switching knob failure would prevent the switching process from being completed during personnel transfer.
[0108] In this embodiment, both the non-safety level system and the safety level system include control units, i.e., control cabinets and other equipment. The control unit of the non-safety level system includes a non-safety level control unit, and the control unit of the safety level system includes a first control unit and a second control unit. The equipment to be monitored includes non-safety level equipment, non-redundant safety level equipment, first redundant safety level equipment and second redundant safety level equipment. The non-redundant safety level equipment automatically enters a stop state when it loses its power source.
[0109] The first control unit provides power and control commands to the non-redundant safety-level device and the first redundant safety-level device; the second control unit provides power and control commands to the second redundant safety-level device; the non-safety-level system is used to control the operation of the non-safety-level device through the non-safety-level monitoring unit, and to monitor the operation of the first redundant safety-level device and the non-redundant safety-level device through the first control unit / monitor the operation of the second redundant safety-level device through the second control unit; the safety-level system is used to monitor the first redundant safety-level device and the second redundant safety-level device through the first control unit and the second control unit, so that only one of the first redundant safety-level device and the second redundant safety-level device is in operation at any given time.
[0110] In this embodiment, both the first control unit and the second control unit are in safety-grade cabinets and are used to monitor safety-grade equipment. The monitoring data of the monitoring instruments and the signals of each safety grade are centrally monitored by each set of control units. The signals centrally monitored by the first control unit and the second control unit are isolated and distributed to the non-safety-grade DCS system. The operator performs centralized monitoring of the entire plant's signals at the NC operator station (OWPS) in the central control room (MCR). When abnormal information is generated and meets the accident judgment conditions, a shutdown strategy needs to be executed. The accident safety shutdown function is executed by two physically isolated RS-grade emergency operating consoles (ECP1 and ECP2) in the central control room and the emergency monitoring room, respectively.
[0111] Specifically, the two sets of monitoring instruments in the first monitoring unit simultaneously acquire the first monitoring data from the first redundant safety-level equipment and the non-redundant safety-level equipment, and send it to the first control unit. The first control unit then sends it to the non-safety-level operating unit, the first operating unit, and the second operating unit (wherein, the first monitoring data sent to the second operating unit is only the first monitoring data from the non-redundant safety-level equipment). The two sets of monitoring instruments in the first monitoring unit simultaneously acquire the first monitoring data from the second redundant safety-level equipment, and send it to the second control unit. The second control unit then sends it to the non-safety-level operating unit and the second operating unit. The first monitoring unit also acquires the first monitoring data from the non-safety-level equipment and sends it to the non-safety-level control unit. The non-safety-level control unit then sends it to the non-safety-level operating unit. Here, the determination of whether the first and second monitoring data are abnormal can be made manually or by setting up an automatic judgment device in the central control room, emergency monitoring room, or emergency command center.
[0112] In standard operating mode (i.e., the state of the MCR during normal operation of the post-treatment plant): The OWPS in the central control room performs all (safety-level and non-safety-level) signal monitoring and operation functions; ECP1 and ECP2 are in a disabled state (only operation functions are disabled, interlocks and logic operate normally); the emergency command center in the off-site habitable area monitors all emergency-related status signals for the entire plant, such as criticality, aerosol, and I-129; an operation service center can also be set up, which, in addition to normal production management functions, can also undertake some emergency signal monitoring functions within the plant area. In this state, all (first) monitoring data is monitored through OWPS; that is, the first control unit sends the monitoring data of the first redundant safety-level equipment and the non-redundant safety-level equipment to the first operating unit (…). Figure 2 (Line ⑤) sends the monitoring data of the first redundant security level device and the non-redundant security level device to the non-security level control unit. Figure 2 Line ① in the middle - then the non-safety level control unit sends it to OWPS, and sends the monitoring data of the non-redundant safety level device to the second operation unit ( Figure 2 Line ⑥), the second control unit sends the monitoring data of the second redundant security level device to the second operation unit ( Figure 2 (line ⑦), and non-safety level control unit ( Figure 2 At line ②) in the middle - it is then sent to OWPS by the non-safety level control unit.
[0113] When an abnormal signal is generated: critical safety parameters of the process system, radiation monitoring data, environmental monitoring data, and meteorological data deviate from normal operating conditions, the second monitoring unit of the emergency command center compares the deviation signal with the emergency response level of the reprocessing plant to determine whether an accident state has been entered. Information can be generated for staff, including the accident state type and level. The first monitoring unit acquires equipment operation monitoring data and determines whether an abnormality exists and whether it can be repaired. If it cannot be repaired, an accident state is declared. If the accident is a critical alarm, aerosol exceeding limits, etc., staff should immediately consider whether to activate the habitable areas within the plant (MCR area) and outside the plant (emergency command center).
[0114] Level 1 Emergency Mode (both ECP1 and ECP2 are available): When the first or second monitoring unit declares the entry into Level 1 emergency mode, all personnel except those required to be on duty in the designated residential areas inside and outside the plant must evacuate the plant area. ECP1 is activated, and a safe shutdown operation is performed via ECP1. At this time, the non-safety-level DCS system is unavailable or unreliable, therefore, the control signals from the non-safety-level system to the safe-level system are blocked (i.e., blocked). Figure 2 (Lines ③ and ④ in the text); The technical support center in the habitable area within the plant can establish a video link with the emergency command center and operation support center outside the plant. Problems that MCR cannot handle can be handled through remote technical support from experts, safely bringing the post-processing plant into a shutdown state.
[0115] Level 2 Incident Mode (ECP1 Unavailable): When an incident such as a fire renders the MCR unavailable, operation switches to ECP2 in the emergency control room. ECP2 disables the operability of all MCR operator stations and deactivates the MCR (i.e., disables control signals from OWPS to the safety-level system). Figure 2 Lines ③ and ④ in the middle) and shielded ECP1) at this time, normal production could no longer be maintained. Through ECP2 in the emergency monitoring room, the entire plant was finally brought to a safe shutdown state.
[0116] The above-mentioned operation and instrument data monitoring and judgment functions can be implemented by electrical equipment or by manual operation / observation judgment by operators.
[0117] In general, the nuclear fuel reprocessing plant emergency shutdown system in this embodiment includes a safety-level control unit (first control unit and second control unit) with redundant configuration, a non-safety-level operating unit (NC digital workstation OWPS), and a redundant first monitoring unit (two sets of monitoring instruments, including internal communication system, radiation monitoring system and fire protection system, etc.).
[0118] The system can be divided into three layers: layer 0 is for local instruments and equipment; layer 1 is the process control layer (redundant RS cabinets), which performs functions such as signal isolation, interlocking and alarm; layer 2 is the monitoring and operation layer (OWPS, redundant RS panels ECP1 and ECP2), through which nuclear safety signals are monitored and operated.
[0119] The process control signals of the redundant control units are isolated and distributed to ECP1, ECP2 and the non-safety level control system (OWPS). Under normal operating conditions, only the internal interlock of the safety level system is activated. The manual operation signals of ECP1 and ECP2 are shielded through knobs and relays. The operator performs full-function centralized monitoring of signals at the NC operator station (OWPS) in the central control room. When abnormal information is generated and the accident condition is met, an emergency shutdown must be performed.
[0120] For displaying monitoring data, the ECP1 in the central control room can display the readings of the two sets of safety-level monitoring instruments acquired by the first control unit; for controlling the safety-level equipment, the safety-level control panel in the central control room can control the first redundant safety-level equipment.
[0121] When the central control room is available but the non-safety level system is unavailable or unreliable (e.g., earthquake, DCS power failure), and the post-processing plant is unable to maintain normal production, first activate ECP1 in the central control room and rotate the 2KAK*-001CC (safety / non-safety switch) on each sub-item panel to "safety level" operation. This prevents unreliable manual control signals from the non-safety level system from having unknown effects on the safety level control system. At this time, the 2KAK*-001LA (non-safety level operation mode allowed) indicator light will turn off, indicating that the DCS signal has been shielded by the ECP system. At the same time, the operator should abandon the non-safety level operator station OWPS and switch to ECP1 operation, which is also located in the central control room.
[0122] When the central control room becomes unavailable (e.g., due to a fire), the operator should immediately disable the operability of all operating stations within the central control room, then abandon the central control room and switch to the safety panel in the emergency monitoring room. This can be done via the switching knobs on ECP1 or ECP2: the "Safety / Non-Safety Switch" and the "Central Control Room / Emergency Monitoring Room Switch." Rotating the "Safety / Non-Safety Switch" to "Safety Level" and the "Central Control Room / Emergency Monitoring Room Switch" to "Emergency Monitoring Room" is both designed with a two-out-of-one logic. The operator operates the safety-level control system in the emergency monitoring room. At this time, ECP2 can display the readings of the two sets of safety-level instruments acquired by the second control unit, as well as the readings of the non-redundant safety-level equipment acquired by the first control unit. For the control of safety-level equipment, ECP2 can control the second redundant safety-level equipment, ultimately bringing the reprocessing plant to a safe shutdown state. Local operation is possible under design-based accidents such as fires or earthquakes in the central control room. However, local operation is not possible under accidents that may cause shielding failure, such as criticality or radiation leakage. The superposition of accidents is not considered in these two scenarios. In this embodiment, the above operations can be performed by personnel located in the central control room or emergency monitoring room, or by automated operating equipment / systems.
[0123] When a fire or other emergency in the safety-grade cabinet room renders safety-grade cabinet sequence 2 (i.e., the second control unit) unavailable, the automatic and manual control logic of safety-grade sequence 1 will be unavailable regardless of the current operating mode. In this situation, operation will be initiated by ECP1 in the central control room, and the sequence 2 equipment will be coordinated via dispatch telephone from the central control room, switching from local operation to shutdown or a safety-designed position.
[0124] When safety-level cabinet 1, i.e., sequence 1 (i.e., the first control unit), is unavailable, regardless of the current operating mode, the automatic and manual control logics of both the first redundant and non-redundant devices will be unavailable. At this time, for redundant safety-level devices, the operator should activate the second redundant safety-level devices. The control room will lose control of the non-redundant devices, and the devices in sequence 1 will be moved from local operation to shutdown or a designed safe position. In this embodiment, the non-redundant devices in the post-processing plant are all valves; even if the device cannot be operated locally, it will automatically be placed in the safe position due to the loss of power.
[0125] Example 3
[0126] The nuclear fuel reprocessing plant of this embodiment includes an equipment area, a habitable area, and the nuclear fuel reprocessing plant emergency shutdown system of Embodiment 2. The habitable area (CREZ) needs to be set up in both the on-site control center and the off-site emergency command center facilities. Therefore, this embodiment includes an on-site habitable area and an off-site habitable area. It can be used under design basis accident conditions, including fire, hazardous gas explosion or leakage, and radioactive contamination accidents. It is a necessary area set up to ensure that the environment in the area is still suitable for people to work and live, so as to ensure the health and safety of the public and plant staff.
[0127] The equipment area is equipped with safety-grade equipment, mainly including non-redundant equipment, primary redundant equipment, and secondary redundant equipment, whose general relationship is as follows: Figure 3 As shown, valve 1 is a non-redundant device in this block, valve 2 and pump 1 are the first redundant devices, and these three are controlled by sequence 1. Valve 3 and pump 2 are the second redundant devices, controlled by sequence 2. The nuclear fuel reprocessing plant emergency shutdown system is located within the habitable area of the plant and is used to monitor and control the equipment in the equipment area. The off-site habitable area is communicatively connected to the on-site habitable area to collect signals from the nuclear fuel reprocessing plant emergency shutdown system and to provide technical support to the on-site habitable area.
[0128] Specifically, such as Figure 4 As shown, the habitable area within the factory includes:
[0129] The central control room (MCR) is equipped with a safety-level (RS) emergency control console (ECP1, or first operating unit), a non-safety-level (NR) operator station (OWPS), a large screen system, communication and broadcasting terminals, telephone terminals, printers, etc. It is responsible for monitoring the measurement points and equipment of the entire plant's process and auxiliary systems. Operators are on duty here during normal operation and first-level fault modes.
[0130] Emergency monitoring room: serving as a backup for MCR, equipped with an emergency operating console (ECP2, or second operating unit), broadcast terminal and telephone terminal, and a level 2 fault mode operator on duty here.
[0131] Technical Support Center: Equipped with a technical support monitoring station and conference system, it provides technical support to operators in the central control room, helps them identify and resolve technical problems, and assists them in ensuring the safe and stable operation of the post-processing plant.
[0132] The off-site habitable area includes:
[0133] The Emergency Command Center, a dedicated emergency response facility within the nuclear fuel reprocessing plant, is responsible for the overall command and coordination of all emergency response actions within the plant during an accident emergency. It includes the Emergency Command Headquarters and the Operations Support Center. Its main sub-tasks are to monitor important safety parameters of the reprocessing plant's process systems, radiation monitoring data, environmental monitoring and meteorological data, accident consequence assessment results, etc., compare and judge these with the reprocessing plant's emergency response level, provide recommendations on the accident status level, and provide decision support for emergency command personnel.
[0134] An operation service center can also be set up outside the plant. The operation service center belongs to the production operation management facility of the post-processing plant. It is mainly responsible for the overall production operation management, resource scheduling and personnel scheduling of the plant. It mainly runs the production execution system (MES) and is located between business systems such as enterprise resource planning (ERP) and the underlying process control system (PCS). The MES system needs to collect some production operation signals from the PCS system in one direction for data analysis, so it undertakes some accident signal monitoring functions.
[0135] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A method for emergency shutdown of a nuclear fuel reprocessing plant, characterized in that, Includes the following steps: Acquire monitoring data from the equipment; Determine whether an accident state has been entered based on the monitoring data: If the system is determined to be in an accident state, it will then determine whether the currently running redundant safety-level device sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level device sequence is inconsistent with the current operating unit sequence, the running redundant safety-level device sequence will be switched to be consistent with the current operating unit sequence. The nuclear fuel reprocessing plant was shut down using a safety-grade system.
2. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 1, characterized in that, If it is determined that the system will not enter an accident state, it will operate as a non-safety-level system monitoring device.
3. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 1 or 2, characterized in that, The aforementioned control of the nuclear fuel reprocessing plant shutdown using a safety-level system specifically includes: The parking operation is achieved by operating the first redundant safety-level device through the first operating unit of the safety-level system or by operating the second redundant safety-level device through the second operating unit of the safety-level system. The step of determining whether the currently running redundant security-level device sequence is consistent with the current operating unit sequence of the security-level system, and switching the running redundant security-level device sequence to be consistent with the current operating unit sequence when they are inconsistent, specifically includes: If the current operating unit is the first operating unit, determine whether the currently running redundant security level device is the first redundant security level device, and if the currently running redundant security level device is not the first redundant security level device, switch the running redundant security level device to the first redundant security level device. If the current operating unit is the second operating unit, determine whether the currently running redundant security level device is the second redundant security level device, and if the currently running redundant security level device is not the second redundant security level device, switch the running redundant security level device to the second redundant security level device.
4. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 3, characterized in that, The parking operation, achieved by operating the first redundant safety-level device through the first operating unit of the safety-level system or by operating the second redundant safety-level device through the second operating unit of the safety-level system, specifically includes: Determine if the first operation unit is valid: When the first operating unit is determined to be valid, the control signal from the non-safety level system to the safety level system is shielded by the first operating unit to prevent the non-safety level system control equipment from operating, and the parking operation is realized by the first operating unit. When the first operating unit is determined to be invalid, the control signal from the non-safety level system to the safety level system and the first operating unit are blocked by the second operating unit to prevent the first operating unit and the non-safety level system control equipment from operating, and the parking operation is achieved through the second operating unit.
5. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 4, characterized in that, When it is determined that no accident state will be entered, the first and second operating units are disabled. When an accident is detected, both the first and second operating units are activated.
6. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 1, characterized in that, The process of determining whether an accident state has been entered based on monitoring data specifically includes: Determine whether an anomaly has occurred based on the monitoring data: If no abnormalities are found in the monitoring data, it is determined that the accident state will not be entered. If the monitoring data is abnormal, further investigation will be conducted to determine whether the safety function signals have been triggered: If not triggered, the repair operation will be performed and the system will be determined not to enter an accident state. If it has been triggered, it is determined that an accident state has been entered.
7. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 6, characterized in that, The acquisition of monitoring data from the equipment includes: acquiring monitoring data from the equipment simultaneously using two sets of monitoring instruments. The process of determining whether an anomaly has occurred based on monitoring data specifically includes: Determine whether there is an instrument malfunction based on the monitoring data obtained from the two sets of monitoring instruments. An anomaly is determined to have occurred when an instrument malfunctions and / or when the monitoring data from any set of monitoring instruments does not meet the first set conditions.
8. The emergency shutdown method for a nuclear fuel reprocessing plant according to claim 7, characterized in that, The monitoring data of the equipment obtained by using two sets of monitoring instruments simultaneously is the first monitoring data, and the two sets of monitoring instruments belong to the first monitoring unit. The second monitoring unit is also used to obtain the second monitoring data of the equipment. The method of determining whether an anomaly has occurred based on monitoring data also includes: If the second monitoring data does not meet the second set conditions, an anomaly is determined to have occurred.
9. An emergency shutdown system for a nuclear fuel reprocessing plant, characterized in that, include: The monitoring unit is used to acquire monitoring data from the equipment; The first judgment unit is electrically connected to the monitoring unit and is used to determine whether an accident state has been entered based on the monitoring data. The second judgment unit is electrically connected to the first judgment unit. When the first judgment unit determines that an accident state has been entered, it is used to determine whether the currently running redundant safety-level equipment sequence is consistent with the current operating unit sequence of the safety-level system. If the redundant safety-level equipment sequence is inconsistent with the current operating unit sequence, the running redundant safety-level equipment sequence is switched to be consistent with the current operating unit sequence. Safety-grade systems are used to control shutdowns at nuclear fuel reprocessing plants.
10. The nuclear fuel reprocessing plant emergency shutdown system according to claim 9, characterized in that: It also includes a non-safety level system, which is electrically connected to the first judgment unit and is used to monitor the operation of the equipment when the first judgment unit determines that it will not enter an accident state.
11. The nuclear fuel reprocessing plant emergency shutdown system according to claim 9 or 10, characterized in that: The operation unit of the security level system includes a first operation unit and a second operation unit, which are separately arranged in different positions. When the monitoring unit determines that no accident state has been entered, the first and second operating units are disabled; when the monitoring unit determines that an accident state has been entered, the first and second operating units are enabled. The first operating unit is used to shield the control signal from the non-safety level system to the safety level system when entering an accident state, so as to prevent the non-safety level system control equipment from operating and to realize the shutdown operation; The second operating unit is used to shield the control signals from the non-safety level system to the safety level system and the first operating unit when the first operating unit fails, so as to prevent the first operating unit and the non-safety level system control equipment from operating and to realize the stop operation.
12. The nuclear fuel reprocessing plant emergency shutdown system according to claim 10, characterized in that: Both the non-security level system and the security level system include control units. The control unit of the non-security level system is a non-security level control unit, and the control unit of the security level system includes a first control unit and a second control unit. The equipment includes a non-safety-level device, a non-redundant safety-level device, a first redundant safety-level device, and a second redundant safety-level device. The non-redundant safety-level device automatically enters a stop state when it loses its power source. The first control unit provides power and control commands to both the non-redundant safety-level device and the first redundant safety-level device; The second control unit provides power and control commands to the second redundant safety level equipment; The non-security level system is used to monitor the operation of non-security level devices through a non-security level control unit, and to monitor the operation of first redundant security level devices and non-redundant security level devices through a first control unit / monitor the operation of second redundant security level devices through a second control unit. The security level system is used to monitor the first redundant security level device and the second redundant security level device through the first control unit and the second control unit, so that only one of the first redundant security level device and the second redundant security level device is in operation at the same time.
13. A nuclear fuel reprocessing plant, characterized in that: Includes equipment areas, habitable areas, and the nuclear fuel reprocessing plant emergency shutdown system as described in any one of claims 9 to 12. The habitable area includes both on-site and off-site habitable areas. The nuclear fuel reprocessing plant's emergency shutdown system is located within the habitable area of the plant and is used to monitor and control equipment in the equipment area. The off-site habitable area is communicatively connected to the on-site habitable area, and is used to collect signals from the nuclear fuel reprocessing plant's emergency shutdown system and to provide technical support to the on-site habitable area.
Citation Information
Patent Citations
Accidence safety analysis method for nuclear fuel reprocessing plant
CN102841600A
Nuclear power station reactor protection system and safety control method therein
CN105575448A