A nuclear reactor protection system with built-in diversity
By adopting a system architecture configuration with built-in diversity, the problem of the RPS+DAS solution being unable to adapt to the compact design of small reactors is solved, and a compact, economical and efficient nuclear reactor protection system is realized that can cope with common cause failures.
Patent Information
- Application Number
- CN202411716173.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2044-11-27
AI Technical Summary
In the existing technology, the traditional RPS+DAS solution cannot perfectly adapt to the compact design requirements of small reactors. The system configuration is complex and the reliability is too high, which leads to over-design.
A system architecture configuration with built-in diversity is adopted, without setting up an additional DAS system. Through a system architecture with three sequences, local coincidence logic and two-level three-out-of-two voting, subgroups and devices with different technical routes are used to implement independent safety function driving paths and perform diversity verification.
A more compact and economical nuclear reactor protection system is achieved, which can effectively deal with common cause failures, adapt to the space requirements of small reactors, and reduce the response time of safety functions.
Smart Images

Figure CN119811723B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of nuclear reactor protection, and particularly relates to a nuclear reactor protection system with built-in diversity. BACKGROUND
[0002] The statements herein are provided only to complement the present application and do not necessarily constitute prior art.
[0003] Nuclear safety is the most critical factor in nuclear energy application, and the reactor protection system (RPS) as the safety-related part of the instrument and control system of nuclear facilities is the "safety guard" to ensure the safe operation of nuclear power plants. The RPS monitors the parameters directly related to the reactor and safety barriers throughout the life of the nuclear facility, and when the safety parameters monitored reach or exceed the preset protection action setting value, it executes safety functions such as emergency shutdown and dedicated safety facility driving to relieve the consequences of operating events or accidents and maintain the integrity of the safety barrier of the nuclear facility. A safe and reliable RPS can maximize the safety of the reactor when the nuclear facility is in an abnormal condition, and reduce the impact and consequences of events / accidents.
[0004] Compared with large-scale nuclear power plants, small nuclear power plants, research reactors, and ship reactors have new design characteristics, including: 1) small reactor power; 2) integrated or compact configuration, small layout space; 3) large coolant capacity; 4) full use of passive safety technology (natural circulation, gravity or pressure accumulation injection). Design characteristics 1), 3), and 4) make the above small reactors have the advantage of high inherent safety, and design characteristic 2) puts higher requirements on the occupied space of each system.
[0005] Currently, the RPS of large commercial nuclear power plants (such as the Gonghe No. 1 reactor, etc.) commonly used in the industry is generally implemented in a configuration mode of 4-redundancy sequence and 4-of-2 logic voting, and an additional diverse actuation system (DAS) is provided to provide the ability to execute backup emergency shutdown and dedicated safety facility driving functions to prevent common cause failure (common cause failure / fault: multiple failures due to the same cause) of the RPS. However, the traditional RPS+DAS scheme cannot perfectly adapt to the application requirements of small reactors. First, the system configuration scheme of RPS+DAS has high complexity and large scale, which cannot meet the design requirements of compactness of small reactors; second, small reactors have good inherent safety, and the system configuration scheme of RPS+DAS has relatively high reliability, which is over-designed. Therefore, it is necessary to carry out architecture design for the RPS of small reactors to meet the characteristics of compactness and high inherent safety of small reactors. SUMMARY
[0006] The present application aims to overcome the deficiencies in the prior art, and provide a nuclear reactor protection system with built-in diversity, which adopts a system architecture configuration with built-in diversity, does not need to additionally set up a DAS system, has better compactness, and is more suitable for the space requirements of small reactors; multiple subgroups use chips based on different technologies, adopt different architecture schemes, different development tools and logic design methods, have independent safety function driving paths, and use diverse means for verification and confirmation, which can effectively respond to the occurrence of common cause failures; compared with the traditional combination of RPS+DAS, it is simpler and has better economic characteristics, which is conducive to popularization and implementation.
[0007] In order to achieve the above-mentioned purpose, the present application is realized by the following technical scheme:
[0008] The technical scheme of the present application provides a nuclear reactor protection system with built-in diversity, which adopts a system architecture with three sequences, local coincidence logic, two-level two-out-of-three voting and two parallel processing technology routes;
[0009] Among them, the three sequences are three multiple sequences, each sequence is composed of multiple sub-sequences using different technology routes, and three sub-sequences using the same technology form a sub-group; each sub-group has the ability to independently execute safety functions;
[0010] The three sequences each contain a fixed value processing subsystem and a voting logic subsystem with the same number of sub-groups; two sequences each further contain a device control subsystem and a shutdown relay matrix;
[0011] The fixed value processing subsystem is used to receive sensor input signals of the sequence and perform fixed value comparison operations, and send the fixed value comparison results to the voting logic subsystem of the same sub-group in the three sequences;
[0012] The voting logic subsystem is used to receive the fixed value comparison results sent by the fixed value processing subsystem of the three sequences belonging to the same sub-group, perform two-out-of-three voting, and send the voting results to the device control subsystem or the shutdown relay matrix of the same sub-group, respectively;
[0013] The device control subsystem is used to receive the logic voting results sent by the three voting logic subsystems of the same sub-group, and perform two-out-of-three voting; when the voting is passed, a device trigger signal is sent to the actuator of the controlled device;
[0014] The shutdown relay matrix is used to receive system-level shutdown driving command signals from the three voting logic subsystems of the same sub-group and other systems, perform two-out-of-three relay logic voting, and send commands to the shutdown circuit breaker.
[0015] In at least one embodiment, the multiple setpoint processing subsystems of each sequence employ different technology routes; the multiple voting logic subsystems of each sequence employ different technology routes.
[0016] In at least one embodiment, the device control subsystems of the two sequences employ different technology routes; the trip relay matrices of the two sequences employ different technology routes.
[0017] In at least one embodiment, the device control subsystems generate system-level device trigger signals upon voting through, fan out device-level trigger signals, and finally send device trigger signals to the actuator of the controlled device through the device interface module.
[0018] In at least one embodiment, when the trip relay matrix sends a command to the trip breaker, the trip breaker connects the power supply loop of the control rod drive mechanism; when the breaker is opened, the control rod drive mechanism is powered off, and the control rod falls into the core due to gravity, completing the shutdown.
[0019] In at least one embodiment, each sequence is provided with independent field sensors, and the measurement signals collected by the field sensors are input to the setpoint processing subsystem of this sequence after data processing; the setpoint processing subsystem compares the measurement value with the set value; if the measurement value exceeds the preset set value, the setpoint processing subsystem will generate a local trip command triggered by the measurement value.
[0020] In at least one embodiment, each device control subsystem includes two two-out-of-three voting modules, each of which receives the two-out-of-three voting results from three voting logic subsystems of the same sub-group and performs two-out-of-three voting processing again; the voting results of the two two-out-of-three voting modules are respectively faned out as device-level trigger signals.
[0021] In at least one embodiment, each device interface module receives two device-level trigger signals respectively faned out by two two-out-of-three voting modules and performs two-out-of-two coincidence logic voting; when the coincidence logic meets, the device interface module sends the final device control command to the actuator of the device.
[0022] In at least one embodiment, the setpoint processing subsystem can also send the setpoint comparison result directly to the trip relay matrix for coincidence logic voting.
[0023] In at least one embodiment, the device control subsystems of the two sequences respectively control two mutually redundant special safety devices in the nuclear power plant system, and any special safety device drive has the ability to completely mitigate the corresponding accident, meeting the single failure criterion.
[0024] The beneficial effects of the technical solutions of the present application are as follows:
[0025] 1) The nuclear reactor protection system with built-in diversity has a system architecture configuration with built-in diversity, does not need to additionally set a DAS system, has better compactness, and is more suitable for the space requirement of a small reactor.
[0026] 2) The nuclear reactor protection system with built-in diversity has three multiple sequences, the sequences are physically and electrically isolated, and from top to bottom include a fixed value logic layer, a compliance logic layer, and a device driving layer, to realize two-level 2 / 3 voting; each sequence is composed of two sub-sequences of devices using different technical routes, three sub-sequences of the same technology constitute a sub-group, the sub-groups are functionally independent, and each sub-group can independently complete emergency shutdown and special driving functions. Each sub-group uses chips based on different technologies, adopts different architecture schemes, different development tools and logic design methods, has an independent safety function driving path, and uses a diversity means for verification and confirmation, which can effectively respond to the occurrence of common cause failures.
[0027] 3) The nuclear reactor protection system with built-in diversity is aimed at the nuclear power high shutdown function path, the fixed value comparison is realized in the nuclear measurement system, and the voting logic is realized in the RTM of two DERPS two sub-groups, which reduces the response time of the safety function in the DERPS to execute analog-to-digital conversion and signal processing.
[0028] 4) The nuclear reactor protection system with built-in diversity is simpler than the traditional combination of RPS+DAS, has better economic characteristics, and is conducive to popularization and implementation. BRIEF DESCRIPTION OF DRAWINGS
[0029] The drawings accompanying the specification of the present application serve to provide a further understanding of the present application, and the illustrative embodiments of the present application and their descriptions serve to explain the present application, and do not constitute an improper limitation on the present application.
[0030] Figure 1 is a schematic diagram of the three processing layers of the nuclear reactor protection system with built-in diversity of the present application from top to bottom;
[0031] Figure 2 is a schematic diagram of the three physical sequences and sub-sequences of the nuclear reactor protection system with built-in diversity of the present application;
[0032] Figure 3 is a schematic diagram of the two sub-groups of the nuclear reactor protection system with built-in diversity of the present application;
[0033] Figure 4is a sequence angle system architecture and signal flow chart of a nuclear reactor protection system with built-in diversity;
[0034] Figure 5 is a sub-group angle system architecture and signal flow chart of a nuclear reactor protection system with built-in diversity;
[0035] Figure 6 is a nuclear power high shutdown function execution method schematic diagram of a nuclear reactor protection system with built-in diversity;
[0036] Figure 7 is a special safety facility drive function execution method schematic diagram of a nuclear reactor protection system with built-in diversity. DETAILED DESCRIPTION
[0037] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the application. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs.
[0038] Term explanation:
[0039] RPS: Reactor Protection System;
[0040] DAS: Diverse Actuation System;
[0041] Common cause failure: multiple failures due to the same cause;
[0042] DERPS: Diversity-Embeded Reactor Protection System;
[0043] Sequence: the name of a given system group or device group, which can be (with) other redundant device groups independent in entity, electrical and functional;
[0044] Local coincidence logic: the two-state logic output signal of each protection parameter of the redundant instrument channel is voted first, and the processed output signal is subjected to "n takes 1" coincidence logic with other similarly processed output signals;
[0045] 3 out of 2 (2oo3) voting: two of the three two-state inputs (0 or 1) are 1, then the output is 1;
[0046] BL: fixed value processing subsystem;
[0047] VL: voting logic subsystem;
[0048] CL: device control subsystem;
[0049] RTM: reactor trip matrix;
[0050] fan-out: to split a system-level trigger signal that drives multiple devices simultaneously into individual device trigger signals;
[0051] device interface module: the interface between RPS and the controlled device actuator, which implements priority selection logic and device driving logic, and belongs to RPS;
[0052] channel: a configuration of components and devices needed to produce a single protection action signal when required by the operating condition of the nuclear power plant. A channel ends at the junction of each single protection action signal.
[0053] As introduced in the background art, the purpose of the present application is to overcome the shortcomings of the prior art, and to provide a nuclear reactor protection system with built-in diversity, which adopts a system architecture configuration with built-in diversity, does not need to additionally set up a DAS system, has better compactness, and is more suitable for the space requirements of small reactors; multiple subgroups use chips based on different technologies, adopt different architecture schemes, different development tools and logic design methods, have independent safety function driving paths, and use diversity means for verification and confirmation, which can effectively deal with common cause failures; compared with the traditional combination of RPS+DAS, it is simpler and has better economic characteristics, which is conducive to popularization and implementation.
[0054] Embodiment 1
[0055] The embodiment discloses a nuclear reactor protection system with built-in diversity, which adopts a system architecture with three sequences, local coincidence logic, two-level two-out-of-three voting, and two parallel technology routes;
[0056] Among them, the three sequences are three multiple sequences, each sequence is composed of multiple sub-sequences of devices using different technology routes, and three sub-sequences using the same technology form a subgroup; each subgroup has the ability to independently execute safety functions;
[0057] Each of the three sequences contains a fixed value processing subsystem and a voting logic subsystem with the same number as the number of subgroups; two sequences each further contain a device control subsystem and a reactor trip matrix;
[0058] The fixed value processing subsystem is used to receive sensor input signals of the sequence and perform fixed value comparison operations, and send the fixed value comparison results to the voting logic subsystem of the same subgroup in the three sequences;
[0059] The voting logic subsystem is used to receive the value comparison results sent by the value processing subsystem of the three sequences in the same subgroup, perform 2 out of 3 voting, and send the voting results to the device control subsystem or the trip relay matrix in the same subgroup, respectively;
[0060] The device control subsystem is used to receive the logic voting results sent by the three voting logic subsystems in the same subgroup, and perform 2 out of 3 voting; when the voting is passed, a device trigger signal is sent to the actuator of the controlled device;
[0061] The trip relay matrix is used to receive the system-level trip driving command signals from the three voting logic subsystems in the same subgroup and other systems, and after performing 2 out of 3 relay logic voting, send a command to the trip circuit breaker.
[0062] In this embodiment, three sequences A, B, and C and two subgroups are described in detail.
[0063] The system architecture of the nuclear reactor protection system with built-in diversity in this embodiment has the following characteristics:
[0064] (1) The three multiple sequences A, B, and C are physically and electrically isolated, and include three processing layers from top to bottom, i.e., value logic layer, coincidence logic layer, and device driving layer, as shown in Figure 1 . Among them, the value logic layer includes a value processing subsystem (BL), the coincidence logic layer includes a voting logic subsystem (VL), and the device driving layer includes a device control subsystem (CL), a trip relay matrix (RTM), and a trip circuit breaker.
[0065] (2) Each sequence is composed of two sub-sequences (sub-sequence I and sub-sequence II) of different technical route devices, as shown in Figure 2 . Three sub-sequences of the same technology form a subgroup (subgroup I and subgroup II), as shown in Figure 3 . The two subgroups are designed to be diverse and functionally independent, and each subgroup can independently complete the output of the device control signal from signal acquisition, and has the ability to independently execute safety functions, i.e., built-in diversity.
[0066] (3) Local coincidence logic is used, i.e., value comparison and 2oo3 voting are performed on the same parameter first, and then the "or" of the functionally related voting results is taken to generate the final driving signal.
[0067] The above two subgroups with different technologies have the following characteristics:
[0068] (1) Based on two different types of chips developed and manufactured by different manufacturers, the two chips have different underlying architectures and operating mechanisms;
[0069] (2) Different architectural approaches are used, including input-output (I / O) and functional logic distribution;
[0070] (3) Different development tools and logic design methods are used;
[0071] (4) No signal transmission between the two subgroups on the safety function driving link, with independence;
[0072] (5) Independent verification and validation are implemented by means with diversity from development activities.
[0073] Therefore, the DERPS of the embodiment does not have a credible potential common cause failure mechanism that causes the two subgroups to fail simultaneously, and does not need to additionally set up a DAS.
[0074] In the embodiment, the three sequences A, B and C each include two set value processing subsystems (BL-X1 and BL-X2, X is A, B or C, corresponding to the three sequences A, B and C) using different technical route devices and two voting logic subsystems (VL-X1 and VL-X2, X is A, B or C, corresponding to the three sequences A, B and C) using different technical route devices. The sequence A and the sequence B each include one device control subsystem, which are CL-A1 and CL-B2 respectively, and the two use different technical route devices. The sequence A and the sequence B each further include one reactor trip matrix (RTM), which are RTM-A2 and RTM-B1 respectively, and the two use different technical route devices.
[0075] The set value processing subsystem (BL) is mainly used to receive input from field sensors to obtain sensor input related to reactor trip and dedicated safety facility driving function, and to calculate or logically operate the obtained sensor input to confirm whether there is an abnormal condition of the reactor. BL-X1 and BL-X2 share the field sensor input signals of the sequence and perform the same data processing and set value comparison operation. After the operation is completed, the BL forms a local trigger signal from the set value comparison result and further sends it to the VL of the same subgroup to which the three sequences belong.
[0076] The voting logic subsystem (VL) is mainly used to determine whether to execute the reactor trip function through control logic and voting. The VL receives the local trigger (set value comparison result) signal sent by the BL of the three sequences belonging to the same subgroup, performs a two-out-of-three (2oo3) voting, and sends the voting result to the CL or the RTM of the same subgroup, respectively. The logic voting result is the system-level dedicated safety facility driving command signal.
[0077] The device control subsystem (CL) primarily determines whether to execute the dedicated safety facility actuation function through control logic and compliance voting. The CL receives system-level dedicated safety facility actuation command signals from the three VLs in the same subgroup and performs a 2oo3 vote. If the vote passes, a system-level device trigger signal is generated. This signal is then fanned out to generate a device-level trigger signal, which is ultimately transmitted through the device interface module to the actuator of the controlled device.
[0078] The trip relay matrix (RTM) is primarily used to determine whether to execute the designated safety feature actuation function through control logic and compliance voting. Serving as the interface between the DERPS cabinet and the trip circuit breaker, the RTM receives system-level trip actuation command signals from the three VLs belonging to the same DERPS subgroup, as well as from other systems. After executing a 2oo3 relay logic vote, it transmits the command to the trip circuit breaker. The trip circuit breaker is connected to the power circuit of the control rod drive mechanism. When the circuit breaker is opened, the control rod drive mechanism is de-energized, and the control rods fall into the core due to gravity, completing the trip.
[0079] like Figure 4 and Figure 5 As shown, DERPS monitors the critical safety parameters of nuclear facilities and their auxiliary facilities. When a selected safety parameter reaches or exceeds a preset first-stage protection action setting, DERPS automatically issues a trip trigger signal, opening the trip circuit breaker. Furthermore, DERPS is used to limit the consequences of anticipated operational events and design basis accidents. When a selected critical safety parameter reaches a preset second-stage protection action setting, indicating a breach in the integrity of a portion of the nuclear facility's safety barriers, DERPS issues a trip command and then a device-driven command to activate the corresponding dedicated safety devices.
[0080] In this embodiment, when the DERPS performs a reactor scram, it uses three measurement channels / sequences for each shutdown variable, each equipped with an independent field sensor. Each of the three DERPS channels receives signals from the corresponding field sensors. The BL processes the sensor signals and compares the measured values with the preset setpoints for the variables. If the BL measurement value of a channel exceeds the preset setpoint, the BL generates a local shutdown command triggered by that variable. Each sequence's BL transmits the local shutdown signal via an isolated data link to the VLs of that sequence and the other two sequences in the same subgroup. The VLs then perform a coincidence logic vote. When the VL meets the 2oo3 trigger condition, it transmits a system-level shutdown actuation command to the RTM of sequence A or B (the other RTM receives the system-level shutdown actuation command from the three VLs in the other subgroup). The RTM performs a 2oo3 relay logic vote to generate a final shutdown signal, triggering the trip circuit breaker controlled by that sequence.
[0081] like Figure 6 As shown in the figure, in order to reduce the response time of the high-power shutdown protection function of some small reactors to the high-power shutdown protection function performed by DERPS, the fixed value comparison function of the high-power shutdown function is placed in the nuclear measurement system. After the fixed value comparison function is executed, the nuclear measurement system directly sends the fixed value comparison result to RTM-B1 and RTM-A2 for logical voting, which reduces the time for sensor input signals to be processed by DERPS.
[0082] In this embodiment, when the DERPS performs the dedicated safety feature actuation function, its three measurement channels utilize independent field sensors (these sensors may monitor the same variables as the trip function). Each of the three DERPS channels receives signals from the corresponding field sensors. After necessary processing, the BL compares the measured values with the set values of the variables. When the measured values exceed the set values, the BL generates a channel-local trigger signal and sends it to the VLs of this sequence and the other two sequences for coincidence logic voting. When the VL's coincidence logic satisfies the 2oo3 condition, the VL sends the system-level dedicated safety feature actuation command to the CL.
[0083] like Figure 7 As shown, the CLs of sequences A and B of the DERPS exhibit diverse design. Each CL includes two 2oo3 voting modules, each receiving the 2oo3 voting results of three VLs from the same subgroup and performing a further 2oo3 process. The voting results (i.e., system-level device trigger signals) generated by the two 2oo3 voting modules are fanned out as device-level trigger signals. Each device interface module receives the device-level trigger signals fanned out by the two 2oo3 voting modules (each controlled device has a corresponding device interface module) and executes the 2oo2 coincidence logic. When the coincidence logic is satisfied, the device interface module sends the final device control command to the device's actuator. In this embodiment, the two sequences of CLs control two redundant dedicated safety devices in the nuclear facility process system. Each dedicated safety device driver has the ability to fully mitigate the corresponding accident, meeting the single failure criterion.
[0084] In this embodiment, the workflow of the nuclear reactor protection system with built-in diversity is as follows:
[0085] (1) Three sequences of sensors monitor safety-related parameters of the nuclear power plant and transmit the monitoring results to the DERPS for executing emergency shutdown or driving of dedicated safety facilities;
[0086] (2) BL-A1 and A2, BL-B1 and B2, BL-C1 and C2 of DERPS receive signals from corresponding sensors and perform engineering unit conversion and value comparison processing respectively;
[0087] (3) VL-A1, VL-B1, VL-C1 of DERPS receive value comparison results from BL-A1, BL-B1, BL-C1 of the same sub-group, and further perform logic voting processing.
[0088] (4) CL-A1 of DERPS receives logic voting results from VL-A1, VL-B1, VL-C1 of the same sub-group, and further performs logic voting, finally outputs device control command to the execution structure of A column dedicated safety device;
[0089] (5) CL-B2 of DERPS receives logic voting results from VL-A2, VL-B2, VL-C2 of the same sub-group, and further performs logic voting, finally outputs device control command to the execution structure of B column dedicated safety device;
[0090] (6) RTM-A2 of DERPS receives logic voting results from VL-A2, VL-B2, VL-C2 of the same sub-group, and further performs logic voting, finally outputs trip command to trip breakers RTA1 and RTA2.
[0091] (7) RTM-B1 of DERPS receives logic voting results from VL-A1, VL-B1, VL-C1 of the same sub-group, and further performs logic voting, finally outputs trip command to trip breakers RTB1 and RTB2.
[0092] Embodiment 2
[0093] On the basis of embodiment 1, the number of diversity sub-groups in the above embodiment 1 is still 2, and the number of 3 sequences can be N sequences, wherein the value of N is 2 or 3 or 4 or 5, etc. The voting logic executed in VL and CL changes with the number of configured sequences.
[0094] Embodiment 3
[0095] On the basis of embodiment 1, the number of 2 diversity sub-groups in the above embodiment 1 can be M sub-group numbers, wherein M≥2, each sub-group has the ability to independently complete emergency shutdown and dedicated safety facility driving, achieving the effect of canceling the diversified driving system.
[0096] Embodiment 4
[0097] On the basis of embodiment 1, the number of layers and the boundary range in the above embodiment 1 are adjusted, which can be merged from 3 layers to 2 layers, or decomposed into 4 layers.
[0098] Example 5
[0099] On the basis of the embodiment 1, the device control subsystem (CL) of each subgroup in the above-mentioned embodiment 1 has the ability to drive a column of special safety devices is adjusted to set a plurality of device control systems to control a column of special safety devices.
[0100] The above only the preferred embodiments of the present application have, and not for limiting the present application, for those skilled in the art, the present application can have various changes and variations. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present application, should be included in the protection scope of the present application.
Claims
1. A nuclear reactor protection system with built-in diversity, characterized in that, The system architecture adopts three sequences, local coincidence logic, two-level three-out-of-two voting and two technical routes in parallel processing; The three sequences are three multiple sequences, each sequence is composed of multiple sub-sequences using equipment of different technical routes, and three sub-sequences using the same technology form a sub-group; each sub-group has the ability to independently execute safety functions; Each sequence contains a constant value processing subsystem and a voting logic subsystem with the same number of sub-groups; two sequences each further contain a device control subsystem and a trip relay matrix; The constant value processing subsystem is used to receive sensor input signals of the sequence and execute constant value comparison operations, and send the constant value comparison results to the voting logic subsystem of the same sub-group in the three sequences; The voting logic subsystem is used to receive the constant value comparison results sent by the constant value processing subsystem of the same sub-group in the three sequences, execute three-out-of-two voting, and send the voting results to the device control subsystem or the trip relay matrix of the same sub-group, respectively; The device control subsystem is used to receive the logical voting results sent by the three voting logic subsystems of the same sub-group, and execute three-out-of-two voting; when the voting is passed, a device trigger signal is sent to the actuator of the controlled device; The trip relay matrix is used to receive system-level trip drive command signals from the three voting logic subsystems of the same sub-group and other systems, execute three-out-of-two relay logic voting, and send commands to the trip circuit breaker.
2. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, The multiple constant value processing subsystems of each sequence use different technical route equipment; the multiple voting logic subsystems of each sequence use different technical route equipment.
3. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, The device control subsystems of the two sequences use different technical route equipment; the trip relay matrices of the two sequences use different technical route equipment.
4. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, The device control subsystem generates a system-level device trigger signal when the voting is passed, then fan-out to generate a device-level trigger signal, and finally sends a device trigger signal to the actuator of the controlled device through the device interface module.
5. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, When the trip relay matrix sends a command to the trip circuit breaker, the trip circuit breaker connects the power supply circuit of the control rod drive mechanism; when the circuit breaker is opened, the control rod drive mechanism is powered off, and the control rod falls into the core due to gravity, completing the shutdown.
6. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, Each sequence is provided with an independent field sensor, the measured value signal collected by the field sensor is input to the constant value processing subsystem of the sequence after data processing, and the constant value processing subsystem compares the measured value with the set value; If the measured value exceeds the preset set value, the constant value processing subsystem will generate a local trip command triggered by the measured value.
7. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, Each device control subsystem includes two three-out-of-two voting modules, each voting module receives the three-out-of-two voting results of the three voting logic subsystems of the same sub-group, and performs three-out-of-two voting processing again; the voting results generated by the two three-out-of-two voting modules are respectively fan-out as device-level trigger signals.
8. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, Each device interface module receives two 2-out-of-3 voting module respectively fan-out device level trigger signals, and performs 2-out-of-3 compliance logic voting; when the compliance logic satisfies, the device interface module sends the final device control command to the device's actuator.
9. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, The set value processing subsystem can also send the set value comparison result directly to the trip relay matrix for compliance logic voting.
10. A nuclear reactor protection system having built-in diversity as defined in claim 1 wherein, The two sequence device control subsystems respectively control two mutually redundant special safety devices in the nuclear construction process system, and any special safety device drive has the ability to completely relieve the corresponding accident, satisfying the single fault criterion.
Citation Information
Patent Citations
Diversified driving system
CN118192361A
Digital reactor protecting system based on parallel hardware and software treatment
CN1289127A