Nuclear power risk analysis method combining internal event probabilistic safety analysis and power generation risk assessment

By combining PSA and GRA methods, an integrated modeling process is constructed to identify and comprehensively analyze initiating events in nuclear power plants. This solves the problem of insufficient analysis by a single method, improves the safety and economy of nuclear power plants, and provides scientific decision support.

CN121010201APending Publication Date: 2025-11-25HARBIN ENG UNIV +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510909826.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-11-25

AI Technical Summary

Technical Problem

Existing single PSA or GRA methods in nuclear power plant analysis suffer from insufficient analysis results and redundant analysis of the target range, resulting in a large workload, low efficiency, and difficulty in achieving a balance between the safety and economy of nuclear power plants.

Method used

By combining internal event probabilistic safety analysis with power generation risk assessment, and through an integrated modeling process, we identify the initiating events of nuclear power plants, construct event tree and fault tree models, conduct comprehensive analysis, identify risk factors and consequences, and optimize the design and operation of nuclear power plants.

Benefits of technology

It has achieved a dual improvement in the safety and economy of nuclear power plants, provided more scientific decision support, reduced redundant analysis, and improved analysis efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121010201A_ABST
    Figure CN121010201A_ABST
Patent Text Reader

Abstract

The invention discloses a nuclear power risk analysis method combining internal event probabilistic safety analysis and power generation risk assessment, and the method comprises the steps: S1, determining an internal originating event of a nuclear power plant, and determining an analysis boundary range; s2, analyzing the originating event sequence, and determining a response process and a corresponding success criterion; s3, constructing a power generation risk event tree model; s4, aiming at the event sequence in the S3, constructing a kernel security risk event tree model through a probabilistic security analysis method; and S5, selecting the system fault tree model in the model in the step S4 to carry out FMEA (Failure Mode and Effect Analysis), FMEA (Failure Mode and Effect Analysis), FMEA (Function Event Fault Tree Analysis), FMEA (Function Event Fault Tree Analysis), FMEA (Function Event Fault Tree Analysis) and correlation analysis. According to the technical scheme, the problem that analysis results of a single PSA or GRA nuclear power plant are insufficient is solved, comprehensive analysis of probability safety analysis and power generation risk analysis of the nuclear power plant is achieved while the workload is reduced and the analysis efficiency is improved by combining the two analysis methods, decision support is provided for design, operation and management of the nuclear power plant, and safety and economical efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The technical solution of the present application belongs to the field of nuclear power system safety analysis and evaluation, and in particular, after the combination of the nuclear power internal event probabilistic safety analysis (PSA) and the generation risk assessment (GRA) in the nuclear power safety analysis and evaluation system, the safety of the nuclear power plant, nuclear power device or other similar complex system under the working mode of multiple working conditions is efficiently analyzed and evaluated, and more scientific and reasonable decisions are provided for the design, operation and management of the entire nuclear power system, that is, a nuclear power risk analysis method combining internal event probabilistic safety analysis and generation risk assessment. BACKGROUND

[0002] The probabilistic safety assessment (PSA) method is used for safety performance evaluation of nuclear power plants, which is a supplement to the deterministic safety evaluation and has been widely recognized by the nuclear power industry. This method has played an important role in guiding the design, safety review and operation management of nuclear power plants. Through the PSA method, the core damage frequency (CDF) or the large early release frequency (LERF) of the plant and the key risk factors can be obtained, and the system design scheme comparison and the basis for the development and modification of the regulations are provided, so as to realize the balance between safety and economy. In the history of nuclear energy development, the three major nuclear accidents of Three Mile Island, Chernobyl and Fukushima have deeply reshaped the safety concept of the nuclear energy industry. The PSA method has built a complete safety analysis framework, and its risk evaluation method has been widely and universally applied. In the state of the increasingly perfect safety evaluation, the market-oriented reform of power supply and demand promotes the participation of nuclear power units in power peak shaving, and the economic indicators of power generation have become an important factor affecting the sustainable development of the industry. The generation risk assessment (GRA) commonly used in the power generation process is mainly applied to the analysis of power generation economy. How to balance the dynamic demand of the safety of nuclear power operation and the economic benefit of nuclear power generation, and use GRA as an innovative tool for quantitative economic risk and optimized operation decision-making, its theoretical value and practical significance are increasingly significant.

[0003] Due to the commonality of the PSA and the GRA method, both are quantitatively calculated by the event tree-fault tree method, based on the nuclear power plant design, operation data, and combined with the analysis object range to establish a model to obtain the safety risk and the power generation risk of the nuclear power plant, which provides a train of thought for the fusion of the two models for comprehensive evaluation of the nuclear power risk. The nuclear power risk evaluation method of fusing the two models breaks through the limitations of single model analysis, and comprehensively considers the safety risk and the economic risk to realize the dual improvement of the safety performance and the economic benefit of the nuclear power plant. The present application is based on this to make innovations in the analysis model and the method, reduces the repetitive work caused by the partial overlap of the analysis range when the two methods are separately analyzed, improves the efficiency of the risk analysis, and creates a technical route for comprehensive analysis of the nuclear power. SUMMARY

[0004] The purpose of the present application is to make up for the insufficient analysis results of the single PSA or GRA in the nuclear power plant, and solve the repeated analysis problem of the target range when the two methods are used together. By combining the two analysis methods, an integrated modeling process for internal event risk analysis is proposed, which can reduce the workload, improve the analysis efficiency, and realize the comprehensive analysis of the probabilistic safety analysis and the power generation risk analysis of the nuclear power plant. A safety characteristic analysis method is provided for the nuclear power plant, which is used for comprehensive evaluation of the safety and the economy during the operation of the nuclear power plant, and can provide decision support for the design, operation and management of the nuclear power plant, and improve the safety and the economy of the nuclear power plant.

[0005] To achieve the above-mentioned purpose of the application, a nuclear power risk analysis method combining internal event probabilistic safety analysis and power generation risk assessment is provided, and the specific technical scheme steps of the method are as follows:

[0006] S1, determining the internal initiating event of the nuclear power plant and clearly defining the analysis boundary range; the initiating event here refers to any event that disturbs the stable operation state of the nuclear power plant and causes an abnormality;

[0007] S2, analyzing the initiating event sequence, determining the response process and the corresponding success criteria; the response process here refers to the mitigation response of the nuclear power plant determined for each initiating event, that is, the related system is required to perform the related function to prevent the occurrence of the undesired event result; the setting or operation of the related function performed by the related system is the success criteria;

[0008] S3, constructing a power generation risk event tree model, that is, constructing an event tree structure model based on the initiating event and the initiating event sequence analysis; identifying all the consequences of the event sequence based on the model and finding out the corresponding sequence for the consequences;

[0009] S4, for all the found event sequences in S3, build a nuclear safety risk event tree model by probabilistic safety analysis method; the model contains but is not limited to the success or failure of each safety system, support system and personnel action in performing safety functions;

[0010] S5, select the system fault tree model in S4 model for Failure Mode and Effects Analysis (FMEA), initiating event fault tree analysis, functional event fault tree analysis and correlation analysis to realize nuclear power risk analysis.

[0011] The internal initiating event of the nuclear power plant in S1 above is analyzed by engineering analysis method to identify the initiating event that may be caused by operation failure. The list of initiating events formed here includes all and partial failure of functions or systems.

[0012] The success criteria in S2 above are determined according to the minimum requirement of each event sequence for its functional performance level; when the system has multiple redundant columns, the success criteria are determined as the number of required operating columns; if the safety function involves multiple safety systems with diversified settings, the success criteria should consider the performance requirements of each system respectively, and consider the partial operation of each system based on the best estimated analysis results.

[0013] The event tree model structure in S3 above is to consider the sequence of the header event representing the operator action and system action, and the specific method is to model in sequence according to the time sequence required for the system or operator, and the event tree model structure also considers the functional or physical correlation caused by equipment failure or personnel error; in the event sequence analysis, all the related combinations of the success or failure of each safety system in the event tree are analyzed to model all the sequences with successful or failed consequences, and the sequence termination state of the event sequence identified by the power generation risk event tree model is divided into three categories: (a) completely perform all the required power generation functions, thereby reducing power operation and shutdown, i.e. original power operation (OK); (b) unable to successfully restore the original power, only able to maintain low power operation (LP); (c) unable to maintain low power stable operation after the accident, thereby safely shutting down (SD); (d) unable to maintain low power stable operation after the accident, and unable to safely shut down, resulting in damage (CD).

[0014] The nuclear safety risk event tree model structure in S4 is to consider the sequence of the initiating event representing the action of the operator and the system, and the specific method is to model the sequence according to the time required by the system or the operator, and to consider the correlation in function or entity caused by equipment failure or personnel error; when analyzing the event sequence, all relevant combinations of the success or failure of each safety system in the event tree are analyzed to model all sequences with successful or failed consequences; the sequence termination state of the event sequence of the nuclear safety risk event tree model is divided into two categories: (A) all necessary safety functions are completely executed, thereby avoiding core damage, i.e. safe shutdown (SD); (B) core damage (CD) is assumed to occur due to the failure of one or more safety functions.

[0015] The initiating event fault tree analysis in S5 is to analyze the initiating event alone, construct a logic model from the equipment failure to the occurrence of the initiating event, including top-level logic construction and system analysis; the functional event fault tree analysis is a logical modeling analysis process of the failure state of the front system, safety system and support system involved in the event sequence analysis; the correlation analysis is to identify the failure function correlation between systems in the model by using the correlation matrix, to identify the situation of the common cause failure of the redundant equipment group, to evaluate the rationality and common cause failure probability of the common cause failure probability of the equipment failure mode. When performing event tree and fault tree method analysis, the logic model (event tree and fault tree) of each initiating event group is subjected to Boolean logic operation, and before quantitative calculation of the model, it is necessary to ensure that there is no logic loop in the model; if there is a logic loop, the loop should be resolved before quantization, and the original correlation should be preserved as much as possible.

[0016] The beneficial effects of the present application are: (1) based on PSA and GRA, an integrated nuclear power plant accident analysis modeling method is given, which makes up for the insufficient analysis of traditional single PSA or GRA method in analyzing nuclear power plant accidents, and obtains the nuclear safety risk and power generation risk of the nuclear power plant, and through the comprehensive analysis of the two kinds of risks, provides support for the risk-based nuclear power plant design, operation and management decision support, optimizes the design, operation and management of the nuclear power plant, and finally improves the safety and economy of the nuclear power plant; (2) the method has wide applicability and can be used to analyze and calculate the safety risk and power generation risk of most nuclear power plant accidents; (3) the method is versatile and can be used for nuclear power plant accident risk analysis, and is also applicable to nuclear power device accident risk analysis; (4) the comprehensive analysis method provides a method fusion idea for subsequent more comprehensive nuclear power evaluation and analysis. BRIEF DESCRIPTION OF DRAWINGS

[0017] Figure 1 A nuclear power plant power generation risk event tree model schematic diagram;

[0018] Figure 2 Nuclear power plant nuclear safety risk event tree model schematic diagram;

[0019] Figure 3 Initiating event fault tree modeling process schematic diagram;

[0020] Figure 4 Basic event coding rule example diagram. DETAILED DESCRIPTION

[0021] In order to make the technical solutions of the present application more specific, the following will describe the specific model scheme in combination with the nuclear power plant equipment probabilistic safety analysis and power generation risk analysis. In the implementation process of the present application, firstly, the nuclear power plant internal initiating event needs to be determined, and the analysis boundary range is clarified. The starting point of integrated risk modeling analysis is to identify the initiating event. The initiating event in the present scheme refers to any event that disturbs the stable operation state of the nuclear power plant and causes abnormality, which may lead to turbine trip or reactor trip. For example, nuclear power plant internal events that cause high turbine vibration or loss of coolant accident (LOCA, Loss of Coolant Accident). The initiating event requires the nuclear power plant mitigation system and personnel to respond correctly, and once the response fails, it may cause undesirable consequences, such as turbine trip or core damage. Systematically identify the initiating event to be analyzed, through deductive analysis, adopt a method similar to fault tree (for example, main logic diagram), take undesirable consequences (for example, failure to maintain original power operation or core damage) as the top event, and gradually decompose into events of different categories that may cause the consequences, and select the initiating event to be analyzed from each event at the bottom. In the analysis, engineering analysis method can be used to analyze all systems (appropriate screening can be carried out before detailed analysis, i.e. related front-end systems, safety systems, support systems), to identify the initiating events (or secondary failures that may cause initiating events) that may be caused by operation failures (total or partial failures) of the systems. The list of initiating events here should include total and partial failures of functions or systems, for example, reduction of feedwater flow of multiple steam generators or loss of feedwater flow of a single steam generator, and complete loss of feedwater flow of all steam generators. Because partial equipment failure may cause the function maintained by the equipment to fail to meet the requirement of the nuclear power plant to maintain current power for continuous stable operation, it may also significantly contribute to the risk.

[0022] After the above step is completed, the response procedure and corresponding success criteria are determined for the initiating event sequence. After the initiating event is determined, the mitigation response of the nuclear power plant for each initiating event group needs to be determined, i.e. the relevant systems are required to perform relevant functions to prevent the occurrence of undesired events; for example, the safety systems perform safety functions to prevent the core damage; the front-line systems perform relevant functions to maintain the original power operation. The safety functions usually include reactor shutdown and keeping it subcritical, the export of the residual heat of the core, the containment of radioactivity, etc.; the relevant functions of the front-line systems usually include maintaining low-power operation, restoring the original power, etc. The functional events contained in the event sequence are used to represent the success or failure of the safety system or personnel action required for the execution of the safety function and to represent the success or failure of the system, device or personnel action required to maintain the nuclear power plant at a lower power or restore the original power level. The final state of the event sequence is to restore to the original power level, abnormal operation, shutdown, core damage. Before determining the success criteria, the system functions required to be performed to maintain the low-power operation, the system functions required to be performed to restore to the original power operation, and the safety functions required to be performed to prevent the core damage are determined for each initiating event group. The required functions depend on the type of reactor and the nature of the initiating event, and usually include: (1) detection of the initiating event; (2) reducing the power and maintaining low-power operation; (3) restoring to the original power; (4) emergency shutdown; (5) shutdown and keep subcritical; (6) export of the residual heat of the core; (7) integrity of the reactor coolant system pressure boundary and containment. At the same time, the system and operator actions required to perform each function should be determined, including the success criteria of each safety system. Among them, the success criteria of the system should be determined according to the minimum requirement of each sequence for its function performance level. When the system has multiple redundant columns, the success criteria should be determined for the number of required operating columns; if the safety function involves multiple safety systems with diversified settings, the success criteria should consider the performance requirements required by each system respectively, at which time the partial operation of each system can be considered based on the best estimate analysis result. The safety system whose failure is caused by the occurrence of the initiating event, or the safety-related equipment which is in a severe environmental condition due to the occurrence of the initiating event, should be identified and considered when determining the success criteria. For example, the initiating event caused by the failure of the support system (such as the power supply and cooling water system); for example, in the case of a large LOCA or medium LOCA accident of a pressurized water reactor, if the break occurs in the cold section, one column of emergency core cooling system connected with the pipe section will not be able to supplement the coolant to the core, which should be fully considered when determining the success criteria.

[0023] The success criteria shall specify the time for the associated system to perform its task, i.e., the time required for the associated system to operate to bring the reactor to the corresponding state and to take long-term actions to maintain that state. For most initiating events, the front-line system task time typically refers to the operating task requirement; the safety system task time can typically be set to 24 hours; for new designs with delayed core damage actions, longer task times can need to be considered. The success criteria requirements for the associated support systems shall be determined based on the success criteria for the front-line systems performing the safety functions.

[0024] The success criteria shall specify the actions required of the operators and the time window allowed for the operators to take the actions in accordance with the nuclear power plant procedures to bring the nuclear power plant to a safe, stable condition or to shutdown. Good practice is to determine the actions that the operators shall take in cooperation with the nuclear power plant operators, system analysts, and human reliability analysts.

[0025] The success criteria here also require supporting analysis. The success criteria for safety systems and support systems are verified through supporting analysis. Supporting analysis includes thermal-hydraulic analysis of decay heat following transients and loss-of-coolant accidents, neutronics analysis of reactor shutdown and subcriticality maintenance, etc. If possible, realistic success criteria based on best estimates should be used in the analysis. If conservative success criteria based on design-basis analysis are used, the overall analysis results should be carefully reviewed to ensure that the conservatism does not distort the risk insights from the probabilistic safety analysis and the risk-informed risk assessment.

[0026] The computer programs used to verify the success criteria shall have the capability to correctly model the accident and the sequence of accidents that need to be analyzed and to give best estimate results. The computer programs can only be used by qualified analysts within their applicable scope. If possible, best estimate input data and assumptions should be used to avoid unnecessary conservatism.

[0027] The third step is to build the power generation risk event tree model, i.e. to build the event tree structure model based on the initiating event and initiating event sequence analysis; to identify all the consequences of the event sequence based on this model and find out the corresponding sequence for the consequences. The specific process is: to determine the event sequence that occurs after each initiating event group. The event tree method is used for modeling, and the success or failure of the front system, the reactor safety shutdown system and the personnel action in performing the related functions are considered in the event sequence modeling. The event tree should cover all the related functions and related systems that need to be performed. The state of the front system (success or failure) is usually taken as the title of the event tree, sometimes also called "event tree top event". In addition, the event tree title can also include any operator action that directly affects the accident process, especially the action specified in the emergency operating procedure. Other events that have a direct and significant impact on the event sequence can also be used as the title. The order of the title events representing operator actions and system actions should be considered in the event tree structure. The usual practice is to model the order as much as possible according to the time required for the system or operator. The relatedness of the functions or entities caused by equipment failure or human error should also be considered in the event tree structure. The event sequence analysis should analyze all the related combinations of the success or failure of each safety system in the event tree to model all the sequences with the consequences of success or core damage. In this process, the definition and division of the event sequence terminal state should reflect the design characteristics of the nuclear power plant. Generally, it can be divided into three categories: the first category is to completely perform all the necessary power generation functions, thereby reducing the power operation and shutdown, i.e. original power operation (OK); the second category is to maintain low power operation (LP) due to the failure to successfully restore the original power; the third category is to fail to maintain low power stable operation after the accident, thereby safely shutting down (SD); the fourth category is to fail to maintain low power stable operation after the accident, and fail to safely shut down, resulting in damage (CD). The nuclear power plant power generation risk event tree model described in the above third step process is shown in the attached Figure 1 .

[0028] After the completion of the power generation risk event tree model, the fourth step of building the nuclear safety risk event tree model is started. Similar to the previous step, the sequence of events that occur after the initiating event group is determined. The event tree method is usually used to build the model, and the success or failure of the safety system, support system and personnel action in performing the safety function is considered in the event sequence modeling. The event tree should cover all safety functions that need to be performed and safety systems. The state of the safety system (success or failure) is usually taken as the event tree header, sometimes also called the "event tree top event". In addition, the event tree header can also include any operator action that directly affects the accident process, especially the actions specified in the emergency operating procedure. Other events that have a direct and significant impact on the event sequence can also be included as the header. The order of the header events representing operator actions and system actions should be considered in the event tree structure. The usual practice is to model the sequence as much as possible according to the time required for the system or operator. The functional or physical correlation caused by equipment failure or personnel error should also be considered in the event tree structure. The event sequence analysis should analyze all relevant combinations of the success or failure of each safety system in the event tree to model all sequences with successful consequences or core damage. The definition and division of the event sequence final state in this step should reflect the design characteristics of the nuclear power plant, which can be divided into two categories: the first category completely performs all necessary safety functions, thereby avoiding core damage, i.e. safe shutdown (SD); the second category assumes that core damage (CD) will occur due to the failure of one or more safety functions. The nuclear safety risk event tree model of the nuclear power plant described in this step is shown in the attached drawings Figure 2 .

[0029] The last step of the scheme is to use the system fault tree model to perform failure mode and effects analysis (FMEA), initiating event fault tree analysis, functional event fault tree analysis and correlation analysis to realize nuclear risk analysis. The system failure involved in the event sequence analysis can be modeled and analyzed using the fault tree method. The top event of the fault tree is the system failure state determined in the event tree analysis. The fault tree starts from the top event and is divided into single bottom events level by level, usually including equipment failure (e.g. failure of pumps, valves, diesel generators, etc.), equipment unavailability caused by maintenance or testing, common cause failure of redundant equipment and personnel error events, etc. The following explains FMEA, initiating event fault tree analysis, functional event fault tree analysis and correlation analysis in detail:

[0030] The FMEA analysis determines the operation state of each device in the system, failure mode, and analyzes the possible effects on nuclear safety risk and power generation risk. There may be devices that affect both nuclear safety risk and power generation risk, devices that affect nuclear safety risk but not power generation risk, devices that affect power generation risk but not nuclear safety risk, and devices that affect neither nuclear safety risk nor power generation risk. Therefore, different failure modes of the device are taken as the bottom event for event tree modeling. The FMEA schematic table is shown in Table 1.

[0031] Table 1: FMEA schematic table of equipment

[0032]

[0033] For the determined initiating event group, the fault tree method can be used to analyze the initiating event separately. A logical model is constructed from the device failure to the occurrence of the top event initiating event. It includes two parts: top-level logic construction and system analysis, as follows. Figure 3 (1) Top-level logic. The top-level logic of the initiating event fault tree can be determined by the following methods: 1) Grouping according to the causes of the initiating event. The top-level logic can be constructed by referring to nuclear power plant shutdown signals, etc. By different shutdown and shutdown signals, the correspondence between system state and top event is determined to construct the top-level logic of the initiating event fault tree. 2) Constructing the top-level logic according to the system function success criteria. The success criteria of each system in the nuclear power plant are referred to determine the top-level logic of the fault tree constructed by the function success criteria. To determine the top-level logic of the initiating event fault tree, it is necessary to distinguish between automatic signals and manual signals. Automatic shutdown signals can refer to control system shutdown protection signals, etc. Manual shutdown signals need to refer to the requirements of the operation technical specification. Generally, automatic shutdown signals are triggered by front-end or support systems, while manual shutdown signals are state-retracted endpoints taken after the failure of auxiliary systems and safety-related systems according to the requirements of the operation technical specification. Under automatic signals, in addition to considering the front-end system failure to trigger the shutdown signal, the signal mis-triggering caused by sensors, signal transmission or control devices also needs to be considered.

[0034] Another method of constructing the top-level logic of the initiating event fault tree from the overall function is similar to the above-mentioned method of referring to the reasons for unplanned shutdown. The difference is that the reference object changes from specific shutdown signals to the overall function of the nuclear power plant. By referring to the design and system specification, the functions of each system in the nuclear power plant are analyzed to determine the configuration of each system under the top event.

[0035] Functional event fault tree analysis process. The purpose of fault tree modeling is to logically model the failure states of the front-line system, safety system, and support system involved in the event sequence analysis. The failure criteria of the top event of each system's fault tree should be logically inverse to the success criteria required in the event sequence. In some cases, a safety system can need to have multiple fault tree models built to handle different success criteria corresponding to different sets of initiating events, or to handle different success criteria depending on the state of the system's precursor events in different branches of the event tree. In practice, different fault tree models can be built for different failure criteria, or logic switches (so-called "house-shaped events") can be used to disable or enable relevant parts of the fault tree model depending on the success criteria requirements. The basic events modeled in the fault tree should match the available equipment failure data. The equipment boundaries and failure modes modeled in the fault tree should be consistent with the definitions in the FMEA. The level of detail of the fault tree model should be down to the level of individual equipment (pumps, valves, diesel generators, etc.) important failure modes and individual human error events, and should include all basic events that can directly cause or combine with other basic events to cause the top event of the fault tree. The fault tree model should include all important equipment required for the operation of the front-line system, safety system, and support system, and should also include non-active equipment whose failure can cause system failure, such as filter plugging, etc. The functional dependencies and equipment failure dependencies should be explicitly considered in the fault tree model, otherwise the analysis conclusions can be seriously biased and underestimate the relative importance of the support system. The level of equipment analysis in the fault tree should be such that all hardware dependencies can be considered in the model. For example, in the case of a cooling water system providing cooling water to multiple equipment, the cooling water system should be explicitly modeled to consider the dependencies between different equipment due to sharing the cooling water system. The availability of equipment reliability data is also a factor in determining the level of equipment analysis to be considered in the fault tree (for example, the reliability data of an entire pump can be available, but the reliability data of its individual components, such as the impeller, coupling, bearing, etc., can not be available). In addition, the need for risk insights on the risk importance of equipment or components that are desired should also be appropriately considered in determining the level of equipment analysis in the fault tree. When multiple equipment are combined together to use a super equipment for fault modeling, it should be demonstrated that the effect of the failure mode of each equipment in the super equipment on the system is the same as the effect of the super equipment as a whole on the system. In addition, all super equipment included in the model should be functionally independent, i.e., the same equipment should not appear in multiple super equipment or as a basic event elsewhere. In addition, a special coding system should be developed to uniformly specify a unique code for each logic gate and basic event. For example, the coding of basic events is shown in Table 1. Figure 4

[0036] ​Correlation analysis. Correlation is one of the main sources of risk in nuclear power plants, and therefore should be modeled in the fault tree analysis. Functional correlation between systems should be explicitly modeled in the event tree or fault tree analysis. Correlation matrix can be used to identify the functional correlation and as the basis information to support the construction of event tree or fault tree. Functional correlation is different from equipment failure correlation, which can be directly modeled by event tree or fault tree method. For equipment failure correlation that cannot be directly handled, common cause failure is usually used to handle it. Functional correlation between systems due to common equipment or common support systems should be identified and explicitly modeled in the fault tree analysis. This correlation may exist in different safety systems that perform the same safety function, or in related support systems, and should be explicitly modeled in the fault tree regardless of the situation. Common cause failure analysis is an important part of correlation analysis, which is used to model equipment failure correlation. A systematic approach should be used to identify, model and quantitatively analyze it. (1) For situations where equipment failure correlation may occur, a list of redundant equipment should be identified and included in the equipment common cause failure model. There are many methods to model and analyze common cause failure, and in the same model, the same method should be used to model common cause failure if there is enough common cause failure data as the basis. In common cause failure modeling, common cause failure events within the system should be considered as comprehensively as possible, and common cause failure events between systems should be considered appropriately. (2) Identify the common cause failure that may affect the redundant equipment group and model it appropriately in the fault tree. All related equipment groups and important failure modes should be identified in the analysis. (3) Demonstrate the reasonableness of the common cause failure probability of each equipment failure mode, which can be considered from the following aspects: redundancy of the system, design characteristics of the equipment, system layout (separation, isolation, equipment identification, etc.), and operation, testing and maintenance of the system. (4) The calculation of common cause failure probability should be based on the specific data of the nuclear power plant as much as possible, and the operation data of similar nuclear power plants and general data should be considered comprehensively; if general common cause failure parameters are used, the applicability of these parameters should be demonstrated, and the equipment boundaries, failure modes and failure root causes in the general data source should be consistent with the assumptions; if expert judgment is used to assign values to common cause failure parameters (when specific data of the nuclear power plant and general data are not available), the assignment of common cause failure parameters should be reasonably demonstrated, and the error factor of the assigned value should match the uncertainty in the process of determining the common cause failure parameters.

[0037] The above analysis processes are realized by quantitative calculation. By using the event tree-fault tree method, Boolean logic operation is performed on the logic model (event tree and fault tree) of each initiating event group. Before the quantitative calculation of the model, it should be ensured that there is no logical loop in the model; if there is a logical loop, the loop should be resolved before quantization, and the original correlation should be preserved as much as possible. The quantitative results of the model should include the following contents: (1) core damage frequency (mean, point estimate and uncertainty interval or probability distribution); (2) contribution of each initiating event group to the core damage frequency; (3) important minimal cut sets and their occurrence frequencies, event sequences and their occurrence frequencies; (4) sensitivity analysis and uncertainty analysis results; (5) importance analysis results.

[0038] The technical scheme of the present application gives an integrated nuclear power plant accident analysis modeling method based on PSA and GRA, which makes up for the problem of insufficient analysis of traditional single PSA or GRA method in analyzing nuclear power plant accidents, and obtains nuclear safety risk and power generation risk of the nuclear power plant. Through comprehensive analysis of the two risks, support is provided for nuclear power plant design, operation and management decision-making based on risk guidance, optimization of nuclear power plant design, operation and management, and finally improvement of safety and economy of the nuclear power plant; the method has wide applicability and strong universality, and can be used for analyzing and calculating safety risk and power generation risk of most nuclear power plant accidents, and is also applicable to nuclear power device accident risk analysis

[0039] The above only describes the preferred embodiments of the present application and is not used to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principles of the present application should be included in the protection scope of the present application.

Claims

1. A nuclear power risk analysis method combining internal event probabilistic safety analysis and power generation risk assessment, characterized in that, The method comprises the following steps: S1, determining a nuclear power plant internal initiating event and clearly analyzing a boundary range; the initiating event refers to any event that interferes with the stable operation state of the nuclear power plant and causes an exception; S2, performing sequence analysis on the initiating event, determining a response process and a corresponding success criterion; the response process refers to the mitigation response of the nuclear power plant determined for each initiating event, that is, the relevant system is required to perform a relevant function to prevent the occurrence of an undesirable event result; the setting or operation of the relevant function performed by the relevant system is the success criterion; S3, constructing a power generation risk event tree model, that is, constructing an event tree structure model based on the initiating event and the sequence analysis of the initiating event; identifying the consequences of all event sequences based on the model and finding the corresponding sequences for the consequences; S4, for all event sequences found in S3, constructing a nuclear safety risk event tree model by a probabilistic safety analysis method; the model includes but is not limited to the success or failure of each safety system, support system and personnel action in performing a safety function; S5, selecting the system fault tree model in the S4 model to perform Failure Mode and Effects Analysis (FMEA), initiating event fault tree analysis, functional event fault tree analysis and correlation analysis to realize nuclear risk analysis.

2. The nuclear power risk analysis method combining internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The nuclear power plant internal initiating event in S1 is analyzed by an engineering analysis method to identify the initiating event that may be caused by an operation failure; the list of initiating events formed herein includes all and partial failures of functions or systems.

3. The nuclear power risk analysis method combining internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The success criterion in S2 is determined according to the minimum requirement of the function performance level of each event sequence; when the system has multiple redundant columns, the success criterion is determined as the number of required operation columns; if the safety function involves multiple safety systems with diversified settings, the success criterion should consider the performance requirements of each system, and consider the partial operation of each system based on the best estimated analysis results.

4. The nuclear power risk analysis method combining internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The event tree model structure in S3 considers the sequence of the subject event representing the operator action and the system action; the specific method is to model in sequence according to the time sequence of the system or operator requirements.

5. The nuclear power risk analysis method combining internal event probabilistic safety analysis with power generation risk assessment according to claim 4, characterized in that, The event tree model structure in S3 also considers the functional or physical correlation caused by equipment failure or personnel error; when analyzing the event sequence, all related combinations of the success or failure of each safety system in the event tree are analyzed to model all sequences with successful or failed consequences.

6. The nuclear power risk analysis method integrating internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The sequence termination state of the event sequence consequences identified by the power generation risk event tree model in S3 is divided into three categories: (a) all required power generation functions are completely executed, thereby reducing the power operation and stopping the reactor, that is, the original power operation (OK); (b) only low power operation (LP) can be maintained due to the failure to successfully restore the original power; (c) after the accident, the low power stable operation cannot be maintained, and the safe shutdown (SD) is not achieved; (d) after the accident, the low power stable operation cannot be maintained, and the safe shutdown is not achieved, resulting in damage (CD).

7. The nuclear power risk analysis method integrating internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The structure of the nuclear safety risk event tree model in S4 is to consider the sequence of the initiating event and the sequence of the subsequent events. The specific method is to model the sequence according to the time sequence of the system or operator requirements, and to consider the functional or physical correlation caused by equipment failure or human error. In the event sequence analysis, all relevant combinations of the success or failure of each safety system in the event tree are analyzed to model all sequences with successful or failed consequences. The sequence termination state of the event sequence consequence of the nuclear safety risk event tree model is divided into two categories: (A) all necessary safety functions are completely executed, thus avoiding core damage, i.e. safe shutdown (SD); (B) core damage (CD) is assumed to occur due to the failure of one or more safety functions.

8. The nuclear power risk analysis method integrating internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The initiating event fault tree analysis in S5 is an analysis of the initiating event alone. A logic model is constructed from the device failure to the occurrence of the initiating event, including the top event. The model includes two parts: top-level logic construction and system analysis.

9. The nuclear power risk analysis method integrating internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The functional event fault tree analysis in S5 is an analysis process of logically modeling the failure state of the front-end system, safety system, and support system involved in the event sequence analysis.

10. The nuclear power risk analysis method integrating internal event probabilistic safety analysis with power generation risk assessment according to claim 1, characterized in that, The correlation analysis in S5 is a correlation matrix analysis to identify the correlation between system failures in the model. Common cause failure analysis is used to identify situations where equipment failure correlation occurs, the common cause of failure of redundant equipment groups, and to evaluate the reasonableness and common cause failure probability of the common cause failure probability of the equipment failure mode.