Nuclear power station control system inspection method and device, storage medium and electronic equipment

By acquiring the target inspection list of the nuclear power plant control system, conducting communication network fault detection and multi-dimensional data collection, and establishing a health status assessment system, the problem of reliance on experience for manual inspection was solved, and an automated and standardized inspection process was realized, improving detection accuracy and efficiency and ensuring the safe and stable operation of the nuclear power plant control system.

CN121559836APending Publication Date: 2026-02-24BEIJING GUODIAN ZHISHEN CONTROL TONGDY
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511549757.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-28
Publication Date
2026-02-24

AI Technical Summary

Technical Problem

Existing manual inspection methods rely on human experience, making it difficult to detect faults in nuclear power plant control systems in a timely manner, resulting in delayed fault warnings and low detection efficiency.

Method used

By acquiring the target inspection list of the nuclear power plant control system, detecting communication network faults, collecting multi-dimensional monitoring data, and establishing a health status assessment system, an automated and standardized inspection process can be achieved, which complies with nuclear safety regulations.

Benefits of technology

It improves the detection accuracy and efficiency of nuclear power plant control systems, ensures the safe and stable operation of the system throughout its entire life cycle, and meets the real-time and data integrity requirements of nuclear safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121559836A_ABST
    Figure CN121559836A_ABST
Patent Text Reader

Abstract

The invention discloses a nuclear power station control system inspection method and device, a storage medium and electronic equipment, and relates to the technical field of nuclear power station control systems. The method comprises the steps that a target inspection list of the nuclear power station control system is acquired, and IP addresses of controllers of all sub-control systems to be inspected in the nuclear power station control system are recorded in the target inspection list; performing fault detection on the communication network of the controller of each sub-control system to obtain a network fault detection result of the controller of each sub-control system; if it is determined that no network communication fault exists in the controller of each sub-control system according to the network fault detection result, multi-dimensional monitoring data are collected according to the type of the controller of each sub-control system, and the type of the controller comprises a security level controller and a non-security level controller; and evaluating the health state of the nuclear power station control system according to the collected multi-dimensional monitoring data. According to the invention, faults of the nuclear power station control system can be found in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of nuclear power plant control system technology, and in particular to a method, apparatus, storage medium and electronic equipment for inspecting a nuclear power plant control system. Background Technology

[0002] In the production and operation of nuclear power plants, the reliability of the control system is directly related to the production safety, environmental safety, and personnel safety of the nuclear power plant.

[0003] Currently, faults in the operation of nuclear power plant control systems are typically detected through manual inspection. However, this method relies heavily on human experience, making it difficult for less experienced operators to detect faults in a timely manner, resulting in delayed fault warnings and low detection efficiency. Summary of the Invention

[0004] In view of this, this application provides a method, device, storage medium and electronic equipment for inspecting a nuclear power plant control system, which is mainly able to detect faults in the nuclear power plant control system in a timely manner and improve the detection accuracy and efficiency of the nuclear power plant control system.

[0005] According to a first aspect of this application, a method for inspecting a nuclear power plant control system is provided, the method comprising: Obtain the target inspection list of the nuclear power plant control system, wherein the target inspection list records the IP addresses of the controllers of each sub-control system to be inspected in the nuclear power plant control system. Fault detection is performed on the communication network of the controller of each sub-control system to obtain the network fault detection results of the controller of each sub-control system. If it is determined from the network fault detection results that there is no network communication fault in the controllers of each sub-control system, then monitoring data in multiple dimensions are collected according to the type of controller of each sub-control system, wherein the type of controller includes safety-level controllers and non-safety-level controllers. The health status of the nuclear power plant control system is assessed based on the collected monitoring data from the multiple dimensions.

[0006] According to a second aspect of this application, a nuclear power plant control system inspection device is provided, the device comprising: The acquisition unit is used to acquire the target inspection list of the nuclear power plant control system, wherein the target inspection list records the IP addresses of the controllers of each sub-control system to be inspected in the nuclear power plant control system. The network detection unit is used to perform fault detection on the communication network of the controller of each sub-control system and obtain the network fault detection result of the controller of each sub-control system. The data acquisition unit is used to collect monitoring data in multiple dimensions according to the type of controller of each sub-control system if it is determined from the network fault detection result that there is no network communication fault in the controller of each sub-control system. The controller types include safety-level controllers and non-safety-level controllers. The health assessment unit is used to assess the health status of the nuclear power plant control system based on the collected monitoring data from the multi-dimensional dimensions.

[0007] According to a third aspect of this application, a storage medium is provided that stores a computer program thereon, which, when executed by a processor, implements the above-described nuclear power plant control system inspection method.

[0008] According to a fourth aspect of this application, an electronic device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the program to implement the above-described nuclear power plant control system inspection method.

[0009] By employing the above technical solution, this application provides a method, apparatus, storage medium, and electronic equipment for inspecting a nuclear power plant control system. Compared with existing manual inspection methods, this method can obtain a target inspection list for the nuclear power plant control system and perform fault detection on the communication networks of the controllers of each sub-control system in the target inspection list. It obtains network fault detection results for each sub-control system controller. If the network fault detection results determine that there are no network communication faults in the controllers of each sub-control system, then multi-dimensional monitoring data is collected according to the type of controller in each sub-control system. Finally, based on the collected multi-dimensional monitoring data, the health status of the nuclear power plant control system is assessed. Therefore, this application, by implementing an automated, standardized, and digital inspection process and establishing a health status judgment system that conforms to nuclear safety laws, can promptly detect faults in the nuclear power plant control system, thereby improving the detection accuracy and efficiency of the nuclear power plant control system and ensuring the safe and stable operation of the nuclear power plant control system throughout its entire lifecycle.

[0010] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0011] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1A flowchart illustrating an inspection method for a nuclear power plant control system provided in an embodiment of this application is shown. Figure 2 A schematic diagram of the operation interface for communication network fault monitoring provided in an embodiment of this application is shown; Figure 3 This illustration shows a schematic representation of data acquisition provided in an embodiment of this application; Figure 4 This illustration shows a schematic diagram of a data acquisition report provided in an embodiment of this application; Figure 5 A schematic flowchart of the health status determination method for a nuclear power plant control system provided in an embodiment of this application is shown. Figure 6 A schematic diagram of the structure of a nuclear power plant control system inspection device provided in an embodiment of this application is shown. Detailed Implementation

[0012] The present application will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the embodiments of the present application can be combined with each other.

[0013] Existing manual inspection methods rely too heavily on human experience, making it difficult for less experienced operators to detect faults in the nuclear power plant control system in a timely manner, resulting in delayed fault warnings and low detection efficiency.

[0014] To address the aforementioned problems, embodiments of the present invention provide a method for inspecting a nuclear power plant control system, such as... Figure 1 As shown, the method includes: Step 10: Obtain the target inspection list for the nuclear power plant control system.

[0015] The target inspection list records the IP addresses of the controllers of each sub-control system in the nuclear power plant control system to be inspected. Each sub-control system controller can be a safety-level controller or a non-safety-level controller. Safety-level controllers have corresponding safety levels, which depend on the subsystem to which they belong and their function.

[0016] In this embodiment of the invention, the nuclear power plant control system includes multiple sub-control systems. Each sub-control system's controller can be a safety-grade controller or a non-safety-grade controller. Based on the desired safety domain or physical partition to be inspected, the IP address range of the sub-control system's controllers can be input, automatically generating a target inspection list. This target inspection list includes multiple safety-grade controllers and multiple non-safety-grade controllers. By inspecting the controllers of each sub-control system, the health status of the entire nuclear power plant control system can be assessed, and faulty sub-control systems can be detected promptly. Tests have shown that for a cluster inspection of 100 non-safety-grade controllers, the total inspection time does not exceed 10 minutes, and the controller data acquisition response time is less than or equal to 2 seconds, fully meeting the real-time requirements for nuclear safety.

[0017] Step 20: Perform fault detection on the communication network of the controllers of each sub-control system to obtain the network fault detection results of the controllers of each sub-control system.

[0018] In this embodiment of the invention, when inspecting each controller in the target inspection list, it is necessary to ensure that the network communication of each controller is normal. Therefore, it is necessary to first detect the communication network of each controller. Specifically, step 20 includes: for any controller in each sub-control system, performing an initial access to that controller; if the initial access fails, performing a second access to that controller based on the backup communication link and a first preset retry interval; if the second access fails, switching to a dedicated maintenance port, and performing a third access to that controller based on the dedicated maintenance port and a second preset retry interval; if the third access fails, determining that that controller has a network communication fault, removing that controller from the target inspection list, and marking that controller as needing maintenance; if any one of the three accesses is successful, determining that that controller does not have a network communication fault.

[0019] The first preset retry interval and the second preset retry interval can be set according to actual business needs. This embodiment of the invention does not impose specific limitations on this. For example, the first preset retry interval can be set to 1 second and the second preset retry interval to 2 seconds.

[0020] Specifically, for any controller, after an initial access failure, a retry is performed via a backup communication link after a 1-second interval. If the backup link fails, after a 2-second interval, for security-level controllers, the retry switches to a dedicated security-level maintenance port; for non-security-level controllers, the retry switches to a dedicated non-security-level maintenance port. If the retry still fails, a fault node isolation mechanism is triggered, automatically removing the controller from the target inspection list and marking it as pending maintenance. An isolation report is generated, including the controller's failure time, communication link status, and backup port detection results. This prevents invalid retries from affecting other security-level or non-security-level devices. The specific operating interface is as follows: Figure 2 As shown.

[0021] This invention employs a three-level retry and fault isolation mechanism for the controller, ensuring uninterrupted inspections without affecting safety functions. Simultaneously, this invention supports automatic report archiving, storing encrypted text reports, tabular reports, and original data files. Historical data can be quickly retrieved by event number, controller IP, and time range, meeting the requirements for nuclear safety event tracing and auditing.

[0022] Step 30: If it is determined from the network fault detection results that there is no network communication fault in the controllers of each sub-control system, then monitoring data in multiple dimensions are collected according to the type of controller of each sub-control system.

[0023] The controller types include security-level controllers and non-security-level controllers. The multiple dimensions include performance metrics, hardware status, and software version. Each of these dimensions includes multiple sub-dimensions, and the sub-dimensions differ depending on the type of controller.

[0024] In this embodiment of the invention, when data is collected, if the controller is a security-level controller, the following data are collected: CPU load, memory usage, and input / output module response latency under the performance metrics dimension; motherboard temperature, redundant module switching status, and security-level card communication status under the hardware status dimension; and firmware version, operating system version, application version, and their corresponding version approval number, release date, version change content, and compatible hardware models under the software version dimension. If the controller is a non-security-level controller, the following data are collected: CPU load, memory usage, disk usage, and network bandwidth usage under the performance metrics dimension; motherboard temperature, fan operation status, and power supply voltage stability under the hardware status dimension; and firmware version, driver version, and version update log under the software version dimension.

[0025] Specifically, when collecting multi-dimensional nuclear safety-related data, for performance indicators, the following data collection methods are employed: For safety-level controllers, CPU load, memory usage, and I / O module response latency are collected via system commands. CPU load can be collected once per second, and the average value is taken after multiple consecutive collections (e.g., 30 times) to reduce the impact of instantaneous fluctuations on safety decisions. When collecting memory usage, it is necessary to distinguish between safe zone memory and non-safe zone memory to prevent non-safe zone programs from occupying safe zone resources. When collecting I / O module response latency, the delay time from input to output of safety-level signals needs to be collected; for example, the delay of emergency shutdown signals must be less than or equal to 100ms. For non-safety-level controllers (such as conventional island turbine controllers), CPU load, memory usage, disk usage, and network bandwidth usage are collected. When collecting disk usage, the system log storage disk is monitored to ensure that fault logs are completely preserved. When collecting network bandwidth usage, the communication bandwidth with the safety-level system is monitored to prevent bandwidth overflow that could lead to data transmission interruptions.

[0026] For hardware status data acquisition, for safety-level controllers, hardware register data is read, and motherboard temperature, redundancy module switching status, and safety-level card communication status are monitored. Specifically, when monitoring motherboard temperature, three key points are collected: controller core chip temperature, power module temperature, and I / O interface temperature. The highest value is used as the judgment criterion. When monitoring redundancy module switching status, the number of redundancy switches, switching reasons, switching time, and safety redundancy switching time are recorded. The safety redundancy switching time must be less than or equal to 50ms. When monitoring safety-level card communication status, card communication error codes and retransmission counts need to be collected. For non-safety-level controllers, motherboard temperature, fan operation status, and power supply voltage stability are monitored. Specifically, when monitoring fan operation status, fan speed and number of failures need to be recorded.

[0027] For software version-level data collection, for safety-grade controllers, embedded security instructions are invoked to verify firmware, operating system, and application versions. Simultaneously, version approval number, release date, version changes, compatible hardware models, and other subsystem versions are recorded. The version approval number must comply with the version approval requirements of nuclear safety regulatory agencies. Version changes require close verification to ensure they do not involve modifications to security logic. Collecting compatible hardware models and other subsystem versions helps prevent cross-version compatibility issues that could lead to security function failures. For non-safety-grade controllers, firmware and driver versions are collected, and version update logs are recorded to ensure the absence of unpatched high-risk vulnerabilities. Specific data collection tables are as follows: Figure 3 As shown, the data collection report is as follows: Figure 4As shown.

[0028] Furthermore, to ensure that the data used meets nuclear safety data requirements, the raw data collected above needs to be processed sequentially through noise reduction, compliance verification, and categorized storage. Specifically, a Kalman filter algorithm is first used to remove abnormal fluctuation data. For example, for data collected from safety-level controllers, the filter coefficient is set to 0.8 to balance real-time performance and accuracy. Then, the data undergoes compliance verification, such as requiring I / O response latency to be less than or equal to 100ms. Data that does not meet this requirement is marked as abnormal and the reason is recorded. Next, the data is categorized and stored according to two dimensions: safety-level controllers and non-safety-level controllers, and performance indicators, hardware status, and software version. The data format must comply with the requirements for digital archive management of nuclear power plants, such as PDF / A-3a format, to support long-term archiving.

[0029] Step 40: Based on the collected monitoring data from the multi-dimensional perspectives, assess the health status of the nuclear power plant control system.

[0030] The health status of a nuclear power plant control system includes health status, early warning status, and fault status.

[0031] In this embodiment of the invention, after data acquisition and standardization processing of the controller, the health status of the nuclear power plant control system can be assessed based on the processed monitoring data. Regarding this assessment method, such as... Figure 5 As shown, it specifically includes: Step 41: Based on the monitoring data under the multiple sub-dimensions corresponding to each dimension, evaluate the health status of the controllers of each sub-control system under the multiple sub-dimensions respectively.

[0032] For security-grade controllers, the performance metrics dimension includes multiple sub-dimensions such as CPU load, memory utilization, and I / O module response latency; the hardware status dimension includes multiple sub-dimensions such as motherboard temperature, redundant module switching status, and security-grade card communication status; and the software version dimension includes multiple sub-dimensions such as firmware version, operating system version, application version, and their respective version approval numbers, release dates, version changes, and compatible hardware models. For non-security-grade controllers, the performance metrics dimension includes multiple sub-dimensions such as CPU load, memory utilization, disk utilization, and network bandwidth utilization; the hardware status dimension includes multiple sub-dimensions such as motherboard temperature, fan operation status, and power supply voltage stability; and the software version dimension includes multiple sub-dimensions such as firmware version, driver version, and version update log.

[0033] In this embodiment of the invention, the health status of the controllers of each sub-control system can be evaluated based on the corresponding regional range of the monitoring data under the multiple sub-dimensions corresponding to each dimension, wherein the health status includes health, early warning, and fault.

[0034] Specifically, for the CPU load settings of the safety-level controller, the normal range of CPU load is 0-40%, the warning range is 41-60%, and the fault range is 61-100%. When judging the CPU load, if the average CPU load is within the normal range and the fluctuation range (difference between the maximum and minimum values) of 30 collected data is less than or equal to 5%, the safety-level controller is considered healthy in terms of CPU load. If the average CPU load is within the warning range, or the fluctuation range is between 5% and 10%, this may cause delays in the response of the safety-level program. Therefore, the safety-level controller is considered to be in a warning state in terms of CPU load, and the operation of the non-safety zone program needs to be investigated within 24 hours. If the average CPU load is within the fault range, or the fluctuation range is greater than 10%, the safety-level controller is considered to be in a fault state in terms of CPU load. At this time, a safety-level alarm is immediately triggered, and the controller is prohibited from participating in the operation of safety logic.

[0035] For example, if a security-level controller has an average CPU load of 30% with a fluctuation range of 3%, it can be determined that the controller is in a healthy state based on CPU load. As another example, if a security-level controller has an average CPU load of 55% with a fluctuation range of 4%, it can be determined that the controller is in a warning state based on CPU load. And if a security-level controller has an average CPU load of 65% with a fluctuation range of 8%, it can be determined that the controller is in a fault state based on CPU load.

[0036] Regarding the response latency settings for the I / O module of the safety-grade controller, the normal range for response latency is 0-100ms, the warning range is 101-150ms, and the fault range is greater than 150ms. When judging the I / O module response latency, if five consecutive response latency measurements are within the normal range, the safety-grade controller is considered healthy in terms of response latency. If a single latency exceeds 101ms, the controller is considered to be in a warning state, requiring inspection of I / O module wiring and signal interference. If a single latency exceeds 150ms, or three consecutive latency measurements exceed 101ms, the controller is considered to be in a fault state, requiring immediate switching to a redundant controller to prevent safety function failure.

[0037] For disk usage settings of non-security-level controllers, the normal range for system log disk usage is 0-70%, the warning range is 71-85%, and the fault range is 86-100%. For other disks, the normal range is 0-80%, the warning range is 81-90%, and the fault range is 91-100%. When judging disk usage, if the disk usage is within the normal range and the disk read / write speed fluctuation is less than or equal to 20% (refer to the disk's rated speed for details), the non-security-level controller is considered healthy in terms of disk usage. If the disk usage is within the warning range, or the read / write speed fluctuation is between 21% and 30%, the non-security-level controller is considered to be in a warning state. If the disk usage is within the fault range, or the read / write speed fluctuation is greater than 30%, the non-security-level controller is considered to be in a fault state in terms of disk usage.

[0038] Regarding the redundancy switching status of the safety-grade controller, if the number of switching events per month is less than or equal to 1 (non-fault-triggered redundancy switching), the switching time is less than or equal to 50ms, and the switching reason has no hardware fault indication, then the redundancy switching status is determined to be within the normal range. When determining the redundancy switching status, if all the above conditions are met, the safety-grade controller is determined to be in a healthy state under the redundancy switching status dimension; if the number of switching events per month is 2-3, or the switching time is 51-100ms, the safety-grade controller is determined to be in a warning state under the redundancy switching status dimension, and the synchronization status of the redundant module needs to be checked; if the number of switching events per month is greater than 3, or the switching time is greater than 100ms, or the switching reason includes a hardware fault, the safety-grade controller is determined to be in a fault state under the redundancy switching status dimension, and the faulty redundant module needs to be replaced immediately.

[0039] Regarding the motherboard temperature settings for the safety-level controller, the normal range for the core chip is 0-60℃, the normal range for the power module is 0-55℃, and the normal range for the I / O interface is 0-50℃. The warning range for the core chip is 61-70℃, the warning range for the power module is 56-65℃, and the warning range for the I / O interface is 51-60℃. The fault range for the core chip is greater than 70℃, the fault range for the power module is greater than 65℃, and the fault range for the I / O interface is greater than 60℃. When determining the temperature, if all three points mentioned above are within the normal range, the safety-level controller is considered healthy according to the motherboard temperature. If any point is within the warning range, the safety-level controller is considered to be in a warning state according to the motherboard temperature, and the cooling system (such as cooling fans and heatsinks) needs to be checked. If any point is within the fault range, the safety-level controller is considered to be in a fault state according to the motherboard temperature, and the system needs to be shut down immediately for cooling to prevent hardware damage that could lead to the failure of safety functions.

[0040] For non-safety-grade controllers, the fan operating status is set as follows: a fan speed greater than or equal to 90% of the rated speed, or more than two fault records, falls within the fault range; a fan speed between 80% and 89% of the rated speed, or one fault record, falls within the warning range; a fan speed less than 80% of the rated speed, and no fault records, falls within the normal range. When determining the fan operating status, if it falls within the normal range, the non-safety-grade controller is considered healthy in the fan operating status dimension; if it falls within the warning range, it is considered in a warning state; and if it falls within the fault range, it is considered in a fault state.

[0041] For the software versions of safety-level controllers, a compliance database for nuclear power plant safety-level software versions is established, which includes the approved version number, corresponding hardware model, compatible subsystem version, and version change approval document number. If the current version is marked as compliant in the database and the version change content does not contain unverified safety logic, the safety-level controller is considered to be in a healthy state in terms of software version. If the version is marked as temporarily compliant and requires formal approval within 3 months, or if there are verified but not yet updated safety patches, the safety-level controller is considered to be in a warning state in terms of software version. If the version is marked as non-compliant, or if there are changes with unverified safety logic, the safety-level controller is considered to be in a fault state in terms of software version. In this case, the controller should be stopped immediately and replaced with a compliant version.

[0042] For non-security-level controllers, if the version has no unpatched high-risk vulnerabilities and is compatible with related subsystems, the non-security-level controller is considered healthy in terms of software version. If there are unpatched low-risk vulnerabilities or poor compatibility with some non-critical subsystem versions, the non-security-level controller is considered to be in a warning state in terms of software version. If there are unpatched high-risk vulnerabilities or incompatibility with critical subsystem versions (such as the security-level data acquisition subsystem), the non-security-level controller is considered to be in a fault state in terms of software version.

[0043] It should be noted that the settings and determination processes for normal, warning, and fault ranges in other dimensions for both safety-level and non-safety-level controllers are similar to those described above, and will not be repeated here. Furthermore, the settings and determination conditions for normal, warning, and fault ranges in this embodiment are not limited to the above and can be adjusted according to actual business needs.

[0044] The embodiments of this invention strictly adhere to nuclear safety regulations and standards such as HAF102 and GB / T 13284-2019. The inspection tool supports separate inspection of safety-grade and non-safety-grade controllers to avoid cross-interference. Furthermore, the data acquisition and judgment process complies with nuclear safety data integrity and confidentiality requirements, and can meet the 15-year data archiving needs of nuclear power plants.

[0045] Furthermore, this invention allows for one-click initiation of multi-domain batch inspections, employing a "safety-priority" concurrency strategy. This improves inspection efficiency (by over 80% compared to manual inspections) while ensuring the real-time performance of safety-grade equipment. An intuitive graphical interface distinguishes between safety-grade and non-safety-grade indicators, eliminating the need for operators to memorize underlying commands. Only 3-5 days of nuclear safety operation training are required to become proficient, reducing the risk of human error.

[0046] Step 42: Based on the health status of the controllers of each sub-control system under the multiple sub-dimensions, comprehensively evaluate the health status of the nuclear power plant control system.

[0047] In this embodiment of the invention, when comprehensively evaluating the health status of a nuclear power plant control system, a health score is determined for each controller in each of the multiple sub-dimensions based on their health status in each of the multiple sub-dimensions. Based on these health scores, a health score is calculated for each controller in each dimension, where the controller types include safety-level controllers and non-safety-level controllers. An average health score is calculated for each of the safety-level and non-safety-level controllers in each dimension, taking into account the number of safety-level and non-safety-level controllers. A weighted sum is then performed on the average health scores for each dimension to obtain the total score for the nuclear power plant control system. Finally, the health status of the nuclear power plant control system is determined based on the total score.

[0048] For example, a controller might be defined as having a health score of 100 for being in a healthy state, 60 for being in a warning state, and 0 for being in a fault state. For a certain security-level controller, whose performance metrics include CPU load and memory utilization as sub-dimensions, if the controller is in a healthy state with a health score of 100 for CPU load and in a warning state with a health score of 60 for memory utilization, then the overall health score for the security-level controller across the performance metrics dimensions is (100 + 60) / 2 = 80.

[0049] Therefore, following the above method, the health scores of all security-level controllers and all non-security-level controllers can be obtained in the dimensions of performance metrics, hardware status, and software version. Then, for each dimension, based on the number of security-level controllers and the number of non-security-level controllers, the average health score for each dimension is calculated. For example, by calculating the health scores of 100 security-level controllers in the performance metrics dimension, the average health score of the 100 security-level controllers in the performance metrics dimension is obtained by summing these 100 health scores. Similarly, the average health scores of all security-level controllers in other dimensions, and the average health scores of all non-security-level controllers in each dimension, can be calculated.

[0050] After calculating the average health score of all safety-level controllers and non-safety-level controllers in each dimension, a weighted sum is performed based on the weights of the performance indicators, hardware status, and software version corresponding to the safety-level controllers and non-safety-level controllers, respectively, to obtain the total score of the nuclear power plant control system. Then, the health status of the entire nuclear power plant control system is determined based on the interval to which the total score belongs.

[0051] For example, a total score of 90-100 indicates a healthy nuclear power plant control system; a score of 70-89 indicates a pre-warning condition; and a score of 0-69 indicates a fault. The weights for performance indicators, hardware status, and software version for safety-grade controllers are 35%, 30%, and 20%, respectively. For non-safety-grade controllers, the weights for performance indicators, hardware status, and software version are all 5%. The total score equals the average health score of the safety-grade controller under the given performance indicators. 35%+ safety-level controllers have an average health score in hardware condition. Average health score of 15%+ security level controllers under different software versions Average health score of 20%+ non-safety-grade controllers under performance metrics Average health score of 5%+ non-safety level controllers in hardware condition Average health score of 5%+ non-safety level controllers under different software versions 5%. After calculating the total score according to the above formula, the health status of the nuclear power plant control system can be determined based on the range to which the total score belongs.

[0052] In some optional embodiments, in order to further ensure the safe operation of the nuclear power plant control system, if the health status of the safety level controller is faulty in any one of the multiple sub-dimensions corresponding to each dimension, then the health status of the nuclear power plant control system is directly determined to be faulty.

[0053] For example, if a certain item in the hardware status of a safety-level controller is faulty, then the health status of the nuclear power plant control system is directly determined to be faulty.

[0054] When the health status of the nuclear power plant control system is in an early warning state, the inspection tool automatically triggers a three-level early warning response. First, an early warning pop-up window is displayed on the nuclear power plant central controller (CCR), indicating the safety level, physical location, warning dimension, and specific reason of the controller. The physical location refers to which system the controller belongs to, and the warning dimension refers to which indicator or sub-dimensional has a problem, whether it is a level one or level two alarm. Second, an encrypted email is sent to the nuclear safety engineer and equipment maintenance team, containing detailed early warning data and troubleshooting suggestions. Third, an early warning event record is generated in the inspection system log, specifically including the event number, occurrence time, and responsible person. The investigation must be completed and closed within 48 hours.

[0055] When the health status of the nuclear power plant's control system is faulty, a nuclear safety fault response is triggered. This immediately activates an audible and visual alarm in the Control Controller (CCR) (e.g., a red alarm, accompanied by a voice prompt indicating a safety-level control fault, requesting immediate action). Simultaneously, a fault signal is automatically sent to the nuclear power plant's emergency command center and personnel dispatched by the nuclear safety regulatory agency. If a safety-level controller fails, redundancy switching is automatically initiated (if redundancy is normal), and the operating permissions of the faulty controller are locked. Furthermore, a fault emergency report is generated, including fault data, an impact assessment (e.g., whether it affects reactor power control), and emergency handling procedures. After the fault is resolved, it must be verified by a nuclear safety engineer to confirm that the health status has returned to normal before the controller can be unlocked.

[0056] In some alternative embodiments, embodiments of the present invention can predict potential controller failures (e.g., a monthly upward trend in CPU load can predict a possible warning after 6 months) by comparing health scores over different periods, thus achieving predictive maintenance.

[0057] This invention's embodiments cover multi-dimensional data on the performance, hardware, and software of both safety-grade and non-safety-grade controllers during a single inspection, with a particular focus on key indicators of nuclear power plants, such as safety-grade redundancy, I / O response latency, and version compliance. Furthermore, the health assessment model established in this invention incorporates nuclear safety thresholds and regulatory requirements. Through weighted scoring and a "one-vote veto" mechanism for safety-grade items, it avoids misjudgments and omissions, providing accurate evidence for fault diagnosis (fault location accuracy ≥ 95%).

[0058] Furthermore, this embodiment of the invention is developed based on the native commands of the mainstream control system of nuclear power plants, supporting safety-level controllers and non-safety-level controllers from different manufacturers and versions. Simultaneously, the inspection tool reserves interfaces for expansion into the nuclear power plant's digital platform (such as the Power Plant Information Management System (SIS)), enabling the linkage analysis of inspection data and power plant production data, thereby improving overall operation and maintenance efficiency.

[0059] The present invention provides a method for inspecting a nuclear power plant control system. By implementing an automated, standardized, and digital inspection process and establishing a health status assessment system that complies with nuclear safety laws, the method can promptly detect faults in the nuclear power plant control system, thereby improving the detection accuracy and efficiency of the nuclear power plant control system and ensuring the safe and stable operation of the nuclear power plant control system throughout its entire life cycle.

[0060] Furthermore, as Figure 1 and Figure 5 The specific implementation of the method shown in this embodiment provides a nuclear power plant control system inspection device, such as... Figure 6 As shown, the device includes: an acquisition unit 101, a network detection unit 102, a data collection unit 103, and a health unit 104.

[0061] The acquisition unit 101 can be used to acquire the target inspection list of the nuclear power plant control system, wherein the target inspection list records the IP addresses of the controllers of each sub-control system to be inspected in the nuclear power plant control system.

[0062] The network detection unit 102 can be used to perform fault detection on the communication network of the controller of each sub-control system and obtain the network fault detection result of the controller of each sub-control system.

[0063] The acquisition unit 103 can be used to acquire monitoring data in multiple dimensions according to the type of controller of each sub-control system if it is determined from the network fault detection result that there is no network communication fault in the controller of each sub-control system. The controller types include safety-level controllers and non-safety-level controllers.

[0064] The health assessment unit 104 can be used to assess the health status of the nuclear power plant control system based on the collected multi-dimensional monitoring data.

[0065] In some embodiments, the network detection unit 102 may be specifically used to perform an initial access to any one of the controllers in each sub-control system; if the initial access fails, a second access is performed to the controller based on a backup communication link and a first preset retry interval; if the second access fails, the system switches to a dedicated maintenance port and performs a third access to the controller based on the dedicated maintenance port and a second preset retry interval; if the third access fails, it is determined that the controller has a network communication fault, the controller is removed from the target inspection list, and the controller is marked as pending maintenance; if any one of the three accesses is successful, it is determined that the controller does not have a network communication fault.

[0066] In some embodiments, the multi-dimensional approach includes a performance metric dimension, a hardware status dimension, and a software version dimension. Each of these dimensions includes multiple sub-dimensions. The acquisition unit 103 can be specifically used to acquire, when the controller is a security-level controller, the CPU load, memory usage, and I / O module response latency of the security-level controller under the performance metric dimension; the motherboard temperature, redundant module switching status, and security card communication status under the hardware status dimension; and the firmware version, operating system version, application version, and their corresponding version approval number, release date, version change content, and compatible hardware models under the software version dimension. When the controller is a non-security-level controller, it can acquire, when the controller is a non-security-level controller, the CPU load, memory usage, disk usage, and network bandwidth usage of the non-security-level controller under the performance metric dimension; the motherboard temperature, fan operation status, and power supply voltage stability under the hardware status dimension; and the firmware version, driver version, and version update log under the software version dimension.

[0067] In some embodiments, each dimension in the multi-dimensional model includes multiple sub-dimensions, and the health assessment unit 104 includes: a first assessment module and a second assessment module.

[0068] The first evaluation module can be used to evaluate the health status of the controllers of each sub-control system under the multiple sub-dimensions corresponding to each dimension, based on the monitoring data.

[0069] The second evaluation module can be used to comprehensively evaluate the health status of the nuclear power plant control system based on the health status of the controllers of each sub-control system under the multiple sub-dimensions.

[0070] In some embodiments, the first evaluation module may be specifically used to evaluate the health status of the controllers of each sub-control system under the multiple sub-dimensions according to the corresponding regional range of the monitoring data under the multiple sub-dimensions corresponding to each dimension, wherein the health status includes health, early warning and fault.

[0071] In some embodiments, the second evaluation module may be specifically configured to: determine the health score of the controllers of each sub-control system in the multiple sub-dimensions based on their health status in the multiple sub-dimensions; calculate the health score of the controllers of each sub-control system in each dimension based on their health scores in the multiple sub-dimensions, wherein the controller types include safety-level controllers and non-safety-level controllers; calculate the average health score of the safety-level controllers and non-safety-level controllers in each dimension based on their health scores in each dimension, as well as the number of safety-level controllers and the number of non-safety-level controllers; perform a weighted summation based on the average health scores of the safety-level controllers and non-safety-level controllers in each dimension to obtain the total score of the nuclear power plant control system; and determine the health status of the nuclear power plant control system based on the total score.

[0072] In some embodiments, the second evaluation module can also be specifically used to determine the health status of the nuclear power plant control system as faulty if the health status of the safety level controller is faulty in any one of the multiple sub-dimensions corresponding to each dimension.

[0073] It should be noted that other corresponding descriptions of the functional units involved in the nuclear power plant control system inspection device provided in this embodiment can be found in [reference needed]. Figure 1 and Figure 5 The corresponding description in [the document] will not be repeated here.

[0074] Based on the above, Figure 1 and Figure 5 Accordingly, this embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements the above-described method. Figure 1 and Figure 5 The method for inspecting the control system of a nuclear power plant is shown.

[0075] Based on this understanding, the technical solution of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as CD-ROM, USB flash drive, mobile hard drive, etc.) and includes several instructions to cause an electronic device (such as personal computer, server, or network device, etc.) to execute the methods of various implementation scenarios of this application.

[0076] Based on the above, Figure 1 and Figure 5 The method shown, and Figure 6To achieve the above objectives, the present application also provides an electronic device, specifically a personal computer, tablet computer, server, or other network device, as shown in the virtual device embodiment. This device includes a storage medium and a processor; the storage medium stores a computer program; the processor executes the computer program to achieve the above-described objectives. Figure 1 and Figure 5 The method for inspecting the control system of a nuclear power plant is shown.

[0077] Optionally, the aforementioned physical devices may also include a user interface, a network interface, a camera, radio frequency (RF) circuitry, sensors, audio circuitry, a Wi-Fi module, etc. The user interface may include a display screen, input units such as a keyboard, etc., and optional user interfaces may also include USB interfaces, card reader interfaces, etc. The network interface may optionally include standard wired interfaces, wireless interfaces (such as Wi-Fi interfaces), etc.

[0078] Those skilled in the art will understand that the physical device structure provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or combine certain components, or have different component arrangements.

[0079] The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the aforementioned physical device, supporting the operation of information processing programs and other software and / or programs. The network communication module is used to enable communication between the various components within the storage medium, as well as communication with other hardware and software in the information processing physical device.

[0080] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware platform, or it can be implemented by hardware.

[0081] This invention, through the implementation of an automated, standardized, and digital inspection process and the establishment of a health status assessment system that complies with nuclear safety laws, can promptly detect faults in the nuclear power plant control system, thereby improving the detection accuracy and efficiency of the nuclear power plant control system and ensuring the safe and stable operation of the nuclear power plant control system throughout its entire life cycle.

[0082] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of a preferred embodiment, and the modules or processes shown in the drawings are not necessarily essential for implementing this application. Those skilled in the art will understand that the modules in the apparatus of the embodiment can be distributed within the apparatus of the embodiment as described, or can be modified to be located in one or more apparatuses different from this embodiment. The modules of the above-described embodiment can be combined into one module, or further divided into multiple sub-modules.

[0083] The serial numbers in this application are for descriptive purposes only and do not represent the superiority or inferiority of any particular implementation scenario. The above disclosures are merely a few specific implementation scenarios of this application; however, this application is not limited thereto, and any variations conceived by those skilled in the art should fall within the protection scope of this application.

Claims

1. A method for inspecting a nuclear power plant control system, characterized in that, include: Obtain the target inspection list of the nuclear power plant control system, wherein the target inspection list records the IP addresses of the controllers of each sub-control system to be inspected in the nuclear power plant control system. Fault detection is performed on the communication network of the controller of each sub-control system to obtain the network fault detection results of the controller of each sub-control system. If it is determined from the network fault detection results that there is no network communication fault in the controllers of each sub-control system, then monitoring data in multiple dimensions are collected according to the type of controller of each sub-control system, wherein the type of controller includes safety-level controllers and non-safety-level controllers. The health status of the nuclear power plant control system is assessed based on the collected monitoring data from the multiple dimensions.

2. The method according to claim 1, characterized in that, The step of performing fault detection on the communication network of the controllers of each sub-control system to obtain the network fault detection results of the controllers of each sub-control system includes: For any one controller in each sub-control system, perform the first access to that controller; If the first access fails, a second access is performed on any one of the controllers based on the backup communication link and the first preset retry interval; If the second access fails, the system switches to a dedicated maintenance port and, based on the dedicated maintenance port and the second preset retry interval, performs a third access to any one of the controllers. If the third access fails, it is determined that any one of the controllers has a network communication failure, and the controller is removed from the target inspection list and marked as pending maintenance. If any one of the three accesses is successful, it is determined that there is no network communication failure in any of the controllers.

3. The method according to claim 1, characterized in that, The multi-dimensional approach includes performance metrics, hardware status, and software version. Each of these dimensions comprises multiple sub-dimensions. Monitoring data is collected across these multi-dimensional dimensions based on the controller type of each sub-control system, including: When the controller is a security-level controller, the following data are collected: CPU load, memory usage, and input / output module response latency under the performance metrics dimension; motherboard temperature, redundant module switching status, and security-level card communication status under the hardware status dimension; and firmware version, operating system version, application version, and their corresponding version approval number, version release time, version change content, and compatible hardware models under the software version dimension. When the controller is a non-security level controller, the following data are collected: CPU load, memory usage, disk usage, and network bandwidth usage under the performance metrics dimension; motherboard temperature, fan operating status, and power supply voltage stability under the hardware status dimension; and firmware version, driver version, and version update log under the software version dimension.

4. The method according to claim 1, characterized in that, Each dimension in the multi-dimensional framework includes multiple sub-dimensions. The assessment of the health status of the nuclear power plant control system based on the collected monitoring data across the multi-dimensional framework includes: Based on the monitoring data under multiple sub-dimensions corresponding to each dimension, the health status of the controllers of each sub-control system under the multiple sub-dimensions is evaluated. The health status of the nuclear power plant control system is comprehensively evaluated based on the health status of the controllers of each sub-control system under the various sub-dimensions.

5. The method according to claim 4, characterized in that, The step of evaluating the health status of the controllers of each sub-control system under the multiple sub-dimensions corresponding to each dimension, respectively, includes: Based on the corresponding regional range of the monitoring data under multiple sub-dimensions corresponding to each dimension, the health status of the controllers of each sub-control system under the multiple sub-dimensions is evaluated, wherein the health status includes health, early warning, and fault.

6. The method according to claim 5, characterized in that, The step of comprehensively evaluating the health status of the nuclear power plant control system based on the health status of the controllers of each sub-control system under the multiple sub-dimensions includes: Based on the health status of the controllers of each sub-control system under the multiple sub-dimensions, determine the health score of the controllers of each sub-control system under the multiple sub-dimensions. Based on the health scores of the controllers of each sub-control system under the multiple sub-dimensions, the health scores of the controllers of each sub-control system under each dimension are calculated, wherein the controller types include safety-level controllers and non-safety-level controllers. Based on the health scores of the security-level controller and the non-security-level controller in each dimension, and the number of security-level controllers and the number of non-security-level controllers, calculate the average health score of the security-level controller and the non-security-level controller in each dimension; The total score of the nuclear power plant control system is obtained by weighted summation of the average health scores of the safety-level controller and the non-safety-level controller in each dimension. The health status of the nuclear power plant control system is determined based on the total score.

7. The method according to claim 6, characterized in that, The method further includes: For any one of the multiple sub-dimensions corresponding to each dimension, if the health status of the safety level controller under any one of the sub-dimensions is faulty, then the health status of the nuclear power plant control system is directly determined to be faulty.

8. A nuclear power plant control system inspection device, characterized in that, include: The acquisition unit is used to acquire the target inspection list of the nuclear power plant control system, wherein the target inspection list records the IP addresses of the controllers of each sub-control system to be inspected in the nuclear power plant control system. The network detection unit is used to perform fault detection on the communication network of the controller of each sub-control system and obtain the network fault detection result of the controller of each sub-control system. The data acquisition unit is used to collect monitoring data in multiple dimensions according to the type of controller of each sub-control system if it is determined from the network fault detection result that there is no network communication fault in the controller of each sub-control system. The controller types include safety-level controllers and non-safety-level controllers. The health assessment unit is used to assess the health status of the nuclear power plant control system based on the collected monitoring data from the multi-dimensional dimensions.

9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.

10. An electronic device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Remote monitoring system and automatic network diagnosis method thereof

    CN102571438A

  • Network security management device for nuclear power plant and action method thereof

    CN107528809A

  • Security monitoring method for industrial control system network

    CN111262722A

  • Decentralized control system state monitoring method and device, storage medium and electronic equipment

    CN118170102A

  • Network communication link fault detection and positioning method, device, equipment and medium

    CN120658561A