Accident operation regulation assessment method, device, equipment and medium
By using automated assessment methods, accident conditions are acquired and compiled into scripts, which are then used to simulate nuclear power plant models. This solves the problems of low efficiency and reliance on manual verification of nuclear power plant accident procedures, and achieves efficient and reliable procedure assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA NUCLEAR POWER ENGINEERING COMPANY LTD
- Filing Date
- 2026-01-14
- Publication Date
- 2026-05-08
AI Technical Summary
In the existing technology, the verification of nuclear power plant accident operation procedures relies on manual methods, which are inefficient and dependent on the subjective factors of designers, resulting in unreliable and incomplete assessment conclusions.
Accident conditions are obtained through automated methods, accident operation procedures are compiled into executable scripts, and simulations are performed using nuclear power plant models to automatically evaluate the effectiveness of accident procedures, including the evaluation of guidance, control, and monitoring procedures.
The automation of accident procedure verification has been achieved, which has improved efficiency, reduced human error, and ensured the reliability and standardization of assessment results.
Smart Images

Figure CN121997577A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of nuclear power, and more particularly to an assessment method, apparatus, equipment, and medium for accident operation procedures. Background Technology
[0002] In nuclear power plants, the effectiveness of accident operating procedures (AOPs) is crucial. Currently, the common method for verifying the effectiveness of AOPs is manual. Designers must simulate accident scenarios step by step on an engineering simulator and manually execute each step of the procedure to observe the system response. After verification, designers also need to manually review the entire process and the final result, using their experience to judge whether the procedure can successfully guide the system to a safe state. If problems are found, the defects must be manually located, the AOPs modified, and the manual verification process repeated. This method forms the technical basis of current verification work.
[0003] The aforementioned verification methods, which heavily rely on manual labor, have significant limitations. First, the entire verification process is inefficient and time-consuming, with manual execution and evaluation consuming substantial manpower and time. Second, the reliability of verification conclusions is severely influenced by the subjective factors of the designers; their depth of technical knowledge, experience, and even human error during operation directly affect the accuracy and completeness of defect identification, making it difficult to fully discover and eliminate potential problems. These limitations make existing manual methods insufficient to meet the modern industrial safety requirements for comprehensive, efficient, and objective effectiveness assessments of accident operation procedures. Therefore, improvements are needed. Summary of the Invention
[0004] This invention provides a method, apparatus, equipment, and medium for evaluating accident operation procedures, in order to solve the technical problem that the effectiveness of accident operation procedures is difficult to evaluate.
[0005] The present invention provides a method for evaluating accident operation procedures, comprising: Acquire all types of accident conditions, and determine the first result for each type of accident condition after executing the corresponding different types of accident operation procedures; All accident operation procedures are compiled to obtain the corresponding accident operation scripts; Accident simulation is performed on the nuclear power plant model. For each type of accident condition, the corresponding accident operation script is executed to obtain the second result of the nuclear power plant model under each type of accident condition and the corresponding accident operation script. Under each type of accident condition, the effectiveness assessment of the corresponding accident operation procedure is completed based on the comparison between the second result and the corresponding first result.
[0006] In one embodiment of the present invention, the types of the accident operation procedures include guidance type, control type, and monitoring type; the number of control type accident operation procedures is multiple and corresponds one-to-one with each type of accident condition, the number of guidance type accident operation procedures and monitoring type accident operation procedures is one each; the first result includes a first guidance result, a first control result, and a first monitoring result; The process of acquiring all types of accident conditions and determining the first result after executing the corresponding different types of accident operation procedures under each type of accident condition includes: Obtain all types of accident conditions, and for each type of accident condition, determine the corresponding control class of accident operation procedures; Under each of the aforementioned accident conditions: The first guidance result is determined after the execution of the guidance-type accident operation procedure; the first guidance result includes the control-type accident operation procedure that is adapted to the operating conditions of this type of accident; The first control result after executing the corresponding control type of accident operation procedure is determined; the first control result includes the status parameters for restoring normal operating conditions, the safety signal for restoring normal operating conditions, and the response time of each device for restoring normal operating conditions; The first monitoring result is determined after the execution of the monitoring-type accident operation procedure; the first monitoring result includes the switching status of redundant equipment.
[0007] In one embodiment of the present invention, the first control result after determining the execution of the corresponding control class's accident operation procedure includes: Determine the abnormal state parameters and triggered safety signals under this type of accident condition; Execute the corresponding control-type accident operation procedure to restore the corresponding accident condition to the normal condition, obtain the status parameters for restoring the normal condition, the safety signal for restoring the normal condition, the response time of each device for restoring the normal condition, and generate the corresponding first control result.
[0008] In one embodiment of the present invention, the type of the accident operation script corresponds to the type of the accident operation procedure, and the second result includes a second guidance result, a second control result, and a second monitoring result; The process of performing accident simulation on a nuclear power plant model involves executing a corresponding accident operation script for each type of accident condition and obtaining a second result for the nuclear power plant model under each type of accident condition and the corresponding accident operation script, including: For each type of accident condition, determine the accident execution script for the control category; Accident simulations were performed on the nuclear power plant model under each of the aforementioned accident conditions: The second guidance result is determined after executing the guidance-type accident operation script; the second guidance result includes the control-type accident operation procedure adapted to the accident conditions of that type; The second control result is determined after executing the corresponding control class's accident execution script; the second control result includes the recovered status parameters, the recovered safety signals, and the response time of each device after recovery; Determine the second monitoring result after executing the monitoring-type accident execution script; the second monitoring result includes the switching status of redundant equipment.
[0009] In one embodiment of the present invention, the step of evaluating the effectiveness of the corresponding accident operation procedure based on the comparison result between the second result and the corresponding first result under each type of accident condition includes: The second guidance result for all types of accident conditions is compared with the corresponding first guidance result to obtain the corresponding comparison result; Judge all comparison results: If all comparison results are passed, the guiding accident operation procedure is deemed valid; If at least one comparison result is a failure, the guiding accident operation procedure is deemed invalid.
[0010] In one embodiment of the present invention, the step of comparing the second guidance result of all types of accident conditions with the corresponding first guidance result to obtain the corresponding comparison result includes: For each type of accident condition, the second guidance result for that type of accident condition is compared with the corresponding first guidance result: If the second guidance result is different from the corresponding first guidance result, the comparison result of this type of accident condition is determined to be a failure. When the second guidance result is the same as the corresponding first guidance result, a robustness test is performed on the accident execution script of the guidance class: if the test passes, the comparison result of the accident condition is determined to be passed; if the test fails, the comparison result of the accident condition is determined to be failed.
[0011] In one embodiment of the present invention, the step of evaluating the effectiveness of the corresponding accident operation procedure based on the comparison result between the second result and the corresponding first result under each type of accident condition includes: For each type of accident condition, a corresponding parameter range is set based on the state parameters for restoring normal operation, and a corresponding duration threshold is set based on the response time of each device after restoring normal operation. The second control result of this type of accident condition is compared with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for returning to normal operating conditions, and the effectiveness evaluation of the corresponding accident operation procedure is completed based on the comparison results.
[0012] In one embodiment of the present invention, the status parameters include unit status parameters, equipment status parameters, and reactor shutdown status parameters; the parameter ranges include normal parameter ranges, abnormal parameter ranges, and alarm parameter ranges; the unit status parameters and the equipment status parameters respectively correspond to the normal parameter range, abnormal parameter range, and alarm parameter range; the reactor shutdown status parameters correspond to the normal parameter range and alarm parameter range. The second control result for this type of accident condition is compared with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for returning to normal operating conditions, and the effectiveness evaluation of the corresponding accident operation procedure is completed based on the comparison results, including: The second control result for this type of accident condition is compared with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for returning to normal operating conditions. When all restored status parameters are within the corresponding normal parameter range, all restored safety signals have returned to normal operating conditions, and the response time of each restored device is less than the corresponding time threshold, the control class accident operation procedure corresponding to this type of accident condition is deemed valid. When the partially recovered status parameters are within the corresponding normal parameter range, and the other recovered status parameters are within the corresponding abnormal parameter range, and all recovered safety signals have returned to normal operating conditions, and the response time of each recovered device is less than the corresponding time threshold, a comprehensive score is calculated based on all unit status parameters and all device status parameters, and the effectiveness evaluation of the control category of the accident operation procedure corresponding to this type of accident condition is completed based on the comprehensive score. When the recovered status parameter is within the corresponding alarm parameter range, and / or the recovered safety signal has not returned to normal operation, and / or the response time of the recovered equipment is less than the corresponding time threshold, the accident operation procedure of the control class corresponding to this type of accident condition is determined to be invalid.
[0013] In one embodiment of the present invention, the step of calculating a comprehensive score based on all unit status parameters and all equipment status parameters, and then evaluating the effectiveness of the control class of the accident operation procedure corresponding to this type of accident condition based on the comprehensive score, includes: Based on the normal or abnormal parameter range of each unit status parameter and each equipment status parameter, a status score is set for each unit status parameter and each equipment status parameter, and all status scores are weighted and summed to obtain a comprehensive score. Compare the overall score with the preset score threshold for this type of accident condition: When the overall score is greater than the score threshold, the accident operation procedure of the control class corresponding to this type of accident condition is deemed valid. Otherwise, the control-type accident operation procedures corresponding to this type of accident condition shall be deemed invalid.
[0014] In one embodiment of the present invention, the state score includes a unit score and an equipment score; the step of setting a state score for each unit state parameter and each equipment state parameter based on the normal or abnormal parameter range in which each unit state parameter and each equipment state parameter respectively belong, and then weighting and summing all state scores to obtain a comprehensive score, includes: Based on the normal or abnormal parameter range of each unit's status parameter, a unit score is set for that unit's status parameter. The product of the unit score and the corresponding preset weight coefficient is calculated to obtain the unit rating for that unit's status parameter. Based on the normal or abnormal parameter range of each device status parameter, a device score is set for that device status parameter, and the product of the device score and the corresponding preset weight coefficient is calculated to obtain the device rating of that device status parameter. A comprehensive score is calculated based on the scores of all generating units and all equipment.
[0015] In one embodiment of the present invention, the step of evaluating the effectiveness of the corresponding accident operation procedure based on the comparison result between the second result and the corresponding first result under each type of accident condition includes: The second monitoring results for all types of accident conditions are compared with the corresponding first monitoring results to obtain the comparison results. Judge all comparison results: If all comparison results are passed, the operating procedures for monitoring-related accidents are deemed valid. If at least one comparison result is a failure, the operation procedure for monitoring-related accidents is deemed invalid.
[0016] In one embodiment of the present invention, the step of comparing the second monitoring results of all types of accident conditions with the corresponding first monitoring results to obtain the corresponding comparison results includes: For each type of accident condition, the second monitoring result for that type of accident condition is compared with the corresponding first monitoring result: If the second monitoring result differs from the corresponding first monitoring result, the comparison result for this type of accident condition is determined to be a failure. When the second monitoring result is the same as the corresponding first monitoring result, the comparison result of this type of accident condition is determined to be a pass.
[0017] The present invention also provides an evaluation device for accident operation procedures, comprising: The accident acquisition module is used to acquire all types of accident conditions and determine the first result after executing the corresponding different types of accident operation procedures for each type of accident condition. The procedure compilation module is used to compile all accident operation procedures to obtain the corresponding accident operation scripts; The accident simulation module is used to perform accident simulation on the nuclear power plant model, execute the corresponding accident operation script for each type of accident condition, and obtain the second result of the nuclear power plant model under each type of accident condition and the corresponding accident operation script. The procedure evaluation module is used to evaluate the effectiveness of the corresponding accident operation procedure based on the comparison between the second result and the corresponding first result under each type of accident condition.
[0018] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the evaluation method for the accident operation procedure.
[0019] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the evaluation method for the accident operation procedure as described above.
[0020] The beneficial effects of this invention are as follows: By automatically compiling various accident operation procedures into accident operation scripts recognizable by an engineering simulator, and driving the nuclear power plant model to automatically execute accident simulations and acquire results, the accident procedure verification process is automated, completely changing the traditional mode that relies on manual step-by-step operation and observation. This automated method significantly improves verification efficiency and shortens the verification cycle. This process eliminates the subjective dependence of evaluation results on the individual technical level and experience of designers, effectively reducing human error and making evaluation conclusions more reliable and standardized. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0022] In the attached diagram: Figure 1 A flowchart of an evaluation method for an accident operation procedure provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of an evaluation device for accident operation procedures provided in one embodiment of the present invention; Figure 3 This is a schematic diagram of an electronic device provided in one embodiment of the present invention.
[0023] The reference numerals in the attached figures are as follows: 100, accident acquisition module; 200, procedure compilation module; 300, accident simulation module; 400, procedure evaluation module; 500, electronic equipment; 510, memory; 520, processor. Detailed Implementation
[0024] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.
[0025] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. The drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0026] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.
[0027] Please see Figure 1This invention discloses an evaluation method for accident operation procedures, which is mainly applied to the design verification and optimization of accident operation procedures in nuclear power plants. This evaluation method compiles the procedures into automatically executable scripts and establishes an automated monitoring, analysis, and evaluation system to achieve a systematic and automated evaluation of the capability and effectiveness of accident operation procedures in responding to various accident conditions, thereby providing technical support for improving the reliability of the procedures and the safety level of nuclear power plants. The evaluation method includes the following steps: S10, obtaining all types of accident conditions and determining the first result after executing the corresponding different types of accident operation procedures under each type of accident condition.
[0028] In some embodiments, when executing S10, specifically, S10 includes: acquiring all types of accident conditions, and for each type of accident condition, determining the corresponding control-type accident operation procedure. The types of accident operation procedures include guidance-type, control-type, and monitoring-type; there are multiple control-type accident operation procedures, each corresponding one-to-one with each type of accident condition; the number of guidance-type and monitoring-type accident operation procedures is one each.
[0029] In some embodiments, based on the unit design and safety analysis of a nuclear power plant, a comprehensive list of all types of accident conditions can be obtained. This list covers classic accident conditions that the nuclear power plant design anticipates needing to address, such as steam generator heat transfer tube rupture, small leaks in reactor coolant piping, and plant-wide power outages. Then, for each type of accident condition in the list, corresponding control-type accident operation procedures are determined based on the design documents, providing specific control and operational guidance for that type of accident. For example, for the accident condition "steam generator heat transfer tube rupture," the corresponding control-type accident operation procedure could be "Procedure A-1"; another example is "Small leak loss in the primary coolant circuit accident," where the corresponding control-type accident operation procedure could be "Procedure B-1." These control-type accident operation procedures correspond one-to-one with the type of accident condition.
[0030] In some embodiments, once a list of accident conditions and corresponding control class accident operation procedures have been determined, subsequent analysis can be conducted category by category, based on the type of accident condition. For example, the accident condition "steam generator heat transfer tube rupture" can be analyzed first, followed by the accident condition "primary loop small rupture water loss accident". In the analysis process for each type of accident condition, it is necessary to determine the expected results to be achieved after executing various accident operation procedures under that type of accident condition.
[0031] In some embodiments, S10 further includes: determining a first guidance result after executing a guidance class of accident operation procedures under each type of accident condition; the first guidance result includes a control class of accident operation procedures that are adapted to the type of accident condition.
[0032] In some embodiments, for the type of accident condition currently being analyzed, it is necessary to determine the expected result that should be obtained after executing a unique guiding accident operation procedure, i.e., the first guiding result. The role of the guiding accident operation procedure is to guide the operator to determine the nature of the accident based on initial, limited unit status information and to guide the execution of a specific control procedure. Therefore, for the current specific accident condition, the content of its first guiding result is clear: by executing the judgment logic of the guiding accident operation procedure, it should ultimately correctly guide the execution of the specific control procedure that matches this type of accident condition. For example, for the "steam generator heat transfer tube rupture" condition, its first guiding result is that, through the steps of the guiding accident operation procedure, it ultimately points to and should execute the control procedure "A-1".
[0033] In some embodiments, S10 further includes: determining a first control result after executing the corresponding control class's accident operation procedure under each type of accident condition; the first control result includes state parameters for restoring normal operating conditions, safety signals for restoring normal operating conditions, and response times of each device for restoring normal operating conditions.
[0034] In some embodiments, the step of determining the first control result after executing the accident operation procedure of the corresponding control class includes: Determine the abnormal state parameters and triggered safety signals under this type of accident condition; Execute the corresponding control-type accident operation procedure to restore the corresponding accident condition to the normal condition, obtain the status parameters for restoring the normal condition, the safety signal for restoring the normal condition, the response time of each device for restoring the normal condition, and generate the corresponding first control result.
[0035] In some embodiments, when analyzing the expected results of control-type accident operation procedures, it is first necessary to accurately define which abnormal primary unit state parameters (such as containment integrity, secondary loop integrity, primary loop subcooling, etc.) and secondary equipment state parameters (such as steam generator level, pressurizer level, etc.) will occur when the current accident condition begins and develops. Simultaneously, it is necessary to identify which important unit safety signals (such as shutdown signals, dedicated safety facility drive signals, etc.) will be triggered. This analysis, based on the unit's design baseline safety analysis, details the deterioration path of state parameters and the response logic of the safety system under specific accident conditions.
[0036] In some embodiments, after defining the abnormal state parameters and safety signals, it is necessary to analyze the final recovery state that the unit should achieve if it operates strictly according to the accident operation procedure (e.g., procedure A-1) designed for that type of accident condition. This analysis determines the specific numerical range or stable state to which various abnormal state parameters (such as steam generator level, primary loop pressure, etc.) should be restored under ideal and complete procedure execution; these are the state parameters for restoring normal operation. All important safety signals of the unit triggered during the accident should be reset or restored to a safe, non-triggered state; these are the safety signals for restoring normal operation. Simultaneously, the expected response time range for each piece of equipment (such as pumps and valves) required to act in the accident operation procedure, from receiving the instruction to completing the prescribed action, is the response time of each piece of equipment for restoring normal operation. These three parts together constitute the expected first control result after executing the control procedure.
[0037] In some embodiments, S10 further includes: determining a first monitoring result after executing the monitoring class's accident operation procedure under each type of accident condition; the first monitoring result includes the switching status of redundant equipment.
[0038] In some embodiments, for the type of accident condition currently being analyzed, it is also necessary to determine the expected result that should be obtained after executing a unique monitoring-type accident operation procedure, i.e., the first monitoring result. The monitoring-type accident operation procedure focuses on monitoring the status and automatic switching functions of critical redundant equipment. Therefore, for the current type of accident condition, the first monitoring result is specifically manifested as follows: when the accident condition causes a series (or a single) of critical equipment (such as an emergency diesel engine or a safety injection pump) to fail, the monitoring-type accident operation procedure should ensure that the backup redundant series (or backup equipment) can be correctly monitored for faults according to design requirements and successfully and automatically switch over and put into operation. This expected successful switching status of redundant equipment is the first monitoring result under this type of accident condition.
[0039] Please see Figure 1 In some embodiments, the evaluation method further includes the following steps: S20, compiling all accident operation procedures to obtain the corresponding accident operation scripts.
[0040] In some embodiments, to automate the execution and verification of accident operation procedures, all accident operation procedures to be evaluated need to be compiled to obtain accident operation scripts that can be recognized and automatically executed by the engineering simulator. The compilation process needs to cover all types of accident operation procedures, including unique guidance classes, unique monitoring classes, and multiple control classes that correspond one-to-one with accident conditions. The compilation process can be performed using a visual, dedicated compilation tool to reduce the programming skills required of the procedure designers. The core of the compilation lies in transforming the diagnostic logic and operational procedures contained in the paper procedure text into structured machine instructions. The entire compilation process is mainly divided into two collaborative parts: a procedure logic calculation compilation module and a procedure path compilation module.
[0041] In some embodiments, the procedural logic calculation compilation module focuses on defining the internal operational rules for each basic logic unit (i.e., "symbol"). Designers design or select standardized logic symbol graphics in the symbol style editing interface, specifying the quantity and direction of their inputs and outputs. These standard symbols can be stored in a symbol library for reuse. Subsequently, in the symbol logic editing interface, each symbol is specifically configured with the input data (such as specific pressure or liquid level signals) that it needs to collect from the engineering simulator, and the internal judgment or calculation logic of the symbol is written (e.g., comparing whether the input value exceeds a threshold, or calculating the difference between two parameters). After the logic editing is completed, the procedural logic calculation compilation module automatically converts this configuration into low-level logic code containing data read addresses, calculation algorithms, and output conditions.
[0042] In some embodiments, the procedure path compilation module is responsible for arranging the execution order of all symbols to construct a complete procedure flow. Designers use "Start" and "End" symbols in the module's visual interface to mark the start and end of the flow. Connecting lines are drawn to link the various logic symbols in the required sequence of steps. The end of the connecting line without an arrow serves as the "input" connected to the "output" of the previous symbol, while the end with an arrow serves as the "output" connected to the "input" of the next symbol. This connection method establishes the transmission path of logic signals between symbols. When the flow starts, signals are transmitted sequentially along the paths defined by the connecting lines, activating the inputs of downstream symbols, thereby triggering their pre-compiled logic operations and generating outputs, thus achieving automated sequential execution of the entire procedure steps.
[0043] In some embodiments, through the collaborative work of the aforementioned procedure logic calculation compilation module and procedure path compilation module, the functional definition of individual logic units and the overall procedure flow arrangement are completed respectively. Finally, the compilation tool integrates these two parts of information (i.e., the internal logic code of each symbol and the connection relationships between them) and encapsulates them into an independent, executable incident execution script. This incident execution script is configured with unified data input and output interfaces to facilitate subsequent instruction interaction and data exchange with the engineering simulator, thereby preparing for automated verification. This compilation process must be repeated for each control-type incident execution procedure, as well as the unique guidance-type and monitoring-type incident execution procedures, to generate their respective corresponding incident execution scripts.
[0044] Please see Figure 1 In some embodiments, the evaluation method further includes the following steps: S30, performing accident simulation on the nuclear power plant model, executing the corresponding accident operation script for each type of accident condition, and obtaining the second result of the nuclear power plant model under each type of accident condition and the corresponding accident operation script; wherein, the type of the accident operation script corresponds to the type of the accident operation procedure, and the second result includes the second guidance result, the second control result, and the second monitoring result.
[0045] In some embodiments, when S30 is executed, specifically, S30 includes: determining the accident execution script for each type of accident condition.
[0046] In some embodiments, for each preset accident condition, it is necessary to determine the appropriate control class accident execution script. First, based on the list of classic accident conditions determined during the unit design phase, such as main steam pipeline rupture accidents and primary loop small-break water loss accidents, accident execution scripts specifically designed to handle these particular accident conditions are identified and selected from the compiled accident execution script library. This ensures that in subsequent simulation verification, each accident condition can invoke its specially designed control strategy script, thus laying the foundation for evaluating the targeted control capabilities of the procedures. These control class accident execution scripts are compiled with their logic and instructions closely matched to the corresponding operating conditions.
[0047] In some embodiments, after determining the accident execution scripts for the control classes corresponding to all accident conditions, the engineering simulator is started to simulate the nuclear power plant model. For each type of accident condition in the accident condition list, the nuclear power plant model is initialized to the initial state of that accident condition, simulating the initial disturbances of the accident condition, such as equipment failure or parameter mutations. Subsequently, through a pre-established data interface, the corresponding control class accident execution scripts, as well as the unique guidance class accident execution scripts and the unique monitoring class accident execution scripts, are loaded into the simulation environment. The entire simulation process will automatically execute these scripts and synchronously collect dynamic change data of unit status parameters and important safety signals in real time.
[0048] In some embodiments, S30 further includes: performing accident simulation on the nuclear power plant model, and determining a second guidance result after executing the accident operation script of the guidance class under each type of accident condition; the second guidance result includes an accident operation procedure of the control class that is adapted to the type of accident condition.
[0049] In some embodiments, the core function of the guided accident operation script is to perform logical judgments based on the real-time status parameters of the unit (such as primary loop pressure, steam generator level, etc.) in the early stages of an accident, when the specific accident type has not yet been clearly diagnosed. This allows the script to filter from multiple control-type accident operation procedures and direct to the one most suitable for the current unit state. Therefore, the second guidance result is specifically reflected in the name or identifier of the specific control-type accident operation procedure ultimately recommended for execution by the guidance logic in this simulation operation. This result is a key basis for evaluating the diagnostic accuracy of the guided procedure.
[0050] In some embodiments, S30 further includes: performing accident simulation on the nuclear power plant model, and determining the second control result after executing the corresponding control class accident operation script under each type of accident condition; the second control result includes the recovered state parameters, the recovered safety signals, and the recovered response time of each device.
[0051] In some embodiments, the second control result includes three specific aspects: First, the restored state parameters, i.e., the stable values of key unit parameters (such as regulator liquid level and primary circuit temperature) at the end of the accident handling, used to determine whether the parameters have been successfully controlled within a safe range; second, the restored safety signals, recording the safety signal states that were triggered during the accident and eventually returned to normal under the control of the procedures; and finally, the response time of each device after recovery, i.e., the time elapsed from the issuance of instructions by the control-type accident operation script to the actual completion of actions by key safety devices (such as safety injection pumps and emergency diesel generators), used to analyze the timeliness of procedure execution.
[0052] In some embodiments, S30 further includes: performing an accident simulation on the nuclear power plant model, and under each type of accident condition, determining a second monitoring result after executing the accident operation script of the monitoring class; the second monitoring result includes the switching status of redundant equipment.
[0053] In some embodiments, a unique monitoring-type accident execution script is executed throughout the entire accident handling process, and the resulting second monitoring results are obtained. The core responsibility of the monitoring-type accident execution script is to monitor the operating status of critical redundant equipment (such as parallel-operated pumps and redundant power systems). Therefore, the second monitoring results mainly reflect the switching status of redundant equipment. Specifically, during the accident evolution and handling process, it is recorded whether the standby equipment can be successfully activated and put into operation according to preset logic when the primary equipment fails or its performance is substandard. This result is an important indicator for evaluating the effectiveness of the power plant's redundancy design and the monitoring logic of the procedures.
[0054] Please see Figure 1 In some embodiments, the evaluation method further includes the following steps: S40, under each type of accident condition, based on the comparison result between the second result and the corresponding first result, to complete the effectiveness evaluation of the corresponding accident operation procedure.
[0055] In some embodiments, when S40 is executed, S40 may specifically include: comparing the second guidance result of all types of accident conditions with the corresponding first guidance result to obtain the corresponding comparison result.
[0056] In some embodiments, the step of comparing the second guidance result of all types of accident conditions with the corresponding first guidance result to obtain the corresponding comparison result may include: For each type of accident condition, the second guidance result for that type of accident condition is compared with the corresponding first guidance result: If the second guidance result is different from the corresponding first guidance result, the comparison result of this type of accident condition is determined to be a failure. When the second guidance result is the same as the corresponding first guidance result, a robustness test is performed on the accident execution script of the guidance class: if the test passes, the comparison result of this type of accident condition is determined to be a pass; if the test fails, the comparison result of this type of accident condition is determined to be a fail.
[0057] In some embodiments, for each preset type of accident condition, a detailed comparison needs to be made between the second guidance result obtained after simulating and executing the accident operation script of the guidance class and the first guidance result, which is pre-set as the evaluation benchmark for that type of accident condition. The first guidance result is the control class accident operation procedure that is most suitable for the specific accident condition, as determined in advance based on the unit safety analysis. Specifically, it is necessary to compare, one by one, whether the accident operation procedure actually recommended by the accident operation script of the guidance class (i.e., the second guidance result) is completely consistent with the expected recommended accident operation procedure (i.e., the first guidance result) for each type of accident condition. For example, for a specific main steam pipeline rupture accident condition, if the first guidance result is set to guide to "main steam pipeline isolation and control procedure", then it will be checked whether the second guidance result is also "main steam pipeline isolation and control procedure". This comparison process is the basis for subsequent correctness and robustness evaluation, ensuring that the evaluation is based on objective, pre-set standards.
[0058] In some embodiments, if, under a certain type of accident condition, the second guidance result obtained through simulation differs from the preset first guidance result—for example, the expected guidance procedure A is followed by the actual procedure B—the comparison result for that type of accident condition will be immediately determined to be a failure. This determination means that the initial guidance behavior of the guidance-type accident operation procedure under that specific accident condition fails to meet the correctness requirement; that is, its diagnostic logic fails to accurately guide the unit status to the correct handling path. Once a comparison fails, it usually indicates a fundamental logical flaw in the design of the guidance-type accident operation procedure, which may not be able to avoid erroneous intervention in real accidents. Therefore, this is a crucial veto judgment.
[0059] In some embodiments, if the second guidance result for a certain type of accident condition is the same as the first guidance result, this only satisfies the preliminary condition for correctness. To comprehensively evaluate the reliability of the guidance-type accident operation procedures, robustness testing is further performed on the guidance-type accident operation scripts for this type of accident condition. The robustness testing method involves artificially simulating, one by one, an error in one of the many state criteria of the guidance-type script, and then observing whether the accident operation script can still stably guide the expected control-type accident operation procedure (i.e., the first guidance result) under this flawed condition. If, in all test scenarios where a single criterion is incorrect, the control-type accident operation procedure ultimately called by the guidance-type accident operation script still matches the first guidance result, then the robustness test for this type of accident condition is deemed passed, and the comparison result for this type of accident condition is ultimately deemed to have passed. Conversely, if, in any single criterion error test, the accident operation script incorrectly guides to other control-type accident operation procedures, then the robustness test is deemed to have failed, and the corresponding comparison result is also deemed to have failed.
[0060] In some embodiments, S40 further includes: determining all comparison results: when all comparison results are passed, the guidance-type accident operation procedure is determined to be valid; if at least one comparison result is failed, the guidance-type accident operation procedure is determined to be invalid.
[0061] In some embodiments, after comparing each of the preset accident conditions, a global summary and check is performed on all independently generated comparison results. This is done by traversing and analyzing the final comparison results (i.e., comparison passed or failed) recorded for each type of accident condition. The purpose of this step is to comprehensively review the overall performance of the guided accident operation procedures in the face of different initiating events, determine whether they are reliable in all test scenarios, and provide a basis for subsequent overall effectiveness determination.
[0062] In some embodiments, if the inspection finds that the comparison results pass without exception for all types of accident conditions, this indicates that the guided accident operation procedure can correctly and robustly perform its guiding function across a wide fault spectrum. Therefore, the guided accident operation procedure is formally deemed to be effective overall. This means that the guided accident operation procedure not only accurately diagnoses but also retains fault tolerance even in extreme cases where individual measurement signals are unreliable, guiding the unit to a safe and correct handling path.
[0063] In some embodiments, if, during the inspection process, at least one accident condition comparison result is found to be unsuccessful, regardless of whether the reason for the failure is an initial guidance error or a robustness test failure, the entire accident operation procedure for that guidance type will be deemed invalid. This determination clearly indicates that the accident operation procedure for that guidance type has design deficiencies and cannot guarantee reliable operation under all preset severe accident conditions. It must be modified and improved to eliminate the identified defects and ensure the safe operation of the nuclear power plant.
[0064] In some embodiments, when S40 is executed, S40 may specifically include: S421, for each type of accident condition, setting a corresponding parameter range based on the state parameters of the recovery to normal operating condition, and setting a corresponding duration threshold based on the response time of each device in the recovery to normal operating condition.
[0065] In some embodiments, for each preset type of accident condition, it is necessary to set various benchmarks for evaluation based on the specific state required for the unit to return to normal operation under that accident condition. Specifically, firstly, based on the numerical range that the key state parameters should be in when returning to normal operation, it is necessary to set a corresponding parameter range for each state parameter. These parameter ranges can be divided into normal parameter ranges, abnormal parameter ranges, and alarm parameter ranges to accurately characterize the different health levels of parameters from severe deterioration to complete recovery. At the same time, based on the maximum time limit allowed for the execution of actions by each key device during the return to normal operation, corresponding duration thresholds are set. These thresholds are the key basis for judging whether the equipment response is timely and whether the function is available.
[0066] In some embodiments, S40 further includes: S422, comparing the second control result of the type of accident condition with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for restoring normal operation, and completing the effectiveness assessment of the corresponding accident operation procedure based on the comparison results; wherein, the status parameters include unit status parameters, equipment status parameters, and reactor shutdown status parameters; the parameter ranges include normal parameter ranges, abnormal parameter ranges, and alarm parameter ranges; the unit status parameters and equipment status parameters correspond to the normal parameter range, abnormal parameter range, and alarm parameter range, respectively; the reactor shutdown status parameters correspond to the normal parameter range and alarm parameter range.
[0067] In some embodiments, equipment status parameters are fundamental physical quantities for monitoring the operational status of a single, independent piece of equipment, directly reflecting whether the equipment is functioning normally within its designed functional range. For example, in the coolant system of a nuclear power plant, the main pump is one of its core components. For the main pump, equipment status parameters include its bearing temperature, motor operating current, and shaft seal water leakage flow rate. Under accident conditions, if the bearing temperature of the main pump continues to rise due to fault or overload and exceeds the normal parameter range, entering the alarm parameter range, this clearly indicates that the main pump itself has a risk of mechanical failure or poor lubrication, and it may be necessary to isolate or activate standby equipment.
[0068] In some embodiments, unit status parameters are macroscopic parameters that characterize the overall operating status and safety level of the entire unit or critical system, calculated or derived from multiple equipment status parameters and system process parameters. For example, the primary loop average temperature and pressurizer water level are two crucial unit status parameters. The primary loop average temperature is not determined by a single measurement point but rather by a combination of measurements from multiple loop hot sections, reflecting the overall balance between the heat generated by the reactor core and the heat removed by the steam generator. In the event of a power outage, even if the equipment status parameters of a single main pump are normal, the overall decrease in primary loop flow will cause the primary loop average temperature—the unit status parameter—to deviate from its normal range. Operators need to assess the macroscopic status of the entire reactor coolant system based on the trends in these parameters and execute appropriate control-type accident operating procedures to stabilize the unit.
[0069] In some embodiments, shutdown status parameters are the final criteria used to define and verify whether the unit has reached and can maintain a desired safe shutdown state after executing accident operating procedures. For example, after successful shutdown cooling, the accident operating procedures require the unit to reach and maintain specific primary loop pressure and temperature ranges; these are the key shutdown status parameters. Shutdown status parameters do not focus on the procedural details of accident handling but rather clearly define the standards for the safe endpoint the unit must reach. In the effectiveness evaluation of accident operating procedures, even if the unit and equipment status parameters recover well during the control process, if the final primary loop pressure fails to decrease to within the preset safe shutdown status parameter range, the accident operating procedures are still deemed to have failed to achieve their fundamental objective—guiding the unit to a safe state—and are therefore evaluated as invalid.
[0070] In some embodiments, when S422 is executed, S422 may include: comparing the second control result of the type of accident condition with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for restoring normal operating conditions.
[0071] In some embodiments, for the type of accident condition being evaluated, its second control result is compared one by one with all the aforementioned benchmarks. This includes comparing the status parameters after the accident handling with preset parameter ranges to check whether the status parameters fall into the ideal normal parameter range, the abnormal parameter range requiring attention, or the dangerous alarm parameter range. Simultaneously, the response times of each device are compared with preset time thresholds to determine whether the operation was completed within the allowed time window. Furthermore, it is verified that all recovered safety signals have returned to their normal operating condition state.
[0072] In some embodiments, S422 further includes: when all recovered state parameters are within the corresponding normal parameter range, all recovered safety signals have returned to normal operating conditions, and the response time of each recovered device is less than the corresponding time threshold, the control class accident operation procedure corresponding to this type of accident condition is determined to be valid.
[0073] In some embodiments, if the comparison results show that the final values of all state parameters affected by the accident and requiring restoration are entirely within the corresponding normal parameter range, this indicates optimal parameter health; simultaneously, all relevant safety signals have been confirmed to have returned to normal operating conditions after the procedure is executed, with no false triggering or non-triggering; and the response time of all critical equipment from receiving the instruction to completing the action is strictly less than the preset time threshold for this type of accident condition, indicating that all operations are timely and effective. When these three conditions are met simultaneously, the control-type accident operation procedure corresponding to this type of accident condition can be determined to be valid. This control-type accident operation procedure successfully guided the unit from the accident state to a completely normal operating state, and the entire process was rapid, leaving no lingering safety hazards.
[0074] In some embodiments, S422 further includes: when the partially recovered status parameters are within the corresponding normal parameter range, and the other recovered status parameters are within the corresponding abnormal parameter range, and all recovered safety signals have returned to normal operating conditions, and the response time of each of the recovered devices is less than the corresponding time threshold, calculating a comprehensive score based on all unit status parameters and all device status parameters, and completing the effectiveness assessment of the control category of the accident operation procedure corresponding to this type of accident condition based on the comprehensive score.
[0075] In some embodiments, the step of calculating a comprehensive score based on all unit status parameters and all equipment status parameters, and then evaluating the effectiveness of the control class of the accident operation procedures corresponding to this type of accident condition based on the comprehensive score, may include: Based on the normal or abnormal parameter range of each unit status parameter and each equipment status parameter, a status score is set for each unit status parameter and each equipment status parameter. All status scores are then weighted and summed to obtain a comprehensive score. The status score includes the unit score and the equipment score. Compare the overall score with the preset score threshold for this type of accident condition: When the overall score is greater than the score threshold, the accident operation procedure of the control category corresponding to this type of accident condition is deemed valid. Otherwise, the control-type accident operation procedures corresponding to this type of accident condition shall be deemed invalid.
[0076] In some embodiments, when the process reaches the point where a comprehensive score needs to be adjudicated, the calculated comprehensive score is compared with a pre-set scoring threshold for that type of accident condition. This scoring threshold is determined based on unit safety analysis and historical operating data, representing the minimum acceptable performance standard for that type of accident condition. The purpose of the comparison is to quantitatively assess whether the overall performance of the evaluation procedures in terms of parameter control has met the expected requirements.
[0077] In some embodiments, if the overall score is significantly greater than the preset scoring threshold for that type of accident condition, it indicates that although there may be some parameters in abnormal ranges or other non-ideal situations, the overall control effect of the accident operation procedure for that control type is still good and within an acceptable range. Therefore, the accident operation procedure for the control type corresponding to that type of accident condition is determined to be valid. This accident operation procedure for that control type has successfully managed and stabilized the unit's status on a macroscopic level.
[0078] In some embodiments, if the overall score is less than or equal to the score threshold, it indicates that the overall performance of the control class's accident operation procedure in terms of controlling the key parameters of the unit has failed to meet the standards, and there is significant control deficiency or fluctuation. Therefore, the control class's accident operation procedure corresponding to this type of accident condition is determined to be invalid. This control class's accident operation procedure needs to be optimized to improve its overall control capability under complex operating conditions. In some embodiments, the step of setting a state score for each unit state parameter and each equipment state parameter based on the normal or abnormal parameter range in which each unit state parameter and each equipment state parameter respectively fall, and then weighting and summing all state scores to obtain a comprehensive score, may include: Based on the normal or abnormal parameter range of each unit's status parameter, a unit score is set for that unit's status parameter. The product of the unit score and the corresponding preset weight coefficient is calculated to obtain the unit rating for that unit's status parameter. Based on the normal or abnormal parameter range of each device status parameter, a device score is set for that device status parameter, and the product of the device score and the corresponding preset weight coefficient is calculated to obtain the device rating of that device status parameter. A comprehensive score is calculated based on the scores of all generating units and all equipment.
[0079] In some embodiments, for each unit status parameter to be evaluated, its status score is first assigned based on the parameter range into which the final value of the unit status parameter falls after accident handling. Specifically, if the unit status parameter is within the normal parameter range, a higher unit score is assigned; if it is within the abnormal parameter range, a lower unit score is assigned. Then, this unit score is taken and multiplied by a pre-set weighting coefficient for that parameter. This weighting coefficient reflects the importance of the unit status parameter to the overall safety of the unit. The product of the two is the unit score for that unit status parameter.
[0080] In some embodiments, for each device status parameter to be evaluated, its status score is also set according to the parameter range in which its final value falls. If the device status parameter is in the normal parameter range, a higher device score is assigned; if it is in the abnormal parameter range, a lower device score is assigned. Then, this device score is multiplied by the corresponding preset weighting coefficient to obtain the device rating for that device status parameter.
[0081] In some embodiments, the unit scores of all unit status parameters are summed with the equipment scores of all equipment status parameters. This sum is the overall score used for final adjudication, which comprehensively reflects the overall effectiveness of control procedures in restoring and maintaining all critical unit and equipment parameters.
[0082] In some embodiments, S422 further includes: when there is a recovered state parameter located in the corresponding alarm parameter range, and / or, there is a recovered safety signal that has not returned to normal operation, and / or, there is a recovered device response time that is less than the corresponding time threshold, determining that the control class of the accident operation procedure corresponding to this type of accident operation is invalid.
[0083] In some embodiments, if any one or more of the following situations are found during the comparison: at least one recovered state parameter falls within the corresponding alarm parameter range, indicating that the state parameter is in a severely deteriorated or dangerous state; or at least one safety signal fails to return to normal operating conditions after the procedure is completed, possibly indicating a functional failure or false alarm; or at least one critical device's response time fails to meet the requirements, i.e., is greater than or equal to the corresponding time threshold, indicating that operational delays may affect the effectiveness of accident handling. If any of the above situations occur, the control-type accident operation procedure corresponding to this type of accident condition will be immediately determined to be invalid. This is a veto judgment, indicating that the control-type accident operation procedure is defective in dealing with this type of accident and cannot guarantee the ultimate safety of the unit.
[0084] In some embodiments, when S40 is executed, S40 may specifically include: S431, comparing the second monitoring results of all types of accident conditions with the corresponding first monitoring results to obtain the corresponding comparison results.
[0085] In some embodiments, when S431 is executed, specifically, S431 may include: For each type of accident condition, the second monitoring result for that type of accident condition is compared with the corresponding first monitoring result: If the second monitoring result differs from the corresponding first monitoring result, the comparison result for this type of accident condition is determined to be a failure. If the second monitoring result is the same as the corresponding first monitoring result, the comparison result of this type of accident condition is determined to be a pass.
[0086] In some embodiments, the core of evaluating the effectiveness of monitoring-based accident operation procedures lies in verifying whether these procedures can correctly drive redundant equipment to switch over when a specific fault occurs, in order to handle overlapping unit accidents. This will be illustrated by taking a detailed comparison of the second monitoring result with the first monitoring result specifically for an accident scenario such as a "single-train instrument compressed air system failure."
[0087] In some embodiments, if a second monitoring result observed by an engineering simulator shows that, after a failure of the operating single-train instrument air compressor system, the standby train instrument air compressor system fails to start as expected, or starts another unexpected system, then the comparison result for this type of accident condition is determined to be a failure. This indicates that the monitoring-related accident operating procedures have failed to respond correctly to the fault and cannot guarantee the continuous operation of the unit's support systems.
[0088] In some embodiments, if the second monitoring result observed by the engineering simulator shows that after a failure of the operating single-train instrument air compressor system, the standby train instrument air compressor system is successfully activated and put into operation, then the comparison result for this type of accident condition is determined to be a pass. This proves that the accident operation procedure for this monitoring type has successfully identified the system failure and correctly executed the redundancy switching logic, effectively addressing the potential risk of overlapping accidents.
[0089] In some embodiments, S40 further includes: determining all comparison results: when all comparison results are passed, the operation procedure for monitoring accidents is determined to be valid; if at least one comparison result is failed, the operation procedure for monitoring accidents is determined to be invalid.
[0090] In some embodiments, if the comparison results for all types of accident conditions are all passed, it means that the accident operation procedure for this monitoring class can correctly complete the redundant equipment switching function in all test scenarios, and therefore the accident operation procedure for this monitoring class is ultimately determined to be valid.
[0091] In some embodiments, if at least one comparison result is determined to be a failure, such as a switching failure occurring in the aforementioned instrument compressed air system fault test, then the fault operation procedure for that monitoring class will ultimately be deemed invalid. This indicates that the fault operation procedure for that monitoring class has design or logical flaws and cannot reliably handle faults within its scope of responsibility, and must be modified and improved.
[0092] In some embodiments, after the effectiveness evaluation process of the accident operation procedure is completed, a detailed diagnostic report will be generated based on the evaluation results and presented to the user intuitively through a human-machine interface. Taking the evaluation of an accident procedure for a specific control class as an example, suppose that the accident procedure for this control class is determined to be invalid when handling a coolant loss accident. Subsequently, based on the detailed data recorded in the evaluation process, the specific reasons for the invalidity of the procedure will be accurately located and listed in categories.
[0093] In some embodiments, the diagnostic report first identifies the specific defect of "unexpectedly deteriorating state parameters." During the execution of the coolant injection control logic of the accident procedure for this control class, in addition to the expected decrease in primary loop pressure, the critical parameter of steam generator feedwater flow rate also experienced an unexpected decrease, deviating from the normal range expected in the safety analysis. This unexpected deterioration means that the procedure's control strategy may, while mitigating a major accident, cause excessive intervention or adverse effects on related systems.
[0094] In some embodiments, the diagnostic report will secondly clearly show the "state parameters that did not recover as expected." In this assessment, after the operational sequence set by the control-type accident procedure was completed, the primary coolant charge state parameters failed to recover to the predetermined safe shutdown state parameter range as expected. This is the direct reason why the control-type accident procedure was deemed invalid. This indicates that the makeup water or isolation strategy in the design of the control-type accident procedure failed to effectively compensate for coolant loss and could not bring the unit to the predetermined safe state.
[0095] In some embodiments, the diagnostic report may also list “unintended triggered unit protection signals.” Assessment data showed that during the later stages of an accident response, the “reactor coolant pump low differential pressure protection” signal, which should not have been triggered, was unexpectedly activated. This unexpected protection signal triggering may have interfered with subsequent procedure execution paths and could even have caused unnecessary equipment shutdowns, revealing a potential conflict or mismatch between the control-related accident procedure operating logic and the unit protection system settings.
[0096] In some embodiments, the diagnostic report also records in detail "critical operations that do not meet availability time requirements." Through precise timestamp recording, it was discovered that after the issuance of the operational command requiring the activation of the emergency boron injection system in the control-type accident procedure, the actual response and deployment time of the relevant equipment exceeded the functional availability time window specified in the safety analysis report. For example, the excessive time delay between the issuance of the control-type accident procedure command and the measurement showing actual boron injection into the reactor coolant system caused the unit to face an unexpected risk of deviating from the nucleation boiling margin in the early stages of an accident, significantly reducing the effectiveness of the procedure.
[0097] In some embodiments, these specific diagnostic items based on monitoring data are integrated into the diagnostic report and presented one by one through a detailed display area of the human-computer interaction interface. For example, each invalid item can be highlighted in red or with a highlight box, and associated with a specific step in the procedure, thereby providing accident procedure designers with precise defect location and clearly indicating the specific steps in the accident procedure logic that need to be modified.
[0098] In some embodiments, finally, for accident procedures that were not deemed invalid but whose performance was not perfect, operators can be provided with "slightly deteriorated state parameters" information based on their comprehensive score. For example, in an evaluation of a procedure that was ultimately effective but received a low score, it can be noted that although the final state met the requirements, the pressure regulator level experienced a short-term but acceptable large fluctuation during the control process. This information helps operators gain a deeper understanding of the procedure's control characteristics, pay more attention to and prepare for these parameters that may experience small fluctuations in actual application, thereby making advance psychological and operational preparations and better optimizing the accident response process.
[0099] As can be seen, in the above scheme, firstly, by automatically compiling various accident operation procedures into accident operation scripts recognizable by the engineering simulator, and driving the nuclear power plant model to automatically execute accident simulations and acquire results, the verification process of accident procedures is automated, completely changing the traditional mode that relies on manual step-by-step operation and observation. This automation method significantly improves verification efficiency and shortens the verification cycle. Secondly, this method uses preset unit state parameters, important safety signals, and unit safety status as the first result, and objectively compares it with the second result obtained by automatic simulation, thereby completing the effectiveness assessment. This process eliminates the subjective dependence of the assessment results on the individual technical level and experience of the designers, effectively reducing human error and making the assessment conclusions more reliable and standardized. Finally, this method can systematically cover all preset accident conditions and conduct a comprehensive evaluation based on comprehensive monitoring and comparison results, thereby achieving the goal of a comprehensive and accurate assessment of the accident operation procedures' ability to respond to accidents.
[0100] Please see Figure 2 The present invention also discloses an evaluation device for accident operation procedures, and the above evaluation method can be applied to the evaluation device. The evaluation device may include an accident acquisition module 100, a procedure compilation module 200, an accident simulation module 300, and a procedure evaluation module 400.
[0101] In some embodiments, the accident acquisition module 100 can be used to acquire all types of accident conditions and determine the first result after executing the corresponding different types of accident operation procedures under each type of accident condition.
[0102] In some embodiments, the procedure compilation module 200 can be used to compile all accident operation procedures to obtain the corresponding accident operation scripts.
[0103] In some embodiments, the accident simulation module 300 can be used to perform accident simulation on a nuclear power plant model, execute the corresponding accident operation script for each type of accident condition, and obtain the second result of the nuclear power plant model under each type of accident condition and the corresponding accident operation script.
[0104] In some embodiments, the procedure evaluation module 400 can be used to evaluate the effectiveness of the corresponding accident operation procedure based on the comparison between the second result and the corresponding first result under each type of accident condition.
[0105] Specific limitations regarding the evaluation device can be found in the limitations of the evaluation method described above, and will not be repeated here. Each module in the aforementioned evaluation device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the memory in the electronic device, or stored in software form in the memory of the electronic device, so that the memory can call and execute the operations corresponding to each module.
[0106] Please see Figure 3 In some embodiments, electronic device 500 may include memory 510, processor 520 and bus, and may also include computer programs stored in memory 510 and executable on processor 520, such as programs for evaluating accident operation procedures.
[0107] In some embodiments, the memory 510 includes at least one type of readable storage medium, including flash memory, portable hard drive, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 510 may be an internal storage unit of the electronic device 500, such as the portable hard drive of the electronic device 500. In other embodiments, the memory 510 may be an external storage device of the electronic device 500, such as a plug-in portable hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the electronic device 500. Furthermore, the memory 510 may include both internal storage units and external storage devices of the electronic device 500. The memory 510 can be used not only to store application software and various types of data installed on the electronic device 500, such as the code of the evaluation method for accident operation procedures, but also to temporarily store data that has been output or will be output.
[0108] In some embodiments, the processor 520 may be composed of integrated circuits, such as a single-packaged integrated circuit or multiple integrated circuits with the same or different functions, including combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 520 is the control unit of the electronic device 500, connecting various components of the electronic device 500 via various interfaces and lines. It executes various functions of the electronic device 500 and processes data by running or executing programs or modules stored in the memory 510 (e.g., programs for evaluating accident operation procedures) and calling data stored in the memory 510.
[0109] In some embodiments, the processor 520 executes the operating system of the electronic device 500 and various installed applications. The processor 520 executes the applications to implement the steps in the evaluation method of the above-described accident operation procedure.
[0110] In some embodiments, a computer program may be divided into one or more modules, one or more of which are stored in memory 510 and executed by processor 520 to complete this application. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of the computer program in electronic device 500. For example, the computer program may be divided into an incident acquisition module 100, a procedure compilation module 200, an incident simulation module 300, a procedure evaluation module 400, etc.
[0111] The above embodiments are merely illustrative of the principles and effects of the present invention and are not intended to limit the invention. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of the present invention. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in the present invention should still be covered by the claims of the present invention.
Claims
1. A method for evaluating accident operation procedures, characterized in that, include: Acquire all types of accident conditions, and determine the first result for each type of accident condition after executing the corresponding different types of accident operation procedures; All accident operation procedures are compiled to obtain the corresponding accident operation scripts; Accident simulation is performed on the nuclear power plant model. For each type of accident condition, the corresponding accident operation script is executed to obtain the second result of the nuclear power plant model under each type of accident condition and the corresponding accident operation script. Under each type of accident condition, the effectiveness assessment of the corresponding accident operation procedure is completed based on the comparison between the second result and the corresponding first result.
2. The evaluation method for accident operation procedures according to claim 1, characterized in that, The types of accident operation procedures include guidance type, control type, and monitoring type; there are multiple control type accident operation procedures, each corresponding to one type of accident condition; there is one guidance type and one monitoring type accident operation procedure; the first result includes a first guidance result, a first control result, and a first monitoring result. The process of acquiring all types of accident conditions and determining the first result after executing the corresponding different types of accident operation procedures under each type of accident condition includes: Obtain all types of accident conditions, and for each type of accident condition, determine the corresponding control class of accident operation procedures; Under each of the aforementioned accident conditions: The first guidance result is determined after executing the guidance-type accident operation procedure; the first guidance result includes the control-type accident operation procedure that is adapted to the accident conditions of this type; The first control result after executing the corresponding control type of accident operation procedure is determined; the first control result includes the status parameters for restoring normal operating conditions, the safety signal for restoring normal operating conditions, and the response time of each device for restoring normal operating conditions; The first monitoring result is determined after the execution of the monitoring-type accident operation procedure; the first monitoring result includes the switching status of redundant equipment.
3. The evaluation method for accident operation procedures according to claim 2, characterized in that, The first control result after determining and executing the corresponding control class's accident operation procedure includes: Determine the abnormal state parameters and triggered safety signals under this type of accident condition; Execute the corresponding control-type accident operation procedure to restore the corresponding accident condition to the normal condition, obtain the status parameters for restoring the normal condition, the safety signal for restoring the normal condition, the response time of each device for restoring the normal condition, and generate the corresponding first control result.
4. The evaluation method for accident operation procedures according to claim 2, characterized in that, The type of the accident operation script corresponds to the type of the accident operation procedure, and the second result includes the second guidance result, the second control result, and the second monitoring result. The process of performing accident simulation on a nuclear power plant model involves executing a corresponding accident operation script for each type of accident condition and obtaining a second result for the nuclear power plant model under each type of accident condition and the corresponding accident operation script, including: For each type of accident condition, determine the accident execution script for the control class; Accident simulations were performed on the nuclear power plant model under each of the aforementioned accident conditions: The second guidance result is determined after executing the guidance-type accident operation script; the second guidance result includes the control-type accident operation procedure adapted to the accident conditions of that type; The second control result is determined after executing the corresponding control class's accident execution script; the second control result includes the recovered status parameters, the recovered safety signals, and the response time of each device after recovery; Determine the second monitoring result after executing the monitoring-type accident execution script; the second monitoring result includes the switching status of redundant equipment.
5. The evaluation method for accident operation procedures according to claim 4, characterized in that, The step of evaluating the effectiveness of the corresponding accident operation procedure under each type of accident condition, based on the comparison between the second result and the corresponding first result, includes: The second guidance result for all types of accident conditions is compared with the corresponding first guidance result to obtain the corresponding comparison result; Judge all comparison results: If all comparison results are passed, the guiding accident operation procedure is deemed valid; If at least one comparison result is a failure, the guiding accident operation procedure is deemed invalid.
6. The evaluation method for accident operation procedures according to claim 5, characterized in that, The comparison of the second guidance result for all types of accident conditions with the corresponding first guidance result to obtain the corresponding comparison result includes: For each type of accident condition, the second guidance result for that type of accident condition is compared with the corresponding first guidance result: If the second guidance result is different from the corresponding first guidance result, the comparison result of this type of accident condition is determined to be a failure. When the second guidance result is the same as the corresponding first guidance result, a robustness test is performed on the accident execution script of the guidance class: if the test passes, the comparison result of the accident condition is determined to be passed; if the test fails, the comparison result of the accident condition is determined to be failed.
7. The evaluation method for accident operation procedures according to claim 4, characterized in that, The step of evaluating the effectiveness of the corresponding accident operation procedure under each type of accident condition, based on the comparison between the second result and the corresponding first result, includes: For each type of accident condition, a corresponding parameter range is set based on the state parameters for restoring normal operation, and a corresponding duration threshold is set based on the response time of each device after restoring normal operation. The second control result of this type of accident condition is compared with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for returning to normal operating conditions, and the effectiveness evaluation of the corresponding accident operation procedure is completed based on the comparison results.
8. The evaluation method for accident operation procedures according to claim 7, characterized in that, The status parameters include unit status parameters, equipment status parameters, and reactor shutdown status parameters; the parameter ranges include normal parameter ranges, abnormal parameter ranges, and alarm parameter ranges; the unit status parameters and the equipment status parameters correspond to the normal parameter range, abnormal parameter range, and alarm parameter range, respectively; the reactor shutdown status parameters correspond to the normal parameter range and alarm parameter range, respectively. The second control result for this type of accident condition is compared with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for returning to normal operating conditions, and the effectiveness evaluation of the corresponding accident operation procedure is completed based on the comparison results, including: The second control result for this type of accident condition is compared with the corresponding parameter range, the corresponding duration threshold, and the corresponding safety signal for returning to normal operating conditions. When all restored status parameters are within the corresponding normal parameter range, all restored safety signals have returned to normal operating conditions, and the response time of each restored device is less than the corresponding time threshold, the control class accident operation procedure corresponding to this type of accident condition is deemed valid. When the partially recovered status parameters are within the corresponding normal parameter range, and the other recovered status parameters are within the corresponding abnormal parameter range, and all recovered safety signals have returned to normal operating conditions, and the response time of each recovered device is less than the corresponding time threshold, a comprehensive score is calculated based on all unit status parameters and all device status parameters, and the effectiveness evaluation of the control category of the accident operation procedure corresponding to this type of accident condition is completed based on the comprehensive score. When the recovered status parameter is within the corresponding alarm parameter range, and / or the recovered safety signal has not returned to normal operation, and / or the response time of the recovered equipment is less than the corresponding time threshold, the accident operation procedure of the control class corresponding to this type of accident condition is determined to be invalid.
9. The evaluation method for accident operation procedures according to claim 8, characterized in that, The process of calculating a comprehensive score based on all unit status parameters and all equipment status parameters, and then evaluating the effectiveness of the control-type accident operation procedures corresponding to this type of accident condition based on the comprehensive score, includes: Based on the normal or abnormal parameter range of each unit status parameter and each equipment status parameter, a status score is set for each unit status parameter and each equipment status parameter, and all status scores are weighted and summed to obtain a comprehensive score. Compare the overall score with the preset score threshold for this type of accident condition: When the overall score is greater than the score threshold, the accident operation procedure of the control class corresponding to this type of accident condition is deemed valid. Otherwise, the control-type accident operation procedures corresponding to this type of accident condition shall be deemed invalid.
10. The evaluation method for accident operation procedures according to claim 9, characterized in that, The status score includes a unit score and an equipment score; based on the normal or abnormal parameter range of each unit status parameter and each equipment status parameter, a status score is set for each unit status parameter and each equipment status parameter, and all status scores are weighted and summed to obtain a comprehensive score, including: Based on the normal or abnormal parameter range of each unit's status parameter, a unit score is set for that unit's status parameter. The product of the unit score and the corresponding preset weight coefficient is calculated to obtain the unit rating for that unit's status parameter. Based on the normal or abnormal parameter range of each device status parameter, a device score is set for that device status parameter, and the product of the device score and the corresponding preset weight coefficient is calculated to obtain the device rating of that device status parameter. A comprehensive score is calculated based on the scores of all generating units and all equipment.
11. The evaluation method for accident operation procedures according to claim 4, characterized in that, The step of evaluating the effectiveness of the corresponding accident operation procedure under each type of accident condition, based on the comparison between the second result and the corresponding first result, includes: The second monitoring results for all types of accident conditions are compared with the corresponding first monitoring results to obtain the comparison results. Judge all comparison results: If all comparison results are passed, the operating procedures for monitoring-related accidents are deemed valid. If at least one comparison result is a failure, the operation procedure for monitoring-related accidents is deemed invalid.
12. The evaluation method for accident operation procedures according to claim 11, characterized in that, The comparison of the second monitoring results for all types of accident conditions with the corresponding first monitoring results to obtain the comparison results includes: For each type of accident condition, the second monitoring result for that type of accident condition is compared with the corresponding first monitoring result: If the second monitoring result differs from the corresponding first monitoring result, the comparison result for this type of accident condition is determined to be a failure. When the second monitoring result is the same as the corresponding first monitoring result, the comparison result of this type of accident condition is determined to be a pass.
13. An evaluation device for accident operation procedures, characterized in that, include: The accident acquisition module is used to acquire all types of accident conditions and determine the first result after executing the corresponding different types of accident operation procedures for each type of accident condition. The procedure compilation module is used to compile all accident operation procedures to obtain the corresponding accident operation scripts; The accident simulation module is used to perform accident simulation on the nuclear power plant model, execute the corresponding accident operation script for each type of accident condition, and obtain the second result of the nuclear power plant model under each type of accident condition and the corresponding accident operation script. The procedure evaluation module is used to evaluate the effectiveness of the corresponding accident operation procedure based on the comparison between the second result and the corresponding first result under each type of accident condition.
14. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The steps of the evaluation method for the accident operation procedure as described in any one of claims 1 to 12 when the processor executes a computer program.
15. A computer-readable storage medium storing a computer program, characterized in that, When a computer program is executed by a processor, it implements the steps of the evaluation method for the accident operation procedure as described in any one of claims 1 to 12.