Nuclear reactor protection systems, methods of operating those systems, and module projection systems

A reactor protection system with multiple independent modules and redundant voting partitions addresses single fault propagation, ensuring safe nuclear reactor operations by logically verifying critical decisions, thereby enhancing reliability and safety.

JP2025124664AActive Publication Date: 2025-08-26NUSCALE POWER LLC +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025077800
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2014-03-06
Filing Date
2025-05-08
Publication Date
2025-08-26
Estimated Expiration
2034-12-23

AI Technical Summary

Technical Problem

Existing nuclear reactor protection systems are vulnerable to single fault propagation, which can lead to unsafe operating conditions due to hardware, software, or software-generated logic failures, compromising the safety and reliability of nuclear power plants.

Method used

The implementation of a reactor protection system comprising multiple functionally independent modules that provide redundant voting partitions and triple redundancy for reactor trip detection, along with a multi-tier voting scheme to prevent single fault propagation, ensuring safe operation by logically determining reactor trip decisions based on diverse inputs.

Benefits of technology

The system effectively prevents single fault propagation, maintaining reactor safety by independently verifying critical decisions through diverse and redundant modules, enhancing the reliability and safety of nuclear power plant operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025124664000001_ABST
    Figure 2025124664000001_ABST
Patent Text Reader

Abstract

To provide nuclear reactor protection systems and nuclear reactor instrumentation and control (I&C) systems that provide automatic initiating signals, automatic and manual control signals, and monitoring displays.SOLUTION: A nuclear reactor protection system comprises: a plurality of functionally independent modules, each of the modules configured to receive a plurality of inputs from a nuclear reactor safety system, and logically determine a safety action based at least in part on the plurality of inputs; and one or more nuclear reactor safety actuators communicably coupled to the plurality of functionally independent modules to receive the safety action determination based at least in part on the plurality of inputs.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application is a continuation of U.S. Provisional Patent Application No. 61 / 922,625, filed December 31, 2013. No. 14 / 198,891 filed March 6, 2014 Priority is claimed, and the entire contents of both applications are incorporated herein by reference. [Technical background] SUMMARY The present disclosure describes a nuclear reactor protection system and related methods. [background] The reactor protection system, and generally the reactor instrumentation and control (I&C) system, To mitigate the consequences of For example, I&C systems provide protection against unsafe nuclear power plants during steady-state and transient power operations. During normal operation, the I&C system monitors various parameters to provide protection against During abnormal operation and accident conditions, the I&C system measures the The system transmits a signal to the reactor protection system and, in some cases, to the reactor protection system's Transmitted to the Reactor Trip System (RTS) and the Engineered Safety Facility Actuation System (ESFAS) and initiates protective action based on predetermined set points. [overview] In a general implementation according to the present disclosure, the reactor protection system comprises a plurality of functionally independent each of the modules receiving a plurality of inputs from the reactor safety system; and configured to make logical decisions about safety actions based at least in part on multiple inputs. and multiple functionally independent modules based at least in part on multiple inputs. Communicatively connect multiple functionally independent modules to receive safety operational decisions and one or more reactor safety actuators.

[0002] In a first aspect, which can be combined with the overall implementation, a plurality of functionally independent modules Each module is responsible for every other module among multiple functionally independent modules. It provides protection against single fault propagation.

[0003] In a second aspect, which can be combined with any of the previous aspects, the reactor safety system , Engineered Safety Facility Actuation System (ESFAS), which consists of multiple functionally independent modules. The module receives multiple ESFAS inputs and generates an ESFAS output based, at least in part, on the ESFAS inputs. Logically determines SFAS component operation.

[0004] In a third aspect, combinable with any of the preceding aspects, a plurality of functionally independent The module provides redundant ESFAS voting divisions. In a fourth aspect, which may be combined with any of the previous aspects, the reactor safety system , including the reactor trip system (RTS), and multiple functionally independent modules receive a number of RTS inputs and generate RTS components based at least in part on the RTS inputs; Logically determines the operation of the

[0005] In a fifth aspect, combinable with any of the preceding aspects, a plurality of functionally independent The module provides redundant RTS voting partitions. In a sixth aspect combinable with any of the preceding aspects, a plurality of functionally independent Each of the modules may be integrated into any other of a number of functionally independent modules. This provides protection against single hardware fault propagation to the module.

[0006] In a seventh aspect combinable with any of the preceding aspects, a plurality of functionally independent Each of the modules may be integrated into any other of a number of functionally independent modules. This provides protection against single software fault propagation to the module.

[0007] In an eighth aspect combinable with any of the preceding aspects, a plurality of functionally independent Each of the modules may be integrated into any other of a number of functionally independent modules. This provides protection against single software-generated logic fault propagation to the module.

[0008] In a ninth aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules provide triple redundancy for a single pathway of reactor trip detection and decision making. do.

[0009] In a tenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module consists of multiple independent trip voting modules for each reactor trip component. Includes rules.

[0010] In an eleventh aspect combinable with any of the preceding aspects, a plurality of functionally independent The module is dedicated to a specific trip component and all other modules The reactor trip is logically determined by separating it from the module.

[0011] In a twelfth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module consists of multiple independent ESFAS actuation voting modules per ESF component. Includes providing a service.

[0012] In a thirteenth aspect combinable with any of the preceding aspects, a plurality of functionally independent A module can be any module that is dedicated to a specific ESF component and has all other modules. Decouple from the module and logically determine ESFAS operation.

[0013] In a fourteenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module includes a plurality of safety function modules. In a second aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules include a plurality of communication modules.

[0014] In a fifteenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules include a plurality of device interface modules. In a sixteenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules logically decide on reactor trip in a single hierarchical voting scheme.

[0015] In a seventeenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules logically decide on reactor trip in a multi-tier voting scheme. In an eighteenth phase, which can be combined with any of the previous phases, a multi-tier voting system The system includes a two-tier voting scheme.

[0016] In a nineteenth phase, which can be combined with any of the previous phases, a two-tier voting scheme The first tier involves a majority voting scheme. In a twentieth aspect, which can be combined with any of the previous aspects, a majority voting scheme includes a two-thirds voting scheme.

[0017] In a 21st phase, which can be combined with any of the previous phases, a two-tier voting scheme The second tier involves non-majority voting schemes. In a 22nd aspect, which can be combined with any of the previous aspects, the second tier is divided into four parts. This includes two voting schemes.

[0018] In another general implementation of the present disclosure, a method for determining a nuclear reactor trip includes: , Engineered Safety Facility Actuation System (ESFAS) or Reactor Trip System (RTS) From one of them, multiple functionally independent modules of the reactor protection system and receiving an input from a plurality of functionally independent modules, and determining either ESFAS safe operation or reactor trip based on multiple inputs. and based on the logical decision, to create multiple functionally independent modules. ESFAS component actuators or reactor trip devices communicatively connected to the reactor and operating one of the circuit breakers.

[0019] The first aspect, which can be combined with the overall implementation, further comprises a plurality of functionally independent modules. One of the modules may be used by any other of several functionally independent modules. This includes limiting single fault propagation to a module.

[0020] In a second aspect, which can be combined with any of the previous aspects, a single fault can be Hardware failure, single software failure, or single software-generated logic failure Contains at least one of these.

[0021] In a third aspect, combinable with any of the preceding aspects, a plurality of functionally independent The module determines whether the ESFAS safety operation or the fundamental operation is based at least in part on the input. The logical decision to trip one of the reactors is made by multiple functionally independent modules. The system determines whether the ESFAS is safe or whether the reactor is tripped through a triple redundant signal path. This involves logically determining:

[0022] In a fourth aspect, combinable with any of the preceding aspects, a plurality of functionally independent The module includes at least one of a redundant RTS voting unit or a redundant ESFAS voting unit. provide.

[0023] In a fifth aspect, combinable with any of the preceding aspects, a plurality of functionally independent The module determines whether the ESFAS safety operation or the fundamental operation is based at least in part on the input. The logical decision to trip one of the reactors is made by multiple functionally independent modules. The system allows multiple independent trip voting modules for each reactor trip component. This involves logically determining the ESFAS safe operation or reactor trip decision through the ESFAS.

[0024] In a sixth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module determines whether the ESFAS safety operation or the fundamental operation is based at least in part on the input. The logical decision to trip one of the reactors is made by multiple functionally independent modules. A specific module in the group can be switched off from all other modules in the group. This includes logically determining the ESFAS safe operation or reactor trip decision in isolation.

[0025] In a seventh aspect, which may be combined with any of the previous aspects, multiple functionally independent The module consists of multiple independent ESFAS-activated voting modules per ESF component. and the method further comprises: Multiple modules dedicated to a specific ESF component can be disconnected from all other modules. This includes logically determining ESFAS operation in isolation.

[0026] In an eighth aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules consist of multiple safety function modules, multiple communication modules, and multiple device interfaces. Includes an interface module.

[0027] In a ninth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module determines whether the ESFAS safety operation or the fundamental operation is based at least in part on the input. The logical decision to trip one of the reactors may be made by multiple functionally independent modules. The module will decide whether to approve ESFAS safe operation or reactor triggering in a single tier voting scheme. This includes logically determining the group decision.

[0028] In a tenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module then determines whether the ESFAS is safe or not, based at least in part on the input. The logical decision to make one of the reactor trip decisions is based on multiple functionally independent The module allows for ESFAS safe operation or reactor triggering in a multi-tier voting scheme. This includes logically determining the top decision.

[0029] In an eleventh phase, which can be combined with any of the previous phases, a multi-tier voting system The system includes a two-tier voting scheme. In a twelfth phase, which can be combined with any of the previous phases, a two-tier voting scheme The first tier involves a majority voting scheme.

[0030] In a thirteenth aspect, which can be combined with any of the previous aspects, a majority voting scheme includes a two-thirds voting scheme. In a fourteenth phase, which can be combined with any of the previous phases, a two-tier voting scheme The second tier involves non-majority voting schemes.

[0031] In a fifteenth aspect, which can be combined with any of the previous aspects, the second tier is divided into four parts. This includes two voting schemes. In another general implementation of the present disclosure, the reactor protection system comprises a single module. It contains multiple functionally independent modules that limit the transfer of a single fault to the system.

[0032] In another general implementation of the present disclosure, the reactor protection system includes three types of modules: A complex system that contains only one module, thereby minimizing the number of replaceable units on the work line. It contains a number of functionally independent modules.

[0033] In another general implementation according to the present disclosure, the reactor protection system It consists of multiple functionally independent modules, including a communication module that determines the schedule by which data passes through the system. Includes modules that have been

[0034] In another general implementation of the present disclosure, the reactor protection system includes a system architecture. The system architecture includes a reactor trip system that defines: For example, data is transferred to the original system via a path exclusively related to safety functions, rather than to post-accident monitoring functions. The trip signal is sent from the reactor trip system to the control room.

[0035] In another general implementation according to the present disclosure, the reactor protection system includes a plurality of functional Each of the plurality of functionally independent modules It is dedicated to a specific reactor trip breaker among multiple reactor trip breakers in the same facility.

[0036] In another general implementation according to the present disclosure, the reactor protection system includes a plurality of functional It includes a plurality of functionally independent modules, each of which is independent of the other modules. Decisions to trip / not trip the reactor or to activate / activate ESFAS are made completely independent of all No decision to be made.

[0037] In another general implementation according to the present disclosure, the reactor protection system includes a plurality of functional Each of the plurality of functionally independent modules A specific ESFAS equipment actuator is selected among multiple ESFAS equipment actuators in the same system. It is exclusive.

[0038] In another general implementation according to the present disclosure, the reactor protection device comprises a reactor safety system and logically determines a safety action based at least in part on the multiple inputs. and a means for receiving a safe operating decision based at least in part on a plurality of inputs. and means for trusting the

[0039] In a first aspect combinable with the overall implementation, a method for receiving a safety action decision is provided. The means receives a plurality of inputs from the reactor safety system and logically determines a safe operation. The communication device is communicatively connected to the means for transmitting the signal.

[0040] In a second aspect, which can be combined with any of the previous aspects, a reactor safety system The means for receiving multiple inputs from the equipment and logically determining safe operation shall be such that a single failure within the equipment Provides protection against propagation.

[0041] In a third aspect, which can be combined with any of the previous aspects, the reactor safety system , equipped with an Engineered Safety Facility Actuation System (ESFAS), which allows multiple inputs from the reactor safety system The means for receiving the force and logically determining a safe operation receives a plurality of ESFAS inputs. , logic for ESFAS component actuation based at least in part on ESFAS inputs. Decide objectively.

[0042] In a fourth aspect, which can be combined with any of the previous aspects, The means for receiving multiple inputs from the redundant ESFAS and logically determining the safe action is Provide a section.

[0043] In a fifth aspect, which may be combined with any of the preceding aspects, the reactor safety system , equipped with a reactor trip system (RTS) and receiving multiple inputs from the reactor safety system and wherein the means for logically determining a safe operation receives a plurality of RTS inputs and comprises at least Logically determines RTS component operation based in part on RTS input.

[0044] In a sixth aspect, which can be combined with any of the previous aspects, The means for receiving multiple inputs from the redundant RTS voting partitions and logically determining the safe action is Equipped with.

[0045] In a seventh aspect, which may be combined with any of the previous aspects, a reactor safety system The means for receiving multiple inputs from a single hardware device and logically determining safe operation shall be Provides protection against hardware fault propagation.

[0046] In an eighth aspect, which may be combined with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from the device and logically determining safe operation shall be implemented by a single software program within the device. Provides protection against software fault propagation.

[0047] In a ninth aspect, which may be combined with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from the device and logically determining safe operation shall be implemented by a single software program within the device. Provides protection against software-generated logic fault propagation.

[0048] In a tenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from and logically determining safe operation includes a reactor trip detector. It has triple redundant signal paths for knowledge and decision.

[0049] In an eleventh aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from and logically determining safe operation is the reactor trip controller. Each component has multiple independent trip voting modules.

[0050] In a twelfth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from and logically determining safe operation is The reactor trip is determined independently for each trip component.

[0051] In a thirteenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from the ESF components and logically determining safe operation shall be Each station will have multiple independent ESFAS-operated voting modules.

[0052] In a fourteenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from a specific ESF controller and logically determining safe operation is Independently determine ESFAS operation for each component.

[0053] In a fifteenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from and logically determining a safe operation includes multiple safety function modules. Equipped with a joule.

[0054] In a sixteenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from the communication modules and logically determining a safe operation may include: Equipped with a ruler.

[0055] In a seventeenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from multiple equipment interfaces and logically determining safe operation shall Equipped with a face module.

[0056] In an eighteenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from and logically determining a safe action is a single hierarchical voting scheme. The reactor trip is logically determined in the team.

[0057] In a nineteenth aspect combinable with any of the preceding aspects, a reactor safety system The means for receiving multiple inputs from and logically determining a safe action comprises a multi-tier voting scheme. The reactor trip is logically determined in the team.

[0058] In a twentieth phase, which can be combined with any of the previous phases, a multi-tier voting scheme is The system has a two-tier voting scheme. In a 21st phase, which can be combined with any of the previous phases, a two-tier voting scheme The first tier comprises a majority voting scheme.

[0059] In a twenty-second aspect, which can be combined with any of the previous aspects, a majority voting scheme has a two-thirds voting scheme. In a 23rd phase, which can be combined with any of the previous phases, a two-tier voting scheme The second tier comprises a non-majority voting scheme.

[0060] In a 24th aspect, which can be combined with any of the previous aspects, the second tier is divided into four parts. It has two voting schemes. Various implementations of the reactor protection system according to the present disclosure may have one, several, or more of the following features: For example, a nuclear reactor protection system may disable safety features in the system. and / or caused by software or software-generated logic errors that may disable As another example, a reactor protection system may: Incorporates key attributes including independence, redundancy, determinism, multi-tiered diversity, testability, and diagnosability The reactor protection system may ensure that the reactor is maintained in a safe state. As another example, a nuclear reactor protection system may be implemented in individual logic engines dedicated to specific functions. It may have increased simplicity through a symmetric architecture with functionality that is As an example, a nuclear reactor protection system is based on a simple deterministic protocol and has redundant paths. This may facilitate communication within the architecture, where communication is via

[0061] Details of one or more implementations of the subject matter described in this specification are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages of the present subject matter will become apparent from the description, drawings, and claims. It will become clear. [Brief explanation of the drawings]

[0062] [Figure 1] 1 illustrates a block diagram of an example implementation of a system including multiple nuclear systems and an instrumentation and control (I&C) system. [Figure 2A] 1 illustrates a block diagram of a modular protection system (MPS) for an I&C system for a nuclear power system. [Figure 2B] 1 illustrates a block diagram of a modular protection system (MPS) for an I&C system for a nuclear power system. [Figure 3A] 1 illustrates a block diagram of a trip decision block of an MPS of an I&C system for a nuclear system. [Figure 3B] 1 illustrates a block diagram of the Engineered Safety Facility Actuation System (ESFAS) of the MPS of the I&C system for nuclear systems. [Figure 4A-4B] 1 illustrates an exemplary chart illustrating a layered diversity strategy for mitigating software or software logic-based common cause failures within an MPS that ensures the I&C system is able to perform its intended safety function. [Figure 5] 1 illustrates a block diagram of a Safety Function Module (SFM) of an MPS of an I&C system for a nuclear system. [Figure 6]1 illustrates a block diagram of a communication module (CM) of an MPS of an I&C system for a nuclear system. [Figure 7] 1 illustrates a block diagram of an Equipment Interface Module (EIM) of an MPS of an I&C system for a nuclear system. [Figure 8] 1 illustrates an exemplary embodiment of a reactor protection system enclosure that communicatively connects one or more SFMs, EIMs, and CMs. [Figure 9A] 1 illustrates a block diagram of a trip decision level interconnection, an RTS level interconnection, and an ESFAS level interconnection utilizing one or more of an SFM, a CM, and an EIM. [Figure 9B] 1 illustrates a block diagram of a trip decision level interconnection, an RTS level interconnection, and an ESFAS level interconnection utilizing one or more of an SFM, a CM, and an EIM. [Figure 9C] 1 illustrates a block diagram of a trip decision level interconnection, an RTS level interconnection, and an ESFAS level interconnection utilizing one or more of an SFM, a CM, and an EIM. [Figure 10] 1 illustrates a diversity analysis diagram for an MPS of an I&C system for a nuclear system. [Figure 11] 1 illustrates a block diagram of an exemplary separation of MPS blocks into four tiers of protection. DETAILED DESCRIPTION OF THE INVENTION

[0063] [Detailed explanation] FIG. 1 illustrates a number of nuclear power systems 150 and a reactor instrumentation and control (I&C) system 13 5. In general, an I&C system System 135 provides automatic start signals, automatic and manual control signals, and monitoring and indicating displays. to prevent or mitigate the consequences of a fault condition in the system 100. 135 describes the normal reactor control and operation of the nuclear system 150 during steady-state and transient power operation. During normal operation, the instrumentation provides protection against unsafe reactor operation. The process parameters are measured and the signals are sent to the control system of the I&C system 135. During abnormal operating and fault conditions, the instrumentation sends signals to multiple parts (modules) of the I&C system 135. Part of the Model Protection System (MPS) 145, e.g. (to mitigate the consequences of an accident) Reactor Trip System (RTS) 147 and Engineered Safety Facility Actuation System (E The SFAS 148 may then be sent to initiate protective action based on predetermined set points.

[0064] In FIG. 1, the system 100 includes a plurality of I&C systems 135 electrically connected to the I&C system 135. nuclear power systems 150. Although only three nuclear power systems 150 are shown in this example, , fewer or more than the number of devices included in or connected to the system 100 There may be many (e.g., 6, 9, 12, or other numbers) of systems 150. In one preferred implementation, twelve nuclear power systems 15 included in the system 100 0 may be present, and one or more of the nuclear systems 150 may be , including modular light water reactors.

[0065] For each nuclear system 150, and although not explicitly shown, the reactor core provides heat. The heat can be utilized to generate electricity (e.g., as in a boiling water reactor). in the primary cooling loop or (as in pressurized water reactors, for example) in the secondary cooling loop. A vaporized coolant, such as steam, is used to power one or more turbines. The turbine may be driven to convert the thermal potential energy into electrical energy. After being compressed, the coolant is then returned to recover more heat energy from the reactor core. The nuclear system 150 is designed to minimize the risks associated with failures within the system. This is an example of any system that requires monitoring and protection functions to

[0066] In certain exemplary implementations of each reactor system 150, the core is cylindrical or capillary. The reactor core is located at the bottom of the cellular reactor vessel. It contains a quantity of fissile material that produces a controlled reaction that can occur. However, control rods may be used to control the rate of fission within the reactor core. Sodium, cadmium, boron, cobalt, hafnium, dysprosium, gadolinium, It may include samarium, erbium, and europium, or alloys and compounds thereof. However, these are only a few of the many possible control rod materials. In a nuclear reactor designed with an operating system, the and, in the case of a computer system, for at least a predetermined period of time without operator intervention or supervision. The laws of physics are used to ensure that safe operation of the reactor is maintained.

[0067] In some implementations, a cylindrical or capsule-shaped containment vessel surrounds the reactor vessel and contains the nuclear reactor. Within the reactor bay, the reactor pool is partially or completely submerged, e.g., below the waterline. The volume between the reactor vessel and the containment vessel is partially or completely evacuated to allow the reactor vessel to However, in other implementations, the reactor volume The volume between the reactor and the containment vessel is filled with gas and / or The containment vessel may be at least partially filled with a liquid or may be at least partially filled with a liquid. It may also be placed on a cart.

[0068] In certain implementations, the core is a liquid, e.g., water, which may contain boron or other additives. The coolant is immersed in the body and rises up the channels after coming into contact with the surface of the core. It moves across the top of the heat exchanger and downwards by convection along the inner wall of the reactor vessel. The coolant then transfers heat to the heat exchanger. After reaching the bottom of the reactor vessel, the core Contact with the cooling water causes the coolant to heat up, and the coolant rises again through the channels. do.

[0069] The heat exchanger within the reactor vessel may include any number of spiral coils wound around at least a portion of the channel. In another implementation, different numbers of spiral coils may be channeled in opposite directions. For example, a first spiral coil may be wound in a counterclockwise direction while a second spiral coil may be wound in a counterclockwise direction. The two spiral coils are wound in a clockwise spiral. However, they are configured differently. and / or other heat exchangers oriented differently, and implementations may be There is no restriction on points.

[0070] In Figure 1, normal operation of the reactor module involves the flow of heated coolant through channels. After contacting the heat exchanger, the refrigerant undergoes an endothermic process. In the example of Figure 1, the reactor vessel The coolant remains at pressure above atmospheric pressure, and thus the coolant vaporizes (e.g. This allows the food to maintain a high temperature without boiling.

[0071] As the temperature of the coolant in the heat exchanger increases, the coolant may begin to boil. Once the coolant begins to boil, the vaporized coolant, e.g., steam, is used to drive one or more turbines. The turbine converts the thermal potential energy of the steam into electrical energy. After condensation, the refrigerant is returned to a location near the base of the heat exchanger. do.

[0072] During normal operation of the nuclear power system 150 of FIG. , the I&C system 135, which are located at various locations within the nuclear system 150. The sensors in the nuclear system may monitor the system temperature, System pressure, primary and / or secondary coolant levels, and neutron flux may be measured. The signal representing the measurement value is transmitted to the I&C system 13 via a communication channel outside the nuclear system. You may report to the interface panel 5.

[0073] The illustrated I&C system 135 generally comprises a master control room 140, modules (or primary control units), MPS (Mutual Power Plant) Protection System (MPS) 145 and Non-Safe Modular Control System (MCS) 1 The main control room 140 contains the control and instrumentation cells for each nuclear system 150. Each control and instrument set 141 includes a manual 1E control 142, a 1E instruments 143, and non-1E controls and instruments 144. In some aspects, 1E" is an IEEE standard approved by, for example, the Nuclear Regulatory Commission Regulatory Guide 1.32 Regulations such as the requirements governing the 1E scheme in Section 3.7 of 308-2001 The 1E scheme can refer to emergency reactor shutdown, containment vessel isolation, core cooling, and the release of radioactive material into the environment, either essential for the heat removal of the containment and reactor, or otherwise. It specifies the safety classification of electrical equipment and systems that is essential when preventing significant emissions. Typically, certain controls and instruments (e.g., manual 1E control 142 and 1E instrument 143) are " 1E compliant, while other controls and instruments (e.g., non-1E controls and The meter 144) does not have to be "1E" compliant.

[0074] Non-1E controls and instruments 144 are in two-way communication with MCS 155. 5 may provide control and monitoring of the non-safety portions of the nuclear system 150. The MCS155 suppresses operational transients to prevent unit trips and Among other things, this re-establishes steady state unit operation.

[0075] As shown in FIG. 1, the MPS 145 includes a manual 1E control device 142 and an 1E instrument 143. The MPS145 generally initiates safety operations and MPS145 is generally required to initiate reactor shutdown. From the sensor to the final operating device (power source, sensor, signal conditioner, starting circuit, (hardware, logic, bypass, control board, interconnects, and actuation devices) This includes all devices (including software and firmware).

[0076] MPS145 includes RTS147 and ESFAS148. RTS147 has several In this aspect, plant parameters that can be used to generate reactor trips are monitored. To observe the results, four independent and separate groups with independent measurement channels (e.g., Physical characteristics of process channels with Class-1E electrical channel designation (A, B, C, or D) a general classification in which a separate and independent power source and process instrumentation transmitter are provided; and Each group is physically and electrically independent of the other groups. Each measurement channel contains a physical classification of the measurement channel. The coincidence logic of the RTS147 ensures that any single fault will trip when required. Any failure in a single measurement channel cannot prevent a reactor trip. It may be designed to be unlikely to produce unnecessary reactor trips.

[0077] In some aspects, ESFAS148 is a four-independent system with independent measurement channels. Contains separate, isolated groups, with independent measurement channels monitoring plant parameters and The event parameters may be used to initiate the operation of Engineered Safety Facility (ESF) equipment. Each measurement channel trips when a parameter exceeds a predetermined set point. The coincidence logic of 8 ensures that any single failure could prevent safeguard activation when needed. and any single failure in a single measurement channel will not result in unnecessary safeguard activation. may be designed to have no possibility of generating

[0078] The system 100 provides four levels of protection as specified in NUREG / CR-6303. layer, for example, to operate the reactor or to shut down and cool the reactor. Specific application of the principles of defense in depth to reactor-mounted instrumentation and control system configurations. In particular, the four tiers are the control system, reactor trip or scram systems, ESFAS, and monitoring and instrumentation systems (e.g., the slowest and most flexible To operate equipment at a level of protection that is nominally assigned to the other three levels Both Class 1E and non-Class 1E manual controls, monitors, and meters required for (a hierarchy of protection, including the device).

[0079] The control system hierarchy is typically MCS155 (e.g., non-Class 1E manual or automatic control devices). The MCS155 periodically prevents the reactor from running into an unsafe operating regime. and are generally used to operate the reactor within the safe power operating range. Annunciators and alarms may be included in the control hierarchy. Typically, any equipment that meets specific regulations and / or requirements, e.g., requirements for remote shutdown panels. The reactor control functions performed by the control system hierarchy are contained in MCS155. The MCS 155 may, for example, maintain the system 100 within its operational limits and This includes features that avoid the need for a backup or ESF activation.

[0080] The reactor trip system hierarchy is typically RTS147, e.g., in response to an uncontrolled runaway. This hierarchy typically includes safety components designed to rapidly reduce core reactions in response to a fault. Instrumentation to detect potential or actual runaway, rapid and full insertion of reactor control rods, It also consists of equipment and processes for neutron ionization, as well as certain chemical neutron moderation systems (e.g. As shown, the reactor trip hierarchy The automatic reactor trip function is included in MPS 145 (e.g., in RTS 147). .

[0081] The ESFAS hierarchy typically includes ESFAS modules 148, which are part of the MPS 145. The ESFAS layer implemented in the ESFAS module 148 typically or otherwise provide three physical barriers to radioactive release (e.g., reactor fuel rods) Includes safety equipment that helps maintain the integrity of the reactor (cladding, reactor vessel, and reactor containment) This hierarchy includes, for example, emergency reactor cooling, pressure relief or depressurization, isolation, and ESF equipment. various support systems (e.g., emergency generators) or devices required for the system to operate Detects the need for functions such as control of valves, motors, and pumps, and then performs them. do.

[0082] The monitoring and instrumentation system hierarchy typically includes a master control room 140 and, in some aspects, It is the slowest and also the most flexible layer of protection. Like the other three layers, , a human operator (e.g., of system 100) may need to accurately It depends on the sensor information, but given the information, time, and means, it can react to unexpected events. In order to respond to these requests, logical operations that are not pre-specified can be performed. The other three tiers (e.g., manual 1E control devices 142, 1E instruments 143, and non-1E control devices) (through devices and instruments 144) required to operate the nominally assigned equipment Includes Class 1E and non-Class 1E control devices, monitors, and instruments. Monitoring and instrumentation systems The functions required by the system hierarchy are the manual controls, displays, and instruments in the main control room. It is provided by MCS155 and includes information from MPS145. The MPS145 includes the functions for tripping the reactor and manual EFS activation. Provides safety monitoring and manual control to maintain operating limits during normal plant operation.

[0083] In addition to including four tiers of protection, system 100 includes multiple levels of diversity. In particular, I&C diversity refers to the use of different techniques, logic, or algorithms to measure variables. The principle is to provide a variety of methods to respond to anticipated plant conditions. where diversity is the ability to generate different results using different techniques, logic, or algorithms. The principle of an instrumentation system that detects a parameter or actuation means is applied to detect a critical event. Diversity is complementary to the principle of defense in depth. and the opportunity for a particular level or depth of protection to be activated when required. In general, there are six attributes of diversity: human diversity, design diversity, software diversity, and There is software diversity, function diversity, signal diversity, and device diversity. As will be discussed in detail, the MPS 145 is designed to minimize common cause failures (e.g., hardware failures) in the MPS 145. Software errors that can negate the redundancy achieved by the hardware architecture or software-generated logic) to mitigate the effects of may incorporate the attributes of diversity.

[0084] In general, human diversity is a measure of human-generated errors ( related to addressing errors, misinterpretations, and misconfigurations) and lifecycle It is characterized by disparities in the execution of the cloud processes.

[0085] Generally, design diversity refers to the combination of software and The use of different approaches, including hardware. Software diversity is design diversity. is a special case of the The rationale for design diversity is that different designs have different failure modes and The point is that they are not affected by the same common factors.

[0086] Typically, software diversity determines, for example, when a nuclear reactor should be tripped. to achieve the same safety goal using two separately designed programs were designed and implemented by different software development groups with different key personnel. The use of different software programs.

[0087] In general, functional diversity refers to the combination of two systems (e.g., For example, a subsystem within system 100, but the two systems may overlap. It may have a safety effect.

[0088] In general, signal diversity is the use of different process parameters to trigger protective action. , in the protection operation, none of the parameters is detected correctly. It may independently indicate an abnormal condition even if the

[0089] In general, equipment diversity is achieved by providing similar safety functions (e.g., all required protective actions are performed by the R A function that supports the completion of TS or ESF or all required protective actions. The established allowable limits for design basis events can be achieved by the completion of a design basis event, or both. (one of the processes or conditions essential to maintaining plant parameters within acceptable limits) The use of different equipment to perform the tasks. In this case, "different" refers to the effectiveness of the equipment against common cause failures. It may also mean that the data is sufficiently different to significantly reduce the vulnerability of the data to be shared.

[0090] In some aspects, the MPS 145 performs continuous (or partially continuous) self-tests. Such a testing strategy may incorporate a combination of routine and periodic surveillance testing. All faults are identified and notified to station personnel (e.g., through the main control room 140). The self-test function can ensure that the system status is continuously (or partially) monitored. A comprehensive diagnostic system may be provided to ensure that all detectable faults are Station personnel may be notified and an indication of the effects of the failure may be provided, and the overall system The self-test function maintains the independence of the isolation groups and partitions. The self-testing feature ensures that the integrity of the system is maintained at all times.

[0091] In some aspects, each sub-module within MPS 145 (described in more detail below) The module provides high fault coverage designed to detect single faults within the module. This may include a self-test feature that minimizes the time required to detect a fault. This provides benefits to safety and system availability. When the self-test is in progress, it is possible to perform the self-test without affecting the performance of the safety functions, e.g., response time. move on.

[0092] The self-test function is responsible for checking the active and inactive logic (e.g., safety functions are activated). Most faults are detected in both the It is possible to detect and avoid having undetected faults. , which occurs at the MPS submodule level and requires plant personnel to be replaced. Allows easy identification of MPS submodules.

[0093] Periodic online monitoring test capability is built in to perform all function tests and checks, calibration checks Periodic surveillance testing may also be performed to ensure that the test results, as well as time response measurements, are verified. Verify the continuous self-test function.

[0094] The self-test and periodic monitoring test functions within the MPS145 are available for all plant operating modes. They may be designed for in-service testability commensurate with the safety functions performed by them. Self-testing and supervisory testing do not require any interim test setup. may be inherent in the system design and add minimal complexity to the safety function logic and data structures. The continuous indication of a bypass condition may be (1) provided by self-test during normal plant operation; (2) when a fault is detected, or (3) when some part of the safety function is bypassed or or if the test is deliberately disabled. When the bypass is complete, the bypass indication is removed. This is to ensure that the bypassed safety function is not in a state where it is appropriate for service. This may ensure that plant personnel can verify that the product has been returned to its original condition.

[0095] Diagnostic data for MPS145 is maintained for each separation group and split. The MWS is located close to the equipment and May facilitate troubleshooting activities. Interface between MPS and MWS may be an optically isolated one-way diagnostic interface. All diagnostic data is , may be communicated by physically separate communication paths, and the diagnostic function is independent of the safety function. Additionally, diagnostic data can be transmitted to a central historian for long-term storage. This provides a means to perform historical analysis of system operation.

[0096] The diagnostic system may maintain a list of installed modules. It is continuously compared with the installed modules that are active in the system and detects the absence of modules. Or it may prevent an incorrect module from being installed.

[0097] All MPS safety data communications are designed to have error detection to enhance data integrity. Protocol functionality is ensured by the ability to detect transmission failures. Similar data integrity features are used to ensure that diagnostic data is reliable and trustworthy. The data may be transferred.

[0098] 2A-2B show a modular protection system for an I&C system for a nuclear power system 150. 2 illustrates a block diagram of a Multi-Profile System (MPS) 200. In some implementations, the MPS 200 may be similar to or identical to MPS 145 shown in FIG. Generally, the illustrated MPS 200 includes four separate groups of sensors and detectors (e.g., sensors 202a-202d), signal conditioning and four separate groups of signal conditioners (e.g., signal conditioners 204a-204d), four separate groups of trip decisions (e.g., trip Decisions 208a-208d), RTS voting and two categories of reactor trip breakers (e.g. (e.g., Division I RTS Ballot 214 and Division II RTS Ballot 216), and Two categories of Engineering Safety Facility (ESF) equipment (e.g., For example, Category I ESFAS Voting 212 and ESF Instruments 224 and Category II ESFAS Voting 218 and ESF equipment 226).

[0099] Generally, the sensors 202a-202d may be used to measure, for example, pressure, temperature, level, and neutron flux. It includes process sensors responsible for measuring different process parameters. , each process parameter of the nuclear system 150 is measured using a different sensor, It is processed by different algorithms executed by different logic engines. In this phase, the neutron flux sensor is capable of withstanding conditions up to 120 percent of full power. It is responsible for measuring the neutron flux from the reactor core. Three types of neutron flux sensors may be used in the MPS 200, including a range.

[0100] Generally, the signal conditioners 204a-204d receive measurements from the sensors 202a-202d. Receives, processes measurements, and provides outputs 206a-206d. The interconnections of the sensors 202a-202d to the signal conditioners 204a-204d are dedicated It may be copper wire or some other method of signal transmission.

[0101] Each of the signal conditioners 204a to 204d may be configured to perform any number of signal conditioners (e.g., depending on the number of sensor inputs). From the plurality of input modules 270a to 270n shown in FIG. 3A (showing the number of modules) The input modules 270a to 270n may receive the signals from the sensors 202a to 202d. Responsible for conditioning, measuring, filtering and sampling field inputs. The input modules 270a to 270n include, for example, 24V or 48V digital inputs, 4 to 20 mA analog input, 0~10V analog input, resistance thermal detector input, or thermocouple input It may be dedicated to a specific input type.

[0102] Each of the input modules 270a to 270n may be composed of an analog circuit and a digital circuit. Analog circuits convert analog voltages or currents into digital representations. The analog circuitry is also referred to as signal conditioning circuitry. The digital part of the 0n may be placed in a logic engine. The logic engine module control, sample and hold filtering, integrity check, self-test, and debug The digital representation of the sensor output is in some cases Using a real interface, the signal conditioner 204a through the outputs 206a-206d ~204d to trip decisions 208a~208d.

[0103] Referring also to FIG. 3A, the trip decisions 208a-208d generally correspond to the trip decisions described above. In this way, the digital signals are output from the signal conditioners 204a to 204d via the serial interface. The trip decision 208a-208d each receive sensor input values ​​in the format Independent safety function modules (SFMs) 272a-2 (described more fully with reference to FIG. 5) 72n, where a particular module implements one set of safety functions (e.g. For example, a set may be a single safety function or multiple safety functions associated with a particular process parameter. For example, a set of safety features may be Each SF may consist of a group of functions related to a key variable, such as trip and low trip. M272a-272n are unique logic elements dedicated to implementing one set of safety functions. This involves each set of safety features being completely different from all other sets of safety features. This results in a gate-level implementation.

[0104] Sensor input values ​​(e.g., outputs 206a-206d) are communicated via deterministic paths. may be provided to a particular SFM 272a-272n within each trip decision 208a-208d. These input values ​​are then converted to engineering units and used to calculate any safety function or safety features. It may determine which set of capabilities is implemented on that particular SFM 272a-272n. Trip decisions 208a-208d may use these engineering unit values, in some instances, as isolated The signal is provided to the control system via a transmit-only fiber optic connection.

[0105] The SFM at each trip decision 208a-208d, if necessary, is and making a reactor trip decision based on the trip request or no trip request signal. In some cases, there is triple redundancy and each RT is connected by a transmit-only serial connection. S division (e.g., RTS votes 214 and 216 for divisions I and II, respectively) The SFM also makes ESFAS activation decisions, if necessary, based on predetermined set points. Sends an isolated, in some cases triple redundant, signal for requesting operation or not. Each ESFAS division (e.g., divisions I and II, respectively) is connected by a serial signal-only connection. ESFAS Votes 212 and 218).

[0106] As shown in FIGS. 3A-3B, for example, a particular trip decision 208a may include a trip request or sends a no trip request signal to the ESFAS poll 212 through output 274a and to the ESFAS poll 212 through output 274b. 274b to the ESFAS ballot 218. Trip Decision 208a A request or no-trip request signal is sent to the RTS poll 214 via output 276a and These outputs also provide the triggers 276b to the RTS vote 216. The outputs 210a-210d from the top decisions 208a-208d are shown generally in FIG. 2A. will be done.

[0107] As further shown in FIG. 3A, for example, a particular trip decision 208a may include a trip request or a no-trip request signal to monitoring and indication (M&I) outputs 278a and 278b (section 1). Outputs 278a and 278b provide non- Output 280 provides process information to the MCS for safety control functions. and trip status information to non-1E controllers and instruments 144.

[0108] Returning to FIG. 2A, for each RTS partition (e.g., RTS votes 214 for partition I and RTS votes 216 for partition I), The RTS votes for I (216) are isolated and in some aspects redundant (e.g., 2 By means of receive-only serial connections 210a-210d (double, triple, or other) As described above, the trip decision 208 receives input from the trip decision 208a-208d. Two or more reactor trip inputs from trip decisions 208a-208d trigger an automatic reactor trip. The output signals are displayed on outputs 228a-228d and 230a-230d (as appropriate for each section). ) and an automatic reactor trip output signal is , of the eight reactor trip breakers (RTBs) (shown in Figure 2B) associated with each division. In other words, the RTS voting logic activates the trip coils for four of the MP In this exemplary implementation of S200, which operates in terms of "two-fourths" logic, the reactor "Tr At least one of the four trip decisions 208a to 208d indicates that a trip is required. If two are shown, the trip signal is sent to RTBs 264a-264d and 266a-266d. This circuit breaker configuration is a safe and simple way to use the MPS200. This will enable online testing.

[0109] Manual trip 250a is a direct tripping function for RTBs 266a-266d (for Division I). manual trip 250b provides RTBs 264a-264d (for Division II) automatic operation, manual trip 234 (for Division I), as well as providing direct tripping of and (for Division II) manual trip 236 to maintain the sequence. We guarantee this.

[0110] As further shown, each of the RTBs 264a to 264d and each of the RTBs 266a to 266d includes manual trips 250a and 250b as inputs. trips 250a and 250b (e.g., manual trips for divisions I and II) are initiated. When the power input 260 is connected to the power supply 230a-230d and the power supply 228a-228d, Regardless of the state (e.g., tripped or untripped), no power is sent to the power output 262. This becomes the case.

[0111] The ESFAS voting and logic, in the exemplary implementation, requires that any single failure When there is no possibility of preventing the safeguard from operating, and the trip decision signal (e.g., 20 Any single failure within 1a to 210d) could potentially produce unnecessary safeguard activation. ESFAS systems are arranged to prevent the occurrence of accidents such as emergency core cooling systems and collapse Both automatic and manual start-up of critical systems, such as heat removal systems, may be provided. stomach.

[0112] Each ESFAS voter 212 / 218 connects inputs 201a-210d to an isolated triple redundant Trip decision 208a by a reliable, receive-only fiber optic (or other communication technique) connection The operating logic and voting takes place within ESFAS Voting 212 / 218. If ESFAS Ballot 212 / 218 determines that action is necessary, ESFAS Ballot 212 / 218 send activation request signals to activate the appropriate ESF devices 224 and 226. SFAS priority logic 220 / 222 respectively.

[0113] The illustrated implementations of MPS 200 in FIGS. 2A-2B and 3A-3B include the following key features: This ensures a high level of independence between the four separate groups of sensors and detectors. 202a-202d, four separations of trip decisions (labeled "a"-"d"). Group, two divisions of RTS214 / 214 (the aforementioned division I and division II), ESFA The two sections of the S circuit configuration 212 / 218 (section I and section II mentioned above) and the ESF equipment This includes the independence between the two sections of 224 / 226 (section I and section II mentioned above). Based on the inputs to the SFM (e.g., in trip decisions 208a-208d), the MPS 200 Implement a set of safety functions independently in each of the four isolation groups. is maintained from the sensors 202a-202d to the trip decision outputs 210a-210d. This configuration allows, in some aspects, the detection of SFM failures by SFM based on the inputs of that module. This strategy helps limit the impact of common cause failures and increases signal diversity. This method of independence also ensures that a failure within an independent safety function does not affect other safety function modules. Furthermore, it is possible to ensure that the fault does not propagate to any of the other SFMs. The fault can be corrected with minimal impact, if any, to other modules. We guarantee that:

[0114] The communication of safety function data within the illustrated MPS200 is triple-module redundant. This communication scheme is Except for inter-voting, a safety function requires that no external factors be involved in achieving that safety function. It can be ensured that the information or resources are not dependent on any other information or resources. Fault propagation between sections I and II is achieved by unidirectional isolation (e.g., optical isolation) of the section trip signal. or other).

[0115] The illustrated implementations of MPS 200 in FIGS. 2A-2B and 3A-3B are It also incorporates redundancy in multiple areas of its architecture. The redundancy within the four separate groups of sensors and detectors (labeled "a" through "d") Loops, trip decisions (labeled "a" through "d"), and RTS and ESFA The MPS 200 also includes two sections of circuitry (section I and section II). A single start signal will ensure that reactor trips or ESF equipment operations occur when required. A two-quarter vote is used to ensure that failures do not interfere. Furthermore, a single failure of the start signal will result in a false or The principle is to prevent unintentional reactor trips or ESF equipment operation when they are not required. It will not be possible to do so.

[0116] The MPS200 also incorporates functional independence by implementing each set of safety functions. Each set of safety functions is configured to handle specific transient events on independent SFMs in a manner that reflects the characteristics of the safety functions. It is used to mitigate against the set of conditions by a unique logic engine.

[0117] In some respects, the MPS200 is a simple and reliable solution for nuclear reactor systems. For example, the MPS200 is designed with four isolation groups. Each of the four isolation groups may be based on a symmetric architecture of two partitions. Each of the two divisions may be functionally equivalent to another division. etc. As noted above, a two-quarter vote is the only As another example, the logic of the MPS 200 may be configured to A finite state machine (e.g., a collection of digital logic circuits) dedicated to a group of safety functions , can be in one of a finite number of states at a time, called the current state. It is in only one state, but can be changed by a set of triggering events or conditions, e.g., a state transition. A collection of digital logic circuits that can change from one state to another when activated Therefore, no kernel or operating system is required. As another example, communication within the MPS 200 may be based on a deterministic protocol, with all Safety data is communicated via redundant communication paths. The diversity attribute of It may be designed to be architecture specific without any

[0118] For example, FIGS. 4A-4B show how the multi-tiered diversity strategy implemented in MPS 200 can be implemented in software. Illustrate how to mitigate software-based or software logic-based common cause failures Exemplary charts 400 and 450 are shown, respectively. The multi-layered diversity strategy implemented in the MPS200 is How to eliminate concerns about software-based or software logic-based CCF In these examples, the transient events are As shown, two different process parameters, A1 and A2 are measured (e.g., via sensors 202a-202d). A is a temperature parameter as shown, while A2 is pressure as shown.

[0119] The different process measurements A1 and A2 correspond to two different safety function algorithms as shown. Two safety features are input to the algorithm: (A1) high temperature and (A2) high pressure. Each of the algorithms resides on a separate and independent SFM within the isolation group. The algorithm, as shown with the MPS200, separates four groups (A, B, C) Two different sets of programmable digital hardware (A / C, D) are divided into and B / D) and two partitions. For example, here, A safety function comprises a single set of safety functions (e.g., two safety function algorithms). Each set may be based on a different technology.

[0120] Each set of programmable digital hardware uses a different set of design tools Design diversity is also organized by the process, as different parts may be designed by different design teams. As an example, the safety function may be implemented in a microprocessor. In this case, the safety functions may be evaluated in a sequential manner. In some aspects, the method may have one safety feature due to the sequential behavior of the processing loop. A dependency of a function (e.g. A2) on another safety function (e.g. A1) may be introduced. As an example, safety functions can be implemented using state-based field programmable gate arrays (FPGAs). In this example, each safety function may be evaluated independently of all other safety functions. This latter example is an example of any consideration of the treatment of one safety function relative to another. This can ensure increased independence by removing dependencies.

[0121] The layered diversity of the loss of water supply transient example allows the software CCF to be configured for a specific safety Disables protection by limiting the function (A1) to one set (A / C) In some aspects, the software CCF provides protection against two Functional independence between safety functions and the processes that safety function algorithms use as inputs Limited to specific safety functions based on measurements. In some aspects, software C CF uses different programmable hardware, design teams, and design tools for each set. By incorporating a rule, the CCF is limited to a specific set of safety functions. In a situation where the system is limited to one set of safety functions, the transient event will Another set (B / D) or both sets (A / C and B / D) of the second safety function (A2) This is mitigated by

[0122] For example, as shown in FIG. 4A, if the protection action is set to 4 (e.g., indicated by a check mark), A1 indicates that the action must be taken by all three separate groups (A, B, C, D). The output of the safety function for a given device may also initiate a protective action (e.g., indicated by "trip"). As shown in Figure 4B, for safety function A1, two separate groups (A and C), and if there are CCFs in two groups within a single division, other separate groups The positive indication of protective action in (B and D) is the protection (in the two-quarter scheme described above). It still provides enough votes to initiate a protective action. CCFs in Groups A and C are evaluated independently for each SFM. It does not propagate to 2.

[0123] Figure 5 shows the safety function module (SF) of the MPS of the I&C system for nuclear power systems. Figure 6 illustrates a block diagram of the I&C system for nuclear power systems. FIG. 7 illustrates a block diagram of the communication module (CM) 600 of the MPS. MPS Equipment Interface Module (EIM) of I&C System for Power System 700. FIG. 8 (discussed below) illustrates a block diagram of a housing (e.g., one or (Mechanical structure that interconnects multiple SFM500, CM600, and EIM700) Generally, (illustrated by housing 800 and described below) The illustrated modules 500, 600, and 700 interconnected within the housing form the MPS2 00 safety functions and isolation group level modules (e.g., signal conditioner 204a ~204d, trip decision 208a~208d), RTS level module (e.g., R TS Voting 214 / 216), and ESFAS level modules (e.g. ESFAS Voting 212 / 218). In some aspects, three types of modules (500, 600, and 700) minimizes the number of interchangeable units in the line. , which minimizes obsolescence. Furthermore, these modules (500, 600, and 700) in each individual module (500, 600, and 700) They are functionally independent so that a single fault in one module does not propagate to other modules or other safety functions. Furthermore, the modules (500, 600, and 700) combination can result in a discrete and deterministic safety signal path.

[0124] In some aspects, the modules (500, 600, and 700) may have one or more characteristics that at least partially define their functional independence. Each of the modules is a part of the overall system / architecture (e.g., in the MPS200 In another example, a module may be completely autonomous with respect to each other. Each module has a role relative to each other module in the overall system / architecture. As yet another example, a module may autonomously perform a specific intended safety function. Each of the may contain dedicated logic that is specific to the particular intended safety function of the module. Therefore, each functionally independent module performs a specific intended safety function. Therefore, it may not depend on logic or functionality from any other module.

[0125] Referring to FIG. 5, the SFM 500 receives inputs from sensors or other SFMs as shown. Process the data to identify the isolation groups to which a particular SFM is assigned (e.g., isolation groups A, B, C, or D) to make a decision to trip the reactor and / or activate the ESF. 500 has two separate configurations: (1) sensor signal conditioning with safety data bus communication; (2) reactor trip decision and / or EFS activation; Or it can be used in safety data bus communication with EFS activation decisions.

[0126] As shown, the SFM 500 generally comprises an input block 504, a functional logic block 506, and a block 512, and communication blocks 514, 516, and 518 (four are shown in FIG. 5). Each input block 504 includes a signal conditioning circuit 506, an analog-to-digital (A / D) Each input block 504 comprises a converter 508 and a serial interface 510. Communicable with sensor 502 (which may be the same as or similar to sensors 202a-202d, for example) As shown, each SFM 500 is connected to It can handle up to four input blocks 504 (in the Requires SFM500 to make trip or ESF activation decisions, including generating turlocks Analog and digital (e.g., 4-20mA, 10-50mA, 0-1 0V).

[0127] The functional logic block 512 is connected to the serial interface of the input block 504 (if used). The programmable portion of the SFM500 that converts the output from the interface 510 into engineering units. The functional logic block 512 also performs a process (e.g., based on sensor measurements from the sensor 502). Triggers based on the output of input block 504 and / or information from the safety data bus. The function logic block 512 may also generate authorizations and / or make ESF activation decisions. As shown, functional logic block 512 , a plurality of deterministic logic engines, each of which has an input block 504 and / or utilize information available from the safety data bus to make trip or ESF activation decisions. conduct.

[0128] The set points and other adjustable information utilized by the function logic block 512 may be (e.g., , on the SFM 500) which allows the user to modify the underlying logic. Furthermore, functional diversity, signal diversity, and software diversity can be achieved. To implement variability, the primary functions and backups used to mitigate AOO or PA The functions do not have to be on the same SFM 500. By using the dedicated SFM500 for this purpose, the main function and backup function can be By ensuring that the software CCF The impact is limited due to the unique logic and algorithms on each module 500. will be done.

[0129] The communication block 514 / 516 / 518 has five separate communication ports (e.g., 514 and Three secure data ports labeled 516, and one port labeled 516. Each port is functionally independent. , a monitoring and instruction (M / I) bus (e.g., block 516), a maintenance workstation, a Mobile Workstation (MWS) bus (e.g., block 518), or a safety bus (e.g., block 5 14). Each safety data bus 514 must communicate the same data. However, each communication port is asynchronous and the ports are independent and unique different communication engines. The use of gins allows data to be packaged and sent differently. For example, The safety data bus 514 may be, for example, sequentially ordered (e.g., 1, 2, ..., 10 ) may transmit 10 packets of data on the bus 514, while another safety bus 514 may transmit the same 10 packets. The third safety bus 514 transmits the bits in reverse order (e.g., 10, 9, ..., 1) first. Send a few packets followed by odd packets (e.g., 2, 4, ..., 10, 1, 3, ..., 9). This triple modular redundancy and diversity allows for communication error detection. as well as affecting the ability of the RTS or ESFAS to make correct trip and / or operation decisions. The communication CCF is limited to a specific bus without affecting the

[0130] Referring to Figure 6, the CM600 is an I&M system for nuclear power systems (e.g., MPS200). Separation group level interconnection of MPS, RTS level interconnection, and ESF of C system Within the AS level interconnection, other modules of the MPS, e.g. SFM500 and EIM700 For example, the CM600 provides independent and redundant communication between the MP It may be a pipeline passing through S as well as a scheduler for such passing of data. The CM600 can operate / transmit data within any particular channel. In the illustrated implementation of CM600, there are three types of blocks: Restricted Communication Block (RCB) 604, Communication Scheduler 606, and Communication There are blocks 608 / 610.

[0131] The RCB 604 consists of four communication ports as shown. Each port is configured to be a different unidirectional (e.g., receive-only or transmit-only) path. In some implementations, as in the illustrated CM 600, a particular RC Information received or transmitted from B 604 passes through an opto-isolator 602. In this case, the opto-isolator 602 prevents data from any particular trip decision from being used for other trip decisions. It helps ensure that data is isolated from the source and therefore provides independent redundancy. obtain.

[0132] The communication scheduler 606 schedules the communication blocks 608 / 610 to the RCB 604 or Responsible for moving data from the RCB 604 to the communications block 608 / 610. In this aspect, the communications engine 606 may be implemented using programmable logic, such as an FPGA, a processor or processors programmed to schedule communications between the interconnections described It consists of other discrete logics that can be used.

[0133] The communication block 608 / 610 has four separate communication ports (e.g., labeled 608). (three secured data ports and one port labeled 610) Each port may be functionally independent and may be connected to a supervisory and instruction (M / I) bus (e.g., The block 610) or the secure data bus (e.g., block 608). In some aspects, the M / I bus 610 is connected to the MPS (e.g., modules 500, 600, and 700) to collect information from all modules in the may collect this information and store it in a "historian" station (e.g., historical data for the MPS). The data is then sent to a dedicated computing system for the data.

[0134] Although each secure data bus 608 may communicate the same data, each communication port may communicate with a bus As described above with reference to 514, the data is packaged and transmitted differently. Depending on the module application, the four communication blocks 608 / 610 can be unidirectional and It can consist of any combination of two-way and two-way paths.

[0135] Referring to Figure 7, the EIM 700 is generally a RTS and / or ESFAS level system. It provides an interface to each component within the nuclear system within the system, Group decisions are voted on and component level activations and operations are performed. , EIM700 includes an output block 720, an instrument feedback block 718, and an IE manual input 716, non-1E manual input 714, voting engine 722, priority logic block 721, It includes a device control block 723 and a communication block 724 / 726 / 728. The EIM700 will vote, or in some cases double vote (e.g. , two-thirds vote for communications and two-quarters vote for trip signals) to carry out a single If a component failure occurs in an I&C system for a nuclear system (e.g., MPS200), System MPS channel level interconnection, RTS level interconnection, and ESFAS level The EIM 700 may ensure that the voting 722, manual actions, Performs priority assignment for automatic signals from the automatic / 1E input 716 and non-1E input 714 You may do so.

[0136] Output block 720 may be used in external circuitry as shown, or and up to three independent outputs that can be connected to electrical loads 702 (e.g., actuators). In some aspects, this includes a switch, or in some instances, more output switches. This allows the EIM 700 to directly control a single component or multiple components. For example, output block 720 can energize a relay, The relays actuate various pumps and open various valves. Each output block 720 also It may include the ability to self-test and perform load continuity checks.

[0137] The instrument feedback block 718, as shown, receives multiple (e.g., and (up to three, or in some instances more) feedback inputs 704. The feedback input 704 may, for example, be a valve position (e.g., fully open, fully closed). ), circuit breaker status (e.g., closed / open), or other feedback from other components. The device feedback 704 may include a voting device control block, as discussed below. It can be used within the

[0138] 1E manual input block 716 may include multiple (e.g., up to two or more in some instances) This portion of the EIM 700 may provide a manual input signal 706 (a number greater than or equal to 100). The priority logic block 721 may be dedicated to the priority.

[0139] A plurality of input signals 708 are input to the non-1E input block 71 via an isolation interface 712. 4. This electrically isolated interface 712 is connected to the priority logic block 721. This allows the use of non-1E signals for the input.

[0140] The voting engine 722 receives trip decision input from a communications block 724. The result is an enable or disable signal for the automatic enable signal provided to the priority logic block 721. In some aspects, the voting engine 722 may implement a voting scheme or, in some cases, Implement a double voting scheme to ensure that the failure of a single component within the MPS does not propagate. For example, in some aspects, the voting engine 722 may The trip decision is received at communication block 724. Each communication block 724 has four channels or Trip decision (e.g., tripping) from separate groups (e.g., channels A to D mentioned above) Within the voting engine 722, in several aspects There are three "A" trip decisions, three "B" trip decisions, and three "C" trip decisions. There may be three "D" trip decisions, and three "D" trip decisions. , a two-thirds decision may be performed for each of the four channels or separation groups. For example, at least two of the three "A" channels must be active for tripping (e.g., tripping If the voting engine 722 provides a At the very beginning, it may communicate that a trip exists on channel "A", while If only one of the "A" channels indicates a trip, the voting engine 722 It may be determined that there is no trip on panel "A."

[0141] The voting engine 722 implements a dual voting scheme as described above to implement the MPS structure. It may further ensure that faults do not propagate throughout the entire Following the communication decision, the voting engine 722 also determines whether a fault (e.g., a false trip) is present or not. In contrast, a two-quarter trip decision is performed to determine whether a trip actually occurred. For example, four votes in the voting engine 722 may be made to make two of the three decisions. The output of the voting block (e.g., two of the three voting logic gates) is used to determine the four decisions. Two of the four voting logic gates are sent to another voting block (e.g., two of the four voting logic gates). Four votes from the first hierarchical voting block (e.g., two of the three blocks) If at least two of the four outputs indicate a trip, the voting engine 722 It is determined that a fault has occurred (and that an EFS device, such as load 702, should be activated). otherwise, the voting engine 722 may assume that no trips have actually occurred. It may be determined that there was no

[0142] The priority logic block includes a voting block 722, a manual entry block 716, and a non- E receives input from manual input block 714. Priority logic block 721 then: Based on all the inputs, it decides what to command the machine control module to do.

[0143] The equipment control block receives commands from the priority logic module and outputs the commands to the output block 72. 0 to perform the appropriate action or operation on the component. , fed from the instrument via instrument feedback block 718 for instrument control purposes. Receive the back.

[0144] The device control block 722, the priority logic block 721, and the voting block 722 are Each sends status information to a Maintenance Workstation (MWS) bus (e.g., Block 7 28). The communication blocks 724 / 726 / 728 provide five separate communication ports ( For example, three secure data ports labeled 724, one labeled 726, One port labeled 728 and one port labeled 729. Each port has a function. may be functionally independent, such as a monitoring and instruction (M / I) bus (e.g., block 726); Maintenance Work Station (MWS) bus (e.g., block 728), or safety data bus (e.g., block 724).

[0145] FIG. 8 shows a configuration in which one or more SFMs 500, EIMs 700, and CMs 600 are communicatively connected. 8 illustrates an exemplary embodiment of an enclosure 800 for a nuclear reactor protection system (e.g., MPS 145) connected to the This diagram shows three SFMs 5 connected to four CMs 600 in a chassis 800. 00 or EIM700. In this example, five data bus paths are shown. For example, there are three secure data ports8 labeled X, Y, and Z, respectively. There is one data bus path 804 labeled M / I. There is one data bus path 804 labeled WS. 2 / 804 in this example, all other data bus paths 802 / 80 within the enclosure 800. 4 may be functionally and electrically independent.

[0146] In this illustrated embodiment, each of the CMs 600 includes a data bus path 802 / 80 4. As shown, the X data bus path 802 The master 808 is part of the CM 600 for the secure data X and Y data paths 80 The second master 810 is the CM 600 for the safety data Y. The master 812 is the CM600 for safety data Z. Finally, as shown in this example: Additionally, the master 814 for the M / I data path 804 is the CM 600 for the M / I. Similarly, in this example, a separate workstation (e.g., a maintenance workstation) There is an MWS master 816 that is connected to the MWS data path 806. The Maintenance Workstation (MWS Master) 816 is controlled by a wiring switch. , may be disconnected for normal operation of the equipment.

[0147] 9A-9C show a method utilizing one or more of the SFM500, CM600, and EIM700. Separate group level interconnections, RTS level interconnections, and ESAFAS level interconnections The block diagram of the connection is shown. In general, the modules SFM500, CM600 and and EIM 700, for example, to detect a single failure (e.g., hardware failure) in an adjacent or other safety function. Functionally unique features that provide protection against the propagation of A separate module (e.g., an assembly of interconnected components with an identified A device, instrument, or piece of equipment that can be configured and separated and removed as a unit. It can be removed and replaced with a spare, and the assembly remains as a unit. MPS (assembly) has definable performance characteristics that allow it to be tested. 200. The module may be implemented in several ways for trip detection and decision making. In some configurations, the modules may provide up to triple redundancy. In addition, they may be arranged to provide redundant RTS and ESFAS voting segments. In some implementations, the module may also include trip components (e.g., circuit breakers, sensors, etc.). Multiple independent trip voting modules may be provided for each trip (e.g., trip sensor, etc.).

[0148] In some cases, the module provides RTS voting, while in other cases, The modules provide ESFAS voting. Regarding the independence of each module, each module The module is dedicated to a specific trip component, separate from all other modules. Make a decision about tripping and whether or not to initiate an RTS / ESFAS trip. In some implementations, the determination of the effective communication of the trip decision may be based on multiple (e.g., In some implementations, the decision may be made by a double voting scheme. In a dual voting scheme, communication of trip decisions is by majority vote. (e.g., two-thirds) and the secondary trip decision vote is activated by a less than majority ( For example, by a two-quarters vote.

[0149] Turning to Figure 9A, an exemplary isolation group level interconnect 900 is illustrated. The channel level interconnect 900 receives the channel sensor input 902, 904 through 920. Channel level interconnects are used to implement a single function or a single set of functions, such as Each SFM500 in the 900 can accept four inputs, in any combination of analog and digital. 902, or in some cases more than one input 902. Each input 902 may The pressure signal from the channel A compressor may be unique to the SFM 500 (e.g., the pressure signal from the channel A compressor may be unique to one SFM 500). (Direct input for FM500 only.) Input data includes status information (e.g., alarm may be available on all four data buses, along with the stomach.

[0150] The safety buses may be functionally independent, and each safety bus may use a master-slave protocol. The master is the CM600. The blocks in the SFM operate in synchronization. The communication between modules may be asynchronous. When requesting information from the SFM500, the SFM500 broadcasts the The advantage of broadcasting is that, for example, SF labeled "1" The information required by the SFM 500 (e.g., permission signal) is labeled "2" by the M 500. , sensor input values), SFM500 "2" listens and obtains the required information. This means that you can gain.

[0151] Three safety data buses (e.g., labeled "X," "Y," and "Z") In addition, there is a fourth illustrated communication bus for monitoring and instruction (M / I). The bus master provides M / I data to the safety gateway and non-safety control systems. In particular, it may be a dedicated CM600. Three safety data buses (e.g. buses X, Y, Unlike the CM600 for the M / I and Z, the M / I CM600 is It may also be possible to listen to broadcast information.

[0152] In some implementations, the Restricted Communication Block (RCB) of the CM600 In the isolation group level interconnect 900, All four communication ports on the RCB may be configured for transmit only. Data from bus CM600 (e.g., CM600 labeled X, Y, and Z) may be transmitted to each section of the RTS and ESFAS (e.g. sections I and II). I Data from the CM600 (e.g., outputs 916 to 920) is sent to the safety gateway and It may also be sent to a non-safety control system.

[0153] The outputs 904 to 914 are, for example, RTS level interconnections and ESFAS level interconnections. For example, as shown, outputs 904, 908, and 912 may be provided to the ESFAS level interconnection, while outputs 906, 910, and 914 may be provided for RTS level interconnection. Only one isolation group level Although interconnect 900 is shown in FIG. 9A, multiple interconnects 900 may be present within an MPS structure. May be present.

[0154] Turning now to FIG. 9B, an exemplary RTS level interconnection divided by partitions is shown. The RTS level interconnection is shown in Figure 1. Each division shown (214 and 216) contains four C votes. Includes an M600 and four EIM700s. For each section (labeled X, Y, and Z), Each of the three safety data buses (e.g., with the same number, i.e., A1 and B The triplets shown as inputs 962-972 (with separate groups labeled 1) Trip or no-trip decisions may be received from all four separation groups. 00 to the non-safety control system and safety gateway (outputs 974 to 979) as shown. 76) may be provided for transmitting data.

[0155] Configure each communication port on the RCB for each safety bus CM600 for "receive only" The M / I CM600 may be optically isolated or may be optically isolated (as described above). , may have all ports in the RCB configured for "send only".

[0156] In some implementations, the traffic for each safety data bus from all isolation groups is Lip determination is available to each of the four EIMs 700. The EIMs 700 are (X, Y All three safety buses (labeled Z, Z, and Z) are used to prevent interruptions due to communication errors. It may be ensured that there are no false trips of the breakers. When at least two of the following (62 to 972) indicate a trip state, the reactor trips. Each EIM 700 is, for example, an undervoltage relay for the reactor trip breaker and In addition to automatic operation, the EIM600 can also Manual section level reactor trip 978, circuit breaker feedback, and ESFAS feed It will have an input for the back.

[0157] (For Category I, they are labeled 980a-980d, and for Category II, they are labeled 982a- The EIM600 outputs (labeled 982d) are associated with specific segments (as shown in Figure 2B). connected to the input for the trip coil of the reactor trip breaker (RTB) This may also be done.

[0158] Turning to FIG. 9C, an exemplary ESFAS level interconnection divided by partitions is shown. The ESFAS level interconnection is shown in Figure 1. For example, ESFAS ballots 212 and 218. 8) includes four CM600s and four EIM700s. For each section, (X, Y, Each of the three safety data buses (labeled Z and Z) is connected as inputs 962-972. The ESF activation decision labeled (four separate groups of signals).

[0159] On the RCB for each safety data bus CM600 (labeled X, Y, and Z) Each communication port in the The M / I CM600 may be isolated in an RCB configured for "transmit only". All ports in the enclosure may be optically isolated.

[0160] In some implementations, the ESF actuation decisions from all the isolation groups are calculated as (X, Y, Available to the EIM700 on all three safety data buses (labeled A and B). For example, the EIM700 uses all three safety data buses to ensure that communication is not affected by errors. It may be possible to ensure that there are no malfunctions of equipment caused by At least two of the four isolation groups (on inputs 962-972) are ESF activated. When the need for safety functions is shown, the ESF functions are classified based on the classification (as shown in Figure 3B). The power supply 990 may be initiated through an output 990 (connected to the power supplies 224 and 226). In this case, each EIM700 is used to control an individual component (e.g., a single ESF component). may be dedicated to a specific purpose.

[0161] In addition to automatic start, each EIM700 can also use manual input 992 to control the components. Additionally, each EIM 700 may also receive non-IE control inputs 994. 3B) (also shown as input 282) is an E for non- Provided to the IM700 to control 1E safety ESF components based on the output of the EIM Component feedback (e.g., limit switches), voting decisions, and other available information (e.g., alarms) are transmitted to the M / IC as outputs 974-976. It may be sent from the M600.

[0162] Figure 10 illustrates a diversity analysis diagram for the I&C system 135 for a nuclear system. For the purposes of diversity analysis, the blocks identified in Figure 10 are Blocks represent a level of detail that simplifies inspection. Those internal faults can be assumed not to propagate to other blocks based on their attributes, It was chosen to represent a physical subset of the equipment and software.

[0163] As shown, the blocks in the diagram of FIG. 10 are the I&C system, in this example, the I&C 10 illustrates the system 135. Block 1002 represents non-1E monitoring and indication equipment; Blocks 1004a / b represent 1E monitoring and instruction I and II, respectively, and blocks 10 Block 1006a / b represents safety blocks I and II, respectively. Block 1006a represents the isolation group. Loops A and C, RTS I, and ESFAS I, while block 1006b includes: Includes Separation Groups B and D, RTS II, and ESFAS II. Block 1008 represents MCS. As shown, connecting lines with arrows indicate communication between blocks. .

[0164] One of the goals for the four tiers is diversity. For example, the MPS is a single The single failure criterion may be (1) a total failure that is identifiable but not detectable; (2) any single detectable failure in the safety system occurring simultaneously with all other failures; (3) all failures resulting from a design basis event requiring the safety function In the presence of all faults and erroneous system behavior resulting from design basis events requires the MPS to perform all safety functions required for design basis events. This requirement may provide increased reliability, but may also increase the risk of the system experiencing common cause failures (CCF). ) for any design, it is not possible to exclude CCF from multiple independent faults. There may be dependencies (e.g., coupling factors) that distinguish between the two. This is because of common causes within the system. This results in two basic forms of prevention of damage: either the causal effects are reduced, or , the system's ability to resist these effects increases.

[0165] These two forms of implementation are based on the six attributes mentioned above: design versatility, equipment It can be implemented with diversity, functional diversity, human diversity, signal diversity, and software diversity. The application of these attributes is shown in each block illustrated in FIG. The attributes between the blocks are checked. Attributes in Block As illustrated and similarly described with reference to the previous figures, separation groups A, B, C, and The two divisions, D and RTS and ESFAS, are based on programmable technology. Safety Blocks I and II are grouped together as a modular protection system (MP S) (e.g. MPS200).

[0166] Regarding signal diversity, for a given transient event, there are likely to be at least two safety functions. Each function can be used to measure different physical effects (e.g., pressure, level, temperature, neutrons, etc.). The loss of one safety function is based on the measured variable (load). This does not prevent the identification of the necessity of

[0167] Regarding software diversity, based on the input, each safety function module (SFM5 00) is dedicated to a safety function or group of safety functions. As a result, each SFM has a unique Each communication module (CM600) has its own algorithm / logic. Each communication engine (608 / 610) in the CM has a different algorithm. It may be necessary to transmit in a different order. 00) may be dedicated to a single component and may have its own unique algorithm / logic. It is okay to bring it about.

[0168] 1E monitoring and instruction is divided into two categories: video display units (VDUs) and physical switches. Each section of the monitoring and instruction (M / I) may be accomplished using block 1004. For design versatility, each division of M / I can be represented by a It may provide the operator with component status information and, at the sectional level, may also take any protective action. For signal diversity, the operator has a manual switch that is activated by the MPS. All measured variables used in the test and whether tripping and / or EFS operation is required. Although not as fast, the operator may determine multiple With the measured variables, the same determinations as in MPS can be made. [Block diversity attributes] Regarding human diversity, the software of Safety Block I and 1E M / II is The safety block II and 1EM / I II may be designed by the design team. In addition, an independent verification and validation team may , the work of each design team can be reviewed to ensure the correctness of the design. Similarly, the settings assigned to the Modular Control System (MCS) and non-1E M / I This is different from the total team.

[0169] Design diversity is the combination of software and hardware to solve the same or similar problems. The key is to use a different approach that includes both To this end, the safety block I 1004a and the 1E M / II block 1006a Safety Block II and 1E M / I II may use different programmable technologies. The MCS and non-1E M / I may also have different programmable technologies. Along with other attributes discussed in, different hardware designs may have different failure modes. , which may reduce the chances of a CCF affecting more than one block. For example, except for the M / I block, the blocks may be physically separated into different rooms. This further reduces the coupling factors that may create conditions in which multiple components are involved in a CCF event. It is intended to reduce

[0170] Software diversity is a subset of design diversity and also achieves the same safety goals. different development groups with different key personnel to Due to the design variability discussed above, different design teams may use different programs. Teams may use different design tools, and thus the tools may not introduce the same failure modes. You don't have to enter.

[0171] Functional diversity may be introduced by having different purposes and functions among the blocks. Safety Blocks I and II form the MPS. These blocks are In the event of a nuclear accident, a reactor trip may be initiated and the ESF may be initiated to mitigate the postulated accident. I-blocks allow operators to monitor and control both safety and non-safety systems. Operators can maintain the plant within operating limits or The MCS provides automatic control of the system or maintain the plant within its operating limits, including limiting operational transients that may occur; do.

[0172] Between blocks, automatic and manual means of operating equipment and protective actions must be provided. Therefore, signal diversity may be provided. MCS and non-1E M / I are instrument-level control , while the 1E M / I block provides partition level control.

[0173] Equipment diversity is the use of different equipment to perform similar safety functions. Activation can be by operator action using a switch or by safety block I or II. Between safety blocks I and II, different Programmable technology may be used, which may include different internal subcomponents and Different manufacturing methods may be required.

[0174] Another analysis guide for the four layers is the type of system failure. Type 1 failures occur between layers of protection. Protect against plant transients initiated by interactive control system errors A failure that does not allow any action to be taken. This is usually due to a failure of a common sensor or signal source. Some of the plant parameters monitored by the MPS are As mentioned above, instead of providing a single signal source, All four separate groups and both ESFAS and RTS divisions are isolated and This allows the MCS to provide information through two-way communication, which allows for redundant and independent Different methods of selecting which signal source to use (e.g., center signal selection) are available. It could become like this.

[0175] Type 2 faults may not directly result in a transient change and are undetected. This is a failure that may cause the protective device to not respond to plant transient changes. Safety Block I Using attributes in and between I and II, the undetected failure or CCF is 2 There may be enough diversity to prevent a block from affecting more than one block. Only one of the two blocks required to automatically start the operation is required. 2 faults are mitigated by the MPS (safety blocks I and II) without further systems Good too.

[0176] A Type 3 failure occurs when the primary sensor, which is relied upon to detect the design basis event, produces an abnormal reading. Signal diversity is the ability to ensure that for any transient event, at least two safety functions are operational. Each can be based on different measurement parameters and can be present in the safety block. All four isolation group sensors for a given safety function provide abnormal readings In this case, there are two possible adverse scenarios for Type 3 failure: 1) limiting the actual When exceeded, abnormal readings indicate that no trip or ESF operation is required. and 2) that a trip or ESF operation is required even if the limit is not exceeded (e.g., There may be abnormal readings indicating faulty operation (false trips or ESF activation). In this case, a type 3 fault occurring simultaneously with a CCF within the safety block will not trigger the required protective action. As mentioned earlier, signal diversity allows separate safety functions to mitigate transient events. The CCF in the MPS can be used to synchronize two safety blocks. The safety block is limited to one of the blocks and prevents or misdirects the protective action from being initiated. For example, as discussed above, the two-quarters match logic is assumed to prevent triggering by The four-quarter coincidence logic may be used for all trips and ESF activations. Two of the isolated groups are connected to the unaffected safety function on the unaffected safety block. indicates the need for tripping or ESF operation and the operator of the action to be taken Provide positive direction to

[0177] In the second scenario, a Type 3 fault occurring simultaneously with a CCF within a safety block will result in a false trigger. When the ESF trips, the 1E M / I block is If the check is positive and one block indicates a false indication of successful operation Or one block is positive and one block does not have an instruction to operate. In either case, assessing and correcting the faulty operation will help the operator for a long time. Although there may be constraints, the ability to realign components as needed is the same as with CCF provided by both 1E and non-1E control devices that will not be affected by can be.

[0178] Another analysis guideline is hierarchical requirements: blocks representing levels of detail that simplify system testing. Four conceptual layers of protection are combined in several blocks to provide (e.g. RTS and ESFAS) as well as separate blocks (e.g. safety blocks) In some cases, the separation Group, RTS, and ESFAS are safe according to the programmable technology on which they are based. Grouped into blocks, e.g., each half of the MPS (e.g., four separate groups) Two of the loops, one of the two segments of the ESFAS, and two segments of the RTS One of the safety blocks may have sufficient diversity attributes. Teams (human diversity) are based on different programmable technologies (design and equipment diversity) Different programmable digital hardware is used, and different programmable technologies have different The M / I hierarchy requires the use of different design tools (software diversity). The 1E M / I block may be divided into 1E M / I blocks. A lock may be specified to have similar diversity attributes as the safety block. How locks fit into the four layers of protection is illustrated in Figure 11, which shows the Diagram 1100 is shown.

[0179] Another analysis guideline is the evaluation method. The blocks selected are those with output signal parameters (discussed below). When analyzed according to the guidelines, all contingencies that need to be anticipated are also the most detrimental. It should be considered a "black box" as it produces results that In some cases, the failure of the operating system may result in a CCF, especially in an automated safety system. When analyzing the time required to identify and respond to conditions that result from The block is a hardware CCF and a software CCF. For each CCF, the block will be assessed based on the most harmful There are three possible outputs that can result in the same outcome: 1) a faulty system with an incorrect indication; 1) A function that remains in place or does not operate when required, 2) with an indication of successful operation and 3) erroneous initiation of a function without indication of successful operation. The EIM in any of the safety blocks can be For example, EIM may not be considered vulnerable to a single ESF component. Component or reactor trip breaker and interface with manual and automatic controls The use of finite state machines allows for all possible priority logic modules. This may allow for exhaustive testing of functionality, including inputs, device states, and state machine outputs. Its testability, EIM diversity attributes, and dedication to a single component Based on this, EIM considers software-based or software logic-based CCF. may be simple enough that is not required.

[0180] Another analysis guideline is the assumed common cause failure of the block. Display unit (digital hardware) and manual control device (non-digital hardware) A VDU may be designed for instruction only and does not have the ability to control equipment. The manual controls in each 1E M / I block 1004a / b are not The operator has the ability to initiate at the division level any protective action that is automatically performed by the Instructions and manual controls may in some instances be provided on different hardware (e.g. Digital vs. open / close contact switch), CCF can be used as both, but not both. It can be assumed that one influences the other. Software CCF and Hardware CCF In both cases, if the fault remains, the operator display of one category may cause an incorrect safe operation. This results in an indication of the operating state or failure of one of the manual switches. The device may have little or no power and therefore may not provide false activation. However, in the case of software CCF, the VDU provides a false indication of successful operation. or provide inaccurate plant status, causing operators to initiate erroneous protective actions. may be required.

[0181] Except for EIM, modules in the safety block are assumed to have software CCF. Due to the diversity attribute in the safety block, the software CCF is M or function may be limited. Safety blocks that prevent the SFM from making the appropriate trip decision. The software CCF within a block is based on the equipment, signal, and software diversity within that block. For each transient event, the 1000 W required to mitigate the event can be The primary and backup safety functions are based on different measured parameters of different physical effects. The three modules can be implemented on separate safety functions using different logic / algorithms. With redundancy implementation, and each data bus sending the same information in a different way, CMs with software CCF will not erroneously initiate protective actions or As a result, the most damaging scenario is the loss of ESFAS functionality. It could be a software CCF in the SFM causing the malfunction.

[0182] The hardware CCF within the safety block is the block's control unit that detects and initiates the required protective action. It can be assumed to be a complete failure. Hardware CCF resulting in incorrect operation of ESF functions. may have the same effect as a false activation caused by a software CCF, and thus , there are also cases where hardware CCF is not considered.

[0183] Non-1E M / I includes control equipment for safety and non-safety equipment. VD for Non-1E The VDU is different from the VDU used by the 1E M / I. Non-1E M / I subsystems (e.g., turbine control) are used for individual operations. Any errors induced by software or hardware CCF in the Any malfunctions may be immediately identifiable and, if operational limits are exceeded, MPS (Safety Measures) may be triggered. Contingencies for non-1E may be mitigated by 1 ) Failure of a subsystem component with or without indication of successful operation 2) a faulty condition with no equipment actually operating; and 3) a condition where no equipment actually operates. It remains in a failed state with indication of successful operation.

[0184] The MCS ensures that day-to-day plant operation is within operational limits, including limiting certain operational transients. It includes non-safety systems that are relied upon to maintain operation. Any failure of the control unit (e.g., rod control) can be immediately detected by the operator. Assumed software and hardware CC for MCS as well as 1E M / I F is a function of 1) the components of a subsystem with and without indication of successful operation; 2) a faulty condition with incorrect operation of the equipment; and 3) no equipment is actually operated. Provides an indication of successful operation when a fault condition occurs.

[0185] Another analytical guideline is the use of identical hardware and software modules. Therefore, the diversity between blocks provides a basis for not considering blocks that are identical. Based on this, the envisaged CCF may be limited to a single block.

[0186] Another analysis guideline is the influence of other blocks. All blocks are either correct or incorrect. Each block is assumed to function correctly in response to a new input. are deemed unaffected by the assumed CCF.

[0187] Another analytical guideline is the output signal. In some aspects, the I&C architecture The safety blocks I and I can prevent errors from propagating backwards and entering the output of the previous block. All information from I to 1E M / I is transmitted through an optically isolated 1E Signals from M / I to safety block can be sent through a transmit-only communication engine. It may be an open / close contact from a manual switch and may depend on the position of the manual switch or The CCF in the safety block cannot change the contact state. From separation groups A and C to ESFAS and RTS category II, and from separation groups B and and D to ESFAS and RTS division I. The groups are independent and redundant. However, for the purposes of illustration in Figure 10, separate groups are Groups are grouped into safety blocks according to the programmable technology they use. . RTS and ES from the isolation group as well as communication between the safety block and 1E M / I Communications to any section of the FAS can also be through an optically isolated transmit-only communications engine. Non-safety inputs to the safety block may be to the ESFAS EIM. , may be limited to isolated open / close contacts.

[0188] All inputs from the safety block are from an optically isolated, transmit-only communication engine. This means that any errors in the 1E M / I will propagate backwards to the safety block. This can prevent the problem from occurring.

[0189] Another analysis guideline is the diversity of predicted operational events. A CF or Type 2 failure may not prevent the MPS from performing its safety function. Safety blocks I and II, which together make up S, are used to limit the CCF to one block. Conventionally, nuclear power plants have implemented a system to prevent the MPS from being disabled by a CCF. A Diversified Actuation System (DAS) or screen may be used to provide multiple ways of initiating a function. However, in the illustrated MPS design, Therefore, there is sufficient diversity in the system for a single CCF to initiate the safety function. Here, the MPS is divided into safety blocks I and II (e.g., 1006a / b). The assumed software or hardware CCF is limited to one safety block. Each block will be based on different programmable technologies (design and device versatility). Based on this, different design teams (human multi-layered) utilize different programmable digital hardware. Diversity) and different programmable technologies use different design tools (software diversity). Within each block, different physical effects may be implemented on separate SFMs. There can be at least two safety functions based on the measured variables of the results. All logic is finite state. The system may be implemented in a state machine and all safety data may be communicated in a deterministic manner. Due to these attributes, even a Type 3 fault associated with a CCF will not trigger the required protective action of the MPS. This may not prevent the device from starting.

[0190] Another analytical guideline is the diversity of accidents. Similar to AOO, CCF errors in MPS -related postulated accidents may not prevent the MPS from performing its safety function .

[0191] Another analysis guideline is manual operator action. Manual component level control may be provided to the operator. , if permitted by the 1E M / I, provided to the operator using non-1E M / I. can be.

[0192] Particular implementations of the subject matter have been described. Other implementations, alternatives, and variations of the described implementations are contemplated. Modifications, as will be apparent to one skilled in the art, are within the scope of the following claims. The actions recited in the claims can be performed in a different order and still achieve desirable results. Therefore, the foregoing description of exemplary implementations does not define or limit the present disclosure. Modifications, substitutions, and alterations are also possible without departing from the spirit and scope of this disclosure. It is possible.

Claims

1. 1. A nuclear reactor protection system, comprising: A plurality of functionally independent modules, each of which is a component of a reactor safety system. receiving a plurality of inputs from the system and determining a safety action based at least in part on the plurality of inputs; a plurality of functionally independent modules configured to logically determine: a plurality of functionally independent modules communicatively connected to the plurality of functionally independent modules, the ... one or more reactor safety actuators that receive the safety action decision based on the plurality of inputs. Eta and A reactor protection system comprising:

2. 2. The reactor protection system of claim 1, Each of the plurality of functionally independent modules An atomic Furnace protection system.

3. 2. The reactor protection system of claim 1, the reactor safety system comprises an Engineered Safety Facility Actuation System (ESFAS); The plurality of functionally independent modules receive a plurality of ESFAS inputs and at least logically determine the operation of ESFAS components based in part on said ESFAS inputs. Reactor protection system.

4. 4. The reactor protection system of claim 3, The plurality of functionally independent modules provide redundant ESFAS voting partitions. Furnace protection system.

5. 2. The reactor protection system of claim 1, the reactor safety system comprises a reactor trip system (RTS); The plurality of functionally independent modules receive a plurality of RTS inputs and at least one logically determining the operation of the RTS component based on the RTS input, Furnace protection system.

6. 6. A reactor protection system according to claim 5, The plurality of functionally independent modules provide redundant RTS voting divisions. Protection system.

7. 2. The reactor protection system of claim 1, Each of the plurality of functionally independent modules protection against a single hardware fault propagation to any of the other Sub-reactor protection system.

8. 2. The reactor protection system of claim 1, Each of the plurality of functionally independent modules protection against a single software fault propagation to any of the other Sub-reactor protection system.

9. 2. The reactor protection system of claim 1, Each of the plurality of functionally independent modules Provides protection against the propagation of a single software-generated logic fault to any other of the Reactor protection system.

10. 2. The reactor protection system of claim 1, The plurality of functionally independent modules provide a single pathway for reactor trip detection and decision making. A reactor protection system providing triple redundancy for:

11. 2. The reactor protection system of claim 1, The plurality of functionally independent modules may include a plurality of reactor trip components. A reactor protection system with an independent trip voting module.

12. 2. The reactor protection system of claim 1, The plurality of functionally independent modules may be pre-programmed and dedicated to specific trip components. The reactor trip is isolated from all other modules among the plurality of modules. Logical decision making, reactor protection system.

13. 2. The reactor protection system of claim 1, The plurality of functionally independent modules may be a plurality of independent modules for each ESF component. A reactor protection system comprising an ESFAS activation voting module.

14. 2. The reactor protection system of claim 1, The plurality of functionally independent modules are dedicated to a particular ESF component. Logically determine the ESFAS operation independently of all other modules. Reactor protection system.

15. 2. The reactor protection system of claim 1, The plurality of functionally independent modules comprises a plurality of safety function modules. Furnace protection system.

16. 2. The reactor protection system of claim 1, The plurality of functionally independent modules comprises a plurality of communication modules. Protection system.

17. 2. The reactor protection system of claim 1, The plurality of functionally independent modules comprises a plurality of device interface modules. Reactor protection system.

18. 2. The reactor protection system of claim 1, The plurality of functionally independent modules may be configured to control the reactor in a single hierarchical voting scheme. A reactor protection system that makes logical decisions about tripping.

19. 2. The reactor protection system of claim 1, The plurality of functionally independent modules may be configured to control the reactor in a multi-tier voting scheme. A reactor protection system that makes logical decisions about tripping.

20. 20. The reactor protection system of claim 19, The nuclear reactor protection system, wherein the multi-tier voting scheme comprises a two-tier voting scheme.

21. 21. The reactor protection system of claim 20, The first tier of the two-tier voting scheme comprises a majority voting scheme. Stem.

22. 22. The reactor protection system of claim 21, The nuclear reactor protection system, wherein the majority voting scheme comprises a two-thirds voting scheme.

23. 21. The reactor protection system of claim 20, a second tier of the two-tier voting scheme comprising a non-majority voting scheme; system.

24. 24. The reactor protection system of claim 23, The second tier of a nuclear reactor protection system includes a two-fourth voting scheme.

25. 1. A method for determining a nuclear reactor trip, comprising: Engineered Safety Facility Actuation System (ESFAS) or Reactor Trip System (RTS) From one of them, multiple functionally independent modules of the reactor protection system receiving an input of The plurality of functionally independent modules at least partially controls the plurality of inputs. logically determine either ESFAS safe operation or reactor trip decision based on the And, Communicatively connecting the plurality of functionally independent modules based on the logical determination. One of the connected ESFAS component actuators or reactor trip breakers To operate the A method comprising:

26. 26. The method of claim 25, By one of the plurality of functionally independent modules, and limiting the propagation of a single fault to any other of the established modules. ,method.

27. 27. The method of claim 26, The single failure may be a single hardware failure, a single software failure, or a single software failure. and / or software-generated logic faults.

28. 26. The method of claim 25, and generating, by said plurality of functionally independent modules, a signal based at least in part on said input. logically determine either ESFAS safe operation or reactor trip decision. The plurality of functionally independent modules transmits the signal through triple redundant signal paths. and logically determining whether to operate the ESFAS safely or to trip the reactor. Law.

29. 26. The method of claim 25, The plurality of functionally independent modules may include redundant RTS voting sections or redundant ESFAS voting sections. providing at least one of the vote categories.

30. 26. The method of claim 25, and generating, by said plurality of functionally independent modules, a signal based at least in part on said input. logically determine either ESFAS safe operation or reactor trip decision. a plurality of functionally independent modules for each reactor trip component; The ESFAS safety operation or the atomic The method comprises logically determining a reactor trip decision.

31. 31. The method of claim 30, and generating, by said plurality of functionally independent modules, a signal based at least in part on said input. logically determine either ESFAS safe operation or reactor trip decision. a specific module among the plurality of functionally independent modules The ESFAS safety operation or comprising logically determining said reactor trip decision.

32. 26. The method of claim 25, The plurality of functionally independent modules may be a plurality of independent modules for each ESF component. Equipped with an ESFAS-activated voting module; The method further comprises: A specific module among the plurality of functionally independent modules A module dedicated to a SF component is disconnected from all other modules of the plurality of modules. and logically determining said ESFAS operation in isolation.

33. 26. The method of claim 25, The plurality of functionally independent modules include a plurality of safety function modules and a plurality of communication modules. A method comprising: a module; and a plurality of device interface modules.

34. 26. The method of claim 25, and generating, by said plurality of functionally independent modules, a signal based at least in part on said input. logically determine either ESFAS safe operation or reactor trip decision. The plurality of functionally independent modules may be used to vote in a single hierarchical voting scheme. logically determining whether to operate the ESFAS safely or to trip the reactor; method.

35. 26. The method of claim 25, and generating, by said plurality of functionally independent modules, a signal based at least in part on said input. logically determine either ESFAS safe operation or reactor trip decision. The plurality of functionally independent modules may be used to select a plurality of priorities in a multi-tier voting scheme. logically determining whether to operate the ESFAS safely or to trip the reactor; method.

36. 36. The method of claim 35, The method, wherein the multi-tier voting scheme comprises a two-tier voting scheme.

37. 37. The method of claim 36, A method, wherein a first tier of the two-tier voting scheme comprises a majority voting scheme.

38. 38. The method of claim 37, The method, wherein the majority voting scheme comprises a two-thirds voting scheme.

39. 37. The method of claim 36, A method wherein a second tier of the two-tier voting scheme comprises a non-majority voting scheme.

40. 40. The method of claim 39, The method, wherein the second tier comprises a two-quarters voting scheme.

41. A reactor protection device comprising: receiving a plurality of inputs from a reactor safety system and determining whether to perform a process based at least in part on the plurality of inputs; means for logically determining safe operation based on the means for receiving the safety action decision based at least in part on the plurality of inputs; Step by step A reactor protection device comprising:

42. 42. The reactor protection apparatus of claim 41, The means for receiving the safety action decision includes receiving the multiple safety action decisions from the reactor safety system. a means for receiving a plurality of inputs and communicatively connecting said means for logically determining said safe operation; Reactor protection device.

43. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; said means for providing protection against single fault propagation within said apparatus; Device.

44. 42. The reactor protection apparatus of claim 41, the reactor safety system comprises an Engineered Safety Facility Actuation System (ESFAS); receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for receiving a plurality of ESFAS inputs and at least partially A reactor protection system that logically determines the operation of ESFAS components based on S inputs. 。

45. 45. The reactor protection apparatus of claim 44, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; wherein said means for providing redundant ESFAS voting segments.

46. 42. The reactor protection apparatus of claim 41, the reactor safety system comprises a reactor trip system (RTS); receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for receiving a plurality of RTS inputs and at least partially determining whether the RTS inputs are relevant to the RTS inputs. The reactor protection device logically determines the operation of the RTS components based on the

47. 47. The reactor protection apparatus of claim 46, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; wherein said means for verifying a failure comprises redundant RTS voting sections.

48. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; said means for providing protection against single hardware fault propagation within said device. , reactor protection equipment.

49. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; said means for providing protection against single software fault propagation within said device. , reactor protection equipment.

50. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for protecting against a single software generated logic fault propagation within the device. Provided, reactor protection device.

51. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; the means for detecting and determining a reactor trip includes a triple redundant signal path for detecting and determining a reactor trip. Protective device.

52. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for determining whether or not a trip vote is performed includes a plurality of independent trip vote modules for each reactor trip component. A nuclear reactor protection device comprising a module.

53. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for independently determining a reactor trip for a particular reactor trip component. Reactor protection devices, which are established and determined.

54. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for determining whether to use the ESFAS may include a plurality of independent ESFAS-activated voting modules for each ESF component. A reactor protection device comprising:

55. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for independently determining ESFAS operation for a particular ESF component. Reactor protection device.

56. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; the means for detecting a failure comprises a plurality of safety function modules.

57. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; the means for communicating comprises a plurality of communication modules.

58. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; the means for connecting the power supply to the reactor comprises a plurality of equipment interface modules.

59. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for logically determining reactor trip in a single hierarchical voting scheme. , reactor protection equipment.

60. 42. The reactor protection apparatus of claim 41, receiving the plurality of inputs from the reactor safety system and logically determining the safety action; The means for logically determining reactor trip in a multi-tier voting scheme. , reactor protection equipment.

61. 61. The reactor protection apparatus of claim 60, The nuclear reactor protection system, wherein the multi-tier voting scheme comprises a two-tier voting scheme.

62. 62. The reactor protection apparatus of claim 61, a first tier of the two-tier voting scheme comprising a majority voting scheme; Place.

63. 63. The reactor protection apparatus of claim 62, The reactor protection system, wherein the majority voting scheme comprises a two-thirds voting scheme.

64. 62. The reactor protection apparatus of claim 61, a second tier of the two-tier voting scheme comprising a non-majority voting scheme; Device.

65. 65. The reactor protection apparatus of claim 64, The second tier comprises a two-fourths voting scheme.

Citation Information

Patent Citations

  • reactor protection system

    JP1998506476A

  • Digital reactor protection system that eliminates common software failures

    JP2004529353A

  • System for digital safety protection system

    JP2010249559A

  • Fault-tolerant reactor protection system

    US5621776A