Nuclear reactor protection systems and methods
The reactor protection system employs multiple independent modules with redundant voting schemes and diverse communication architectures to prevent single failure points and mitigate common cause failures, enhancing nuclear reactor safety.
Patent Information
- Application Number
- JP2025124929
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2016-12-30
- Filing Date
- 2025-07-25
- Publication Date
- 2025-11-05
AI Technical Summary
Existing reactor protection systems lack robust mechanisms to prevent single failure points that could compromise reactor safety, particularly in nuclear power systems, and do not adequately address common cause failures due to software or hardware errors.
A reactor protection system comprising multiple functionally independent modules with redundant voting schemes and diverse communication architectures, including analog and digital modules, to ensure safe operation by preventing single failure points and mitigating common cause failures.
The system provides enhanced safety by ensuring that single failures do not compromise reactor safety and effectively mitigates common cause failures, maintaining reactor safety through redundant and diverse pathways.
Smart Images

Figure 2025165996000001_ABST
Abstract
Description
[Technical Field]
[0001]
[0001] This application is filed in its entirety under 35 U.S.C. § 119. U.S. Provisional Patent Application filed December 30, 2016, which is incorporated herein by reference. This application claims priority from Application No. 62 / 440,989.
[0002] BACKGROUND OF THE INVENTION
[0002] This disclosure describes a nuclear reactor protection system and an associated method for a nuclear reactor protection system. [Background technology]
[0003]
[0003] Reactor protection systems, and reactor instrumentation and control (I&C) systems in general, Automatic initiation signals, automatic and manual control signals, and monitoring indications to mitigate the consequences of harmful conditions For example, I&C systems provide protection against unsafe nuclear power sources during steady-state and transient power operations. During normal operation, the I&C system measures various parameters During abnormal operation and accident conditions, the I&C system Reactor protection system and, if necessary, reactor trip system of the reactor protection system ( Transmits a signal to the RTS and the Engineered Safety Facility Actuation System (ESFAS) to reset the system to a predetermined set point. Initiate protective measures based on the Summary of the Invention
[0004] In a general embodiment, a reactor protection system includes a plurality of functionally independent modules. a system in which each module receives a plurality of inputs from a reactor safety system and and configured to logically determine a safety action based at least in part on the input of the Each functionally independent module is a digital module or a combined digital and analog module. and an adapter electrically coupled to one or more of the functionally independent modules. and receiving a safety action decision based at least in part on a plurality of inputs. Thus, one or more atoms communicatively coupled to multiple functionally independent modules and a reactor safety actuator.
[0005] In a first aspect that can be combined with the general embodiment, an input to an analog module The activation of the functionally independent modules causes one or more operations of at least one of the functionally independent modules. Override.
[0006] In a second aspect which may be combined with any of the preceding aspects, the analog module comprises: Contains only analog circuitry.
[0007]
[0007] In a third aspect which can be combined with any of the previous aspects, At least one input is a manual override input and the analog module Upon activation of the override input, at least one of the functionally independent modules configured to override digital operations.
[0008]
[0008] In a fourth aspect which can be combined with any of the preceding aspects, At least one input is a manual bypass input and the analog module Upon activation of the access input, the digital operation of at least one of the functionally independent modules is configured to bypass the
[0009]
[0009] In a fifth aspect which can be combined with any of the preceding aspects, At least one input is a manually actuated input and the analog module Upon startup, activate the digital operation of at least one of the functionally independent modules. It is designed to allow
[0010]
[0010] In a sixth aspect which can be combined with any of the preceding aspects, One or more outputs of the reactor protection system are routed through the backplane to multiple functional It is fed as an input to a separate module.
[0011] In a seventh aspect combinable with any of the preceding aspects, the analog module comprises: a first analog module, and the reactor protection system is connected to a second analog module and , an Engineered Safety Facility Actuation System (ESFAS) consisting of multiple functionally independent modules A first subset of rules receives multiple ESFAS inputs and has at least one ESFAS input. logically determine the operation of the ESFAS components based in part on the first analog module; The module is a functionally independent module of a first subset of the plurality of functionally independent modules. an engineered safety facility actuation system (ESFAS) electrically coupled to the module; A reactor trip system (RTS) comprising a second of a plurality of functionally independent modules a subset of the RTS inputs, and The second analog module logically determines the operation of the RTS components and provides multiple functional electrically connected to the functionally independent modules of the second subset of independent modules and a reactor trip system (RTS) that is integrated with the reactor.
[0012] In an eighth aspect, which may be combined with any of the preceding aspects, a plurality of functionally independent Each module is designed to prevent a single failure from affecting any other of multiple functionally independent modules. It provides protection from disruptions.
[0013] In a ninth aspect which may be combined with any of the preceding aspects, a nuclear reactor safety system comprises: It includes the Engineered Safety Facility Actuation System (ESFAS), which consists of multiple functionally independent modules. The module receives multiple ESFAS inputs and generates a The operation of ESFAS components is logically determined based on the
[0014] In a tenth aspect combinable with any of the preceding aspects, a plurality of functionally independent The modules provide redundant ESFAS voting divisions.
[0015] In an eleventh aspect which may be combined with any of the preceding aspects, a nuclear reactor safety system , including the reactor trip system (RTS), and consists of multiple functionally independent modules receives multiple RTS inputs and generates an RTS configuration based at least in part on the RTS inputs. Logically determine the activation of the element.
[0016] In a twelfth aspect combinable with any of the preceding aspects, a plurality of functionally independent The module provides redundant RTS voting divisions.
[0017] In a thirteenth aspect combinable with any of the preceding aspects, the analog module converts non-safety related signals to analog voltage levels and transmits them through the chassis backplane By passing the logged voltage level to the relevant function module, unsafety-related systems are protected from Related signals are electrically isolated.
[0018] In a fourteenth aspect combinable with any of the preceding aspects, functionally independent modules At least one of the modules receives at least one hardware signal from the analog module. Includes an Equipment Interface Module (EIM) that contains wired analog input signals do.
[0019] In a fifteenth aspect combinable with any of the preceding aspects, the EIM comprises at least At least one hardwired analog input signal for each digital input signal It includes a priority activation and priority logic (APL) circuit.
[0020]
[0020] In a sixteenth aspect combinable with any of the preceding aspects, at least one digital The analog signal is a safety-related signal and the APL circuitry converts it to digital from a hardwired analog signal. Digital signals take priority.
[0021] In a seventeenth aspect combinable with any of the preceding aspects, at least one hard The hard-wired analog input signal is a safety-related signal from a manually operated switch and is The circuit prioritizes hardwired analog input signals over digital signals.
[0022] In an eighteenth aspect combinable with any of the preceding aspects, at least one hard The wired analog input signal is the reactor trip signal.
[0023] In a nineteenth aspect which can be combined with any of the preceding aspects, a manually operated switch at least one hardwired analog input signal is a non-safety related control signal; The APL circuitry prioritizes the digital signal over the hardwired analog input signal.
[0024] In another schematic embodiment according to the present disclosure, a reactor protection system includes a plurality of functional Each module receives multiple inputs from the reactor safety system. and logically determining a safety action based at least in part on the plurality of inputs. The system is composed of multiple functionally independent modules that logically decide safety measures using a two-tier voting method. The first voting tier of the two-tier voting scheme includes a non-majority voting scheme, and the second voting tier of the two-tier voting scheme includes a The layer includes a majority voting system, and one or more reactor safety actuators are configured to respond to multiple inputs with a minority vote. Multiple functionally independent modules to receive safeguard decisions based at least in part on the The device is communicatively coupled to the controller.
[0025] In a first aspect that can be combined with the general embodiment, the first voting layer includes a plurality of redundant The trip signals from the signal channels are evaluated and each trip signal is related to a reactor parameter. The second layer evaluates the voting results from multiple redundant first layer channels. .
[0026] In a second aspect that may be combined with any of the preceding aspects, the first voting layer comprises: Evaluate the trip signal from the trip system (RTS).
[0027] In a third aspect that may be combined with any of the preceding aspects, the first voting layer comprises: Evaluate trip signals from the Safety Facility Actuation System (ESFAS).
[0028] In a fourth aspect that may be combined with any of the preceding aspects, the first voting layer comprises two voting layers. Includes out-of-four voting methods.
[0029] In a fifth aspect that may be combined with any of the preceding aspects, the second voting layer Includes out-of-three voting methods.
[0030] In a sixth aspect which may be combined with any of the preceding aspects, a reactor safety system includes: Multiple functionally independent modules, including the Engineered Safety Facility Actuation System (ESFAS) receives multiple ESFAS inputs and generates an ESFAS based at least in part on the ESFAS inputs. Logically determine the operation of SFAS components.
[0031] In a seventh aspect, which may be combined with any of the preceding aspects, a plurality of functionally independent The module provides redundant ESFAS voting divisions.
[0032] In an eighth aspect that may be combined with any of the preceding aspects, a reactor safety system includes: Multiple functionally independent modules, including the Reactor Trip System (RTS), receive RTS input and generate RTS components based at least in part on the RTS input. Logically judge the movement.
[0033] In a ninth aspect which may be combined with any of the preceding aspects, a plurality of functionally independent The module provides redundant RTS voting divisions.
[0034] In a tenth aspect which may be combined with any of the preceding aspects, the reactor safety system comprises: , a module functionally independent from the power supply of a non-safety-related reliable DC power system (EDSS) 1E class components to provide isolation and power monitoring to at least one of include.
[0035] In yet another general embodiment according to the present disclosure, there is provided a method for determining a nuclear reactor trip. However, the Engineered Safety Facility Actuation System (ESFAS) or Reactor Trip System (RTS) from one of the reactor protection systems to multiple inputs in multiple functionally independent modules. A two-tier voting system using multiple functionally independent modules that receive power. Therefore, it is not possible to logically determine one of the ESFAS safety actions or reactor trip conditions. and, by the first layer of the two-layer voting system, at least one of the multiple inputs to the first layer is half of the tests indicate an ESFAS safety action or reactor trip condition, and By the second layer of the stratum voting system, at least a majority of the plurality of inputs to the second layer indicates an ESFAS safety action or reactor trip condition and based on logical judgment Based on this, the ESFAS component is communicatively coupled to multiple functionally independent modules. and activating one of the actuators or the reactor trip breaker.
[0036] In a first aspect that can be combined with the general embodiment, the first voting layer includes a plurality of redundant The trip signals from the signal channels are evaluated and each trip signal is related to a reactor parameter. The second layer evaluates the voting results from multiple redundant first layer channels. .
[0037] In a second aspect that can be combined with any of the preceding aspects, the first voting layer Includes out-of-four voting methods.
[0038] In a third aspect that can be combined with any of the preceding aspects, the second voting layer Includes out-of-three voting methods.
[0039] In a fourth aspect which may be combined with any of the preceding aspects, the method further comprises: One of the functionally independent modules controls the other of the multiple functionally independent modules. The present invention further includes limiting the propagation of a single failure to any one of the above.
[0040] In a fifth aspect which may be combined with any of the preceding aspects, the single fault is a single hardware fault. hardware failure, a single software failure, or a single software-generated logic failure Contains at least one.
[0041] In a sixth aspect, which may be combined with any of the preceding aspects, a plurality of functionally independent The module is used to determine whether an ESFAS safety measure or atomic The logical decision to make one of the reactor trip decisions is made by multiple functionally independent modules. Using the control system, ESFAS safety measures or reactor trip decisions are made via triple redundant signal paths. This includes logically determining the following.
[0042] In a seventh aspect which may be combined with any of the preceding aspects, a plurality of functionally independent The module is used to determine whether an ESFAS safety measure or atomic The logical decision to make one of the reactor trip decisions is made by multiple functionally independent modules. via an independent trip voting module for each reactor trip component using the , including logically determining ESFAS safety actions or reactor trip decisions.
[0043] In an eighth aspect which may be combined with any of the preceding aspects, a plurality of functionally independent The module consists of multiple safety function modules, multiple communication modules, and multiple equipment interfaces. Includes an interface module.
[0044] In another schematic embodiment of the present disclosure, the reactor protection system display system includes a digital a display interface module coupled to a digital display panel; The display interface module includes a reactor modular protection system (MPS) Receives input data, generates a graph of the input data, and displays the individual pixels of the digital display panel. The display system is configured to drive a digital display panel and a a first power supply coupled to both the digital display panel and the display interface module; and a second power supply coupled to both the display interface module and the second The power supply is independent of the first power supply.
[0045] In a first aspect that can be combined with the general embodiment, the display system includes a second digital a second display interface module coupled to the second digital display panel; A second display interface module receives input from the same reactor MPS. and receiving the data and generating a graph of the input data and displaying it on individual screens of a second digital display panel. It is configured to drive the elements to display the graph.
[0046] In a second aspect which can be combined with any of the preceding aspects, a display interface module The module includes a field programmable logic array (FPGA).
[0047] In a third aspect which can be combined with any of the preceding aspects, a display interface module The module includes a first field programmable logic array (FPGA) and a second display. The interface module includes a second FPGA, the second FPGA providing design versatility. To provide this, the second FPGA is a different type of FPGA from the first FPGA.
[0048] In a fourth aspect which can be combined with any of the preceding aspects, a display interface module The first display module and the second display interface module are functionally independent.
[0049] In another schematic embodiment of the present disclosure, a reactor protection system display system includes a first each display arrangement of the first pair of display arrangements comprising a digital display panel and a display interface module coupled to the digital display panel. The interface module is a reactor module protection system ( MPS), generate a graph of the first input data, and The graph is displayed by driving individual pixels of the display panel. The stem display system includes a second pair of display arrangements, and each display of the second pair of display arrangements The arrangement includes a digital display panel and a display interface module coupled to the digital display panel. The display interface module includes an atomic receiving second input data from the reactor module protection system MPS and A graph is generated and configured to drive individual pixels of a digital display panel to display the graph. It is done.
[0050]
[0050] In a first aspect combinable with the general embodiment, of the first pair of display arrangements Each display arrangement supports different types of field programmable LEDs to provide design versatility. FPGAs are FPGAs.
[0051]
[0051] In a second aspect which can be combined with any of the previous aspects, the first pair of display arrangements The display interface modules are functionally independent from each other.
[0052]
[0052] In a third aspect which can be combined with any of the preceding aspects, the first pair of display arrangements The display interface module within each of the display arrangements provides design versatility within the first pair. to implement the The display interface module in each display arrangement of the second pair of display arrangements It includes different types of FPGAs to provide design diversity within the
[0053]
[0053] In a fourth aspect which can be combined with any of the preceding aspects, the first pair of display arrangements The display interface modules are functionally independent of each other and are a second pair of display arrangements. The display interface modules are functionally independent from each other.
[0054]
[0054] In a fifth aspect which can be combined with any of the preceding aspects, the first pair of display arrangements The display interface module of each of the display arrangements is configured to receive first input data. coupled to a module protection system (MPS) gateway of the first reactor module; The display interface module of each display arrangement of the second pair of display arrangements receives a second input. The MPS gateway is coupled to receive the data from the second reactor module.
[0055] In another general embodiment, a method for presenting reactor protection system data includes: a display interface module coupled to a digital display panel and a In a display arrangement including the reactor power module, data associated with the reactor module The data received from the Nuclear Protection System (MPS) and associated with the reactor power module. generating a graph of the data and driving individual pixels of a digital display panel to display the reactor voltage. and displaying a graph of the data associated with the force module.
[0056] A first aspect that can be combined with the general embodiment is a digital display through a first power source. The display panel further includes providing power to the display interface module.
[0057]
[0057] A second aspect that can be combined with any one of the above aspects is a power supply that is independent of the first power supply. Power is supplied to the digital display panel and display interface module through a second power supply. further comprising providing:
[0058] In a third aspect that can be combined with any one of the preceding aspects, the second power source is a first It is electrically independent from the power supply.
[0059]
[0059] In a fourth aspect which can be combined with any one of the preceding aspects, a display interface The module includes a field programmable logic array (FPGA).
[0060]
[0060] In a fifth aspect which can be combined with any one of the preceding aspects, the display arrangement is A display arrangement, the display interface module is a first display interface module. The digital display panel is the first digital display module.
[0061]
[0061] A sixth aspect that can be combined with any one of the above aspects is a second digital display panel. a second display interface module coupled to the second digital display panel; In a second display arrangement including: data associated with the reactor power module; received from the Module Protection System (MPS) and associated with the reactor power module generating a second graph of the acquired data; and displaying the individual pixels of the second digital display panel. to display a second graph of data associated with the reactor power module. It further includes and.
[0062]
[0062] In a seventh aspect which may be combined with any one of the preceding aspects, the first and second displays The locations are functionally independent.
[0063]
[0063] In an eighth aspect combinable with any one of the preceding aspects, a first display interface The interface module includes a first FPGA of a first FPGA type and a second display interface. The base module includes a second FPGA of a second FPGA type.
[0064]
[0064] In a ninth aspect which can be combined with any one of the preceding aspects, a first FPGA type and The first and second FPGA types are different.
[0065] Various embodiments of the reactor protection system according to the present disclosure may have one of the following features: For example, a reactor protection system may include a system Any software or software that may disable and / or defeat safety features within the system Can mitigate common cause failures (CCF) caused by incident logic errors As another example, a nuclear reactor protection system is an independent, redundant, deterministic, multi-layered, diverse, testable, The reactor protection system can incorporate key attributes including: As another example, reactor maintenance can ensure that the reactor is maintained in a safe condition. The protection system has functionality implemented within individual logic engines dedicated to specific functions. Through a symmetric architecture, increased simplicity can be achieved. Therefore, the reactor protection system will protect the reactor via redundant paths based on a simple deterministic protocol. As another example, the communication architecture may facilitate communication with a nuclear reactor maintenance The protection system uses hardwired analog signaling to operate the digital protection system. This allows for manual control of the protective measures.
[0066]
[0066] Details of one or more embodiments of the subject matter described herein are set forth in the accompanying drawings, in which: and in the description that follows. Other features, aspects, and advantages of the subject matter are set forth in the description, drawings, and claims. This becomes clear from the scope of the request. [Brief explanation of the drawings]
[0067] [Figure 1] FIG. 1 is a block diagram of an exemplary embodiment of a system including multiple nuclear systems and an instrumentation and control (I&C) system.
[0068] [Figure 2A] FIG. 2A is a block diagram of a modular protection system (MPS) of an I&C system for a nuclear power system. [Figure 2B] FIG. 2B is a block diagram of a modular protection system (MPS) of an I&C system for a nuclear power system.
[0069] [Figure 3A] FIG. 3A is a block diagram of a trip decision block of an MPS of an I&C system for a nuclear power system.
[0070] [Figure 3B] FIG. 3B is a block diagram of an Engineered Safety Facility Actuation System (ESFAS) of an MPS of an I&C system for a nuclear system.
[0071] [Figure 4A]
[0071] Figure 4A is an exemplary chart showing a multi-tier diversity strategy for mitigating common cause failures based on software or software logic within the MPS that ensures the I&C system is able to perform its intended safety function(s). [Figure 4B]
[0071] Figure 4B is an exemplary chart showing a multi-tier diversity strategy for mitigating common cause failures based on software or software logic within the MPS that ensures the I&C system is able to perform its intended safety function(s).
[0072] [Figure 5] FIG. 5 is a block diagram of a safety function module (SFM) of an MPS of an I&C system for a nuclear system.
[0073] [Figure 6] FIG. 6 is a block diagram of a communications module (CM) of an MPS of an I&C system for a nuclear system.
[0074] [Figure 7]FIG. 7 is a block diagram of an Equipment Interface Module (EIM) of an MPS of an I&C system for a nuclear system.
[0075] [Figure 8] FIG. 8 illustrates an exemplary embodiment of a chassis for a reactor protection system that communicatively couples one or more SFMs, EIMs, and CMs.
[0076] [Figure 9A] FIG. 9A is a block diagram of the interconnections of the trip determination, RTS, and ESFAS levels utilizing one or more of the SFM, CM, and EIM. [Figure 9B] FIG. 9B is a block diagram of the interconnections of the trip determination, RTS, and ESFAS levels utilizing one or more of the SFM, CM, and EIM. [Figure 9C] FIG. 9C is a block diagram of the interconnections of the trip determination, RTS, and ESFAS levels utilizing one or more of the SFM, CM, and EIM.
[0077] [Figure 10]
[0077] Figure 10 is a diagram of the diversity analysis of the MPS of the I&C system for the nuclear power system.
[0078] [Figure 11] FIG. 11 is a block diagram of an exemplary separation of the MPS block into four layers of defense.
[0079] [Figure 12] FIG. 12 is a schematic diagram of another exemplary embodiment of an MPS safety architecture for a nuclear system.
[0080] [Figure 13] FIG. 13 is a schematic diagram of an exemplary embodiment of a split group communication architecture for an MPS.
[0081] [Figure 14A] FIG. 14 is a schematic diagram of an exemplary separation group and division reactor trip system (RTS) and ESFAS communication architecture. [Figure 14B] FIG. 14 (continued) is a schematic diagram of an exemplary separation group and division reactor trip system (RTS) and ESFAS communication architecture. [Figure 14C] FIG. 14 (continued) is a schematic diagram of an exemplary separation group and division reactor trip system (RTS) and ESFAS communication architecture.
[0082] [Figure 15] FIG. 15 is a schematic diagram of an exemplary embodiment of an EIM.
[0083] [Figure 16A] FIG. 16 is a schematic diagram of an exemplary embodiment of an MPS gateway. [Figure 16B]
[0083] Figure 16 (continued) is a schematic diagram of an exemplary embodiment of an MPS Gateway.
[0084] [Figure 17] FIG. 17 is a block diagram of a nuclear plant protection system (PPS).
[0085] [Figure 18] FIG. 18 is a schematic diagram of an exemplary embodiment of a safety indication and marking system for an MPS.
[0086] [Figure 19] FIG. 19 is a schematic diagram of an exemplary embodiment of a safety marking and indicator hub for an MPS.
[0087] [Figure 20]
[0087] FIG. 1 is a block diagram of an exemplary embodiment of a display system for an MPS.
[0088] [Figure 21A] FIG. 21 is a schematic diagram of another exemplary embodiment of an SFM. [Figure 21B] FIG. 21 (continued) is a schematic diagram of another exemplary embodiment of an SFM.
[0089] [Figure 22] FIG. 22 is a schematic diagram of an exemplary embodiment of a monitoring and indicator (MIB) communication module of the MPS.
[0090] [Figure 23] FIG. 23 is a schematic diagram of an exemplary embodiment of a scheduling and bypass module (SBM) of an MPS.
[0091] [Figure 24] FIG. 24 is a schematic diagram of an exemplary embodiment of the Scheduling and Voting Module (SVM) of the MPS.
[0092] [Figure 25] FIG. 25 is a schematic diagram of an exemplary embodiment of an Equipment Interface Module (EIM) of an MPS.
[0093] [Figure 26] FIG. 26 is a block diagram of the hardwired module (HWM) of the MPS.
[0094] [Figure 27] FIG. 27 is a table of reactor trip functions for an exemplary nuclear system.
[0095] [Figure 28A] FIG. 28A is a table of exemplary ESFAS functions. [Figure 28B]FIG. 28B is a table of exemplary ESFAS functions. [Figure 28C] FIG. 28C is a table of exemplary ESFAS functions.
[0096] [Figure 29] FIG. 29 is a table of exemplary variables monitored by an exemplary PPS.
[0097] [Figure 30A]
[0097] Figure 30A is a table of exemplary MPS interlocks, permissives, and overrides. [Figure 30B]
[0097] Figure 30B is a table of exemplary MPS interlocks, permissives, and overrides. [Figure 30C]
[0097] Figure 30C is a table of exemplary MPS interlocks, permissives, and overrides. DETAILED DESCRIPTION OF THE INVENTION
[0098] FIG. 1 illustrates an exemplary embodiment of a system 100. The system 100 includes a plurality of The nuclear power system 150 and the reactor instrumentation and control (I&C) system 135. Thus, the I&C system 135 may be configured to prevent or mitigate the consequences of a fault condition within the system 100. To this end, automatic initiation signals, automatic and manual control signals, and monitoring and sign indications are provided. The C system 135 controls the normal operation of the nuclear power system 150 during steady-state and transient power operations. Provides reactor control and protection from unsafe reactor operation. During normal operation, the instrumentation Measures important process parameters and transmits signals to the control system of the I&C system 135 During abnormal operation and accident conditions, the instrumentation may be part of the I&C system 135 (e.g., modules). The Reactor Trip System (RTS)1, which is part of the Module Protection System (MPS)145 47 and Engineered Safety Facility Actuation Systems (ESFAS) 148 (e.g., to mitigate the consequences of an accident) The system transmits a signal to the power supply to reduce the power consumption and initiate protective action based on a predetermined set point.
[0099] In FIG. 1, the system 100 includes a plurality of I&C systems 135 electrically coupled to the I&C system 135. Included are nuclear power systems 150. In this example, only three nuclear power systems 150 are shown. However, fewer or more systems 150 may be included or combined with system 100. (e.g., 6, 9, 12, or other). In one preferred embodiment, Two nuclear power systems 150 may be included in the system 100, and these nuclear power systems One or more of the systems 150 may be modular light water submarines, as further described below. Includes furnace.
[0100]
[0100] For each nuclear system 150, although not explicitly stated, a reactor core can provide heat. This heat is then used to power the primary coolant loop (e.g., in a boiling water reactor) or the secondary coolant loop. Boiling water in the coolant loop (e.g., in a pressurized water reactor). The generated coolant can be used to drive one or more turbines, The turbines convert the thermal potential energy into electrical energy. The coolant then returns to remove more heat energy from the reactor core. 150 requires monitoring and protection functions to minimize the risks associated with failures within the system. This is an example of any system that:
[0101]
[0101] In a particular exemplary embodiment of each reactor system 150, a cylindrical or capsule-shaped The reactor core is positioned in the bottom portion of the reactor vessel. of fissile material, and this reaction would likely occur over a period of several years or longer. Although not shown in Figure 1, control rods are used to control the rate of nuclear fission in the core. Control rods can be made of silver, indium, cadmium, boron, cobalt, Fe, dysprosium, gadolinium, samarium, erbium, and europium However, these may include many possible control Only some of the rod material is in the reactor, which is designed with a passive operating system. , during normal operation or in emergency conditions, without operator intervention or supervision, at least to some extent. To ensure that the safe operation of the reactor is maintained for a predefined period of time The laws of physics are used to
[0102] In an embodiment, a cylindrical or capsule-shaped containment vessel surrounds the reactor vessel. and are partially or completely submerged in the reactor pool, e.g., below the water line in the reactor bay. The volume between the reactor vessel and the containment vessel is used to transfer heat from the reactor vessel to the reactor pool. However, in other embodiments, the air may be partially or completely evacuated to reduce the The volume between the reactor vessel and the containment vessel increases the heat transfer between the reactor and the containment vessel. The containment vessel may be at least partially filled with gas and / or liquid. It can be located on the periphery at the bottom of the part.
[0103] In certain embodiments, the core is made of a material such as water, which may contain boron or other additives. The core is immersed in a liquid that rises up the channel after contacting the surface of the core. The coolant travels over the top of the heat exchanger and is drawn downward by convection along the inner wall of the reactor vessel. The bottom of the reactor vessel is enclosed within the reactor core, allowing the coolant to give up heat to the heat exchanger. After reaching this point, the coolant heats up due to contact with the core and is forced through the channels again. Rise.
[0104]
[0104] The heat exchanger in the reactor vessel may comprise any suitable material wrapped around at least a portion of the channel. In another embodiment, a different number of spiral coils may be arranged in an opposing direction. The first spiral coil may be wound around the channel in a counterclockwise direction, for example. The first spiral coil winds in a clockwise direction, and the second spiral coil winds in a clockwise direction. The use of heat exchangers of different configurations and / or different orientations is not prevented and no practical application in this regard is required. The embodiment is not limited.
[0105]
[0105] In Figure 1, normal operation of the reactor module involves the flow of heated coolant through channels. After contacting the heat exchanger, the coolant flows through the heat siphon. In the example of Figure 1, the reactor vessel The coolant inside remains at a pressure above atmospheric pressure, so that the coolant does not evaporate (e.g., boil). This makes it possible to maintain a high temperature without causing a rise in temperature.
[0106]
[0106] As the temperature of the coolant in the heat exchanger increases, the coolant may begin to boil. When the coolant in the heat exchanger begins to boil, the evaporated coolant, such as steam, is used to The turbine or turbines may drive one or more thermal pots of steam. After condensation, the coolant is pumped through the bottom of the heat exchanger. Return to the area near the surface.
[0107] During normal operation of the nuclear power system 150 of FIG. 1, various locations in the nuclear power system 150 The atoms are detected by sensors positioned within the I&C system 135, for example. Various performance parameters of the power system can be monitored. system temperature, system pressure, primary and / or secondary coolant levels, and neutron flux. Signals representing these measurements are transmitted to the I&C system 135 interface. A communication channel to the base panel allows reporting outside the nuclear system.
[0108] The illustrated I&C system 135 generally comprises a master control room 140 and modules (or Reactor Protection System (MPS) 145 and Unsafe Modular Control System (MCS) 1 55. The main control room 140 includes a set of control and signage for each nuclear system 150. Each set of control and indicator units 141 includes a manual 1E control 142 and an 1E indicator unit 143. 43 and non-1E control and indicator section 144. In some aspects, "1E" refers to the original IEEE Standard 308-2001 No. 10 ... It can refer to regulatory requirements such as those defining the 1E method according to Chapter 3.7, and the above regulatory guidelines The id is essential for emergency reactor shutdown, containment isolation, core cooling and containment, and reactor heat removal. Safety classification of essential electrical equipment and systems or to prevent significant release of radioactive material into the environment. Typically, certain controls and indicators are defined as " 1E-compliant (e.g., manual 1E controls 142 and 1E indicators 143); Other controls and indicators are deemed "1E" ineligible (e.g., non-1E control and indicator 144). It is possible.
[0109]
[0109] The non-1E control and indication section 144 is in bidirectional communication with the MCS 155. 55 can provide control and monitoring of unsafe portions of the nuclear system 150. The MCS155 then suppresses transients during operation and prevents unit tripping, among other things. and re-establish steady state unit operation.
[0110]
[0110] The MPS 145 includes the manual 1E control 142 and 1E indicator 143 shown in FIG. MPS 145 generally initiates safety actions and responds to the consequences of a design basis event. The MPS 145 generally reduces the sensor load required to initiate reactor shutdown. From the power supply to the final actuation device (power supply, sensors, signal conditioners, initiation circuits, logic, bypass, control All equipment (hardware, software, and firmware).
[0111] MPS145 includes RTS147 and ESFAS148. RTS147 is In some embodiments, four independent, separate groups (e.g., electrical circuits of the same 1E class) are used. a physical grouping of process channels with a channel name (A, B, C, or D) These separate groups have separate and independent power sources and process instrumentation transmitters. Each group is physically and electrically independent from the other groups. Independent monitoring of plant parameters that can be used to generate a Each measurement channel generates an emergency signal when a parameter exceeds a predetermined set point. The coincidence logic of the RTS147 ensures that a single fault will prevent the required reactor trip. so that a failure in a single measurement channel does not generate an unnecessary reactor trip. It can be designed so that
[0112]
[0112] The ESFAS 148, in some embodiments, comprises four independent measurement channels. These measurement channels are used by the Engineered Safety Facility (ESF) facility. Monitors plant parameters that can be used to trigger the operation of the device. The channel will be shut down when the parameter exceeds a predetermined set point. The coincidence logic ensures that no single fault will prevent the required safeguard action and that a single measurement Design so that a single fault in the channel will not produce unnecessary safeguard activation It is possible.
[0113]
[0113] The system 100 may include four layers of defense, for example, NUREG / As defined in CR-6303, for the purpose of reactor operation or shutdown and cooling, The specific application of the defense-in-depth principle to the layout of reactor-mounted instrumentation and control systems Specifically, the four levels are the control system, reactor trip or shutdown, clam systems, ESFAS, and monitoring and marking systems (e.g., nominally three other Class 1E and non-Class 1E required to operate equipment assigned to one tier (The slowest and most flexible defense layer, including both manual control, observation, and signage elements of the class.) .
[0114] The control system hierarchy typically includes MCS155 (e.g., non-1E class manual MCS155 includes the reactor excursion into an unsafe operating area. These systems routinely prevent nuclear volatilization and generally operate reactors within a safe power operating range. Within the control hierarchy, indicators, annunciators, and alarms can be included. The reactor control system is typically subject to specific regulations and / or requirements, e.g., remote shutdown panels. It includes several devices to meet the requirements for the control system hierarchy. The reactor control functions are included in the MCS 155. The MCS 155 is, for example, Maintaining the system 100 within operating limits to avoid the need for trip or ESF actuation Includes features.
[0115]
[0115] The reactor trip system hierarchy is typically controlled by the RTS 147, e.g. designed to rapidly reduce core reactivity in response to an uncontrolled excursion. This tier typically includes safety equipment that detects potential or actual excursions. The instrumentation equipment and processes for rapid and complete insertion of reactor control rods are It may also include a chemical neutron moderation system (e.g., boron implantation). As such, the automatic reactor trip function performed by the reactor trip hierarchy is (e.g., in RTS147).
[0116]
[0116] The ESFAS hierarchy typically consists of an ESFAS module that is part of the MPS 145. The ESFAS hierarchy implemented within the ESFAS module 148 is typically There are three physical barriers to the removal of heat or otherwise releasing radioactive material, including: safety mechanisms that help maintain the integrity of the nuclear fuel rod cladding, reactor vessel, and reactor containment This layer includes the various support systems ( Emergency reactor cooling (for example, emergency generators) or devices (valves, motors, pumps), Detects the need for and performs functions such as pressure relief or pressure reduction, isolation, and control. To carry out.
[0117]
[0117] The monitoring and signage system hierarchy typically includes a main control room 140, with several In terms of defense, it is the slowest and most flexible layer of defense. As with the other three layers, the operator ( For example, an operator of the system 100 may perform his or her task depending on accurate sensor information. but performs a logical computation that is not specified in advance, given information, time, and means. The monitoring and signage tier is nominally the same as the other three Operate the devices assigned to the hierarchy (for example, manual 1E control 142, 1E indicator 143, and non-1E control and indication unit 144) Includes non-1E class manual control, monitoring, and signage. The required functions are the manual control system in the main control room containing information from MCS155 and MPS145. Safety monitoring, manual reactor trip, and manual The automatic ESF activation function is contained within MPS145. MCS155 is Provides unsafe monitoring and manual control to maintain operating limits during operation.
[0118] In addition to including four layers of defense, system 100 also provides multiple levels of diversity. Specifically, I&C diversity involves the creation of diverse ways of responding to anticipated plant conditions. measuring or actuating variables using different techniques, logic, or algorithms to provide Here, we will introduce several ways to detect and respond to important events. Use different technology, logic, or algorithms or operating means to provide the method A variety of applications of this principle exist in instrumentation systems that sense different parameters. Diversity is complementary to the principle of defense in depth, and it is important to understand the need for a particular level or depth of defense. In general, human diversity, design diversity, software diversity, There are six types of diversity: hardware diversity, functional diversity, signal diversity, and equipment diversity. As discussed in more detail in this disclosure, the MPS 145 may be configured to Failures (e.g., that disable redundancies implemented by the hardware architecture) (failures caused by software errors or software-generated logic) To mitigate the impact of , six attribute diversity can be incorporated.
[0119]
[0119] In general, human diversity is a human-induced addressing potential problems (e.g., mistakes, misinterpretations, errors, configuration problems) It is characterized by dissimilarity in the execution of life cycle processes.
[0120]
[0120] Generally, design diversity refers to the combination of software and Software diversity is the use of different approaches, including software and hardware. It is a special case of variability and is mentioned separately because of its potential importance and potential drawbacks. The rationale for design diversity is that different designs have different failure modes and may not suffer from the same common effects. The advantage is that it is less susceptible to influence.
[0121]
[0121] In general, software diversity is used to determine, for example, whether a nuclear reactor should be shut down. Use two separately designed programs to determine the same safety goal. It is designed and implemented by different software development groups, including different key personnel, to The solution is to use different software programs.
[0122]
[0122] In general, functional diversity is a combination of different, though potentially overlapping, safety effects. Two systems (e.g., subsystems within system 100) that perform physical or logical functions. Refers to the system.
[0123] Generally, signal diversity involves detecting different process parameters to initiate protective action. The goal is to use one of these parameters so that the other parameters are accurately detected. If the signal is not detected, it can independently indicate an abnormal condition.
[0124] Generally, device diversity involves using different devices to perform similar safety functions. (e.g., safety functions must be able to operate within established acceptable limits for design basis events) is one of the processes or conditions essential to maintaining plant parameters at The RTS or ESF must complete all necessary protective measures or provide supporting support. The feature is realized by completing all necessary protective measures, or both. In this case, "different" means significantly reducing vulnerability to common cause failures. It can mean that they are not similar enough to be similar.
[0125] In some embodiments, the MPS 145 performs continuous (or partially continuous) self-tests and Such a testing strategy may incorporate a combination of periodic surveillance testing and periodic monitoring testing. Detectable faults are identified and personnel are notified (e.g., via the main control room 140). The self-test feature ensures that the system state is continuously (or partially) A comprehensive diagnostic system can be provided to ensure that all tests are monitored. It can notify personnel of possible faults and determine the overall health of the system. The self-test feature can provide an indication of the effects of a failure. Self-test features ensure system integrity is maintained at all times. Make sure.
[0126] In some embodiments, each sub-module within MPS 145 (described in more detail below) The NI 9111A / 9112A / 9113A / 9114A / 9115A / 9116A / 9117A / 9118A / 9119 ... It may include a self-test feature that provides a range of tests necessary to detect faults. This can minimize the time spent on maintenance and provide safety and system availability benefits. When the system is operating normally, the self-test does not affect the performance of the safety functions, such as response time. It is carried out without any impact.
[0127] The self-test feature is active and inactive to avoid having undetected faults. Logic that is both active and inactive (e.g., activated only when the safety function is required to operate) Most faults can be detected by the MPS. This is done at the submodule level and plant personnel must identify the MPS submodules that need to be replaced. It becomes possible to easily identify it.
[0128] All functional tests and inspections, calibration verifications, and time response measurements are certified. To ensure this, periodic online surveillance testing capability can be incorporated. The visual test also verifies the continuous self-test functionality.
[0129] The self-test and periodic monitoring test features within the MPS 145 are used to monitor all plant operating modes. The safety functions performed on the board should be designed for in-service testability commensurate with the Performance self-tests and monitoring tests do not require temporary test setup. Experimental features are inherent in the design of the system and add complexity to the safety function logic and data structures. Continuous indication of bypass status can be minimized during: (1) normal plant operation; (2) a fault is detected by self-test, or (3) some safety features are bypassed, or is deliberately made inoperative for testing. After the bypass is complete, the bypass indicator is removed, ensuring that the bypassed safety function continues to operate properly. This ensures that plant personnel can verify that the system has returned to normal operation.
[0130] Diagnostic data for MPS145 are shown for each isolation group and division. The MWS is used for troubleshooting activities. The MPS and MWS can be located close to the equipment for ease of operation. The interface may be an optically isolated one-way diagnostic interface. All diagnostic data can be communicated over physically separate communication paths, thereby This ensures that the diagnostic functions are independent of the safety functions. The data can be transmitted to a central historian for long-term storage. A means is provided for performing historical analysis of system behavior.
[0131] The diagnostic system can maintain a list of installed modules. These lists are used to protect against missing or incorrectly installed modules. It can be continuously compared with the installed modules active in the system.
[0132] All MPS secure data communications enforce data integrity with error detection. The protocol features ensure that communications are robust and reliable. , and has the ability to detect transmission failures. Similar data integrity features can be used to store diagnostic data. It can also be transmitted.
[0133] 2A-2B show modular protection of an I&C system for a nuclear power system 150. 2 shows a block diagram of a multi-purpose protection system (MPS) 200. In some embodiments, the MPS 20 0 may be similar to or identical to the MPS 145 shown in FIG. S200 separates four groups of sensors and detectors (e.g., sensors 202a-202d). loop, signal conditioning and signal conditioners (e.g., signal conditioners 204a-204d) and four tripping decisions (for example, tripping decisions 208a to 208d). Separate groups and RTS voting and reactor trip interrupters (e.g., Division I Two divisions (RTS Vote 214 and Division II RTS Vote 216) and Engineered Safety Facility Actuation System (ESFAS) voting and Engineered Safety Facility (ESF) equipment ( For example, ESFAS Voting Division I 212 and ESF Equipment 224, and Division The two divisions are ESFAS Votes 218 and ESF Instruments 226.
[0134] Generally, the sensors 202a-202d are used to measure pressure, temperature, level, neutron flux, etc. It includes process sensors responsible for measuring different process parameters of the nuclear system. Each process parameter of the system 150 is measured using a different sensor and has a different logic. The engine processes the data using different algorithms. The neutron flux sensor measures neutrons from the core from shutdown to 120 percent of full power. The MPS200 is responsible for measuring the neutron flux. It consists of three regions: the source region, the intermediate region, and the power region. Three types of neutron flux detectors can be used:
[0135] Generally, the signal conditioners 204a-204d process the measurements from the sensors 202a-202d. The device receives measurements, processes these measurements, and provides outputs 206a-206d. In an embodiment, the interconnection of the sensors 202a-202d to the signal conditioners 204a-204d is It can be a dedicated copper wire or some other method of signal transmission.
[0136]
[0136] Each of the signal conditioners 204a-204d includes a plurality of input modules, as shown in FIG. 3A. modules 270a to 270n (for example, any number of modules may be shown depending on the number of sensor inputs) The input modules 270a to 270n can be configured from sensors 202a to 202n. Responsible for conditioning, measuring, filtering, and sampling field inputs from 202d Each input module 270a to 270n accepts 24V or 48V digital input, 4 to 10V digital input, 20mA analog input, 0~10V analog input, resistance heat detector input, or thermocouple input They can be dedicated to specific input types such as force.
[0137]
[0137] Each of the input modules 270a to 270n is composed of an analog circuit and a digital circuit. Analog circuits can be constructed to convert analog voltages or currents into digital representations. The analog circuit is also called a signal conditioning circuit. The digital portion of 270n can be located in a logic engine. Control of all input modules, sample and hold filtering, integrity checks Performs check, self-test, and digital filtering functions. Digital representation of sensor output. In some cases, a serial interface is used to transmit the signals through outputs 206a-206d. , are communicated from the signal conditioners 204a-204d to the trip decision makers 208a-208d.
[0138]
[0138] Referring also to FIG. 3A, the trip determinations 208a-208d generally The sensor input values from the signal conditioners 204a to 204d are transmitted via the interface. The trip determinations 208a to 208d are each performed by an independent safety function module. Modules (SFM) 272a to 272n (described in more detail with reference to FIG. 5) A specific module performs a set of safety functions (e.g., a set (It can be a single safety function or multiple safety functions related to the process parameters). For example, one set of safety functions may be a first order variable, such as a high trip and a low trip from the same pressure input. Each SFM 272a-272n can consist of a set of functions related to numbers. Contains a unique logic engine dedicated to the implementation of the safety function. As a result, each set of safety function gates The implementation of the level is completely different from all other sets of safety features.
[0139]
[0139] The sensor input values (e.g., outputs 206a-206d) are transmitted via a deterministic path. The trip determination unit 208a to 208d can communicate with the specific SFM 272a to 272d. These input values are then converted to engineering units and used to determine which safety function or It is possible to determine which set of safety functions is implemented in that particular SFM 272a-272n. The trip determinations 208a-208d may be implemented in some cases using isolated optical transmissions. These engineering unit values are provided to the control system via a fiber connection.
[0140]
[0140] The SFM in each trip decision 208a-208d is set to a predetermined value if necessary. Reactor trip decisions are based on fixed points and isolated, possibly triple redundant, transmission-only systems are used. A trip or non-trip request signal is sent to each RTS division (e.g., For example, RTS ballots 214 and 216 for Divisions I and II, respectively. The FM also makes ESFAS activation decisions based on predetermined set points and intervals, if required. Activation or deactivation requests via a separate, possibly triple redundant, transmission-only series connection Signals are assigned to each ESFAS division (e.g., ESF Divisions I and II, respectively). AS Votes 212 and 218).
[0141] As shown in FIGS. 3A-3B, for example, a particular trip decision 208a may be 74a to ESFAS ballot 212, and output 274b to ESFAS ballot 218 , providing a trip or no-trip request signal. Trip decision 208a provides output 276a to the RTS poll 214, and output 276b to the RTS poll 216, trip or These outputs also provide the trip decision 208a-208c, respectively. 208d are also shown generally in FIG. 2A as outputs 210a-210d.
[0142]
[0142] As further shown in Figure 3A, for example, a particular trip decision 208a may A trip or non-trip request signal is sent to Monitoring & Indication (M&I) outputs 278a and 278b (Division Outputs 278a and 278b are provided to the , provides process information to the MCS for unsafe control functions. Output 280 is and provides trip status information to the non-1E control and indication section 144.
[0143] Returning to FIG. 2A, for each RTS division (e.g., R TS ballot 214 and RTS ballot 216 for Division II) are isolated, In some embodiments, redundant (e.g., dual, triple, or other), receive-only serial connections 2 Receives input from the above-mentioned trip decision 208a to 208d via 10a to 210d. The trip inputs are combined in the RTS voting logic, resulting in a trip decision 208. Two or more reactor trip inputs from outputs 228a-228d and 23 0a to 230d (as appropriate for each division) to cause an automatic reactor trip output signal; Outputs 228a-228d and 230a-230d are associated with the respective divisions. The tripping for four of the eight reactor trip breakers (RTBs) (shown in Figure 2B) was In other words, in this exemplary embodiment of the MPS 200: The RTS voting logic works on a "two out of four" logic, which means that there are four trip decisions. At least two of the conditions 208a-208d require a reactor trip. When the trip signal is output from each of the RTBs 264a to 264d and 266a to 266d, This circuit breaker configuration allows for safe and simple on-off of the MPS200. Line testing becomes possible.
[0144]
[0144] The manual trip 250a is a direct tripping of the RTB 266a to 266d (Division I). Provides tripping, manual trip 250b, RTB 264a-264d (Division II) direct tripping, as well as automatic manual tripping 234 (Division I) and provides input to manual trip 236 (Division II) to ensure sequence is maintained. Ensure that
[0145]
[0145] As further shown, each of the RTBs 264a to 264d and each of the RTBs 266a to 266 d includes manual trip 250a or 250b as an input. Trips 250a and 250b (e.g., manual trips for Divisions I and II) When the data transfer is started, the status of the inputs 230a to 230d and the inputs 228a to 228d is Regardless of whether the power input 260 is tripped or not (e.g., tripped or not), the power input 260 is is not transmitted to
[0146] In an exemplary embodiment, the ESFAS voting and logic is A single fault does not prevent operation, and a trip determination signal (e.g., 210a to 210d ) are arranged so that a single failure in E will not produce unnecessary safeguard activation. The SFAS system is a critical system that includes the emergency core cooling system and the decay heat removal system. Both automatic and manual initiation of the system can be provided.
[0147] Each ESFAS poll 212 / 218 is an isolated, triple redundant receive-only optical fiber Input 21 is received from trip decision 208a-208d via a driver (or other communication technique) connection. 0a to 210d. The operating logic and voting are carried out within ESFAS Voting 212 / 218. When ESFAS ballot 212 / 218 determines that activation is required, ESF The AS votes 212 / 218 transmit the activation request signals to the ESFAS priority logic 220 / 222, respectively. The ESFAS priority logic 220 / 222 then creates the appropriate ESF devices 224 and 226. Move.
[0148]
[0148] The embodiment of MPS 200 shown in Figures 2A-2B and 3A-3B includes, among its main elements: This ensures a high level of independence. There are four separate groups for tripping (denoted by "a" to "d"), Two divisions of RTS214 / 216 (listed Division I and Division II) and ESFAS Circuit 212 / 218 (listed Division I and Division II) The two divisions and ESF equipment 224 / 226 (described in Division I and Division II) Including the independence between the two divisions of SFM (e.g., Trilogy) Based on the input to group decisions 208a-208d, MPS 200 divides the four separation groups into Each group independently performs a set of safety functions. 202a to 202d to the trip determination outputs 210a to 210d. In this aspect, this configuration limits SFM failures to those based on the input of that module. This strategy can limit the impact of common cause failures and enhance signal diversity. This independent method also ensures that a failure within an independent safety function does not affect any of the other safety function modules. Furthermore, it is possible to ensure that the online version of the failed SFM does not spread to other Replacement of the module allows the failure to be corrected with minimal, if any, impact on other modules. Ensure that this is possible.
[0149]
[0149] The communication of safety function data within the illustrated MPS200 is performed in a triple-module, redundant, independent manner. This communication method is transmitted or received via an optically isolated, one-way communication path. The formula is separate from the inter-division vote, and the safety function is implemented by the Ensure that the Division does not rely on any information or resources originating from outside the Division. 1. Inter-division barriers in the E class (e.g., Divisions I and II) Spreading is the unidirectional isolation (e.g., optical isolation or other) of the division trip signal. This is prevented by
[0150]
[0150] The embodiment of MPS 200 shown in Figures 2A-2B and 3A-3B is Redundancy within the MPS200 is further built into multiple areas of the architecture. and detectors (denoted by "a" to "d"), and trip judgment (denoted by "a" to "d") Separate groups and RTS and ESFAS circuits (listed Division I and Division II) I) and two divisions. MPS200 also includes a two-out-of-four ballot. Use of the system to initiate the necessary reactor trip or ESF equipment operation. In addition, it prevents a single signal failure from interfering with the operation of the reactor. Ensure that a single failure of the initiating signal does not cause a trip or ESF equipment operation.
[0151]
[0151] The MPS 200 also provides functional independence by implementing each set of safety functions. Each set of safety functions is implemented by a logic engine that is unique to that particular set of safety functions. This is used by a separate SFM to mitigate specific transient events.
[0152] In some embodiments, the MPS 200 provides a simple and reliable method for controlling nuclear reactor systems. For example, the MPS200 implements four design techniques to achieve a safe design. It can be based on a symmetric architecture with separate groups and two divisions. Each of the isolation groups can be functionally equivalent to the other isolation group, and the two Each vision can be functionally equivalent. Voting may be the only voting strategy in the illustrated embodiment. The logic of the MPS200 is implemented within a finite state machine dedicated to a particular safety function or group of safety functions. (For example, a finite state machine is a set of digital logic circuits that can be It can be in one of several states, only one at a time, and this is called the current state. It is called a state transition, and is initiated by a trigger event such as a state transition or a set of states. (It can change from one state to another). As another example, communication within the MPS 200 may be performed using a deterministic protocol. and all safety data is communicated via redundant communication paths. As such, the versatility attribute of the MPS200 allows for the development of additional systems based on completely different platforms. It can be designed to be architecture specific without adding system complexity.
[0153] For example, FIGS. 4A-4B show exemplary charts 400 and 450, respectively. Charts 400 and 450 show that the multi-tier diversity strategy implemented within MPS 200 Demonstrate how to mitigate common cause failures based on hardware or software logic. Ports 400 and 450 are used to determine whether the multi-layer diversity strategy implemented within MPS 200 is a For example, questions to the CCF based on software or software logic within the MPS200 In these examples, transient events are shown to be a significant problem in nuclear systems. As shown, two different process parameters, A1 and A1 and A2 are measured (for example, via sensors 202a-202d). A2 in the figure is pressure.
[0154]
[0154] Different process measurements A1 and A2 are inputs to two different safety function algorithms. The two safety function algorithms are (A1) high temperature and (A2) high pressure as shown. Each algorithm is located in a separate and independent SFM within the isolation group. uses two different sets of programmable digital hardware (A / C and B / D) This can be done by dividing the four separation groups (A, B, For example, here the two safety functions are ,contains a single set of safety functions.,Each set (e.g., consisting of two safety function,algorithms) can be based on different technologies.
[0155] Design diversity can also occur due to different design teams using different sets of design tools. Each set of programmable digital hardware can be designed, allowing for As an example, the safety function(s) may be implemented within a microprocessor. In this example, the safety function(s) can be evaluated sequentially, but In some embodiments, the sequential operation of the processing loop may be used to perform one safety function (e.g., 2) A dependency on another safety function (e.g., A1) can be introduced. As a safety function, the safety functions are implemented using a state-based field programmable gate array (FPGA). In this example, each safety function can be implemented independently of all other safety functions. In this latter example, the effect of one safety function on another can be evaluated. By removing any dependencies in the process, increased independence can be ensured. do.
[0156]
[0156] The multi-layer diversity for the loss of water transient example is a set of software CCFs (A / CCF disables protective measures by limiting them to specific safety functions (A1) In some embodiments, the software CCF provides two safety features: Functional independence between functions and the safety function algorithms are based on process measurements used as inputs In some embodiments, the software CCF is limited to certain security functions based on the Incorporating different programmable hardware, design teams, and design tools into the suite By doing so, the CCF is limited to a set of specific safety functions. If limited, the transient event may disrupt the safety function (A1) of the other set (B / D) or both sets (A / C and B / D) is mitigated by the second safety feature (A2).
[0157] For example, as shown in FIG. 4A, all four separation groups (A, B, C, D ) (e.g., indicated by a check mark) The output of the safety function to A1 indicates that a protective action (e.g., indicated by a "trip") As shown in Figure 4B, two divisions in a single division for safety function A1 are started. Even in one group, if there are CCFs in two separate groups (A and C), Positive indications of protective measures within the outlying groups (B and D) still trigger protective measures. (the two-out-of-four method described above). On the other hand, CCFs in Groups A and C are not considered to be safety functions due to independent evaluation of each SFM. It will not spread to A2.
[0158]
[0158] Figure 5 shows a safety function module of an MPS of an I&C system for a nuclear power system. Figure 6 shows a block diagram of the (SFM) 500. FIG. 7 shows a block diagram of the communication module (CM) 600 of the MPS. The I&C system for the MPS's Equipment Interface Module (EIM) 700 FIG. 8 (discussed below) illustrates a chassis (e.g., one or more SFMs) 5 shows the communication paths within the mechanical structure interconnecting the CM 500, CM 600, and EIM 700. Generally, the illustrated modules are interconnected within a chassis (represented by chassis 800, described below). The Joule 500, 600, and 700 implement the safety functions of the MPS200 and are A level module (e.g., signal conditioners 204a-204d, trip decision 208a ~208d), RTS level modules (e.g., RTS voting 214 / 216), and Constructing ESFAS level modules (e.g. ESFAS Voting 212 / 218). In some embodiments, there are three types of modules (500, 600, and 700). This minimizes the number of line replaceable units and therefore obsolescence. Furthermore, these modules (500, 600, and 700) can be used in conjunction with any individual A single failure in a module (500, 600, and 700) can cause damage to other modules or other safety In addition, the function can be made functionally independent so that it does not affect other functions. The combination of modules (500, 600, and 700) that are applied Routes can be provided.
[0159] In some embodiments, the modules (500, 600, and 700) are functionally non- It may have one or more characteristics that at least partially define the dependency. For example, each module is a part of the overall system / architecture (e.g., MPS200). Within a module, modules can be completely autonomous with respect to each other. Each module performs a specific intended safety function within the overall system / architecture. As yet another example, a module can execute autonomously with respect to each Each module may contain dedicated logic that is specific to the particular intended safety function of the module. Thus, each functionally independent module cannot share logic or functionality with any other module. The specific intended safety function can be accomplished independently of the system's functionality.
[0160]
[0160] Referring to Figure 5, the SFM 500 receives sensor inputs from other SFMs as shown. The output or data is processed to identify the separation group (e.g., separation Make a decision to trip the reactor and / or activate the ESF for Group A, B, C, or D The SFM 500 (1) provides safety data bus communication and reactor trip and / or ESF (2) reactor trip determination and / or ESF activation determination It can be used in two separate configurations: secure data bus communication via
[0161] As shown, the SFM 500 generally comprises an input block 504, a functional logic block 506, Each input block 512 includes a communication block 514, 516, and 518. 04 (four are shown in FIG. 5) are signal conditioning circuits 506, analog-to-digital (A / D) converters; Each input block 504 is made up of a sensor, a converter 508, and a serial interface 510. 502 (which may be the same as or similar to sensors 202a-202d, for example). As shown, each SFM 500 can connect up to four input blocks 5 04 (in the illustrated exemplary embodiment). The input type is SFM5 00 makes trip or ESF operation judgments including permissive and interlock generation. Any combination of analog and digital signals (e.g., 4 to 20 mA, 10 to 50 mA, 0 to 10 V).
[0162]
[0162] The functional logic block 512 is a block of the SFM 500 that is connected to the input block 504 (used A programmable logic circuit converts the output from the serial interface 510 (if used) to engineering units. The functional logic block 512 also receives the output of the input block 504 (e.g., , sensor measurements from the sensor 502) and / or information from the safety data bus. The functional logic block 512 can also perform the trip and / or ESF activation determination. , permissive and control interlocks can be created. The processing block 512 uses information obtained from the input block 504 and / or the safety data bus. The system includes multiple deterministic logic engines that determine whether to trip or activate the ESF.
[0163] The set points and other adjustable information utilized by functional logic block 512 are , can be stored in non-volatile memory (e.g., on the SFM 500). This allows for changes without modifying the underlying logic. To implement software diversity, primary and secondary The functions and auxiliary functions are not located on the same SFM 500. Therefore, Use a dedicated SFM 500 for the function, with the primary and auxiliary functions on separate modules 500 By ensuring that each module 500 has unique logic and algorithms, This limits the impact of software CCF.
[0164]
[0164] The communications block 514 / 516 / 518 has five separate communications ports (e.g., Three secure data ports labeled 514, one port labeled 516, and one port labeled 518 Each port can be functionally independent. a monitoring and indicator (M / I) bus (e.g., block 516), a maintenance workstation, a mobile workstation (MWS) bus (e.g., block 518), or a safety bus (e.g., block 5 Each safety data bus 514 can communicate the same data, but Each communication port is asynchronous and uses a different, independent, and unique communication engine. For example, one safety data Bus 514 may transmit, for example, 10 packets of data sequentially (e.g., 1, . . . , 10 ), and another safety bus 514 can transmit the same 10 packets in the reverse order (e.g. , 10, 9, .., 1), and the third safety bus 514 transmits even packets first. followed by an odd number of packets (e.g., 2, 4, ..10, 1, 3, . 9). This triple module redundancy and diversity not only allows for communication error detection, but also rather, the ability of the RTS or ESFAS to make accurate trip and / or actuation decisions. Restricting communication CCFs to specific buses without affecting the
[0165]
[0165] Referring to Figure 6, the CM600 is a management system for an I&C system for a nuclear power system. Interconnection at the separation group level of PS (e.g., MPS200), and RTS level In connection and ESFAS level interconnection, Provides independent and redundant communication between other modules in the MPS. For example, the CM600 , a pipeline for passing data through the MPS, and the sequence of such data passing. The CM 600 can be a scheduler. In the illustrated embodiment of CM 600, the movement / passage of data within the Restricted Communication Block (RCB) 604, Communication Scheduler 606, and Communication Block There are three types of blocks: 608 / 610.
[0166]
[0166] The RCB 604 consists of four communication ports as shown. Each port can be configured as a different unidirectional path (for example, receive-only or transmit-only). In some embodiments, such as the illustrated CM600, a specific R Information received from or sent to CB 604 is passed through optical isolator 602 In some cases, the optical isolator 602 may be configured to separate the data from any particular trip decision from other trip decisions. Helps ensure trip decision data is isolated, providing independent redundancy You can be sure.
[0167]
[0167] The communication scheduler 606 schedules communication between the communication blocks 608 / 610 and the RCB 604. In some aspects, the communications engine 606 is responsible for moving data between the interconnections described. programmable logic, such as an FPGA, programmed to schedule communication between the It consists of a microprocessor or other discrete logic.
[0168]
[0168] The communication block 608 / 610 has four separate communication ports (e.g., 608 and Each port has three secure data ports marked 610. The ports can be functionally independent and are connected to a monitoring and indicator (M / I) bus (e.g. , block 610) or a secure data bus (e.g., block 608). In some embodiments, the M / I bus 610 connects all modules (e.g., modules) in the MPS. information from the modules 500, 600, and 700, including the status of each such module. This information can be collected and sent to a "historian" station (e.g., the MPS (a dedicated calculation system for historical data).
[0169]
[0169] Each secure data bus 608 can communicate the same data, but each communication port The data is packaged and transmitted separately as described above with reference to bus 514. Depending on the application of the communication module, the four communication blocks 608 / 610 can be unidirectional and Any combination of bidirectional paths can be configured.
[0170]
[0170] Referring to Figure 7, the EIM 700 generally votes on trip decisions and In order to operate and operate the levels, the elements within the RTS and / or ESFAS level systems It provides an interface to each component in the power system. As shown, the EIM 700 output block 720, instrument feedback block 718, 1E manual input 716, non 1E Manual Input 714, Voting Engine 722, Priority Logic Block 721, Equipment Control Block 723, and communication blocks 724 / 726 / 728. The failure of one component may affect the MPS (e.g., M PS200) channel level interconnection, RTS level interconnection, and ESFAS level Voting based on trip signals to ensure no spillover within the Bell interconnection , possibly double voting (e.g., two-out-of-three voting for communication and The EIM700 can perform two-out-of-four voting for the for voting 722, manual actuation / 1E input 716, and automatic signals from non-1E input 714 Priority allocation can be implemented.
[0171]
[0171] The output block 720 may have up to three independent output switches, as shown, or In some cases, these output switches may be used in external circuits. , and is coupled to an electrical load 702 (e.g., an actuator). This allows the EIM 700 to directly control a single component or multiple components. For example, the output block 720 can provide a start signal to the relay. Each output block energizes a power supply, which starts various pumps and opens multiple valves. The circuit 720 may also include the capability to self-test and perform load continuity checks.
[0172]
[0172] The instrument feedback block 718 receives multiple (e.g. For example, up to three, or in some examples more, feedback inputs 704. The feedback input 704 can be, for example, a valve position (e.g., fully open). , fully closed), circuit breaker state (e.g., closed / open), or other feedback from other components. The device feedback 704 may include feedback from the voting device control system discussed below. It can be used in the control block 723.
[0173]
[0173] 1E manual input block 716 may be configured to accept multiple (e.g., up to two, or in some cases A manual input signal 706 (or more) can be provided. This part of the EIM 700 may be dedicated to manual input and is utilized within the priority logic block 721.
[0174]
[0174] A plurality of input signals 708 are input to the non-1E input block via isolation interface 712. This electrical isolation interface 712 allows the priority logic block This allows the use of non-1E signals for input to the 721.
[0175]
[0175] Voting engine 722 receives trip decision input from communications block 724. The result of the vote is to provide an activation or deactivation signal to the priority logic block 721 for the automatic activation signal. In some aspects, the voting engine 722 may be configured to detect the failure of a single component within the MPS. To ensure that the results are not transmitted, a voting system, possibly a double voting system, should be implemented. For example, in some aspects, the voting engine 722 may communicate with the communication block 72 4 receives the trip decision. Each communication block 724 has four channels or isolation groups. Trip determination (for example, trip or Within the voting engine 722, in some aspects, , three "A" trip decisions, three "B" trip decisions, three "C" trip decisions, and there can be three "D" trip decisions. Therefore, the voting engine 72 2 performs a two-out-of-three decision in each of the four channels or separation groups. At least two of the three "A" channels can be used, e.g. If the tripping status is not met, the tripping status will be In this case, the voting engine 722 will, at least initially, determine that there is a trip on channel "A." can be communicated and if only one of the three "A" channels indicates a trip, The voting engine 722 may determine that there is no trip on channel "A."
[0176]
[0176] The voting engine 722, as described above, is designed to prevent failures from propagating throughout the MPS structure. To further ensure that no votes are cast, a double voting scheme can be implemented. For example, After the two-out-of-three communication determination described above, the voting engine 722 also determines whether the trip is actually to determine whether the fault was correct (e.g., the fault did not indicate a false trip) For example, a two-out-of-four trip decision can be made. The output of the four voting blocks (e.g., three two of the voting logic gates) into another voting block (for example For example, two-of-four voting logic gates). For example, if at least two of the four outputs from a two-of-three block are tripped, If the trip indicates a trip, the voting engine 722 determines that a trip has occurred (and that the E, such as the load 702, otherwise, the voting element The engine 722 may determine that an actual trip did not occur.
[0177] The priority logic blocks are the voting block 722, the 1E manual entry block 716, and Input is received from non-1E manual input block 714. Priority logic block 721 then: Based on all the inputs, it makes a decision on what to command the Equipment Control Module to do. conduct.
[0178] The device control block receives commands from the priority logic module and outputs them to the output block. The equipment control block performs the appropriate action or operation on the component via block 720. For instrument control purposes, feedback is received from the instrument via instrument feedback block 718. Receive the request.
[0179]
[0179] The device control block 722, the priority logic block 721, and the voting block 722 Each sends status information to a maintenance workstation (MWS) bus (e.g., block 728). The communication blocks 724 / 726 / 728 provide five separate communication ports (for example, For example, there are three secure data ports labeled 724, one port labeled 726, and one port labeled 727. Each port is functionally independent. and monitoring and indicator (M / I) buses (e.g., block 726), maintenance workstations, and a Mobile Workstation (MWS) bus (e.g., block 728), or a secure data bus (e.g., , block 724).
[0180]
[0180] FIG. 8 shows a system for communicating one or more SFMs 500, EIMs 700, and CMs 600. 1 is an exemplary diagram of a chassis 800 for a nuclear reactor protection system (e.g., MPS145) that is coupled to the This figure shows three CMs 600 connected to four CMs 600 in a chassis 800. An example of an SFM 500 or EIM 700 is provided. In this example, five data bus paths are For example, three secure data ports 802 are shown, labeled X, Y, and Z, respectively. One data bus path 804 is labeled M / I. Each data bus path 802 / 804 is represented as MWS. In this example, all other data bus paths 802 / 804 within the chassis 800 are functionally independent. and electrically independent.
[0181] In this illustrated embodiment, the CMs 600 each have a data bus path 802 / 804 As shown, the master of the X data bus path 802 Data 808 is part of the CM 600 for safety data X. Master 810 is CM 600 for safety data Y. Master 81 of Z data path 802 2 is CM600 for safety data Z. Finally, as shown in this example, The master 814 for the data path 804 is the CM 600 for the M / I. Similarly, the MWS Master 816 may be connected separately (e.g., as a maintenance workstation). ) is the master of the MWS data path 806. The power supply 816 can be disconnected from the normal operation of the equipment by a hardwired switch. Cut.
[0182]
[0182] Figures 9A to 9C show one or more of SFM500, CM600, and EIM700. Figure 1 shows a block diagram of the interconnection of multiple isolation groups, RTS, and ESFAS levels. Generally, the modules SFM500, CM600, and EIM700 have a single-failure (e.g., hardware, software, or other) to adjacent or other safety features Provide protection from spillover, e.g., functionally independent modules (e.g., Constitutes an identifiable device, instrument, or equipment that can be disconnected and removed as a unit definable performance that can be replaced with spare parts and tested as a unit (assembly of interconnected components having the same characteristics) to be placed within the MPS200. These modules may, in some embodiments, provide trip sensing and decision making. The module can also provide up to three-way redundancy for configuration. so that it can be arranged to provide redundant RTS and ESFAS voting divisions. In some embodiments, the module may include a trip component (e.g., a circuit breaker, A separate trip voting module can be provided for each trip node (sensor, or otherwise).
[0183] In some cases, the module provides RTS voting, and in other cases, the module provides ESF voting. Provides AS voting. For the independence of each module, each module is Specific trip components as to whether or not to initiate a FAS trip. Makes decisions for specific trip components separately from all other modules dedicated to that In some embodiments, the determination of valid communication for trip determination is based on a majority vote. (e.g., two out of three). These decisions can be made using a double voting system, and trip decision communication is done by majority vote ( For example, two of three (e.g., two of three) are certified, and the secondary trip decision vote is determined by a majority vote. Smaller (for example, two of four).
[0184]
[0184] Referring to Figure 9A, an exemplary isolation group level interconnect 900 is shown. The illustrated channel level interconnect 900 includes a channel sensor input 902 and an input 903. 902 and CM 600 which communicates output 904 through 920. As shown, channel-level Each SFM 500 in the interconnect 900 can handle four signals, in any combination of analog and digital. Each input 902 may include a specific The SFM500 can be unique (e.g., the Channel A compressor pressure signal is 1 (Direct input to only one SFM500) Status information (e.g., alarms, logic decisions, monitors) Input data, including module state, may be made available on all four data buses. can.
[0185]
[0185] The safety buses may be functionally independent, and each safety bus may be It uses a master-slave protocol with 0 as the master. The blocks in the SFM are synchronized. The CM6 bus operates in parallel with the PLC, but communication between modules can be asynchronous. When a 00 requests information from a specific SFM 500, the SFM 500 broadcasts the information to the bus. The benefit of broadcast communication is that it can be responded to by a broadcast message, for example, by SFM50, which is written as "1". 0 indicates the information required by the SFM 500 (e.g., permission If the SFM500 has the required information (e.g., sensor input value), the SFM500 "2" will You can wait and get it.
[0186]
[0186] In addition to the three safety data buses (e.g., labeled "X," "Y," and "Z") A fourth communication bus for monitoring and indication (M / I) is shown. The data is provided by a dedicated C / P server that provides M / I data to the safety gateway and non-safety control systems. M600. Three safety data buses (e.g., buses X, Y, and Z) Unlike the CM600 for M / I, the CM600 for M / I transmits information on all three safety buses. It is possible to listen for broadcast of the information.
[0187] In some embodiments, the restricted communications block (RCB) of the CM 600 includes: It can have a variety of point-to-point configurations. In 900, all four communication ports on the RCB can be configured for transmission only. From each safety data bus CM600 (for example, CM600s designated X, Y, and Z) Data are collected from each division of the RTS and ESFAS (e.g. Divisions I and II) ) can be sent to the M / I CM600. 0) can be sent to the safety gateway and the unsafe control system.
[0188]
[0188] The outputs 904 to 914 are, for example, interconnections at the RTS and ESFAS levels (later For example, as shown, outputs 904, 908, and 91 2 can be provided to the ESFAS level interconnection, with outputs 906, 910, and 9 14 can be provided to the RTS level interconnect. Although only a top-level interconnect 900 is shown, multiple interconnects 900 having an MPS structure may be used. 00 can be set.
[0189]
[0189] Referring to Figure 9B, an exemplary RTS level interconnection divided into divisions is shown. The RTS level interconnection is shown in the diagram, along with the RTS Division I and II (e.g., RTS votes 214 and 216). 14 and 216) includes four CM600 and four EIM700. For each of the three safety data buses (denoted X, Y, and Z), inputs 962 to 972 are Receive a trip or no trip decision from all four isolation groups shown as (For example, separate groups can be denoted by the same number, i.e., A1 and B1. The fourth CM600 transmits data (as outputs 974-976) to the unsecured It can be provided for transmission to a control system and a safety gateway.
[0190]
[0190] Each communication port on the RCB for each safety bus CM600 is configured as "receive only." The M / I CM600 can be configured as a It is possible to have all ports in the RCB configured as "transmit only."
[0191] In some embodiments, the number of secure data buses from all isolation groups is Tripping decisions are available for each of the four EIM700s. All three safety buses (labeled X, Y, and Z) are used to simulate a circuit breaker failure due to a communication error. It is possible to ensure that there is no similar operation. Four separate groups (inputs 962 to 972) ) indicates a tripped state, the reactor trip breaker is opened. Each EIM 700 may be used to, for example, control the undervoltage relay and shunt trip relay of a reactor trip breaker. In addition to automatic operation, the EIM600 can also be used with manual dial Vision level reactor trip 978, circuit breaker feedback, and ESFAS feedback The input for feedback is
[0192]
[0192] EIM600 output (980a-980d for Division I, The elements associated with a particular division (982a-982d for IV) The input to the trip coil of the reactor trip breaker (RTB) (shown in Figure 2B) It is possible.
[0193]
[0193] Referring to Figure 9C, an exemplary ESFAS level profile divided into divisions is shown. The interconnections at the ESFAS level are shown in the figure. Division I and II (e.g., ESFAS Votes 212 and 218). Divisions (212 and 218) include four CM600s and four EIM700s. For each division, three safety data buses (labeled X, Y, and Z) each have an input From all the separated groups denoted as 962 to 972 (in this example, the four denoted as D) Receive ESF activation determination from the
[0194]
[0194] Each communication in the RCB for each safety data bus CM600 (labeled X, Y, and Z) The transmit ports can be configured as "receive only" and can be optically isolated (see above). The M / I CM600 has all ports in the RCB configured as "transmit only". These ports can be optically isolated as well.
[0195] In some embodiments, the ESF activation decisions from all separation groups are All three safety data buses (designated X, Y, and Z) are available to the EIM700. For example, the EIM700 ensures that spurious equipment operation is not caused by communication errors. All three safety data buses can be used to ensure At least two of the isolation groups indicate the need for ESF activation (e.g., input 96 2 to 972 above), output 990 (ESF based on division as shown in Figure 3B) Initiating a safety function(s) via the safety function(s) connected to the devices 224 and 226 In some embodiments, each EIM 700 may be implemented as an individual component (e.g., a single It can be dedicated to a single ESF component.
[0196] Aside from automatic initiation, each EIM 700 can also be configured to use manual input 992 to Additionally, each EIM 700 also receives non-IE control inputs 994. The non-1E control input 994 (also shown as input 282 in FIG. 3B) can provides to the EIM 700 to control the 1E safety ESF components on the output of the EIM Component feedback (e.g., limit switches), voting decisions, and and other available information (e.g., alarms) are output from the M / I CM600 via outputs 974-977. It can be transmitted as 6.
[0197]
[0197] Figure 10 shows a diversity analysis diagram for the I&C system 135 of a nuclear system. For the purposes of diversity analysis, the blocks identified in Figure 10 simplify system exploration. Represents a level of detail. Blocks can determine whether internal failures propagate to other blocks based on their attributes. selected to represent the physical subset of equipment and software that is not likely to be .
[0198] As shown, the blocks in FIG. 10 are connected to an I&C system, in this example, Block 1002 represents non-IE monitoring and marking equipment, and block 100 4a / b represent 1E monitoring and indication I and II, respectively, and blocks 1006a / b represent Block 1006a represents safety blocks I and II, respectively. Block 1006b represents isolation groups A and C. , RTS I, and ESFAS I; block 1006b includes separation groups B and and D, RTS II, and ESFAS II. Block 1008 represents the MCS. As shown, connecting lines with arrows indicate communication between blocks.
[0199]
[0199] One of the goals for the four tiers is diversity. For example, MPS is a single-factor The failure criteria can be met, which are: (1) all identifiable but undetectable faults; (2) a single detectable fault in a safety system occurring simultaneously with a fault; (3) all failures that result in a design basis event requiring the safety function; or all failures and pseudo-errors caused by design basis events requiring the safety function. In the presence of system operation, the MPS performs all safety functions required for design basis events. This requirement may provide increased reliability. However, this does not prevent the system from being vulnerable to common cause failures (CCF). There may be dependencies (e.g., coupling coefficients) on This distinguishes the failure from multiple independent failures, thereby reducing or eliminating the causal effect. common cause failures in a system, increasing the system's ability to withstand their effects. Two basic forms of prevention are obtained:
[0200]
[0200] These two types of embodiments have the advantages of design versatility, equipment versatility, It is implemented in six attributes: functional diversity, human diversity, signal diversity, and software diversity. The application of these attributes can be performed for each block shown in Figure 10 and The attributes between the blocks shown are examined.
[0201]
[0201] Attributes in a block
[0202]
[0202] As shown and described with reference to the figures, separation groups A, B, C, and D, and The two divisions, RTS and ESFAS, are based on programmable technology. Therefore, they are grouped together. Safety Blocks I and II are both part of the modular protection system ( Configure the MPS (for example, MPS200).
[0203]
[0203] Regarding signal diversity, for a given transient event, there must be at least two safety functions. Each safety function can be triggered by a different physical action (e.g. pressure, level, temperature, The loss of one safety function is based on the measured variable(s) of the block. This does not prevent the identification of the need for protective measures.
[0204] Regarding software diversity, based on the input, each safety function module (S Each SFM (FM500) is dedicated to one safety function or group of safety functions. Each communication module (CM600) has a unique algorithm / logic. The information of the packets is transmitted in a different order, which includes the communication engines (608 / 610) in the CM. It may be necessary for each device interface module to have different algorithms. The module (EIM700) can be dedicated to a single component, resulting in a unique You can get the algorithm / logic.
[0205]
[0205] 1E monitoring and display consists of two components: a video display unit (VDU) and a physical switch. This can be achieved using the divisions. John can be block 1004a / b. For design diversity, M / I Each division must provide plant status information to operators on digital displays. and have a manual switch to manually initiate any protective action at the division level. For signal diversity, the operator must have all the measured variables. These variables can be used to determine if a trip and / or ESF operation is required. It is used by the MPS to make the same decisions as the MPS, although it is not as fast. To do this, one can have multiple measured variables of different physical effects.
[0206]
[0206] Diversity attributes between blocks
[0207]
[0207] With regard to human diversity, the software of Safety Block I and 1E M / II Safety Block II and 1E M / II can be designed by one design team. I can be designed by different design teams. In addition, independent verification and certification The team can inspect the work of each design team to ensure accuracy of the design. The design team is also assigned to the modular control system (MCS) and non-1E M / I. This is different from the team that was selected.
[0208]
[0208] Design diversity is the combination of software and hardware to solve the same or similar problems. The key to limiting the potential and outcomes of CCF is to use different methods, including both To achieve this, the safety block I 1004a and the 1EM / II block 1006a are Block II and 1E M / I II can use different programmable technology. MCS and non-1E M / I can also have different programmable technologies. Along with the other attributes discussed above, different hardware designs have different failure modes. This reduces the chances that a CCF affects more than one block. For example, except for the M / I block, the blocks can be physically located in different rooms. This allows for the situation where multiple components are involved in a CCF event to be effectively separated. The intention is to further reduce the coupling coefficient that may result.
[0209]
[0209] Software diversity is a subset of design diversity, achieving the same safety goal. Therefore, different projects are designed and implemented by different development groups with different key personnel. The design versatility discussed above allows for different design options. Design teams can use different design tools, and these tools can therefore No failure modes are introduced.
[0210]
[0210] Functional diversity is introduced by having different purposes and functions among the blocks. Safety blocks I and II form the MPS. These blocks are: If the operational limits are exceeded, a reactor trip can be initiated, and the ESF can be initiated to The M / I block allows the operator to identify both safe and unsafe situations. It is possible to monitor and control the system. The operator can operate the plant. The MCS can maintain the situation within the limits or initiate necessary protective measures. To keep the plant within its operating limits, including suppressing certain operating transients Provides automatic control of the system.
[0211]
[0211] By having automatic and manual means of actuation and protection measures, Signal diversity can be provided. MCS and non-1E M / I are controlled at the equipment level. The 1E M / I block provides control at the division level.
[0212]
[0212] Equipment diversity is the use of different equipment to perform similar safety functions. Initiation of the protective action may be by operator action using a switch, or This can be done automatically by Safety Block I or II. Different programmable technologies can be used between the NI 9110 and NI 9110, including different internal sub-systems. Components and different manufacturing methods may be required.
[0213] Another analysis guideline for the four levels is system failure type. Type 1 failures are: Plant transients initiated by control system errors due to interactions between defense layers. This is typically a failure of a common sensor or are associated with the fault of the signal source. Some of these signals are provided to the MCS for normal plant control. As mentioned above, one signal Rather than providing a source of information, all four separate groups and both ESFAS and RTS Each division provides information via isolated one-way communication. Different ways for S to select which redundant independent signal sources to use (e.g., intermediate value signals) It may be possible to use the
[0214]
[0214] Type 2 faults do not directly cause transient changes, but rather are caused by undetected faults in the protective equipment. It does not respond to plant transients due to faults. By using the attributes between all blocks I and II, it is possible to detect two or more undetected faults or CCFs. You can get enough diversity to prevent it from affecting the other blocks. If only one of the blocks is required to automatically initiate a protective measure, Type 2 failures can be mitigated by the MPS (Safety Blocks I and II) without additional systems. This can be done.
[0215]
[0215] A Type 3 failure occurs when the primary sensor relied upon to detect a design basis event reads abnormally. By providing at least two safety functions, the safety barrier Signal diversity is available within the lock, and each safety function responds differently to any transient event. Based on the measured parameters, all four isolation groups of sensors for a given safety function If the loop provides an abnormal reading, then for a Type 3 fault, 1) the abnormal reading , indicating that no trip or ESF operation is required when the limit is actually exceeded, and 2) abnormal readings do not exceed limits but require a trip or ESF operation. Two possible adverse scenarios are indicated (e.g., spurious trip or ESF operation). In the first scenario, the CCF and the simultaneous occurrence type in the safety block 3. Failures cannot prevent the initiation of the necessary protective action(s). Signal diversity can enable separate safety features to mitigate transient events. The CCF in the MPS is restricted to one of two safety blocks, and the opening of protective measures It is considered that the initiation is prevented or prevented by false indications. For example, as discussed above, Two-out-of-four coincidence logic may be used for all trips and ESF activations. This allows four safety blocks to be configured for the unaffected safety functions on the unaffected safety blocks. Two of the isolation groups indicate the need for tripping or ESF operation and are actuated. This is meant to provide a positive indication to the operator of the action being taken.
[0216] In the second scenario, a Type 3 fault occurs simultaneously with a CCF in the safety block. , resulting in a false trip or ESF operation, and the 1E M / I block has one positive and one negative Either one false indication of successful operation or one positive indication but no indication of operation. In this case, it may take the operator longer to evaluate and correct the spurious actuation. The ability to realign the necessary components should not be affected by the same CCF. Both ESF and non-ESF controls are provided. Pseudo-ESF operation is the most limited in this scenario. It can be considered a constant phenomenon.
[0217] Another analysis guideline is hierarchy requirements. A hierarchy is a set of levels of detail that simplify system investigation. To provide a lock, the four conceptual layers of defense are combined in several blocks. not only be integrated into the system (e.g. RTS and ESFAS), but also into separate blocks (e.g. In some embodiments, the total blocks are divided into blocks I and II, 1E M / II and II. , Separation Group, RTS, and ESFAS are based on programmable technology. For example, each half of the MPS (for example, four Two of the separate groups, one of the two divisions of ESFAS, and one of the RTS One of the two divisions or one safety block has sufficient diversity attributes. Different programs can be implemented based on different programmable technologies (design and device variability). Different design teams (human diversity) using programmable digital hardware The M / I hierarchy also requires the use of separate blocks of design tools (software diversity). 1E M / I block can be divided into blocks similar to safety blocks. It can be identified that the selected blocks have a diversity attribute of 4. The three layers of defense are illustrated in FIG. 11, which shows a diagram 1100.
[0218] Another analytical guideline is the evaluation method. The selected blocks are then evaluated as "black boxes." " and therefore any certain failure that needs to be assumed The force signal will produce the most unfavorable results as analyzed according to the guidelines (discussed above). In some embodiments, the system may identify and correct conditions resulting from CCFs, particularly in automated safety systems. When analyzing the time required to respond to this, the inability of the system to operate is It may not be a worst case failure. The block is a hardware CCF and a software For each CCF, this block is evaluated as follows: 1) 2) Functions that are malfunctioning due to false indications or without the necessary measures, or 3) Functions that are malfunctioning due to indications of successful operation and 3) simulated initiation of a function(s) without indication of successful operation. This gives three possible outputs that may result in the most undesirable outcome. None of the EIMs in the locking mechanism are considered vulnerable to software CCF. For example, the EIM may not have a priority dedicated to a single ESF component or reactor trip breaker. It can be a logic module and interfaces with manual and automatic controls. Using a state machine, all possible inputs, device states, and outputs of the state machine can be calculated. Its testability, EIM diversity attribute, EIM is software or software theory that is dedicated to a single component based on its nature. It can be simple enough that theoretical considerations of CCF are not required.
[0219] Another analysis guideline is the assumed common cause failure of the block. The block consists of a video display unit (digital hardware) and manual controls (non-digital hardware). VDUs can be designed specifically for display purposes and have the ability to control equipment. The manual controls in each 1E M / I block 1004a / b are safety blocks. Initiating any protective measures automatically implemented by Division I or II at the Division level In some instances, the indicators and manual controls may be different hardware. (e.g. digital and open / close contact switch), the CCF should be It can be thought of as affecting one or the other. Both software and hardware In the case of a CCF, the result of the failure is one division of the operator display. indicates a false safe operating state or a failure of one division of the manual switch. , have little or no control capabilities and therefore provide pseudo-actuation However, the software CCF allows the VDU to initiate pseudo-protective measures. This may provide false indications of successful operation or inaccurate plant status.
[0220]
[0220] Except for the EIM, the modules in the safety block have software CCFs. Due to the diversity attribute within the safety block, the software CCF is assumed to be The SFM can be restricted to a CM or function(s) to make appropriate trip decisions. The software CCF in a safety block prevents the equipment, signals, and It can be mitigated by software diversity. For each transient event, the mitigation event The primary and secondary safety functions required to Based on the data, different logic / algorithms can be used to implement different safety functions. It has triple modular redundancy, with each data bus transmitting the same information in a different way. In this embodiment, a CM with a software CCF may initiate a pseudo or protective action. As a result, the most unfavourable scenario is that the ESF It becomes a software CCF within the SFM that provides pseudo-operation of the AS function.
[0221]
[0221] The hardware CCF in the safety block detects and It can be assumed that the ESF function is a complete failure that cannot be initiated. Hardware CCFs that cause a false start-up have the same effect as software CCFs. This may have adverse effects and therefore should not be repeated for hardware CCFs. .
[0222] Non-1E M / I includes controls for safe and unsafe equipment. DU is different from that used by 1E M / I. Non-1E M / I uses non-1E M / I subsystems (e.g., turbine control, Any spurious actuation induced by software or hardware CCF within the are immediately identifiable and, if the operating limits are exceeded, the MPS (Safety Block I and I The expected failures for non-1E can be mitigated by 1) the success of the operation 1) Simulated operation of components of a subsystem, whether labeled or not, and 2) equipment that is actually operating. The failure is due to the indication of successful operation when not in motion.
[0223]
[0223] The MCS must be able to perform day-to-day plant maintenance within operating limits, including the suppression of certain operational transients. This includes unsafe systems that are relied upon to maintain system operation. Any failure of the control rods can be detected immediately by the operator. Assumed software and hardware CCF for MCS as well as 1E M / I 1) simulated actuation of a subsystem component with or without indication of successful actuation; and 2) ) Failure of normal conditions by providing an indication of successful operation when the equipment is not actually operating. results.
[0224] Another analytical strategy is to use the same hardware and software modules. Here, the diversity between blocks provides a basis for not considering the blocks to be identical. On this basis, the envisaged CCF can be limited to a single block.
[0225] Another analysis guideline is the influence of other blocks. Every block has a certain degree of accuracy or inaccuracy. It is believed that each block functions correctly in response to the correct input. It is not expected to be affected by the assumed CCF in the block.
[0226] Another analytical guideline is the output signal. In some embodiments, the I&C architecture can prevent errors from propagating backward into the output of previous blocks. All information from Blocks I and II to 1EM / I is transmitted via optically isolated, dedicated transmission lines. 1E M / I to safety block The signal to the lock can be an open or closed contact from a manual switch, and these positions or The contact state is not changed by the CCF in the safety block. The signal was transferred from Separate Groups A and C to Division II of the ESFAS and RTS, and to the Separate Data sent from Groups B and D to ESFAS and RTS Division I The four separate groups are independent and redundant, but for the purposes of the example in Figure 10 These isolation groups are then organized into safety blocks according to the programmable technology used. Similar to the communication between the safety block and the 1E M / I, Communications from the RTS and ESFAS divisions shall be transmitted via optically isolated transmission lines. This is done through a dedicated communication engine. Unsafe inputs to safety blocks are transmitted via the ESF AS EIM, which can be limited to isolated make and break contacts do.
[0227]
[0227] All inputs from the safety block are optically isolated and transmitted through a dedicated communication engine. This allows any error in the 1E M / I to trigger a safety block. This can prevent the problem from spreading backward to other networks.
[0228] Another analysis guideline is the diversity of anticipated operational events. A CCF or Type 2 failure of the MPS will not prevent it from performing its safety function. Safety blocks I and II that make up the MPS are designed to limit the CCF to one block. Conventionally, nuclear plants have been able to select the MPS when it is disabled by the CCF. Diverse Actuation Systems (DAS) or The Scrum Failure Event (ATWS) system has been relied upon. However, in the MPS design shown Therefore, there is sufficient diversity in the system for a single CCF to initiate the safety function. Here, the MPS is divided into safety blocks I and II (e.g., 1006a / b). The assumed software or hardware CCF is restricted to one safety block. Each block should be limited to the use of different design tools (software diversity). Different programmable digital hardware is required based on different programmable technologies. Use different design teams (people diversity) that utilize software (design and equipment diversity). Within each block, the measured variables are those of different physical processes carried out on separate SFMs. There can be at least two safety functions based on (or) The process can be implemented within a finite state machine and all safety data is communicated deterministically. These attributes allow for Type 3 failures associated with CCFs to be avoided without the need for MPS. cannot prevent the initiation of necessary protective measures.
[0229] Another analytical guideline is accident diversity. Similar to AOO, CC in MPS A possible accident related to an F error would prevent the MPS from performing its safety function. cannot be done.
[0230] Another analytical guideline is manual operator actions. Division level manual actuation can be provided to the operator. Control of the device may be passed to the operator using a non-1E M / I if permitted by the 1E M / I. Provided.
[0231]
[0231] Figure 12 shows another exemplary MPS1200 safety architecture for a nuclear system. 2A and 2B show schematic diagrams of embodiments. The MPS 120 shown in FIG. 0 is a group of four separate sensors and detectors (e.g., sensors 1202a-1202d). and four signal conditioning and signal conditioners (e.g., signal conditioners 1204a-1204d). Two separate groups and tripping decisions (e.g., tripping decisions 1208a-1208d) Four separate groups of RTS votes and reactor trip interrupters (e.g., division Two divisions (RTS Vote 1214 in Division I and RTS Vote 1216 in Division II) John and the Engineered Safety Facility Actuation System (ESFAS) and the Engineered Safety Facility (ESF) ) equipment (e.g., Division I ESFAS Voting 1212 and ESF Equipment 1224, and two data sets in Division II (ESFAS Ballot 1218 and ESF Equipment 1226). This includes the division.
[0232] Generally, sensors 1202a-1202d measure pressure, temperature, level, fluid flow rate, and It includes process sensors responsible for measuring different process parameters such as temperature and neutron flux. Thus, each process parameter of the nuclear system 150 is measured using a different sensor. are processed by different algorithms executed by different logic engines. In some embodiments, the neutron flux sensors measure the reactor power from shutdown to 120 percent of full power. The MPS1200 is responsible for measuring the neutron flux from the core. Three types of neutron flux detectors can be used, including power areas.
[0233] Generally, the signal conditioners 1204a-1204d are connected to the sensors 1202a-1202d. In some embodiments, the system receives measurements from the sensor, processes these measurements, and provides an output. The interconnection of the sensors 1202a-1202d to the signal conditioners 1204a-1204d is performed by dedicated The signal may be transmitted by copper wire or some other signal transmission method.
[0234]
[0234] As shown in Figure 21, each of the signal conditioners 1204a to 1204d has a plurality of input modules. modules 2104a-2104d (for example, any number of modules may be used depending on the number of sensor inputs) The input modules 2104a to 2104d are Conditioning, measuring, filtering, and servicing of field inputs from sensors 1202a-1202d Each input module 2104a to 2104d is responsible for sampling. digital input, 4~20mA analog input, 0~10V analog input, resistance thermal detection It can be dedicated to a specific input type, such as a temperature sensor input, or a thermocouple input.
[0235]
[0235] Each of the input modules 2104a to 2104d includes an analog circuit 2106 and a digital The analog circuit 2106 can be configured from an analog voltage or Responsible for converting electrical current into a digital representation. Analog circuits are also called signal conditioning circuits. The digital portion 2108 of each input module 2104a-2104d is The logic engine controls all input modules, sample outputs, and Bound-hold filtering, integrity check, self-test, and digital filtering The digital representation of the sensor output is provided through a serial interface in some cases. The trip decision 1208 is made by using the signal conditioners 1204a to 1204d through the output. a to 1208d. In some embodiments, the sensor output is communicated to any suitable The sensors 1202a to 1202b pass through a transmission channel (for example, optical fiber, copper wire, etc.). d to the respective signal conditioners 1204a-1204d.
[0236] FIG. 13 illustrates the split group signal adjustment and trip decision 1204a of the MPS 1200. / 1208a (e.g., separation group A) of an exemplary embodiment of a communication architecture 12 and 13, the trip determinations 1208a to 1208d are Generally, the signals are transmitted from the signal conditioners 1204a to 1204d described above via a serial interface. The trip determinations 1208a to 1208d receive the sensor input values in digital format. Each of the independent safety function modules (SFM1 to SFMn) 1300 (see FIG. 21) It consists of a safety module (described in more detail below) and a specific module performs a set of safety functions (e.g. For example, a set may include a single safety function or multiple safety functions related to a particular process parameter. For example, a set of safety functions may be configured to trip high from the same pressure input. Each SFM1 may consist of a group of functions related to a primary variable, such as low tripping and low temperature. 300 contains a unique logic engine dedicated to implementing one set of safety functions. The gate level implementation of the safety function is completely different from all other sets of safety functions.
[0237]
[0237] Sensor input values can be communicated via deterministic paths, and each trip decision These input values are then provided to a specific SFM 1300 within 208a-208d. Convert to engineering units and determine which safety function or set of safety functions is used with that specific SFM1300. It is possible to determine whether or not the trip determination 1208a to 1208d is performed. In some cases, these engineering unit values are transmitted via isolated, dedicated fiber optic connections. More specifically, trip determination is performed by providing the appropriate engineering unit value to the MIB120 8, and the MIB 1208 provides these values to the control system.
[0238]
[0238] The trip determinations 1208a to 1208d in each SFM 1300 are performed when necessary. If necessary, the reactor trip decision is made based on predetermined set points and an isolated, possibly triple redundant, A trip or non-trip request signal is sent to each RTS division via a long, transmission-only series connection. John (e.g., RTS votes 1214 and 1216 in Divisions I and II, respectively) SFM also provides ESFAS production, based on predetermined set points, when required. and activates the system via an isolated, possibly triple redundant, transmission-only series connection. or an Immobilization Request signal to each ESFAS Division (e.g., Division I and II ESFAS Votes 1212 and 1218).
[0239]
[0239] As shown in Figure 13, for example, a particular trip determination SFM 1300 is Tripping or non-tripping is performed through the switching and bypass module (SBM) 1306. Provides trip request signal to ESFAS poll 1212 / 1218. Trip decision SFM 130 0 through the scheduling and bypass module (SBM) 1306 Or provide a non-trip request signal to the RTS poll 1214 / 1216. These outputs are also generally shown in FIG. 12 as trip decisions 1208a-1208d, respectively. The outputs 1210a to 1210d are shown.
[0240]
[0240] Returning to Figure 12, for each RTS division (e.g., R TS Vote 1214 and RTS Vote 1216 for Division II) were isolated, In some embodiments, redundant (e.g., dual, triple, or other), receive-only direct via a column connection, optical fiber, or other connection, trip decision 1208a, as described above. 1208a to 1208d (separation groups A, B, C, and D) The RTS vote and logic, in an exemplary embodiment, will take necessary safeguard action. A single fault does not prevent the trip determination signal (e.g., 1210a to 1210d) from ) are arranged so that a single failure in R does not produce unnecessary safeguard activation. The TS system is a critical system for emergency core cooling and decay heat removal. Both automatic and manual initiation can be provided.
[0241] The trip inputs are combined in the RTS voting logic, resulting in trip decision 1. Two or more reactor trip inputs from 208a-1208d cause outputs 1228 and 123 0 (as appropriate for each division) to cause an automatic reactor trip output signal, and outputs 1228 and and 1230 are reactor trip interrupters (RTBs) associated with their respective divisions. ) Activate the trip coil for 1244.
[0242] In an exemplary embodiment, the ESFAS voting and logic is A single fault does not prevent operation, and a trip determination signal (e.g., 1210a to 121 0d) are arranged so that a single failure within the The ESFAS system is a critical system for emergency core cooling and decay heat removal. Both automatic and manual initiation of the stem can be provided.
[0243] Each ESFAS ballot 1212 / 1218 is isolated and in some respects redundant. via a receive-only optical fiber connection, such as duplex, triplex, or other As described above, trip determinations 1208a to 1208d (separate groups A, B, C, and D) The operating logic and voting is performed by the ESFAS voting 12 The ESFAS ballot 1212 / 1218 is required to be activated. When it is determined that the ESFAS vote 1212 / 1218 is to operate, the ESFAS vote 1212 / 1218 sends the operation request signal to the ES The ESFAS priority logic 1220 / 1222 then sends the The appropriate ESF devices 1224 and 1226 are activated.
[0244] FIG. 14 illustrates an exemplary separation group and division reactor trip system ( A schematic diagram 1400 of the RTS and ESFAS communication architecture is shown. For example, FIG. Signal Coordination and Trip Decision Group A (1204a / 1208a), RTS Voting Director Vision I1214 and the individual component modules of ESFAS Voting Division I1212 In addition, Figure 14 shows the separation group (HWM1310), RTS division (HWM1402) and ESFAS Division (HWM1408) As explained in more detail below, each HWM1310 / 1402 / 1408 are the backplanes 1312 / 1404 / 1406 to connect hardwired analog signals to associated component modules. Pass it to the manager.
[0245]
[0245] With collective reference to Figures 12-14, the primary purpose of the MPS1200 is to monitors parameters, provides automatic start signals in response to out-of-normal conditions, and provides steady-state and transient power The objective of the NIRS is to provide protection against unsafe nuclear system operation during operation. There is one MPS1200 for each system. The MPS1200 performs two main functions: One is to monitor plant parameters and facilitate plant safety analysis during anticipated operational events. By shutting down the reactor when specified set points based on analytical limits are reached or exceeded. An exemplary nuclear system reactor trip function for the RTS is shown in Table 1 (Figure 27). The other is to monitor plant parameters and monitor the plant during anticipated operational events. ESFA when specified set points based on analytical limits in the plant safety analysis are reached or exceeded. The operation of the ESFAS equipment will activate the reactor core and reactor coolant system. Damage to stem components is prevented or mitigated and containment integrity is ensured. AS functions are summarized in Table 2 (shown in Figures 28A-28C).
[0246]
[0246] The MPS 1200 also transmits status and information signals to the non-safety related MCS 155 (see Figure 1). 18), a maintenance workstation (MWS) 1316, and an SDIS (1800 in FIG. 18). ) to perform monitoring for the Post-Accident Monitoring (PAM) function.
[0247]
[0247] The MPS1200 is built on a highly integrated protection system platform. ,This is a system based on a field programmable gate array (FPGA). As mentioned above, the MPS1200 has the following characteristics: independence, redundancy, predictability, and repeatability, as well as Incorporate fundamental I&C design principles of diversity and defense in depth.
[0248]
[0248] The MPS1200 is a four-part system consisting of separate groups: sensor electronics, input panel, and signal conditioning. One separation group, four separation groups for trip determination, division power distribution panel, Provides isolation and power monitoring from non-safety related reliable DC power systems (EDSS) sources 1E class components, sensor and MPS components that also provide isolation from non-safety related EDSS Eight voltage sensors to detect loss of power to the device, 480VAC to the EDSS battery charger four reactor trip breakers, four pressurizer heater trip breakers, two unsafe functions MWS, two non-safety related MPS gateways 1314, PAM only mode Three 24-hour timers per division, RTS voting and actuation devices 1214 / 1216 Two divisions, ESFAS Voting and Operating Equipment 1212 / 1218 Reactor Trip Breaker 1244 and Associated Cabling Pressurizer Heater Trip Circuit Breakers and Associated Cabling, Low Voltage AC Electrical Distribution System (ELVS) 480 V Safety-related elements: AC bus voltage sensor and associated cabling for input to the MPS The MPS boundary may include a configuration that is actuated from the output connections of the sensor and the detector. Extends to the input connection of the element.
[0249]
[0249] The SFM 1300 for signal conditioning 1204a-1204d is It receives inputs from sensors and detectors to measure process parameters as shown in Figure 12. The interconnection of process sensors and detectors to the controls 1204a-1204d is by dedicated copper wires. and routed according to where it is needed based on sensor requirements. performs three main functions: signal conditioning, trip decision making, and communication engine. The function is a SF consisting of a signal conditioning circuit, an analog-to-digital converter, and a serial interface. The signal conditioning function consists of a field input module that is part of the M1300. It is responsible for force regulation, measurement, filtering, and sampling.
[0250]
[0250] The trip decision 1208a to 1208d are connected to the signal adjustment unit 1208a through the serial interface. Receives process and detector input values from the node block in digital format. Trip decision 1 208a-1208d execute safety function algorithms and trigger based on predetermined set points. perform a tap decision and isolate, and in some aspects redundant (e.g., double, triple, or Other), transmit a trip or no-trip request signal to each RTS through a dedicated series connection. Division 1214 / 1216. The SFM 1300 also provides Based on this, ESFAS operation judgment is made, and the ESFAS is activated or operated through an isolated series connection dedicated to transmission. Provides no-movement request signals to each ESFAS Division 1212 / 1218.
[0251] Within the SFM are the Monitoring and Indication Bus (MIB) functions and the Calibration and Test Bus (C There are two other logical functions: the MIB (Management Information Base) function and the MIB (Management Information Base) function. It obtains parameter, trip decision, status, and diagnostic information from the controller and provides it to the MIB. The CTB function logic ensures that the MWS1316 maintains nonvolatile memory when the SFM1300 is idle. Allows updating of tunable parameters in memory. Interface Module Separation group architecture showing interconnection of SFM1300 to 1306 / 1308 , as shown in Figure 13.
[0252]
[0252] The SFM1300 communications engine transmits trip and operational data to the chassis backplane. Three safety data buses (SDB1, SDB2, and SDB3) 130 on lanes 1312 2, and this data is sent to the scheduling and bypass module (SBM SD1, Received on SBM SD2 and SBM SD3 1306. The bus and bypass module (SBM) 1306 is the bus master for the associated bus, Responsible for scheduling communications. Communication paths and devices are redundant, and safety data is stored in a single database. The SBM1306 provides fault tolerance for single or multiple failures along the data path. and authenticates both the RTS1214 / 1216 and ESFAS1212 / 1218 divisions. This data is then sent to each scheduled server via an isolated one-way transmission connection to the server. The four separate groups are then transmitted to the SVM 1410 / 1420. The redundant data for RTS1214 / 1216 and ESFAS are shown in Figure 12. Received by each division of 1212 / 1218.
[0253] All status and diagnostic information for the SFM 1300 and SBM 1306 is stored in the MI The MIB communication module (MIB-CM) 1308 is provided to B. MIB-CM1308 is the master that schedules communications for the MIB. Status and diagnostic information is transmitted to the MCS155 and MPS gates through a separate, one-way, transmit-only output. The MPS gateway 1314 provides the data to the MWS 131 6 and SDIS1800. MIB-CM1308 also provides calibration information for each safety function. and parameter updates from MWS1316 to SFM13 through the CTB. 00 (path 1304). In some embodiments, the parameter To allow for changes or channel calibration, the safety function must be inactive and M A temporary cable 1318 from WS 1316 to MIB-CM 1308 is required. S1318 can access only one isolation group at a time using temporary cable 1318. It can be accessed.
[0254]
[0254] Separate group signal adjustment and trip decision 1204a / 1208a also A manual switch in the Main Control Room (MCR) allows the operator to trigger the reactor. Allows for manual initiation of a group and bypass for one or more separate group signals Controls are provided for manually bypassing each trip signal. through the separate group hardwired module HWM1310, SFM130 0. The isolation group HWM1310 is Analog hardwired backplane 11312 through SFM1300, SBM14 06 and MIB1308.
[0255] An MIB is included for each separate group and each division. MIB-CM1412 / 1422 is Division RTS and ESFAS MIB-CM There is no calibration available for the 1412 / 1422, so it only serves the monitoring and marking functions.
[0256] In some embodiments, the RTS comprises one RTS from each of the separate groups (A, B, C, and D). Four redundant trip signals are used to detect when RTS parameters exceed predetermined limits. Completes the logic decisions necessary to automatically open the reactor trip breaker 1244 when Exemplary analytical limits for RTS are listed in Table 1 (above).
[0257]
[0257] The SFM 1300 for each separation group generates a trip signal and The signal is routed through SBM1306 to both RTS divisions 1214 / 1216. The SVM 1410 then sends the trip decision status to the SVM 1410. Voting, for example, two out of four (2oo4) consensus logic voting. If more than one trip decision signal generates a reactor trip, the trip signal is generated and sent to the associated equipment interface module (EIM) 1414; The reactor trip breaker 1244 is opened.
[0258] Each EIM 1414 in the RTS generates redundant triggers from the outputs produced in the SVM 1410. receive a pop signal and decide based on a majority vote, e.g., two out of three (2oo3) vote. and provides a trip signal from the incoming signal as shown in Figure 14. The two divisions of the / 1216 circuit and reactor trip breaker 1244 are Provided to ensure that loss of RTS function does not result in reactor trip. The breakers 1244 may be configured in a series-parallel configuration, for example as shown in FIG. 2B. do.
[0259] As mentioned above, the separation of the voting layers between the SVM 1410 and the EIM 1414 The SVM non-majority voting method provides a more efficient and robust voting method. The EIM collects the results of the SVM votes. ,A majority vote is performed using the SVM signal.
[0260]
[0260] The EIM 1414 is configured to provide the MPS 1200 for each reactor trip breaker 1244. Each atom is contained within both RTS divisions 1214 / 1216, which are operated by The reactor trip circuit breaker EIM1414 has two separate logic paths. The secondary coil is connected to the foot voltage trip circuit for each reactor trip breaker 1244. Each RTS division 1214 / 1216 is connected to a shunt trip circuit for each parallel In the path, one reactor trip breaker 1244 is controlled. The Service Vision 1214 / 1216 will also be able to realize reactor trips. When a trip signal is generated within the SVM1410, the undervoltage trip circuit is disconnected and the The reactor trip circuit is energized. Either action energizes all four reactor trip breakers. 244 is then released. Power from the control rod drive power supply is then cut off and the control rods are pulled by gravity. and inserted into the reactor core.
[0261] The RTS also provides manual trip capability. A manual switch within the MCR is operated Allows the operator to manually initiate a reactor trip. One per division. Two manual switches are provided for manually initiating reactor trips. The RTS Hardwired Module (HWM) 1402 sends the reactor trip signal to the Input to the Action and Priority Logic (APL) associated with the system EIM 1414. The TS HWM1402 connects to the analog hardwired backplane 1404. Connected to SVM1410, EIM1414, and MIB1412. Manual trip function In addition, the RTS HWM1402 can also generate one or more RTS trip signals, non-1E cable (e.g., unsafe enable), and operational bypass control for unsafe control signals In some embodiments, non-1E enabled controls may be provided. Control signals from the interfacing system control the RTS system operation (e.g., RTB1 244).
[0262]
[0262] APL is a digital trip signal from the SFM1300, its associated R Non-digital manual trip signal from TS Division 1214 / 1216, MCS155 It accepts commands from three sources: a non-digital manual control signal from the
[0263]
[0263] Non-digital (e.g., analog) signals are not connected to the digital portion of the MPS1200. Different. APL allows you to activate a single device based on the highest priority. A separate logic is used to allow manual start regardless of the state of the digital system. It can always be performed at the application level. Enable unsafe control permissive is active. If there is an automatic or manual activation signal, the MCS155 will initiate a reactor trip interrupt. It is possible to operate the circuit breaker.
[0264] The results from the APL are used to operate the equipment connected to the EIM 1414. The reactor trip breaker status is provided to the EIM 1414. The breaker status information is , sent to MIB-CM1412 along with the status of the SDB signal.
[0265] In some embodiments, the ESFAS is a mixture of each of the separate groups (A, B, C, and D). Four redundant operation judgement signals are used, one from each of the four, to determine the required ESF, as shown in Figure 12. Complete the logical decisions necessary to automatically initiate an action. The analytical limits are listed in Table 2 (above).
[0266] When the ESFAS parameters exceed the predetermined limits, the S for each separation group The FM1300 generates an actuation signal, which passes through the SBM1306 to both Sent to SVM1420 in ESFAS Division 1212 / 1218. SVM14 20 is a non-majority vote regarding the trip decision state, e.g., two out of four unanimous votes. Performs logical voting. If two or more actuation signals generate actuation of the ESF system, the SV An activation signal is generated in the EIM1420. This signal is then transmitted to the associated EIM14 24 to disconnect the solenoid of the associated ESF system or Open the circuit breaker of the ESF system.
[0267]
[0267] The EIM 1424 provides the Each EIM 1424 is contained within a separate ESF To allow connectivity to the components, there can be two separate logical paths: The components are connected to two separate EIMs 1424, resulting in two EIMs 1424 provides redundant control to each component, as shown in Figure 15. This allows the connected functions EIM1424 can be taken out of service and replaced online without operating the device. It becomes possible.
[0268] As mentioned above, the separation of the voting layers between the SVM 1420 and the EIM 1424 SVM's non-majority voting scheme is a more efficient and robust method of voting. , three) SVM1420 can be run redundantly, and the EIM1424 Collect the results of the VM votes. The EIM 1424 votes on the SVM signals.
[0269]
[0269] Figure 15 shows a schematic of an exemplary embodiment of the ESFAS EIM 1424a / 1424b. 15 shows a schematic diagram 1500. When the ESFAS actuation signal is generated within the SVM 1420, As shown in Figure 1, all four switching outputs from EIM1424a / 1424b 504-1510 are activated. For example, the power to the component solenoids 1512 / 1518 When the power is interrupted, the component can be actuated. The solenoid is disconnected and the component In the case of a pressurizer heater, the undervoltage trip circuit is disconnected. The shunt trip circuit is energized. Either action opens all four circuit breakers. .
[0270]
[0270] The ESFAS may also provide manual actuation capabilities. For example, some In this embodiment, a manual switch in the MCR allows the operator to manually initiate the ESF function. Two manual switches, one for each division 1212 / 1218, are provided. , are provided to manually start each ESF function. These manual switches are S HWM1408 and associated with the engineered safety facility activation system EIM1424 The ESFAS HWM1408 is an analog hardwired bus. Through the backplane 1406, the SVM 1420, the EIM 1424, and the MIB 1422 In addition to the manual ESF component actuation capability, the ESFAS HWM1408 One or more ESFAS trip signals, non-1E enabling controls (e.g., non-safety enable cable), and operational bypass control for unsafe control signals. In some embodiments, the non-1E enabling control is achieved by a control signal from a non-safety related system: To control ESFAS system operation (e.g., to operate ESF components) Make it possible.
[0271]
[0271] The APL receives the digital trip signal from the SFM1300, its own ESFAS Non-digital manual trip signal from Division 1212 / 1218, from MCS155 It accepts commands from three sources:
[0272]
[0272] Non-digital (e.g., analog) signals are not connected to the digital portion of the MPS1200. Different. APL allows a single component to be activated based on the highest priority. Separate logic is used to allow manual starts to be performed regardless of the state of the digital system. Enable non-safety related control permissives is active. When the MCS155 is in ESF configuration, and there is no automatic or manual activation signal, The element can be controlled (e.g., manipulated).
[0273]
[0273] The results from the APL are used to control and operate the equipment connected to the EIM 1424. The equipment status is transmitted to each EIM 1424. The equipment status information is stored in the MIB - Sent to CM1422 along with the state of the SDB signal.
[0274]
[0274] Each MPS 1200 Separation Group and Division, and MPS Gateway 1 314 is a dedicated HWM (e.g., isolation group HWM1310, RTS HWM14 02, and ESFAS HWM1408). The characteristics of HWM are as shown in Figure 25. The HWM receives a hardwired signal from outside the MPS cabinet. and route these signals to other modules via the chassis backplane (for example, These signals are available on the M Manually operated switch, operation bypass switch, override switch from CR155, and enable unsafe control switches. Operation bypass and override switches are , which are described in more detail below. Other inputs to the HWM are the SFM1300 trip / bypass Includes switch, MCS155 control input, and component position feedback.
[0275]
[0275] Figure 16 shows a schematic diagram of an exemplary embodiment of an MPS Gateway 1314. Each division of the PS has a non-safety related MPS gateway 1314. The gateway is divided into four separate groups (e.g., groups A, B, C, and D), RTS1 Received from two divisions, 214 / 1216 and ESFAS 1212 / 1218 The MPS gateway 1314 includes a plurality of communication modules 1602 that integrate the received information. It also provides device status feedback from the device to the HWM1624 for PAM-only mode. (Position Feedback 1622) can be collected, as well as the Timer SFM1612 The MPS gateway 1314 passes through the MPS gateway 1314 and reads the status of the three 24-hour timers 1614. All of the information transmitted to the gateway is transmitted to a single communication module acting as a gateway master 1604. Separate group and division communication module 1602 and The timer SFM1612 passes through the RS-485 physical layer 1608 to the gateway master. 1604, which then communicates with the gateway on the MPS gateway backplane 1626. The Waymaster 1604 communicates via an isolated, well-formed, one-way communication path as shown in FIG. The integrated data is transmitted to the MWS1316 and SDIS hub. There is one MPS gateway 1314.
[0276]
[0276] Each division of the MPS1200 shall, for maintenance and calibration purposes, WS1316. One-way read-only data is stored in the MPS for that division. The gateway 1314 is provided and transmitted serially on the MWS 1316 of each division. The MWS1316 is available for adjustment within the SFM1300 when the safety function is not in operation. Used to update adjustable parameters relied upon to perform safety functions. Controls are put in place to prevent modifications to the SFM1300 while the MWS131 is in operation. 6. Two-way communication to update set points and adjustable parameters within the SFM1300 Used for off-line maintenance and calibration using temporary cable 1318 which allows When the FM1300 is deactivated by operating its deactivation switch, The trip / bypass switch position associated with the SFM1300 is the same as that of the SBM1306 and used as the state for the SFM1300 outputs. Each division of 00 is a point-to-point cable (e.g., copper or fiber optic). ) through an isolated one-way communication port using the MPS Gateway 1314 and a non-safety related MWS 1316 permanently connected for online monitoring purposes.
[0277] In some embodiments, the EDSS is the power source for the MPS1200. C-DC voltage converters are used for class 1E isolation and protection of MPS equipment. MPS power for version I is DC-DC conversion for 1E class isolation from power channels A and C. Division II electricity is generated through a converter and then auctioned. Similar to Vision I, the separation groups are generated from power channels B and D. Each separation group is a single Redundantly supplied and auctioned by the EDSS channel of the MPS Division EDSS Power Channels A and C, which provide power to MPS Division II, provide power to MPS Division II. It is completely independent of the EDSS power channels B and D it supplies.
[0278] In some embodiments, 24 hours for A and D batteries and 24 hours for B and C batteries To ensure EDSS battery power for the entire 72-hour mission time loads associated with maintaining a closed ECCS valve or functional PAM instrumentation Only these remain energized during ECCS hold and PAM only modes. Loads include the MPS and Neutron Monitoring System (NMS) cabinets, including power to sensors. , ECCS valve solenoid, Radiation Monitoring (RM) Bioshield radiation monitor, and E Includes a DSS battery monitor. Two of the four sensors are connected to both the B and C battery chargers. If a loss of voltage is detected at the switchgear, the MPS will trip the reactor, trip the decay heat removal system, (DHRS) operation, pressurizer heater trip, demineralized water supply isolation, and containment isolation are automatically generated. , start three 24-hour timers per division. The first 24 hours after loss of voltage Over the course of four separate groups of MPS instruments and both ESFAS and RTS devices The vision remains energized. If ECCS operation is not required due to plant conditions, If the ECCS trip solenoid valve is turned off, the ECCS will not operate (the ECCS trip solenoid valve will remain energized). This allows time for AC power to be restored and prevents ECCS activation. During this 24-hour period, the associated ESFAS signal is defined as S-hold mode. If generated, the ECCS will still operate. If power to the switch is not restored, the 24-hour timer will expire. At this point, the ES MWS for FAS and RTS chassis and both MPS divisions will automatically This action disconnects the ECCS solenoid trip valve, preventing the ECCS from operating. The PAM instrumentation will be maintained at EDs B and C for an additional 48 hours (72 hours total). It remains powered by the SS battery. This configuration is defined as PAM only mode. do.
[0279] FIG. 17 shows a block diagram of a nuclear plant protection system (PPS) 1700. The PPS1700 monitors parameters at the plant level and provides normal and off-normal The PPS1700 is a system common to multiple nuclear power systems. Monitors and controls selected variables monitored and actuated by the PPS1700. Equipment requiring increased quality levels. The PPS1700 is Each division may have the function of realizing PPS functions. is possible.
[0280]
[0280] PPS is built on a highly integrated protection system platform, The system is based on FPGA. Figure 17 shows the architecture of one PPS division. The architecture of the second division should be similar. be.
[0281]
[0281] Division I and Division II of PPS1700 are located in separate rooms in the control building. The boundaries of the PPS1700 can be located from the sensor and detector output connections to Extends to the input connection of the device to be operated. Within the boundaries of the PPS1700, A voltage sensor is also included; the ELVS AC voltage sensor is part of the PPS1700. Non-safety related displays that receive data from the PPS1700 are classified as SDIS or PPS1700. It is any part of the runt control system (PCS).
[0282]
[0282] Process sensors measure different process parameters such as radiation, level, and voltage. Separate sensors provide information to the two PPS divisions. The sensors measure They are suitable for environmental conditions before, during, and after a design basis event. These sensors provide input to the PPS1700, but the system in which they are installed It is classified as part of the
[0283]
[0283] An individual PPS SFM 1704 is responsible for each function performed by the PPS 1700. Each SFM1704 receives inputs from up to four sensors. 702. To convert the sensor signal into a digital representation, a signal conditioning In the case of digital signals, the SFM1704 will operate at the speed required for its function. It performs the necessary algorithms and set point comparisons to determine whether or not the actuation decision is made. , output to three separate communication buses 1712 between the SFM 1704 and the EIM 1714. The SFM1704 also provides redundant communication for parameter values, status information, and alarms. It provides communication outputs (for example, via MIB-CM1706) that The diagnostic information for each SFM 1704 is also sent to the MWS 131. Sent to 6.
[0284]
[0284] The PPS1700 architecture has three independent data buses dedicated to the differential signals. It uses the 1712 bus. Three communication safety data buses (SDB1, SDB2, and SDB3) ) 1712 are each configured with a master-slave communication protocol. Three redundant SBMs ( SBM1, SBM2, and SBM3 are masters for their associated buses. Yes, providing redundant SDB1712 communication from SFM1704 to EIM1714. SD B1, SDB2 and SDB3 1712 are dedicated to processing the actuation signal.
[0285]
[0285] MIB-CM1706 is independent of the three SDB communication modules and is B. MIB-CM1706 uses the same master-slave communication protocol. It processes information and stores it in the registers on the SFM1704, communication module, and EIM1714. These registers are used for the operational data path. The MIB-CM1706 uses the MIB to communicate with the CTB communication module 171. 0 and update the MWS 1316. One-way data to the PCS and SDIS is transmitted to the MI The data is transmitted through the isolated data path of the B-CM1706. This interface Certain failures of unsafe equipment will not prevent the PPS1700 from performing its functions It is designed to be.
[0286]
[0286] The CTB communication module 1710 is the master of the CTB, but during normal operation There are no transactions on the bus. The CTB is not calibrating or changing parameters. It becomes active only when the channel is deactivated. Isolation of the CTB communication module 1710 The data path carries unidirectional data to the MWS 1316.
[0287]
[0287] The EIM 1714 provides the Contained within each division, each EIM1714 has a "primary" component and a "secondary" component. To allow connections to the elements, two separate logical paths can be used. Element 1716 is connected to two separate EIMs 1714, resulting in two EIMs 1717. 14 provides redundant control to each component 1716. This allows any device 1716 EIM1714 can be taken out of service and replaced online without having to operate the become.
[0288]
[0288] The activation signals from the redundant SDBs 1712 are combined and APL is (1) a digital actuation signal from the SFM1704, (2) (3) a non-digital manual actuation input signal from its own PPS division, and (4) a non-digital manual actuation input signal from the PCS It accepts commands from three sources: non-digital manual control signals, non-digital signals, and The signal is different from the digital part of the PPS1700. The APL gives it the highest priority. A separate logic is used to operate a single device based on the Manual initiation of an action can be initiated at the division level regardless of the system state. When appropriate configuration is enabled by the operator, the PCS allows for component level The control can be realized.
[0289]
[0289] The results from the APL are used to control and operate the equipment connected to the EIM1714. The device status is fed back to each EIM 1714. The back information is sent to MIB-CM1706 along with the SDB signal and APL status. .
[0290]
[0290] Each division of PPS 1700 has its own dedicated MWS 1316. Maintenance Activities To do this, the MWS1316 must be able to execute write commands to the device. will be done.
[0291] Each PPS division cabinet contains one or more HWM1722 / 172 4, the HWM1722 / 1724 can accept external signals and transmit these signals to other modules. These signals are available on the backplane 1720 for the manual actuation switch. Includes a switch, an unsafe control signal, and a trip bypass control.
[0292]
[0292] PPS1700 is a system for monitoring and controlling plant systems common to multiple nuclear power plants. Although the PPS1700 is non-safety related, it supports PAM functions. The PS1700 is designed to meet increased quality and regulatory requirements. All of the example variables monitored by the PPS 1700 listed (shown in Sent to PCS and displayed in MCR if required by those systems These include the operation of the control room habitability system and the required PAM from the PPS1700. Displays and indicators are provided to accommodate the variables.
[0293] FIG. 18 shows an exemplary MPS1200 Safety Indication and Marking System (SIDS). 1 shows a schematic diagram of an embodiment. SDIS is related to the state of MPS1200 and PPS1700. Accurate, complete, and timely information, as well as the ability to manually initiate protective actions when needed. Provide informational displays to assist in the identification of vehicles. The informational displays minimize the possibility of ambiguous markings. , designed to enhance the human-system interface (HSI) for the operator. .
[0294]
[0294] The primary function of SDIS is to ensure that the plant operates within the limits defined by the safety analysis. Providing HSI and data to operators to ensure operation, ES Notifying operators when FAS, RTS, and PPS setpoints are reached; It provides operators with the data they need to ensure the system is in a safe state after an accident. and accurate, complete, and timely information regarding the status of the MPS1200 and PPS1700. The objective of the ISS is to provide information on the incident and display information to support post-accident monitoring (PAM). SDIS provides HSI for MPS and PPS to monitor and display PAM variables. It provides the capability for control inputs and status information. In some instances, the SDIS may be a system for detecting non-critical safety-related risks. To accommodate PAM functionality, the SDIS is an augmented Meet quality and regulatory requirements.
[0295]
[0295] Information about parameter values and device status is stored in the MPS1200 and PPS1700. will be provided to SDIS by each separate group and division.
[0296]
[0296] SDIS communicates with MPS1200 and PPS1700 via a communication module. The MPS interface is called the MPS Gateway 1314. The interface with the PPS is through the MIB communication module 1706. , which consists of two independent divisions of equipment. Each SDIS division consists of a communications hub, A display interface module (DIM) (described later with reference to FIG. 20) and a display panel The SDIS boundaries and interfaces are shown in Figure 18.
[0297]
[0297] The SDIS Hub 1800 is an MPS gateway and a Plant Protection System MIB Each MPS Gateway 1314 receives data from the communication module. 1800 to a separate communication module 1804. The data received from the MPS1200 and PPS1700 is transmitted to an optically isolated directional fiber optic cable associated with each nuclear system or PPS Distributed to the DIM. Communication module on SDIS Hub 1800 for each SDIS Hub rack. The data from each of the modules 1804 is collected in a single communications module. The module passes through the backplane to the rack and connects to each of the communication modules on that rack. The communication module then provides an optically isolated, unidirectional interface. Pass through and send the collected information to PCS1802.
[0298]
[0298] The SDIS Hub 1800 has two chassis of communication modules for each division. The first chassis is the MPS120 associated with Nuclear Systems 1-6. The second shutter houses the communication module for the PPS1700 and the communication module for the PPS1700. The system is a communication module for only the MPS1200 associated with nuclear systems 7 to 12. Both the first and second chassis of the communication module are It houses the communications module that interfaces with the system.
[0299] FIG. 19 illustrates an exemplary embodiment of an SDIS hubrack 1900 for an MPS 1200. A schematic diagram of an SDIS rack 1900 includes multiple SDIS communication modules 1902. In some embodiments of the MPS 1200, each rack 1900 includes a modular reactor Includes SDIS-CM1902 for one division of the system. SDIS-CM 1902 can be interconnected over an RS-485 physical layer 1904. For example, each Rack 1900 contains 12 Nuclear Power Modules (NPM) SDIS-CM1902, Each nuclear module has an I&C device associated with one of the 12 module reactors. The PPS SDIS-CM1902 is configured to receive and display PPS data. The second rack 1 is configured to receive and display I&C data associated with the The 900 is similar, but offers different types of software and / or The SDIS rack 1900 can be implemented by hardware components. It can provide an efficient way to collect I&C data from multiple reactor systems.
[0300] FIG. 20 illustrates an exemplary embodiment of a display system (DS) 2000 for the MPS 1200. The DS2000 includes a digital display panel 2004 (e.g., a liquid crystal display). In electrical communication with the LCD or Light Emitting Diode (LED) display The DS2000 includes a Display Interface Module (DIM) 2002. Includes independent power supplies 2010 and 2012. Each power supply 2010 / 2012 is a DIM200 2 and the display panel 2004. Two independent power supplies The use of sources 2010 / 2012 ensures redundant power supply to the DS2000.
[0301]
[0301] The DIM2002 in the SDIS is connected through an isolated fiber-to-copper interface. The received data can be displayed immediately on the FPGA2006. For example, DIM2002 processes the data and converts it into a suitable format (such as For example, a graphical user interface) and a display for panel 2004. It acts as a play driver. Therefore, the format that can be displayed immediately is the display panel 2004 The pixel matrix may be a panel drive signal.
[0302]
[0302] Then, DIM2002 sends the ready-to-display data through the cable. The display panel 2004 receives the data from the MPS1200 and PPS1700. Available data is displayed to the plant operator in the MCR. Data from the S1700 is displayed on its own dedicated monitor. There are two monitors. The MPS1200 and PPS1700 data divisions are both , displayed on both SDIS division displays.
[0303] In some embodiments, each DS 2000 includes a pair of DIMs 2002 and a pair of Display panel 2004. To provide redundancy for data display, each The same MPS or PPS data is provided to the DIM2002. Both DIM2002s in the 0 are connected to the same SDIS output. Redundancy is a design versatility feature. To provide this, different types of FPGAs 2006 can be used within each DIM 2002. Similarly, the FPGA 2006 of each DIM 2002 is To provide software diversity, different data and graphics processing algorithms are used. It can be programmed like this.
[0304]
[0304] Figure 21 shows a schematic diagram of another exemplary embodiment of the SFM 2100. The SFM 2100 processes the sensor input and sends the The module determines whether to trip the reactor and / or activate the ESF. , signal conditioning / analog-to-digital conversion (input sub-modules) 2104a to 2104d, Digital logic 2114 (e.g., safety function algorithms, calculations, diagnostics), and communication It consists of three functional areas: engine 2120.
[0305]
[0305] The SFM2100 uses the FPGA2112 device to implement safety function algorithms. All logic circuits, including the system, engineering unit calculations, bus communication logic, and indicator and diagnostic information (IDI) logic. The SFM2100 houses all the digital logic circuits. There is an Out of Service (OOS) switch on the front of the SFM2100. 2124 exists and allows the SFM2100 to be put into an out-of-operation state. 4 When the switch is activated, the safety function trips / bypasses the SFM2100. Based on the position of the switch, the device is placed in trip or bypass. This allows for the storage of adjustable parameters and set points in the non-volatile memory (NVM) 2110. Amendments are allowed.
[0306]
[0306] The input sub-modules 2104a to 2104d receive information from multiple inputs 2102. The input sub-modules 2104a-2104d receive the signal conditioning circuit 2106, the analog Each SFM2 includes a log-to-digital (A / D) converter 2108 and a serial interface. 100 includes multiple (e.g., four or more) input sub-modules 2104a-2104b. 04d. The input 2102 type can be permissive or interlocked. The analog and digital signals that the SFM2100 needs to generate to determine operation are Any combination of digital (e.g. RTD, TC, 4~20mA, 10~50mA, 0~ 10V).
[0307]
[0307] The logic functions are implemented in the programmable part (FPGA) 2112 of the SFM 2100. The output of each of the input sub-modules is fed to multiple redundant core logic circuits within the FPGA 2112. The signal is routed to the MIB logic module 2114 and sent to the MIB logic module 2116 logic. Each of the modules 2114 functions in a redundant signal path. This includes, but is not limited to, executing safety function algorithms, comparing algorithm outputs to set points to make trip and / or ESF activation decisions; and The IO_CONTROL_INTERLOCK_CONTROL_INTERLOCK function performs functions including generating permissive and control interlocks.
[0308]
[0308] Each core module 2114 operates within a separate core logic signal path and is It performs its functions logically independent of the other core modules, resulting in three functionally independent This allows for separate core logic functions and provides three redundant signal paths. The safety algorithm uses three redundant paths to provide error detection and fault tolerance for the safety function. It is processed through the pathway.
[0309]
[0309] Within the FPGA 2112, there is a MIB logic module 2116 and a CTB logic module 2117. There are two other logic functions in the Monitor and Indicator Bus (MIB) logic module 2118. The control 2116 receives parameters, trip decisions, status, and This information is provided to the MIB-CM and MIB-M. It is sent through the PS Gateway to the MCS, SDI, and MWS. CTB Logical Module The rule 2118 indicates that the SFM 2100 is out of service (the OOS switch 2124 is activated). Allows MWS to update tunable parameters within the NVM2110 when To do so.
[0310]
[0310] Logic modules 2114 / 2116 / 2118 each include a plurality of deterministic state machines. The logic function algorithms include multiple redundant logic circuits to provide error detection and fault tolerance. The SFM2100 is dedicated to one function or group of functions. By doing so, the software C The impact of CF is limited.
[0311]
[0311] The communications block consists of five separate, logically independent communications engines 2120 (e.g. For example, data can be transmitted regardless of the state of another communication engine. The Sinn 2120 is equipped with Safety Data Bus 1 (SDB1), Safety Data Bus 2 (SDB2), and Safety Data Bus 3 (SDB3), Monitoring and Indication Bus (MIB), and Calibration and Test Bus (C Each SDB communicates the same data, but is dedicated to one of the communication buses, the SDB TB. Each communication port packages and transmits data separately. 0 packets of data can be transmitted sequentially (e.g., 1, 2, ..., 10), and S DB2 transmits the same 10 packets in reverse order (e.g., 10, 9, ..., 1), SDB3 transmits even packets first, followed by odd packets (e.g. , 2, 4, ..., 10, 1, 3, ..9).
[0312] In some embodiments, triple redundancy is used for core logic functions on the SDB. This not only allows for communication error detection, but also ensures that downstream components are accurately tripped. and / or restricting communications CCFs to specific buses without affecting their ability to make operational decisions. It is possible.
[0313] FIG. 22 illustrates the monitoring and indicator (MIB) communication module 2200 of the MPS 1200. A schematic diagram of an exemplary embodiment is shown. A communication module (CM) 2200 transmits safety data to the S This is the base module that provides the communication channel for communication from FM to EIM. 200 also provides monitoring and indication and diagnostic information from outside the protection system architecture. (1) Fault monitoring and display systems (e.g., SDI); and (2) Control, Diagnostic, and Display. , and provides communication capabilities to other systems (e.g., MCS and MWS) for monitoring purposes. do.
[0314] In some embodiments, the CM2200 also controls logic level backplane signals Incorporates hardwired signal inputs via. If used, these hardwired The yard signal can be hardwired into modules in the same chassis or in daisy-chain chassis. The card is placed directly onto the backplane through the HWM.
[0315]
[0315] The CM2200 can be configured differently based on their functionality. The communication modules of each type are based on the same modular hardware architecture. ,Monitoring and Indication Bus CM (MIB-CM), Scheduling and Bypass Module ( SBM), Scheduling and Voting Module (SVM), MPS Gateway CM include.
[0316] The basic CM 2200 consists of an FPGA 2202, scheduling and communication logic 2 214, Indication and Diagnostic Information (IDI) 2210, CM Functional Logic Circuit 2212 (CM specific based on the desired functionality), hardwired signal inputs, and The CM uses the FPGA 2202 device to Implements logic circuits based on the specific functions they perform. The logic includes bus communication and scheduling logic, any functions performed by the CM, and IDI logic. For example, in MIB-CM, the function logic 2212 includes the monitoring and targeting logic. The MIB CM is configured to collect and assign information about the SFM, SBM, and and EIM, and sends the indicators and diagnostic information to the It is used to transmit information to the SDI system and PCS.
[0317] Each of the four copper-fiber physical layers 2216 can be configured for receive-only or transmit-only. Inter-division communications or communications to non-safety-related or other safety-related systems The communication must pass through a dedicated communication port (e.g., copper or optical fiber) that is either transmit-only or receive-only. These ports must provide 1E class isolation for receive or transmit configurations. The CM consists of FPGA logic, non-volatile memory (NVM), clock circuitry, and power and self-test capabilities to ensure detection of faults in the power management circuitry.
[0318]
[0318] MIB-CM collects indications and diagnostic information from SFM, SBM, SVM, and EIM. Collect this information and pass it to the MCS and MPS game engines via a separate, qualified, one-way data path. The MIB-CM is also used to transmit data to the Calibration and Test Bus (CTB ) information from the MWS to the SFM.
[0319]
[0319] For each Separate Group and MIB-CM within the RTS and ESFAS Divisions Three of the copper-fiber data ports are configured for transmission only, and support MCS, Divisi Send information to the Division I MPS Gateway and the Division II MPS Gateway The remaining copper-fiber data ports on the MIB-CM in the separate group are configured as receive-only. It receives information from the MWS through a temporary cable that is configured and connected during maintenance activities. The remaining ports on the MIB-CM in the RTS and ESFAS divisions are spare.
[0320] FIG. 23 shows the Scheduling and Bypass Module (SBM) of the MPS 1200. 23 shows a schematic diagram of an exemplary embodiment of an SBM 2300. The SBM 2300 is a scheduling and and bypass functions. For example, the SBM-C Within M, function logic 2212 is configured to perform scheduling and bypass functions. As mentioned above, one for each safety data bus, and one for each isolation group. There are multiple redundant SBMs 2300 (for example, three SBMs per group). The M2300 requests and receives safety data from each SFM and then The associated SVM and ESFAS divisions in the vision are The SBM copper-fiber data port 2210 transmits this data to the SVM. , RTS and ESFAS. The SBM2300 is triple redundant to aid in error detection and the ability to detect transmission faults. Provides a data communication path.
[0321]
[0321] The HWM for the isolation group controls the trip / bypass switch position for each safety function. converts this information into logic level signals for the chassis backplane, This information is received by the SBM 2300 hardwired signal interface 2304. The data packet received from the SFM contains the location of the OOS switch on the SFM. The SBM2300 receives the OOS switch position information from the SFM in the data packet. If SFM is not operational and triggered, When the bypass / top-up switch is in bypass, the SBM2300 will not output the SFM safety function. Whatever the force is asking for, it sends a no-operation condition to the SVM. When the Trip / Bypass switch is in Trip position, the SBM2300 will Whatever it is, it sends an activation signal to the SVM. If the SFM is not inactive, the SB The M2300 calculates and transmits the safety function algorithm results from the SFM to the SBM2300. Transmit the results.
[0322] If the SBM 2300 does not receive a valid response from the SFM, an alarm is generated. The SBM2300 uses the position of the trip / bypass switch to determine what to transmit to the SVM. If the trip / bypass switch is in the trip position, the SBM230 0 transmits an activation signal to the SVM for its safety function. When the switch is in the bypass position, If so, the SBM2300 transmits a no-operation signal to the SVM for its safety function.
[0323] FIG. 24 shows the scheduling and voting module (SVM) 2 of the MPS 1200. 4 shows a schematic diagram of an exemplary embodiment of the SVM 2400. CM 2200 configured to perform voting functions. For example, within the SVM-CM, The function logic 2212 is configured to perform scheduling and voting functions. The SVM2400 receives data from four separate groups and provides a non-multiple Perform a voting vote (e.g., 2oo4 voting) to determine whether a trip or trip signal is required. Determine whether two or more separate groups are required for a trip or activation signal. If a match is found, a trip or activation signal is passed to the appropriate EIM for that safety function. As mentioned above, within each division of the RTS, there is one for each safety data bus. There are three redundant SVM2400s, three within each division of the ESFAS. Port 2216 is configured as receive only.
[0324]
[0324] HWM for RTS and HWM for ESFAS are operational bypass switches. converts the position of the device into logic level signals and places this information on the chassis backplane. The information is received at the SVM 2400 hardwired signal interface 2404. If an operational bypass signal is present for a safety function for which Any activation signal is ignored and a no activation signal is transmitted to the appropriate EIM.
[0325]
[0325] Figure 25 shows the equipment interface module of the MPS1200 or PPS1700. 25 shows a schematic diagram of an exemplary embodiment of the EIM 2500. The EIM 2500 is The final operating device for SFAS and PPS. EIM2500 is FPGA2502 , bus communication logic 2508, IDI logic 2512, automatic activation voting logic 2510, hardware Yard signal logic 2504, Actuation and Priority Logic (APL) 2514, Switching Output 25 16, and a circuit called position feedback input 2518.
[0326] Logic implemented within FPGA 2502 includes bus communication logic 2508, auto-activation voting, The bus communication logic 2508 includes SDB (SD B1, SDB2, and SDB3) and feeds that data into an automated voting logic 2510. The IDI logic 2512 sends the MIB communication logic 2520 the PCS, S Processed by DIS Hub and MWS.
[0327] The auto-activation voting logic 2510 votes on activation signals received from the three SDBs. The auto-activation voting logic 2510 determines whether activation is guaranteed for the primary or secondary activation path. For example, the auto-activation voting logic 2510 performs a majority vote on the activation signal. The auto-activation voting logic 2510 determines whether the two out of three (2oo3) activation signals are active. When indicated, automatic operation is guaranteed. Data communication is triple redundant, with single failure Voted to eliminate disability issues.
[0328] IDI logic 2512 collects status and diagnostic information from various circuits on the EIM 2500. The MIB communication logic 2520 collects and sends this diagnostic information to the MIB communication logic 2520 for processing.
[0329]
[0329] The EIM2500 can be connected to the HWM through the chassis backplane. (e.g. RTS HWM1402, ESFAS HWM1408, and PPS Each HWM is responsible for the manual switch position and safety related control signals. It converts this information into analog logic level signals and places it on the chassis backplane. The hardwired signal logic 2504 passes this information from the chassis backplane to the APL2 514. The hardwired signal 2506 is not limited to Not specified, but may include manual actuation signals, non-safe (NS) enabling switch position signals, These may include permissive signals, bypass signals, and non-safety related control signals.
[0330] APL 2514 is constructed from individual logic components and includes self-actuating voting logic 251 0, hardwired signal logic 2504, and receives commands from PCS control signals. The APL2514 will process the highest priority command it receives. For example, the APL2514 can control automatic and manual operation using the PCS control signal and NS enable signal. For example, if the NS enable switch is active, the PCS , when a higher priority function activation signal is not present, the termination coupled to the EIM2500 However, automatic or manual activation commands are not available through the PCS input. Without the NS enable signal, the EIM2500 always For example, the APL2514 ignores a higher priority signal (such as Unless a signal (e.g., automatic or manual actuation signal) is present, the terminating device is Unsafe signals to activate or reset (e.g., NS enable and PCS command signals) Furthermore, the APL2514 prevents such actions from unsafe signals. While allowing, any fault error from an unsafe system (e.g. PCS) will Prevents propagation through the M2500 into safety systems (e.g. RTS or ESFAS) Prevent.
[0331] In some embodiments, each EIM 2500 may control multiple components. For example, each EIM2500 can control two field components. The EIM2500 has four switching outputs 2516, two primary and two secondary. The switching output 2516 can be used to provide redundant output without affecting the output operation. and a single failure of one of the drive components is automatically detected and mitigated. A single fault in one of the four switching outputs 2516 will prevent the output channel from exciting the load. The self-test capability is only available when the solenoid is energized. This is accomplished by measuring the current through the switching output 2516 when This is achieved by measuring continuity through the solenoid when it is disconnected. The switching outputs are provided to allow connection to unsafe components or voltage sources. , isolated from the field.
[0332]
[0332] If only one EIM2500 is supplying power to the coil of the end device, Failure or removal of the EIM2500 should cause field components to be activated. To allow replacement of the EIM2500 without operating the end device, a second EI The M2500 switching output is placed in parallel with a second EIM2500, see Figure 15 As shown and described below, each EIM2500 maintains its output energized. This configuration also allows for more thorough testing of the EIM2500 circuit.
[0333]
[0333] Figure 26 shows the hardwired module (HWM) 2600 of the MPS1200. Block diagram showing each MPS separation group and division, and MPS gateway , and each PPS division has its own dedicated HWM2500 (e.g., HWM1310, 1 402, 1408, 1722, 1724). HWM2600 is an MPS cabinet. Accepts hardwired analog signals from outside the unit and transmits these signals to other modules. For example, these signals are made available on the chassis backplane 2602 to the Signals include, but are not limited to, manual actuation switches from the MCR, actuation by Includes pass switches, override switches, and enable non-safety control switches. Other inputs to the WM are the SFM trip / bypass switch, the MCS control input, and the configuration Includes elementary position feedback.
[0334]
[0334] HWM2600 receives signals from the manual switch in the main control room and individual signals from the MCS. Receives control signals, position feedback, and trip / bypass switch panel The HWM2600 is built entirely from discrete analog components and is programmable. These signals are not connected to separate group switch inputs (e.g., maintenance trips). bypass / bypass (each isolation group), RTS and ESFAS switch inputs (e.g. manual Operation (MCR), Block or Override (MCR), Enable NS Control (MC R), Operational Bypass (MCR), Non-Safety Related MCS Control Signals), and MPS Gateway (e.g., position feeds from RTS and ESFAS components for incident monitoring indications) Back).
[0335]
[0335] All signals from manual switches and non-safety related MCS signals are It is isolated and converted to analog logic voltage levels and can be used by any module that requires it. An exemplary H The WM2600 has a maximum of 32 inputs coming from the top of the module. The 32 inputs are divided into 4 The inputs are divided into sets of eight inputs 2604. Each set 2604 receives its own electrical Each input channel has three adjacent pairs of inputs 2604. We offer a unique galvanic isolation 2608. Galvanic isolation is an optical isolator device Each set of eight inputs 2608 can provide an isolated power supply. It has its own DC-DC converter to
[0336]
[0336] Operational bypasses are not required for certain plant operating modes when specific protective measures are not required. Different plant operating modes provide automatic or manual bypass of safety functions. Operational bypass is used to allow mode changes. Maintenance A bypass is provided to bypass safety system equipment during maintenance, testing, or repair. Maintenance bypass may reduce equipment redundancy but does not result in the loss of the safety function. Operational and maintenance bypasses are explained in the following paragraphs.
[0337]
[0337] The MPS may automatically, or by a combination of automatic and manual actions, Interlocks, permissives, and and operational and maintenance bypasses.
[0338]
[0338] The MPS logic determines whether the permissive or interlock conditions for action bypass are met. If not, the activation of the operating bypass shall be automatically prevented or appropriate safety feature(s) shall be implemented. Operational bypass circuits bypass the protection functions when the functions are not needed. Both permissive features allow for the execution of a command, and bidirectional features allow for the execution of a command when a condition is met. Contains interlocking features that automatically activate paths. Permissive and Interlocking Conditions If the conditions are no longer met, the operational bypass is automatically deactivated.
[0339]
[0339] Operational bypass allows for a change of plant mode and is used for safety analysis or plant operation. It is required to provide operator control of certain functions based on the MPS function, interface, Exemplary operational bypasses for locks and permissives are shown in Table 4 (see Figures 30A-30C). These bypasses are listed in the section on power lines that would normally be used to control plant operation (e.g., Automatic or manual blocking of certain protection measures that prevent mode changes during the start of a transaction. The bypass is used when the plant is brought into an operating state where protective measures are required to be operational. When any part of the system is bypassed or taken out of service, If so, indications will be provided in the control room.
[0340]
[0340] The manually operated bypass has two switches, one for each division. Some designs use only a manually operated bypass to achieve the bypass function. Use permissive with manual bypass for momentary control. It can be a tactile switch, normally open, which performs an operational bypass function Therefore, it is closed only momentarily.
[0341]
[0341] In the identified event, the failure is limited to one of the two MPS divisions. Other MPS divisions are fully operational and capable of performing their safety functions. A single fault does not disable the safety function. The other MPS divisions are limited to one MPS division. It is not possible to perform the function.
[0342]
[0342] In the case of automatic and manual operation bypass, permissive or interactive A trip decision is used for locking, which is similar to the trip decision for protective measures. To determine whether operational bypass is guaranteed, a three-out-of-four Matching is used. Permissive or interlocking is enabled to eliminate operational bypass. Two out of four of the isolation group are required to determine that the operation is no longer effective. The bypass is automatically reset.
[0343] The MPS variable activates a protection function that utilizes two-out-of-four match logic. This configuration allows for a single contingency failure of the protection channel. If a fault occurs simultaneously with a channel in the maintenance bypass, the required safety function remains operable. It will be possible to leave it as it is.
[0344] The MPS shall permit administrative bypass of the protection channel for maintenance, test, or repair. The MPS channel is administratively bypassed or deactivated. If possible, a sign will be provided in the control room to deactivate the equipment in a maintenance bypass. The period of time is administratively controlled by the plant's technical specifications.
[0345] To perform maintenance on the MPS, the switches and SFMs associated with each SFM must be There are two associated switches, the non-operation switch on the front of the FM, which are used for maintenance and repair. This allows you to take the SFM out of service for maintenance purposes. The safety function is tripped based on the position of the trip / bypass switch for that SFM. By activating the inactive switch, non-volatile memory is Allows modification of adjustable parameters and set points in memory. Trip Bypass Switch The switch state input is received through a hardwired module (HWM), which The switch position is converted into a logic level signal and this information is placed on the backplane. .
[0346]
[0346] The data packet received from the SFM stores the location of the non-operating switch on the SFM. The Scheduling and Bypass Module (SBM) receives the data packets from the SFM. Determines whether the SFM is out of service based on the out-of-service switch location information received in the packet. The SFM is out of service and the trip / bypass switch is in bypass. In this case, the SBM will schedule a no-operation or no-trip condition regardless of the output of the SFM. The result is transmitted to the voting module (SVM). The two-out-of-four voting agreement logic is changed. Instead, one isolated group provides no trips to the SVM and is received by the SVM. Two of the remaining three channels must vote to trip / operate. In this case, the MPS still provides the redundancy and Depending on the level of continuity, safety functions can be performed.
[0347]
[0347] If the SFM is out of service and the trip / bypass switch is in trip In this case, the SBM transmits a trip / operation signal to the SVM regardless of the output of the SFM. - No changes to out-of-four voting agreement logic. SBM trips one channel. One isolation group provides trip / activation input to the SVM, thereby One other separate group issues votes to determine whether a trip / operation is triggered for a particular safety function. In this case, the MPS is in a "partial trip" state. However, it still meets the single failure criterion and provides the safety function with the required redundancy level. It is possible to do this.
[0348] In some embodiments, the maintenance trip / bypass switch is located in the MPS equipment room. These switches can be located on panels in separate group cabinets. The switch is connected to the HWM in the SFM chassis (shown in Figure 13).
[0349]
[0349] If the SFM is not out of service, the SBM is calculated and transmitted from the SFM to the SBM. If the SBM does not receive a valid response from the SFM, If not, an alarm is generated and the SBM uses the trip / bypass switch position to Determines what to transmit to the VM.
[0350]
[0350] The SFM non-operational feature allows for specific adjustments during shutdown and fuel cycles. This allows for periodic parameter updates of the parameters that can be used to verify the operability of the safety functions. Periodic testing is required to
[0351]
[0351] The MPS is designed to allow for periodic corrective maintenance during normal operation and shutdown. To perform maintenance, the safety function must be deactivated. The channel receiving this signal will be in a tripped state or bypassed, subject to technical specification limitations.
[0352]
[0352] For test or corrective maintenance, safety functions within an isolation group may be bypassed or tripped. The RTS and ESFAS divisions do not have a bypass function, The module has continuous self-test coverage. The reactor trip breaker is Therefore, they can be tested at output by opening one breaker at a time. This allows the reactor trip circuit to be shut down without the need for a maintenance bypass associated with the reactor trip circuit breaker. Most of the ESFAS components are trip or engineering breaker test capable. Since this will cause the activation of the ESF, it is not tested at power output, but must be tested during shutdown. Manual trip and operating switches within the MCR cannot be tested at the output. , are tested during shutdown in accordance with the plant's technical specifications.
[0353]
[0353] Four reactor trip breakers are associated with each of the two divisions of the MPS. The MPS division is designed to open a single division of the circuit breaker, The drive mechanism is configured to disconnect, thus causing a reactor trip (Figure 12 During the trip operation logic test, the reactor trip breaker undervoltage trip mechanism The trip signal of the MPS is not activated. The MPS logic and the reactor trip breaker are redundant. The test is designed to allow online testing.
[0354] The part of the MPS that is not tested at output is the operational priority logic on the EIM. This activates the manual MCR switch and enables the unsafe control, which provides input to the override logic. The activation priority logic consists of individual components and includes a switch. directly cause reactor shutdown or adversely affect operation. The priority logic is tested when the reactor is shut down. For simplicity of the operational priority logic circuitry, Therefore, testing during the shutdown state ensures that the operational priority logic functions are performed when required. It is enough to
[0355] For purposes of maintenance bypass, the NMS is treated as a sensor input to the MPS, and the MPS provides bypass capability for maintenance purposes.
[0356] If the MPS channel is administratively bypassed or deactivated, the control Signs will be provided in the room. The period allowed for non-operation in maintenance bypass is , administratively controlled by technical specifications.
[0357] MPS equipment status information is automatically sent to the MCS and SDIS. The SDIS provides the operator with continuous indication of bypass, trip, and out-of-service conditions. The display of the state information allows the operator to identify the operability of the safety function.
[0358]
[0358] A set of Division I and Division II manual switches shall be used to manually operate the protective measures. provided for initiation and connected to the corresponding HWM of the RTS and ESFAS divisions The input signals to the HWM are isolated, converted to logic level signals, and distributed on the backplane. These signals are placed in the associated FPGA logic downstream of the automatic signal generation. The EIM priority logic is provided to the associated EIM operation priority logic.
[0359]
[0359] Division I and Division II manual actuation switches are located within the MCR as follows: Each manually operated switch is provided for its associated division. The division switches operate the respective protection functions within the Manually operated switches are not limited to those sufficient to complete the safety function. However, reactor trip, ECCS operation, decay heat removal operation, containment isolation, demineralized water system Isolation, chemical and volume control system isolation, pressurizer heater trip, and low temperature overpressure protection A hardwired manually actuated switch input can be configured in the MPS via a digital configuration Because of the downstream nature of the element, failure of the MPS automatic function prevents manual initiation of the required protective action. No.
[0360]
[0360] This is made possible by the operator using a safety-related enable unsafe control switch. If this is the case, the ability to manually control the ESF equipment at the component level will be compromised by concerns about the MCS and the HWM. It is possible to use all individual hardwired inputs. These signals are then connected to the E Any automatic or manual safety-related signals are input to the operational priority logic on the IM. Overrides signals and takes priority within the operational priority logic. Use safety-related override switches for operating equipment to prevent automatic signals from being overridden. Safety signals can be prioritized.
[0361]
[0361] Override switches are provided for the following functions: The switch can contain two switches, one for each division. The override switch overrides the containment water injection and drainage systems and valves. The manual override switch can generate an alarm when activated. Manual controls are administratively controlled by approved plant procedures.
[0362]
[0362] Specific embodiments of the subject matter have been described. Other embodiments, modifications, and variations are possible. Any permutation of the embodiments that would be apparent to one skilled in the art is within the scope of the following claims. For example, the actions recited in the claims can be performed in a different order and still Desired results can be achieved. Therefore, the above description of the exemplary embodiment These and other aspects of the present disclosure are not intended to define or constrain the present disclosure without departing from the spirit and scope of the present disclosure. , other variations, substitutions, and alterations are also possible.
Claims
1. A plurality of functionally independent modules, each of said modules being a part of a reactor safety system. receiving a plurality of inputs from the system and taking a safety action based at least in part on the plurality of inputs; each of said functionally independent modules is configured to logically determine a digital location; Multiple functional modules with digital or combined digital and analog modules and independent modules, an analog module electrically coupled to one or more of said functionally independent modules; Modules and receiving a decision on the safety action based at least in part on the plurality of inputs; one or more reactor safety modules communicatively coupled to said plurality of functionally independent modules; All actuators; A reactor protection system comprising:
2. Activation of an input to the analog module is performed by one of the functionally independent modules.
10. The nuclear reactor protection system of claim 1, wherein at least one overrides the one or more actions. Protection system.
3. 10. The method of claim 1, wherein the analog module comprises only analog circuitry. Reactor protection system.
4. At least one input to the analog module includes a manual override input. the analog module, upon activation of the manual override input, configured to override the digital operation of at least one of the established modules.
2. The nuclear reactor protection system of claim 1, wherein:
5. At least one input to the analog module includes a manual bypass input; an analog module that, upon activation of said manual bypass input, configured to bypass at least one digital operation of the Item 1. A reactor protection system according to item 1.
6. At least one input to the analog module includes a manually actuated input, a log module that, upon activation of said manually actuated input, 10. The method of claim 1, wherein the method is configured to operate at least one digital operation of: Reactor protection system.
7. One or more outputs from the analog module are connected to the buffer of the reactor protection system. and the plurality of functionally independent modules are provided as inputs through a clock plane.
10. The reactor protection system of claim 1.
8. The analog module includes a first analog module, and the reactor protection system M, a second analog module; An Engineered Safety Facility Actuation System (ESFAS) comprising: A first subset of modules receives a plurality of ESFAS inputs and performs a calculation based on the ESFAS inputs. logically determining the operation of the ESFAS component based at least in part on the first action; an analog module in the first subset of the plurality of functionally independent modules; an engineered safety facility activation system electrically coupled to said functionally independent modules; Stem (ESFAS) and A reactor trip system (RTS) comprising: a second subset of the plurality of RTS inputs, the plurality of RTS inputs being at least partially and logically determining the operation of the RTS component based on the second analog module: The functionally independent modules of the second subset of the plurality of functionally independent modules a reactor trip system (RTS) electrically coupled to the module; 10. The reactor protection system of claim 1, comprising:
9. Each of the plurality of functionally independent modules 10. The method of claim 1, wherein the method provides protection from a single failure propagating to any other of the Reactor protection system.
10. The reactor safety system comprises an engineered safety facility actuation system (ESFAS). , the plurality of functionally independent modules receive a plurality of ESFAS inputs, logically determine the operation of ESFAS components based at least in part on SFAS inputs; 2. The reactor protection system of claim 1 .
11. The plurality of functionally independent modules provide redundant ESFAS voting divisions.
11. The reactor protection system of claim 10,
12. The reactor safety system includes a reactor trip system (RTS), A number of functionally independent modules receive a plurality of RTS inputs and perform a number of functions on the RTS inputs.
10. The method of claim 1, wherein the RTS component is logically determined to be activated based at least in part on the Reactor protection system.
13. The plurality of functionally independent modules provide redundant RTS voting divisions.
13. The reactor protection system of claim 12.
14. The analog module converts the non-safety related signals to analog voltage levels, and By passing the analog voltage levels through the backplane to the associated function modules.
10. The method of claim 1, wherein the non-safety related signals are electrically isolated from the safety related system. Sub-reactor protection system.
15. At least one of the functionally independent modules is the analog module an instrument interface with at least one hardwired analog input signal from 10. The reactor protection system of claim 1, comprising an EIM.
16. The EIM controls the at least one hardware input signal in response to the at least one digital input signal. and an APL circuit that prioritizes the hard-wired analog input signal.
16. The reactor protection system of claim 15.
17. The at least one digital signal includes a safety-related signal, and the APL circuit 17. The method of claim 16, wherein the digital signal is prioritized over a hardwired analog signal. Sub-reactor protection system.
18. The at least one hardwired analog input signal may be from a manually actuated switch. a safety-related signal, and the APL circuitry converts the digital signal into the hardwired door signal; 17. The nuclear reactor protection system of claim 16, wherein the analog input signal is prioritized.
19. The at least one hardwired analog input signal includes a reactor trip signal.
20. The reactor protection system of claim 18, including:
20. the at least one hardwired analog input signal from a manually operated switch; a hardwired analog input signal; 17. The nuclear reactor protection system of claim 16, wherein the digital signal is prioritized over the digital signal.
Citation Information
Patent Citations
reactor protection system
JP1998506476A
Plant protection system and method using field programmable gate array
US20110202163A1
Method and platform to implement safety critical systems
US20110313580A1
Nuclear reactor protection systems and methods
WO2015112304A2