Nuclear Safety Channel Architecture With Two-Level Majority Voting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital control safety systems in nuclear power plants face reliability issues due to distributed software applications, inefficient majority redundancy, lack of remote manual control, and inadequate diagnostic communication, leading to potential false commands and prolonged recovery times.
Innovation Solution
Implementing a digital control safety system with a single processor per safety channel, reducing interchannel links, and using a fault-tolerant I/O bus with duplex 'point-to-point' interfaces in a tree structure for enhanced reliability, remote control capabilities, and improved diagnostic functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If distributed software applications are used across multiple processors, then system functionality is enhanced, but reliability degrades due to potential common cause failures
Solution Approach 1:
The system divides software functionality into separate safety channels (at least two independent channels), where each channel contains a complete set of protection algorithms and can operate independently. This segmentation ensures that failures in one channel do not propagate to other channels, maintaining reliability while preserving functionality.
Solution Approach 2:
Each safety channel is equipped with dedicated resources including processors, memory, and I/O interfaces specific to that channel. This local allocation of quality resources ensures that each channel can function autonomously with full capabilities, preventing common cause failures while maintaining complete system functionality.
2Reliability
If multiple digital processing devices are used with interchannel links, then redundancy is improved, but device complexity increases
Solution Approach 1:
The system extracts and eliminates unnecessary interchannel links between safety channels, keeping only essential communication paths. Each safety channel operates independently with dedicated I/O interfaces, removing complex cross-channel connections while maintaining adequate redundancy through independent channel operation.
Solution Approach 2:
Instead of connecting multiple processing devices across channels with extensive interchannel links, the system inverts the approach by giving each channel its own complete processing capability and removing redundant connections. This simplifies the overall device complexity while preserving reliability through independent channel operation.
3Adaptability or versatility
If extensive interchannel communication paths are implemented, then data exchange capability is improved, but recovery time increases when failures occur
Solution Approach 1:
The system removes unnecessary interchannel communication paths, retaining only essential data exchange capabilities within each safety channel. This extraction of redundant communication paths reduces the complexity and potential failure points, enabling faster recovery when failures occur while maintaining adequate data exchange capability for safety functions.
4Power
If distributed processing is used, then computational capability is enhanced, but software development difficulty increases
Solution Approach 1:
The system segments software development into independent safety channels, where each channel contains complete protection algorithms that can be developed, tested, and verified separately. This segmentation reduces software development difficulty compared to distributed processing while maintaining enhanced computational capability through parallel channel operation.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This configuration enhances the reliability and availability of the control safety system by reducing common cause failures, eliminating false commands, and enabling efficient fault localization and rapid recovery through encapsulated software development and two-level majority redundancy.
Implementation Method 1
Physically separated safety channels are cross-connected with each other by optical fiber communication paths
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to automatics and computer engineering, and can be used in I&C systems of nuclear power plants (NPP) for constructing control safety systems (CSS) of NPP. Technical result of the invention is as follows: - improvement of multichannel control safety system (CSS) reliability by means of using in every safety channel of a single processor for solving all the tasks of NPP state analysis and protection control, - exclusion of common cause failure due to encapsulated errors in software owing to the possibility of developing the entire applied software using computer-aided methods in software environment of a single processor, - enhancement of majority redundancy efficiency owing to the reduction of a number of digital processing devices to a single processor, and consequently reduction of levels of interchannel exchange and majority redundancy of those devices, - elimination of false commands sent to actuation devices due to failure of signal input devices and a processing device owing to the two-level majority redundancy, - extension of remote control and diagnosing functions due to introduction of data communication of every channel processor with the normal operation system and the main control room and emergency control room of the CSS, - reduction of restoring time and enhancement of the CSS availability due to use of fault-tolerant and diagnosed I/O bus that is built based on communications modules and duplex 'point-to-point'-type interfaces in the form of a tree-type structure. Technical result is achieved by the fact that in the digital control safety system of a nuclear plant that contains multiple identical safety channels, each channel includes process signal I/O stations IOS1-n, actuation mechanism priority control stations PCS1-m connected with the main control room MCR and emergency control room ECR, safety features automation controller (SF AC), safety feature I/O bus SF IOB for data exchange between SF AC controller and IOS/PCS stations, and is cross-connected with other safety channels by means of duplex optical fiber communication paths; the IOS station contains modules of communication with the process MCP1-k and communication module - converter of communication interfaces CIC of SF IOB bus; the PCS station contains actuation mechanism priority control modules PCM1-e and communication modules: voting communication module VCM and voting module VM of SF IOB bus; the automation controller SF AC contains safety feature automation processor module SF APM and communication modules - branching modules BM-41-p of SF IOB bus; safety feature automation processor module SF APM of every safety channel is connected with SF APM of the other safety channels by means of cross-connected links implemented based on interprocessor interfaces IPI of 'point-to-point' type built based on Ethernet interface and specific data-level communication protocol. SF IOB bus of a safety channel has a tree-type structure, the upper root node of which is SF APM of the safety channel, and the low end nodes are modules of communication with the process MCP1-k of IOS1-n stations and priority control modules PCM1-e of PCS1-m stations of its own safety channel, and priority control modules PCM1-e of PCS1-m stations of other safety channels; and intermediate nodes are communication modules: BM-41-p of automation controller, CIC of I/O stations, and VCM and VM of the priority control stations; links between the modules being in the nodes of the SF IOB bus are implemented as the lines of serial duplex 'point-to-point'-type interface; interchannel links between automation controller SF AC of each safety channel and priority control stations PCS1-m of other safety channels are implemented using fiber optic cables. Each safety channel is implemented using a single processor located in the automation processor module APM; and the majority redundancy according to the algorithm of choosing commands and data '2 out of N', where N is a number of safety channels, is implemented here at the two levels of interchannel communiations: at the level of the processors of SF APM modules, when the processor of the SF APM module of each safety channel receives commands and measured parameters from the processors of the SF APM modules of other safety channels via interprocessor interfaces IPI, and at the level of the priority control stations in communication modules VM of PCS1-m stations, when control commands come to PCS1-m stations from the processors of the SF APM modules of all safety channels via the SF IOB buses. In the PCM modules of PCS stations the output of the programmable logic circuit PLC of the actuation mechanism priority control logic PCL - (PCL PLC) is connected to the AM and via feedback links to SF AC controller of the safety channel via safety feature programmable logic circuits (SF PLC) and SF IOB bus. SF AC controllers of the safety channels are connected with the MCR and ECR via interprocessor interfaces IPI of 'point-to-point' type implemented based on Ethernet interface and specific data-level communication protocol. Automation controllers SF AC of all safety channels are connected to the normal operation system via redundant bus EN built based on switched Ethernet interface, ring structure of net switch connection, and specific data-level communication protocol. In IOS station of every safety channel, communication module CIC of the SF IOB bus is connected via separate SF IOB communication lines with the automation controller SF AC of the safety channel and with each module MCP1-k. In each safety channel, PCS stations are combined into groups of N stations; the number of PCS stations is determined by the number of safety channels; the first station of the group PCS1 is connected by the SF IOB communication line with SF AC controller of its safety channel; the other stations PCS2-N of the group are connected with SF AC controllers of other safety channels N-1; communication module VCM of each PCS station is connected with the communication module of voting according to '2 out of 4' majority principle VM of its own PCS station and communication modules VM of the other PCS stations of the group; communication module VM of each PCS station is connected via SF IOB communication lines with the priority control modules PCM1-e of this station.