Nuclear Safety Logic Verification via Static and Dynamic Methods

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing safety protection systems for nuclear reactors, such as those described in JP-2005-249609-A, are unable to achieve the high level of safety integrity level (SIL4) required by IEC61508 standards due to limitations in verification methods, primarily relying on dynamic simulation verification which only reaches SIL3 levels.

Innovation Solution

The proposed solution involves a verification method that combines static verification by property description using a formal verification language with dynamic verification by simulation for the application logic, including macro logics, operation control units, and data storage areas, to ensure a high level of safety equivalent to SIL4. This involves configuring the safety protection system with macro logics that perform floating-point operations and using a selector to manage data for these operations, along with an output value processing unit to handle processed data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only dynamic verification by simulation is used, then the verification process is simpler and faster, but the safety level can only reach SIL3 at best

Engineering Contradiction:
Improvesafety levelVSAvoidverification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification process is segmented into two distinct phases: static verification by property description and dynamic verification by simulation. Each phase serves a specific purpose - static verification establishes formal safety properties and invariants, while dynamic verification validates behavior under specific test cases. This segmentation allows the system to achieve SIL4 safety level by combining the rigorousness of static verification with the practical validation of dynamic verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Static verification by property description is performed as a preliminary action before dynamic verification. The formal verification language defines safety properties, invariants, and constraints that must be satisfied before the system undergoes simulation testing. This preliminary formal verification ensures that the basic safety architecture is correct before investing resources in extensive simulation testing.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If static verification by property description is performed for all components, then the safety level reaches SIL4, but the verification time and computational resources increase

Engineering Contradiction:
Improvesafety levelVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system divides verification efforts into two segments with different resource requirements. Static verification by property description is applied to critical safety functions and core logic components where formal verification is most beneficial. Dynamic verification by simulation handles less critical components and provides comprehensive behavioral testing. This segmented approach achieves SIL4 for safety-critical elements without requiring exhaustive static verification of all system components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different verification methods are applied to different parts of the system based on their safety criticality. High-safety static verification by property description is applied to the application logic, macro logics, and safety control functions. Lower-safety dynamic verification by simulation is applied to peripheral systems and non-critical components. This local quality approach optimizes verification resources while maintaining overall SIL4 safety level for the safety protection system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10929273B2Application logic, and verification method and configuration method thereof
Publication Date: 2021.02.23 HITACHI LTD
  • US10929273B2 patent drawing
  • US10929273B2 patent drawing
  • US10929273B2 patent drawing

AI summary

A verification method for an application logic provided with one or more macro logics configured to perform a predetermined operation, a macro operation control unit configured to instruct the one or more macro logics to start the operation to cause the one or more macro logics to perform the operation, and an operation data storage area configured to store data. In the application logic, static verification by property description of a formal verification language is performed for each of the one or more macro logic, the macro operation control unit, and the operation data storage area, and dynamic verification by simulation is further performed for at least one of the one or more macro logics.