Reactor Protection Architecture Against Common-Cause Software Failures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing nuclear reactor protection systems face challenges in effectively mitigating common-cause failures caused by software or software-developed logic errors, which can defeat safety functions and compromise system reliability.
Innovation Solution
The proposed nuclear reactor protection system incorporates a modular architecture with functionally independent modules, including digital and analog components, that utilize a two-tier voting scheme and analog overrides to ensure safety actions are determined redundantly and securely, with manual override capabilities and redundant power supplies to prevent single failure propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If digital modules are used for reactor protection system operations, then automation and productivity are improved, but reliability deteriorates due to susceptibility to common-cause software failures
Solution Approach 1:
The system divides the protection system into functionally independent modules (analog module, digital modules, voting modules) where each module performs a specific function. This segmentation ensures that a failure in one module does not propagate to other modules, thereby maintaining reliability while allowing digital automation in non-critical paths.
Solution Approach 2:
The analog module serves as an intermediary that receives sensor inputs and generates actuation signals independently of digital processing. This intermediary path ensures that even if digital modules fail due to software errors, the safety function can still be executed through the analog pathway, thus resolving the reliability-automation contradiction.
2Ease of operation
If fully digital systems are implemented, then ease of operation and adaptability are improved, but reliability worsens due to common-cause software errors
Solution Approach 1:
Instead of making the entire system digital for ease of operation, the patent inverts the approach by making the critical safety path (sensor to actuator) analog and independent. This inversion ensures that the most reliability-critical path is immune to software failures, while digital systems can still provide ease of operation for non-critical functions.
Solution Approach 2:
The system changes the operational parameter of the critical path from digital to analog domain. By operating the safety-critical signal path in the analog domain with dedicated hardware circuits, the system maintains ease of operation through standardized analog interfaces while eliminating software-related reliability issues in the critical path.
3Reliability
If manual override capabilities are added to bypass digital operations, then reliability is improved by preventing digital failure propagation, but device complexity increases
Solution Approach 1:
The analog module is pre-configured with manual override and bypass capabilities that are always available but normally inactive. This preliminary preparation ensures that when digital failures occur, operators can immediately switch to the analog path without needing to reconfigure or add complex switching logic during the emergency, thus improving reliability without excessive complexity.
Solution Approach 2:
The manual override and bypass functionality is extracted as a separate, independent capability within the analog module rather than being integrated into the digital control logic. This extraction simplifies the overall system architecture by isolating the reliability-critical manual intervention path from the complex digital control system.
Data Source
AI summary
A nuclear reactor protection system includes a plurality of functionally independent modules, each of the modules configured to receive a plurality of inputs from a nuclear reactor safety system, and logically determine a safety action based at least in part on the plurality of inputs, each of the functionally independent modules comprising a digital module or a combination digital and analog module, an analog module electrically coupled to one or more of the functionally independent modules, and one or more nuclear reactor safety actuators communicably coupled to the plurality of functionally independent modules to receive the safety action determination based at least in part on the plurality of inputs.


