Reactor Protection Architecture Against Common-Cause Software Failures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing nuclear reactor protection systems face challenges in effectively mitigating common-cause failures caused by software or software-developed logic errors, which can defeat safety functions and compromise system reliability.

Innovation Solution

The proposed nuclear reactor protection system incorporates a modular architecture with functionally independent modules, including digital and analog components, that utilize a two-tier voting scheme and analog overrides to ensure safety actions are determined redundantly and securely, with manual override capabilities and redundant power supplies to prevent single failure propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If digital modules are used for reactor protection system operations, then automation and productivity are improved, but reliability deteriorates due to susceptibility to common-cause software failures

Engineering Contradiction:
Improveautomation of safety action determinationVSAvoidsystem reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system divides the protection system into functionally independent modules (analog module, digital modules, voting modules) where each module performs a specific function. This segmentation ensures that a failure in one module does not propagate to other modules, thereby maintaining reliability while allowing digital automation in non-critical paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analog module serves as an intermediary that receives sensor inputs and generates actuation signals independently of digital processing. This intermediary path ensures that even if digital modules fail due to software errors, the safety function can still be executed through the analog pathway, thus resolving the reliability-automation contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If fully digital systems are implemented, then ease of operation and adaptability are improved, but reliability worsens due to common-cause software errors

Engineering Contradiction:
Improveease of operationVSAvoidsystem reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of making the entire system digital for ease of operation, the patent inverts the approach by making the critical safety path (sensor to actuator) analog and independent. This inversion ensures that the most reliability-critical path is immune to software failures, while digital systems can still provide ease of operation for non-critical functions.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system changes the operational parameter of the critical path from digital to analog domain. By operating the safety-critical signal path in the analog domain with dedicated hardware circuits, the system maintains ease of operation through standardized analog interfaces while eliminating software-related reliability issues in the critical path.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual override capabilities are added to bypass digital operations, then reliability is improved by preventing digital failure propagation, but device complexity increases

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The analog module is pre-configured with manual override and bypass capabilities that are always available but normally inactive. This preliminary preparation ensures that when digital failures occur, operators can immediately switch to the analog path without needing to reconfigure or add complex switching logic during the emergency, thus improving reliability without excessive complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The manual override and bypass functionality is extracted as a separate, independent capability within the analog module rather than being integrated into the digital control logic. This extraction simplifies the overall system architecture by isolating the reliability-critical manual intervention path from the complex digital control system.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12597529B2Nuclear reactor protection systems and methods
Publication Date: 2026.04.07 NUSCALE POWER LLC
  • US12597529B2 patent drawing
  • US12597529B2 patent drawing
  • US12597529B2 patent drawing

AI summary

A nuclear reactor protection system includes a plurality of functionally independent modules, each of the modules configured to receive a plurality of inputs from a nuclear reactor safety system, and logically determine a safety action based at least in part on the plurality of inputs, each of the functionally independent modules comprising a digital module or a combination digital and analog module, an analog module electrically coupled to one or more of the functionally independent modules, and one or more nuclear reactor safety actuators communicably coupled to the plurality of functionally independent modules to receive the safety action determination based at least in part on the plurality of inputs.