In the models developed by probabilistic safety analyses (PSA) and in their applications associated with nuclear power plants (NPPs), the risk importance of a particular feature can be, most generally, divided into two categories: importance with respect to the risk-increase potential and importance with respect to the risk-decrease potential. A representative measure of the first category is risk achievement worth (RAW), while a representative measure of the second category is risk reduction worth (RRW). The present paper discusses the use of RAW and RRW in achieving safe design and points out some implications of their mutual dependency on the selection of a risk-reduction strategy. A simple example is provided to illustrate the differences between the two basic strategies and point out to the main issues and conclusions.
Containment is a combination of a steel shell and concrete shield building enclosure, completely surrounding a nuclear reactor, designed to prevent the release of radioactive material in the event of an accident. The NEK (Krško Nuclear Power Plant) reactor containment building nodalization in APROS 6 computer code has been developed based on the plant’s available documents and GOTHIC nodalization. The heat structure’s data are based on USAR (Updated Safety Analyses Report) Chapter 6 passive heat structures. In all other aspects, realistic calculations based on containment geometry have been performed except for the interior concrete, which has been explicitly calculated.An original containment nodalization based on 10 control volumes is proposed, taking into account the containment layout (well‐defined physical boundaries and corresponding communication openings) and accident behaviour. The nodalization is suitable for containment thermal‐hydraulic modelling according to design basis accidents. In the end, APROS nodalization is prepared based on the same 10‐volume nodalization, for which annulus‐volume is also included in the model, connecting the reactor building to the environment. The containment model was tested for transient response for conditions, which occur in a Double‐Ended Hot Leg Guillotine Break accident.
Although of very low probability, severe accidents in spent fuel pools (SFP) in nuclear power plants (NPP) have been subject to many risk analyses during the last decade, particularly after the Fukushima events. In a number of currently operating NPPs, SFPs are located outside the reactor containment and may present a direct source of radioactivity release in the case of a rare event involving fuel damage in SFP. An important element of the SFP risk analysis is the assessment of a possible impact of a severe accident in the reactor, which is in the containment, to SFP outside the containment. The paper deals with one particular aspect of this problem and evaluates possible direct or indirect impact of the combustible gases generated in the course of reactor accident and propagated out of the containment. The methodology for assessment of possible hydrogen presence in the containment annulus, its flammability, and leakages through the penetrations toward the fuel handling building (FHB) in the case of a long-term station blackout (SBO) without successful restoration of the core cooling is described. The SBO accident sequence progression, containment conditions, hydrogen production, and its migration to the containment annulus are evaluated using the MAAP5.03 code.Particularly, the paper demonstrates that the best estimate sensitivity plant-specific deterministic analyses (by MAAP or MELCOR) would be needed to evaluate more realistically containment leakage distribution, including a more detailed presentation of connections between FHB/SFP and the containment, as well as a more detailed model of adjacent buildings (even if the analysis shows that the probability of flammability conditions due to a leakage of combustible gasses from the containment in adjacent areas is small) due to:Necessity for adequate PSA (probability safety assessment) model linkage of the at-power PSA event tree (ET) with the SFP event trees (S-ET) in the full-plant PSA model to justify the probability of such scenario,Necessity for plant operators and Technical Support Centre (TSC) to take into account a such situation and proactively activate necessary mitigative measures to prevent accumulation of combustible gasses in the annulus or adjacent FHB.
Being a facility with potential for radioactive release, any nuclear power plant (NPP) is, over its operating life time, permanently subject to numerous safety reviews with different scopes and objectives. The reviews may be initiated and implemented by various stakeholders, including regulators, utilities or industry. Some of them are, by their nature, general and extensive in terms of different safety areas or safety attributes which are covered. An example of such a review is a Periodic Safety Review (PSR) which is promoted by the International Atomic Energy Agency (IAEA) and a number of national safety authorities in Europe and worldwide. The others may, depending on the objective, be targeted at particular safety area (e.g., ageing management or equipment qualification or safety analyses). Both of the mentioned cases (single general review or multiple targeted reviews over a time period) can generate an inventory of observations (“findings”) or “issues” which need to be addressed but may be very different in their nature and implications, as well as in benefits or resources associated with their resolutions. For some issues a resolution may be straightforward. For others, it may require a feasibility study and identification of options for possible resolution. Also, in some cases the resolution is simply a “must” (e.g., discrepancy from licensing basis) while in some other cases it may be a matter of balance (e.g., effectiveness of maintenance program). Furthermore, while some of the issues may be directly related to operational safety (e.g., non-compliance with single failure criterion or aging-related degradation of safety features), for some others the link to operational safety may not be explicit (e.g., comparison of safety bases against the newly emerging methodologies or issues observed with regard to so called “soft factors”). The paper discusses types of different observations or issues which may come from general or targeted safety reviews and outlines some basic principles for their comparison and prioritizing with regard to possible safety impacts, which is many times needed for the purpose of developing an action plan for safety improvements.
In the project NARSIS – New Approach to Reactor Safety ImprovementS – possible advances in safety assessment of nuclear power plants (NPPs) were considered, which also included possible improvements in the field of management of low probability accident scenarios. As a part of it, a supporting software tool for making decisions under severe accident management was developed. The mentioned tool, named Severa, is a prototype demonstration-level decision supporting system, aimed for the use by the technical support center (TSC) while managing a severe accident, or for the training purposes. Severa interprets, stores and monitors key physical measurements during accident sequence progression. It assesses the current state of physical barriers: core, reactor coolant system, reactor pressure vessel and containment. The tool gives predictions regarding accident progression in the case that no action is taken by the TSC. It provides a list of possible recovery strategies and courses of action. The applicability and feasibility of possible action courses in the given situation are addressed. For each action course, Severa assesses consequences in terms of probability of the containment failure and estimated time window for failure. At the end, Severa evaluates and ranks the feasible actions, providing recommendations for the TSC. The verification and validation of Severa has been performed in the project and is also described in this paper. Although largely simplified in its current state, Severa successfully demonstrated its potential for supporting accident management and pointed toward the next steps needed with regard to further advancements in this field.
In all operating modes of a nuclear power plant a lot of activities take place, including maintenance, surveillance testing and plant modifications. Some of these activities can impose temporary increase in risk level, as they may change the status of equipment important to plant safety. Such risk increases are usually controlled by risk monitoring, which considers changes in risk due to changes in the status (e.g. availability) of plant systems and functions. Risk monitors are, in many cases, designed and operated to be system-oriented (or function-oriented), as they focus on “measuring” the risk associated with different system configurations (from where comes the often used term “configuration risk management”). On the other hand, components of plant systems are placed in various locations and at various floors (elevations) of plant buildings. Piping, as well as cabling, is routed through one or more buildings. Equipment performing different functions is, sometimes, located near each other due to architectural limitations. Where required, barriers are applied in order to ensure physical separation and independency. Due to these reasons, a particular plant area (compartment, room, part of a large room,…) can contain a variety of mechanical, electrical and / or other equipment with different safety implications. As well as system components, plant areas are also related to each other, with different degrees of relative importance. Since activities performed in different plant areas can imply changes, actual or potential, in the status of associated equipment, structures and / or barriers, there is also a need that risk monitoring considers the area-oriented aspects, beside considering those which are system-oriented or function-oriented. Risk impact of an activity taking place in a particular plant area can be considered in terms of changes (potential or actual) to its three components: 1) likelihood of initiators which can be triggered by equipment in the area (but which are not mitigated by any of the equipment in the same area); 2) mitigating capability regarding the initiators which are not triggered in this area; 3) likelihood of initiators triggered in this area and mitigating capability regarding the same initiators. Activity in a particular plant area may be related to none or to any combination of the three risk impact components. Normally, risk impact under 3) is limited by the architectural engineering principles (because it may become very large risk contributor). However, it may be present in some residual form and it cannot be excluded (as demonstrated by area-related risk studies performed in the past, such as internal fire and internal flooding analyses). With activity taking place in a particular area, the relevant importance of any other plant area (and, hence, potential risk impact of any activity that may be planned to go on at the same time) is then considered in terms of, respectively: 1) whether it contains the equipment relevant for mitigation of initiators that can be triggered in the considered area; 2) whether it includes the potential for triggering an initiator which is mitigated by the equipment located in the considered area; 3) whether it contains the relevant mitigation equipment or include the potential for relevant initiators. The paper discusses these and other related issues and describes some basic concepts for the area-oriented risk management.
The Slovenian Krško Nuclear Power Plant (NEK) model was built in using APROS - Advanced PROcess Simulation environment. The basis for the this model was the RELAP5/MOD3.3 Engineering Handbook, the model was updated to the 26th cycle and also includes the upflow conversion modification. A detailed model nodalisation was created for each system and every system was separately validated. The current model covers the primary circuit with the core kinetics model, the secondary circuit and their control systems. The steady state of the APROS NEK model already having been validated, the plan now is to validate the model for some transients and design basis accidents. In this article the plant behaviour after the manual reactor trip is analysed in detail. Two scenarios of the manual reactor trip transient are performed, where either the Main Steam Isolation Valve (MSIV) closes after 60s – case A, or remains open – case B. After the manual reactor trip from the 100% power, the control system signal actuations and their times were followed and then the responses of different affected systems were being observed. All those recorded values were then compared with the identical transient performed on the similar NEK model with the RELAP5/MOD3.3 system code. This procedure allowed to bring the current APROS NEK model one step forward towards being assured to have accurate calculations.
Fukushima Daiichi NPP accident showed that plant technical support center (TSC) in an extreme and rare external event (design extended condition (DEC)) can have a problem in the case of coincident loss of decay heat removal from the core (possibly resulting in significant core damage) and loss of decay heat removal from spent fuel pool. From the point of view of prioritizing severe accident management strategies it looks like the priority mitigation action should be to reestablish the emergency core cooling in the reactor pressure vessel. The reason is the longer time window available before the water inventory in the spent fuel pool would be evaporated and spent fuel exposed to overheating. However, if such actions would not be successful and reactor core would, consequently, be damaged, potential design basis leakage (or even greater leakage) from the containment to the fuel handling building (FHB) can affect already established TSC measures or operator accessibility to FHB, or it can jeopardize functioning of the systems, structures and components due to radioactive releases and presence of hydrogen (independently of the fact that containment atmosphere can be inerted by steam or that containment may be equipped with passive autolytic recombiners (PARs)). Paper describes an engineering evaluation of possible hydrogen presence in the containment annulus, its flammability and leakages through the penetrations toward FHB in the case of long term station blackout (SBO) without successful restoration of the core cooling in the reactor pressure vessel. SBO accident sequence progression and amount of produced hydrogen is evaluated by MAAP code.
In using risk-informed approaches for ensuring safety of operating nuclear power plants (NPPs), risk importance measures obtained from probabilistic safety assessments (PSAs) of the plants are integral elements of consideration in many cases. In PSA models and applications associated with NPPs the risk importance of a particular feature (e.g. function, system, component, failure mode or operator action) can be, most generally, divided into two categories: importance with respect to risk increase potential and importance with respect to risk decrease potential. The representative of the first category, as used for practical purposes, is Risk Achievement Worth (RAW). Representative of the second category, as mentioned in consideration of risk importance, is Risk Reduction Worth (RRW). It can be shown that the two risk importance measures, RAW and RRW, are dependent on each other. The only parameter in this mutual dependency is probability of failure of the considered feature. The paper discusses the relation between RAW and RRW and some of its implications, including those on the general strategies for the reduction of risk imposed for the operation of the considered facility. Two general risk reduction strategies which are considered in the discussion are: a) risk reduction by decreasing the failure probability of the considered feature; and b) risk reduction while keeping the failure probability of the considered feature at the same level. Simple examples are provided to illustrate the differences between two strategies and point to main issues and conclusions.
The paper provides an overview of the regulatory design requirements for new reactors addressing Single Failure Criterion (SFC) in accordance to international best-practices, particularly considering the SCF relation to in-service testing, maintenance, repair, inspection and monitoring of systems, structures and components important to safety. The report [1] discusses the detailed comparison of the current SFC requirements and guidelines published by the IAEA, WENRA, EUR and nuclear regulators in the United States, United Kingdom, Russia, Korea, Japan, China and Finland. However, this paper presents the summary of work from [1] and 2major examples from IAEA and WENRA and applications for small and modular reactors.
The project NARSIS - New Approach to Reactor Safety ImprovementS - is making scientific steps towards addressing the update of some elements required for the safety assessment of nuclear power plants. These improvements mainly concern: Natural hazards characterization, in particular by considering concomitant external events, either simultaneous-yet-independent hazards or cascading events, and the correlation in intra-event intensity parameters. Vulnerability of the elements to complex aggressions, with the integration of new approaches such as vector-based fragility surfaces and reduced models. Better treatment of uncertainties through adoption of probabilistic framework for vulnerability curves and non-probabilistic approach to constraining the "expert judgments". Develop decision support tool for severe accident management. In the first step, the referential nuclear power plant (NPP) is identified: pressurized water reactor NPP with two loops. In the second step, the severe accident management guidelines for referential NPP are characterized. In the third step, the relevant scenarios are identified, hazard-induced damage states defined and state-specific accident progression event tree for demonstration purposes are developed. In the fourth step, the applicable deterministic analyses of severe accidents are performed. In the last, fifth, step, the decision support tool for severe accidents - Severa is developed. Its purpose is a prototype demonstration-level decision support system aimed at supporting the technical support center (TSC) while managing a severe accident. Severa represents, stores and monitors selected physical measurements of the NPP. It assesses the current state of barriers: core, reactor coolant system, reactor pressure vessel and containment. The prediction of future accident progression, if no action is undertaken is one of basic functions. The support tool provides a list of possible management recovery strategies and courses of action. The applicability and feasibility of possible actions in the given situation is identified. For each action the prediction of the consequences in terms of probability of the last barrier (containment) failure and estimated time window for failure. At the end, Severa evaluates and ranks the feasible actions, providing recommendations for the TSC.
Nuclear power plants produce electricity with relatively low operational costs and low impacts on the environment, but are also associated with the fear of severe accidents. These are extremely rare, but once they occur, they put an immense pressure on the accident management team. In this paper, we report about an ongoing development of a decision support system called Severa, aimed at supporting the decision-making team during the course of an accident or a training exercise. The software is being developed in the context of the EU H2020 project NARSIS. The system assesses the plant damage state, predicts possible accident progressions and assesses available management actions and their consequences. Two already implemented modules are presented: a monitoring and radioactive-release assessment module. The methodological approach primarily relies on qualitative rule-based multi-criteria models, but also includes other techniques: data analysis, probabilistic safety assessment and event-tree modelling.
The paper discusses the framework for a risk-informed root cause analysis process. Such process enables scaling of the analysis performed based on the risk associated with the undesired event or condition, thereby creating tiers of analysis where the greater the risk, the more sophisticated the analysis. In a risk-informed root cause analysis process, a situation is normally not analyzed at a level less than what actually occurred. However, a situation may be investigated as though the consequence were greater than actually happened, especially if only slight differences in circumstances could result in a significantly higher consequence. While operational events or safety issues are normally expected to result only with negligible or marginal actual consequences, many of those would actually have certain potential to develop or propagate into catastrophic events. This potential can be expressed qualitatively or quantitatively. Risk-informing of root cause analysis relies on mapping the event or safety issue into a risk matrix which, traditionally, is a two-dimensional probability-consequence matrix. A new concept employed in the risk matrix for root cause analysis is that, while the probability reflects the observed or expected range of values (retaining, thus, its “traditional” meaning), the consequence reflects not only the observed or materialized impact (such as failure of equipment) but, also, its potential to propagate or develop into highly undesirable final state. The paper presents main elements of risk-informed root cause analysis process and discusses qualitative and quantitative aspects and approaches to determination of risk significance of operational events or safety issues.
The paper presents preliminary severe accident (SA) simulations performed to generate a database of plant states dedicated to be used with Severe Accident Management Guidelines Decision Making Tool (SAMG DM). The novel software is being developed in the framework of the NARSIS Horizon-2020 research project. It is intended to be a supporting tool for the SAMGs implementation, Emergency Preparedness and selection of Severe Accident Management (SAM) strategies. Simulations were performed with MELCOR 2.2 integral computer code for generic Nuclear Power Plant (NPP) with Gen-II Pressurized Water Reactor (PWR). The database covers results for parameters important for both in-vessel and ex-vessel phases of different accident scenarios. Two general types of scenarios are considered in the database: low-pressure and high-pressure sequences. In this paper, a comparison was prepared for two base case low-pressure scenarios, that is hot leg and cold leg LB-LOCAs without safety injection. Sensitivity simulations were performed with and without Containment Filtered Venting (CFV) as it substantially influences the containment performance. Both accidents are characterized by rapid progression with core meltdown within 2 hours and containment failure within 40 hours and eventual venting with CFV after 13-15 hours. It was observed that for the cold-leg break, the Reactor Pressure Vessel failure occurs earlier only by similar to 5 minutes. On the contrary, the containment failure is predicted to occur three hours earlier for the hot-leg LOCA.
Safety is one of the major concerns connected with the operation of nuclear power plants. Severe accidents are very rare, but may cause very large consequences. The prevention and management of accidents requires carefully designed safety plans, guidelines and decision support tools. In this paper, we present a conceptual design of a decision support system for severe accident management. The system is aimed at providing essential information to the accident management team, in terms of the assessment of the damage state, prediction of possible progressions of the accident, and assessment of available management actions and their consequences. The system will employ components and models developed through probabilistic safety assessment and qualitative multi-criteria decision modeling. The software is being developed in the context of the EU H2020 project NARSIS. Its first prototype is expected in 2020.
A Model of Krsko Nuclear Power Plant (NEK) Intermediate Building (IB) was developed in computer code Apros 6. In order to validate the model, simulations performed in Apros 6 environment were compared to similar calculation results made with the coupled RELAP5 and GOTHIC codes.A double-ended Main Steam Line Break (MSLB) in IB model was simulated in Apros 6, representing best estimate analysis of transient. The break was assumed between Steam Generator (SG) outlet and Main Steam Isolation Valve (MSIV), so the blowdown of affected SG could not be prevented. In first part, Apros stand-alone IB model results was compared to selected reference mass energy release vectors used in GOTHIC calculations. After stand-alone IB model was validated to GOTHIC results, Stand-alone IB model was integrated into large Apros model, for simulation of primary and secondary systems response of NEK model to MSLB transient. MSLB energy release in coupled Apros model of NEK was adjusted on the point of break to achieve similar mass release parameters than previous GOTHIC reference vectors, previously used to validate stand-alone model of MSLB in IB.Simulated results of Apros MSLB in IB transient present pressures, temperatures and break flows in IB rooms. Large coupled model presents additional comparison of multiple NEK primary and secondary system response parameters to MSLB transient for first 5000 seconds.
At the beginning, we introduce two basic terms which will be used in all considerations to come. Both of them are “events”:
The Nuclear Engineering and Technology for the 21st Century monograph series provides current and future engineers, researchers, technicians and other professionals and practitioners with practical, concise but key information concerning the nuclear technologies from areas of medical applications, mining, processing and manufacturing, environmental monitoring to safe and energy-efficient plant operation and electricity generation. In using risk-informed approaches for ensuring safety of operating nuclear power plants (NPPs), risk importance measures obtained from probabilistic risk assessments (PRAs) of the plants are integral elements of consideration in many cases. Obtaining these measures in appropriate forms is helpful for decision makers and can facilitate the use of risk information.
A demonstrative example application was carried out using a simplified PRA model to calculate the component-level risk importance measures from the PRA-calculated risk importance measures of the basic events relating to the components. The simplified PRA model used for the demonstrative examples is presented in Appendix B.1. It is based on a pressurized water reactor and is built on RiskSpectrum® PRA computer code. It is pointed out that this model was developed for demonstration of risk importance measures only and should not be related to actual NPP risk.
Marko Bohanec合作论文数Jo?ef Stefan Institute;Department of Knowledge Technologies4