Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Digital Instrumentation and Control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Instrumentation and Control Digital Modernization Research Plan for Long-Term Sustainability in the Nuclear Industry

This report, developed by Idaho National Laboratory (INL) in collaboration with Oak Ridge National Laboratory (ORNL), outlines a comprehensive research plan to support the digital modernization of safety-related instrumentation and control (I&C) systems in the U.S. nuclear industry. The modernization effort is critical to ensuring the long-term safety, reliability, and economic viability of both existing and future nuclear power plants (NPPs), particularly as aging analog systems become increasingly obsolete and difficult to maintain.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

DOE Fffice of Nuclear Energy cybersecurity research, development and demonstration program plan

This document describes the Cybersecurity Research Development and Demonstration (RD&D) Program, established by the Department of Energy Office of Nuclear Energy (NE) to provide sciencebased methods and technologies necessary for cost-effective, cyber-secure digital instrumentation, control and communication in collaboration with nuclear energy stakeholders. It provides an overview of program goals, objectives, linkages to organizational strategies, management structure, and stakeholder and cross-program interfaces.

97 MATHEMATICS AND COMPUTING↗

Business Case Analysis for Digital Safety-Related Instrumentation & Control System Modernizations

This LWRS research seeks to assist in breaking the impasse which has precluded digital safety system upgrades by generating and demonstrating a process and related business case tool to enable a Business Case Analysis (BCA). The purpose of a BCA is to show such upgrades can be economically justified. This BCA methodology first systematically establishes a forecast of expected lifecycle costs for I&C identified for upgrade by: • Definitively bounding the scope of current I&C systems envisioned for upgrade. • Collecting historical labor and material usage data that bound cost contributors related to the systems to be upgraded. • Synthesizing and analyzing the data to establish lifecycle cost forecasts for the current systems. In collaboration with engineers familiar with the attributes of the digital equipment to be used in the upgrade and how it is envisioned to be applied, cost savings categories and expected savings in those categories are then identified and applied using the analysis tools developed for this purpose. The result is an estimate NPV of savings enabled by the upgrade. This includes both direct cost savings (e.g., surveillance labor costs) as well as cost avoidance items (e.g., inventory carrying costs). Finally, when utility-provided digital upgrade costs estimates are included, the resultant BCA provides an NPV for the upgrade project. Development of a useful BCA methodology requires a real-world basis. With the cooperation of Exelon Generation (“Owner”), an Exelon-owned 2-Unit BWR Station (“Station”) was used as the foundation for this research. Exelon is pursuing a digital upgrade of current, first-echelon, safety-related I&C systems at these units, including the following: • Reactor Protection System (RPS) • Nuclear Steam Supply Shutoff System (N4S) • Emergency Core Cooling Systems (ECCS) • Anticipated Transient Without Scram (ATWS) Mitigation System

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Demonstration of the Human and Technology Integration Guidance for the Design of Plant-Specific Advanced Automation and Data Visualization Techniques

Nuclear power continues to be a safe, reliable, and carbon-free electricity generating source for the United States, though the cost of operating and maintaining the current United States nuclear power plant fleet has become uncompetitive with other sources. This gap is attributed to the advent of new digital instrumentation and control technologies that other electricity generating industries are currently leveraging to streamline work and greatly reduce operating, maintenance, and support costs. Digital instrumentation and control systems and control room modernization offers significant opportunities to reduce operating and maintenance costs to ensure the continued operation of the existing United States light-water reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Safety-Related Instrumentation and Control Pilot Upgrade: Initial Scoping Phase Implementation and Lessons Learned

In May 2016, the U.S. Nuclear Regulatory Commission (NRC) staff provided a digital instrumentation and control (I&C) regulatory infrastructure integrated action plan to the NRC for approval. One of the objectives of that plan was to establish a clear regulatory structure with reduced regulatory uncertainty to enable the expanded safe use of digital I&C in commercial nuclear reactors while continuing to ensure safety and security. To achieve this end, the NRC, with collaboration from industry, developed a streamlined License Amendment Request Alternate Review (AR) process for safety-related (SR) digital I&C upgrades. In spite of this effort, the industry has remained reluctant to perform such I&C upgrades because of perceived regulatory and financial risks associated with being the first or an early adopter of the AR process for SR I&C upgrades. The U.S. Department of Energy Light Water Reactor Sustainability Program at the Idaho National Laboratory performed Initial Scoping Phase research to help break this impasse by supporting a SR I&C Pilot Upgrade, working with MPR Associates, ScottMadden Inc., and Exelon Generation. Exelon’s Limerick Generating Station (LGS) was selected as the target for this research. This paper summarizes the Initial Scoping Phase engineering and operations, licensing, and project management activities necessary to bound the scope, schedule, and estimated cost of the project sufficiently to enable utility management authorization of Conceptual Design Phase activities. These efforts and associated products are intended to provide a template to support larger industry efforts to perform similar upgrades as a foundation stone for a digital transformation that will improve plant safety, reliability, and operational performance while lowering plant total cost of ownership. As a result of the combined effort of Exelon Generation and research participants, Conceptual Design Phase activities for the subject upgrade at LGS were approved by Exelon. Further, the U.S. Department of Energy also awarded a $50 million cost share award to Exelon in order to pave the way for SR I&C modernization and associated control room upgrades across the U.S. nuclear fleet. Additional research reports are planned for the Conceptual Design Phase, Detailed Design Phase, and the Implementation Phase of the LGS project to document the process followed and promulgate lessons learned to industry.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Business Case Analysis for Digital Safety-Related Instrumentation & Control System Modernizations

The commercial nuclear sector faces unprecedented financial challenges driven by low natural gas prices and subsidized renewables in a marketplace that does not reward carbon-free baseload capacity. These circumstances, along with increasingly antiquated labor-centric operating models and analog technology, have forced the premature closure of multiple nuclear facilities and placed a much larger population of nuclear power stations at risk. Nuclear plant economic survival in current and forecasted market conditions requires an efficient and technology-centric operating model that harvests the native efficiencies of advanced technology. This is analogous to transformations in nearly every other industry. In light of previous industry experience in modernizing safety Instrumentation and Controls (I&C) systems, nuclear utilities are reluctant to pursue these upgrades due to uncertainty in licensing and cost.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Technical Specification Surveillance Interval Extension Using Self-Diagnostics

As part of the Light Water Reactor Sustainability program, an ongoing research effort is being conducted on technical specifications surveillance interval extension of digital equipment in nuclear power plants. The research team is led by Idaho National Laboratory and includes Pacific Northwest National Laboratory, Technology Resources, and Oak Ridge National Laboratory. This research focuses on developing methods for applying the U.S. Nuclear Regulatory Commission (NRC)–approved guidance to implement a licensee-controlled, risk-informed surveillance frequency change program in digital instrumentation and control (I&C) systems that include self-diagnostics and online monitoring (OLM) capabilities. Although approved methods exist for extending technical specifications (TS) surveillance test intervals (STIs) for general equipment, including analog I&C equipment, gaps remain in technology and guidance on crediting newer digital equipment’s internal self-diagnostics and OLM characteristics. Previous research described a general methodology for crediting internal self-diagnostics for extending surveillance test intervals. The methodology used self-diagnostics to detect—and credited recovery from—failure. Self-diagnostics were also applied for performance monitoring during the extended surveillance interval. This report discusses the status of recent activities to evaluate the previously developed methodology using a pilot study. Although both a utility partner for a pilot study and a specific digital asset were identified in FY2020, delays in obtaining proprietary information resulted in a limited ability to fully evaluate the methodology, and further interactions were complicated by the COVID pandemic. Therefore, at that time, the use of public-domain information—along with current processes for surveillance interval extension through a surveillance frequency control program—identified the need to fully assess diagnostic coverage as part of the pilot study. Furthermore, self-diagnostics were also identified as a potential option to replace the drift analyses conducted as part of current STI extension procedures. In FY2022, the project was reconstituted with the industry partner, and information and data were made available by the industry partner to the research team for review. The shared information included failure event descriptions and data for a digital I&C system since its implementation, as well as recent STI extension interval reports developed by the utility partner on that digital I&C system. This report presents an evaluation of this information and data and describes an application of the proposed methodology cited above. The methodology seeks to take advantage of the self-diagnostics and OLM capabilities to reduce risk or reduce the level of qualitative monitoring assessment needed to perform a risk-informed STI extension using existing NRC approved guidance or both. Addressing these issues of STI extension by crediting self-diagnostics is likely to result in benefits for current and future nuclear power plant (NPP) operations, including lowering the barriers to adoption of digital I&C systems and increasing cost savings by deferring or eliminating unneeded preventive maintenance (tasks or checks or activities). Specifically, self-diagnostic and OLM capabilities of newer digital equipment being installed in non-safety and safety applications are designed to detect failures, provide early warning of potential failures, and notify plant operators to take appropriate action to reduce out of service (OOS) time thus protecting safety margins. Moreover, the equipment is expected to provide information that time-related operational degradation is identified early to ensure timely and planned corrective actions instead of a reactive and unplanned approach ahead of an extended-surveillance interval.

42 ENGINEERING↗

Dynamic Model Agnostic Reliability Evaluation of Machine-Learning Models Integrated in Instrumentation & Control Systems

In recent years, the field of machine learning (ML), specifically neural networks, has grown significantly and has spurred research in its applicability to digital instrumentation and control systems (DI&C). While ML models have shown promise in operational contexts, the trustworthiness of using such algorithms has not been adequately assessed. Failures of ML integrated systems are not well understood, and the lack of comprehensive risk modeling can degrade the trustworthiness in these systems. In recent reports by the National Institute for Standards and Technology (NIST) [1] and the Nuclear Regulatory Commission (NRC) [2], they indicate that trustworthiness in ML is a critical barrier and will play a vital role in the safe, accountable, and secure operation of intelligent systems. Thus, in this work, we demonstrate a dynamic model-agnostic method to quantify the relative reliability of AI/ML predictions by incorporating out-of-distribution (OOD) detection on the training dataset. It is well documented that most ML algorithms excel at interpolation (or near-interpolation) tasks but experience significant performance degradation at extrapolation. The method, referenced as the Laplacian distributed decay for reliability (LADDR), determines the difference between the operational and training datasets which can used to the relative reliability of AI/ML predictions. LADDR is then demonstrated on a feedforward neural network based digital twin used for the prediction of safety significant factors during a loss-of-flow transient. LADDR is used to demonstrate how training data can be used as evidence to support the relative reliability of ML/AI predictions enhancing the overall trustworthiness of the system.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

Overview and Recommendations for Cyber Risk Assessment in Nuclear Power Plants

Digital instrumentation and control (I&C) systems are being deployed in nuclear power plants (NPPs) for both existing and advanced reactor designs. As I&C systems become more digitized to allow features like near autonomous control and remote operation, they introduce greater cyber risk to NPPs. Cyberattacks targeting industrial control systems (ICSs) are growing in both qualities and capabilities, which indicates that cybersecurity needs to be an integral part of risk assessment in the industry. Although there are some risk assessment methods in traditional information technology (IT) cybersecurity, the differences between IT and ICS cybersecurity make it infeasible to apply these risk assessment methods directly to ICSs. Some research has focused on risk assessment methods for ICSs, but few studies focus on applications to NPPs. Ideal risk frameworks for the nuclear industry are dynamic and account for system dependencies; this survey review focuses on such risk assessment methods both in and outside the nuclear field. In this article, the major challenges in cybersecurity risk assessment research are pointed out, and further research suggestions and considerations for cyber risk assessment in I&C systems are identified.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Reactor instrumentation and control design and performance simulation for SP-100

The SP-100 flight system will be launched with all primary and secondary lithium in the solid state. Once in orbit, the reactor will be brought critical and maintained at a low power level while the lithium is thawed out. Once the system is thawed out, the reactor power will be controlled to provide the energy source required by the power conversion system to meet the payload electrical power requirements. The Reactor Instrumentation and Control subsystem which includes the reactor control drives, instrumentation and the digital controller provides for the control of the nuclear subsystem to perform these operating maneuvers as well as providing for automatic shutdown and restart under certain off-normal conditions. The design and performance of this system are described.

Meyer, R. A.↗

A Bayesian and HRA-Aided Method for the Novel Reliability Analysis of Software

Technological advancements and nuclear power plant modernization has inspired considerable research in the areas of safety and reliability, yet there remains a lack of consensus for the reliability assessment of digital instrumentation and control (I&C) systems. Motivated by the lack of consensus for reliability analysis methods, this work employs a novel framework that incorporates Bayesian, human reliability, and common-cause failure (CCF) modeling techniques. The novel framework allows the use of state-of-the-art or classical modeling techniques when accounting for human and CCF effects on system reliability. The Bayesian and HRA-Aided Method for the Reliability Analysis of Software (BAHAMAS) is demonstrated by a case study for the quantification of software hazards found in a previous analysis of a digital reactor trip system. The results demonstrate the ability of BAHAMAS to account for human activities during the software development life cycle and their influence on software reliability. BAHAMAS is a flexible tool for extending the coverage of conventional probabilistic risk assessments to include modernized digital I&C systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

WTEC monograph on instrumentation, control and safety systems of Canadian nuclear facilities

This report updates a 1989-90 survey of advanced instrumentation and controls (I&C) technologies and associated human factors issues in the U.S. and Canadian nuclear industries carried out by a team from Oak Ridge National Laboratory (Carter and Uhrig 1990). The authors found that the most advanced I&C systems are in the Canadian CANDU plants, where the newest plant (Darlington) has digital systems in almost 100 percent of its control systems and in over 70 percent of its plant protection system. Increased emphasis on human factors and cognitive science in modern control rooms has resulted in a reduced workload for the operators and the elimination of many human errors. Automation implemented through digital instrumentation and control is effectively changing the role of the operator to that of a systems manager. The hypothesis that properly introducing digital systems increases safety is supported by the Canadian experience. The performance of these digital systems has been achieved using appropriate quality assurance programs for both hardware and software development. Recent regulatory authority review of the development of safety-critical software has resulted in the creation of isolated software modules with well defined interfaces and more formal structure in the software generation. The ability of digital systems to detect impending failures and initiate a fail-safe action is a significant safety issue that should be of special interest to nuclear utilities and regulatory authorities around the world.

Uhrig, Robert E.↗

Investigation of the Use of Dynamic Probabilistic Risk Assessment Methodologies for Identifying Digital I&C System Common Cause Failures

Digital Instrumentation and Control (I&C) systems have a key role in nuclear power plants in the upgrade of aging analog systems. Digital systems improve plant safety and reliability through features such as increased hardware reliability and stability and improved failure detection capability. There is no consensus on which of the current probabilistic risk assessment methods are most suitable for use in the reliability analysis of digital I&C systems. While the traditional event-tree/fault-tree (ET/FT) approach is still used for their reliability modeling, there are concerns regarding this approach in properly accounting for dynamic interactions among system components since potentially significant dependencies among failure events may not be identified and/or their likelihood may not be properly quantified. Dynamic methodologies are expected to provide a much more accurate representation of probabilistic evolution of the I&C systems in time due to their capability to more properly account for complex interactions than the static approach. The applicability of dynamic PRA methodologies for digital I&C system is investigated using the criteria presented in the NUREG/CR-6901, and the comparisons made in NUREG/CR-6901 are updated in light of the latest studies. The Dynamic Event Tree (DET) approach has been identified as one of the top dynamic methods when evaluated against the requirements for the reliability modeling of digital I&C systems. The DET method is a strong candidate for integration into existing PRA studies, as it bears many similarities to the traditional ET approach. In this study, the DET approach has been applied to the Plant Protection System of the APR1400 design, and the results are compared to results from its available traditional ET/FT analysis. Possible approaches to evaluate and quantify the effects of common cause failures on system safety using dynamic methods are also examined.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

AVIRIS onboard data handling and control

The timing and flow of detector and ancillary data for the Airborne Visible/Infrared imaging spectrometer (AVIRIS) are controlled within the instrument by its digital electronics assembly. In addition to providing detector and signal chain timing, the digital electronics receives, formats, and rate-buffers digitized science data; collects and formats ancillary (calibration and engineering) data; and merges both into a single tape record. Overall AVIRIS data handling is effected by a combination of dedicated digital electronics to control instrument timing, image data flow, and data rate buffering and a microcomputer programmed to handle real-time control of instrument mechanisms and the coordinated preparation of ancillary data.

Steinkraus, Ronald E.↗

AVIRIS onboard data handling and control

The timing and flow of detector and ancillary data for the Airborne Visible/Infrared Imaging Spectrometer (AVIRIS) are controlled within the instrument by its digital electronics assembly. In addition to providing detector and signal chain timing, the digital electronics receives, formats, and rate-buffers digitized science data; collects and formats ancillary (calibration and engineering) data; and merges both into a single tape record. Overall AVIRIS data handling is effected by a combination of dedicated digital electronics to control instrument timing, image data flow, and data rate buffering and a microcomputer programmed to handle real-time control of instrument mechanisms and the coordinated preparation of ancillary data.

Steinkraus, Ronald E.↗