Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP (Poster)
Poster for ECRA poster session.
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Poster for ECRA poster session.
Digital Instrumentation and Control (I&C) systems have a key role in nuclear power plants in the upgrade of aging analog systems. Digital systems improve plant safety and reliability through features such as increased hardware reliability and stability and improved failure detection capability. There is no consensus on which of the current probabilistic risk assessment methods are most suitable for use in the reliability analysis of digital I&C systems. While the traditional event-tree/fault-tree (ET/FT) approach is still used for their reliability modeling, there are concerns regarding this approach in properly accounting for dynamic interactions among system components since potentially significant dependencies among failure events may not be identified and/or their likelihood may not be properly quantified. Dynamic methodologies are expected to provide a much more accurate representation of probabilistic evolution of the I&C systems in time due to their capability to more properly account for complex interactions than the static approach. The applicability of dynamic PRA methodologies for digital I&C system is investigated using the criteria presented in the NUREG/CR-6901, and the comparisons made in NUREG/CR-6901 are updated in light of the latest studies. The Dynamic Event Tree (DET) approach has been identified as one of the top dynamic methods when evaluated against the requirements for the reliability modeling of digital I&C systems. The DET method is a strong candidate for integration into existing PRA studies, as it bears many similarities to the traditional ET approach. In this study, the DET approach has been applied to the Plant Protection System of the APR1400 design, and the results are compared to results from its available traditional ET/FT analysis. Possible approaches to evaluate and quantify the effects of common cause failures on system safety using dynamic methods are also examined.
The requirements for U.S. nuclear power plants to maintain a large onsite physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This integrated process for physical security analysis is named Modeling and Analysis for Safety Security using Dynamic EMRALD Framework (MASS-DEF). This document provides an update on the progress in applying the MASS-DEF process to an operating commercial nuclear power plant as well as additional industry feedback regarding use of the tool for other physical security risk-informed topics. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, and integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5 or MAAP. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report is an update the progress of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report also provides an update to the procedural guidance for the MASS-DEF process and an overview of the generic models available for use by utilities. This report does not contain any plant’s sensitive information and/or safeguards information. This study’s purpose was to verify that the results achieved using generic models are similar to actual plant results and refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.
This paper describes ongoing work within the Light Water Reactor Sustainability (LWRS) Program at Idaho National Laboratory (INL) to optimize security and cost of nuclear power plants (NPPs). It reviews the conservatisms in conventional physical security posture and regulations. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). The dynamic assessment methodology leverages EMRALD to process results of force-on-force (FOF) simulations and crediting safety mitigation actions from probabilistic risk assessment (PRA) models as well as diverse and flexible coping strategies (FLEX) mitigation strategies. Timing information from these simulations are compared against the available time to perform mitigations obtained from Reactor Excursion and Leak Analysis Program (RELAP5) simulations. To illustrate the methodology, a station blackout (SBO) attack scenario was modeled in commercially available FOF simulation tools. The simulation results provide valuable insights into possible attack outcomes and as the probabilistic risk of a core damage event given these outcomes. Safety mitigation procedures were modeled in EMRALD, and were dependent on the attack outcomes by considering human operator uncertainties. RELAP5 simulations incorporating human and hardware uncertainties were performed to estimate the distribution of time-to-core damage. The results demonstrate that, even in the extreme case of a successful adversarial attack, plant mitigation strategies provide significantly high-likelihood of preventing radiological release. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the NPPs to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security.
One of the lessons learned from the Fukushima Daiichi nuclear power plant (NPP) accident is strengthening the station blackout (SBO) mitigation capabilities by enhancing defense in depth for all existing and new NPPs. One of the possible remedies is diverse and flexible coping strategies (FLEX). The objective of this study is to address the benefits of FLEX in various accident scenarios in terms of both risk and cost. FLEX was originally devised against SBO accidents. In this research, we investigate the fundamental plant responses against accidents considering two fundamentally different cases: accidents that lead to high pressure on the primary side and accidents that lead to low pressure on the primary side. Several uncertainties are associated with the characteristics of the FLEX portable equipment. Specifically, the time for FLEX deployment may depend on several factors such as type of accident, point of injection, availability of safety systems, battery backup timings, and human actions. This study utilizes a dynamic risk assessment framework to analyze accident scenarios and suggests a novel importance measure, which is a cumulative distribution function– based importance metric that characterizes the influence of input distribution on complete output distribution. The importance of the existing and newly developed FLEX strategy based on risk significance is illustrated with examples. The suggested measure provides clear insight into how FLEX affects risk of the whole system and additional risk margins thanks to new safety systems.
This paper describes ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize the security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD is leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions, including dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios are modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of a core damage event given these outcomes. Safety mitigation procedures are modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.
This paper describes an ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD was leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions including the dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios were modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of core damage event given these outcomes. Safety mitigation procedures were modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.
RAVEN is a generic software framework to perform parametric and probabilistic analysis based on the response of complex system codes. The initial development was aimed to provide dynamic risk analysis capabilities to the Thermo-Hydraulic code RELAP-7, currently under development at the Idaho National Laboratory (INL). Although the initial goal has been fully accomplished, RAVEN is now a multi-purpose probabilistic and uncertainty quantification platform, capable to agnostically communicate with any system code. This agnosticism includes providing Application Programming Interfaces (APIs). These APIs are used to allow RAVEN to interact with any code as long as all the parameters that need to be perturbed are accessible by inputs files or via python interfaces. RAVEN is capable of investigating the system response, and investigating the input space using Monte Carlo, Grid, or Latin Hyper Cube sampling schemes, but its strength is focused to- ward system feature discovery, such as limit surfaces, separating regions of the input space leading to system failure, using dynamic supervised learning techniques. The development of RAVEN has started in 2012, when, within the Nuclear Energy Advanced Modeling and Simulation (NEAMS) program, the need to provide a modern risk evaluation framework became stronger. RAVEN principal assignment is to provide the necessary software and algorithms in order to employ the concept developed by the Risk Informed Safety Margin Characterization (RISMC) program. RISMC is one of the pathways defined within the Light Water Reactor Sustainability (LWRS) program. In the RISMC approach, the goal is not just the individuation of the frequency of an event potentially leading to a system failure, but the closeness (or not) to key safety-related events. Hence, the approach is interested in identifying and increasing the safety margins related to those events. A safety margin is a numerical value quantifying the probability that a safety metric (e.g. for an important process such as peak pressure in a pipe) is exceeded under certain conditions. The initial development of RAVEN has been focused on providing dynamic risk assessment capability to RELAP-7, currently under development at the INL and, likely, future replacement of the RELAP5-3D code. Most the capabilities that have been implemented having RELAP-7 as principal focus are easily deployable for other system codes. For this reason, several side activates are currently ongoing for coupling RAVEN with soft- ware such as RELAP5-3D, etc. The aim of this document is the explanation of the input requirements, focalizing on the input structure.
The economic potential of micro-reactors is vast and underestimated. Commonly-emphasized applications include niche markets such as remote communities, mines and military bases. However, micro-reactors could be used as flexible energy generators also for larger markets, such as mobile and containerized agriculture and manufacturing facilities, district heating, micro-grids for data centers, sea ports, airports and hospitals. The implication is that micro-reactors may have to be deployed also in non-remote locations. Successful implementation of micro-reactors needs a navigable and predictable licensing process, technology-appropriate siting restrictions, risk-informed emergency and safety requirements, and practical operating and maintenance requirements. The primary goal of this project was to develop siting criteria that are tailored to micro-reactors deployable in densely-populated areas, e.g., urban environments. To achieve that goal, we compared the characteristics of the MIT research reactor (MITR) with those of leading micro-reactor concepts (e.g., eVinci, USNC, Aurora), and evaluated whether and how the MITR design basis (e.g., inherent safety features, engineered safety systems, source term, emergency planning and emergency operating procedures) and associated regulations may be applicable to these new micro-reactors as well. What makes MITR a unique analogue in this context is its small power rating (6 MWt) and physical size, mode of operations (24/7 with a somewhat more commercial flavor than typical university reactors), and especially its urban location. Of course significant differences exist, such as mission (power production vs. research) and the reactor design itself. Leveraging the MITR experience, this project was able to generate criteria that will allow micro-reactors to realize their full economic potential as flexible heat and electricity generators for a diverse portfolio of applications in non-remote locations. As such, the outcome of this project might encourage investment in and use of micro-reactors. A second goal of the project was to conceptualize a model of operations for micro-reactors that would minimize the staffing requirements, and thus reduce the cost of electricity and heat generated by these systems. Here too our approach was to systematically review the MITR experience and requirements, as well as survey the innovations in autonomous control technologies and monitoring (e.g., advanced sensors, drones, robotics, AI) that would permit a dramatic reduction in staffing at future micro-reactor installations. The scope of work was expanded after the start date to include also an evaluation of micro-reactor security, using the so-called consequence-based analysis, and the development of a methodology to perform dynamic risk assessment for micro-reactors, using system theory and modeling and simulation.
Zero Trust is a cybersecurity paradigm centered on the idea that a network breach is inevitable and so no user or asset should be implicitly trusted. Entities on the network are continuously monitored and access-granting decisions are based on dynamic risk assessment using multiple inputs. To limit the damage from an attack, privileges and lateral access are constrained by default. This report provides an overview of current models and constructs employed in building out these concepts into a zero trust architecture.
This work proposes a dynamic evaluation methodology to relax the conservatism in physical security evaluation, by leveraging an ongoing work in the Light Water Reactor Sustainability pathway. This methodology is implemented in a dynamic risk assessment tool named Event Modeling Risk Assessment using Linked Diagrams (EMRALD). The work extends EMRALD’s capability to support a sandbox feature where analysts can easily create attack scenarios and modify advanced/small modular reactor (A/SMR) security and safety features using templates. This approach saves time and cost since the analysis does not require creating detailed computer-aided design models, as is commonly required in commercial force-on-force software tools. EMRALD is completely free to use at https://emraldapp.inl.gov. We have developed basic templates including physical barriers, intrusion sensors, physical areas, and safety actions, that can be downloaded from EMRALD’s GitHub site: https://github.com/idaholab/EMRALD. These templates use generic data commonly used for training purposes, which do not reflect any actual operating nuclear reactor. Users may adjust the data in the templates with their own dataset and/or create new templates in EMRALD. The proposed methodology combines security and safety by assessing sabotage effects up to the radiological consequence to the public instead of merely the core damage state. This practice follows the industry standard for advanced non-light-water reactors currently proposed for endorsement by the Nuclear Regulatory Commission. The combination of security and safety is expressed in an achievability-consequence chart. EMRALD can be used to generate data for this chart. A hypothetical case study using a representative sodium-cooled fast reactor (SFR) facility is presented in this report to demonstrate this methodology. This case study does not contain any actual nuclear plant information. This work will benefit A/SMR vendors and utilities to implement security by design during the reactor design iteration phase, such that they do not have to perform upgrades and retrofits to the reactor after it is installed to improve its physical protection system. The tool may also be used to analyze domestic or foreign reactor designs to support the International Nuclear Security Techniques for Advanced Reactors (INSTAR) bilateral missions. Future works are planned to implement the methodology on a reference SFR reactor and a reference high-temperature gas-cooled reactor to obtain insights and lessons-learned for the A/SMR community.
A program that defines and assesses the dynamic risk of software vulnerabilities and considers the dynamic risks into patch scheduling to reduce security risks posed by vulnerabilities and provide formal guidance to security operations at various organizations.
Advancements in nuclear system designs with automated control features provide many benefits, but can lead to complex coupled systems and dynamic failure scenarios. This is especially true for microreactor designs where components are not expected to be replaced during the reactor’s lifetime. Hence, the life of the system, in addition to the safety, needs to be evaluated. Modeling these sequences of time-dependent events requires addressing cyclical processes and changing failure rates in ways that represent the actual system dynamics in contrast to a single sampling for a component’s time to failure. This research presents two distinct analytical methods for several failure distributions that evaluate a final time to failure used for different scenarios where the time to failure must be sampled multiple times. The first method is used when evaluating a component whose failure rate increases due to an outside event after the initial sampling but before the initially sampled time to failure. The second method is used when evaluating multiple identical components or a component that has been replaced with a new identical version before the second sampling. The two methods were implemented in a few representative case studies developed in the dynamic probabilistic risk assessment tool Event Modeling Risk Assessment using Linked Diagrams. Overall, this paper provides guidelines on how these approaches give a more realistic and accurate dynamic probabilistic risk assessment of complex systems.
In this study, we propose an interpolation-based response surface surrogate methodology to manage a large number of scenarios in dynamic probabilistic risk assessment. It adopts the shape Dynamic Time Warping algorithm to cluster the interpolation neighborhood from time series sample data. The interpolation method was adapted from Taylor Kriging to allow a reduced-order model of the Taylor series. In order to demonstrate its applicability to complex issues in risk assessment for nuclear engineering, an example risk response surface to estimate emergency core cooling system (ECCS) criteria for triplex silicon carbide (SiC) accident-tolerant fuel was constructed. The response surface was exploited to estimate the cumulative failure probability of the fuel cladding structure due to the uncertainties in operator actions and safety systems. The functional failures were assessed based on a combination of individual layer failures computed by coupling Risk Analysis Virtual Environment software with a pressurized water reactor 1000-MW(electric) RELAP5 model and the in-house fuel performance assessment module. Results showed that SiC cladding failure probability spiked less than 1 min after a large-break loss-of- coolant accident whenever the current ECCS criteria for Zircaloy-4 (Zr-4) cladding was used. However, it still provides an increased safety margin of three orders of magnitude compared to Zr-4. This positive margin could be utilized to relax active ECCS requirements by allowing deviations of up to 450 s in its actuation time. The proposed surrogate methodology generated a response surface of SiC cladding failure probability reasonably well, with a significant savings of computation time. This methodology is expected to be useful in the analysis of system response with complex uncertainty sources.
Event Modeling Risk Assessment using Linked Diagrams (EMRALD) is a software tool developed at Idaho National Laboratory for researching the capabilities of dynamic probabilistic risk assessment. It provides a simple interface to represent complex interactions often seen when developing dynamic models. EMRALD can also interface with other applications by modifying inputs, running, and using their results within EMRALD for dynamic and integrated assessment. This report goes over the work performed as part of the Risk-Informed Systems Analysis Pathway under the Light Water Reactor Sustainability program to upgrade the EMRALD software.
This paper presents a dynamic event data-based stability risk assessment method for power grids with high penetrations of inverter-based resources (IBRs). This method relies on obtaining the IBRs' DQ admittance through dynamic event data and computing the system's eigenvalues based on the admittance models. Two critical technologies are employed in this research, including time-domain and frequency-domain data fitting and dq-frame voltage and current signal derivation. The first technology is key to obtaining the s-domain expressions from the transient response data, and the s-domain DQ admittance model from the frequency-domain measurements. The second technology is key to obtaining the dq-frame voltage and current signals from either the three-phase instantaneous measurements or the phasor measurement unit (PMU) data. The method is illustrated using data generated from a Type-4 wind power plant modeled in PSCAD. This paper demonstrates the technical feasibility of the proposed approach.
Event Modeling Risk Assessment using Linked Diagrams (EMRALD) is a software tool developed at Idaho National Laboratory for researching the capabilities of dynamic probabilistic risk assessment. It provides a simple interface to represent complex interactions often seen when developing dynamic models. EMRALD can also interface with other applications by modifying inputs as well as running and using their results within EMRALD for dynamic and integrated assessment. To enable wider industry use cases, collaborative work between Idaho National Laboratory and FPoliSolutions was performed through the technology commercialization fund TCF-20-21448. This report covers the additional features and capabilities developed under this work.
In the past few decades, the increasing complexity of modern engineering systems has been driven by the integration of a large number of components whose operations may involve many disciplines (e.g., thermal hydraulics, plant operations, cybersecurity). Most computational tools used by industry and regulators for system safety and reliability assessments are still based on the traditional fault tree (FT) and event tree (ET) approach, which may not be able to capture complex interactions among system constituents. The use of simulation tools has widely increased in the past few decades to improve the fidelity of the reliability and safety analyses. However, the direct use of simulation tools as part of dynamic probabilistic risk assessment (DPRA) methods is not getting traction since (1) modeling the whole system under consideration with DPRA methods may be computationally expensive and unnecessary, and (2) the manual integration of DPRA models into existing state-of-practice probabilistic risk assessment models (i.e., based on FTs and ETs) can be time consuming and prone to errors. Here, in this paper we propose a procedure to overcome this limitation by presenting several algorithms designed to automatically construct subsystem ETs and FTs from DPRA methods for integration into an existing ET/FT system model.