Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Dynamic risk assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP

The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. To address this, Idaho National Laboratory [JL2.1]has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal-hydraulics modeling [JL3.1]to enhance security planning while reducing costs. We developed a tool that produces reduced order models using thermal hydraulic simulations from the Modular Accident Analysis Program (MAAP) [1]. These models can quickly evaluate reactor core behavior during attack simulations, and in so doing, address two barriers of traditional methods: (1) MAAP simulations are computationally intensive, and (2) attack scenarios must be run in a secure environment, which complicates analysis and validation. By precomputing scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Architecture for Integrated Medical Model Dynamic Probabilistic Risk Assessment

Probabilistic Risk Assessment (PRA) is a modeling tool used to predict potential outcomes of a complex system based on a statistical understanding of many initiating events. Utilizing a Monte Carlo method, thousands of instances of the model are considered and outcomes are collected. PRA is considered static, utilizing probabilities alone to calculate outcomes. Dynamic Probabilistic Risk Assessment (dPRA) is an advanced concept where modeling predicts the outcomes of a complex system based not only on the probabilities of many initiating events, but also on a progression of dependencies brought about by progressing down a time line. Events are placed in a single time line, adding each event to a queue, as managed by a planner. Progression down the time line is guided by rules, as managed by a scheduler. The recently developed Integrated Medical Model (IMM) summarizes astronaut health as governed by the probabilities of medical events and mitigation strategies. Managing the software architecture process provides a systematic means of creating, documenting, and communicating a software design early in the development process. The software architecture process begins with establishing requirements and the design is then derived from the requirements.

Probability Theory↗

Strategy for Risk Quantification of Spaceflight Crew Health and Performance Using Dynamic Probabilistic Risk Assessment

At NASA, the Crew Health and Performance (CHP) system represents the span of countermeasures, capabilities, interventions, and tested processes and procedures that in combination work to mitigate the human component of spaceflight mission risk. Across the varying NASA mental models of the CHP system, the different functionalities needed to meet human flight systems standards can be broken down into specific categories (i.e. medical capability, environmental health, behavioral health). These categories can be further broken down into specific subgroups generally associated with the CHP functionalities meant to mitigate or buy down individual human system risks. Taking a similar development approach we seek to leverage dynamic probabilistic risk assessment as a means to quantify and relatively assess the human risk state within the crew health and performance domain. By utilizing existing tools as integrators, we propose a rapid development strategy for incorporating research and operational data that represent the influence of the CHP system functionalities, in order to provide order of magnitudes estimates of the influence on most human system risks outcomes. The model system utilizes a modest cumulative risk approach and that limits the scope to primary paths of influence between the CHP functionalities and human system risks, thus enabling quick prototypes of the integrative effects of CHP functional combinations to solicit valuable feedback from stakeholders and customers on the data, relationship, and structure of the integration.

Drayton Munster↗

Comparative Analysis of Static and Dynamic Probabilistic Risk Assessment

This study examines three different methodologies for producing loss-of-mission (LOM) and loss-of-crew (LOC) risks estimates for probabilistic risk assessments (PRA) of crewed spacecraft. The three bottom-up, component-based PRA approaches examined are a traditional static fault tree, a dynamic Monte Carlo simulation, and a fault tree hybrid that incorporates some dynamic elements. These approaches were used to model the reaction control system thruster pod of a generic crewed spacecraft and mission, and a comparative analysis of the methods is presented. The methodologies are assessed in terms of the process of modeling a system, the actionable information produced for the design team, and the overall fidelity of the quantitative risk evaluation generated. The system modeling process is compared in terms of the effort required to generate the initial model, update the model in response to design changes, and support mass-versus-risk trade studies. The results are compared by examining the top-level LOM/LOC estimates and the relative risk driver rankings at the failure mode level. The fidelity of each modeling methodology is discussed in terms of its capability to handle real-world system dynamics such as cold-sparing, changes in mission operations due to loss of redundancy, and common cause failure modes. The paper also discusses the applicability of each methodology to different phases of system development and shows that a single methodology may not be suitable for all of the many purposes of a spacecraft PRA. The fault tree hybrid approach is shown to be best suited to the needs of early assessments during conceptual design phases. As the design begins to mature, the level of detail represented in the risk model must go beyond redundancy and nominal mission operations to include dynamic, time- and state-dependent system responses as well as diverse system capabilities. This is best accomplished using the dynamic simulation approach, since these phenomena are not easily captured by static methods. Ultimately, once the design has been finalized and the goal of the PRA is to provide design validation and requirement verification, more traditional, static fault tree approaches may become as appropriate as the simulation method.

Mattenberger, Christopher J.↗

Method and system for dynamic probabilistic risk assessment

The DEFT methodology, system and computer readable medium extends the applicability of the PRA (Probabilistic Risk Assessment) methodology to computer-based systems, by allowing DFT (Dynamic Fault Tree) nodes as pivot nodes in the Event Tree (ET) model. DEFT includes a mathematical model and solution algorithm, supports all common PRA analysis functions and cutsets. Additional capabilities enabled by the DFT include modularization, phased mission analysis, sequence dependencies, and imperfect coverage.

Dugan, Joanne Bechta↗

Comparative Analysis of Static and Dynamic Probabilistic Risk Assessment

Implementation of risk-informed design allows the design team to thoroughly explore the risks of a system while iterating the operations concept, design, and requirements until the system meets mission objects and is achievable within constraints. To arrive at a space system design that is likely to meet all constraints placed upon mass, cost, performance and risk, the system requirements must be understood and traded against each other as early as the conceptual design phase. Depending on the project phase and the goals of the risk analysis, various PRA methodologies could be used to produce quantitative risk estimates to enable such a process. In order to better understand the applicability, advantages, and limitations of various PRA methodologies, a comparative analysis of three bottom-up, component-based PRA approaches was performed. The three methods examined are a traditional static fault tree, a fault tree hybrid, and a dynamic Monte Carlo simulation. Each approach was used to assess a generic reaction control system (RCS) thruster pod and mission. The methods are assessed in terms of the process of modeling a system, the actionable information produced for the design team, and the overall fidelity of the quantitative risk evaluation generated. The paper also discusses the applicability of each methodology to the different phases of system development.

Probablistic↗

An Approach to Dynamic Human Reliability Analysis and Its Data Collection Framework

Human reliability analysis (HRA) is a method for evaluating human errors in a variety of complex systems such as nuclear power plants, military systems, aircraft, and chemical plants. Most HRA methods currently used by regulatory institutes or utilities are called static HRA and are carried out by simple worksheets or simple calculators. To date, there are many unsolved or intrinsic challenges in static HRA. For example, existing static HRA does not realistically model and evaluate human actions as they would be performed at actual systems. There is no method with HRA to objectively estimate the time required for human actions despite being essential to HRA processes. In addition, many HRA methods still rely on a dataset generated prior to the 1980s, from unrelated industry experience or simply from expert judgment. Accordingly, this study attempted to research how to overcome the challenges of existing HRA via dynamic risk assessment (a.k.a., simulation-based or computation-based risk assessment) techniques. First, this study developed a dynamic HRA method, named as PRocedure-based Investigation Method of EMRALD Risk Assessment – HRA (PRIMERA-HRA). The PRIMERA-HRA mainly concentrates on providing HRA analysts with specific guidelines on how to reasonably model human actions, assign human reliability data and evaluate output of simulation within a dynamic probabilistic risk assessment tool, called as Event Modeling Risk Assessment using Linked Diagrams (EMRALD). Second, this study also developed a module for performance shaping factors (i.e., the key concept in HRA quantification) applicable to dynamic HRA, then implemented it based on PRIMERA-HRA within the EMRALD tool. Third, this study developed an HRA data collection framework to support dynamic HRA, called as Simplified Human Error Experimental Program (SHEEP). Originally, the SHEEP study aimed to support static HRA and its data collection, but recently extended the scope to the new technologies such as dynamic HRA or HRA for advanced reactors. SHEEP focuses on the use of data collected from simplified simulators to complement—but not replace—data collection studies using full-scope simulators and actual operators. To date, many experiments were conducted under the SHEEP framework. Multiple analyses, such as human performance analysis, human error analysis, task complexity analysis, learning effect analysis and time distribution analysis, were also carried out using the collected data. Then, based on the major insights, an approach to inferring full-scope data based on simplified simulator data was proposed. The PRIMERA-HRA and SHEEP research are expected to evaluate human actions more realistically than existing static HRA, provide an opportunity to collect more HRA data with reasonable cost and labor, then contribute to enhance the quality of HRA.

99 - GENERAL AND MISCELLANEOUS↗

An Approach to Dynamic Human Reliability Analysis and Its Data Collection Framework

Human reliability analysis (HRA) is a method for evaluating human errors in a variety of complex systems such as nuclear power plants, military systems, aircraft, and chemical plants. Most HRA methods currently used by regulatory institutes or utilities are called static HRA and are carried out by simple worksheets or simple calculators. To date, there are many unsolved or intrinsic challenges in static HRA. For example, existing static HRA does not realistically model and evaluate human actions as they would be performed at actual systems. There is no method with HRA to objectively estimate the time required for human actions despite being essential to HRA processes. In addition, many HRA methods still rely on a dataset generated prior to the 1980s, from unrelated industry experience or simply from expert judgment. Accordingly, this study attempted to research how to overcome the challenges of existing HRA via dynamic risk assessment (a.k.a., simulation-based or computation-based risk assessment) techniques. First, this study developed a dynamic HRA method, named as PRocedure-based Investigation Method of EMRALD Risk Assessment – HRA (PRIMERA-HRA). The PRIMERA-HRA mainly concentrates on providing HRA analysts with specific guidelines on how to reasonably model human actions, assign human reliability data and evaluate output of simulation within a dynamic probabilistic risk assessment tool, called as Event Modeling Risk Assessment using Linked Diagrams (EMRALD). Second, this study also developed a module for performance shaping factors (i.e., the key concept in HRA quantification) applicable to dynamic HRA, then implemented it based on PRIMERA-HRA within the EMRALD tool. Third, this study developed an HRA data collection framework to support dynamic HRA, called as Simplified Human Error Experimental Program (SHEEP). Originally, the SHEEP study aimed to support static HRA and its data collection, but recently extended the scope to the new technologies such as dynamic HRA or HRA for advanced reactors. SHEEP focuses on the use of data collected from simplified simulators to complement—but not replace—data collection studies using full-scope simulators and actual operators. To date, many experiments were conducted under the SHEEP framework. Multiple analyses, such as human performance analysis, human error analysis, task complexity analysis, learning effect analysis and time distribution analysis, were also carried out using the collected data. Then, based on the major insights, an approach to inferring full-scope data based on simplified simulator data was proposed. The PRIMERA-HRA and SHEEP research are expected to evaluate human actions more realistically than existing static HRA, provide an opportunity to collect more HRA data with reasonable cost and labor, then contribute to enhance the quality of HRA.

99 - GENERAL AND MISCELLANEOUS↗

Investigation of the Use of Dynamic Probabilistic Risk Assessment Methodologies for Identifying Digital I&C System Common Cause Failures

Digital Instrumentation and Control (I&C) systems have a key role in nuclear power plants in the upgrade of aging analog systems. Digital systems improve plant safety and reliability through features such as increased hardware reliability and stability and improved failure detection capability. There is no consensus on which of the current probabilistic risk assessment methods are most suitable for use in the reliability analysis of digital I&C systems. While the traditional event-tree/fault-tree (ET/FT) approach is still used for their reliability modeling, there are concerns regarding this approach in properly accounting for dynamic interactions among system components since potentially significant dependencies among failure events may not be identified and/or their likelihood may not be properly quantified. Dynamic methodologies are expected to provide a much more accurate representation of probabilistic evolution of the I&C systems in time due to their capability to more properly account for complex interactions than the static approach. The applicability of dynamic PRA methodologies for digital I&C system is investigated using the criteria presented in the NUREG/CR-6901, and the comparisons made in NUREG/CR-6901 are updated in light of the latest studies. The Dynamic Event Tree (DET) approach has been identified as one of the top dynamic methods when evaluated against the requirements for the reliability modeling of digital I&C systems. The DET method is a strong candidate for integration into existing PRA studies, as it bears many similarities to the traditional ET approach. In this study, the DET approach has been applied to the Plant Protection System of the APR1400 design, and the results are compared to results from its available traditional ET/FT analysis. Possible approaches to evaluate and quantify the effects of common cause failures on system safety using dynamic methods are also examined.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

SafeMAP: Safe Multi-Agent Planning Framework Based on Dynamic Probabilistic Risk Assessment

This paper proposes a risk-aware framework for Safe Multi-Agent Planning (SafeMAP) that unifies disparate models for multi-agent systems in a Markovian process that allows for simultaneous system health monitoring, decision making under uncertainty, and multi-agent system collaboration. As operations beyond low earth orbit mature, there is an increased need for autonomous cyber-physical systems with onboard decision making capabilities. Multi-agent cyber-physical systems in particular offer the potential of increased efficiency, resiliency, and mission capabilities for future applications such as multi-rover terrain operations, distributed satellite operations, and management of smart lunar habitats. SafeMAP utilizes physics-based models of each agent and the relevant components, probability models of the environment and component operational states, and reward models for mission-specific objectives such as scientific task completion or resource consumption. The output of SafeMAP is a set of mission plans that satisfy the mission objective under specified risk/reward constraints. A readable interpretation of each of these generated mission plans is provided as an additional output. SafeMAP has been demonstrated on a simulated case study involving a four-rover system performing surface mapping operations and science tasks. Results of this paper demonstrate SafeMAP’s ability to generate explainable mission plans that satisfy the mission objective while minimizing risk under nominal and off-nominal conditions.

Mohammad Hejase↗

SafeMAP: Safe Multi-Agent Planning framework based on Dynamic Probabilistic Risk Assessment

This paper proposes a risk-aware framework for Safe Multi-Agent Planning (SafeMAP) that unifies disparate models for multi-agent systems in a Markovian process that allows for simultaneous system health monitoring, decision making under uncertainty, and multi-agent system collaboration. As operations beyond low earth orbit mature, there is an increased need for autonomous cyber-physical systems with onboard decision making capabilities. Multi-agent cyber-physical systems in particular offer the potential of increased efficiency, resiliency, and mission capabilities for future applications such as multi-rover terrain operations, distributed satellite operations, and management of smart lunar habitats. SafeMAP utilizes physics-based models of each agent and the relevant components, probability models of the environment and component operational states, and reward models for mission-specific objectives such as scientific task completion or resource consumption. The output of SafeMAP is a set of mission plans that satisfy the mission objective under specified risk/reward constraints. A readable interpretation of each of these generated mission plans is provided as an additional output. SafeMAP has been demonstrated on a simulated case study involving a four-rover system performing surface mapping operations and science tasks. Results of this paper demonstrate SafeMAP’s ability to generate explainable mission plans that satisfy the mission objective while minimizing risk under nominal and off-nominal conditions.

Mohammad Hejase↗

An Evaluation of The Dynamic Physical Security Risk Assessment Methodology for Fleet-Wide Applications

The requirements for U.S. nuclear power plants to maintain a large onsite physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This integrated process for physical security analysis is named Modeling and Analysis for Safety Security using Dynamic EMRALD Framework (MASS-DEF). This document provides an update on the progress in applying the MASS-DEF process to an operating commercial nuclear power plant as well as additional industry feedback regarding use of the tool for other physical security risk-informed topics. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, and integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5 or MAAP. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report is an update the progress of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report also provides an update to the procedural guidance for the MASS-DEF process and an overview of the generic models available for use by utilities. This report does not contain any plant’s sensitive information and/or safeguards information. This study’s purpose was to verify that the results achieved using generic models are similar to actual plant results and refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Dynamic Simulation Probabalistic Risk Assessment Model for an Enceladus Sample Return Mission

Enceladus, a moon of Saturn, has geyser-like jets that spray plumes of material into orbit. These jets could enable a free-flying spacecraft to collect samples and return them to Earth for study to determine if they contain the building blocks of life. The Office of Planetary Protection at NASA requires containment of any unsterilized samples and prohibits destructive impact of the spacecraft upon return to Earth, with a sample release probability of less than 1 in 1,000,000 as a recommended goal. This paper describes a probabilistic risk assessment model that uses dynamic simulation techniques to capture the physics-based, time- and state-dependent interactions between the sample return system and the environment, which drive the risk of sample release. The dynamic approach uses a Monte Carlo-style simulation to integrate the many phases and sources of risk for a sample return mission. The model is used to assess the achievability of the planetary protection reliability goal. This is accomplished by performing sensitivity studies assessing the impact of modeling assumptions to identify where uncertainties drive the risk. These results, in turn, are used to examine the feasibility of meeting key design and performance parameters that are needed to achieve the reliability goal for a given architecture with existing technologies.

Dynamic Simulation↗

Sensitivity Analysis of Effectiveness of FLEX Strategies Using a CDF-Based Importance Measure Under Accident Conditions

One of the lessons learned from the Fukushima Daiichi nuclear power plant (NPP) accident is strengthening the station blackout (SBO) mitigation capabilities by enhancing defense in depth for all existing and new NPPs. One of the possible remedies is diverse and flexible coping strategies (FLEX). The objective of this study is to address the benefits of FLEX in various accident scenarios in terms of both risk and cost. FLEX was originally devised against SBO accidents. In this research, we investigate the fundamental plant responses against accidents considering two fundamentally different cases: accidents that lead to high pressure on the primary side and accidents that lead to low pressure on the primary side. Several uncertainties are associated with the characteristics of the FLEX portable equipment. Specifically, the time for FLEX deployment may depend on several factors such as type of accident, point of injection, availability of safety systems, battery backup timings, and human actions. This study utilizes a dynamic risk assessment framework to analyze accident scenarios and suggests a novel importance measure, which is a cumulative distribution function– based importance metric that characterizes the influence of input distribution on complete output distribution. The importance of the existing and newly developed FLEX strategy based on risk significance is illustrated with examples. The suggested measure provides clear insight into how FLEX affects risk of the whole system and additional risk margins thanks to new safety systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Dynamic Risk Framework for the Physical Security of Nuclear Power Plants

This paper describes ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize the security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD is leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions, including dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios are modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of a core damage event given these outcomes. Safety mitigation procedures are modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Dynamic Risk Framework for the Optimization of Physical Security Posture of Nuclear Power Plants

This paper describes an ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD was leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions including the dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios were modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of core damage event given these outcomes. Safety mitigation procedures were modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗