Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Dynamic risk assessment”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Sensitivity Analysis of Effectiveness of FLEX Strategies Using a CDF-Based Importance Measure Under Accident Conditions

One of the lessons learned from the Fukushima Daiichi nuclear power plant (NPP) accident is strengthening the station blackout (SBO) mitigation capabilities by enhancing defense in depth for all existing and new NPPs. One of the possible remedies is diverse and flexible coping strategies (FLEX). The objective of this study is to address the benefits of FLEX in various accident scenarios in terms of both risk and cost. FLEX was originally devised against SBO accidents. In this research, we investigate the fundamental plant responses against accidents considering two fundamentally different cases: accidents that lead to high pressure on the primary side and accidents that lead to low pressure on the primary side. Several uncertainties are associated with the characteristics of the FLEX portable equipment. Specifically, the time for FLEX deployment may depend on several factors such as type of accident, point of injection, availability of safety systems, battery backup timings, and human actions. This study utilizes a dynamic risk assessment framework to analyze accident scenarios and suggests a novel importance measure, which is a cumulative distribution function– based importance metric that characterizes the influence of input distribution on complete output distribution. The importance of the existing and newly developed FLEX strategy based on risk significance is illustrated with examples. The suggested measure provides clear insight into how FLEX affects risk of the whole system and additional risk margins thanks to new safety systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Dynamic Risk Framework for the Physical Security of Nuclear Power Plants

This paper describes ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize the security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD is leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions, including dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios are modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of a core damage event given these outcomes. Safety mitigation procedures are modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Dynamic Risk Framework for the Optimization of Physical Security Posture of Nuclear Power Plants

This paper describes an ongoing work within the Light Water Reactor Sustainability pathway at Idaho National Laboratory (INL) to optimize security and cost of nuclear power plants. It introduces the dynamic risk assessment tool developed at INL, Event Modeling Risk Assessment using Linked Diagrams (EMRALD). EMRALD was leveraged to optimize the security posture of a nuclear power plant by integrating force-on-force (FOF) simulations and operator mitigation actions including the dynamic and flexible coping strategies (FLEX). To illustrate the methodology, four attack scenarios were modeled in a commercially available FOF simulation tool using a hypothetical nuclear power plant facility. The simulation results provide valuable insights into possible attack outcomes, as well as the probabilistic risk of core damage event given these outcomes. Safety mitigation procedures were modeled in EMRALD dependent on the attack outcomes by considering human operator uncertainties. The results demonstrate that the number of armed responders can be optimized, while still maintaining the same protection level as the initial security posture. The proposed modeling and simulation framework of integrating FLEX equipment with FOF models enables the nuclear power plants to credit FLEX portable equipment in the plant security posture, resulting in an efficient and optimized physical security system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Flexible Siting Criteria and Staff Minimization for Micro-Reactors

The economic potential of micro-reactors is vast and underestimated. Commonly-emphasized applications include niche markets such as remote communities, mines and military bases. However, micro-reactors could be used as flexible energy generators also for larger markets, such as mobile and containerized agriculture and manufacturing facilities, district heating, micro-grids for data centers, sea ports, airports and hospitals. The implication is that micro-reactors may have to be deployed also in non-remote locations. Successful implementation of micro-reactors needs a navigable and predictable licensing process, technology-appropriate siting restrictions, risk-informed emergency and safety requirements, and practical operating and maintenance requirements. The primary goal of this project was to develop siting criteria that are tailored to micro-reactors deployable in densely-populated areas, e.g., urban environments. To achieve that goal, we compared the characteristics of the MIT research reactor (MITR) with those of leading micro-reactor concepts (e.g., eVinci, USNC, Aurora), and evaluated whether and how the MITR design basis (e.g., inherent safety features, engineered safety systems, source term, emergency planning and emergency operating procedures) and associated regulations may be applicable to these new micro-reactors as well. What makes MITR a unique analogue in this context is its small power rating (6 MWt) and physical size, mode of operations (24/7 with a somewhat more commercial flavor than typical university reactors), and especially its urban location. Of course significant differences exist, such as mission (power production vs. research) and the reactor design itself. Leveraging the MITR experience, this project was able to generate criteria that will allow micro-reactors to realize their full economic potential as flexible heat and electricity generators for a diverse portfolio of applications in non-remote locations. As such, the outcome of this project might encourage investment in and use of micro-reactors. A second goal of the project was to conceptualize a model of operations for micro-reactors that would minimize the staffing requirements, and thus reduce the cost of electricity and heat generated by these systems. Here too our approach was to systematically review the MITR experience and requirements, as well as survey the innovations in autonomous control technologies and monitoring (e.g., advanced sensors, drones, robotics, AI) that would permit a dramatic reduction in staffing at future micro-reactor installations. The scope of work was expanded after the start date to include also an evaluation of micro-reactor security, using the so-called consequence-based analysis, and the development of a methodology to perform dynamic risk assessment for micro-reactors, using system theory and modeling and simulation.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Zero Trust Cybersecurity: Concepts and Models for Application

Zero Trust is a cybersecurity paradigm centered on the idea that a network breach is inevitable and so no user or asset should be implicitly trusted. Entities on the network are continuously monitored and access-granting decisions are based on dynamic risk assessment using multiple inputs. To limit the damage from an attack, privileges and lateral access are constrained by default. This report provides an overview of current models and constructs employed in building out these concepts into a zero trust architecture.

97 MATHEMATICS AND COMPUTING↗

Methodology and Tool for the Physical Security Analysis of Micro and Advanced Reactors

This work proposes a dynamic evaluation methodology to relax the conservatism in physical security evaluation, by leveraging an ongoing work in the Light Water Reactor Sustainability pathway. This methodology is implemented in a dynamic risk assessment tool named Event Modeling Risk Assessment using Linked Diagrams (EMRALD). The work extends EMRALD’s capability to support a sandbox feature where analysts can easily create attack scenarios and modify advanced/small modular reactor (A/SMR) security and safety features using templates. This approach saves time and cost since the analysis does not require creating detailed computer-aided design models, as is commonly required in commercial force-on-force software tools. EMRALD is completely free to use at https://emraldapp.inl.gov. We have developed basic templates including physical barriers, intrusion sensors, physical areas, and safety actions, that can be downloaded from EMRALD’s GitHub site: https://github.com/idaholab/EMRALD. These templates use generic data commonly used for training purposes, which do not reflect any actual operating nuclear reactor. Users may adjust the data in the templates with their own dataset and/or create new templates in EMRALD. The proposed methodology combines security and safety by assessing sabotage effects up to the radiological consequence to the public instead of merely the core damage state. This practice follows the industry standard for advanced non-light-water reactors currently proposed for endorsement by the Nuclear Regulatory Commission. The combination of security and safety is expressed in an achievability-consequence chart. EMRALD can be used to generate data for this chart. A hypothetical case study using a representative sodium-cooled fast reactor (SFR) facility is presented in this report to demonstrate this methodology. This case study does not contain any actual nuclear plant information. This work will benefit A/SMR vendors and utilities to implement security by design during the reactor design iteration phase, such that they do not have to perform upgrades and retrofits to the reactor after it is installed to improve its physical protection system. The tool may also be used to analyze domestic or foreign reactor designs to support the International Nuclear Security Techniques for Advanced Reactors (INSTAR) bilateral missions. Future works are planned to implement the methodology on a reference SFR reactor and a reference high-temperature gas-cooled reactor to obtain insights and lessons-learned for the A/SMR community.

97 MATHEMATICS AND COMPUTING↗

Dynamic Risk-Aware Patch Scheduling

A program that defines and assesses the dynamic risk of software vulnerabilities and considers the dynamic risks into patch scheduling to reduce security risks posed by vulner­abilities and provide formal guidance to security operations at various organizations.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Probabilistic Methods for Cyclical and Coupled Systems with Changing Failure Rates

Advancements in nuclear system designs with automated control features provide many benefits, but can lead to complex coupled systems and dynamic failure scenarios. This is especially true for microreactor designs where components are not expected to be replaced during the reactor’s lifetime. Hence, the life of the system, in addition to the safety, needs to be evaluated. Modeling these sequences of time-dependent events requires addressing cyclical processes and changing failure rates in ways that represent the actual system dynamics in contrast to a single sampling for a component’s time to failure. This research presents two distinct analytical methods for several failure distributions that evaluate a final time to failure used for different scenarios where the time to failure must be sampled multiple times. The first method is used when evaluating a component whose failure rate increases due to an outside event after the initial sampling but before the initially sampled time to failure. The second method is used when evaluating multiple identical components or a component that has been replaced with a new identical version before the second sampling. The two methods were implemented in a few representative case studies developed in the dynamic probabilistic risk assessment tool Event Modeling Risk Assessment using Linked Diagrams. Overall, this paper provides guidelines on how these approaches give a more realistic and accurate dynamic probabilistic risk assessment of complex systems.

97 MATHEMATICS AND COMPUTING↗

Light Water Reactor Sustainability Program: Upgrade of EMRALD to a Modern JavaScript-based Framework

Event Modeling Risk Assessment using Linked Diagrams (EMRALD) is a software tool developed at Idaho National Laboratory for researching the capabilities of dynamic probabilistic risk assessment. It provides a simple interface to represent complex interactions often seen when developing dynamic models. EMRALD can also interface with other applications by modifying inputs, running, and using their results within EMRALD for dynamic and integrated assessment. This report goes over the work performed as part of the Risk-Informed Systems Analysis Pathway under the Light Water Reactor Sustainability program to upgrade the EMRALD software.

97 MATHEMATICS AND COMPUTING↗

From Event Data to Wind Power Plant DQ Admittance and Stability Risk Assessment

This paper presents a dynamic event data-based stability risk assessment method for power grids with high penetrations of inverter-based resources (IBRs). This method relies on obtaining the IBRs' DQ admittance through dynamic event data and computing the system's eigenvalues based on the admittance models. Two critical technologies are employed in this research, including time-domain and frequency-domain data fitting and dq-frame voltage and current signal derivation. The first technology is key to obtaining the s-domain expressions from the transient response data, and the s-domain DQ admittance model from the frequency-domain measurements. The second technology is key to obtaining the dq-frame voltage and current signals from either the three-phase instantaneous measurements or the phasor measurement unit (PMU) data. The method is illustrated using data generated from a Type-4 wind power plant modeled in PSCAD. This paper demonstrates the technical feasibility of the proposed approach.

17 WIND ENERGY↗

EMRALD Technology Advancements for Commercial Grade Dedication Readiness

Event Modeling Risk Assessment using Linked Diagrams (EMRALD) is a software tool developed at Idaho National Laboratory for researching the capabilities of dynamic probabilistic risk assessment. It provides a simple interface to represent complex interactions often seen when developing dynamic models. EMRALD can also interface with other applications by modifying inputs as well as running and using their results within EMRALD for dynamic and integrated assessment. To enable wider industry use cases, collaborative work between Idaho National Laboratory and FPoliSolutions was performed through the technology commercialization fund TCF-20-21448. This report covers the additional features and capabilities developed under this work.

97 MATHEMATICS AND COMPUTING↗

Automatic Generation of Event Trees and Fault Trees: A Model-Based Approach

In the past few decades, the increasing complexity of modern engineering systems has been driven by the integration of a large number of components whose operations may involve many disciplines (e.g., thermal hydraulics, plant operations, cybersecurity). Most computational tools used by industry and regulators for system safety and reliability assessments are still based on the traditional fault tree (FT) and event tree (ET) approach, which may not be able to capture complex interactions among system constituents. The use of simulation tools has widely increased in the past few decades to improve the fidelity of the reliability and safety analyses. However, the direct use of simulation tools as part of dynamic probabilistic risk assessment (DPRA) methods is not getting traction since (1) modeling the whole system under consideration with DPRA methods may be computationally expensive and unnecessary, and (2) the manual integration of DPRA models into existing state-of-practice probabilistic risk assessment models (i.e., based on FTs and ETs) can be time consuming and prone to errors. Here, in this paper we propose a procedure to overcome this limitation by presenting several algorithms designed to automatically construct subsystem ETs and FTs from DPRA methods for integration into an existing ET/FT system model.

97 MATHEMATICS AND COMPUTING↗

Evaluation of Physical Security Risk for Potential Implementation of FLEX using Dynamic Simulation Methods

The requirements for United States nuclear power plants to maintain a large onsite physical security force contribute to their large operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability Program Physical Security Pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. This pathway will analyze and minimize the conservatisms built into current security postures in order to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within this pathway has successfully developed a dynamic force-on-force (FOF) modeling framework using various computer simulation tools and integrated them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This document provides an overview of lessons learned in applying a dynamic computational framework that links results from a commercially available FOF simulation tool, a commercially available thermal-hydraulic tool, and EMRALD to an operating commercial nuclear power plant. This process of including plant procedures and multiple analysis results is being called Modeling and Analysis for Safety Security using Dynamic EMRALD Framework. Previous reports described how a user could integrate their plant-specific FOF models with the dynamic simulation tool EMRALD, model operator actions, integrate with probabilistic risk assessment tools, such as Computer Aided Fault Tree Analysis System or Systems Analysis Programs for Hands-on Integrated Reliability Evaluations, and with thermal-hydraulic tools, such as RELAP-5. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report documents the results of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. The purpose of this study was to verify that results achieved using generic models are similar to actual plant results and to refine our guidance of the use of the framework. Such an assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants. NOTE: The work performed in this report is based on a generic EMRALD model with actual plant data used for the analysis. However, only the generic model and general results of the analysis are in the report. No plant’s sensitive information is discussed in this report. The discussion shows examples of insights that can be obtained from the MASS-DEF methodology.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Plant-specific Model and Data Analysis using Dynamic Security Modeling and Simulation

The requirements for U.S. nuclear power plants to maintain a large on-site physical security force contribute to their high operational costs. The cost of maintaining the current physical security posture is approximately 10% of the overall operation and maintenance budget for commercial nuclear power plants. The goal of the Light Water Reactor Sustainability (LWRS) program’s physical security pathway is to develop tools, methods, and technologies and provide the technical basis for an optimized physical security posture. The conservatisms built into current security postures may be analyzed and minimized in order to reduce security costs while still ensuring adequate security and operational safety. The research performed at Idaho National Laboratory within LWRS program’s physical security pathway has successfully developed a dynamic force-on-force modeling framework using various computer simulation tools and integrating them with the dynamic assessment Event Modeling Risk Assessment using Linked Diagrams (EMRALD) tool. This document provides an update on the progress in applying a dynamic computational framework that links results from a commercially available force-on-force simulation tool, a commercially available thermal-hydraulic tool, and EMRALD to an operating commercial nuclear power plant. This report is only a summary of the progress and does not contain specific modeling results as those contain sensitive security information. This process of including plant procedures and multiple analysis results is being called Modeling and Analysis for Safety Security using Dynamic EMRALD Framework or MASS-DEF. Previous reports described how a user could integrate their plant-specific force-on-force models with the dynamic simulation tool EMRALD, model operator actions, integrate with probabilistic risk assessment tools, such as CAFTA (Computer Aided Fault Tree Analysis System) or SAPHIRE (Systems Analysis Programs for Hands-on Integrated Reliability Evaluations), and with thermal-hydraulic tools, such as RELAP-5. Previous reports applied various combinations of available simulations codes with EMRALD using generic plant models to demonstrate how to perform the analysis. This report documents the results of applying the dynamic computational framework to an actual nuclear facility using their security scenarios and timelines. This report does not contain any plant's sensitive information and/or Safeguards Information. The purpose of this study was to verify that results achieved using generic models are similar to actual plant results and to refine our guidance on the use of the framework. This assessment enables further analysis, such as what-if scenarios and staff-reduction evaluation, thereby optimizing physical security at plants.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

AUTOMATIC GENERATION OF EVENT TREES AND FAULT TREES: A MODEL-BASED APPROACH

In the past few decades, increasing complexity in modern engineering systems has been driven by the integration of a large number of components and by the fact that the system operations involve many disciplines (e.g., thermal-hydraulics, plant operations, cyber-security). Current safety/reliability modeling approaches to such systems are labor intensive, difficult to learn, and rely heavily on simplistic Boolean logic to depict failure propagation and accident progression. While these methods serve well for simple systems (i.e., linear causal systems with limited small inter- and intra-system interactions), their results are difficult to verify when modeling complex systems (typically performed through the extensive use of modeling assumptions). The development of new methods is addressed to meet these challenges through a model-based system engineering (MBSE) lens. Under MBSE philosophy, every aspect of the system (form or function) is represented by a model that completely characterizes its architecture or behavior. MBSE approach greatly improves the management of design, analysis and verification of complex systems. An integration of Dynamic Probabilistic Risk Assessment (DPRA) methods with MBSE models is proposed to perform safety/reliability analyses of engineering systems. In particular, MBSE representation of the system (performed using Systems Modeling Language [SysML]) is coupled with DPRA methods to automatically generate event trees and fault trees.

97 - MATHEMATICS AND COMPUTING↗

Rancor-HUNTER: Using a Simulator Engine for Realistic Human Performance Modeling of Nuclear Power Operations

The Human Unimodel for Nuclear Technology to Enhance Reliability (HUNTER) is a software system to simulate human performance in support of human reliability analysis (HRA) in nuclear power plants. This paper summarizes recent work to integrate HUNTER with a plant simulator, namely the Rancor Microworld Simulator. Rancor is an offshoot of earlier work at Idaho National Laboratory (INL) to support plant modernization. The graphical software tools used to mimic digital human-system interface upgrades at INL’s Human Systems Simulation Laboratory were linked to the Rancor Microworld Simulator, an INL-developed simplified plant model. HUNTER becomes a “virtual operator” coupled to the Rancor simulator, thereby allowing a tight coupling between a digital human twin and a digital twin of the plant. Rancor-HUNTER may be run through Monte Carlo iterations across a dynamic range of performance shaping factors, thereby producing distributions of human performance in terms of procedure paths, errors instantiations, and task durations. This paper overviews the various unique features of Rancor-HUNTER and presents an example run of Rancor-HUNTER for a startup scenario.

99 - GENERAL AND MISCELLANEOUS↗

Performing Numerical Analysis of Cybersecurity Options Using Dynamic Risk Analysis Tool EMRALD

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Considering a cyber threat should involve defense-in-depth methods and a quantitative or numerical evaluation of overall effectiveness against dynamic, time-dependent attacks to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related safety is a requirement set by North American Electric Reliability and the U.S. Nuclear Regulatory Commission. They are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks may focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want to know business reliability and recovery from those threats, and that requires modeling physical behavior of the targets. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with different tools having issues such as state-base explosion. Dynamic modeling enables time and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic numerical risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies. Keywords: cyber modeling; cyber-physical systems; numerical cyber modeling

97 - MATHEMATICS AND COMPUTING↗

PSA 2025 DPRA for Cyber Optimization

Cyberattacks can have many different attack paths, durations, and goals. There are also many different mitigation options involving hardware, software, and/or humans. Evaluating defense options should include quantitative evaluation of overall effectiveness to make cost and risk-informed decisions. Typical cyberattack modeling methods only provide a qualitative evaluation and have difficulty with time dependent scenarios. The main areas of cybersecurity are confidentiality, integrity, and availability. For companies with cyber-physical systems such as advanced nuclear reactors, cyber-related integrity is a requirement set by the U.S. Nuclear Regulatory Commission. But companies are also concerned about availability or reliability as a business case. As cyber threats are evolving to a business-for-hire structure, more attacks focus on disrupting business success and reliability, causing financial and economic stability risk. Companies want reliability analysis while optimizing cost, which requires more than safety modeling methods. Dynamic-state-based and Markov-based modeling provides a method for better cyber scenario modeling with timing and conditional features not found in other numerical evaluation methods. EMRALD (Event Modeling Risk Assessment using Lined Diagrams) is a dynamic risk analysis modeling and simulation tool and has features that reduce modeling issues such as state-base explosion found in Markov-based tools. It has been used to model different time-dependent events including plant behavior and operator procedures. As a general modeling tool, EMRALD can also be used to model cyberattack scenarios with varying mitigation options and quantify effectiveness, producing numerical data for risk-informed decisions. This paper uses EMRALD to demonstrate that dynamic risk analysis can be used for cyber threat modeling to provide insights for design decision-making and optimize defense strategies.

97 - MATHEMATICS AND COMPUTING↗