Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “SAFETY MARGINS”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 37 records · Page 2

Brazed Joints Design and Allowables: Discuss Margins of Safety in Critical Brazed Structures

This slide presentation tutorial discusses margins of safety in critical brazed structures. It reviews: (1) the present situation (2) definition of strength (3) margins of safety (4) design allowables (5) mechanical testing (6) failure criteria (7) design flowchart (8) braze gap (9) residual stresses and (10) delayed failures. This presentation addresses the strength of the brazed joints, the methods of mechanical testing, and our ability to evaluate the margins of safety of the brazed joints as it applies to the design of critical and expensive brazed assemblies.

FLom, Yury↗

An Approach for Defining IASMS Services, Functions, and Capabilities

Assuring safety in the NAS with the inclusion of new entrants, such as Advanced Air Mobility (AAM), will require overcoming unique safety challenges that result from combining innovative technologies with novel airspace concepts for moving people and cargo using autonomous vehicles. The focus of the In-time Aviation Safety Management System (IASMS) is to overcome AAM’s safety assurance challenges. The IASMS Concept of Operations (ConOps) describes an interconnected set of services, functions, and capabilities (SFCs) designed to manage operational risks, identify unknown risks, and inform system designs. This paper describes an approach for defining SFCs based on technology trends in research, assessment of known and unknown risks in voluntary safety reports, and causal and contributing factors in aviation accidents and incidents. This approach would identify potential SFCs that further expand the Monitor, Assess, and Mitigate (M-A-M) functionality that represents the enabling framework of the IASMS. Safety implications that will result from integration of AAM in the transformation of the National Airspace System (NAS) were addressed in National Academies committees reports on AAM and IASMS. Development of a ConOps for IASMS was a top recommendation and can be represented as a reframing of safety assurance that builds on real-time alerting such as the Traffic Alert and Collision Avoidance System, and adds the more encompassing in-time temporal parameter in recognition of the different timelines for collecting and assessing safety data for risk mitigations. For example, mining for safety trends from data sources such as the Aviation Safety Information Analysis and Sharing system occurs over a longer time period. Research on AAM operations poses that SFCs can be designed to monitor the safety margin appropriate for AAM including with regards to the distance between current flight parameters and nominal ideal conditions. These in-time comparisons will become more complex as the density of operations increases at least in certain areas and can include planned and actual 4D trajectory, and in-time comparisons having implications on conflict modeling and prediction including expected and actual departure time, fix/waypoint crossing times, and arrival time. These comparisons would be integrated as part of SFCs that redefine and inform new safety margin. An increased safety margin improves management of operational risks while reducing the potential for anomalies. An increased safety margin also has implications for operator confidence in the certainty of its operations and trust in automation. Technology trends in research could be used to refine existing SFCs and define needs for additional SFCs that provide safety improvements to the design and operation of vehicles, airspace design, and operator performance requirements. NASA is developing innovative approaches to safeguard against major accidents and incidents that have occurred in the NAS and those anticipated with the inclusion of envisioned AAM operations. The innovations use operational performance data to monitor, detect, and predict flight variations exceeding safe nominal patterns, such as would be caused by navigational error, severe weather complications, or hijacking of UAS controls. These innovative approaches have high potential to prevent accidents and incidents in the new AAM era. It is anticipated that elements of the innovations will evolve into SFCs for the IASMS. Voluntary safety reports can be monitored to identify anomalies related to design or operational performance risks. Reports could be periodically monitored and assessed for specific topics. Reports might serve as weak signals or precursors indicative of emergent risk such as when combined with other safety information. The architecture could include SFCs that are based on voluntary safety reports recognizing the periodic temporal nature of data analysis. As previously mentioned, aviation accidents with their causal and contributing precursors can inform the need for SFCs in the IASMS. Accidents and incidents at San Francisco International Airport such as Asiana 214 and Air Canada 759 illustrate how combinations of different factors lead to increased risk. These types of precursors and different factors have implications on the types of SFCs that could be needed to monitor and manage different sources and types of design and operational risk. Continuing to assure the safety of AAM as designs and operations gain in complexity can be accompanied by defining SFCs that also increase in complexity. These SFCs can leverage information from findings and recommendations synthesized across on-going research, voluntary safety reports, and accident and incident reports. These SFCs can serve to refine accuracy of algorithms and resolve limitations with current practices. The IASMS architecture represents the framework for the SFCs and their critical role in safety assurance.

In-Time Aviation Safety Management System↗

Developing Probabilistic Safety Performance Margins for Unknown and Underappreciated Risks

Probabilistic safety requirements currently formulated or proposed for space systems, nuclear reactor systems, nuclear weapon systems, and other types of systems that have a low-probability potential for high-consequence accidents depend on showing that the probability of such accidents is below a specified safety threshold or goal. Verification of compliance depends heavily upon synthetic modeling techniques such as PRA. To determine whether or not a system meets its probabilistic requirements, it is necessary to consider whether there are significant risks that are not fully considered in the PRA either because they are not known at the time or because their importance is not fully understood. The ultimate objective is to establish a reasonable margin to account for the difference between known risks and actual risks in attempting to validate compliance with a probabilistic safety threshold or goal. In this paper, we examine data accumulated over the past 60 years from the space program, from nuclear reactor experience, from aircraft systems, and from human reliability experience to formulate guidelines for estimating probabilistic margins to account for risks that are initially unknown or underappreciated. The formulation includes a review of the safety literature to identify the principal causes of such risks.

Safety Performance Margin↗

Development, fabrication and test of a high purity silica heat shield

A highly reflective hyperpure ( 25 ppm ion impurities) slip cast fused silica heat shield material developed for planetary entry probes was successfully scaled up. Process development activities for slip casting large parts included green strength improvements, casting slip preparation, aggregate casting, strength, reflectance, and subscale fabrication. Successful fabrication of a one-half scale Saturn probe (shape and size) heat shield was accomplished while maintaining the silica high purity and reflectance through the scale-up process. However, stress analysis of this original aggregate slip cast material indicated a small margin of safety (MS. = +4%) using a factor of safety of 1.25. An alternate hyperpure material formulation to increase the strength and toughness for a greater safety margin was evaluated. The alternate material incorporates short hyperpure silica fibers into the casting slip. The best formulation evaluated has a 50% by weight fiber addition resulting in an 80% increase in flexural strength and a 170% increase in toughness over the original aggregate slip cast materials with comparable reflectance.

Rusert, E. L.↗

Coolant passage heat transfer with rotation. A progress report on the computational aspects

Turbine airfoils are subjected to increasingly higher heat loads which escalate the cooling requirements in order to satisfy life goals for the component materials. If turbine efficiency is to be maintained, however, cooling requirements should be as low as possible. To keep the quantity of cooling air bounded, a more efficient internal cooling scheme must be developed. One approach is to employ airfoils with multipass cooling passages that contain devices to augment internal heat transfer while limiting pressure drop. Design experience with multipass cooling passage airfoils has shown that a surplus of cooling air must be provided as a margin of safety. This increased cooling air leads to a performance penalty. Reliable methods for predicting the internal thermal and aerodynamic performance of multipass cooling passage airfoils would reduce or eliminate the need for the safety margin of surplus cooling air. The objective of the program is to develop and verify improved analytical methods that will form the basis for design technology which will result in efficient turbine components with improved durability without sacrificing performance. The objective will be met by: (1) establishing a comprehensive experimental data base that can form the basis of an empirical design system; (2) developing computational fluid dynamic techniques; and (3) analyzing the information in the data base with both phenomenological modeling and mathematical modeling to derive a suitable design and analysis procedure.

Aceto, L. D.↗

ASRM nozzle thermal analysis

This report describes results from the nozzle thermal analysis contract which has been performed to support NASA/Marshall Space Flight Center in the development of the Advanced Solid Rocket Motor (ASRM). The emphasis of this study has been directed to four potential problem areas of the nozzle. These areas are the submerged nozzle region containing the flex seal, the nozzle entrance region, the material interface region in the nozzle exit cone, and the aft region of the exit cone. This study was limited throughout by inadequate material response models, especially for the polyisoprene flex seal and the low density carbon phenolic used in the exit cone. Thermal response and particle erosion calculations were performed for each of the potential problem areas. Results from these studies showed excessive erosion (large negative safety margins) to occur in the flex seal and nozzle entrance regions. The exit cone was found to be marginally adequate (near zero safety margins) and the material interface region was found not to be a problem.

Strobel, Forrest↗

A Conceptual Aerospace Vehicle Structural System Modeling, Analysis and Design Process

A process for aerospace structural concept analysis and design is presented, with examples of a blended-wing-body fuselage, a multi-bubble fuselage concept, a notional crew exploration vehicle, and a high altitude long endurance aircraft. Aerospace vehicle structures must withstand all anticipated mission loads, yet must be designed to have optimal structural weight with the required safety margins. For a viable systems study of advanced concepts, these conflicting requirements must be imposed and analyzed early in the conceptual design cycle, preferably with a high degree of fidelity. In this design process, integrated multidisciplinary analysis tools are used in a collaborative engineering environment. First, parametric solid and surface models including the internal structural layout are developed for detailed finite element analyses. Multiple design scenarios are generated for analyzing several structural configurations and material alternatives. The structural stress, deflection, strain, and margins of safety distributions are visualized and the design is improved. Over several design cycles, the refined vehicle parts and assembly models are generated. The accumulated design data is used for the structural mass comparison and concept ranking. The present application focus on the blended-wing-body vehicle structure and advanced composite material are also discussed.

Mukhopadhyay, Vivek↗

Structural Analyses and Margins of Safety

There is an increasing reliance on modeling and simulation to verify, quantify, and certify designs of complex structures. The availability of a range of commercial modeling and simulations tools and packages with a variety of capabilities, in conjunction with increased computational resources, is allowing analysts to rapidly perform detailed analyses. However, care should be taken to understand specific tool limitations, assumptions, and boundary conditions as erroneous results can be generated without being recognized by the analysts. In addition, the reported margins of safety should be carefully interrogated to identify any false positive or negative margins and highlight any areas for structural concern.

Structural Analyses↗

Orion MPCV Touchdown Detection Threshold Development and Testing

A robust method of detecting Orion Multi ]Purpose Crew Vehicle (MPCV) splashdown is necessary to ensure crew and hardware safety during descent and after touchdown. The proposed method uses a triple redundant system to inhibit Reaction Control System (RCS) thruster firings, detach parachute risers from the vehicle, and transition to the post ]landing segment of the Flight Software (FSW). The vehicle crew is the prime input for touchdown detection, followed by an autonomous FSW algorithm, and finally a strictly time based backup timer. RCS thrusters must be inhibited before submersion in water to protect against possible damage due to firing these jets under water. In addition, neglecting to declare touchdown will not allow the vehicle to transition to post ]landing activities such as activating the Crew Module Up ]righting System (CMUS), resulting in possible loss of communication and difficult recovery. A previous AIAA paper gAssessment of an Automated Touchdown Detection Algorithm for the Orion Crew Module h concluded that a strictly Inertial Measurement Unit (IMU) based detection method using an acceleration spike algorithm had the highest safety margins and shortest detection times of other methods considered. That study utilized finite element simulations of vehicle splashdown, generated by LS ]DYNA, which were expanded to a larger set of results using a Kriging surface fit. The study also used the Decelerator Systems Simulation (DSS) to generate flight dynamics during vehicle descent under parachutes. Proto ]type IMU and FSW MATLAB models provided the basis for initial algorithm development and testing. This paper documents an in ]depth trade study, using the same dynamics data and MATLAB simulations as the earlier work, to further develop the acceleration detection method. By studying the combined effects of data rate, filtering on the rotational acceleration correction, data persistence limits and values of acceleration thresholds, an optimal configuration was determined. The lever arm calculation, which removes the centripetal acceleration caused by vehicle rotation, requires that the vehicle angular acceleration be derived from vehicle body rates, necessitating the addition of a 2nd order filter to smooth the data. It was determined that using 200 Hz data directly from the vehicle IMU outperforms the 40 Hz FSW data rate. Data persistence counter values and acceleration thresholds were balanced in order to meet desired safety and performance. The algorithm proved to exhibit ample safety margin against early detection while under parachutes, and adequate performance upon vehicle splashdown. Fall times from algorithm initiation were also studied, and a backup timer length was chosen to provide a large safety margin, yet still trigger detection before CMUS inflation. This timer serves as a backup to the primary acceleration detection method. Additionally, these parameters were tested for safety on actual flight test data, demonstrating expected safety margins.

Daum, Jared↗

Evaluation of Margins of Safety in Brazed Joints

One of the essential steps in assuring reliable performance of high cost critical brazed structures is the assessment of the Margin of Safety (MS) of the brazed joints. In many cases the experimental determination of the failure loads by destructive testing of the brazed assembly is not practical and cost prohibitive. In such cases the evaluation of the MS is performed analytically by comparing the maximum design loads with the allowable ones and incorporating various safety or knock down factors imposed by the customer. Unfortunately, an industry standard methodology for the design and analysis of brazed joints has not been developed. This paper provides an example of an approach that was used to analyze an AlBeMet 162 (38%Be-62%Al) structure brazed with the AWS BAlSi-4 (Al-12%Si) filler metal. A practical and conservative interaction equation combining shear and tensile allowables was developed and validated to evaluate an acceptable (safe) combination of tensile and shear stresses acting in the brazed joint. These allowables are obtained from testing of standard tensile and lap shear brazed specimens. The proposed equation enables the assessment of the load carrying capability of complex brazed joints subjected to multi-axial loading.

Flom, Yury↗

RAVEN Theory Manual

RAVEN is a software framework able to perform parametric and stochastic analysis based on the response of complex system codes. The initial development was aimed at providing dynamic risk analysis capabilities to the thermohydraulic code RELAP-7, currently under development at Idaho National Laboratory (INL). Although the initial goal has been fully accomplished, RAVEN is now a multi-purpose stochastic and uncertainty quantification platform, capable of communicating with any system code. In fact, the provided Application Programming Interfaces (APIs) allow RAVEN to interact with any code as long as all the parameters that need to be perturbed are accessible by input files or via python interfaces. RAVEN is capable of investigating system response and explore input space using various sampling schemes such as Monte Carlo, grid, or Latin hypercube. However, RAVEN strength lies in its system feature discovery capabilities such as: constructing limit surfaces, separating regions of the input space leading to system failure, and using dynamic supervised learning techniques. The development of RAVEN started in 2012 when, within the Nuclear Energy Advanced Modeling and Simulation (NEAMS) program, the need to provide a modern risk evaluation framework arose. RAVEN’s principal assignment is to provide the necessary software and algorithms in order to employ the concepts developed by the Risk Informed Safety Margin Characterization (RISMC) program. RISMC is one of the pathways defined within the Light Water Reactor Sustainability (LWRS) program. In the RISMC approach, the goal is not just to identify the frequency of an event potentially leading to a system failure, but the proximity (or lack thereof) to key safety-related events. Hence, the approach is interested in identifying and increasing the safety margins related to those events. A safety margin is a numerical value quantifying the probability that a safety metric (e.g. peak pressure in a pipe) is exceeded under certain conditions. Most of the capabilities, implemented having RELAP-7 as a principal focus, are easily deployable to other system codes. For this reason, several side activates have been employed (e.g. RELAP5-3D, any MOOSE-based App, etc.) or are currently ongoing for coupling RAVEN with several different software. The aim of this document is to provide a set of commented examples that can help the user to become familiar with the RAVEN code usage.

97 MATHEMATICS AND COMPUTING↗

RAVEN User Manual

RAVEN is a generic software framework to perform parametric and probabilistic analysis based on the response of complex system codes. The initial development was aimed to provide dynamic risk analysis capabilities to the Thermo-Hydraulic code RELAP-7, currently under development at the Idaho National Laboratory (INL). Although the initial goal has been fully accomplished, RAVEN is now a multi-purpose probabilistic and uncertainty quantification platform, capable to agnostically communicate with any system code. This agnosticism includes providing Application Programming Interfaces (APIs). These APIs are used to allow RAVEN to interact with any code as long as all the parameters that need to be perturbed are accessible by inputs files or via python interfaces. RAVEN is capable of investigating the system response, and investigating the input space using Monte Carlo, Grid, or Latin Hyper Cube sampling schemes, but its strength is focused to- ward system feature discovery, such as limit surfaces, separating regions of the input space leading to system failure, using dynamic supervised learning techniques. The development of RAVEN has started in 2012, when, within the Nuclear Energy Advanced Modeling and Simulation (NEAMS) program, the need to provide a modern risk evaluation framework became stronger. RAVEN principal assignment is to provide the necessary software and algorithms in order to employ the concept developed by the Risk Informed Safety Margin Characterization (RISMC) program. RISMC is one of the pathways defined within the Light Water Reactor Sustainability (LWRS) program. In the RISMC approach, the goal is not just the individuation of the frequency of an event potentially leading to a system failure, but the closeness (or not) to key safety-related events. Hence, the approach is interested in identifying and increasing the safety margins related to those events. A safety margin is a numerical value quantifying the probability that a safety metric (e.g. for an important process such as peak pressure in a pipe) is exceeded under certain conditions. The initial development of RAVEN has been focused on providing dynamic risk assessment capability to RELAP-7, currently under development at the INL and, likely, future replacement of the RELAP5-3D code. Most the capabilities that have been implemented having RELAP-7 as principal focus are easily deployable for other system codes. For this reason, several side activates are currently ongoing for coupling RAVEN with soft- ware such as RELAP5-3D, etc. The aim of this document is the explanation of the input requirements, focalizing on the input structure.

97 MATHEMATICS AND COMPUTING↗

Derivation of improved load transformation matrices for launchers-spacecraft coupled analysis, and direct computation of margins of safety

Load and stress recovery from transient dynamic studies are improved upon using an extended acceleration vector in the modal acceleration technique applied to structural analysis. Extension of the normal LTM (load transformation matrices) stress recovery to automatically compute margins of safety is presented with an application to the Hubble space telescope.

Klein, M.↗

Dynamic Probabilistic Safety Assessment Studies for Advanced Reactor Using RAVEN

Probabilistic Safety Assessment (PSA) is used extensively to evaluate the risks associated with complex engineering systems like Nuclear Power Plants (NPPs). Current PSA models are based on the Event-Tree/Fault-Tree (ET/FT) methodology. ET and FT models are static and are based on Boolean logic approaches. In the past, concerns have been raised in the literature regarding the capability of the traditional static modelling approaches to adequately account for the impact of process, hardware, software, firmware and human interactions on the stochastic system behaviour. To overcome the limitations of the traditional approach to PSA, several dynamic PSA methodologies have been proposed. One of the dynamic PSA methodologies used for dynamic evaluations is Dynamic Event Tree (DET) framework which can be used to assess the impact of the parameter variability and scenario dynamics on the PSA model for the initiating event. The DET framework couples the stochastic model (number of component/trains that start on demand, operator action timing, etc.) with a Thermal-Hydraulic (TH) model of the plant. This paper explores the use of DET along with a case study on advanced reactor. The initiating event selected for the study was Class IV power supply failure event. The TH analysis considering uncertainty in various parameters was performed using RELAP5 and Reactor Analysis and Virtual control ENvironment (RAVEN) tool. Based on the uncertainty analysis, it is concluded that the peak clad temperatures (PCT) are within the limits in all the code runs implying a high-degree of safety margin. However, variation in time to reach the PCT was observed among the code runs and the mean time to reach the PCT was found to be around 8590sec (approximately 2.4 hours). Hence, sufficient time margin is available for human intervention and the operator might have a relatively stress-free state during such an accident scenario. Due to the static nature of the traditional PSA models, the safety margin available was lesser, whereas, with the help of dynamic PSA models, one can demonstrate that the actual available safety margin is more in the present case study and is valuable input from the design point of view.

99 GENERAL AND MISCELLANEOUS↗

Fuel performance evaluation of two high burnup PWR core designs during normal operation, control rod withdrawal, and control rod ejection scenarios

There is interest among utilities to extend the current, 18-month operating cycle to 24 months. Economically, this extension would require greater than 5 % enrichment and peak rod average discharge burnup levels above 62 GWd/MTU. A notable challenge of increasing enrichment is the resulting additional excess reactivity encountered during the early stages of fuel life. To accommodate, burnable absorbers beyond soluble boron are introduced into the fuel system. In high burnup fuels, the possibilities of cladding lift-off and fuel melting increase due, in part, to increased rod internal pressures and limited fuel thermal conductivity, respectively. This work collaboratively employs PARCS, RELAP5-3D, and BISON to compare the fuel performance of two high burnup fuel candidates with higher than 5 % enrichment. Here, the fuel performance parameters were compared to current NRC guidance. The results demonstrate an annular fuel design with homogenously blended gadolinium as a burnable absorber operates with greater safety margins during normal operation, allowing for additional operational flexibility. During normal operation, the core design utilizing Integral Fuel Burnable Absorber pins contained fuel pins which reached plenum pressures above 15.5 MPa by the end of the first fuel cycle and fuel pins experienced cladding hoop strains above 1 %. In the Gd core design, only two observed pins experienced plenum pressures above 15.5 MPa and no pins exceeded 1 % cladding hoop strain. During the control rod withdrawal scenario, plenum pressures for pins in both designs marginally exceeded system pressure, however neither experienced excessive hoop strain. The Gd core design experienced a maximum fuel temperature of 2418 K, which is significantly higher than the Integral Fuel Burnable Absorber design at 2157 K, but still within regulatory guidance. We predicted that the fuel in both could return to service after the CRW event. We also predicted that cladding would not fail during the Control Rod Ejection in either core design. Generally, the Integral Fuel Burnable Absorber core design performed with greater safety margin with regards to temperature during normal operation and the transient events. However, the Gd core design performed with greater safety margin regarding plenum pressure and hoop strain limits during normal operation and both transient events.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Calculating Radiation Damage (DPA) from Transmutation Products

This is a poster for an INL poster session. Accurate models for radiation damage are crucial for predicting material performance in radiation environments. The uncertainty of state-of-the-art radiation damage models is large, contributing to excessive safety margins. A major source of this uncertainty is neglecting the effect that transmutation products have on radiation damage. Transmutation products are new nuclides formed by neutron activation during irradiation; they can contribute to radiation damage by additional neutron capture or decay events. Ignoring the contribution of transmutation products leads to a significant underprediction of the radiation damage (e.g., >10% error in 316 stainless steel). This underprediction is accounted for in part by adding larger safety margins to designs. Currently, the state of the art explicitly accounts for only a single transmutation product, namely nickel-59, during the radiation damage calculation. All other transmutation products are assumed to not contribute to the radiation damage, because there is currently no established method to systematically track all or a selection of radiation damage contributions of transmutation products during activation. In the case of nickel-59, the current method is to apply a precalculated correlation that cannot be used for any other nuclide and is largely dependent on all nuclear engineers being experts in this niche topic. This project proposed to methodically find other transmutation products that cause significant radiation damage, and then to develop a general framework for systematically tracking the radiation damage from these nuclides. This was accomplished by combining the radiation damage calculation into the transmutation calculation already performed for irradiated structural materials. The key idea of our framework is to introduce radiation-damage "pseudo-nuclides" to the list of nuclides used in the transmutation analysis. This allows radiation damage to be tracked alongside the creation and destruction of transmutation products. The main deliverable of this project is a general framework for computing radiation damage while the damaged material undergoes transmutation; this capability allows a significantly more accurate estimation of radiation damage, and in turn reduce required safety margins thereby reducing the cost to construct reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Quantitative Risk Analysis of High Safety Significant Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants using IRADIC Technology

This report documents the activities performed by Idaho National Laboratory (INL) during fiscal year (FY) 2021 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) Risk Assessment project. In FY-2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems (IRADIC technology) was proposed for this strategy, which aims to (1) provide a best-estimate risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the High Safety Significant Safety-related (HSSSR) DI&C systems, (2) develop an advanced risk assessment technology to support transition from analog to DI&C technologies for nuclear industry, (3) assure the long-term safety and reliability of vital HSSSR DI&C systems, (4) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the IRADIC technology is instructive for nuclear vendors and utilities to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify responding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the individual level, system level, and plant level, (4) providing insights and suggestions on designs to manage the risks; thus, to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). In this report, an approach for performing software CCF analysis, given limited data, is developed and demonstrated using a case study of a highly redundant digital reactor trip system. Consequence analysis is also performed based on different accident scenarios. Results indicate that plant modernization including the improvement of HSSSR DI&C systems will make great benefits to plant safety by providing more safety margins to accident management. In addition, a novel approach is proposed in this report for the quantification of software hazards when sufficient operational and testing data available. The method incorporates software development quality as well as strong analysis techniques to identify and link software defects to potential failure modes. The approach includes both semantic and test-based analysis to detect failures that can exist in different stages of the software development life cycle. This method is applied to an advanced human system interface relevant to reactor trip safety developed from the APR 1400 design.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

An Integrated Framework for Risk Assessment of Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology Advancement and Application

This report documents activities performed by Idaho National Laboratory (INL) during fiscal year (FY) 2024 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, Digital Instrumentation and Control (DI&C) Risk Assessment project. The goal of the RISA Pathway is to optimize safety margins and minimize uncertainties to achieve economic efficiencies while maintaining high levels of safety. This is accomplished by providing scientific basis to better represent safety margins and factors that contribute to cost and safety, and by developing new technologies that reduce operating costs. The research efforts for FY 2024 encompass methodology refinement and exploration. The efforts include: (1) The implementation of a natural language processing tool to expedite key aspects of the reliability analysis methods developed by INL; (2) advances to support intersystem CCF analysis by providing guidance for and identification of coupling mechanisms that may contribute to CCF; (3) the investigation of how generative artificial intelligence tools can aid in hazard analysis and diversity and defense in depth (i.e., D3) assessments; (4) Industry collaboration, allowing the demonstration of and INL's risk assessment tools to support risk assessment of DI&C systems at early and late stages of development; (4) a roadmap for the development of a software for each of INL's risk assessment tools; (5) The development of a theory and methodology manual for a risk quantification methodology; (6) the development of a reliability analysis for machine learning (ML)-integrated control systems.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗