Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Common Cause Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Failure Mechanism Traceability and Application in Human System Interface of Nuclear Power Plants using RESHA

In recent years, there has been considerable effort to modernize existing and new nuclear power plants with digital instrumentation and control systems (DI&C). However, there has also been considerable concern both by industry and regulatory bodies for the risk and consequence analysis of these systems. Of particular concern are digital common cause failures (CCFs) specifically related to software defects. These “misbehaviors” by the software can occur in both the control and monitoring of a system. While many new methods have been proposed to identify potential software failure modes, such as Systems-theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), etc., these methods are focused primarily on the control action pathway of a system. In contrast, the information feedback pathway lacks unsafe control actions (UCAs), which are typically related to software basic events; thus, assessment of software basic events in such systems is unclear. In this work, we present the idea of intermediate processors and unsafe information flow (UIF) to help safety analysts trace failure mechanisms in the feedback pathway and how they can be integrated into a fault tree for improved assessment capability. The concepts presented are demonstrated in two comprehensive case studies, a smart sensor integrated platform for unmanned autonomous vehicles and another on a representative advanced human system interface (HSI) for safety critical plant monitoring. The qualitative software basic events are identified, and a fault tree analysis is conducted based on a modified Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) methodology. The case studies demonstrate the use of UIF and intermediate processors in the fault tree to improve traceability of software failures in highly complex digital instrumentation feedback. The improved method can also clarify fault tree construction when multiple component dependencies are present in the system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Failure Mechanism Traceability and Application in Human System Interface of Nuclear Power Plants using RESHA

In recent years, there has been considerable effort to modernize existing and new nuclear power plants with digital instrumentation and control systems (DI&C). However, there has also been considerable concern both by industry and regulatory bodies for the risk and consequence analysis of these systems. Of particular concern are digital common cause failures (CCFs) specifically related to software defects. These “misbehaviors” by the software can occur in both the control and monitoring of a system. While many new methods have been proposed to identify potential software failure modes, such as Systems-theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), etc., these methods are focused primarily on the control action pathway of a system. In contrast, the information feedback pathway lacks unsafe control actions (UCAs), which are typically related to software basic events; thus, assessment of software basic events in such systems is unclear. In this work, we present the idea of intermediate processors and unsafe information flow (UIF) to help safety analysts trace failure mechanisms in the feedback pathway and how they can be integrated into a fault tree for improved assessment capability. The concepts presented are demonstrated in two comprehensive case studies, a smart sensor integrated platform for unmanned autonomous vehicles and another on a representative advanced human system interface (HSI) for safety critical plant monitoring. The qualitative software basic events are identified, and a fault tree analysis is conducted based on a modified Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) methodology. The case studies demonstrate the use of UIF and intermediate processors in the fault tree to improve traceability of software failures in highly complex digital instrumentation feedback. The improved method can also clarify fault tree construction when multiple component dependencies are present in the system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Evaluation of Hardware and Software Bill of Materials (HBOMs/SBOMs) Extraction Methods

Hardware and software bills of materials (HBOMs and SBOMs) provide important visibility into the components, dependencies, and supply chain relationships within programmable digital devices. This visibility is critical for advanced nuclear reactor applications, where use of common or shared hardware components, software libraries, suppliers, or manufacturing processes may create common cause failure (CCF) vulnerabilities despite apparent diversity. This paper evaluates current approaches for obtaining and analyzing HBOMs and SBOMs in support of CCF, diversity and defense-in-depth (D3) assessments, and begins to explore potential methods for artificial intelligence/machine learning-based analysis. The availability of BOM information from advanced reactor manufacturers and vendors, representative hardware and software categories found in advanced reactor systems continues to limit research [13]. This paper compares commonly used BOM formats, including CycloneDX, SPDX, and SWID. It also surveys publicly available tools for generating BOMs from source code, compiled binaries, and hardware-related information, noting limitations in language coverage, system age, and format interoperability. Finally, this paper evaluates methods for correlating BOM data with vulnerability and exploitability information, including VEX, CVE, and CWE resources. The findings indicate that publicly available nuclear-vendor BOMs are limited, making third-party extraction and research into novel analysis techniques necessary.

Cybersecurity↗

An Integrated Framework for Risk Assessment of Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology Refinement and Exploration

This report documents activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2023 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a technical basis to support effective, and secure DI&C technologies for digital upgrades/designs. A risk assessment-informed framework was proposed for this strategy, which aims to (1) provide a best-estimate, risk informed capability to quantitatively estimate the safety margin obtained from plant modernization, especially for safety-related DI&C systems, (2) support and supplement existing risk informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems, (4) assure the long-term safety and reliability of safety-related DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals, the LWRS-developed framework provides a means to address relevant technical issues by: (1) defining a risk informed analysis process for DI&C upgrade that integrates hazard analysis, reliability analysis, and consequence analysis, (2) applying risk informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development and deployment of advanced DI&C technologies in nuclear power plants (NPPs). Adding diversity within a system or components is the primary means to eliminate and mitigate CCFs, but diversity also increases system complexity and may not address all sources of systematic failures. Optimization of diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in safety-related DI&C systems of NPPs and supporting relevant design optimization, the proposed framework provides: (a) A best-estimate, risk informed capability to address new technical digital issues quantitatively, focusing on software CCFs in safety-related DI&C systems of NPPs; (b) A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to predict and prevent risk in the early design stage of DI&C systems; (c) Technical bases and risk informed insights to assist users address the risk informed alternatives for evaluation of CCFs in safety-related DI&C systems of NPPs; and (d) A risk informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The research and development efforts of this project in FY 2023 are focused on refining current methods on software CCF modeling and estimation and exploring additional innovative approaches to risk assessment of DI&C systems to enable a more comprehensive and complete assessment of various safety-related DI&C design architectures. The primary audience of this report are DI&C designers, engineers, and probabilistic risk assessment (PRA) practitioners. This includes stakeholders, such as the nuclear utilities and regulators who consider the deployment and upgrade of DI&C systems, DI&C software developers and reviewers, and cybersecurity specialists. It should be noted that all the analyses are performed for the demonstration of the methodology, not for the evaluation of an actual digital control system. Results are obtained based on limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Risk Analysis of Various Design Architectures for High Safety-significant Safety-related Digital Instrumentation and Control Systems of Nuclear Power Plants during Accident Scenarios

This report documents the plus-up activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2022 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems was proposed for this strategy, which aims to (1) provide a best-estimate, risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the high safety-significant safety-related (HSSSR) DI&C systems, (2) support and supplement existing advanced risk-informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems to support system design decisions and diversity and redundancy applications, (4) assure the long-term safety and reliability of HSSSR DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the LWRS-developed framework instructs nuclear vendors and utilities on how to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). Adding diversity within system or components is the main means to eliminate and mitigate CCFs, but diversity also increases plant complexity and errors and may not address all sources of systematic failures. How to optimize the diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in HSSSR DI&C systems of NPPs and supporting relevant design optimization, the framework provides: ? An integrated best-estimate, risk-informed capability to address new technical digital issues quantitatively, accurately, and efficiently in plan modernization progress, such as software CCFs in HSSSR DI&C systems of NPPs ? A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to efficiently predict and prevent risk in the early design stage of DI&C systems ? Technical bases and risk-informed insights to assist U.S. Nuclear Regulatory Commission (NRC) and industry to address and fulfill the risk-informed alternatives for evaluation of CCFs in HSSSR DI&C systems of NPPs ? An integrated risk-informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The plus-up research and development efforts of this project in FY 2022 are focused on methodology improvement of software CCF modeling and estimation, prevention analysis, importance analysis and risk analysis of various design architectures of HSSSR DI&C systems. This work greatly enhances the capability of the LWRS-developed framework for the risk assessment and design optimization of safety-critical DI&C systems. It should be noted that all the analyses are performed for the demonstration of the LWRS-developed framework, not for the evaluation of relevant systems. Results are obtained based on very limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Evaluation of Joint Cyber/Safety Risk in Nuclear Power Systems

This report presents an analysis of the Emergency Core Cooling System (ECCS) for a generic Boiling Water Reactor (BWR)-4 NPP. The Electric Power Research Institute (EPRI) developed Hazards and Consequences Analysis for Digital Systems (HAZCADS) process is applied to the ECCS and its subsystems to identify unsafe control actions (UCAs) which act as possible cyber events of concern. The analysis is performed for two design basis events: Small-break Loss of Coolant Accident (SLOCA) and general transients (TRANS), such as unintended reactor trip. In previous work, HAZCADS UCAs were combined with other cyber-attack analysis to develop a risk-informed approach; however, this was for a single system. This report explores advanced systems engineering modeling approaches to model the interactions between digital assets across multiple systems which may be targeted by cyber adversaries. The complex and interdependent design of digital systems has the potential to introduce emergent cyber properties that are generally not covered by hazard analyses nor formal nuclear Probabilistic Risk Assessment (PRA). The R&D and supporting analysis presented here explores approaches to predict and manage how interdependent system properties effect risk. To show the potential impact of a successful cyber-attack to formal PRA event tree probabilities, HAZCADS analysis was also used. HAZCADS was also used to model the automatic depressurization system (ADS) automatic actuation. This analysis extended to an integrated system analysis for common-cause failure (CCF). In this aspect, the HAZCADS analysis continued by analyzing plant design details for system connectivity in support of critical plant functions. A dependency matrix was developed to depict the integrated functionality of the interconnected systems. Areas of potential CCF are indicated. Future work could include adversary attack development to show how CCF could be caused, resulting in PRA events. Across the multiple systems that comprise the ECCS, the analysis shows that the change in such probabilities was very different between systems. This indicates that some systems have a larger potential risk impact from successful cyber-attack or digital failure, which indicates a need for these systems to have a higher priority for design and defensive measures. Furthermore, we were able to establish that a risk analysis using any arbitrary threat model establishes an ordering of components with regard to cyber-risk. This ordering can be used to influence the overall system design with an eye to lowering risk, or as a way to understand real-time risk to operational systems based on a current threat landscape. Expert knowledge of both the analysis process and the system being analyzed is required to perform a HAZCADS analysis. The need for a tiered risk analysis is demonstrated by the results of this report.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

An Integrated Framework for Risk Assessment of High Safety Significant Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology and Demonstration

This report documents the activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2022 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a technical basis to support effective and secure DI&C technologies for digital upgrades/designs. A framework was proposed for this strategy, which aims to (1) provide a best-estimate, risk-informed capability to quantitatively and accurately estimate the risk impact of plant modernization, considering the introduction of high safety-significant safety-related (HSSSR) DI&C systems, (2) support and supplement existing risk-informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems, (4) assure the long-term safety and reliability of HSSSR DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals, the framework provides a means to address relevant technical issues by: (1) defining a risk-informed analysis process for DI&C upgrade, that integrates hazard analysis, reliability analysis, and consequence analysis, (2) applying risk-informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development and deployment of advanced DI&C technologies on nuclear power plant (NPPs).

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Programmable Digital Devices used in Advanced Reactors

This paper introduces the concepts of common cause failure, diversity, and defense-in-depth used by the nuclear industry to analyze resilience in reactors. A survey of publicly traded and private companies building advanced reactors and their licensing status is presented. Safety and non-safety systems found in the NuScale Power design are summarized and the likely hardware and software categories used by those systems are enumerated. The importance of industry partners is highlighted. This paper also identifies an alternate path forward without industry partners to advance the knowledge needed to use artificial intelligence to analyze HBOMs and SBOMs to better understand reactor resiliency.

cybersecurity↗

Aircraft cabin water spray disbenefits study

The concept of utilizing a cabin water spray system (CWSS) as a means of increasing passenger evacuation and survival time following an accident has received considerable publicity and has been the subject of testing by the regulatory agencies in both the United States and Europe. A test program, initiated by the CAA in 1987, involved the regulatory bodies in both Europe and North America in a collaborative research effort to determine the benefits and 'disbenefits' (disadvantages) of a CWSS. In order to obtain a balanced opinion of an onboard CWSS, NASA, and FAA requested the Boeing Commercial Airplane Group to investigate the potential 'disbenefits' of the proposed system from the perspective of the manufacturer and an operator. This report is the result of a year-long, cost-sharing contract study between the Boeing Commercial Airplane Group, NASA, and FAA. Delta Air Lines participated as a subcontract study team member and investigated the 'return to service' costs for an aircraft that would experience an uncommanded operation of a CWSS without the presence of fire. Disbenefits identified include potential delays in evacuation, introduction of 'common cause failure' in redundant safety of flight systems, physiological problems for passengers, high cost of refurbishment for inadvertent discharge, and potential to negatively affect other safety systems.

Reynolds, Thomas L.↗

Factors which Limit the Value of Additional Redundancy in Human Rated Launch Vehicle Systems

The National Aeronautics and Space Administration (NASA) has embarked on an ambitious program to return humans to the moon and beyond. As NASA moves forward in the development and design of new launch vehicles for future space exploration, it must fully consider the implications that rule-based requirements of redundancy or fault tolerance have on system reliability/risk. These considerations include common cause failure, increased system complexity, combined serial and parallel configurations, and the impact of design features implemented to control premature activation. These factors and others must be considered in trade studies to support design decisions that balance safety, reliability, performance and system complexity to achieve a relatively simple, operable system that provides the safest and most reliable system within the specified performance requirements. This paper describes conditions under which additional functional redundancy can impede improved system reliability. Examples from current NASA programs including the Ares I Upper Stage will be shown.

Anderson, Joel M.↗

Techniques for Assuring NASA Mission Success Using Redundancy and Multi-Functionality Designs

Topics include NASA centers around the country; 2009 highlights of significant successes in space transportation, exploration, and science; significant accomplishments; places to explore include Lagrange points, near-Earth objects, Mars and the Moon, and International Space Station research; Marshall's missions include propulsion and transportation systems, life support systems, and earth and space science spacecraft, systems, and operations; project lifecycle management model; motivation of avionics fault-tolerance, redundancy needs and concerns, redundancy versus reliability; parallel-series configurations; effect of adding redundancy on mission success; example of rules-based approach where reliability and safety interaction impacts design; impact of common cause failure; approach ot bottom-up reliability analysis; three factors that lead to redundant system failure; Apollo 13 multi-functional reliability and example; and mitigating the risk of single string spacecraft architecture;.

Shivers, Herb↗

Practical Application of PRA as an Integrated Design Tool for Space Systems

This paper presents the application of the first comprehensive Probabilistic Risk Assessment (PRA) during the design phase of a joint NASA/NOAA weather satellite program, Geostationary Operational Environmental Satellite Series R (GOES-R). GOES-R is the next generation weather satellite primarily to help understand the weather and help save human lives. PRA has been used at NASA for Human Space Flight for many years. PRA was initially adopted and implemented in the operational phase of manned space flight programs and more recently for the next generation human space systems. Since its first use at NASA, PRA has become recognized throughout the Agency as a method of assessing complex mission risks as part of an overall approach to assuring safety and mission success throughout project lifecycles. PRA is now included as a requirement during the design phase of both NASA next generation manned space vehicles as well as for high priority robotic missions. The influence of PRA on GOES-R design and operation concepts are discussed in detail. The GOES-R PRA is unique at NASA for its early implementation. It also represents a pioneering effort to integrate risks from both Spacecraft (SC) and Ground Segment (GS) to fully assess the probability of achieving mission objectives. PRA analysts were actively involved in system engineering and design engineering to ensure that a comprehensive set of technical risks were correctly identified and properly understood from a design and operations perspective. The analysis included an assessment of SC hardware and software, SC fault management system, GS hardware and software, common cause failures, human error, natural hazards, solar weather and infrastructure (such as network and telecommunications failures, fire). PRA findings directly resulted in design changes to reduce SC risk from micro-meteoroids. PRA results also led to design changes in several SC subsystems, e.g. propulsion, guidance, navigation and control (GNC), communications, mechanisms, and command and data handling (C&DH). The fault tree approach assisted in the development of the fault management system design. Human error analysis, which examined human response to failure, indicated areas where automation could reduce the overall probability of gaps in operation by half. In addition, the PRA brought to light many potential root causes of system disruptions, including earthquakes, inclement weather, solar storms, blackouts and other extreme conditions not considered in the typical reliability and availability analyses. Ultimately the PRA served to identify potential failures that, when mitigated, resulted in a more robust design, as well as to influence the program's concept of operations. The early and active integration of PRA with system and design engineering provided a well-managed approach for risk assessment that increased reliability and availability, optimized lifecyc1e costs, and unified the SC and GS developments.

Kalia, Prince↗

Scaling Impacts in Life Support Architecture and Technology Selection

For long-duration space missions outside of Earth orbit, reliability considerations will drive higher levels of redundancy and/or on-board spares for life support equipment. Component scaling will be a critical element in minimizing overall launch mass while maintaining an acceptable level of system reliability. Building on an earlier reliability study (AIAA 2012-3491), this paper considers the impact of alternative scaling approaches, including the design of technology assemblies and their individual components to maximum, nominal, survival, or other fractional requirements. The optimal level of life support system closure is evaluated for deep-space missions of varying duration using equivalent system mass (ESM) as the comparative basis. Reliability impacts are included in ESM by estimating the number of component spares required to meet a target system reliability. Common cause failures are included in the analysis. ISS and ISS-derived life support technologies are considered along with selected alternatives. This study focusses on minimizing launch mass, which may be enabling for deep-space missions.

Lange, Kevin↗

Methods and Costs to Achieve Ultra Reliable Life Support

A published Mars mission is used to explore the methods and costs to achieve ultra reliable life support. The Mars mission and its recycling life support design are described. The life support systems were made triply redundant, implying that each individual system will have fairly good reliability. Ultra reliable life support is needed for Mars and other long, distant missions. Current systems apparently have insufficient reliability. The life cycle cost of the Mars life support system is estimated. Reliability can be increased by improving the intrinsic system reliability, adding spare parts, or by providing technically diverse redundant systems. The costs of these approaches are estimated. Adding spares is least costly but may be defeated by common cause failures. Using two technically diverse systems is effective but doubles the life cycle cost. Achieving ultra reliability is worth its high cost because the penalty for failure is very high.

deep space life support↗

Safety Expertise and the Perils of Novelty

Emerging aviation markets such as urban air mobility are giving rise to new technologies and means of operation. However, novelty may hide ‘unknown unknowns,’ raising new hazards. This paper examines how expertise and safety techniques enable transformative technologies such as reduced crew operations, hybrid wing-borne and rotor-born flight, federated air traffic services, and urban operations. We explore how analysts use expertise to address common-cause failures, collect and interpret safety data, and perform exacting tradeoffs between dissimilarity, redundancy, independence, and diversity (human, process lifecycle, or otherwise) to ensure safety. When novelty is present, analysts might not possess the expertise needed to fully understand the implications of design decisions and tradeoffs being made, especially in early lifecycle phases, on emergent properties such as safety. Safety expertise must be carefully cultivated. The conflicting views of safety experts must be unpacked to identify the divergence in fundamental assumptions, models, means, and methods that may be causing them. Once systems venture beyond the basis of what safety expertise can reliably guarantee, projects take on risk that must be managed. The paper contains key takeaways and actionable recommendations for novel OEMs and regulators touching on topics such as robust monitoring; clear and transparent reporting; incremental approaches to fielding novel systems in hazard-rich, risk-tolerant environments; the cultivation of safety culture and expertise in an organization; and the use of scientific study to reduce epistemic uncertainty in novel operations with new technologies. Since excessive novelty in aviation can undermine the current foundation of safety, humility and incrementalism are necessary to enable emerging aviation markets safely.

safety expertise↗

Safety Expertise and the Perils of Novelty

Emerging aviation markets such as urban air mobility are giving rise to new technologies and means of operation. However, novelty may hide ‘unknown unknowns,’ raising new hazards. This paper examines how expertise and safety techniques enable transformative technologies such as reduced crew operations, hybrid wing-borne and rotor-born flight, federated air traffic services, and urban operations. We explore how analysts use expertise to address common-cause failures, collect and interpret safety data, and perform exacting tradeoffs between dissimilarity, redundancy, independence, and diversity (human, process lifecycle, or otherwise) to ensure safety. When novelty is present, analysts might not possess the expertise needed to fully understand the implications of design decisions and tradeoffs being made, especially in early lifecycle phases, on emergent properties such as safety. Safety expertise must be carefully cultivated. The conflicting views of safety experts must be unpacked to identify the divergence in fundamental assumptions, models, means, and methods that may be causing them. Once systems venture beyond the basis of what safety expertise can reliably guarantee, projects take on risk that must be managed. The paper contains key takeaways and actionable recommendations for novel OEMs and regulators touching on topics such as robust monitoring; clear and transparent reporting; incremental approaches to fielding novel systems in hazard-rich, risk-tolerant environments; the cultivation of safety culture and expertise in an organization; and the use of scientific study to reduce epistemic uncertainty in novel operations with new technologies. Since excessive novelty in aviation can undermine the current foundation of safety, humility and incrementalism are necessary to enable emerging aviation markets safely.

safety expertise↗

Nuclear Safety [Vol. 36, No. 1, January-June 1995]

Nuclear Safety is a journal that covers significant issues in the field of nuclear safety. Its primary scope is safety in the design, construction, operation, and decommissioning of nuclear power reactors worldwide and the research and analysis activities that promote this goal, but it also encompasses the safety aspects of the entire nuclear fuel cycle, including fuel fabrication, spent-fuel processing and handling, and nuclear waste disposal, the handling of fissionable materials and radioisotopes, and the environmental effects of all these activities. Table of Contents for this issue follows. THE CHORNOBYL ACCIDENT: 1 The Chornobyl Accident Revisited, Part II: The State of the Nuclear Fuel Located Within the Chornobyl Sarcophagus, A A. Borovoi and A. R. Sich; GENERAL SAFETY CONSIDERATIONS: 33 Nuclear Power Safety in Central and Eastern Europe, R. Wilson; 46 Safety of Nuclear Power Reactors in the Former Eastern European Countries, S. Chakraborty; 53 Technical Note: On the Definition of Common-Cause Failures, H. Paula; ACCIDENT ANALYSIS: 58 Modeling and Analysis of Core-Debris Recriticality During Hypothetical Severe Accidents in the Advanced Neutron Source Reactor, S.-H. Kim, V. Georgevich, D. B. Simpson, C. O. Slater, and R. P. Taleyarkhan; 68 Ignitability of Hydrogen/Oxygen/Diluent Mixtures in the Presence of Hot Surfaces, R. K. Kumar and G. W. Koroll; 94 Coupled RELAP5 and CONTAIN Accident Analysis Using PVM, K. A. Smith, A. J. Baratta, and G. E. Robinson; CONTROL AND INSTRUMENTATION: 109 Application of Fuzzy Logic in Nuclear Reactor Control Part I: An Assessment of State-of-the-Art, A. S. Heger, N. K. Alang-Rashid, and M. Jamshidi; DESIGN FEATURES: 122 Twenty-Third DOE/NRC Nuclear Air-Cleaning and Treatment Conference, R. R. Bellamy, J. J. Hayes, and M. W. First; ENVIRONMENTAL EFFECTS: 135 Atmospheric Dispersion and the Radiological Consequences of Normal Airborne Effluents from a Nuclear Power Plant, D. Fang, C. Z. Sun, and L. Yang; 142 Calculation of Distribution Coefficients for Radionuclides in Soils and Sediments, I. Puigdomenech and U. Bergstrom: OPERATING EXPERIENCES: 155 Reactor Shutdown Experience, Compiled by J. W. Cletcher; U.S. NUCLEAR REGULATORY COMMISSION INFORMATION AND ANALYSES: 158 Operating Experience Feedback Report—Reliability of Safety-Related Steam Turbine-Driven Standby Pumps Used in U.S. Commercial Nuclear Power Plants, J. R. Boardman; 166 Turbine Building Hazards, H. L Ornstein; RECENT DEVELOPMENTS: 169 Reports, Standards, and Safety Guides, D. S. Queener; 175 Proposed Rule Changes as of Dec. 31,1994; ANNOUNCEMENTS: 32 Harvard School of Public Health In-Place Filter Testing Workshop; 134 International Conference on Advances in the Operational Safety of Nuclear Power Plants; 193 30th Tennessee Industries Week; 193 DOE Technical Standards Program 1995 Workshop; 194 Multiphase Flow Experiments and Instrumentation; 180 The Authors; 185 Indexes to Nuclear Safety, Volumes 34 and 35.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Sensitivity and Importance Measure Analyses for Various Design Architectures for High Safety-Significant Safety-Related Digital Instrumentation and Control Systems of Nuclear Power Plants

A transition from analog instrumentation and control (I&C) technologies to digital I&C technologies is taking place for license renewals of existing nuclear power plants and for operating licenses of new advanced reactors. This transition necessitates research on risk and economic assessments of digital I&C technologies to ensure the long-term safety and reliability of vital systems, reduce uncertainty in licensing costs in addition to timeline, support integration of digital I&C systems in the plant, and find the most efficient technology upgrades. Adding redundancy within systems or components is a common means of improving design safety; however, it can also make designs more prone to common-cause failures (CCFs). Introducing diversity into redundant systems or components is a way to mitigate and possibly eliminate CCFs, but it also increases plant complexity and may be costly. The balance between redundancy and diversity remains a challenge for digital I&C systems. This study performs sensitivity and importance analyses for four design architectures of two digital I&C systems—the reactor-trip system and the engineered safety features actuation system. For each system, two architectures are examined, including a redundant, non-diverse configuration and a redundant, diverse configuration. The sensitivity analysis will provide insights on the impact of introducing diversity to system reliability. The importance results will help identify risk-significant and risk-sensitive components and failure modes, which may be good candidates for future design improvement.

99 GENERAL AND MISCELLANEOUS↗