Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “Digital Instrumentation and Control”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Failure Mechanism Traceability and Application in Human System Interface of Nuclear Power Plants using RESHA

In recent years, there has been considerable effort to modernize existing and new nuclear power plants with digital instrumentation and control systems (DI&C). However, there has also been considerable concern both by industry and regulatory bodies for the risk and consequence analysis of these systems. Of particular concern are digital common cause failures (CCFs) specifically related to software defects. These “misbehaviors” by the software can occur in both the control and monitoring of a system. While many new methods have been proposed to identify potential software failure modes, such as Systems-theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), etc., these methods are focused primarily on the control action pathway of a system. In contrast, the information feedback pathway lacks unsafe control actions (UCAs), which are typically related to software basic events; thus, assessment of software basic events in such systems is unclear. In this work, we present the idea of intermediate processors and unsafe information flow (UIF) to help safety analysts trace failure mechanisms in the feedback pathway and how they can be integrated into a fault tree for improved assessment capability. The concepts presented are demonstrated in two comprehensive case studies, a smart sensor integrated platform for unmanned autonomous vehicles and another on a representative advanced human system interface (HSI) for safety critical plant monitoring. The qualitative software basic events are identified, and a fault tree analysis is conducted based on a modified Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) methodology. The case studies demonstrate the use of UIF and intermediate processors in the fault tree to improve traceability of software failures in highly complex digital instrumentation feedback. The improved method can also clarify fault tree construction when multiple component dependencies are present in the system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Failure Mechanism Traceability and Application in Human System Interface of Nuclear Power Plants using RESHA

In recent years, there has been considerable effort to modernize existing and new nuclear power plants with digital instrumentation and control systems (DI&C). However, there has also been considerable concern both by industry and regulatory bodies for the risk and consequence analysis of these systems. Of particular concern are digital common cause failures (CCFs) specifically related to software defects. These “misbehaviors” by the software can occur in both the control and monitoring of a system. While many new methods have been proposed to identify potential software failure modes, such as Systems-theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), etc., these methods are focused primarily on the control action pathway of a system. In contrast, the information feedback pathway lacks unsafe control actions (UCAs), which are typically related to software basic events; thus, assessment of software basic events in such systems is unclear. In this work, we present the idea of intermediate processors and unsafe information flow (UIF) to help safety analysts trace failure mechanisms in the feedback pathway and how they can be integrated into a fault tree for improved assessment capability. The concepts presented are demonstrated in two comprehensive case studies, a smart sensor integrated platform for unmanned autonomous vehicles and another on a representative advanced human system interface (HSI) for safety critical plant monitoring. The qualitative software basic events are identified, and a fault tree analysis is conducted based on a modified Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) methodology. The case studies demonstrate the use of UIF and intermediate processors in the fault tree to improve traceability of software failures in highly complex digital instrumentation feedback. The improved method can also clarify fault tree construction when multiple component dependencies are present in the system.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Advanced Human-System Interface Risk Analysis Based on Redundancy-guided Systems-theoretic Hazard Analysis and Human Reliability Analysis

Human-system interfaces (HSIs) play an important role in enabling operators to communicate with the nuclear power plant (NPP) side. Getting the information required to understand a NPP’s current status or perform necessary actions for responding to a given operational context are representative operator tasks performed using HSIs. To date, HSIs have been mainly evaluated in the context of human reliability analysis (HRA). However, the current HSI evaluation that occurs during HRA may be challengeable on two fronts: (1) reflecting the unique characteristics of HSI systems and (2) considering situations in which HSIs are poorly operated due to software/hardware malfunctions. Accordingly, this study proposes an approach for specifically evaluating HSIs for digital instrumentation and controls (DI&C) systems, using Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) and HRA. RESHA is a method for analyzing DI&C systems with redundancy features. In this study, we investigate how HSIs are evaluated in existing HRA methods, and what challenges exist in the current approaches. To better evaluate HSIs for DI&C systems, this study modifies the existing HSI evaluation process by additionally modeling the HSI back- and front- ends. In this paper, a HSI fault tree for the APR1400 DI&C system is introduced through a piping and instrumentation diagram. It then touches upon what aspects of the suggested method must be further researched.

99 GENERAL AND MISCELLANEOUS↗

Digital Engineering and Cybersecurity Decision Analysis in Early Phases of SMR-Driven IES Projects

Considerable efforts are underway to ensure cybersecurity is integrated into the systems engineering lifecycle. Cyber-informed engineering and security-by-design frameworks are intended to identify and engineer out cybersecurity risks throughout the lifecycle. While these approaches are valuable for promoting the need to include cybersecurity considerations in early design phases to create more secure systems, they may not consider the entirety of digital risks. Digital risks in a digital instrumentation and control system include adversarial and unintentional risks from internal and external factors, such as human performance errors, design flaws, environmental conditions, and equipment degradation or failure. This report provides a detailed discussion on digital risk prior to describing the background and concept of operations for a small modular reactor-driven integrated energy system connected to industrial applications. The challenges of competing objectives and competing stakeholder requirements are discussed and the impacts on digital engineering, security considerations, and interdependencies are evaluated for mission-level, facility-level, and system-level decisions.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

Demonstration and Evaluation of the Human-Technology Integration Guidance for Plant Modernization

The significance of nuclear power in its role producing carbon-free electricity to the U.S. cannot be overstated. However, with changes in the energy market coupled with changes in incentives given to certain resources like solar and wind, the operating and maintenance costs for these sources have seen a significant reduction, which has consequently negatively impacted the economic viability of the existing U.S. nuclear power plant fleet. Digital instrumentation and control (I&C) and control room modernization is a major critical work domain to reduce operating and maintenance costs. Existing nuclear power plants are commonly configured with mostly legacy analog I&C as well as isolated pockets of digital I&C (a plant process computer, digital recorders, etc.). One challenge with this analog I&C is that replacement parts are becoming prohibitively more expensive and difficult to obtain. Moreover, a significant challenge with the existing analog I&C is that the way in which plants are currently operated and maintained is no longer competitive with other electricity generating sources, like natural gas, where advanced digital I&C technologies are commonplace. This gap between the waynuclear power plants are operated compared to other electricity generating sources significantly challenges the economic viability of the nuclear industry. Indeed, digital I&C systems can fundamentally change the way the plant is operated (i.e., the concept of operation). The introduction of digital I&C technologies offers a wealth of benefits to the nuclear industry. However, it is important to emphasize that, to realize these benefits, a careful understanding of how to integrate technology in a collaborative way that leverages the capabilities of people and technologies is necessary. Human-technology integration applies human factors engineering methods and tools to ensure the safe and reliable use of these technologies while ensuring that the inherent features of the technologies that provide economic value are not missed. The scope of this work documents the demonstration of the recently developed human and technology integration methodology, as applied to developing a new vision and concept of operations for a major U.S. nuclear power plant fleet. This report focuses on the methodological aspects of developing a vision and concept of operations. This report shares the tools, activities, and lessons learned during a modernization currently underway for industry as a whole to consider when planning any significant digital modification and developing a new vision and concept of operations.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Progress on the MARVEL Cybersecurity by Design Model-Based Systems Engineering Project

Formal model-based systems engineering (MBSE) combines a model, systems thinking, and systems engineering to visually depict the boundaries, context, and behavior of interconnected systems, facilitating effective design, development, and utilization of engineered systems throughout the systems engineering lifecycle. Although nuclear reactor vendors employ these tools to integrate functionality, performance, and safety, they are not yet addressing digital risk concerns introduced by use of operational technology, such as digital instrumentation and control systems. To accomplish this objective, the Microreactor Applications Research Validation and EvaLuation (MARVEL) microreactor was used as an MBSE case study. This real-world application provides a first-of-a-kind opportunity to demonstrate the benefits of integrating digital risk and cybersecurity into the MBSE design process of a nuclear reactor. This paper provides an update of the ongoing MARVEL Cyber MBSE project as it specifically relates to the integration of digital risk management and cybersecurity by design.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

SECURED: Simulator-Enhanced Control and Understanding of Reactor systems for cyber-Event Defense

The study discusses a learning approach for analyzing cyber-events in reactor systems using integrated hardware and personal computer simulator models. Key points include the rise in cyber-attacks and their sophistication in industrial control systems (ICS), the necessity for awareness, understanding, resource allocation, and preparation to combat these threats, and the digital transformation of old and new nuclear plants, increasing their exposure to cyber threats. It highlights the cyber vulnerabilities of advanced reactor systems, which rely on digital instrumentation and control for operations and safety functions, making them susceptible to cyber-attacks. The approach involves demonstrating reactor system plant ICS cyber-attacks under various operational conditions utilizing tools like simulator models and hardware-based kits. A strategic solution approach tailored to critical infrastructure is emphasized, along with community engagement for public and government support, adopting effective learning approaches, and the preparation for anticipated future challenges. The presentation concludes with a call to action to address challenges, leverage opportunities, and advance through lesson learning in cybersecurity for nuclear energy systems.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

How the NRC modernized its digital I&C infrastructure and where it goes from here

The NRC first formally developed infrastructure for the review of digital instrumentation and control (I&C) systems in the 1990’s. Although, the current U.S. fleet of nuclear power plants were originally designed and constructed with analog systems, the U.S. nuclear industry has for more that thirty years been working to upgrade these older systems with modern digital systems. Digital systems have many advantages but also pose different engineering challenges and need to be reviewed by the Nuclear Regulatory Commission (NRC) in a different way. Because of this the NRC started looking at its regulatory infrastructure to see if changes needed be made to support the expanded safe use of digital systems in nuclear power plants. Several efforts in the 1990’s included a review by the National Academies’ National Research Council, a review of the impact of potential new digital systems by the NRC staff as a result of advanced reactor designs and the NRC staff’s update to the I&C section of the Standard Review Plan (SRP) (Ref 1).

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Cyber threat assessment of machine learning driven autonomous control systems of nuclear power plants

We report advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)-based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber–physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems.

99 GENERAL AND MISCELLANEOUS↗

Cyber-Informed Engineering Guidance—Implementing CIE in Early Systems Engineering Lifecycle Stages

Traditionally, cybersecurity is not considered in the design process. Design engineers typically focus on building safety and reliability into their products and applications. Security against malicious cyber incidents is often an afterthought, resulting in deployment of security solutions during installation or operation. Unfortunately, waiting to consider cybersecurity until later in the systems engineering lifecycle often results in less effective and more expense security. Idaho National Laboratory (INL) developed the concept of Cyber-Informed Engineering (CIE) in 2015 to provide a framework that enables cybersecurity to be built into systems beginning at the conceptual design stage. In addition to ongoing research by INL, the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response has recently developed a National CIE Strategy document for incorporating CIE into the design and operation of infrastructure systems reliant on digital monitoring or controls. This paper provides a brief review of this National CIE Strategy as well as a roadmap to historical, current, and future CIE research by INL through the U.S. DOE Office of Nuclear Energy (NE) Cybersecurity Crosscutting Technology Development Program. A near-term focus of the DOE-NE’s research and development is to extend the foundational CIE work into detailed guidance for implementation during initial systems engineering stages in nuclear digital instrumentation and control projects and to demonstrate use of the guidance in an integrated energy systems project.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Human and Technology Integration Evaluation of Advanced Automation and Data Visualization

While the existing United States (U.S.) light water reactors are highly reliable, safe, and provide a significant proportion of carbon-free electricity, the cost of operating and maintaining them has become less competitive compared to other electricity generating sources. The reason for the gap in operating and maintenance (O&M) costs can be at least in part attributed to the advent of new digital technologies that other electricity generating industries are currently using. Advanced capabilities including digital instrumentation and control (I&C) systems, advanced automation and analytics, and greater span of data integration (i.e., connectedness) across these non-nuclear plants has transformed the way work is performed and ultimately given them a competitive advantage in terms of the cost required for operating, maintaining, and supporting them. To reduce O&M cost and address obsolescence of the aging I&C infrastructure of the existing U.S. light water reactors, the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program Plant Modernization Pathway is conducting targeting multidisciplinary research that 1) delivers a sustainable business model to enable a cost-competitive U.S. nuclear industry and 2) is developing technology modernization solutions that address aging and obsolescence challenges. The work described in this report supports these two objectives and describes the demonstration of human and technology integration across recent industry collaborations to support their large-scale digital I&C modifications. This technical report describes the demonstration of the human and technology integration methodology in performing full-scale performance-based human-in-the-loop tests to evaluate plant-specific advanced automation and data visualization applications within these collaborators’ digital modifications. This technical report also documents future applications of human and technology integration that expand beyond main control room modernization and digital I&C upgrades, which have been a central focus to date. Thus, this technical report discusses how to implement human and technology integration across new business opportunities and how to develop an evaluation plan that defines measures and criteria, and documents key assumptions to support full plant modernization.

99 GENERAL AND MISCELLANEOUS↗

Survey of Cyber Risk Analysis Techniques for Use in the Nuclear Industry

Using traditional probabilistic risk analysis methods for severe accident safety risk management on non-digital systems, structures, and components at nuclear power plants is well-established. In contrast, cyber risk analysis of digital assets is still an immature field with unproven techniques due, in part, to the continuously changing threat environment and the challenge of digital assets failing in unexpected ways. As the nuclear fleet continues to adopt digital instrumentation and control systems, it is increasingly important to have effective and efficient cyber risk analysis techniques to support risk management decisions, such as risk elimination by system redesign or risk mitigation by implementation of prioritized security controls. To understand the state of the art in cyber risk analysis for future research, we surveyed 36 publications across ten application domains. We describe our survey methodology and rate each technique based upon scope, adoptability, and repeatability. In this work, we examine the unique constraints of the nuclear industry and outline the strengths and weaknesses of using the cyber risk analysis techniques in the industry, highlighting gaps with current techniques. We also discuss challenges and potential research directions for advancing the science for both existing and new advanced reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Barriers to adopting artificial intelligence and machine learning technologies in nuclear power

Artificial intelligence and machine learning (AI/ML) technologies offer unique opportunities to transform nuclear plant operations and power generation. Benefits will be felt not only within existing analog and digital instrumentation and control, but also within work processes, the integration of people with technology and most importantly, the business case. The application of this new technology can help simplify complex problems and produce more effective decision-making, making nuclear power safer, more efficient, and more economically viable in the current energy market. Nonetheless, there are potential barriers to its adoption that must be overcome. The purpose of this paper is to categorize, review, and discuss barriers to AI/ML adoption within the nuclear power industry, with a focus on existing commercial reactors. Unique considerations for advanced reactors are also offered. Here we provide a comprehensive overview of the historical, technical, and business barriers that the industry faces, as well as stakeholder readiness, and end-user acceptance. We underscore the importance of user experience and offer potential solutions in overcoming each barrier. These include provisions for easier plant data access, a friendly regulatory environment, and investment in user trust and explainable AI.

12 MANAGEMENT OF RADIOACTIVE AND NON-RADIOACTIVE W↗

Cyber-Informed Engineering Case Study of an Integrated Hydrogen Generation Plant

Strategies for securing digital instrumentation and control (I&C) systems within the nuclear industry are provided by multiple standards and guidance documents. However, since selection and use of security controls outlined in these documents are frequently only considered during or after installation, there are often limitations on their use, such as technological constraints related to design or operation. Furthermore, alternative controls intended to provide the same or similar security countermeasure as the primary control may also be infeasible at these stages, leaving the I&C system vulnerable to cyber-attacks. The limitations associated with ‘bolting on’ security controls late in the systems engineering lifecycle can be reduced by integrating Cyber-Informed Engineering (CIE) into the process. This paper evaluates the use of CIE during the high-level design stage of a hydrogen generation project where heat and electricity are provided by a nuclear power plant. Applying CIE to this project highlighted potential cyber vulnerabilities of the initial design, leading to recommendations for process flow and I&C system design modifications to reduce, and at times eliminate, the risk from both deliberate and unintentional cyber incidents.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Vendor-Independent Design Requirements for a Boiling Water Reactor Safety System Upgrade

This Vendor-Independent License Amendment Request (LAR) Framework Document is a research product developed for the Idaho National Laboratory Light Water Reactor Sustainability (LWRS) Program. It was developed by MPR Associates, Inc. with technical input from LWRS and Exelon Generation personnel. To accomplish the purpose of this research, an operating plant (Limerick Generating Station [LGS]) was used as a reference to provide a concrete example and to present a "top-down" view of design concepts consistent with functional requirements baseline documents (references X and Y) also developed for this research. While this document is written in a framework to support a complete LAR submittal, its purpose is to communicate research concepts and provide an example of how to present digital information necessary to address expectations with regard to leveraging the Alternate Review Process as provided in Digital Instrumentation and Controls Interim Staff Guidance #06, Revision 2, Licensing Process. To leverage that process, this research document presupposes that a utility would select a vendor platform which has been prequalified for safety-related by the United States Nuclear Regulatory Commission. While this document is written using the Exelon Generation Limerick Generating Station (LGS) Units 1 and 2 as a baseline, this document is a research product. This document contains no commitments and makes no binding design decisions for Exelon Generation. Exelon Generation is leveraging this research to support their in-progress LGS Plant Protection System (PPS) upgrade efforts and plans to leverage it for their Redundant Reactor Control System (RRCS) replacement. The LWRS Program appreciates the research support provided by Exelon Generation in the generation of this document.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗

A Cybersecurity Event Simulation Tool and Platform

Digital Instrumentation and Control Systems (ICSs) have replaced analog control systems in nuclear power plants raising cybersecurity concerns. To study and understand the cybersecurity risks of nuclear power plants both high fidelity models of the plant physics and controllers must be created, and a framework to test and evaluate cyber security events must be established. A testing and evaluation framework of cybersecurity events consists of a method of interfering with control systems, a simulation of the plant network, and a network packet capture and recording tool. Sandia National Labs (SNL) in collaboration with the University of New Mexico’s Institute for Space and Nuclear Power Studies (UNM-ISNPS) is developing such a cybersecurity testing framework.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Explainable Artificial Intelligence Technology for Predictive Maintenance

The domestic nuclear power plant fleet has relied on labor-intensive and time-consuming preventive maintenance programs, thus driving up operation and maintenance costs to achieve high-capacity factors. Artificial intelligence and machine learning can help simplify complex problems, such as diagnosing equipment degradation, to enable more effective decision-making. Benefits will be felt not only within existing analog and digital instrumentation and control, but also work processes, the integration of people with technology, and most importantly, the business case. Together, these hold promise to make nuclear power more efficient and reduce costs associated with operation and maintenance. While the artificial intelligence and machine learning technologies hold significant promise in the nuclear industry, there are challenges or barriers to their adoption. This report outlines the those different machine learning adoption barriers (categorized as historical, technical, economic, regulatory, and user) that the industry must overcome to realize the full benefits of artificial intelligence and machine learning capabilities for long-term economic sustainability. This report also provides solutions for some of these barriers by focusing on improving the explainability of machine learning to encourage trust from the end-user. Trust and explainability are essential to machine learning adoption. This report focuses on research-developed solutions to some of these barriers while analyzing a non-safety-related system, namely the circulating water system. This system frequently experiences waterbox fouling which our models preemptively diagnoses then explains to the operator how those conclusions were reached. This report presents and discusses the inherent trade-off between machine learning performance (in terms of accuracy) and explainability, where highly accurate machine learning methods (such as deep-learning) are the least explainable, and the most explainable methods (such as decision trees) are the least accurate. In addition, explainability of artificial intelligence techniques in terms of transparency and post-hoc metrics are discussed. This report outlines the importance of data novelty and value of new information in evaluating both the explainability and trustworthiness. Novelty detection helps to establish consistency or inconsistency of the new data with respect to the training data. On the other hand, value of information could be a part of the user-centric visualization recommendation system that request additional information to be collected, thereby strengthening the machine learning outcomes. During this project, a copyrighted user-centric visualization that aligns with a human-in-the-loop approach was developed. The user-centric visualization presents different levels of information and can be tailored as per user credentials to gain user confidence. One of the salient features of the user-centric visualization is it presents machine learning methods with explainability metrics. A simplified version of the user-centric visualization was presented to 32 users with varying levels of machine learning expertise. Feedback was solicited to test the hypothesis that the app contained sufficient explainability and that the users would trust the algorithm. Overall, the app was positively received, and the hypothesis was supported. This report discusses the trust-but-verify framework – a potential approach to build user trust artificial intelligence. The framework discusses trust from the human level to artificial intelligence level. The fundamental premise of the trust but verify framework is derived from an observation of nuclear safety culture (i.e., nuclear power plant personnel do not rely on a singular source of data to make a decision). This also ties back to the user-centric visualization that presents different levels of information to achieve both explainability and trustworthiness of artificial intelligence. Even so, the adoption of artificial intelligence and machine learning in the nuclear industry faces additional barriers, namely regulatory and stakeholder readiness. To overcome these challenges, new solutions must gain regulatory approval and cater to stakeholder needs. The Nuclear Regulatory Committee has a 5-year strategic plan which prepares them for reviewing artificial intelligence technologies in licensee submissions. Early and frequent engagement with the regulator is encouraged. Additionally, artificial intelligence solutions should incorporate human-in-the-loop considerations and offer explainability. Stakeholders must prepare by hiring or training staff to adapt to advancing technology in everyday plant tasks.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗