Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “SAFETY MARGINS”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 73 records · Page 4

Design of evaporator of spacelab refrigerator/freezer

An Evaporator has been designed for NASA-Johnson Space Center Life Sciences to conduct experiments in Spacelab mission SLS-1 using different samples such as blood, urine, human tissues etc. Two units will fly - one as a Refrigerator (4 C) and the other as a Freezer (-22 C). The evaporator tube is dip brazed on a grooved flat plate. Aluminum heat sink is dip brazed on the other side of the plate. Freon R5O2 is pumped through the tube and air is circulated over the finned surface to transfer heat. As freon 5O2 is considered toxic, the whole freon tube is covered with an evaporator cover to contain any freon leakage to avoid exposure to crew members. This containment is under vacuum and this pressure is monitored along with the freon pressure to determine freon leakage so that necessary steps can be taken to stop contamination of the spacelab air. An stress analysis has been done and it is found to have adequate safety margin to meet the requirements of NASA safety and reliability standards.

Hye, A.↗

The Parable of the Boiled System Safety Professional: Drift to Failure

Recall from the Parable of the Boiled Frog, that tossing a frog into boiling water causes the frog to jump out and hop away while placing a frog in suitable temperature water and slowly bringing the water to a boil results in the frog boiling due to not being aware of the slowly increasing danger, theoretically, of course. System safety professionals must guard against allowing dangers to creep unnoticed into their projects and be ever alert to notice signs of impending problems. People have used various phrases related to the idea, most notably, latent conditions, James Reason in Managing the Risks of Organizational Accidents (1, pp 10-11), Drift to Failure, Sydney Dekker (2, pp 82-86) in Resilience Engineering: Chronicling the Emergence of Confused Consensus in Resilience Engineering: Concepts and Precepts, Hollnagel, Woods and Leveson, and normalization of deviance, Diane Vaughan in The Challenger Launch Decision: Risky Technology, Culture, and Deviance at NASA (3). Reason also said, If eternal vigilance is the price of liberty, then chronic unease is the price of safety (1, p 37). Our challenge as system safety professionals is to be aware of the emergence of signals that warn us of slowly eroding safety margins. This paper will discuss how system safety professionals might better perform in that regard.

Shivers, C. Herbert↗

System Guidelines for EMC Safety-Critical Circuits: Design, Selection, and Margin Demonstration

Demonstration of safety margins for critical points (circuits) has traditionally been required since it first became a part of systems-level Electromagnetic Compatibility (EMC) requirements of MIL-E-6051C. The goal of this document is to present cost-effective guidelines for ensuring adequate Electromagnetic Effects (EME) safety margins on spacecraft critical circuits. It is for the use of NASA and other government agencies and their contractors to prevent loss of life, loss of spacecraft, or unacceptable degradation. This document provides practical definition and treatment guidance to contain costs within affordable limits.

Lawton, R. M.↗

Transition Core Planning and Safety Analyses in Support of LEU Fuel Conversion of the University of Missouri Research Reactor (MURR)

The University of Missouri Research Reactor (MURR®) is one of six U.S. High Performance Research Reactors (USHPRR), including one critical facility, that is working with the National Nuclear Security Administration (NNSA) Office of Material Management and Minimization (M3) Reactor Conversion Program to convert from highly enriched uranium (HEU) to low-enriched uranium (LEU) fuel. The M3 Reactor Conversion USHPRR Project objectives include the development of LEU fuel element designs that will ensure safe reactor operations and to maintain the existing experimental performance of each facility. The work is being conducted through many inter-related activities being completed by four Project Pillars: Fuel Qualification (FQ), Fuel Fabrication (FF), Reactor Conversion (RC), and Cross Cutting (CC). A new type of LEU fuel based on an alloy of uranium-10 wt% molybdenum (U-10Mo) is expected to allow the conversion of those USHPRR, like MURR, requiring higher density fuels. The very-high-density LEU U-10Mo monolithic fuel is currently undergoing irradiation testing and post-irradiation examination under a planned and documented fuel qualification effort. The FQ Pillar will document fuel property and fuel performance data and qualify the fuel for use in these reactors. The FF Pillar is fabricating fuel for ongoing and future irradiation tests, as well as conducting fabrication demonstrations to validate or update preliminary fabrication assumptions. The FF Pillar is also working to develop and install commercial manufacturing capacity with the U-10Mo monolithic fuel to produce prototypic fuel. Working with the RC Pillar at Argonne, MURR has progressed through a preliminary fuel element design using preliminary data for the proposed monolithic alloy of U-10Mo. Analyses were completed in previous work that found for typical equilibrium operations with the preliminary LEU fuel element design, in conjunction with a power uprate to 12 MW and appropriate changes to the MURR Limiting safety system settings (LSSS), MURR will have adequate margins to safety for steady-state operations and postulated transient accidents and will have experimental performance in key locations that meets or exceeds current operations with HEU fuel. The purpose of this work is to develop a sequence of transition cycles that will enable MURR to transition from operation with the reactor core loaded with fresh LEU fuel elements only to typical equilibrium operations with mixed-burnup cores following conversion while meeting operational requirements on safety and experimental performance. It is expected that the use of fresh LEU fuel at conversion and subsequent low burnup of the LEU fuel elements that will initially be available for use following conversion will result in critical control blade positions that will substantially change the axial power distribution in the core and the neutron flux available in key experimental locations relative to equilibrium LEU operations. Given the constraints of MURR safety margins, operational practices, and production and research, a novel method has been developed to identify a transition sequence that minimizes the time MURR operates atypically compared to the current prototypic cycles using HEU fuel. The proposed transition sequence moves quickly to the same sort of equilibrium cycles for the LEU fuel that have already been evaluated in documented preliminary safety analyses. Although shifting the neutron flux peak to the lower half of the core during initial cycles with LEU at 12 MW reduces the experiment performance in some key locations relative to current HEU operations at 10 MW, all LEU cores provide an average performance that meets or exceeds that of HEU. An LEU cycle is reached that meets or exceeds the level of experimental performance predicted for current HEU and equilibrium LEU operations in more than 450 key locations identified by a reactor specialist at MURR by the 23rd cycle following conversion and that afterwards will enable MURR to consistently meet its experimental performance requirements. The proposed transition sequence only requires the fabrication of 34 fresh LEU elements in the first year of operation and does not exceed the anticipated availability of fresh elements that can be produced by the fuel fabricator. By the third year after conversion, 22 fresh LEU elements will be required each year, which is the same as expected for equilibrium LEU operations and the same as current operations with HEU fuel. The proposed transition sequence thus combines a relatively short time period before equilibrium burnup is achieved, a temporary increase of fuel elements needed annually relative to typical operations that are within the production capabilities of the fuel fabricator, and demonstrates comparable experimental performance of the LEU cores relative to current HEU operations. Further measures may be taken to reduce any initial experimental performance penalty even further, where possible, by repositioning certain experiments to leverage the increased performance in the lower axial experimental positions in the initial cycles following conversion or leaving the experiments in the irradiation facilities longer in order to achieve the required neutron fluence. This analysis may require refinement depending on the experimental facilities in use at the time of conversion. Nonetheless, the results presented here, including the experimental performance, core burnup, and critical control blade positions throughout the transition cycles, show that the proposed transition cycle fuel management patterns are consistent with what is expected and desired for MURR operation with LEU U-10Mo fuel. Detailed core power distributions from the neutronics models were also used to evaluate safety margins during steady-state operations for the selected transition cycles and the equilibrium LEU core. It is shown that there are adequate safety margins for both steady-state operations and postulated accident scenarios. For the steady-state operations with the preliminary LEU fuel element design the analysis predicts at least 2.49 MW margin to the onset of flow instability at the LSSS power of 15 MW. Considering the LSSS power is 125% of full license power, the margin to OFI is sufficient. In addition, the critical heat flux ratio at LSSS power is well above the requirement of CHFR > 2.0 from NUREG-1537 for all considered cases. For postulated transient accidents, the minimum margin to the fuel temperature safety limit is at least 109 °C. In summary, the proposed sequence of core loadings for MURR operations following conversion to LEU fuel and a power uprate to 12 MW provides sufficient safety margins for both steady-state operations and postulated transient accidents during a proposed sequence of transition cycles to equilibrium operations. Analysis has shown that there are some local experimental performance penalties during the initial cycles. Although there are local shifts in the experimental performance, on average all LEU cores at 12 MW have equal or higher performance than HEU at 10 MW. Temporary adjustments are being planned that will produce suitable experimental performance during these cycles. The results indicate that for the equilibrium LEU core the experimental performance exceeds that of current HEU operations in all key locations while also demonstrating sufficient safety margins.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Safety Benefits Assessment for Accident Tolerant Fuels in Consideration of Steam Generator Tube Degradation Using Dynamic Event Tree Analysis

Accident tolerant fuel (ATF) is expected to delay or prevent core damage by providing additional coping time under accidents involving loss of core cooling. The effect of extended coping time may vary depending on the plant response to accidents. Age-related component degradation that deteriorates plant performance over time could have an impact on the actual advantages of ATF. The potential safety benefits of two near-term ATF candidates, including Cr-coated Zr cladding and FeCrAl cladding, are assessed for a 2-in. loss-of-coolant accident with failed high-pressure safety injection using the dynamic event tree (DET) approach considering possible stress corrosion cracking of steam generator (SG) tubing under aging. The DET approach allows likelihood quantification of accident sequences leading to core damage, including stochastic variation of system response and human actions during accident mitigation. The safety benefits of the selected ATF claddings in terms of additional coping time and the core damage frequency reduction rate under specified accident situations were quantitatively estimated. The results show that the deployment of the two selected ATF claddings is expected to lead to longer coping times and lower core damage frequency due to the wider safety margin to peak cladding temperature they provide. The safety advantages would be greater as SG tube degradation proceeds. Thus, the two ATF candidates would lead to less severe consequences in terms of likelihood of core damage and susceptibility to the SG tube degradation than UO 2 -Zr fuel.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Comparative Analysis of Standard and Advanced USL Methodologies for Nuclear Criticality Safety

The American National Standards Institute/American Nuclear Society national standards 8.1 and 8.24 provide guidance on the requirements and recommendations for establishing confidence in the results of the computerized models used to support operation with fissionable materials. By design, the guidance is not prescriptive, leaving freedom to the analysts to determine how the various sources of uncertainties are to be statistically aggregated. Due to the involved use of statistics entangled with heuristic recipes, the resulting safety margins are often difficult to interpret. Also, these technical margins are augmented by additional administrative margins, which are required to ensure compliance with safety standards or regulations, eliminating the incentive to understand their differences. With the new resurgent wave of advanced nuclear systems, e.g., advanced reactors, fuel cycles, and fuel concepts, focused on economizing operation, there is a strong need to develop a clear understanding of the uncertainties and their consolidation methods to reduce them in manners that can be scientifically defended. In response, the current studies compare the analyses behind four notable methodologies for upper subcriticality limit estimation that have been documented in the nuclear criticality safety literature: the parametric, nonparametric, Whisper, and TSURFER methodologies. Specifically, the work offers a deep dive into the various assumptions of the noted methodologies, their adequacies, and their limitations to provide guidance on developing confidence for the emergent nuclear systems that are expected to be challenged by the scarcity of experimental data. Here, to limit the scope, the current work focuses on the application of these methodologies to criticality safety experiments, where the goal is to calculate a bias, a bias uncertainty, and a tolerance limit for k eff in support of determining an upper subcriticality limit for nuclear criticality safety.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

An Integrated Framework for Risk Assessment of Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology Refinement and Exploration

This report documents activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2023 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a technical basis to support effective, and secure DI&C technologies for digital upgrades/designs. A risk assessment-informed framework was proposed for this strategy, which aims to (1) provide a best-estimate, risk informed capability to quantitatively estimate the safety margin obtained from plant modernization, especially for safety-related DI&C systems, (2) support and supplement existing risk informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems, (4) assure the long-term safety and reliability of safety-related DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals, the LWRS-developed framework provides a means to address relevant technical issues by: (1) defining a risk informed analysis process for DI&C upgrade that integrates hazard analysis, reliability analysis, and consequence analysis, (2) applying risk informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development and deployment of advanced DI&C technologies in nuclear power plants (NPPs). Adding diversity within a system or components is the primary means to eliminate and mitigate CCFs, but diversity also increases system complexity and may not address all sources of systematic failures. Optimization of diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in safety-related DI&C systems of NPPs and supporting relevant design optimization, the proposed framework provides: (a) A best-estimate, risk informed capability to address new technical digital issues quantitatively, focusing on software CCFs in safety-related DI&C systems of NPPs; (b) A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to predict and prevent risk in the early design stage of DI&C systems; (c) Technical bases and risk informed insights to assist users address the risk informed alternatives for evaluation of CCFs in safety-related DI&C systems of NPPs; and (d) A risk informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The research and development efforts of this project in FY 2023 are focused on refining current methods on software CCF modeling and estimation and exploring additional innovative approaches to risk assessment of DI&C systems to enable a more comprehensive and complete assessment of various safety-related DI&C design architectures. The primary audience of this report are DI&C designers, engineers, and probabilistic risk assessment (PRA) practitioners. This includes stakeholders, such as the nuclear utilities and regulators who consider the deployment and upgrade of DI&C systems, DI&C software developers and reviewers, and cybersecurity specialists. It should be noted that all the analyses are performed for the demonstration of the methodology, not for the evaluation of an actual digital control system. Results are obtained based on limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Safety Analysis of FeCrAl Accident-Tolerant Fuels with Increased Enrichment and Extended Burnup

The U.S. nuclear industry is facing a strong challenge to maintain regulatory-required levels of safety while ensuring economic competitiveness to stay in business. Safety remains a key parameter for all aspects related to the operation of light water reactor nuclear power plants (NPPs), and it can be achieved more economically by using a risk-informed ecosystem, such as that being developed by the Risk-Informed Systems Analysis Pathway under the U.S. Department of Energy Light Water Reactor Sustainability Program. This program is promoting a wide range of research and development activities to maximize both the safety and economically efficient performance of NPPs through improved scientific understanding, especially given that many plants are considering a second license renewal. The Risk-Informed Systems Analysis Pathway has two main goals: (1) The deployment of methodologies and technologies that enable a better representation of the safety margins and factors that contribute to cost and safety, and (2) The development of advanced applications that enable cost-effective plant operation. As part of this pathway, the Enhanced Resilient Plant project refers to an NPP where safety is improved by implementing various measures, such as accident-tolerant fuels, diverse and flexible coping strategies, enhancements to plant components and systems, incorporation of augmented or new passive cooling systems, and utilization of advanced battery technologies. The objective of the Enhanced Resilient Plant project is to use novel methods and computational tools to enhance existing reactors’ safety while reducing operational costs. This report documents research and development conducted in support of deployment of accident-tolerant fuels. This project performed safety analyses for the steady-state normal operation, anticipated operational occurrences, and design-basis accidents of a representative four-loop pressurized water reactor model with Zr and FeCrAl accident-tolerant fuel clad with higher enrichment and burnup supporting plant refueling cycles of 18 and 24 months. The source terms and environmental impacts were studied for a large-break loss of coolant accident, including uncertainty analyses.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Optimization and stabilization of Fermilab Booster using hybrid Bayesian/RL framework

PIPII project will raise Fermilab Booster intensity and ramp rate. Beam losses will limit average power and are hard to simulate. Presently, Booster uses operator-guided empirical tuning. This task is challenging due to high dimensionality, multiple objectives, critical safety constraints, and drifts. We developed a synergistic suite of Bayesian optimization (BO) and reinforcement learning (RL) tools to optimize and stabilize beam losses. First, active learning was used to build a rough model. Data was collected parasitically using two novel safety constraint types – nonlinear input space restrictions (based on optics model), and uncertainty constraints (to stop bad steps/beam aborts). We then applied online multi-objective BO with scalarized objectives and fitting to improve/rebalance losses, increasing safety margins by 25%. Using BO model as a safety veto, we tried several on/off-policy RL agents for long term stabilization; SAC had best performance. We found that adding contextual (state) information further improved performance, eventually integrating key knobs like linac phase and temperature into the parameter space. Long term testing is ongoing to enable operational use.

Kuklev, Nikita [Fermilab]↗

Development and Demonstration of a Risk-Informed Approach to the Regulatory Required Fuel Reload Safety Analysis

The United States (U.S.) nuclear industry is facing a strong challenge to maintain regulatory-required levels of safety while ensuring economic competitiveness to stay in business. Safety remains a key parameter for all aspects related to the operation of light water reactor (LWR) nuclear power plants (NPPs) and can be achieved more economically by using a risk-informed ecosystem such as that being developed by the Risk-Informed Systems Analysis (RISA) Pathway under the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program. The LWRS Program is promoting a wide range of research and development (R&D) activities with the goal to maximize both the safety and economically efficient performance of NPPs through improved scientific understanding, especially given that many plants are considering second license renewal. The RISA Pathway has two main goals: (1) the deployment of methodologies and technologies that enable better representation of safety margins and the factors that contribute to cost and safety; and (2) the development of advanced applications that enable cost-effective plant operation. The plant reload optimization framework development project aims to build an artificial intelligence, i.e., Genetic Algorithm (GA), based reactor core designing tool taking into account reactor safety and fuel performance analyses.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Assessment of Modeling and Simulation Technical Gaps in Safety Analysis of High Burnup Accident-Tolerant Fuels

The United States nuclear industry is facing a strong challenge to maintain regulatory-required levels of safety while ensuring economic competitiveness to stay in business. Safety remains a key parameter for all aspects related to the operation of light water reactor (LWR) nuclear power plants (NPPs), and it can be achieved more economically by using a risk-informed ecosystem, such as that being developed by the Risk-Informed Systems Analysis (RISA) Pathway under the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program. The LWRS Program is promoting a wide range of research and development activities to maximize both the safety and economically efficient performance of NPPs through improved scientific understanding, especially given that many plants are considering second license renewal. The RISA Pathway has two main goals: The deployment of methodologies and technologies that enable better representation of safety margins and the factors that contribute to cost and safety, and; The development of advanced applications that enable cost-effective plant operation. As part of the RISA Pathway, the Enhanced Resilient Plant (ERP) project refers to an NPP where safety is improved by implementing various measures, such as accident-tolerant fuels (ATF), diverse and flexible coping strategy (FLEX), enhancements to plant components and systems, incorporation of augmented or new passive cooling systems, and utilization of advanced battery technologies. The objective of the ERP research is to use novel methods and computational tools to enhance existing reactors’ safety while reducing operational costs. Many U.S. utilities are targeting implementation of ATFs instead of traditional fuel in the near future since ATFs offer benefits in terms of improved performance and cost savings. The robust properties of ATF make it possible to extend the refueling cycle from 18 to 24 months in addition to the opportunity to use less of fuel. Extensive safety assessments are required to support regulatory requirements and obtain the approvals to use ATFs and the ERP project support the industry by developing novel effective methodologies for safety evaluations. In this project, the technical gaps in the modeling and simulation of the high burnup (HBU) ATF were assessed in terms of the fuel cladding behavior during the postulated accident events. The issues were identified in modeling the cladding deformation, the hydrodynamic change due to cladding deformation and the critical heat flux (CHF). The RELAP5-3D cladding deformation model was assessed by multiple verification tests and validation with the instrumented fuel assembly (IFA) experiment.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Demonstration of the Plant Fuel Reload Process Optimization for an Operating PWR

The United States (U.S.) nuclear industry is facing a strong challenge to maintain regulatory-required levels of safety while ensuring economic competitiveness to stay in business. Safety remains a key parameter for all aspects related to the operation of light water reactor (LWR) nuclear power plants (NPPs) and can be achieved more economically by using a risk-informed ecosystem such as that being developed by the Risk-Informed Systems Analysis (RISA) Pathway under the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program. The LWRS Program is promoting a wide range of research and development (R&D) activities with the goal to maximize both the safety and economically efficient performance of NPPs through improved scientific understanding, especially given that many plants are considering second license renewal. The RISA Pathway has two main goals: (1) the deployment of methodologies and technologies that enable better representation of safety margins and the factors that contribute to cost and safety; and (2) the development of advanced applications that enable cost-effective plant operation. This report summarizes the research outcomes in FY-2021, which the project progressed from the planning and methodology development phase to the early demonstration phase. The highlights of these activities are: (1) the development of a multi-objective optimization process using Genetic Algorithms (GAs); (2) the development and test of an approach for optimization process acceleration using artificial intelligence (AI) that significantly reduces the computational burden; (3) the demonstration of the fuel reload optimization framework for a generic pressurized water reactor (PWR); and (4) the demonstration of limiting design basis accident (DBA) scenarios for evaluation of the transition from deterministic to risk-informed approach for fuel reload optimization.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Conjugate Heat Transfer Modeling of Salt-Filled Fuel Pins for Stable Salt Reactor Safety Analysis

The Stable Salt Reactor (SSR) combines the proven structural design of light water reactor fuel assemblies with the inherent safety and fuel-cycle advantages of molten salt technology. In its fast reactor configuration, the SSR utilizes recycled nuclear waste as fuel, sealed within narrow salt-filled fuel pins and cooled by a surrounding liquid salt coolant. Reliable transfer of heat from the molten fuel salt through the cladding to the external coolant is essential for both reactor safety and performance. This work investigates conjugate heat transfer (CHT) in the SSR’s salt-filled fuel pins using NekRS, a high-fidelity spectral element computational fluid dynamics (CFD) solver. The analyses capture internal natural convection within the molten fuel salt and external forced convection in the coolant, under steady-state and transient operating conditions. Parametric studies evaluate how variations in reactor power and coolant flow rate influence heat transfer distributions and system response. The high-fidelity CFD results are time-averaged and post-processed for direct comparison with moderate-fidelity Reynolds-averaged Navier–Stokes (RANS) models, and for the development of reduced-order models within the SAM system code. These validated models support fast-running safety analyses of normal and off-normal transients, improving predictive capability for key safety margins. By integrating advanced CFD with system-level safety tools, this study strengthens the modeling framework for SSR design, reduces uncertainty in molten salt CHT simulations, and accelerates the engineering and licensing of next-generation nuclear reactors.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

A Risk-Informed Performance-Based Methodology to Manage Fire Protection Systems in Nuclear Facilities

Fire protection systems (FPSs) and features are installed in U.S. Department of Energy (DOE) Hazard Category 1, 2, or 3 nuclear facilities to protect property (maximum possible fire loss thresholds), life, and nuclear safety (i.e., structures, systems, and components). These FPSs and features are designed and maintained in accordance with the prescriptive guidance provided in applicable building codes and National Fire Protection Association codes and standards. Management, operations, and maintenance activities of FPSs involve significant effort. A DOE facility’s documented safety analysis or other safety basis document could also rely on FPSs to provide either a safety significant or safety class function to mitigate fire hazards and minimize radiological consequences. In some cases, the designation of safety significant or safety class may be determined to provide a layer of defense-in-depth to minimize nuclear safety risks independent of the fire risk. DOE standards allow the use of performance-based design alternatives developed by the fire industry but do not consider the defense-in-depth layers of protection provided in DOE facilities to prevent or mitigate the risks associated with unintended release of radioactive materials into the environment. Pacific Northwest National Laboratory developed a decision-making methodology tailored for DOE non-reactor nuclear facilities to manage FPSs and features by integrating nuclear safety risk insights into a performance-based analysis. This risk-informed, performance-based (RIPB) methodology can be used to provide the technical basis for classifying an FPS as safety class and safety significant, tailoring administrative controls (e.g., technical safety requirements), and ranking the importance of FPSs to prioritize maintenance, upgrades, and replacement activities. The RIPB methodology is a graded approach to inform DOE facility owners and Fire Protection Program managers of the most risk-significant FPSs and equipment, and those systems would be cost-beneficial to relax rigor if there is a need to re-design the FPS coverage or deviate from DOE and National Fire Protection Association standards for those systems that would be less significant. This paper describes the framework used to develop the RIPB methodology and the outcome of implementing this methodology in a use-case nuclear facility. This paper also discusses the impact to DOE policies and standards and the safety margins and defense-in-depth measures credited in nuclear safety assessments in a facility’s documented safety analysis and the benefits of implementing an RIPB methodology in lieu of a prescriptive method to comply with fire protection requirements.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Risk Analysis of Various Design Architectures for High Safety-significant Safety-related Digital Instrumentation and Control Systems of Nuclear Power Plants during Accident Scenarios

This report documents the plus-up activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2022 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems was proposed for this strategy, which aims to (1) provide a best-estimate, risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the high safety-significant safety-related (HSSSR) DI&C systems, (2) support and supplement existing advanced risk-informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems to support system design decisions and diversity and redundancy applications, (4) assure the long-term safety and reliability of HSSSR DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the LWRS-developed framework instructs nuclear vendors and utilities on how to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). Adding diversity within system or components is the main means to eliminate and mitigate CCFs, but diversity also increases plant complexity and errors and may not address all sources of systematic failures. How to optimize the diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in HSSSR DI&C systems of NPPs and supporting relevant design optimization, the framework provides: ? An integrated best-estimate, risk-informed capability to address new technical digital issues quantitatively, accurately, and efficiently in plan modernization progress, such as software CCFs in HSSSR DI&C systems of NPPs ? A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to efficiently predict and prevent risk in the early design stage of DI&C systems ? Technical bases and risk-informed insights to assist U.S. Nuclear Regulatory Commission (NRC) and industry to address and fulfill the risk-informed alternatives for evaluation of CCFs in HSSSR DI&C systems of NPPs ? An integrated risk-informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The plus-up research and development efforts of this project in FY 2022 are focused on methodology improvement of software CCF modeling and estimation, prevention analysis, importance analysis and risk analysis of various design architectures of HSSSR DI&C systems. This work greatly enhances the capability of the LWRS-developed framework for the risk assessment and design optimization of safety-critical DI&C systems. It should be noted that all the analyses are performed for the demonstration of the LWRS-developed framework, not for the evaluation of relevant systems. Results are obtained based on very limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Benchmark Specification for FFTF LOFWOS Test #13

The Fast Flux Test Facility (FFTF) at the Hanford site in Washington was designed by the Westinghouse Electric Corporation for the U.S. Department of Energy. FFTF was a 400 MW thermal, oxide-fueled, liquid sodium cooled test reactor, built to assist development and testing of advanced fuels and materials for fast breeder reactors. After reaching criticality in 1980, FFTF operated until 1992, providing the U.S. Department of Energy (DOE) with the means to test fuels, materials, and other components in a fast neutron flux environment. In July 1986, a series of unprotected transients (with the plant protection system intentionally disabled) were performed in FFTF as part of the passive safety demonstration program. Among these were thirteen loss of flow without scram (LOFWOS) tests. The goals of this program included confirming the liquid metal reactor safety margins, providing data for computer code validation, and demonstrating the inherent and passive safety benefits of specific design features. The test defined in this benchmark is LOFWOS Test #13, which was initiated at 50% power and 100% flow with the pump pony motors turned off. This benchmark specification is intended to support collaborative efforts within international partnerships on the validation of simulation tools and models in the area of Sodium-cooled Fast Reactor (SFR) safety. Validated tools and models are needed to evaluate SFR inherent safety characteristics and assess the impact of passive design features in response to accident initiators. Comparisons with experimental data and the results of safety analyses from other groups create unique opportunities to improve predictive capabilities of computational codes and methods for SFR modeling and simulation. The conditions of the LOFWOS test along with the feedback from FFTF’s limited free bow core restraint system and the novel passive reactivity control Gas-Expansion Modules (GEMs) pose a very challenging and uniquely valuable benchmark exercise.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Thermal Model of Oxide Growth for Full Size Fuel Plate Experiments in the Advanced Test Reactor

The full-size plate number one (FSP-1) irradiation test designed for irradiation testing of plate type fuel is planned to be irradiated in the Advanced Test Reactor (ATR) at the Idaho National Laboratory (INL). This FSP-1 experiment is a non-instrumented drop-in test where aluminum-clad fuel plates are cooled directly by the ATR Primary Coolant System (PCS) water. This experiment is one of a series of experiments being irradiated at ATR for the United States High Performance Research Reactor (USHPRR) program. This fueled experiment contains aluminum-clad fuel full-size plates consisting of monolithic U-10Mo. Previous thermal analyses have been documented concerning oxide growth [1] and thermal safety margins [2] for similar U-10Mo mini plate experiments. This analysis is part of the thermal safety analysis of the experiment to be irradiated in ATR. Departure from nucleate boiling ratio (DNBR) and flow instability ratio (FIR) have been calculated for the flow coastdown condition 2 and the reactivity insertion accident condition-2 (RIA2) transient. The purpose of this paper is to investigate the thermal margin of the fuel meat during a RIA2 transient when oxide has accumulated on the plate surfaces acting as an insulator.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

SAS4A/SASSYS-1 Validation with the FFTF LOFWOS Tests #10-12

The FFTF liquid sodium cooled test reactor was built to assist the development and testing of advanced fuels and material for fast reactors. The goals of the FFTF Passive Safety Testing program included confirming the safety margins of FFTF as a liquid metal reactor, providing data for computer code validation, and demonstrating the inherent and passive safety benefits of its specific design features. The program included thirteen unprotected loss of flow without scram tests. The results of modeling and simulation of LOFWOS Tests #10, #11, and #12 are presented in this report to support validation of Argonne’s SAS4A/SASSYS-1 fast reactor safety analysis code. These three tests did not use the primary loop pony motors and thus transitioned to natural circulation flow rates from varying initial power levels. This validation activity leverages modeling and simulation efforts that originated under an International Atomic Energy Agency Coordinated Research Project (CRP) for benchmark analysis of the FFTF LOFWOS Test #13. The SAS4A/SASSYS-1 model originally developed for the CRP has been extended to include LOFWOS Tests #10-12 and modernized to utilize new code features and modeling practices. Predicted results from SAS4A/SASSYS-1 were compared to measured test data and differences were investigated. Overall, it was concluded that, for LOFWOS Tests #10-12, there was good agreement between the flow, power, and temperature predictions and the measured data.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗