Systems-Theoretic Hazard Analysis of Digital Human-System Interface Relevant to Reactor Trip
Slides for 2021 ANS-NPIC-HMIT conference
SEARCH · Engineering Papers
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Slides for 2021 ANS-NPIC-HMIT conference
Replacing the existing aging analog instrumentation and control (I&C) systems with modern safety control and protection digital technology offers one of the foremost means of performance improvements and cost reductions for the existing nuclear power plants (NPPs). However, the qualification of digital I&C systems remains a challenge, especially considering the issue of software common-cause failures (CCFs), which are difficult to address. With the application and upgrades of advanced digital I&C systems, software CCFs have become a potential threat to plant safety because most redundant designs use similar digital platforms or software in the operating and application systems. With complex designs of multilayer redundancy to meet the single-failure criterion, digital I&C safety systems (e.g., engineered safety-features actuation system [ESFAS]) are of a particular concern in the U.S. Nuclear Regulatory Commission (NRC) licensing procedures. This paper applies a modularized approach to conduct redundancy-guided systems-theoretic hazard analysis for an advanced digital ESFAS with multilevel redundancy designs. Systematic methods and risk-informed tools are incorporated to address both hardware and software CCFs, which provide guidance to eliminate the triggers of potential single points of failure in the design of digital safety systems in advanced plant designs.
We report digital instrumentation and control (I&C) upgrades are a vital research area for the nuclear industry. Despite their performance benefits, deployment of digital I&C in nuclear power plants (NPPs) has been limited. Digital I&C systems exhibit complex failure modes including common cause failures (CCFs), which can be difficult to identify. This paper describes the development of a redundancy-guided application of the Systems-Theoretic Process Analysis and fault tree analysis for the hazard analysis of digital I&C in advanced NPPs. The resulting Redundancy-Guided Systems-Theoretic Hazard Analysis (RESHA) is applied for the case study of a representative state-of-the-art digital reactor trip system. The analysis qualitatively and systematically identifies the most critical CCFs and other hazards of digital I&C systems. Ultimately, the RESHA can help researchers make informed decisions for how, and to what degree, defensive measures such as redundancy, diversity, and defense in depth can be used to mitigate or eliminate the potential hazards of digital I&C systems.
A fire hazard analysis, required for many U.S. Department of Energy (DOE) facilities, is a complex, cumbersome, and costly process. Fire hazard analyses may be viewed as a checkbox, but ideally and in spirit with the DOE-STD-1066, the fire hazard analysis (FHA) should be a part of the workflow and used to help in modifications, maintenance, and improving operational safety. With current FHA development processes, it is both time and cost prohibitive for true integration. A tool called Fire Risk Investigation in 3D or FRI3D was developed under the DOE Light Water Reactor Sustainability program to simplify and automate many aspects of a fire probabilistic risk analysis for existing nuclear power plants. The FRI3D tool automates fire scenarios by combining approved fire simulation codes, U.S. Nuclear Regulatory Commission fire calculations methods, 3D modeling and visualization, and probabilistic risk analysis models into a single workflow supported with a user interface. FRI3D was initially designed for used in combination with a PRA, this case study, evaluated using FRI3D for a plant modification, determined the benefits that detailed fire modeling can have for U.S. Department of Energy facilities with or without a PRA model. It also looked at what tasks from DOE requirements could be reduced using the tool and what is needed to integrate fire hazard analysis into site workflow.
Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.
Traditional hazards analysis (HA) methods, originally developed to address physical and operational risks, often fall short when it comes to identifying and mitigating cyber threats. These cyber threats pose unique and evolving risks to critical infrastructure and industrial control systems (ICS). This report explores the integration of Cyber-Informed Engineering (CIE) principles into existing HA methods to enhance their ability to address cyber-induced risks. CIE provides organizations with a practical, cost-effective approach to closing the gap between traditional HA methods and the need for cyber risk mitigation. By leveraging existing safety processes and controls, CIE allows users to examine and mitigate cyber vulnerabilities without overhauling existing HA methods. This report identifies areas where HA and CIE naturally align and where their approaches diverge. It emphasizes how CIE principles can be used to adapt HA methods, broadening their scope to include cyber risks and enabling the mitigation of cyber- induced impacts alongside traditional hazards and failure scenarios. This report examines how CIE can be applied across various HA methods—such as Hazard and Operability Studies (HAZOP), Probabilistic Risk Assessment (PRA), Failure Modes and Effects Analysis (FMEA), Systems-Theoretic Process Analysis (STPA), Hazard and Consequence Analysis for Digital Systems (HAZCADS), and Layers of Protection Analysis (LOPA). It provides strategies for integrating CIE to strengthen the identification, assessment, and mitigation of cyber-induced risks. The findings offer a structured entry point for organizations to embed CIE concepts into hazards and safety analyses, as well as broader engineering processes, ultimately supporting the design and operation of a more resilient infrastructure.
A hazard analysis has been requested from Nuclear Criticality Safety (NCS) regarding the identification of normal and credible abnormal conditions relative to machining activities performed at NMCA location UMPETY in Room SQUAT of SHANGRALA.
Human-system interfaces (HSIs) play an important role in enabling operators to communicate with the nuclear power plant (NPP) side. Getting the information required to understand a NPP’s current status or perform necessary actions for responding to a given operational context are representative operator tasks performed using HSIs. To date, HSIs have been mainly evaluated in the context of human reliability analysis (HRA). However, the current HSI evaluation that occurs during HRA may be challengeable on two fronts: (1) reflecting the unique characteristics of HSI systems and (2) considering situations in which HSIs are poorly operated due to software/hardware malfunctions. Accordingly, this study proposes an approach for specifically evaluating HSIs for digital instrumentation and controls (DI&C) systems, using Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) and HRA. RESHA is a method for analyzing DI&C systems with redundancy features. In this study, we investigate how HSIs are evaluated in existing HRA methods, and what challenges exist in the current approaches. To better evaluate HSIs for DI&C systems, this study modifies the existing HSI evaluation process by additionally modeling the HSI back- and front- ends. In this paper, a HSI fault tree for the APR1400 DI&C system is introduced through a piping and instrumentation diagram. It then touches upon what aspects of the suggested method must be further researched.
Battery based energy storage systems are becoming a critical part of a modernized, resilient power system. However, batteries have a unique combination of hazards that can make design and engineering of battery systems difficult. This report presents a systematic hazard analysis of a hypothetical, grid scale lithium-ion battery powerplant to produce sociotechnical "design objectives" for system safety. We applied system's theoretic process analysis (STPA) for the hazard analysis which is broken into four steps: purpose definition, modeling the safety control structure, identifying unsafe control actions, and identifying loss scenarios. The purpose of the analysis was defined as to prevent event outcomes that can result in loss of battery assets due to fires and explosions, loss of health or life due to battery fires and explosions, and loss of energy storage services due to non- operational battery assets. The STPA analysis resulted in identification of six loss scenarios, and their constituent unsafe control actions, which were used to define a series of design objectives that can be applied to reduce the likelihood and severity of thermal events in battery systems. These design objectives, in all or any subset, can be utilized by utilities and other industry stakeholders as "design requirements" in their storage request for proposals (RFPs) and for evaluation of proposals. Further, these design objectives can help to protect firefighters and bring a system back to full functionality after a thermal event. We also comment on the hazards of flow battery technologies.
The Ocean & Geohazard Analysis (OGA) tool: AI/ML enhanced integrated offshore hazard analysis.
The backbone approach to constructing a ground-motion logic tree for probabilistic seismic hazard analysis (PSHA) can address shortcomings in the traditional approach of populating the branches with multiple existing, or potentially modified, ground-motion models (GMMs) by rendering more transparent the relationship between branch weights and the resulting distribution of predicted accelerations. To capture epistemic uncertainty in a tractable manner, there are benefits in building the logic tree through the application of successive adjustments for differences in source, path, and site characteristics between the host region of the selected backbone GMM and the target region for which the PSHA is being conducted. The implementation of this approach is facilitated by selecting a backbone GMM that is amenable to such host-to-target adjustments for individual source, path, and site characteristics. The NGA-West2 GMM of Chiou and Youngs (CY14) has been identified as a highly adaptable model for crustal seismicity that is well suited to such adjustments. Rather than using generic source, path, and site characteristics assumed appropriate for the host region, the final suite of adjusted GMMs for the target region will be better constrained if the host-region parameters are defined specifically on the basis of their compatibility with the CY14 backbone GMM. To this end, making use of a recently developed crustal shear-wave velocity profile consistent with CY14, we present an inversion of the model to estimate the key source and path parameters, namely the stress parameter and the anelastic attenuation. With these outputs, the effort in constructing a ground-motion logic tree for any PSHA dealing with crustal seismicity can be focused primarily on the estimation of the target-region characteristics and their associated uncertainties. The inversion procedure can also be adapted for any application in which different constraints might be relevant.
To design good software, you must always keep the end user in mind. Some benefits of incorporating the user-centered design process include saving users time and effort and helping them to utilize all capabilites of an application. In my work on the All Hazards Analysis (AHA) application, I employed principles of user-centered design to make the application easier for new users to navigate. This poster describes user-centered software design in general and showcases some of my user-centered design work on the AHA application.
Reliability, safety, and performance are vital aspects of any nuclear operation. Fusion technology continues to grow in public, private, and research interest, and coupled with rapidly growing energy needs, fusion technology research is poised for fast progress. The development of a Fusion Nuclear Science Facility (FNSF) is seen as stepping stone for demonstrating long-cycle fusion. Naturally, such operation requires systems that are available, reliable, and safe. This work provides a novel demonstration of systems theory coupled with traditional hazard analysis to provide insights into the risk priority of components and systems found within the FNSF. The results of this work are a set of identified hazards that should be considered for the risk-informed design and development of the FNSF.
Replacing the existing aging analog instrumentation and control (I&C) systems with modern safety control and protection, digital technology offers one of the foremost means of performance improvements and cost reductions for the existing nuclear power plants (NPPs). However, the qualification of digital I&C systems remains a challenge, especially considering the issue of software common-cause failures (CCFs), which are difficult to address. With the application and upgrades of advanced digital I&C systems, software CCFs have become a potential threat to plant safety because most redundant designs use similar digital platforms or software in the operating and application systems. With complex designs of multilayer redundancy to meet the single-failure criterion, digital I&C safety systems (e.g., engineered safety-features actuation system [ESFAS]) are of a particular concern in the U.S. Nuclear Regulatory Commission (NRC) licensing procedures. Here, this paper applies a modularized approach to conduct redundancy-guided systems-theoretic hazard analysis for an advanced digital ESFAS with multilevel redundancy designs. Systematic methods and risk-informed tools are incorporated to address both hardware and software CCFs, which provide guidance to eliminate the causal factors of potential single points of failure in the design of digital safety systems in advanced plant designs.
Explore the source record for details and available documents.
Onur et al. (2017) compiled the first comprehensive earthquake catalog for Iraq, covering 1900 to 2009 within 26°–40°N latitude and 36°–51°E longitude. This catalog was utilized in a probabilistic seismic hazard assessment (PSHA) by Abdulnaby et al. (2020) to aid in updating Iraq’s building code seismic provisions. Recently, we have updated the earthquake catalog for Iraq by adding earthquakes recorded from 2010 to 2021 and directly calculating moment magnitude (Mw) for about 2,800 earthquakes using the coda envelope methodology and waveform data from the Mesopotamian Seismological Network (MPSN) in Iraq.
Not Available
Not provided.