Engineering PapersSearch

SEARCH · Engineering Papers

Results for “System Safety”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Passive Safety System [Slides]

These slides are intended as an introduction to the concept of passive safety systems in LWRs and a discussion on designs that incorporate passive safety.

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Reactor System Safety: A case for New and Advanced Reactors

This presentation covers a generic overview of reactor system safety testing, analysis, and related research and development (R&D) focusing on new and advanced reactor systems. This presentation is prepared for graduate-level student seminar talks. No specific reactor design information is provided. Only publicly available information and related published articles and book contents are utilized.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN

Nuclear Safety System Cybersecurity Panel Summary

The panel discussion titled "Innovations in Advanced Cybersecurity Technologies for Safety Systems Within Nuclear Power Plants (NPPs)" took place at the American Nuclear Society (ANS) Annual Meeting in Las Vegas on Tuesday, June 18, 2024. The session was moderated by Lee Maccarone of Sandia National Laboratories (SNL) and featured four experts: Benjamin Karch from Sandia National Laboratories, Ismael Garcia from the U.S. Nuclear Regulatory Commission (NRC), Trevor Taylor from Paragon Energy Solutions (ES), and Forrest Shriver from Sentinel Devices.

22 GENERAL STUDIES OF NUCLEAR REACTORS

System Safety Risk Analysis Models (SSRAM)

This presentation provides a high level overview of the System Safety Risk Analysis (SSRAM) methodology and motivation.

Clark, Andrew Jordan [Sandia National Laboratories

Bayesian Optimized Deep Ensemble for Uncertainty Quantification of Deep Neural Networks: a System Safety Case Study on Sodium Fast Reactor Thermal Stratification Modeling

Deep neural networks (DNNs) are increasingly important to scientific computing and engineering system simulations. Accurate uncertainty quantification (UQ) for DNNs is critical in safety-sensitive engineering domains. Traditional Deep Ensemble (DE) methods, while easy to implement, frequently suffer from poorly calibrated uncertainty estimates and limited predictive accuracy due to reliance on fixed architectures with varied weight initializations. To address these issues, we introduce a workflow that combines Bayesian Optimization (BO) and DE. The workflow is modular, scalable, and integrates parallel BO initialized with Sobol sequences to individually optimize the hyperparameters of each ensemble member. This method enhances ensemble diversity, improves predictive accuracy, and provides reliable uncertainty estimates. We evaluate the proposed BODE approach in a sodium fast reactor thermal stratification modeling case study, where we used a densely connected convolutional neural network to predict turbulent viscosity during the reactor transient with consideration of data noise. We benchmark its performance against several optimization approaches, including baseline deep ensemble, evolutionary algorithm-optimized ensemble, ensemble formed via random search combined with greedy selection, and a BO ensemble using random initialization. Here, our results demonstrate superior performance of the developed BODE approach. In noise-free scenarios, BODE notably reduces incorrect aleatoric uncertainty and significantly enhances predictive accuracy. Under conditions of 5% and 10% Gaussian noise, BODE adaptively quantifies uncertainty proportional to data noise, achieving up to an 80% reduction in root mean square error compared to baseline methods and producing well-calibrated prediction intervals.

Bayesian optimization

Development of copper thiolate organometallic compound as thermal sensitive coating for energy storage system safety

Safety and reliability are primary concerns for the deployment of lithium-ion batteries, especially in electric vehicles (EV) and larger-scale energy storage systems (ESS). Current technology in battery management systems (BMS) includes cell voltage monitoring and positioning temperature sensors in selected locations. For a system with hundreds to thousands of individual batteries, single-point temperature monitoring is inadequate to detect hot spots and cell overheating, which could lead to thermal runaway. Here, we have developed a temperature-sensitive copper-thiol compound that can be directly coated onto battery pouch foils to enable early detection of thermal runaway. Upon reaching specific temperatures, this compound releases a sulfur-containing detectable gas, which can be identified using chemically specific gas sensors to trigger an early warning signal. Such a signal propagate through air offers broad signal coverage and enables a more comprehensive approach to large-area temperature monitoring. The Cu-ethanethiol coating is designed to release volatile gases when the substrate surface temperature exceeds 70 °C, with continuous outgassing as the temperature increases. The compound is composed of Cu, S, Cl, hydrocarbons and trace amounts of oxygen. Upon heating, the oxidation state of Cu(I) transitions to Cu (II), accompanied by gas release. Thermogravimetric analysis coupled with mass spectrometry correlated well with the onset of gas release temperature and emission of sulfur-containing volatile gases. Additionally, an acrylic overcoat is applied to enhance the adhesion of the thermally sensitive compound film to the battery pouch foil. This coating is expected to offer an additional safety layer for ESS, alerting possible thermal runaway events before a failure occurs, thereby allowing sufficient time to implement a mitigation plan.

Early warning systems

Hazard Analysis to Support Fusion Systems Safety Assessments

Reliability, safety, and performance are vital aspects of any nuclear operation. Fusion technology continues to grow in public, private, and research interest, and coupled with rapidly growing energy needs, fusion technology research is poised for fast progress. The development of a Fusion Nuclear Science Facility (FNSF) is seen as stepping stone for demonstrating long-cycle fusion. Naturally, such operation requires systems that are available, reliable, and safe. This work provides a novel demonstration of systems theory coupled with traditional hazard analysis to provide insights into the risk priority of components and systems found within the FNSF. The results of this work are a set of identified hazards that should be considered for the risk-informed design and development of the FNSF.

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Development of New Reactor Core Configuration for Power Uprate - Fuel Reload & Heat Processing Analyses, Core Design, System Safety Assessments, and Fuel Performance Analyses

With the passage of the Infrastructure Investment and Jobs Act in 2021 and the Inflation Reduction Act (IRA) in 2022, the United States stands at a critical juncture for the future of nuclear power. These landmark policies provide significant support for clean energy initiatives, positioning nuclear power as a key component of the nation’s strategy to reduce carbon emissions and achieve energy security. This growing emphasis on nuclear energy is driven by the need for reliable, low-carbon power sources as the country transitions away from fossil fuels. Federal policy, along with increasing state-level support, is encouraging investment in nuclear technology advancements to meet these demands. Building new nuclear power plants (NPPs), however, presents significant challenges due to high costs and long construction timelines. As a result, increasing the power output of existing NPPs through power uprates has emerged as a more feasible and cost-effective strategy. One key area of advancement is the development of accident-tolerant fuel (ATF), such as chromium-coated zirconium alloy cladding, which offers enhanced material performance, enabling power uprates in light water reactors (LWRs). Given the growing demand for nuclear energy fueled by federal policies and state initiatives, it is essential to evaluate the feasibility and benefits of significant power uprates in existing pressurized water reactors (PWRs) using advanced fuel technologies. The introduction of ATF concepts opens new opportunities for safely and economically achieving these power increases. Assessing whether these innovations can support substantial power uprates while maintaining operational safety is crucial to maximizing the potential of the nation’s existing nuclear infrastructure. This project aims to explore how power uprates can be achieved by boosting reactor thermal power output and optimizing reactor core design, while ensuring the safety and economic viability of NPPs. Specifically, it will focus on demonstrating the technical and economic feasibility of power uprates in a PWR using low 5-10% enrichment uranium (LEU+) high burnup (HBU) fuel combined with ATF concepts. In fiscal year 2024 (FY24), the research and development focus on building foundational models and conducting multi-physics performance and safety analyses to support the power uprate. The findings of the study would be shared through LWRS Seasonal Meetings, conferences and workshops with utility companies and researchers. These also serve as a basis for further study of fuel reloading optimization with ATF claddings.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS

Foundational Research for Fusion Systems Safety Assessment Overview

Presentation detailing work package to develop comprehensive fusion device safety models over the course of the next three years, including references to a blanket, divertor and magnet design, and statistical reliability models

70 - PLASMA PHYSICS AND FUSION TECHNOLOGY

Application of Ocean Thermal Energy Conversion (OTEC) Systems for Powering Safety Monitoring Systems of Offshore Oil and Gas Operations, OESI 2.0 M-1 T-1-P1.1 – Objective 3 Report: Collocation of OTEC with Offshore Oil and Gas Activities

This report is a component of a comprehensive research initiative aimed at evaluating the technoeconomic feasibility of deploying Ocean Thermal Energy Conversion (OTEC) systems to power safety monitoring systems for offshore oil and gas operations in the Gulf of America (GOA). The overarching study has three primary objectives: summarizing existing oil and gas equipment monitoring systems, modeling OTEC as a renewable marine energy source, and exploring the collocation of OTEC power sources with offshore oil and gas activities to offset power demand. This report specifically addresses Objective 3, focusing on the integration of OTEC systems with floating oil and gas facilities.

02 PETROLEUM

Application of Ocean Thermal Energy Conversion (OTEC) Systems for Powering Safety Monitoring Systems of Offshore Oil and Gas Operations. OESI 2.0 M-1 T-1-P1.1 – Objective 1 Interim Report: Summary of Offshore Oil and Gas Well Monitoring Systems and Process Power Requirements

This report is part of a comprehensive research initiative aimed at evaluating the technoeconomic feasibility of deploying greenhouse gas (GHG) emissions monitoring systems powered by small-scale renewable energy sources on the U.S. Outer Continental Shelf (OCS). The study has three primary objectives: summarizing available GHG monitoring systems for the OCS, modeling a renewable marine energy source (specifically ocean thermal energy conversion, or OTEC), and modeling the collocation of OTEC power sources with offshore oil and gas activities to offset power demand.

02 PETROLEUM

DEVELOPMENT OF AN INTEGRATED SECURITY AND SAFETY MONITORING SYSTEM FOR SPENT NUCLEAR FUEL AND HIGH-LEVEL WASTE TRANSPORTATION

This paper provides an overview of the progress to date, and discussion of the path forward, related to designing, fabricating, and testing an integrated security and safety monitoring system (ISSMS) for railcars used to transport spent nuclear fuel (SNF) and high-level radioactive waste (HLW) in the United States. The system will comply with the US Department of Energy’s (DOE) Order 460.2B “Departmental Materials Transportation Management” and the Association of American Railroads’ (AAR) standard S-2043 “Performance Specification for Trains Used to Carry High-level Radioactive Material” [1] developed specifically for railcars used to transport high-level radioactive material (HLRM). DOE is in the process of developing and testing an ISSMS that will satisfy both DOE requirements and AAR standards. DOE has already developed railcar designs for transportation of HLRM. In 2024, DOE’s Atlas railcar project completed the design, fabrication and testing of three railcar types: transportation cask-carrying, buffer, and security escort, resulting in AAR conditional approval to operate on freight rail networks in North America. DOE decided to combine the required security and safety systems into one system, and this combined system is the subject of the current effort. DOE is developing and proposes to implement the ISSMS for these railcars as part of the build out of the railcar fleet. DOE began planning for development of the ISSMS in February 2020. The project is divided into seven phases starting with conceptual design and continuing through production design, as shown in Figure 1. An earlier version of the system was tested as part of the Atlas railcar consist demonstration test run in 2023. This paper describes the design features and system testing using the Atlas project railcars, and laboratory testing completed to date. The paper will also describe the activities planned to support the DOE project to ship the High Burn-Up Research Cask (HBRC) in 2027.

Schultze, Michael [ORNL] (ORCID:0000000283205671)

Success Path Method: Conformance with Safety Management Systems

All industrial facilities deal with safety hazards such as equipment failures, chemical and toxic releases, and fires and explosions just to name a few. A disciplined framework for managing the integrity of operating systems and processes that handle hazardous substances by applying good design principles, engineering, and operating practices is called process safety. The goal of such framewoks is to prevent the release of energy or material that could cause harm to people or damage to equipment and/or environment. Process safety covers all aspects of facility operation also including design, maintenance, and human and organizational factors that could possibly have effect on process safety. As it will be seen from the discussion below, process safety is just one of the pieces of the much bigger matter, a safety culture. Many industries have long recognized the importance of safety culture in their day-to-day operation. Although the definition of safety culture can slightly differ from organization to organization, in general, a safety culture is how things are done to demonstrate a commitment to safety by everyone involved. An organization acquires safety culture over time as the product of individual and group values, actions, and behaviors toward overall safety. It is important to note that safety culture should not be viewed as some static state that an organization wants to reach. It is more like a constantly evolving level of “how things are done when nobody is watching.” Safety culture is an inherent characteristic of an organization, it is always present, but the level can range on a continuum from undesirable to desirable or more commonly used, from negative to positive. An example for an undesirable, negative safety culture would be a company in which accidents resulting in harm (physical and/or emotional) of its employees, equipment or surrounding environment and community occur frequently. At the other end of the spectrum would be a company in which such accidents are rare or do not occur at all (desired or positive safety culture). Every company/industry exists somewhere within this spectrum.

42 ENGINEERING

Portable and Cost-Effective Device for Reliable Detection of Counterfeit and Non-compliant Refrigerants in Diverse Applications

Counterfeit refrigerants pose significant challenges to safety, system reliability, and operational effectiveness due to their harmful contaminants or incompatible chemical compositions. Utilizing these noncompliant products can lead to reduced efficiency, equipment failures, and expensive repairs. Additionally, heightened demand for alternative refrigerants during the industry's transition has created supply gaps, enabling counterfeit products to proliferate. Accurate detection and analysis tools are therefore essential to verify refrigerant authenticity and ensure system integrity in diverse applications. This paper presents the development of a portable device designed for reliable identification and detailed analysis of refrigerant composition. By integrating precision gas sampling, controlled pressure regulation, and automated sensor technology, the device not only detects deviations from standard refrigerant properties but also provides a comprehensive composition breakdown. Pre-calibrated sensors measure the refrigerant gas to identify specific concentrations and contaminants, with an intuitive LED-based indicator system ensuring quick interpretation of results. The user-friendly interface enables operators to select refrigerant types for targeted testing, further enhancing accuracy and usability for field technicians. Comprehensive testing was conducted on mildly flammable A2L refrigerants, showcasing the device’s robustness and adaptability in analyzing composition and detecting discrepancies. The device demonstrated consistent accuracy across a range of refrigerant samples, affirming its reliability in diverse operational environments. Its design minimizes contamination risks during sampling and provides detailed composition results within 90 seconds, ensuring efficient and precise analysis. With a projected price point under $150, the proposed solution delivers affordability alongside its lightweight portability and straightforward operation. Unlike complex and costly alternatives, such as gas chromatography systems, this device provides an accessible option for technicians, customs personnel, and industry operators in need of quick and effective refrigerant verification. Compatible with both current formulations and emerging refrigerant technologies, the device addresses critical counterfeit detection needs across a range of applications. By delivering accurate composition analysis and counterfeit identification, this innovation enhances system performance, safety, and operational reliability in crucial industries.

Cheekatamarla, Praveen [ORNL] (ORCID:0000000248827

Architecture of the personnel protection systems for Spallation Neutron Source Second Target Station

The Oak Ridge National Laboratory (ORNL) is implementing a major upgrade to the Spallation Neutron Source (SNS) facility, encompassing the addition of the Second Target Station (STS). Preliminary design reviews have been conducted on several STS Personnel Protection Systems (PPS). The reviews focused primarily on the integration with the existing SNS PPS, the new proton transport tunnel, and the target areas. Development of the PPS is ongoing, to ensure a coherent safety system with the mission of protecting users and workers from prompt radiation hazards while providing high beam availability to operations. The STS PPS element in the Integrated Control System (ICS) is a facility-wide system composed of multiple safety subsystems, including the Ring to Second Target (RTST) beam transport tunnel, Target, Bunker and Instruments. Personnel working in all these geographic areas are protected by modular reliable PPS solutions. The safety system enforces access controls, radiation monitoring, beam destination control, and application of critical device inhibit upon detection of abnormal condition. It uses well-documented processes, Common Industrial Protocol (CIP) safety, pulsed test, and redundancy to achieve the desired Safety Integrity Level (SIL). This paper gives an architectural overview of the STS PPS and a detailed safety plan for the SNS facility, addressing safety solutions and human factors.

Michaelides, Tommy [ORNL] (ORCID:0000000190499869)

Sensitivity Analyses of Natural Convection in the AP1000 Passive Containment Cooling System Following LBLOCA Using CFD

The AP1000 power plant has implemented multiple layers of passive safety systems to enhance reactor safety and ensure system integrity during postulated scenarios, such as loss of coolant accident (LOCA) and main steam line break (MSLB). Among these, the passive containment cooling system (PCCS) is a safety-related system designed to prevent the containment from exceeding the design limits of both pressure and temperature following a postulated design basis accident, by transferring heat from the steel containment vessel to the atmosphere. During LOCA, natural air convection plays a vital role in removing heat from the steel containment vessel to the atmosphere. This is integrated with the condensate film from the Passive Containment Cooling Water Storage Tank (PCCWST). Air natural convection is also the only heat removal mechanism after the dry-out of the PCCWST and during the loss of shutdown decay heat removal (LOSDHR) event. Therefore, it is essential to investigate the thermal hydraulics behavior of the containment under transient conditions to ensure its safety and integrity. This paper presents a simplified CFD/ANSYS FLUENT model developed to analyze the impact of different parameters, such as air relative humidity, air temperature, and steel containment temperature, on the natural convection capability to remove the decay heat following LOCA. The model aims to examine the thermal behavior of the containment and provides a comprehensive understanding of the system's natural convection capability during postulated accidents. The results obtained from the model can be used to improve the safety and integrity of the containment system and provide valuable insights for future research in the field.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS

Proposed Classifications of Remote Operations for Nuclear Reactors Based on Physical and Cybersecurity Considerations

The incorporation of remote operations into reactor operations is a topic of high interest among advanced and small modular reactor (A/SMR) vendors, with some considering it essential to the success of their business models. However, remote operations are a concept novel to the nuclear industry. While various technical aspects of remote operations have been explored, a significant gap remains in understanding the security implications of integrating remote operations into reactor designs, particularly concerning the security requirements for remote-operations facilities and infrastructure. This report aims to address this gap by first defining classes of remote operation based on the extent of remote access to reactor control systems and grounded in the existing regulatory framework with compatible terminology. Secondly, the report outlines the physical and cybersecurity requirements applicable to remote-operations facilities and infrastructure at each defined class. These requirements are based on existing licensing frameworks provided by 10 Code of Federal Regulations (CFR) Part 50 and 10 CFR Part 52, as well as the upcoming A/SMR licensing framework in the proposed Part 53. The assessment focuses specifically on security regulations, such as 10 CFR Part 73, which includes provisions for both cybersecurity (§ 73.54) and physical security (§ 73.55). This report proposes five classes of remote reactor operations. Class 1 involves remote monitoring only, with no control over reactor systems. Class 2 allows for the remote issuance of allowlisted commands to the reactor facility. Class 3 extends control to non-safety-significant, non-safety-related, or not important to safety systems and equipment. Class 4 permits remote control of safety-significant systems. Finally, Class 5 allows remote control of safety-related systems. It is important to note that these classes were defined purely with functionality in mind, without considering the practicality or feasibility of implementation for each class under current or upcoming regulatory guidance. The intention behind this approach is to enable an assessment of which security requirements apply to each class, allowing readers to evaluate the implementation possibilities for their specific use cases. Following the definition of remote-operation classes, the report assesses the specific physical and cybersecurity requirements applicable to the remote-operations facility and infrastructure within each defined class. This includes defining the types and locations of operators that are possible at each class of operation and, based on operator type and location, as well as functionality within each class, outlining the physical and cybersecurity requirements. By detailing the security requirements by class, the report provides readers with the information needed to determine the type of security program they may need to implement for their desired concept of operation. The next contribution of this report was to assess the practicality of implementing each proposed class of remote operations based upon the security requirement assessment. In short, three of the five proposed remote-operation classes were found to possibly have a practical path forward to implementation under the U.S. regulatory framework. Class 1 remote operations are currently in use in the U.S. while Class 2 and 3 remote operations may be logistically possible to implement under the U.S. regulatory framework. The final two Classes, 4 and 5, would likely be logistically difficult, if not infeasible to implement within the current U.S. physical- and cybersecurity regulatory framework. Given the results of the feasibility assessment, an example architecture is proposed for both Class 2, remote allowlisted commands, and Class 3, remote control of non-safety systems as well as security implication assessments of each architecture. These example implementations are not meant to be prescriptive in terms of how Class 2 or Class 3 remote operations should be deployed; instead, they are intended to be informative to stakeholders on how Class 2 or Class 3 could potentially be applied in order to inform their system design. An example architecture for Class 1 remote monitoring was not provided as Class 1 in already in use in U.S. nuclear operations. Example architectures for Class 4 and Class 5 were not provided due to their assessment of being likely infeasible to implement. The final contribution is an assessment of the physical- and cybersecurity implications of introducing autonomous operations into an A/SMR. What was found was that the security implications can be separated into two cases. Autonomous operations supported by SSCs located only at the reactor site, and autonomous operations supported by SSCs outside of the reactor site. For the first case, the introduction of autonomous systems will likely not change the facility’s requirement to comply with existing cyber and physical security regulation

22 - GENERAL STUDIES OF NUCLEAR REACTORS

Advanced Reactor Designs Security Analysis, Risk, and Recommendations: Risks, Consequences, and Possible by-Design Mitigation Approaches Associated with Select Advanced Reactors

Next-generation advanced reactors (ARs) incorporate enhanced safety systems, have smaller source terms, and feature compact modular designs, which should lessen their collective risk profiles. However, to fully evaluate risk, security needs to be a part of the equation. Without taking security into consideration, safety systems and components in the new ARs may be vulnerable to sabotage. These base attributes, coupled with enhanced security features specific to AR design through sound engineering and security-by-design (SeBD), should provide developers and operators with lower inherent security risk profiles. Building security early into the AR design may remove or passively secure potential critical targets from an adversary’s reach , thereby increasing overall safety and security. An integrated approach and diverse design team that includes engineering, operations, and security experts are fundamental to building security into the design without sacrificing fundamental operational efficiencies and principles. The objective of this project was to evaluate the security and safety interfaces for five classes of reactors, identify potential security vulnerabilities of structures, systems, and components (SSC), and underscore the need to consider security alongside safety in the design o f these concepts. The five reactor classes evaluated in this project and presented in this report are molten-salt reactors (MSR), high temperature gas reactors (HTGR), sodium-fast reactors (SFR), advanced light-water reactors (ALWR), and microreactors. These designs were selected because they reflect the concepts that are closest to market deployment and have received significant resource investments from the public and private sector. This project assesses the inherent security risks posed by common classes of ARs, provides a methodology and framework to assess security along with safety, and offers an analysis of potential mitigation strategies that could be incorporated. For each AR technology, the SSCs that relate to radionuclide source safety functions are discussed to understand the SSC contribution to safety and relative importance in the protective strategy for the design. The assumptions that went into evaluating each reactor concept originated from generic publicly available nonproprietary information and should not directly be used to qualify an absolute risk profile nor to rank specific AR designs. Instead, the purpose of the analysis is to understand and compare the generic inherent security risks of different AR technologies.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL