Search NASA⌕ Search

SEARCH · Search NASA

Results for “Safety Analysis”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 217 records · Page 12

Possible safety hazards associated with the operation of the 0.3-m transonic cryogenic tunnel at the NASA Langley Research Center

The 0.3 m Transonic Cryogenic Tunnel (TCT) at the NASA Langley Research Center was built in 1973 as a facility intended to be used for no more than 60 hours in order to verify the validity of the cryogenic wind tunnel concept at transonic speeds. The role of the 0.3 m TCT has gradually changed until now, after over 3000 hours of operation, it is classified as a major NASA research facility and, under the administration of the Experimental Techniques Branch, it is used extensively for the testing of airfoils at high Reynolds numbers and for the development of various technologies related to the efficient operation and use of cryogenic wind tunnels. The purpose of this report is to document the results of a recent safety analysis of the 0.3 m TCT facility. This analysis was made as part of an on going program with the Experimental Techniques Branch designed to ensure that the existing equipment and current operating procedures of the 0.3 m TCT facility are acceptable in terms of today's standards of safety for cryogenic systems.

Webster, T. J.↗

Development of Composite Sandwich Bonded Longitudinal Joints for Space Launch Vehicle Structures

The NASA Composite Technology for Exploration (CTE) Project is developing and demonstrating critical composite technologies with a focus on composite bonded joints; incorporating materials, design/analysis, manufacturing, and tests that utilize NASA’s expertise and capabilities. The project has goals of advancing composite technologies and providing lightweight structures to support future NASA exploration missions. In particular, the CTE project will demonstrate weight-saving, performance-enhancing composite bonded joint technology for Space Launch System (SLS)-scale composite hardware. Advancements from the CTE project may be incorporated as future block upgrades for SLS structural components. This paper discusses the details of the development of a composite sandwich bonded longitudinal joint for a generic space launch vehicle structure called the CTE Point Design. The paper includes details of the design, analysis, materials, manufacturing, and testing of sub-element joint test articles to test the capability of the joint design. The test results show that the composite longitudinal bonded joint design significantly exceeds the design loads with a 2.0 factor of safety. Analysis pre-test failure predictions for all sub-element bonded joint test coupons were all within 10% of the average test coupon failure load. This testing and analysis provides confidence in the potential use of composite bonded joints for future launch vehicle structures.

Segal, Kenneth N.↗

Revision of Paschen's Law Relating to the ESD of Aerospace Vehicle Surfaces

The purpose of this work is to develop a form of Paschen's law that takes into account the flow of gas past electrode surfaces. This work was performed under a NASA Science Innovation Fund (SIF) project at the Kennedy Space Center in collaboration with the University of Central Florida. In 2010 the Electrostatics and Surface Physics Laboratory (ESPL) at the Kennedy Space Center performed an electrostatic safety analysis on the flight termination system (FTS) antenna for the Ares I rocket. Paschen's law, derived by Friedrich Paschen in 1889 to relate sparking voltage to gas pressure and electrode separation, does not take into account the effect of flowing gas between the electrodes. The safety of the FTS housing to triboelectric charging was shown only after extensive laboratory testing. Potential benefits are of a form of Paschen's law that considers gas velocity. This work is applicable to current and planned rockets and aerospace vehicles and could lead to possible relaxation of electrostatic launch criteria. Launch aborts can cost up to about a million US dollars depending on the vehicle. [ElectroStatic Discharge (ESD)]

Paschen↗

High Flux Isotope Reactor Low-Enriched Uranium High Density Silicide Fuel Preliminary Design Update: System Transient Analysis

As a part of conversion efforts from highly enriched uranium (HEU) to low-enriched uranium (LEU) fuel under direction of the National Nuclear Security Administration of the U.S. Department of Energy, multiple proposed designs of the High Flux Isotope Reactor (HFIR) have been created and assessed regarding reactor physics performance metrics, including designs utilizing uranium silicide dispersion fuel (U3Si2-Al). This report updates the previous analyses that evaluated the nuclear safety performance of LEU fuel designs with respect to selected accident events from the HFIR Safety Analysis Report (SAR). Both the Low Density (LD) and High Density (HD) Optimized designs’ reactivity initiated accident fuel performance improved relative to the HEU fuel, attributed to greater 238 U negative Doppler feedback. However, the thermal margins for primary coolant system accidents were reduced with some acceptance criteria unable to be met. The need to resolve reduced thermal margin, open modeling items, and unresolved assumptions was identified.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Progress Towards the Validation of a new RELAP5-3D model of the High Temperature Test Facility

Validation is a key step in the development of any type of systems model. As the next generation of reactors approaches, the need for codes that have been validated for these new types of systems continues to grow. An example of a prominent option is the Reactor Excursion Leak Analysis Program (RELAP5-3D), developed by Idaho National Laboratory. This code was developed for the purpose of systems level thermal-hydraulic modeling of light water reactors (LWRS) and postulated transients that can occur in LWRS.RELAP5-3D has been substantially validated against LWR data. Due to its long history as a reactor safety analysis tool, there has been an effort to adapt RELAP5-3D for the purposes of advanced reactor concepts such as prismatic high-temperature gas-cooled reactors (HTGRs). However, RELAP5-3D has not nearly been validated and verified for HTGRs to the degree of LWRs, warranting verification and validation opportunities with computational benchmarks and existing experimental facilities. Examples of such facilities include the modular high-temperature gas-cooled reactor (MHTGR) 350 and the high temperature engineering test reactor (HTTR) from Japan. The MHTGR 350 is a benchmark design concept for code-to-code verification purposes; therefore, it does not provide any experimental data for validation opportunities The HTTR provides useful multiphysics validation data but does not have the in-core instruments to generate thermal-hydraulic experimental data to help with RELAP5-3D validation. Consequently, a facility that could provide key in-core temperatures for thermal-hydraulic validation was still needed. The High Temperature Test Facility (HTTF) is an integral effects facility for HTGR thermal hydraulics developed and operated by Oregon State University. HTTF represents ¼ length scale of the General Atomics MHTGR and is rated for a total power of 2.2 MW. Axially, the core consists of an upper and lower reflector and 10 blocks, numbered from bottom to top (Block 1 is right above lower reflector). The core is heated via graphite resistive heater rods, with respective channels distributed throughout the core. The primary coolant is helium and heat can radiate out of the core to the reactor cavity cooling system (RCCS), which is cooled by water. The primary purpose of the facility is to investigate pressurized conduction cooldown (PCC) and depressurized conduction cooldown (DCC) transients, which are also referred to as the pressurized and depressurized loss of forced cooling respectively. Two experiments were chosen to perform the validation study with a RELAP5-3D model of HTTF. These experiments are PG-27 (PCC) and PG-29 (DCC). These were chosen based off of the quality of available experimental data before and during the experiment which led to their inclusion in the HTGR Thermal Hydraulics Benchmark.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

High-Temperature Gas-Cooled Pebble-Bed Reactors Running In And Transient Modeling Capabilities Demonstration

This study presents a comprehensive benchmarking and verification effort of several thermal-hydraulic and multiphysics capabilities for high-temperature gas-cooled reactor (HTGR) applications. The first part of this effort focuses on the running-in verification of Griffin's multiphysics capabilities, specifically for simulating the evolution of Pebble Bed reactor cores from startup to equilibrium. In the absence of validation data, code-to-code comparisons are conducted with Kugelpy, showing good agreement for key quantities like maximum power density and fresh core k-eigenvalue predictions. However, discrepancies in equilibrium core predictions suggest potential issues with cross sections, underscoring the need for further refinement and evaluation. The HTTF system analysis code benchmark involves RELAP5-3D, SAM, and GAMMA+ to assess their predictive capabilities for HTTF behavior under both normal operation and pressurized conduction cooldown (PCC) transient conditions. While there is good agreement in predicting major parameters such as coolant temperature, solid temperature, and flow distribution, discrepancies in transient behavior highlight differences in modeling approaches, nodalizations, and heat transfer models. The HTTF lower plenum CFD benchmark employs nekRS to simulate flow mixing phenomena, successfully capturing relevant flow physics and demonstrating mesh independence in complex geometries. Preliminary results suggest a relatively uniform temperature field but significant unsteadiness in the flow, requiring time-averaging analyses. The GPBR200 system analysis code benchmark uses SAM's core channel and porous media models, incorporating an RCCS loop for decay heat removal. During steady-state and transient conditions, including protected de-pressurized and pressurized loss of forced cooling (DLOFC and PLOFC), both models show good agreement in predicting temperature profiles and key parameters. Notably, while the core channel model underpredicts convective heat transfer effects, both models maintain temperatures well below the TRISO fuel safety limit. These benchmarking efforts collectively enhance the predictive capabilities of the tools used in HTGR design and safety analysis, guiding developments to improve their accuracy and applicability.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Lidar performance analysis

Section 1 details the theory used to build the lidar model, provides results of using the model to evaluate AEOLUS design instrument designs, and provides snapshots of the visual appearance of the coded model. Appendix A contains a Fortran program to calculate various forms of the refractive index structure function. This program was used to determine the refractive index structure function used in the main lidar simulation code. Appendix B contains a memo on the optimization of the lidar telescope geometry for a line-scan geometry. Appendix C contains the code for the main lidar simulation and brief instruction on running the code. Appendix D contains a Fortran code to calculate the maximum permissible exposure for the eye from the ANSI Z136.1-1992 eye safety standards. Appendix E contains a paper on the eye safety analysis of a space-based coherent lidar presented at the 7th Coherent Laser Radar Applications and Technology Conference, Paris, France, 19-23 July 1993.

Spiers, Gary D.↗

Failure Assessment

Three questions to which software developers want accurate, precise answers are "How can the software system fail?", "mat bad things will happen if the software fails?t', and "How many failures will the software experience?". Numerous techniques have been devised to answer these questions; three of the best known are: 1) Software Fault Tree Analysis (SFTA) 2) Software Failure Modes, Effects, and Criticality Analysis (SFMECA 3) Software Fault/Failure Modeling. SFTA and SFMECA have been successfully used to analyze the flight software for a number of robotic planetary exploration missions, including Galileo, Cassini, and Deep Space 1. Given the increasing interest in reusing software components from mission to mission, one of us has developed techniques for reusing the corresponding portions of the SFTA and SFMECA, reducing the effort required to conduct these analyses. SFTA has also been shown to be effective in analyzing the security aspects of software systems; intrusion mechanisms and effects can easily be modeled using these techniques. The Bi- Directional Safety Analysis (BDSA) method combines a forward search (similar to SFMECA) from potential failure modes to their effects, with a backward search (similar to SFTA) from feasible hazards to the contributing causes of each hazard. BDSA offers an efficient way to identify latent failures. Recent work has extended BDSA to product-line applications such as flight-instrumentation displays and developed tool support for the reuse of the failure-analysis artifacts within a product line. BDSA has also been streamlined to support those projects having tight cost and/or schedule constraints for their failure analysis efforts. We discuss lessons learned from practice, describe available tools, and identi@ some future directions for the topic. A substantial amount of research has been devoted to estimating the number of failures that a software system will experience during test and operations, as well as the number of faults that have been inserted into that system during its development. One of us has found that the amount of structural change to a system during its development is strongly related to the number of faults inserted into it. Using techniques requiring no additional effort on the part of the development organization, the required measurements of structural evolution can be easily obtained from a development effort's configuration management system and readily transformed into an estimate of fault content. So far, structure-fault relationships have been identified for source code; current work seeks to examine artifacts available earlier in the lifecycle to determine if similar relationships between structure and fault content can be found. In particular, relationships between requirements change requests and the number of faults inserted into the implemented system would provide a significant improvement in our ability to control software quality during the early development phases.

fault tree↗

Argument-Based Airworthiness Assurance of Small UAS

Presently, there are three avenues by which Unmanned Aircraft System (UAS) operations are authorized in the U.S. National Airspace System (NAS): obtaining either (i) a certificate of authorization (COA), or (ii) a special airworthiness certificate (SAC) in either the experimental, or the restricted category, or (iii) an exemption from an airworthiness certificate together with a civil COA. The first is meant primarily for public entities, such as NASA; the remaining two are the only available means for civil UAS operations. Recently, the Federal Aviation Administration (FAA) has also proposed a regulatory framework targeted for certain small UAS, specifically those weighing 55 pounds or less, although final rulemaking remains pending. We have previously shown how an assurance case can aggregate heterogeneous reasoning and safety evidence, with application to UAS safety. In this paper, we describe how assurance cases can serve as a common framework to justify overall system safety, unifying both operational aspects and airworthiness, in particular system design assurance. We also show how this approach can coexist with, and augment, existing safety analysis processes and best-practices, by transforming the artifacts they produce into structured assurance arguments. To illustrate the applicability and utility of our approach, we have been applying it for the design assurance of an unmanned rotorcraft system, intended for precision agriculture operations, as part of the NASA Unmanned Aircraft System (UAS) Integration in the National Airspace System (NAS) project.

Rotocraft↗

SCALE inventory and reactivity analysis as part of the Hermes 2021 PSAR review

The readiness of SCALE for comprehensive studies of pebble-bed reactors has been demonstrated through detailed analysis of a fluoride salt–cooled, high-temperature pebble-bed reactor (PB-FHR). The methods developed for pebble-bed reactor modeling in SCALE, particularly for inventory generation, have proven effective in gaining insights into the reactor physics of this advanced reactor. Excellent agreement with another code package has been observed, further highlighting SCALE’s strong performance. The SCALE results supported the US Nuclear Regulatory Commission’s construction permit application review of the Hermes low-power PB-FHR demonstration reactor. A SCALE model of the Hermes reactor was developed at Oak Ridge National Laboratory using information from the Preliminary Safety Analysis Report (PSAR) and supplemented with publicly available data. SCALE reactivity coefficient simulations reproduced PSAR results within 1σ statistical uncertainties. Sensitivity studies emphasized the importance of graphite specifications for accurate keff predictions.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

Non-Cooled Power System for Venus Lander

The Planetary Science Decadal Survey of 2013-2022 stated that the exploration of Venus is of significant interest. Studying the seismic activity of the planet is of particular importance because the findings can be compared to the seismic activity of Earth. Further, the geological and atmospheric properties of Venus will shed light into the past and future of Earth. This paper presents a radioisotope power system (RPS) design for a small low-power Venus lander. The feasibility of the new power system is then compared to that of primary batteries. A requirement for the power source system is to avoid moving parts in order to not interfere with the primary objective of the mission - to collect data about the seismic activity of Venus using a seismometer. The target mission duration of the lander is 117 days, a significant leap from Venera 13, the longest-lived lander on the surface of Venus, which survived for 2 hours. One major assumption for this mission design is that the power source system will not provide cooling to the other components of the lander. This assumption is based on high-temperature electronics technology that will enable the electronics and components of the lander to operate at Venus surface temperature. For the proposed RPS, a customized General Purpose Heat Source Radioisotope Thermoelectric Generator (GPHSRTG) is designed and analyzed. The GPHS-RTG is chosen primarily because it has no moving parts and it is capable of operating for long duration missions on the order of years. This power system is modeled as a spherical structure for a fundamental thermal analysis. The total mass and electrical output of the system are calculated to be 24 kilograms and 26 Watts, respectively. An alternative design for a battery-based power system uses Sodium Sulfur batteries. To deliver a similar electrical output for 117 days, the battery mass is calculated to be 234 kilograms. Reducing mission duration or power required will reduce the required battery mass. Finally, the advantages and disadvantages of both power systems with regard to science return, risk, and cost are briefly compared. The design of the radioisotope power system is considerably riskier because it is novel and would require additional years of further refinement, manufacturing, safety analysis, and testing that the primary batteries do not need. However, the lifetime of the radioisotope power system makes its science return more promising.

planetary↗

Investigating the Impact of Temporal and Directional Traffic Distribution on Crash Frequencies

Safety Performance Functions (SPFs) are mathematical models that establish relationships between the frequency of various crash types and site-specific characteristics, serving as essential tools for traffic safety analysis and roadway design. Traditional SPFs, however, often overlook the temporal fluctuations in traffic flow (such as peak-hour surges) and directional imbalances between opposing traffic streams. These traffic patterns can exacerbate congestion, disrupt driver behavior, and create unexpected conflict points, potentially leading to increased crash frequencies and more severe accidents. In light of this gap, this study aims to explore the potential of incorporating K-factors (representing peak-hour traffic proportions) and D-factors (reflecting the imbalance of directional traffic) into the development of SPFs to assess whether these factors can effectively represent the impact of temporal and spatial traffic distribution on roadway safety. Using crash data from Pennsylvania urban-suburban collector roadways, it is found that the D-factor plays a significant role in predicting the frequency of total crashes, fatal + injury crashes, and angle crashes, with positive coefficient signs indicating that higher directional imbalances correspond to increased crash risks. Similarly, the K-factor emerges as a critical predictor for fatal + injury crashes and rear-end crashes, with negative coefficients suggesting that a more pronounced traffic peak is associated with a reduction in expected crash frequencies. These results highlight the importance of accounting for uneven traffic distribution in both time and direction when developing SPFs, offering deeper insights into crash patterns and supporting more effective safety interventions and roadway designs.

Xu, Guanhao [ORNL] (ORCID:0000000214326357)↗

Conceptual Launch Vehicle and Spacecraft Design for Risk Assessment

One of the most challenging aspects of developing human space launch and exploration systems is minimizing and mitigating the many potential risk factors to ensure the safest possible design while also meeting the required cost, weight, and performance criteria. In order to accomplish this, effective risk analyses and trade studies are needed to identify key risk drivers, dependencies, and sensitivities as the design evolves. The Engineering Risk Assessment (ERA) team at NASA Ames Research Center (ARC) develops advanced risk analysis approaches, models, and tools to provide such meaningful risk and reliability data throughout vehicle development. The goal of the project presented in this memorandum is to design a generic launch 7 vehicle and spacecraft architecture that can be used to develop and demonstrate these new risk analysis techniques without relying on other proprietary or sensitive vehicle designs. To accomplish this, initial spacecraft and launch vehicle (LV) designs were established using historical sizing relationships for a mission delivering four crewmembers and equipment to the International Space Station (ISS). Mass-estimating relationships (MERs) were used to size the crew capsule and launch vehicle, and a combination of optimization techniques and iterative design processes were employed to determine a possible two-stage-to-orbit (TSTO) launch trajectory into a 350-kilometer orbit. Primary subsystems were also designed for the crewed capsule architecture, based on a 24-hour on-orbit mission with a 7-day contingency. Safety analysis was also performed to identify major risks to crew survivability and assess the system's overall reliability. These procedures and analyses validate that the architecture's basic design and performance are reasonable to be used for risk trade studies. While the vehicle designs presented are not intended to represent a viable architecture, they will provide a valuable initial platform for developing and demonstrating innovative risk assessment capabilities.

Launch Vehicle↗

VARI3D & PERSENT: Perturbation and Sensitivity Analysis (Revision 5)

The nodal diffusion method is one of the most widely used approaches in modern reactor analysis. In the nodal diffusion method, a coarse multi-group set of “homogenized” parameters is constructed such that the complex geometry of a reactor core along with the energy dependence of neutron and gamma ray cross sections in a nuclear reactor are conserved in the simpler geometry. The homogenization is typically done on a fuel assembly level as is the case in the DIF3D code developed at Argonne National Laboratory. The nodal methodology is used primarily to predict fuel cycle behavior of nuclear systems of which there is a substantial amount of validation in the literature. Another use of the nodal method is to obtain reactivity coefficients and kinetics parameters for use in a safety analysis of a given nuclear reactor. While there are many ways to obtain reactivity worth and kinetics parameters, the work presented in this manuscript is unique as it provides the user with the ability to compute reactivity worths, kinetics parameters, and cross section sensitivities with a Cartesian and hexagonal geometry-based transport code.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

VARI3D & PERSENT: Perturbation and Sensitivity Analysis

The nodal diffusion method is one of the most widely used approaches in modern reactor analysis. In the nodal diffusion method, a coarse multi-group set of “homogenized” parameters is constructed such that the complex geometry of a reactor core along with the energy dependence of neutron and gamma ray cross sections in a nuclear reactor are conserved in the simpler geometry. The homogenization is typically done on a fuel assembly level as is the case in the DIF3D code developed at Argonne National Laboratory. The nodal methodology is used primarily to predict fuel cycle behavior of nuclear systems of which there is a substantial amount of validation in the literature. Another use of the nodal method is to obtain reactivity coefficients and kinetics parameters for use in a safety analysis of a given nuclear reactor. While there are many ways to obtain reactivity worth and kinetics parameters, the work presented in this manuscript is unique as it provides the user with the ability to compute reactivity worths, kinetics parameters, and cross section sensitivities with a Cartesian and hexagonal geometry based transport code. This manuscript serves as a single manual for two separate codes: VARI3D and PERSENT. The VARI3D code (VARIational 3D) is based upon the classic finite difference diffusion theory solver available in DIF3D. The PERSENT code (PERturbation and SENitivity for Transport) is based upon the variational nodal method employed in DIF3D termed VARIANT. The VARIANT solver was added to DIF3D in 1995 and has seen continued development and use for the last 18 years. Because VARI3D primarily uses deprecated coding practices, rather than incorporating the perturbation and sensitivity treatments for transport within VARI3D, a new coding development was built using modern Fortran coding. The primary purpose of this manual is to describe the theory behind PERSENT (and by convenience, that of VARI3D) and discuss the input and output of PERSENT along with giving potential users an idea of how to use it. While this manuscript does describe the input and output of VARI3D, the PERSENT code is intended to be the replacement capability of VARI3D as PERSENT can generate nearly identical (if not superior) diffusion theory results. In this manuscript, the relevant aspects of generalized perturbation theory and exact perturbation theory that apply to both VARI3D and PERSENT are covered. The input and output of VARI3D is displayed by excerpting several of the example problems. Similarly, the input and output of PERSENT is displayed along with tips on how best to use the code. Note that the input and output of the inhomogeneous solver wrapped around DIF3D (DIF3D_IFS) is also discussed as it is needed to carry out some of the sensitivities in PERSENT such as reaction rate ratios. This manuscript describes several perturbation and sensitivity problems, and the results computed using PERSENT. From these sections, potential users should find that PERSENT provides not only the typical tables of numbers desired in perturbation and sensitivity analysis work, but also can visually plot the result for a more thorough understanding of the space and energy distribution (Section 5). Overall, PERSENT is observed to produce accurate reactivity worths and sensitivities for the displayed set of test problems and clearly demonstrates the need to have a transport-based sensitivity capability as evident from the thousands of percent errors observed in the 21-group hexagonal fast reactor problem (covered in Section 7). The uncertainty calculation capability is described in Section 3 and demonstrated in Section 7.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Shear joint capability versus bolt clearance

The results of a conservative analysis approach into the determination of shear joint strength capability for typical space-flight hardware as a function of the bolt-hole clearance specified in the design are presented. These joints are comprised of high-strength steel fasteners and abutments constructed of aluminum alloys familiar to the aerospace industry. A general analytical expression was first arrived at which relates bolt-hole clearance to the bolt shear load required to place all joint fasteners into a shear transferring position. Extension of this work allowed the analytical development of joint load capability as a function of the number of fasteners, shear strength of the bolt, bolt-hole clearance, and the desired factor of safety. Analysis results clearly indicate that a typical space-flight hardware joint can withstand significant loading when less than ideal bolt hole clearances are used in the design.

Lee, H. M.↗

Reassessing Double-Ended Guillotine Break Requirements: Evidence-Based Analysis of Regulatory Assumptions After Five Decades of Nuclear Operation

After five decades of nuclear power operation encompassing more than 20,000 reactor-years across 35 countries and 647 reactors, zero double-ended guillotine breaks (DEGBs) have been documented in commercial reactor coolant systems—despite DEGB being the fundamental design-basis assumption driving Emergency Core Cooling System (ECCS) sizing, structural protection requirements, and containment design specifications. This report examines the basis for DEGB requirements in nuclear power plant design. The DEGB postulate assumes the instantaneous, complete circumferential severance of the largest diameter pipes in reactor coolant systems, driving major design requirements under 10 Code of Federal Regulations 50.46, General Design Criterion 4 and containment design specifications. The United States (4,880 reactor-years) and France (2,505 reactor-years) contribute the largest operational datasets. Probabilistic assessments estimate direct DEGB occurrence probabilities with extremely low event frequencies, far below the 10-5/reactor-year thresholds typically used to define non-credible events in nuclear-safety analyses; i.e., events with probability this low fall into beyond-design-basis events. Current material-science knowledge demonstrates that the ductile steel materials used in nuclear piping systems exhibit stable crack-growth behavior fundamentally incompatible with instantaneous severance. International regulatory experience, particularly Germany’s comprehensive break-preclusion implementation, and successful leak-before-break (LBB) applications in almost all of U.S. pressurized water reactor units validate that alternatives can maintain safety performance while reducing economic burden. Current DEGB protection systems impose estimated lifetime costs of hundreds of millions of dollars per unit, over the life of a plant across the nuclear industry (including ongoing costs), representing substantial resource allocation toward scenarios with extremely low probability. Although this report acknowledges uncertainties regarding long-term aging effects, potential synergistic degradation mechanisms, and site-specific seismic considerations that warrant continued evaluation as regulatory policy evolves, there remains no documented evidence that a DEGB has occurred as a consequence of the conditions or mechanisms described in this report. This report acknowledges the Nuclear Regulatory Commission’s (NRC’s) recent efforts—outlined in the draft Interim Staff Guidance (ISG) NRC-DSS-ISG-2025-XX (“Treatment of Certain Loss-of-Coolant Accident Locations as Beyond-Design-Basis Accidents Draft Interim Staff Guidance”)—to reduce overly conservative requirements for large-break loss of coolant accidents through technical justifications and exemptions. However, extensive operating experience and validated methodologies—such as LBB and in-service inspection programs—demonstrate that the probability of a DEGB in reactor coolant-loop piping is extremely low, even under seismic conditions. The authors and reviewers of this report recommend that DEGB be removed as a design-basis event through formal rulemaking, rather than case-by-case exemptions, to better reflect credible failure modes, align with current data, and align with modern, risk-informed safety analysis.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Improving Cyber Situational Understanding

Effective cybersecurity operations require the ability to analyze large amounts of information to assess security risks and formulate defensive strategies against adversaries. This has become more complex in recent years as the sprawl and interconnectivity of devices grows through implementation of virtualization, cloud computing, and Internet of Things (IoT). The amount of data and analysis required for effective cybersecurity command and control decisions far exceeds humans’ capacity to perform manually. We characterize the analysis problem as cyber situational understanding. The research presented to improve cyber situational understanding focuses on vulnerability analysis and threat intelligence. Regarding vulnerabilities, entities must analyze and plan work for between thousands and tens of thousands of software vulnerabilities annually. Entities heavily use network firewalls to limit vulnerability exposure. As a result, some of these vulnerabilities permit exposure to adversarial exploitation, whereas others are inaccessible and therefore present negligible risk of exploitation. Distinguishing between high and low risk software vulnerabilities requires a deep understanding of the vulnerability, network firewall protection, and characteristics of the targeted device. This problem is solved by extracting network service features from vulnerability data features using both machine-learning and natural language processing. Then, the network firewall topology is parsed to determine which vulnerabilities are reachable by adversaries. Ultimately, a state-based safety analysis ascertains which vulnerabilities are unsafe. A related vulnerability analysis problem occurs in cybersecurity operations when associating an entity’s hardware and software assets to public vulnerability databases. Assets often reveal hardware and software through installation artifacts and network service identification, and entities store these artifacts in inventory databases. However, software and hardware vendors apply a standard Common Platform Enumeration (CPE) naming convention when publicly reporting vulnerabilities. Associating these two datasets often requires many hours to days of manual inspection. The proposed solution automates the mapping approach of human analysts using fuzzy matching techniques, natural language processing, and, ultimately, machine learning to present a small set of recommendations for mapping the two datasets. The result significantly reduces human analysis time and reduces the occurrence of false positives in vulnerability notifications. Finally, cyber threat intelligence (CTI) requires associating cyber observable artifacts, such as IP addresses, URIs, and file hashes, with cyber threat tactics, techniques, and procedures. Unfortunately, most CTI data is compartmentalized across multiple organizations and cannot be shared due to the legal and reputational risk with cyber threat being associated with the entity. The approach to solving this problem inovlves using a distributed ledger with anonymous token spending and authentication. This allows a consortium of semi-trusted entities to share the workload of curating CTI for a threat sharing community’s cooperative benefit.

Huff, Philip↗