Search NASA⌕ Search

SEARCH · Search NASA

Results for “risk-informed”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 55 records · Page 3

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer Based Hydrogen Production Facility

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at NREL's Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Radiological Releases from Novel Fuel Forms in Advanced Reactors During Severe Accidents for Consequence Analyses

Various advanced reactor developers are exploring the potential for reductions in the size of physical security forces and emergency planning zones. These reductions are based on robust fuel forms and inherently safe reactor designs. However, such reductions in physical protection measures could increase the risk of sabotage. To assess the possibility of reducing these measures, sabotage-induced radiological consequence analyses were carried out. These analyses considered accident scenarios that were beyond design basis accidents and overly conservative (Shah, 2025a; Shah, 2025b; Shah and Hartanto, 2026), yielding very large release fractions. These fractions, which can be used to evaluate physical protection and emergency planning requirements, have been crudely determined and applied as demonstrations for a sodium-cooled fast reactor (SFR) (Shah and Hartanto, 2025a), a high-temperature gas-cooled reactor (HTGR) (Shah and Hartanto, 2025b), a heat pipe–cooled reactor (HPR) (Shah and Hartanto, 2025c), and a molten salt–cooled reactor (MSR) (Shah et al., 2026). A Sandia National Laboratories (SNL) team used MELCOR—a fully integrated severe accident analysis code—to demonstrate the code’s capability to analyze advanced (i.e., not light water–cooled) reactors (including a fluoride salt–cooled high-temperature reactor [FHR]) and calculate radiological releases to the environment during severe accidents (Wagner et al., 2022a, 2022b, 2022c, 2023a, and 2023b). Although the analyses were carried out to demonstrate MELCOR’s growing capability, the release source terms were estimated for advanced reactors, providing valuable insights into the accident progression and radiological releases. These findings from prior SNL studies, including estimated source terms and related sensitivity studies, were leveraged to derive source terms for postulated sabotage-induced accidents. Insights from these sensitivity studies informed the scaling of SNL’s estimated source terms for the defined accident scenarios. The derived release fractions for the severe accident scenarios for the respective reactor designs can be used to perform more nuanced dose consequence analyses to evaluate the reactors’ physical protection and emergency planning zone requirements. These analyses are in accordance with the risk-informed, performance-based approach proposed under 10 CFR Part 53. This study builds on the prior source term analyses and associated sensitivity studies by SNL to derive time-dependent and design-informed release fractions. Section 2 describes the diverse advanced reactor designs analyzed by the SNL team. Section 3 discusses the severe accident analyses, the release fractions calculated, and the limitations and assumptions of the demonstration project. Section 4 presents the release percentages derived for the hypothetical sabotage-induced severe accidents at the advanced reactors. Section 5 summarizes the study’s findings and conclusions.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Security Licensing Basis Framework Development

This report summarizes a technology-inclusive and performance-based method to determine the physical security licensing basis for a commercial nuclear reactor under the proposed 10 CFR 73.100 for Part 53 licensees. The method focuses on the identification of security functions, the contributing security systems and programs to meet those functions, the identification of security events that will provide the foundation for the security licensing basis and includes a risk-informed performance-based defense in depth adequacy method. The method can also be employed to justify performance-based alternative measures to traditional security requirements found in 10 CFR 73.55.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Reassessing Double-Ended Guillotine Break Requirements: Evidence-Based Analysis of Regulatory Assumptions After Five Decades of Nuclear Operation

After five decades of nuclear power operation encompassing more than 20,000 reactor-years across 35 countries and 647 reactors, zero double-ended guillotine breaks (DEGBs) have been documented in commercial reactor coolant systems—despite DEGB being the fundamental design-basis assumption driving Emergency Core Cooling System (ECCS) sizing, structural protection requirements, and containment design specifications. This report examines the basis for DEGB requirements in nuclear power plant design. The DEGB postulate assumes the instantaneous, complete circumferential severance of the largest diameter pipes in reactor coolant systems, driving major design requirements under 10 Code of Federal Regulations 50.46, General Design Criterion 4 and containment design specifications. The United States (4,880 reactor-years) and France (2,505 reactor-years) contribute the largest operational datasets. Probabilistic assessments estimate direct DEGB occurrence probabilities with extremely low event frequencies, far below the 10-5/reactor-year thresholds typically used to define non-credible events in nuclear-safety analyses; i.e., events with probability this low fall into beyond-design-basis events. Current material-science knowledge demonstrates that the ductile steel materials used in nuclear piping systems exhibit stable crack-growth behavior fundamentally incompatible with instantaneous severance. International regulatory experience, particularly Germany’s comprehensive break-preclusion implementation, and successful leak-before-break (LBB) applications in almost all of U.S. pressurized water reactor units validate that alternatives can maintain safety performance while reducing economic burden. Current DEGB protection systems impose estimated lifetime costs of hundreds of millions of dollars per unit, over the life of a plant across the nuclear industry (including ongoing costs), representing substantial resource allocation toward scenarios with extremely low probability. Although this report acknowledges uncertainties regarding long-term aging effects, potential synergistic degradation mechanisms, and site-specific seismic considerations that warrant continued evaluation as regulatory policy evolves, there remains no documented evidence that a DEGB has occurred as a consequence of the conditions or mechanisms described in this report. This report acknowledges the Nuclear Regulatory Commission’s (NRC’s) recent efforts—outlined in the draft Interim Staff Guidance (ISG) NRC-DSS-ISG-2025-XX (“Treatment of Certain Loss-of-Coolant Accident Locations as Beyond-Design-Basis Accidents Draft Interim Staff Guidance”)—to reduce overly conservative requirements for large-break loss of coolant accidents through technical justifications and exemptions. However, extensive operating experience and validated methodologies—such as LBB and in-service inspection programs—demonstrate that the probability of a DEGB in reactor coolant-loop piping is extremely low, even under seismic conditions. The authors and reviewers of this report recommend that DEGB be removed as a design-basis event through formal rulemaking, rather than case-by-case exemptions, to better reflect credible failure modes, align with current data, and align with modern, risk-informed safety analysis.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Operating Experience Data Analysis for Digital Instrumentation and Control System Reliability and Risk Assessment in Nuclear Power Plants

The implementation of advanced digital instrumentation and control (DI&C) systems in U.S. nuclear power plants (NPPs) can bring significant advancements in reliability, monitoring, and control capabilities. However, these systems also introduce new challenges, particularly in assessing risks such as common-cause failures (CCFs) and establishing robust reliability estimates for DI&C components. Addressing these challenges is critical for ensuring the safe and efficient operation of NPPs. Recently, Idaho National Laboratory was tasked by the U.S. Nuclear Regulatory Commission (NRC) to conduct a DI&C reliability study using operating experience data from the nuclear industry. The two operating experience data sources for the study are the Institute of Nuclear Power Operations’ Industry Reporting and Information System (IRIS) and the NRC’s Licensee Event Report database which is hosted at Idaho National Laboratory at https://lersearch.inl.gov/LERSearchCriteria.aspx. This report provides a comprehensive examination of DI&C systems, including their architecture, operational advantages, and associated challenges. It reviews existing industry DI&C studies and failure mode taxonomies, along with reliability data from various industries. Through a detailed analysis of these databases, the study provides insights into DI&C system performance. Considerations should be given to incorporate DI&C failure data into the NRC's Integrated Data Collection and Coding System and updating the Reliability and Availability Data System to support ongoing DI&C reliability studies. Recommendations are also provided for modeling DI&C reliability and CCF in probabilistic risk assessment, thereby supporting risk-informed decision-making and enhancing the reliability and safety of NPPs.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Hazard Analysis to Support Fusion Systems Safety Assessments

Reliability, safety, and performance are vital aspects of any nuclear operation. Fusion technology continues to grow in public, private, and research interest, and coupled with rapidly growing energy needs, fusion technology research is poised for fast progress. The development of a Fusion Nuclear Science Facility (FNSF) is seen as stepping stone for demonstrating long-cycle fusion. Naturally, such operation requires systems that are available, reliable, and safe. This work provides a novel demonstration of systems theory coupled with traditional hazard analysis to provide insights into the risk priority of components and systems found within the FNSF. The results of this work are a set of identified hazards that should be considered for the risk-informed design and development of the FNSF.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

An Integrated Approach to Life Cycle Analysis

Life Cycle Analysis (LCA) is the evaluation of the impacts that design decisions have on a system and provides a framework for identifying and evaluating design benefits and burdens associated with the life cycles of space transportation systems from a "cradle-to-grave" approach. Sometimes called life cycle assessment, life cycle approach, or "cradle to grave analysis", it represents a rapidly emerging family of tools and techniques designed to be a decision support methodology and aid in the development of sustainable systems. The implementation of a Life Cycle Analysis can vary and may take many forms; from global system-level uncertainty-centered analysis to the assessment of individualized discriminatory metrics. This paper will focus on a proven LCA methodology developed by the Systems Analysis and Concepts Directorate (SACD) at NASA Langley Research Center to quantify and assess key LCA discriminatory metrics, in particular affordability, reliability, maintainability, and operability. This paper will address issues inherent in Life Cycle Analysis including direct impacts, such as system development cost and crew safety, as well as indirect impacts, which often take the form of coupled metrics (i.e., the cost of system unreliability). Since LCA deals with the analysis of space vehicle system conceptual designs, it is imperative to stress that the goal of LCA is not to arrive at the answer but, rather, to provide important inputs to a broader strategic planning process, allowing the managers to make risk-informed decisions, and increase the likelihood of meeting mission success criteria.

Chytka, T. M.↗

Altair Lunar Lander Development Status: Enabling Human Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a minimum functionality approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicles safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to begin Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. A blended NASA-industry team will continue to refine the lander configuration and mature the vehicle design over the next few years. This paper will update the international community on the status of the Altair Project as it addresses the challenges of project formulation, including optimizing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

Altair Lunar Lander Development Status: Enabling Lunar Exploration

As a critical part of the NASA Constellation Program lunar transportation architecture, the Altair lunar lander will return humans to the moon and enable a sustained program of lunar exploration. The Altair is to deliver up to four crew to the surface of the moon and return them to low lunar orbit at the completion of their mission. Altair will also be used to deliver large cargo elements to the lunar surface, enabling the buildup of an outpost. The Altair Project initialized its design using a "minimum functionality" approach that identified critical functionality required to meet a minimum set of Altair requirements. The Altair team then performed several analysis cycles using risk-informed design to selectively add back components and functionality to increase the vehicle's safety and reliability. The analysis cycle results were captured in a reference Altair design. This design was reviewed at the Constellation Lunar Capabilities Concept Review, a Mission Concept Review, where key driving requirements were confirmed and the Altair Project was given authorization to began Phase A project formulation. A key objective of Phase A is to revisit the Altair vehicle configuration, to better optimize it to complete its broad range of crew and cargo delivery missions. Industry was invited to partner with NASA early in the design to provide their insights regarding Altair configuration and key engineering challenges. NASA intends to continue to seek industry involvement in project formulation activities. This paper will update the international coimmunity on the status of the Altair Project as it addresses the challenges of project formulation, including optinuzing a vehicle configuration based on the work of the NASA Altair Project team, industry inputs and the plans going forward in designing the Altair lunar lander.

Laurini, Kathleen C.↗

A Corrosion Risk Assessment Model for Underground Piping

The Pressure Systems Manager at NASA Ames Research Center (ARC) has embarked on a project to collect data and develop risk assessment models to support risk-informed decision making regarding future inspections of underground pipes at ARC. This paper shows progress in one area of this project - a corrosion risk assessment model for the underground high-pressure air distribution piping system at ARC. It consists of a Corrosion Model of pipe-segments, a Pipe Wrap Protection Model; and a Pipe Stress Model for a pipe segment. A Monte Carlo simulation of the combined models provides a distribution of the failure probabilities. Sensitivity study results show that the model uncertainty, or lack of knowledge, is the dominant contributor to the calculated unreliability of the underground piping system. As a result, the Pressure Systems Manager may consider investing resources specifically focused on reducing these uncertainties. Future work includes completing the data collection effort for the existing ground based pressure systems and applying the risk models to risk-based inspection strategies of the underground pipes at ARC.

Datta, Koushik↗

2009 Space Shuttle Probabilistic Risk Assessment Overview

Loss of a Space Shuttle during flight has severe consequences, including loss of a significant national asset; loss of national confidence and pride; and, most importantly, loss of human life. The Shuttle Probabilistic Risk Assessment (SPRA) is used to identify risk contributors and their significance; thus, assisting management in determining how to reduce risk. In 2006, an overview of the SPRA Iteration 2.1 was presented at PSAM 8 [1]. Like all successful PRAs, the SPRA is a living PRA and has undergone revisions since PSAM 8. The latest revision to the SPRA is Iteration 3. 1, and it will not be the last as the Shuttle program progresses and more is learned. This paper discusses the SPRA scope, overall methodology, and results, as well as provides risk insights. The scope, assumptions, uncertainties, and limitations of this assessment provide risk-informed perspective to aid management s decision-making process. In addition, this paper compares the Iteration 3.1 analysis and results to the Iteration 2.1 analysis and results presented at PSAM 8.

Hamlin, Teri L.↗

Quantifying Uncertainty in High CO₂ Capture rate with MEA Solvent Systems

This presentation covers the methodology and key findings from an uncertainty quantification study of monoethanolamine (MEA) solvent-based systems operating under high CO₂ capture conditions. The goal is to identify critical operational parameters, assess their impact on system performance, and provide insights to support risk-informed design and optimization of carbon capture processes.

monoethanolamine (MEA)↗

Development of a Digital Twin for Hydrogen Dispersion and Safety Assessment in an Electrolyzer-Based Hydrogen Production Facility: Preprint

Digital twin models are virtual representations of physical systems that use real-time data to simulate and optimize performance. This study presents the development and initial implementation of a digital twin (DT) for the electrolyzer-based hydrogen production facility at the National Renewable Energy Laboratory (NREL)'s Advanced Research on Integrated Energy Systems (ARIES), focused on enhancing safety and optimizing sensor placement through physics-based simulations and metadata integration. The DT incorporates detailed facility-specific information, including component layout, leak locations, and controlled release parameters, to model hydrogen dispersion under varying environmental conditions. Using steady-state computational fluid dynamics (CFD) simulations informed by real meteorological data, such as wind speed, direction, and vertical wind profiles, the DT enables visualization of hydrogen plume behavior and spatial concentration distributions. Comparative analysis between high and low wind speed scenarios illustrates the significant influence of wind dynamics on plume shape and extent, with horizontal momentum dominating dispersion at higher speeds, while buoyancy effects become more prominent under low wind conditions. These simulations generate a rich dataset embedded within the DT, allowing users to assess potential leak outcomes and identify optimal sensor locations based on concentration thresholds. The model supports scenario-based analysis to guide safety strategies and equipment deployment for open-area hydrogen infrastructure. The digital twin thus serves as a dynamic platform for virtual prototyping, providing predictive insight into hydrogen behavior and enhancing risk-informed decision-making. This initial phase establishes a validated foundation for future integration of transient, uncontrolled leak scenarios and real-time sensor feedback, positioning the DT as a critical tool for safety design, operational planning, and adaptive monitoring in hydrogen systems. Overall, the approach demonstrates the value of combining environmental data with digital simulations to inform safer and more efficient deployment of hydrogen technologies.

08 HYDROGEN↗

Advancing Multi-Hazard Risk and Safety Considerations for Aging Nuclear Facilities

While probabilistic risk assessment (PRA) of nuclear facilities is expected to include internal and external hazards for a risk-informed and performance-based design, the current state of practice treats each hazard independently. However, such an independent treatment of hazards may not account for the correlations between different hazards and their response of and damage to the structures, systems, and components (SSCs) in a plant resulting in underestimating the overall risk. This project proposes to advance the multi-hazard PRA of nuclear facilities to more adequately evaluate concurrent hazards and contribute to an increased safety of nuclear plants. A framework for multi-hazard PRA will be developed by identifying concurrent hazard events (both internal and external) and event sequences that include interdependencies through the response of SSCs. An example application of the multi-hazard PRA framework will be demonstrated by considering a generic pressurized water reactor (PWR) subjected to seismic and internal flooding hazards. Computational models for the response of components will be developed to generated multi-hazard fragility surfaces under seismic and flooding loads. A PRA model consisting of event and fault trees will also be developed to quantify the multi-hazard risk profile and compare it with the independent hazard risk profile. Overall, by advancing the multi-hazard PRA of nuclear facilities, this project enhances nuclear safety and reduces costs by mitigating unforeseen consequences caused by correlations between concurrent hazards.

97 - MATHEMATICS AND COMPUTING↗

An Approach to Automate tools for the Risk Assessment of Digital Instrumentation and Control Systems

Reliable digital instrumentation and control systems (DI&C) are integral for sustaining the continued operation of nuclear power plants. These systems ensure that nuclear reactors operate safely, efficiently, and within regulatory requirements. Yet, the cost of designing and licensing new nuclear DI&C can be prohibitively expensive. Under the U.S. Department of Energy Light Water Reactor Sustainability Program, Idaho National Laboratory has developed a framework for supporting the risk-informed design of DI&C systems by offering methods to support the identification, quantification, and evaluation of risks for various DI&C design architectures. The framework indicates potential software failure modes and provides pathways for quantifying the potential for these software failures, including common cause failures. Using the framework’s systematic approach, challenges for assessing risks within new and existing nuclear DI&C systems can be reduced. Nevertheless, the current framework can be further improved using the convenience of automation. This paper introduces the development of Software for the Hazard Identification and Evaluation of Digital Systems (SHIELDS). SHIELDS is an engineering software package that enables the identification, elimination, and mitigation of potential risks and reduces the burden of deploying reliable DI&C systems. This work introduces plans and techniques to digitize and improve the manual risk assessment modules of the framework. These improvements will save time and increase the repeatability and usability of the framework, making it more accessible to a wider range of users. Ultimately, this introduces SHIELDS and how its modules support efficient development of safe and reliable DI&C systems.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN↗

Hungary 908 Event - Risk Based Graded Approach to ITM

This presentation, Risk-Based, Graded Approach to Insider Threat Mitigation: Human Measures, introduces a structured framework for managing insider threat risk using internationally recognized guidance from the International Atomic Energy Agency (IAEA) Nuclear Security Series No. 8-G (Rev. 1) and the Joint Statement on Mitigating Insider Threats (INFCIRC/908). The presentation emphasizes that effective insider threat mitigation (ITM) depends on both positional controls, which manage inherent risk based on access, authority, and knowledge, and human measures, which address residual risk reflected in behavior, motivation, and reliability. Using a risk-informed and graded approach, the presentation outlines methods for identifying and prioritizing high-risk positions, applying layered organizational controls, and integrating human reliability mechanisms such as the Behavior Observation Program (BOP), Fitness-for-Duty (FFD) evaluations, Employee Assistance Programs (EAP), and Nuclear Security Culture (NSC). The human-focused portion examines behavioral and organizational indicators of opportunity, vulnerability, motivation, and crisis, demonstrating how early detection, deterrence, and response can prevent insider events. The session concludes with a case review of the Millstone Nuclear Power Station incident involving engineer George Galatis. The case illustrates how weak leadership and a poor safety culture can create conditions for failure and how a comprehensive ITM framework could have altered the outcome. The objective of this presentation is to help practitioners apply a risk-based, graded philosophy to human factors and promote a culture of accountability, communication, and resilience within nuclear organizations.

99 - GENERAL AND MISCELLANEOUS↗