Search NASA⌕ Search

SEARCH · Search NASA

Results for “Common Cause Failure”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Common Cause Failure Modeling

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFS are a set of dependent type of failures that can be caused by: system environments; manufacturing; transportation; storage; maintenance; and assembly, as examples. Since there are many factors that contribute to CCFs, the effects can be reduced, but they are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and CCF (dependent) failure and data is limited, especially for launch vehicles. The Probabilistic Risk Assessment (PRA) of NASA's Safety and Mission Assurance Directorate at Marshall Space Flight Center (MFSC) is using generic data from the Nuclear Regulatory Commission's database of common cause failures at nuclear power plants to estimate CCF due to the lack of a more appropriate data source. There remains uncertainty in the actual magnitude of the common cause risk estimates for different systems at this stage of the design. Given the limited data about launch vehicle CCF and that launch vehicles are a highly redundant system by design, it is important to make design decisions to account for a range of values for independent and CCFs. When investigating the design of the one-out-of-two component redundant system for launch vehicles, a response surface was constructed to represent the impact of the independent failure rate versus a common cause beta factor effect on a system's failure probability. This presentation will define a CCF and review estimation calculations. It gives a summary of reduction methodologies and a review of examples of historical CCFs. Finally, it presents the response surface and discusses the results of the different CCFs on the reliability of a one-out-of-two system.

Hark, Frank↗

Common Cause Failure Modeling

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFS are a set of dependent type of failures that can be caused by: system environments; manufacturing; transportation; storage; maintenance; and assembly, as examples. Since there are many factors that contribute to CCFs, the effects can be reduced, but they are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and CCF (dependent) failure and data is limited, especially for launch vehicles. The Probabilistic Risk Assessment (PRA) of NASA's Safety and Mission Assurance Directorate at Marshal Space Flight Center (MFSC) is using generic data from the Nuclear Regulatory Commission's database of common cause failures at nuclear power plants to estimate CCF due to the lack of a more appropriate data source. There remains uncertainty in the actual magnitude of the common cause risk estimates for different systems at this stage of the design. Given the limited data about launch vehicle CCF and that launch vehicles are a highly redundant system by design, it is important to make design decisions to account for a range of values for independent and CCFs. When investigating the design of the one-out-of-two component redundant system for launch vehicles, a response surface was constructed to represent the impact of the independent failure rate versus a common cause beta factor effect on a system's failure probability. This presentation will define a CCF and review estimation calculations. It gives a summary of reduction methodologies and a review of examples of historical CCFs. Finally, it presents the response surface and discusses the results of the different CCFs on the reliability of a one-out-of-two system.

Hark, Frank↗

Common Cause Failures and Ultra Reliability

A common cause failure occurs when several failures have the same origin. Common cause failures are either common event failures, where the cause is a single external event, or common mode failures, where two systems fail in the same way for the same reason. Common mode failures can occur at different times because of a design defect or a repeated external event. Common event failures reduce the reliability of on-line redundant systems but not of systems using off-line spare parts. Common mode failures reduce the dependability of systems using off-line spare parts and on-line redundancy.

reliability↗

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures↗

Common Cause Failures Dominate and Defeat Redundancy

Common cause failures occur when several malfunctions are produced by a single event or process. They are especially damaging when they eliminate an entire set of redundant systems and disable their intended function. Redundancy is used when the individual system failure probability is unacceptably high. Redundancy can improve the overall system failure probability if the failures are independent, but the reliability gain is limited if there are dependent failures having a common cause. No amount of redundancy can reduce the total failure probability below the common cause failure probability. Common cause failures defeat redundancy. Systems with high reliability requirements often use extensive redundancy. These highly redundant systems rarely fail unless all the redundant components providing a particular function fail. Complete failures of such highly redundant systems are then usually common cause failures. Common cause failures are prevalent in highly redundant, high reliability systems. Common cause failures dominate redundancy. Redundant systems may fail due to specification, design, manufacturing, operations, or maintenance problems that disable all the identical redundant systems. Common cause failures typically account for one tenth of all failures. If the failure probability is relatively low and common cause failures are significant, adding more than two or three redundant identical units usually gives little added reliability improvement. Common cause failures can be reduced by using diverse components with different technologies and manufacturers, by separating and shielding subsystems, and by avoiding shared control, power, or location. External events and shared vulnerabilities may still cause common cause failures.

common cause failures↗

Common Cause Failure Modeling in Space Launch Vehicles

Common Cause Failures (CCFs) are a known and documented phenomenon that defeats system redundancy. CCFs are a set of dependent type of failures that can be caused for example by system environments, manufacturing, transportation, storage, maintenance, and assembly. Since there are many factors that contribute to CCFs, they can be reduced, but are difficult to eliminate entirely. Furthermore, failure databases sometimes fail to differentiate between independent and dependent CCF. Because common cause failure data is limited in the aerospace industry, the Probabilistic Risk Assessment (PRA) Team at Bastion Technology Inc. is estimating CCF risk using generic data collected by the Nuclear Regulatory Commission (NRC). Consequently, common cause risk estimates based on this database, when applied to other industry applications, are highly uncertain. Therefore, it is important to account for a range of values for independent and CCF risk and to communicate the uncertainty to decision makers. There is an existing methodology for reducing CCF risk during design, which includes a checklist of 40+ factors grouped into eight categories. Using this checklist, an approach to produce a beta factor estimate is being investigated that quantitatively relates these factors. In this example, the checklist will be tailored to space launch vehicles, a quantitative approach will be described, and an example of the method will be presented.

Hark, Frank↗

Common Cause Failure Modeling: Aerospace Versus Nuclear

Aggregate nuclear plant failure data is used to produce generic common-cause factors that are specifically for use in the common-cause failure models of NUREG/CR-5485. Furthermore, the models presented in NUREG/CR-5485 are specifically designed to incorporate two significantly distinct assumptions about the methods of surveillance testing from whence this aggregate failure data came. What are the implications of using these NUREG generic factors to model the common-cause failures of aerospace systems? Herein, the implications of using the NUREG generic factors in the modeling of aerospace systems are investigated in detail and strong recommendations for modeling the common-cause failures of aerospace systems are given.

Stott, James E.↗

Modeling Common Cause Failures of Thrusters on ISS Visiting Vehicles

This paper discusses the methodology used to model common cause failures of thrusters on the International Space Station (ISS) Visiting Vehicles. The ISS Visiting Vehicles each have as many as 32 thrusters, whose redundancy makes them susceptible to common cause failures. The Global Alpha Model (as described in NUREG/CR‐5485) can be used to represent the system common cause contribution, but NUREG/CR‐5496 supplies global alpha parameters for groups only up to size six. Because of the large number of redundant thrusters on each vehicle, regression is used to determine parameter values for groups of size larger than six. An additional challenge is that Visiting Vehicle thruster failures must occur in specific combinations in order to fail the propulsion system; not all failure groups of a certain size are critical.

Haught, Megan↗

Modeling Common Cause Failures of Thrusters on ISS Visiting Vehicles

This paper discusses the methodology used to model common cause failures of thrusters on the International Space Station (ISS) Visiting Vehicles. The ISS Visiting Vehicles each have as many as 32 thrusters, whose redundancy and similar design make them susceptible to common cause failures. The Global Alpha Model (as described in NUREG/CR-5485) can be used to represent the system common cause contribution, but NUREG/CR-5496 supplies global alpha parameters for groups only up to size six. Because of the large number of redundant thrusters on each vehicle, regression is used to determine parameter values for groups of size larger than six. An additional challenge is that Visiting Vehicle thruster failures must occur in specific combinations in order to fail the propulsion system; not all failure groups of a certain size are critical.

Haught, Megan↗

Developing Component-Specific Prior Distributions for Common Cause Failure Alpha Factors

This report presents the development of component-specific common cause failure (CCF) prior distributions for five component categories: pump, valve, strainer, generator, and other. For ease in comparing these component-specific CCF priors with the 2015 generic CCF priors, the same method used to develop the 2015 generic CCF priors was also employed in this report, along with the same set of failure data (1997–2015) featured in INL/EXT-21-43723. For selected CCF templates, this report also evaluates the effects of applying component-specific priors to CCF parameters.

99 GENERAL AND MISCELLANEOUS↗

Common Cause Failure Analysis for Nuclear Power Plant Instrumentation and Control Systems

This presentation is prepared for the IAEA Virtual Consultancy Meeting on Preparation of a Coordinated Research Project on Common Cause Failures in Nuclear Power Plant Instrumentation and Control Systems from February 5 ? 8, 2024. It provides an overview of the INL activities on the common cause failure analysis for instrumentation and control system in nuclear power plants.

99 GENERAL AND MISCELLANEOUS↗

Common Cause Failure Modeling

Space Launch System (SLS) Agenda: Objective; Key Definitions; Calculating Common Cause; Examples; Defense against Common Cause; Impact of varied Common Cause Failure (CCF) and abortability; Response Surface for various CCF Beta; Takeaways.

Hark, Frank↗

Common Cause Failure Modes

High technology industries with high failure costs commonly use redundancy as a means to reduce risk. Redundant systems, whether similar or dissimilar, are susceptible to Common Cause Failures (CCF). CCF is not always considered in the design effort and, therefore, can be a major threat to success. There are several aspects to CCF which must be understood to perform an analysis which will find hidden issues that may negate redundancy. This paper will provide definition, types, a list of possible causes and some examples of CCF. Requirements and designs from NASA projects will be used in the paper as examples.

Wetherholt, Jon↗

Analyzing Hardware and Software Common Cause Failures in Digital Instrumentation and Control Systems using Dual Error Propagation Method

This paper develops a methodology for quantifying software common cause failures (CCFs) in digital instrumentation and control (I&C) systems of nuclear power plants. To support the transition of analog I&C systems to digital in nuclear power plants, probabilistic risk assessment (PRA) techniques are used. The hardware components of the I&C systems have reliability databases that can be used in the PRA studies. However, the failure data for redundant software components of the systems is sparse. Failure of components constitutes a CCF, wherein two or more components or systems fail due to a single shared cause and coupling mechanism. This paper proposes a quantification approach that can simultaneously model hardware and software components, incorporate the CCFs of software systems in the models, and bridge the gap between the failure quantification of models and the development of CCF parametric databases. We demonstrate the dual error propagation method (DEPM) by developing I&C systems failure models for a representative digital reactor trip system. The DEPM models are built to simulate the control and data flows within the systems and can accommodate failure states. By expanding DEPM to software CCFs, we generated alpha factor parameter estimates for each of the modeled error propagation mechanisms.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Common Cause Failure Evaluation of High Safety Significant Safety-related Digital Instrumentation and Control Systems using IRADIC Technology

Digital instrumentation and control (DI&C) systems in nuclear power plants (NPPs) have many advantages over analog systems but also pose different engineering and technical challenges, such as potential threats due to common cause failures (CCFs). This paper proposes an integrated risk assessment technology for DI&C systems (IRADIC) developed by Idaho National Laboratory for dealing with potential software CCFs in DI&C systems of NPPs. The methodology development of the IRADIC technology on the quantitative evaluation of software CCFs in high safety-significant safety-related DI&C systems in NPPs is illustrated in this paper. In IRADIC, qualitative hazard analysis and quantitative reliability and consequence analysis are successively implemented to obtain quantitative risk information, compare with respective risk evaluation acceptance criteria, and provide suggestions for risk reduction and design optimization. A comprehensive case study was also performed and documented in this paper. Results show that the IRADIC technology can effectively identify potential digital-based CCFs, estimate their failure probabilities, and evaluate their impacts to system and plant safety.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Quantitative evaluation of common cause failures in high safety-significant safety-related digital instrumentation and control systems in nuclear power plants

Digital instrumentation and control (DI&C) systems at nuclear power plants (NPPs) have many advantages over analog systems. They are proven to be more reliable, cheaper, and easier to maintain given obsolescence of analog components. However, they also pose new engineering and technical challenges, such as possibility of common cause failures (CCFs) unique to digital systems. Here this paper proposes a Platform for Risk Assessment of DI&C (PRADIC) that is developed by Idaho National Laboratory (INL). A methodology for evaluation of software CCFs in high safety-significant safety-related DI&C systems of NPPs was developed as part of the framework. The framework integrates three stages of a typical risk assessment—qualitative hazard analysis and quantitative reliability and consequence analyses. The quantified risks compared with respective acceptance criteria provide valuable insights for system architecture alternatives allowing design optimization in terms of risk reduction and cost savings. A comprehensive case study performed to demonstrate the framework's capabilities is documented here in this paper. Results show that the PRADIC is a powerful tool capable to identify potential digital-based CCFs, estimate their probabilities, and evaluate their impacts on system and plant safety.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Investigation of the Use of Dynamic Probabilistic Risk Assessment Methodologies for Identifying Digital I&C System Common Cause Failures

Digital Instrumentation and Control (I&C) systems have a key role in nuclear power plants in the upgrade of aging analog systems. Digital systems improve plant safety and reliability through features such as increased hardware reliability and stability and improved failure detection capability. There is no consensus on which of the current probabilistic risk assessment methods are most suitable for use in the reliability analysis of digital I&C systems. While the traditional event-tree/fault-tree (ET/FT) approach is still used for their reliability modeling, there are concerns regarding this approach in properly accounting for dynamic interactions among system components since potentially significant dependencies among failure events may not be identified and/or their likelihood may not be properly quantified. Dynamic methodologies are expected to provide a much more accurate representation of probabilistic evolution of the I&C systems in time due to their capability to more properly account for complex interactions than the static approach. The applicability of dynamic PRA methodologies for digital I&C system is investigated using the criteria presented in the NUREG/CR-6901, and the comparisons made in NUREG/CR-6901 are updated in light of the latest studies. The Dynamic Event Tree (DET) approach has been identified as one of the top dynamic methods when evaluated against the requirements for the reliability modeling of digital I&C systems. The DET method is a strong candidate for integration into existing PRA studies, as it bears many similarities to the traditional ET approach. In this study, the DET approach has been applied to the Plant Protection System of the APR1400 design, and the results are compared to results from its available traditional ET/FT analysis. Possible approaches to evaluate and quantify the effects of common cause failures on system safety using dynamic methods are also examined.

46 INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND ↗