Search NASA⌕ Search

SEARCH · Search NASA

Results for “Digital Main Control Room”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

Simulator Data Analysis to Inform Digitalized Environment Impacts on Human Reliability

The U.S. Nuclear Regulatory Commission (NRC) has developed a human reliability analysis (HRA) method, termed the Integrated Human Event Analysis System for Event and Condition Assessment (IDHEAS-ECA), in order to estimate human error probabilities (HEPs) in risk-informed regulatory applications. To update the quantification part of IDHEAS-ECA, the NRC required human performance and error data from fully digitalized main control rooms (MCRs); therefore, it requested that Idaho National Laboratory (INL) revisit previous data collection studies and investigate how the following three factors impact human reliability: self-checking, peer-checking, and automation. The HRA data collection studies revisited were the Human Reliability Data Extraction (HuREX) project, developed by the Korea Atomic Energy Research Institute (KAERI), and the Simplified Human Error Experimental Program (SHEEP), developed by INL. HuREX is a representative HRA data collection study that collects human reliability data from full-scope simulators staffed by licensed operators. SHEEP, on the other hand, has been proposed to complement such full-scope studies by collecting data via simplified simulators staffed by non-licensed student operators. In the HuREX study, KAERI collected HRA data from fully digitalized MCRs for the Advanced Power Reactor (APR)–1400. The SHEEP data were obtained from simplified simulators that partially mimicked the features of digitalized MCRs. The present report mainly discusses how the impacts of the aforementioned three factors on human errors were derived from these two data collection studies.

99 GENERAL AND MISCELLANEOUS↗

Advanced Human-System Interface Risk Analysis Based on Redundancy-guided Systems-theoretic Hazard Analysis and Human Reliability Analysis

Human-system interfaces (HSIs) play an important role in enabling operators to communicate with the nuclear power plant (NPP) side. Getting the information required to understand a NPP’s current status or perform necessary actions for responding to a given operational context are representative operator tasks performed using HSIs. To date, HSIs have been mainly evaluated in the context of human reliability analysis (HRA). However, the current HSI evaluation that occurs during HRA may be challengeable on two fronts: (1) reflecting the unique characteristics of HSI systems and (2) considering situations in which HSIs are poorly operated due to software/hardware malfunctions. Accordingly, this study proposes an approach for specifically evaluating HSIs for digital instrumentation and controls (DI&C) systems, using Redundancy-guided Systems-theoretic Hazard Analysis (RESHA) and HRA. RESHA is a method for analyzing DI&C systems with redundancy features. In this study, we investigate how HSIs are evaluated in existing HRA methods, and what challenges exist in the current approaches. To better evaluate HSIs for DI&C systems, this study modifies the existing HSI evaluation process by additionally modeling the HSI back- and front- ends. In this paper, a HSI fault tree for the APR1400 DI&C system is introduced through a piping and instrumentation diagram. It then touches upon what aspects of the suggested method must be further researched.

99 GENERAL AND MISCELLANEOUS↗

Human and Technology Integration Evaluation of Advanced Automation and Data Visualization

While the existing United States (U.S.) light water reactors are highly reliable, safe, and provide a significant proportion of carbon-free electricity, the cost of operating and maintaining them has become less competitive compared to other electricity generating sources. The reason for the gap in operating and maintenance (O&M) costs can be at least in part attributed to the advent of new digital technologies that other electricity generating industries are currently using. Advanced capabilities including digital instrumentation and control (I&C) systems, advanced automation and analytics, and greater span of data integration (i.e., connectedness) across these non-nuclear plants has transformed the way work is performed and ultimately given them a competitive advantage in terms of the cost required for operating, maintaining, and supporting them. To reduce O&M cost and address obsolescence of the aging I&C infrastructure of the existing U.S. light water reactors, the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program Plant Modernization Pathway is conducting targeting multidisciplinary research that 1) delivers a sustainable business model to enable a cost-competitive U.S. nuclear industry and 2) is developing technology modernization solutions that address aging and obsolescence challenges. The work described in this report supports these two objectives and describes the demonstration of human and technology integration across recent industry collaborations to support their large-scale digital I&C modifications. This technical report describes the demonstration of the human and technology integration methodology in performing full-scale performance-based human-in-the-loop tests to evaluate plant-specific advanced automation and data visualization applications within these collaborators’ digital modifications. This technical report also documents future applications of human and technology integration that expand beyond main control room modernization and digital I&C upgrades, which have been a central focus to date. Thus, this technical report discusses how to implement human and technology integration across new business opportunities and how to develop an evaluation plan that defines measures and criteria, and documents key assumptions to support full plant modernization.

99 GENERAL AND MISCELLANEOUS↗

3D Modeling of Safety-Related Upgrade Pilot Project

Constellation Energy and the United States Department of Energy (DOE) have established a public/private partnership to implement a pilot digital upgrade to replace legacy analog, safety-related reactor protection and emergency safety feature actuation systems (RPS/ESFAS) with modern digital systems. This effort is occurring at Constellation’s Limerick Generating Station. This project is being performed in accordance with industry processes that have been adapted to better support digital upgrades. These processes include IP-ENG-001, Standard Design Process, NISP-EN-04, Standard Digital Engineering Process and Electric Power Research Institute Report 3002011816, Digital Engineering Guide. The Light Water Reactor Sustainability (LWRS) Program at the Idaho National Laboratory (INL) has been supporting this effort. Latest INL HFE efforts in support of this project have focused on definition and implementation of the Human Factors Engineering (HFE) Program in support of Constellation design and related licensing efforts. This paper will present the development of the HFE 3D modeling execution of the Main Control Room safety upgrades. New equipment and modifications are planned for upgrading the new safety systems. 3D modeling allows for visualization of the new equipment and modifications to be shared with engineering and design teams for evaluation and review. Anthropometric considerations such as sight lines and functional reach can be evaluated directly using the 3D model. This effort has helped to provide visualizations for additional review with operations personnel and project stakeholders.

3D Modeling↗

Human Factors for Advanced Reactors

Existing light water reactors in the U.S. are primarily large baseload electricity generating facilities. The concept of operations for these plants remains largely unchanged since the advent of commercial nuclear power—the main control room serves as the hub of plant activities and is staffed with multiple licensed operators who work in tandem under the shift supervisor, and staff such as field workers support the control room remotely. While newer plants have brought the advent of digital human-machine interfaces to replace earlier analog and mechanical instrumentation and controls, much of the control process remains unchanged and manual. It is simply a newer version of legacy concepts. Advanced reactors potentially bring considerable changes to the size, fuel type, automation, and staffing of nuclear power plants, necessitating a fundamental shift not just from analog to digital, but further from human to automation, from onsite to remote, from control to monitoring, and from many to few operators. Despite this multitude of parallel evolutions in reactor designs, many of the vendors developing the next generation of reactors represent smaller research and development enterprises. It is therefore not feasible to address all aspects of plant design at the same time. In particular, the competing design aspects of new reactors present a significant challenge to the development of robust and human factored systems at the plant. As vendors develop new reactor designs, much of the early focus is naturally on the fuel and reactor system technology. Looming behind these early advances is the daunting prospect of first-of-a-kind control concepts that have not yet been developed or validated. A failure to address the human element of reactor design early will lead to missed opportunities. The quickest development process is the replication of existing concepts of operations at legacy plants, even when such systems were long ago surpassed by better human-machine technologies outside the nuclear industry. Conversely, attempting to undertake novel concepts of operations late in the design life cycle of a plant could result in protracted development efforts and delays in licensing and deployment. This does not have to happen, and it is imperative that human factors be considered now, early in the design of new reactors.

99 GENERAL AND MISCELLANEOUS↗

SEU/SET Tolerant Phase-Locked Loops

The phase-locked loop (PLL) is an old and widely used circuit for frequency and phase demodulation, carrier and clock recovery, and frequency synthesis [1]. Its implementations range from discrete components to fully integrated circuits and even to firmware or software. Often the PLL is a highly critical component of a system, as for example when it is used to derive the on-chip clock, but as of this writing no definitive single-event upset (SET)/single-event transient (SET) tolerant PLL circuit has been described. This chapter hopes to rectify that situation, at least in regard to PLLs that are used to generate clocks. Older literature on fault-tolerant PLLs deals with detection of a hard failure, which is recovered by replacement, repair, or manual restart of discrete component systems. Several patents exist along these lines (6349391, 6272647, and 7089442). A newer approach is to harden the parts of a PLL system, to one degree or another, such as by using a voltage-based charge pump or a triple modular redundant (TMR) voted voltage-controlled oscillator (VCO). A more comprehensive approach is to harden by triplication and voting (TMR) all the digital pieces (primarily the divider) of a frequency synthesis PLL, but this still leaves room for errors in the VCO and the loop filter. Instead of hardening or voting pieces of a system, such as a frequency synthesis system (i.e., clock multiplier), we will show how the entire system can be voted. There are two main ways of doing this, each with advantages and drawbacks. We will show how each has advantages in certain areas, depending on the lock acquisition and tracking characteristics of the PLL. Because of this dependency on PLL characteristics, we will briefly revisit the theory of PLLs. But first we will describe the characteristics of voters and their correct application, as some literature does not follow the voting procedure that guarantees elimination of errors. Additionally, we will find that voting clocks is a bit trickier than voting data where an infallible clock is assumed. It is our job here to produce (or recover) that assumed infallible clock!

Shuler, Robert L., Jr.↗

Integrated Operations for Nuclear: Work Reduction Opportunity Demonstration Strategy

EXECUTIVE SUMMARY The Light Water Reactor Sustainability Program Plant Modernization Pathway has been working with industry for a number of years to leverage digital technology to extend the life and improve the performance of the existing fleet through modernized technologies and improved processes for plant operation and power generation. This includes development of modernization solutions to improve reliability and economic performance while addressing US nuclear industry’s aging and obsolescence challenges. The objective of these efforts is to deliver a sustainable business model that enables US nuclear industry to remain competitive. Digital Infrastructure (DI) research has established a technical foundation for these efforts. This effort began with technical analysis and support for a safety-related instrumentation and control (I&C) pilot upgrade being performed at Constellation Energy Generation’s Limerick Nuclear Plant. The following publicly available reports were produced as part of this effort. • INL/EXT-20-61079, Vendor-Independent Design Requirements for a Boiling Water Reactor Safety System Upgrade [1] • INL/EXT-20-59371, Business Case Analysis for Digital Safety-Related Instrumentation & Control System Modernizations [2] • INL/EXT-20-59809, “Safety-Related Instrumentation and Control Pilot Upgrade: Initial Scoping Phase Implementation Report and Lessons Learned [3] • INL/RPT-23-72105, Safety-Related Instrumentation and Control Upgrade: Conceptual – Detailed Design Phase Report and Lessons Learned [4]

99 GENERAL AND MISCELLANEOUS↗

Short Circuiting the Controller – Missteps in Maintenance and Inspection of Process and Wiring in STS-93

The primary objective of the Space Transportation System mission 93 (STS-93) was to deploy the Chandra X-Ray Observatory. Chandra, the world's most powerful X-Ray telescope, allowed scientists from around the world to study some of the most distant and dynamic objects in the universe. Stripped of nearly 7,000 pounds of its own gear to make room for the payload, the orbiter assigned to this mission was Space Shuttle Columbia. Prior to STS-93, Columbia had flown 25 flights and was NASA's oldest and heaviest orbiter. On July 23, 1999, after two prior launch scrubs, Eileen Collins and her crew of four launched from Kennedy Space Center. About five seconds after launch, Mission Control at Johnson Space Center detected a voltage drop on one of Columbia's electrical buses. As a result of this power fluctuation, a primary and back-up Main Engine controller dropped offline. Given design redundancy, the two remaining controllers supported all three engines. If there had been any other AC bus issues, one engine of the three on the Orbiter would have shut down. The redundant set of digital computer units in each engine controller saved Columbia and her crew from a very risky contingency abort. Post-flight inspection revealed soot on a screw head and a hole in an adjacent Kapton insulated wire. The single strand of polyimide wire was located nearly half-way down the payload bay. The Shuttle Independent Assessment Team (SIAT) reported that the wire had rubbed and chaffed against a burred screw head. The burr was later determined to be the result of overtightening of the screw by a technician during a maintenance refurbishment. Alone, the burr may not have been problematic, but later, during another ground processing event, possibly years after, someone inadvertently stepped on the wiring harness. With the pressure and motion of unintended contact, some of the Kapton insulation rubbed off against the burred screw head. The SIAT suspected the wire damage was pre-existing and was caused 4 or 5 years prior to the flight. Finally, the intense vibrations during the launch sequence allowed contact between the exposed conductor and exposed metal area on the burred screw head, resulting in the arcing and shorting of the wire. Due to the quick turnaround times of Space Shuttle Orbiters, wiring issues caused from multiple maintenance events were often overlooked. Additionally, failing to incorporate thorough and early inclusion of human systems integration (HSI) applications as a crucial part of the decision process can result in these types of misshaps. In order to reduce human error associated with integrated manufacturing, maintenance, refurbishment and flight preparations, wire inspection criteria should be refined and standardized, visual inspection processes should be quantified, and technicians should be certified by specially trained instructors. This case, among many others, unveils why human error management and development of safety metrics is a vital piece in the development of complex systems, and why it should be supported aggressively and implemented program wide.

Human Systems Integration↗

Electronics for Low-Temperature Space Operation Being Evaluated

Electronic components and systems capable of low-temperature operation are needed for many future NASA missions where it is desirable to have smaller, lighter, and cheaper (unheated) spacecraft. These missions include Mars (-20 to -120 C) orbiters, landers, and rovers; Europa (-150 C) oceanic exploratory probes and instrumentation; Saturn (-183 C) and Pluto (-229 C) interplanetary probes. At the present, most electronic equipment can operate down to only -55 C. It would be very desirable to have electronic components that expand the operating temperature range down to -233 C. The successful development of these low-temperature components will eventually allow space probes and onboard electronics to operate in very cold environments (out as far as the planet Pluto). As a result, radioisotope heating units, which are used presently to keep space electronics near room temperature, will be reduced in number or eliminated. The new cold electronics will make spacecraft design and operation simpler, more flexible, more reliable, lighter, and cheaper. Researchers at the NASA Glenn Research Center are evaluating potential commercial off-the- shelf devices and are developing new electronic components that will tolerate operation at low temperatures down to -233 C. This work is being carried out mainly inhouse and also through university grants and commercial contracts. The components include analog-to-digital converters, semiconductor switches, capacitors, dielectric and packaging material, and batteries. For example, the effect of low temperature on the capacitance of three different types of capacitors is shown in the graph. Using these advanced components, system products will be developed, including dc/dc converters, battery charge/discharge management systems, digital control electronics, transducers, and sensor instrumentation.

Patterson, Richard L.↗

Light Water Sustainability Program: Optimizing Information Automation Using a New Method Based on System-Theoretic Process Analysis

This report describes the interim progress for research supporting the design and optimization of information automation systems for nuclear power plants. Much of the domestic nuclear fleet is currently focused on modernizing technologies and processes, including transitioning toward digitalization in the control room and elsewhere throughout the plant, along with a greater use of automation, artificial intelligence, robotics, and other emerging technologies. While there are significant opportunities to apply these technologies toward greater plant safety, efficiency, and overall cost-effectiveness, optimizing their design and avoiding potential safety and performance risks depends on ensuring that human-performance-related organizational and technical design issues are identified and addressed. This report describes modeling tools and techniques, based on sociotechnical system theory, to support these design goals and their application in the current research effort. The report is intended for senior nuclear energy stakeholders, including regulators, corporate management, and senior plant management. We have developed and employed a method to design an optimized information automation ecosystem (IAE) based on the systems-theoretic constructs underlying sociotechnical systems theory in general and the Systems-Theoretic Accident Modeling and Processes (STAMP) approach in particular. We argue that an IAE can be modeled as an interactive information control system whose behavior can be understood in terms of dynamic control and feedback relationships amongst the system’s technical and organizational components. Up to this point, we have employed a Causal Analysis based on STAMP (CAST) technique to examine a performance- and safety-related incident at an industry partner’s plant that involved the unintentional activation of an emergency diesel generator. This analysis provided insight into the behavior of the plant’s current information control structure within the context of a specific, significant event. Our ongoing analysis is focused on identifying near-term process improvements and longer-term design requirements for an optimized IAE system. The latter analyses will employ a second STAMP-derived technique, System-Theoretic Process Analysis (STPA). STPA is a useful modeling tool for generating and analyzing actual or potential information control structures. Finally, we have begun modeling plantwide organizational relationships and processes. Organizational system modeling will supplement our CAST and STPA findings and provide a basis for mapping out a plantwide information control architecture. CAST analysis findings indicate an important underlying contributor to the incident under investigation, and a significant risk to information automation system performance, was perceived schedule pressure, which exposed weaknesses in interdepartmental coordination between and within responsible plant organizations and challenged the resilience of established plant processes, until a human caused the initiating event. These findings are discussed in terms of their risk to overall system performance and their implications for information automation system resilience and brittleness. We present two preliminary information automation models. The proactive issue resolution model is a test case of an information automation concept with significant near-term potential for application and subsequent reduction in significant plant events. The IAE model is a more general representation of a broader, plantwide information automation system. From our results, we have generated a set of preliminary system-level requirements and safety constraints. These requirements will be further developed over the remainder of our project in collaboration with nuclear industry subject matter experts and specialists in the technical systems under consideration. Additionally, we will continue to pursue the system analyses initiated in the first part of our effort, with a particular emphasis on STPA as the main tool to identify weak or weakening control structures that affect the resilience of organizations and programs. Our intent is to broaden the scope of the analysis from an individual use case to a related set of use cases (e.g., maintenance tasks, compliance tasks) with similar human-system performance challenges. This will enable more generalized findings to refine the Proactive Issue Resolution and IAE models, as well as their system-level requirements and safety constraints. We will use organizational system modeling analyses to supplement STPA findings and model development. We conclude the report with a set of summary recommendations and an initial draft list of system-level requirements and safety constraints for optimized information automation systems.

99 GENERAL AND MISCELLANEOUS↗