Search NASA⌕ Search

SEARCH · Search NASA

Results for “Reactor Protection System”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

97 MATHEMATICS AND COMPUTING↗

Field Programmable Gate Array-Based Reactor Protection Systems and Potential for Inclusion of Secure Elements to Improve Cybersecurity

For acceptable implementations of technologies like wireless communications, remote monitoring, etc., strong mitigations must be developed and evaluated to ensure that new attack pathways do not increase risk for Advanced Reactors. Secure Elements can be adopted and adapted for this purpose based on tamper resistance and cryptographic abilities, but research must be done to properly integrate into critical components such as FPGA-based Important to Safety systems in conjunction with current and future regulations on cyber security features in Advanced Reactors. Typically, the integration of a Secure Element happens during the POST and UEFI boot of a computing platform, performed by the Operating System, which is not possible with FPGAs because they do not include these firmware components. Work must be done to identify a reliable and secure method for integration in FPGA-based systems which lack Operating Systems and therefore complex boot procedures, system calls, etc.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Uncertainty Propagation from Experiment Measurements to Modeling Approaches: A Case for SMR Steam Entrainment Testing

To license new and advanced reactor designs, regulators must be convinced that their unique safety cases—relative to existing large scale reactors—have been adequately addressed by the designed reactor protection systems. In water cooled small modular reactors (SMRs), droplet entrainment in steam flow has significant implications on the progression of accident scenarios due to its compact design features, which requires representative test data applicable to SMR designs. Computer code, modeling and simulation (M&S) tools and models require adequate verification, assessment, and qualification. This includes M&S results validation against scaled empirical data within allowable uncertainty bands to gain regulatory approvals during the various stages of reactor system design, demonstration, and commercialization. However, measurement uncertainty within the empirical datasets and test data applicability ranges requires careful consideration of M&S inputs (i.e., boundary conditions, and initial conditions), and verification and validation efforts. This study focuses on uncertainty quantification in designing scaled test facilities for SMR applications with appropriate measurements and a standard data-reduction method to estimate thermal hydraulics characteristics parameters that incorporate physics phenomena of interest. In addition, this study supports the evaluation model development and assessment process using M&S that interfaces with advanced computing tools and digital twin capabilities. This will allow synchronization between experiment and modeling approaches for droplet entrainment testing and analysis, improving diagnostics, prognostics, and decision-making to accelerate regulatory approval.

21 SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLANTS↗

MARVEL Instrumentation, Control, and Software Considerations

This paper details the various I&C considerations and design decisions made throughout the MARVEL (Micro-reactor Applications Research Validation and Evaluation) project, including sensor and actuator selection, safety-related functionality, digital control hardware and software, and testing methodologies. Key challenges such as managing radiation, temperature, and space constraints are discussed, along with the trade-offs between using standard equipment and custom solutions. The successful integration of off-the-shelf components, the emphasis on minimizing safety-related instrumentation, and the lessons learned from prototyping and testing are highlighted. The authors aim to provide insights that can benefit future micro-reactor designs and emphasize the importance of real-world testing in advancing reactor technology.

46 - INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AN↗

SPC-70783 Rev 0 Seismic Detector and Switch Survey and Verification Specification

A. Idaho National Laboratory (INL) is developing a microreactor to produce electrical power utilizing a small nuclear core and Stirling engines under the Microreactor Application Research Validation and Evaluation (MARVEL) program. The MARVEL microreactor Reactor Protection System (RPS) will have a seismic trip function. The selected part for this design is ETNA2 manufactured by Kinemetrics, Inc. B. Acceptance of the items delivered under this scope of work can be performed through a direct evaluation of the supplier’s controls and a factory acceptance test.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

Autonomous Control of Space Nuclear Reactors

Nuclear reactors to support future robotic and manned missions impose new and innovative technological requirements for their control and protection instrumentation. Long-duration surface missions necessitate reliable autonomous operation, and manned missions impose added requirements for failsafe reactor protection. There is a need for an advanced instrumentation and control system for space-nuclear reactors that addresses both aspects of autonomous operation and safety. The Reactor Instrumentation and Control System (RICS) consists of two functionally independent systems: the Reactor Protection System (RPS) and the Supervision and Control System (SCS). Through these two systems, the RICS both supervises and controls a nuclear reactor during normal operational states, as well as monitors the operation of the reactor and, upon sensing a system anomaly, automatically takes the appropriate actions to prevent an unsafe or potentially unsafe condition from occurring. The RPS encompasses all electrical and mechanical devices and circuitry, from sensors to actuation device output terminals. The SCS contains a comprehensive data acquisition system to measure continuously different groups of variables consisting of primary measurement elements, transmitters, or conditioning modules. These reactor control variables can be categorized into two groups: those directly related to the behavior of the core (known as nuclear variables) and those related to secondary systems (known as process variables). Reliable closed-loop reactor control is achieved by processing the acquired variables and actuating the appropriate device drivers to maintain the reactor in a safe operating state. The SCS must prevent a deviation from the reactor nominal conditions by managing limitation functions in order to avoid RPS actions. The RICS has four identical redundancies that comply with physical separation, electrical isolation, and functional independence. This architecture complies with the safety requirements of a nuclear reactor and provides high availability to the host system. The RICS is intended to interface with a host computer (the computer of the spacecraft where the reactor is mounted). The RICS leverages the safety features inherent in Earth-based reactors and also integrates the wide range neutron detector (WRND). A neutron detector provides the input that allows the RICS to do its job. The RICS is based on proven technology currently in use at a nuclear research facility. In its most basic form, the RICS is a ruggedized, compact data-acquisition and control system that could be adapted to support a wide variety of harsh environments. As such, the RICS could be a useful instrument outside the scope of a nuclear reactor, including military applications where failsafe data acquisition and control is required with stringent size, weight, and power constraints.

Merk, John↗

Integrated Operations for Nuclear: Work Reduction Opportunity Demonstration Strategy

EXECUTIVE SUMMARY The Light Water Reactor Sustainability Program Plant Modernization Pathway has been working with industry for a number of years to leverage digital technology to extend the life and improve the performance of the existing fleet through modernized technologies and improved processes for plant operation and power generation. This includes development of modernization solutions to improve reliability and economic performance while addressing US nuclear industry’s aging and obsolescence challenges. The objective of these efforts is to deliver a sustainable business model that enables US nuclear industry to remain competitive. Digital Infrastructure (DI) research has established a technical foundation for these efforts. This effort began with technical analysis and support for a safety-related instrumentation and control (I&C) pilot upgrade being performed at Constellation Energy Generation’s Limerick Nuclear Plant. The following publicly available reports were produced as part of this effort. • INL/EXT-20-61079, Vendor-Independent Design Requirements for a Boiling Water Reactor Safety System Upgrade [1] • INL/EXT-20-59371, Business Case Analysis for Digital Safety-Related Instrumentation & Control System Modernizations [2] • INL/EXT-20-59809, “Safety-Related Instrumentation and Control Pilot Upgrade: Initial Scoping Phase Implementation Report and Lessons Learned [3] • INL/RPT-23-72105, Safety-Related Instrumentation and Control Upgrade: Conceptual – Detailed Design Phase Report and Lessons Learned [4]

99 GENERAL AND MISCELLANEOUS↗

The SAS4A/SASSYS-1 Version 5.8 Safety Analysis Code System

SAS4A/SASSYS-1 is a software simulation tool used to perform deterministic analysis of anticipated events as well as design basis and beyond design basis accidents for advanced nuclear reactors. Detailed, mechanistic models of steady-state and transient thermal, hydraulic, kinetic, and mechanical phenomena are employed to describe the response of the reactor core, the reactor primary and secondary coolant loops, the reactor control and protection systems, and the balance-of-plant to accidents caused by changes in coolant flow, loss of heat rejection, or reactivity insertion. The consequences of single and double-fault accidents can be modeled, including fuel and coolant heating, fuel and cladding mechanical behavior, core reactivity feedbacks, coolant loop performance including natural circulation, and decay heat removal. Analyses are typically terminated upon demonstration of reactor and plant shutdown to permanently coolable conditions, or upon violation of design basis margins. The objective of the analysis is to quantify accident consequences as measured by the transient behavior of system performance parameters, such as fuel and cladding temperatures, reactivity, and cladding strain. Originally developed for analysis of sodium cooled reactors with oxide fuel clad by stainless steel, the models were subsequently extended and specialized to metallic fuel clad with advanced alloys and to several other coolant options, including lead, LBE, and water.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

List of Commercial and Advanced Developmental Niobium-Based Alloys of the Space Age

This report compiles a list of commercial and developmental niobium-based alloys developed during the Space Age (late 1950s through mid-1970s) for extreme-temperature applications, including rocket engine thrust chambers, hypersonic re-entry thermal protection systems, and space fission reactor loops. Niobium (Nb) was widely pursued because it provided the lowest density (~8.6 g/cc) among the primary refractory metals, a high melting temperature (~2470°C), exceptional low-temperature ductility, good formability, and compatibility with liquid alkali metals. An evaluation of physical metallurgy mechanisms, focusing on solid-solution strengthening via heavy refractory solutes (W, Mo, Ta), dual-purpose reactive solutes (Hf, Zr, Ti), and dispersion strengthening using carbides, nitrides, and oxides is presented. Additionally, the report compares Western and Soviet Union metallurgical approaches, explaining how supply chain factors and manufacturing infrastructure influenced element selection, interstitial chemistry, and alloy identification/naming conventions. Cataloging these historical alloy chemical compositions serves as a foundational reference for modern alloy additive manufacturing, thermodynamic CALPHAD modeling, and machine-learning discovery pipelines for next-generation extreme-environment niobium-based alloys.

Physical Metallurgy↗

Performance Analysis and Simulaion of the Hydraulic Scram System in TREAT Reactor

The Transient Reactor Test Facility (TREAT) at Idaho National Laboratory (INL) serves a vital role in nuclear fuel safety research, enabling transient experiments that simulate reactivity excursions and accident scenarios. Central to these operations is the transient control rod drive system (TCRDS), which drives rapid motion of the transient control rods such that TREAT can simulate rapid power changes typical of reactor accidents. The reliability and performance of this system are critical for protecting both fuel specimens and reactor infrastructure. This study presents the initial phase of a two-year investigation into the dynamics and reliability of the TREAT hydraulic TCRDS. Conducted in collaboration with INL, the research employs a combined computational and experimental approach to analyze the system's response time, pressure transients, and potential failure modes. Emphasis is placed on understanding how fluid characteristics influence the TCRDS’s ability to achieve both rapid power changes and mechanical stability. The TRDS and the skid that powers it will be analyzed throughout this investigation. Computational modeling using computational fluid dynamics (CFD) will simulate the hydraulic response under varying conditions. In parallel, experimental testing planned at INL will validate these models and capture key performance metrics. This paper outlines the system design, analytical framework, and modeling strategies that form the foundation for later testing. Ultimately, this work aims to support improvements to the TCRDS’s design and reliability, contributing to the broader goal of enhancing nuclear fuel safety and sustaining TREAT’s mission as a premier nuclear fuel test facility.

21 - SPECIFIC NUCLEAR REACTORS AND ASSOCIATED PLAN↗

SP-100 control system modeling

SP-100 Control Systems modeling was done using a thermal hydraulic transient analysis model called ARIES-S. The ARIES-S Computer Simulation provides a basis for design, integration and analysis of the reactor including the control and protection systems. It is a modular digital computer simulation written in FORTRAN that operates interactively in real time on a VAX minicomputer.

Meyer, R. A.↗

Fault tree applications within the safety program of Idaho Nuclear Corporation

Computerized fault tree analyses are used to obtain both qualitative and quantitative information about the safety and reliability of an electrical control system that shuts the reactor down when certain safety criteria are exceeded, in the design of a nuclear plant protection system, and in an investigation of a backup emergency system for reactor shutdown. The fault tree yields the modes by which the system failure or accident will occur, the most critical failure or accident causing areas, detailed failure probabilities, and the response of safety or reliability to design modifications and maintenance schemes.

W. E. Vesely↗

Reassessing Double-Ended Guillotine Break Requirements: Evidence-Based Analysis of Regulatory Assumptions After Five Decades of Nuclear Operation

After five decades of nuclear power operation encompassing more than 20,000 reactor-years across 35 countries and 647 reactors, zero double-ended guillotine breaks (DEGBs) have been documented in commercial reactor coolant systems—despite DEGB being the fundamental design-basis assumption driving Emergency Core Cooling System (ECCS) sizing, structural protection requirements, and containment design specifications. This report examines the basis for DEGB requirements in nuclear power plant design. The DEGB postulate assumes the instantaneous, complete circumferential severance of the largest diameter pipes in reactor coolant systems, driving major design requirements under 10 Code of Federal Regulations 50.46, General Design Criterion 4 and containment design specifications. The United States (4,880 reactor-years) and France (2,505 reactor-years) contribute the largest operational datasets. Probabilistic assessments estimate direct DEGB occurrence probabilities with extremely low event frequencies, far below the 10-5/reactor-year thresholds typically used to define non-credible events in nuclear-safety analyses; i.e., events with probability this low fall into beyond-design-basis events. Current material-science knowledge demonstrates that the ductile steel materials used in nuclear piping systems exhibit stable crack-growth behavior fundamentally incompatible with instantaneous severance. International regulatory experience, particularly Germany’s comprehensive break-preclusion implementation, and successful leak-before-break (LBB) applications in almost all of U.S. pressurized water reactor units validate that alternatives can maintain safety performance while reducing economic burden. Current DEGB protection systems impose estimated lifetime costs of hundreds of millions of dollars per unit, over the life of a plant across the nuclear industry (including ongoing costs), representing substantial resource allocation toward scenarios with extremely low probability. Although this report acknowledges uncertainties regarding long-term aging effects, potential synergistic degradation mechanisms, and site-specific seismic considerations that warrant continued evaluation as regulatory policy evolves, there remains no documented evidence that a DEGB has occurred as a consequence of the conditions or mechanisms described in this report. This report acknowledges the Nuclear Regulatory Commission’s (NRC’s) recent efforts—outlined in the draft Interim Staff Guidance (ISG) NRC-DSS-ISG-2025-XX (“Treatment of Certain Loss-of-Coolant Accident Locations as Beyond-Design-Basis Accidents Draft Interim Staff Guidance”)—to reduce overly conservative requirements for large-break loss of coolant accidents through technical justifications and exemptions. However, extensive operating experience and validated methodologies—such as LBB and in-service inspection programs—demonstrate that the probability of a DEGB in reactor coolant-loop piping is extremely low, even under seismic conditions. The authors and reviewers of this report recommend that DEGB be removed as a design-basis event through formal rulemaking, rather than case-by-case exemptions, to better reflect credible failure modes, align with current data, and align with modern, risk-informed safety analysis.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Advanced refractory metals and composites for extraterrestrial power systems

Concepts for future space power systems include nuclear and focused solar heat sources coupled to static and dynamic power-conversion devices; such systems must be designed for service lives as long as 30 years, despite service temperatures of the order of 1600 K. Materials are a critical technology-development factor in such aspects of these systems as reactor fuel containment, environmental protection, power management, and thermal management. Attention is given to the prospective performance of such refractory metals as Nb, W, and Mo alloys, W fiber-reinforced Nb-matrix composites, and HfC precipitate-strengthened W-Re alloys.

Titran, R. H.↗

Lunar Surface Reactor Shielding Study

Nuclear reactor system could provide power to support a long term human exploration to the moon. Such a system would require shielding to protect astronauts from its emitted radiations. Shielding studies have been performed for a Gas Cooled Reactor (GCR) system because it is considered to be the most suitable nuclear reactor system available for lunar exploration, based on its tolerance of oxidizing lunar regolith and its good conversion efficiency (Wright, 2003). The goals of the shielding studies were to provide optimal material shielding configuration that reduces the dose (rem) to the required level in order to protect astronauts, and to estimate the mass of regolith that would provide an equivalent protective effect if it were used as the shielding material. All calculations were performed using MCNPX code, a Monte Carlo transport code.

Monte Carlo N-Particle eXtended (MCNPX)↗

Nuclear Safety [Vol. 30, No. 3, July-September 1989]

Nuclear Safety is a review journal that covers significant developments in the field of nuclear safety. Its scope includes the analysis and control of hazards associated with nuclear energy, operations involving fissionable materials, and the products of nuclear fission and their effects on the environment. Primary emphasis is on safety in reactor design, construction, and operation; however, the safety aspects of the entire fuel cycle, including fuel fabrication, spent-fuel processing, nuclear waste disposal, handling of radioisotopes, and environmental effects of these operations, are also treated. Table of Contents for this issue follows. GENERAL SAFETY CONSIDERATIONS: 325 Safety of Framatome Advanced Nuclear Steam Supply Systems Designs by J. A. Charles and D. Lange, 333 Book Review of Nuclear Accidents: Intervention Levels for the Protection of the Public by H. B. Piper; ACCIDENT ANALYSIS: 335 Living PRA Computer Systems by S. C. Dinsmore and H.-P. Balfanz, 343 Summary of ICAP Assessments of RELAP5/MOD2 by W. E. Driskell and R. G. Hanson; CONTROL AND INSTRUMENTATION: 352 Thermal Performance Monitoring System at Maanshan Nuclear Power Plant by H.-J. Chao, Y.-P. Lin, G.-H. Jou, L.-Y. Liao, and Y.-B. Chen; DESIGN FEATURES: 358 Warning Systems for Nuclear Power Plant Emergencies by J. H. Sorensen and D. S. Mileti; WASTE AND SPENT FUEL MANAGEMENT: 371 Activities Related to Waste Management Compiled by E G. Silver; OPERATING EXPERIENCES: 382 Steam Generator Tube Performance: Experience with Water-Cooled Nuclear Power Reactors During 1985 by O. S. Tatone and R. L. Tapping, 400 Systems Interaction Analyses: Concepts and Techniques (Part II) by M. D. Muhlheim and G. A. Murphy, 413 Reactor Shutdown Experience Compiled by J. W. Cletcher, 416 Operating U.S. Power Reactors Compiled by E G. Silver; RECENT DEVELOPMENTS: 440 General Administrative Activities Compiled by E G. Silver, 460 Reports, Standards, and Safety Guides by D. S. Queener, 466 Status of Power-Reactor Licensing Activities Compiled by E G. Silver, 470 Proposed Rule Changes as of Mar. 31, 1989; ANNOUNCEMENTS: 334 Proceedings Published, 351 CEC Seminar on Methods and Codes for Assessing the Off-Site Consequences of Nuclear Accidents, 357 Short Course on Multiphase Flow and Heat Transfer: Bases and Applications in A: The Nuclear Power Industry B: The Process Industries, 357 International Conference on Probabilistic Safety Assessment and Management, 478 International Topical Meeting on the Safety, Status, and Future of Non-Commercial Reactors and Irradiation Facilities, 475 The Authors.

11 NUCLEAR FUEL CYCLE AND FUEL MATERIALS↗

Solving the Pulsed-Power Driven Inertial Fusion Energy Standoff Problem (Abbreviated Final Report)

The standoff problem in pulsed-power driven IFE (Inertial Fusion Energy) refers to the problem of electrically connecting a fusion target with the driver in a way that preserves the driver/target interface in the presence of a large fusion energy release (100’s of megajoules to 1000 megajoules). High yield fusion drivers for stockpile stewardship applications have similar concerns, but without the complication of the high repetition rate needed for energy production. All proposed IFE or high yield systems have the challenge of protecting the reactor vessel and driver from the energy release, but pulsed power drivers have the additional challenge of establishing an electrical connection in a way that does not create excessive debris or require costly/massive structures that must be expendable. Fortunately, there are conceptual solutions in the form of very low mass transmission lines, usually in the form of wires or foils, since very little mass is needed to overcome the magnetic forces driving the transmission lines apart or provide a low resistance pathway given the short pulse duration of the driver. Several important aspects of the standoff problem were analyzed in the course of this LDRD project. Conceptual means of introducing the low mass transmission lines into the reactor chamber were proposed, including analysis of methods to retain the power flow gap between the electrodes in the presence of the chamber environment. The energy losses due to ohmic dissipation and magnetic acceleration of the low mass transmission lines were evaluated for candidate driver pulses and different transmission line masses, and the fluence of x-ray and neutron energy on the persistent power flow structures that must survive the pulse of energy were evaluated. Finally, means of rapidly pumping down the chamber were explored as a way to return the system to low pressure following the multi-atmosphere post-pulse pressure rise. The overall conclusion from the analysis is that, while the reactor environment creates stressful conditions for a low mass transmission line standoff system, there are concepts expending 10 kg or less of electrode mass each pulse with the potential to mitigate the stresses and successfully drive fusion targets. Whether such a system could lead to a practical and economical fusion reactor would require extensive research and development beyond the scope of the feasibility study.

70 PLASMA PHYSICS AND FUSION TECHNOLOGY↗