Search NASA⌕ Search

SEARCH · Search NASA

Results for “security margin”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 19 records

Deep Learning-Based Adaptive Remedial Action Scheme with Security Margin for Renewable-Dominated Power Grids

The Remedial Action Scheme (RAS) is designed to take corrective actions after detecting predetermined conditions to maintain system transient stability in large interconnected power grids. However, since RAS is usually designed based on a few selected typical operating conditions, it is not optimal in operating conditions that are not considered in the offline design, especially under frequently and dramatically varying operating conditions due to the increasing integration of intermittent renewables. The deep learning-based RAS is proposed to enhance the adaptivity of RAS to varying operating conditions. During the training, a customized loss function is developed to penalize the negative loss and suggest corrective actions with a security margin to avoid triggering under-frequency and over-frequency relays. Simulation results of the reduced United States Western Interconnection system model demonstrate that the proposed deep learning–based RAS can provide optimal corrective actions for unseen operating conditions while maintaining a sufficient security margin.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Machine Learning Solutions for a Stable Grid Recovery

Grid operating security studies are typically employed to establish operating boundaries, ensuring secure and stable operation for a range of operation under NERC guidelines. However, if these boundaries are severely violated, existing system security margins will be largely unknown, as would be a secure incremental dispatch path to higher security margins while continuing to serve load. As an alternative to the use of complex optimizations over dynamic conditions, this work employs the use of machine learning to identify a sequence of secure state transitions which place the grid in a higher degree of operating security with greater static and dynamic stability margins. Several reinforcement learning solution methods were developed using deep learning neural networks, including Deep Q-learning, Mu-Zero, and the continuous algorithms Proximal Reinforcement Learning, and Advantage Actor Critic Learning. The work is demonstrated on a power grid with three control dimensions but can be scaled in size and dimensionality, which is the subject of ongoing research.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Validating a Dynamic PWR Safety and Security Model?

Nuclear power plants (NPPs) are assessed for safety and security using separate models that cannot capture how an attacker's decisions and a plant's response unfold together in real time, leaving regulators and operators without a complete picture of true plant vulnerability. Traditional probabilistic risk assessment (PRA) methods treat adversarial events as fixed initiators with predetermined outcomes, and are structurally incapable of representing the time-dependent interplay between physical security events, safety system response, and operator mitigative actions. At Idaho National Laboratory (INL), I contributed to the development and validation of Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF). Where static PRA relies on event-tree logic that cannot evolve mid-scenario, MASS-DEF couples a time-dependent dynamic PRA tool EMRALD (Event Modeling Risk Assessment using Linked Diagrams) with attack simulation software, allowing attacker behavior, plant system states, and operator actions to interact across time. My work focused on validating a general Pressurized Water Reactor (PWR) model. I traced model logic against PWR plant to identified errors in logic and confirm accuracy. I then built and tested attack scenarios against a general PWR model to verify that the model produced expected outcomes across all logical pathways. I also contributed a section to a related technical paper applying the same EMRALD platform to radiation dose modeling. Results show that MASS-DEF can quantitatively demonstrate that many plants exceed their regulatory security thresholds. This demonstrated margin provides a technically defensible basis for reducing the number of guards without compromising regulatory compliance. Physical security costs represent roughly 10% of annual operating budgets, making such reductions directly meaningful to INL's mission of sustaining existing commercial NPPs. This internship strengthened my understanding of nuclear systems, probabilistic modeling, and technical writing, and has solidified my pursuit of a career at a national laboratory.

98 - NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL↗

Robust Distribution State Estimation for Reliable Locational Marginal Pricing under Cyber-Attacks

Here this paper examines the impact of false data injection (FDI) cyber-attacks on distribution system state estimation (DSSE) and the resulting distribution locational marginal price (DLMP) in power markets. Two robust high-breakdown regression estimators, namely S- and MM- estimators, are implemented to provide resistance against FDI attacks targeting measurements and grid topology, creating leverage points. The introduced estimators are compared to the weighted least squares (WLS) with a bad data detection and rejection module (BDD) and the robust Huber M-estimator. The proposed estimators are shown to be effective and compare favorably to both existing Huber M- and the WLS with BDD in the presence of topology FDI attacks. Both the S- and MM-estimators provide good performance in the case of clean and corrupted measurements. Their performance is comparable in this case to the Huber M- and the WLS, followed by a BDD module. The simulation considered a modified distribution IEEE 13 and 34-bus systems where the impact of FDI attack scenarios is shown on the state and the DLMP pricing in the presence of distributed Generation.

24 POWER TRANSMISSION AND DISTRIBUTION↗

Load Margin Constrained Moving Target Defense against False Data Injection Attacks

Cyber physical security of power systems with high penetration of renewable generation has attracted attention from researchers. One critical issue is that cyber-physical attacks, disguised as uncertain renewable generation, can target conventional power system state estimation (SE). Moving target defense (MTD) is a promising defense strategy to detect stealthy false data injection (FDI) attacks against SE. However, all existing studies myopically perturb the reactance of transmission lines equipped with distributed flexible AC transmission system (D-FACTS) devices without adequately considering the system voltage stability. Exacerbated by the renewable generation uncertainty, existing MTD may cause voltage instability when the power grid is under stress. To address this issue, we propose a novel MTD framework that explicitly considers system voltage stability by using continuation power flow. We utilize the sensitivity matrix of power injection to line impedance, on which an optimization problem for maximizing load margin is formulated. This framework is validated on the IEEE 14-bus system and the IEEE 118-bus system, in which net load redistribution attacks are launched by sophisticated attackers. Steady-state simulations and dynamic simulations on PSS/E show the effectiveness of the proposed framework in circumventing the voltage instability while maintaining the detection effectiveness of MTD. The impact of the proposed method on attack detection effectiveness is also revealed.

Zhang, Hang↗

Study on Conduction Cooling of Superconducting Magnets for the ILC Main Linac

In the main linac of the International Linear Collider (ILC), superconducting magnets for beam focusing and steering will be located periodically in superconducting RF (SRF) cavity string for beam acceleration in common cryomodules. A concept of conduction cooling of the combined-functioned, splittable superconducting magnets has been proposed and investigated to adapt much different features and to meet different requirements for the superconducting magnet and SRF cavity in fabrication, assembly, and operation. It is required to integrate the superconducting magnet after the SRF cavity string assembly which completed under an ultra-clean environment. The magnet must be conductively cooled down through thermal links to a liquid helium supply pipe. According to this concept, a model magnet development was carried out in cooperation with Fermilab and KEK, and has been demonstrated in KEK superconducting RF test facility (STF). In addition, an important issue has been recently identified. High gradient SRF cavities naturally emit field emission electron flux from the inner surface, so-called dark current. It may pass through the subsequent SRF cavity string and penetrate into the superconducting magnets placed downstream. It may heat up the superconducting coils, and may cause a quench. Therefore, further study on reliable conduction cooling and to secure the superconducting magnet operation with a keeping sufficient safety margin is quite essential. In this paper, we report the installation, the improvement achieved in STF, and the R&D progress in the study on the conduction cooling of the superconducting magnet for the ILC main linac.

43 PARTICLE ACCELERATORS↗

A Multilevel Approach To Addressing Emerging Technologies In Nuclear Security

Emerging technologies present a unique set of challenges to operators and regulators. Although emerging technologies can be used to strengthen nuclear security systems, they also can increase risks to nuclear facilities. The disruptive nature of emerging technologies could also leave operators unprepared for threats to nuclear materials or facilities. To address the potentially dangerous consequences associated with these innovations, strong adaptive mechanisms and international cooperation on threat mitigation and technological integration are vital. This paper examines the nuclear security implications of emerging technologies from an institutional (as opposed to technology-specific) perspective. Drawing on insights from a recent workshop series hosted by the Stimson Center and the National Nuclear Security Administration’s Office of Global Material Security, as well as research funded by Global Material Security and separate research conducted by Stimson, the paper begins with a definition of emerging technology that bounds the scope of the problem while leaving some margin for expert interpretation. The subsequent sections highlight the challenges as well as potential benefits that these technologies pose at each level of the nuclear security establishment, from the operators of sites hosting radiological or nuclear material, to regulators and national policy makers, to international institutions. Each section also includes specific recommendations for incorporating emerging technologies into radiological and nuclear security planning.

Andrews, Ian↗

W-13 Advanced Engineering Analysis Group Overview [Slides]

W-13 provides the Nuclear Weapons Program at Los Alamos National Laboratory with excellence in engineering analysis, predictive modeling, validated simulations, and the quantification of margins and uncertainty. Our customers include the nuclear weapons program, the Department of Homeland Security, and the Department of Defense, among others.

42 ENGINEERING↗

Restoring Soil Fertility on Degraded Lands to Meet Food, Fuel, and Climate Security Needs via Perennialization

A continuously growing pressure to increase food, fiber, and fuel production to meet worldwide demand and achieve zero hunger has put severe pressure on soil resources. Abandoned, degraded, and marginal lands with significant agricultural constraints—many still used for agricultural production—result from inappropriately intensive management, insufficient attention to soil conservation, and climate change. Continued use for agricultural production will often require ever more external inputs such as fertilizers and herbicides, further exacerbating soil degradation and impeding nutrient recycling and retention. Growing evidence suggests that degraded lands have a large potential for restoration, perhaps most effectively via perennial cropping systems that can simultaneously provide additional ecosystem services. Here we synthesize the advantages of and potentials for using perennial vegetation to restore soil fertility on degraded croplands, by summarizing the principal mechanisms underpinning soil carbon stabilization and nitrogen and phosphorus availability and retention. We illustrate restoration potentials with example systems that deliver climate mitigation (cellulosic bioenergy), animal production (intensive rotational grazing), and biodiversity conservation (natural ecological succession). Perennialization has substantial promise for restoring fertility to degraded croplands, helping to meet future food security needs.

54 ENVIRONMENTAL SCIENCES↗

Data-Driven Probabilistic Anomaly Detection for Electricity Market under Cyber Attacks

Information and communication technologies have been widely used in smart grid for efficient operation. However, these technologies are vulnerable to malicious cyber attacks, which may lead to severe reliability and economic issues. Recently, a variety of data-driven anomaly detection approaches have been explored to detect potential cyber attacks in smart grids. In this paper, we researched on the electricity market data aiming to identify anomalies from the locational marginal prices (LMPs) and provide a new indicator for potential cyber attacks in power grids. Specifically, a novel data-driven probabilistic anomaly detection framework is proposed for electricity market, which consists of three major components: long short-term memory (LSTM) based deterministic electricity price forecasting, probabilistic electricity price forecasting and anomaly detection. This framework is tested on a model-based electricity market simulator under two types of cyber attacks, i.e., load redistribution attack (LRA) and price responsive attack (PRA). Numerical results on the simulated LMPs show that the proposed framework is capable of detecting data anomalies over these attacks.

29 ENERGY PLANNING, POLICY, AND ECONOMY↗

Cybersecurity Standards for Photovoltaic Operations

Solar energy plays an important role in securing a more resilient, cyber-secure electrical grid in Pennsylvania. Solar's ability to be widely "distributed" on residential and large roofs, marginal lands, and many other locations across Pennsylvania - as opposed to being centralized - offers a strong option for addressing the myriad of potential disruptions that can occur to the grid's infrastructure. And when combined with energy storage, local energy needs can be met immediately without having to wait on the delivery of an off-site fuel source. As more and more distributed solar electricity generation is brought online, researchers, technology developers, solar developers and grid operators are paying close attention to the potential for solar to enhance grid cybersecurity. Although nobody may know when, where, or how the next cyberattack will take place, there are security measures, technical solutions, and management practices that are being implemented across the industry to protect against network control issues and grid operations. Everyone participating in the solar value chain stands to gain from a coordinated, iterative approach to protect against cyber vulnerabilities and build deeper resilience into the architecture of our grid.

cybersecurity↗

Land use for bioenergy: Synergies and trade-offs between sustainable development goals

Bioenergy aims to reduce greenhouse gas (GHG) emissions and contribute to meeting global climate change mitigation targets. Nevertheless, several sustainability concerns are associated with bioenergy, especially related to the impacts of using land for dedicated energy crop production. Cultivating energy crops can result in synergies or trade-offs between GHG emission reductions and other sustainability effects depending on context-specific conditions. Using the United Nations Sustainable Development Goals (SDGs) framework, the main synergies and trade-offs associated with land use for dedicated energy crop production were identified. Furthermore, the context-specific conditions (i.e., biomass feedstock, previous land use, climate, soil type and agricultural management) which affect those synergies and trade-offs were also identified. The most recent literature was reviewed and a pairwise comparison between GHG emission reduction (SDG 13) and other SDGs was carried out. A total of 427 observations were classified as either synergy (170), trade-off (176), or no effect (81). Most synergies with environmentally-related SDGs, such as water quality and biodiversity conservation, were observed when perennial crops were produced on arable land, pasture or marginal land in the ‘cool temperate moist’ climate zone and ‘high activity clay’ soils. Most trade-offs were related to food security and water availability. Previous land use and feedstock type are more impactful in determining synergies and trade-offs than climatic zone and soil type. This study highlights the importance of considering context-specific conditions in evaluating synergies and trade-offs and their relevance for developing appropriate policies and practices to meet worldwide demand for bioenergy in a sustainable manner.

09 BIOMASS FUELS↗

Evidence of human influence on Northern Hemisphere snow loss

Documenting the rate, magnitude and causes of snow loss is essential to benchmark the pace of climate change and to manage the differential water security risks of snowpack declines. So far, however, observational uncertainties in snow mass have made the detection and attribution of human-forced snow losses elusive, undermining societal preparedness. Here we show that human-caused warming has caused declines in Northern Hemisphere-scale March snowpack over the 1981–2020 period. Using an ensemble of snowpack reconstructions, we identify robust snow trends in 82 out of 169 major Northern Hemisphere river basins, 31 of which we can confidently attribute to human influence. Most crucially, we show a generalizable and highly nonlinear temperature sensitivity of snowpack, in which snow becomes marginally more sensitive to one degree Celsius of warming as climatological winter temperatures exceed minus eight degrees Celsius. Such nonlinearity explains the lack of widespread snow loss so far and augurs much sharper declines and water security risks in the most populous basins. Together, our results emphasize that human-forced snow losses and their water consequences are attributable—even absent their clear detection in individual snow products—and will accelerate and homogenize with near-term warming, posing risks to water resources in the absence of substantial climate mitigation.

54 ENVIRONMENTAL SCIENCES↗

The Dual-Axis Radiographic Hydrodynamic Test Facility Capability eXpansion (DCX) Strategy

The Dual-Axis Radiographic Hydrodynamic Test (DARHT) facility is a vital and important part of the Nation’s nuclear security enterprise. The Department of Energy/National Nuclear Security Administration (DOE/ NNSA) Stockpile Stewardship Management Plan (SSMP) identifies DARHT as a weapons mission critical facility along with the need to modernize DARHT to support weapons modernization efforts. With more than two decades of operations, DARHT has a storied history. Conceived in the 1970s, constructed in the 1990s, and operational since 2000, DARHT has advanced from open-air hydrodynamic experiments (hydros) to foam-confined hydros, to vessel-confined hydros, and in 2022, the 75 th hydro was successfully completed. Radiography has advanced from a single-axis, single-pulse system to a dual-axis, multi-pulse capability to variable fields of view (VFV) on both accelerators. The culmination of these experiences, accomplishments, and advancements has brought us to a very important question: What do the next two decades at DARHT look like? The world is not the same place it was in the 1990s when construction at DARHT was in progress. Evolving threats, an expanding mission, and technology changes necessitate adaptation. The 2018 Nuclear Posture Review (NPR) states that the nuclear weapons infrastructure has suffered the effects of age and underfunding with no margin for further delay in recapitalizing the physical infrastructure. To adapt, the aging facility, accelerators, vessels, and detector systems require improvements to ensure DARHT remains the Nation’s hydrodynamic data foundation for stockpile certification, safety, surety, and global security threats.

98 NUCLEAR DISARMAMENT, SAFEGUARDS, AND PHYSICAL P↗

An Integrated Framework for Risk Assessment of Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants: Methodology Refinement and Exploration

This report documents activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2023 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a technical basis to support effective, and secure DI&C technologies for digital upgrades/designs. A risk assessment-informed framework was proposed for this strategy, which aims to (1) provide a best-estimate, risk informed capability to quantitatively estimate the safety margin obtained from plant modernization, especially for safety-related DI&C systems, (2) support and supplement existing risk informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems, (4) assure the long-term safety and reliability of safety-related DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals, the LWRS-developed framework provides a means to address relevant technical issues by: (1) defining a risk informed analysis process for DI&C upgrade that integrates hazard analysis, reliability analysis, and consequence analysis, (2) applying risk informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development and deployment of advanced DI&C technologies in nuclear power plants (NPPs). Adding diversity within a system or components is the primary means to eliminate and mitigate CCFs, but diversity also increases system complexity and may not address all sources of systematic failures. Optimization of diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in safety-related DI&C systems of NPPs and supporting relevant design optimization, the proposed framework provides: (a) A best-estimate, risk informed capability to address new technical digital issues quantitatively, focusing on software CCFs in safety-related DI&C systems of NPPs; (b) A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to predict and prevent risk in the early design stage of DI&C systems; (c) Technical bases and risk informed insights to assist users address the risk informed alternatives for evaluation of CCFs in safety-related DI&C systems of NPPs; and (d) A risk informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The research and development efforts of this project in FY 2023 are focused on refining current methods on software CCF modeling and estimation and exploring additional innovative approaches to risk assessment of DI&C systems to enable a more comprehensive and complete assessment of various safety-related DI&C design architectures. The primary audience of this report are DI&C designers, engineers, and probabilistic risk assessment (PRA) practitioners. This includes stakeholders, such as the nuclear utilities and regulators who consider the deployment and upgrade of DI&C systems, DI&C software developers and reviewers, and cybersecurity specialists. It should be noted that all the analyses are performed for the demonstration of the methodology, not for the evaluation of an actual digital control system. Results are obtained based on limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Advanced Simulation and Computing: ASC FY24 Implementation Plan

The DOE National Nuclear Security Administration (NNSA) Stockpile Stewardship Program (SSP) is an integrated technical program for maintaining the safety, security, and reliability of the U.S. nuclear stockpile. The SSP incorporates nuclear test data, computational modeling and simulation, and experimental facilities to advance understanding of nuclear weapons. The suite of data analyzed comes from activities including previous nuclear tests, stockpile surveillance, experimental research, and development and engineering programs. This integrated national program requires the continued use of experimental facilities and the computational capabilities to support the SSP missions. These component parts, in addition to an appropriately scaled production capability, enable NNSA to support stockpile requirements. The ultimate goal of the SSP, and thus of the Advanced Simulation and Computing (ASC) program, is to ensure that the U.S. maintains a safe, secure, and effective strategic deterrent. The ASC program is a cornerstone of the SSP, providing simulation capabilities and computational resources to support the annual stockpile assessment and certification process, study advanced nuclear weapons design and manufacturing processes, analyze accident scenarios and weapons aging, and provide the tools to enable stockpile Life Extension Programs (LEPs) and the resolution of Significant Finding Investigations (SFIs). This work requires a balance of resources, including technical staff, hardware, simulation software, and computer science solutions. The ASC program focuses on increasing the predictive capabilities in a three-dimensional (3D) simulation environment while maintaining support to the SSP. The Program continues to improve its unique tools for understanding and solving progressively more difficult stockpile problems (sufficient resolution, dimensionality, and scientific details), and quantifying critical margins and uncertainties. Resolving each issue requires increasingly difficult analyses because the aging process has progressively moved the stockpile further from the original test base. While the focus remains on the U.S. nuclear weapons program, where possible, the Program also enables the use of high-performance computing (HPC) and simulation tools to address broader national security needs, such as foreign nuclear weapon assessments and nuclear counterterrorism. The 2022 Nuclear Posture Review (NPR) calls for NNSA to “deliver a modern, adaptive nuclear security enterprise based on an integrated strategy for risk management, production-based resilience, science and technology innovation, and workforce initiatives.” Furthermore, “NNSA will establish a Science and Technology Innovation Initiative to accelerate the integration of science and technology (S&T) throughout its activities.” Executing this strategy necessitates the continued emphasis on developing and sustaining high-quality scientific and engineering staff, as well as supporting computational and experimental capabilities. These components constitute the foundation of the nuclear weapons program. The continued success of the SSP and LEPs is predicated upon the ability to credibly certify the stockpile, without a return to underground nuclear tests (UGTs). Shortly after the nuclear test moratorium entered into force in 1992, the Accelerated Strategic Computing Initiative (ASCI) was established to provide an extensive simulation capability to underpin stockpile certification. While computing and simulation have always been essential to the success of the nuclear weapons program, the program goal of ASCI was to execute NNSA’s vision of using these tools in support of the stockpile stewardship mission. The ASCI program was essential to the successful demonstration of the SSP, providing critical nuclear weapons simulation and modeling capabilities. ASCI officially evolved into the ASC program in fiscal year (FY) 2005, but the mission remains essentially the same: provide the simulation and computational capabilities that underpin the ability to maintain a safe, secure, effective nuclear weapon stockpile, without returning to underground nuclear testing. The capabilities that the ASC program provides at the national laboratories play a vital role in the nuclear security enterprise and are necessary for fulfilling the stockpile stewardship and life extension requirements outlined for NNSA. The Program develops modern simulation tools that provide insights into stockpile aging issues, provide the computational and simulation tools that enable designers and analysts to certify the current stockpile and life-extended nuclear weapons, and inform the decision-making process when any modifications in nuclear warheads or the associated manufacturing processes are deemed necessary. Furthermore, ASC is enhancing the predictive simulation capabilities that are essential to evaluate weapons effects, design experiments, and ensure test readiness. The ASC program continues to improve its unique tools to solve stockpile problems— with a focus on sufficient resolution, dimensionality, and scientific detail—to enable Quantification of Margins and Uncertainties (QMU) and to resolve the increasingly difficult analyses needed for stockpile stewardship. The needs of the Stockpile Management and Production Modernization programs (formerly Directed Stockpile Work) also drive the requirements for simulation and computational resources. These requirements include planned LEPs, stockpile support activities, and mitigation efforts against the potential for technical surprise. All of the weapons within the current stockpile are in some stage of the life extension process. The simulation and computational capabilities are crucial for successful execution of these life extensions and for ensuring NNSA can certify these life-extended weapons without conducting a UGT.

97 MATHEMATICS AND COMPUTING↗

Risk Analysis of Various Design Architectures for High Safety-significant Safety-related Digital Instrumentation and Control Systems of Nuclear Power Plants during Accident Scenarios

This report documents the plus-up activities performed by Idaho National Laboratory (INL) during Fiscal Year (FY) 2022 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) risk assessment project. In FY 2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems was proposed for this strategy, which aims to (1) provide a best-estimate, risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the high safety-significant safety-related (HSSSR) DI&C systems, (2) support and supplement existing advanced risk-informed DI&C design guides by providing quantitative risk information and evidence, (3) offer a capability of design architecture evaluation of various DI&C systems to support system design decisions and diversity and redundancy applications, (4) assure the long-term safety and reliability of HSSSR DI&C systems, and (5) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the LWRS-developed framework instructs nuclear vendors and utilities on how to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify corresponding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the component level, system level, and plant level, and (4) providing insights and suggestions on designs to manage the risks, thus to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). Adding diversity within system or components is the main means to eliminate and mitigate CCFs, but diversity also increases plant complexity and errors and may not address all sources of systematic failures. How to optimize the diversity and redundancy applications for the safety-critical DI&C systems remains a challenge. To deal with the technical issues in addressing potential software CCFs in HSSSR DI&C systems of NPPs and supporting relevant design optimization, the framework provides: ? An integrated best-estimate, risk-informed capability to address new technical digital issues quantitatively, accurately, and efficiently in plan modernization progress, such as software CCFs in HSSSR DI&C systems of NPPs ? A common and a modularized platform for DI&C designers, software developers, cybersecurity analysts, and plant engineers to efficiently predict and prevent risk in the early design stage of DI&C systems ? Technical bases and risk-informed insights to assist U.S. Nuclear Regulatory Commission (NRC) and industry to address and fulfill the risk-informed alternatives for evaluation of CCFs in HSSSR DI&C systems of NPPs ? An integrated risk-informed tool that offers a capability of design architecture evaluation of various DI&C systems to support system design decisions in diversity and redundancy applications. The plus-up research and development efforts of this project in FY 2022 are focused on methodology improvement of software CCF modeling and estimation, prevention analysis, importance analysis and risk analysis of various design architectures of HSSSR DI&C systems. This work greatly enhances the capability of the LWRS-developed framework for the risk assessment and design optimization of safety-critical DI&C systems. It should be noted that all the analyses are performed for the demonstration of the LWRS-developed framework, not for the evaluation of relevant systems. Results are obtained based on very limited design information and testing data.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Quantitative Risk Analysis of High Safety Significant Safety-related Digital Instrumentation and Control Systems in Nuclear Power Plants using IRADIC Technology

This report documents the activities performed by Idaho National Laboratory (INL) during fiscal year (FY) 2021 for the U.S. Department of Energy (DOE) Light Water Reactor Sustainability (LWRS) Program, Risk Informed Systems Analysis (RISA) Pathway, digital instrumentation and control (DI&C) Risk Assessment project. In FY-2019, the RISA Pathway initiated a project to develop a risk assessment strategy for delivering a strong technical basis to support effective, licensable, and secure DI&C technologies for digital upgrades/designs. An integrated risk assessment technology for the DI&C systems (IRADIC technology) was proposed for this strategy, which aims to (1) provide a best-estimate risk-informed capability to quantitatively and accurately estimate the safety margin obtained from plant modernization, especially for the High Safety Significant Safety-related (HSSSR) DI&C systems, (2) develop an advanced risk assessment technology to support transition from analog to DI&C technologies for nuclear industry, (3) assure the long-term safety and reliability of vital HSSSR DI&C systems, (4) reduce uncertainty in costs and support integration of DI&C systems in the plant. To achieve these technical goals and deal with the expensive licensing justifications from regulatory insights, the IRADIC technology is instructive for nuclear vendors and utilities to effectively lower the costs associated with digital compliance and speed industry advances by: (1) defining an integrated risk-informed analysis process for DI&C upgrade, including hazard analysis, reliability analysis, and consequence analysis, (2) applying systematic and risk-informed tools to address common cause failures (CCFs) and quantify responding failure probabilities for DI&C technologies, particularly software CCFs, (3) evaluating the impact of digital failures at the individual level, system level, and plant level, (4) providing insights and suggestions on designs to manage the risks; thus, to support the development, licensing, and deployment of advanced DI&C technologies on nuclear power plant (NPPs). In this report, an approach for performing software CCF analysis, given limited data, is developed and demonstrated using a case study of a highly redundant digital reactor trip system. Consequence analysis is also performed based on different accident scenarios. Results indicate that plant modernization including the improvement of HSSSR DI&C systems will make great benefits to plant safety by providing more safety margins to accident management. In addition, a novel approach is proposed in this report for the quantification of software hazards when sufficient operational and testing data available. The method incorporates software development quality as well as strong analysis techniques to identify and link software defects to potential failure modes. The approach includes both semantic and test-based analysis to detect failures that can exist in different stages of the software development life cycle. This method is applied to an advanced human system interface relevant to reactor trip safety developed from the APR 1400 design.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗