WorldWideScience

Sample records for safety system functional

  1. Probabilistic safety criteria at the safety function/system level

    International Nuclear Information System (INIS)

    1989-09-01

    A Technical Committee Meeting was held in Vienna, Austria, from 26-30 January 1987. The objectives of the meeting were: to review the national developments of PSC at the level of safety functions/systems including future trends; to analyse basic principles, assumptions, and objectives; to compare numerical values and the rationale for choosing them; to compile the experience with use of such PSC; to analyse the role of uncertainties in particular regarding procedures for showing compliance. The general objective of establishing PSC at the level of safety functions/systems is to provide a pragmatic tool to evaluate plant safety which is placing emphasis on the prevention principle. Such criteria could thus lead to a better understanding of the importance to safety of the various functions which have to be performed to ensure the safety of the plant, and the engineering means of performing these functions. They would reflect the state-of-the-art in modern PSAs and could contribute to a balance in system design. This report, prepared by the participants of the meeting, reviews the current status and future trends in the field and should assist Member States in developing their national approaches. The draft of this document was also submitted to INSAG to be considered in its work to prepare a document on safety principles for nuclear power plants. Five papers presented at the meeting are also included in this publication. A separate abstract was prepared for each of these papers. Refs, figs and tabs

  2. Safety system function trends

    International Nuclear Information System (INIS)

    Johnson, C.

    1989-01-01

    This paper describes research to develop risk-based indicators of plant safety performance. One measure of the safety-performance of operating nuclear power plants is the unavailability of important safety systems. Brookhaven National Laboratory and Science Applications International Corporation are evaluating ways to aggregate train-level or component-level data to provide such an indicator. This type of indicator would respond to changes in plant safety margins faster than the currently used indicator of safety system unavailability (i.e., safety system failures reported in licensee event reports). Trends in the proposed indicator would be one indication of trends in plant safety performance and maintenance effectiveness. This paper summarizes the basis for such an indicator, identifies technical issues to be resolved, and illustrates the potential usefullness of such indicators by means of computer simulations and case studies

  3. Safety critical systems handbook a straightforward guide to functional safety : IEC 61508 (2010 edition) and related standards

    CERN Document Server

    Smith, David J

    2010-01-01

    Electrical, electronic and programmable electronic systems increasingly carry out safety functions to guard workers and the public against injury or death and the environment against pollution. The international functional safety standard IEC 61508 was revised in 2010, and this is the first comprehensive guide available to the revised standard. As functional safety is applicable to many industries, this book will have a wide readership beyond the chemical and process sector, including oil and gas, power generation, nuclear, aircraft, and automotive industries, plus project, instrumentation, design, and control engineers. * The only comprehensive guide to IEC 61508, updated to cover the 2010 amendments, that will ensure engineers are compliant with the latest process safety systems design and operation standards* Helps readers understand the process required to apply safety critical systems standards* Real-world approach helps users to interpret the standard, with case studies and best practice design examples...

  4. Expansion of passive safety function

    International Nuclear Information System (INIS)

    Inai, Nobuhiko; Nei, Hiromichi; Kumada, Toshiaki.

    1995-01-01

    Expansion of the use of passive safety functions is proposed. Two notions are presented. One is that, in the design of passive safety nuclear reactors where aversion of active components is stressed, some active components are purposely introduced, by which a system is built in such a way that it behaves in an apparently passive manner. The second notion is that, instead of using a passive safety function alone, a passive safety function is combined with some active components, relating the passivity in the safety function with enhanced controllability in normal operation. The nondormant system which the authors propose is one example of the first notion. This is a system in which a standby safety system is a portion of the normal operation system. An interpretation of the nondormant system via synergetics is made. As an example of the second notion, a PIUS density lock aided with active components is proposed and is discussed

  5. 33 CFR 96.240 - What functional requirements must a safety management system meet?

    Science.gov (United States)

    2010-07-01

    ... a safety management system meet? 96.240 Section 96.240 Navigation and Navigable Waters COAST GUARD, DEPARTMENT OF HOMELAND SECURITY VESSEL OPERATING REGULATIONS RULES FOR THE SAFE OPERATION OF VESSELS AND SAFETY MANAGEMENT SYSTEMS Company and Vessel Safety Management Systems § 96.240 What functional...

  6. Safety system function trend indicator: Theory and test application

    International Nuclear Information System (INIS)

    Azarm, M.A.; Carbonaro, J.F.; Boccio, J.L.; Vesely, W.E.

    1989-01-01

    The purpose of this paper is to summarize research conducted on the development and validation of quantitative indicators of safety performance. This work, performed under the Risk-Based Performance Indicator (RBPI) Project, FIN A-3295, for the Office of Research (RES), is considered part of NRC's Performance Indicator Program which is being coordinated through the Office for the Analysis and Evaluation of Operational Data (AEOD). The program originally focused on risk-based indicators at high levels of safety indices (e.g., core-damage frequency, functional unavailabilities, and sequence monitoring). The program was then redirected towards a more amenable goal, safety system unavailability indicators, mainly due to the lack of PRA models and plant data. In that regard, BNL published a technical report that introduced the concept of cycle-based indicators and also described various alternatives of monitoring safety system unavailabilities. Further simplification of these indicators was requested by NRC to facilitate their applications to all plants in a timely manner. This resulted in the development of Safety System Function Trend (SSFT) indicators which minimize the need for detailed system model as well as component history. The theoretical bases for these indicators were developed through various simulation studies to determine the ease of detecting a trend and/or unacceptable performance. These indicators, along with several other indicators, were then generated and compared using plant data as a part of a test application. The SSFT indicators, specifically, were constructed for a total of eight plants, consisting of two systems per plant. Emphasis was placed on examining relative changes, as well as the indicator's actual level. Both the trend and actual indicator level were found to be important in identifying plants with potential problems

  7. An approach for functional safety improvement of an existing automotive system

    NARCIS (Netherlands)

    Khabbaz Saberi, A.; Luo, Y.; Pawel Cichosz, F.; Brand, M. van den; Jansen, S.T.H.

    2015-01-01

    Safety of automotive systems is becoming more involved, specially for the case of autonomous vehicles. The ISO 26262 standard offers a systematic approach for designing a safe road vehicle (or subsystems of a car) from design phase through its production. However, providing functional safety

  8. Validation of risk-based performance indicators: Safety system function trends

    International Nuclear Information System (INIS)

    Boccio, J.L.; Vesely, W.E.; Azarm, M.A.; Carbonaro, J.F.; Usher, J.L.; Oden, N.

    1989-10-01

    This report describes and applies a process for validating a model for a risk-based performance indicator. The purpose of the risk-based indicator evaluated, Safety System Function Trend (SSFT), is to monitor the unavailability of selected safety systems. Interim validation of this indicator is based on three aspects: a theoretical basis, an empirical basis relying on statistical correlations, and case studies employing 25 plant years of historical data collected from five plants for a number of safety systems. Results using the SSFT model are encouraging. Application of the model through case studies dealing with the performance of important safety systems shows that statistically significant trends in, and levels of, system performance can be discerned which thereby can provide leading indications of degrading and/or improving performances. Methods for developing system performance tolerance bounds are discussed and applied to aid in the interpretation of the trends in this risk-based indicator. Some additional characteristics of the SSFT indicator, learned through the data-collection efforts and subsequent data analyses performed, are also discussed. The usefulness and practicality of other data sources for validation purposes are explored. Further validation of this indicator is noted. Also, additional research is underway in developing a more detailed estimator of system unavailability. 9 refs., 18 figs., 5 tabs

  9. Safety design guide for safety related systems for CANDU 9

    International Nuclear Information System (INIS)

    Lee, Duk Su; Chang, Woo Hyun; Lee, Nam Young; A. C. D. Wright

    1996-03-01

    In general, two types of safety related systems and structures exist in the nuclear plant; The one is a systems and structures which perform safety functions during the normal operation of the plant, and the other is a systems and structures which perform safety functions to mitigate events caused by failure of the normally operating systems or by naturally occurring phenomena. In this safety design guide, these systems are identified in detail, and the major events for which the safety functions are required and the major safety requirements are identified in the list. As the probabilistic safety assessments are completed during the course of the project, additions or deletions to the list may be justified. 3 tabs. (Author) .new

  10. Safety design guide for safety related systems for CANDU 9

    Energy Technology Data Exchange (ETDEWEB)

    Lee, Duk Su; Chang, Woo Hyun; Lee, Nam Young [Korea Atomic Energy Research Institute, Daeduk (Korea, Republic of); Wright, A.C.D. [Atomic Energy of Canada Ltd., Toronto (Canada)

    1996-03-01

    In general, two types of safety related systems and structures exist in the nuclear plant; The one is a systems and structures which perform safety functions during the normal operation of the plant, and the other is a systems and structures which perform safety functions to mitigate events caused by failure of the normally operating systems or by naturally occurring phenomena. In this safety design guide, these systems are identified in detail, and the major events for which the safety functions are required and the major safety requirements are identified in the list. As the probabilistic safety assessments are completed during the course of the project, additions or deletions to the list may be justified. 3 tabs. (Author) .new.

  11. Safety functions and safety function indicators - key elements in SKB'S methodology for assessing long-term safety of a KBS-3 repository

    International Nuclear Information System (INIS)

    Hedin, A.

    2008-01-01

    The application of so called safety function indicators in SKB safety assessment of a KBS-3 repository for spent nuclear fuel is presented. Isolation and retardation are the two main safety functions of the KBS-3 concept. In order to quantitatively evaluate safety on a sub-system level, these functions need to be differentiated, associated with quantitative measures and, where possible, with quantitative criteria relating to the fulfillment of the safety functions. A safety function is defined as a role through which a repository component contributes to safety. A safety function indicator is a measurable or calculable property of a repository component that allows quantitative evaluation of a safety function. A safety function indicator criterion is a quantitative limit such that if the criterion is fulfilled, the corresponding safety function is upheld. The safety functions and their associated indicators and criteria developed for the KBS-3 repository are primarily related to the isolating potential and to physical states of the canister and the clay buffer surrounding the canister. They are thus not directly related to release rates of radionuclides. The paper also describes how the concepts introduced i) aid in focussing the assessment on critical, safety related issues, ii) provide a framework for the accounting of safety throughout the different time frames of the assessment and iii) provide key information in the selection of scenarios for the safety assessment. (author)

  12. Diagnosis function of safety status in the safety parameter display system (SPDS)

    International Nuclear Information System (INIS)

    Zhang Yuanfang

    1993-04-01

    An automatic diagnosis function of safety status for nuclear power plant adopted in the SPDS is introduced. To guarantee diagnosis diversification, two diagnosis criteria of a design basis accident monitoring and a critical safety function monitoring used in plant emergency operation are provided. As an extensive function, a parameter deviation monitoring used in plant normal operation is also provided

  13. Operator Actions Within a Safety Instrumented Function

    International Nuclear Information System (INIS)

    Suttinger, L.T.

    2002-01-01

    This paper presents an overview of the factors that should be considered when crediting operator action for performing a safety function or being a part of the process of enabling a safety function. Criteria for evaluating operator action, such as required time response and operator training among others, are discussed. The paper will address these and other factors that should be considered when determining the reliability of the operator to respond and perform his/her part of the safety function. The entire safety function includes the operator and the reliability of the instrumented system that provides the alarm or indication, the final control element, and support systems. The integration of the operator performance with the hardware safety availability, including the effects of the supporting systems is discussed. The analysis of these factors will provide the justification for the amount of risk reduction or safety integrity level that can be credited for the Safety Instrumented Function (SIF), including operator action

  14. Barrier and system performances within a safety case: their functioning and evolution with time

    International Nuclear Information System (INIS)

    Hedin, A.; Voinis, S.; Fillion, E.; Keller, S.; Lalieux, Ph.; Nachmilner, L.; Nys, V.; Rodriguez, J.; Sevougian, D.; Wollrath, J.

    2002-01-01

    The following six questions were used as the basis for the discussions in a Working Group: - What is the role of each barrier as a function of time or in the different time frames? What is its contribution to the overall system performance or safety as a function of time? - Which are the main uncertainties on the performance of barriers in the timescales? To what extent should we enhance the robustness of barriers because of the uncertainties of some component behaviour with time? - What is the requested or required performance versus the expected realistic or conservative behaviour with time? How are these safety margins used as arguments in a safety case? - What is the issue associated with the geosphere stability for different geological systems? - How are barriers and system performances, as a function of time, evaluated (presented and communicated) in a safety case? - What kind of measures are used for siting, designing and optimising robust barriers corresponding to situations that can vary with time? Are human actions considered to be relevant? (authors)

  15. Software Safety Risk in Legacy Safety-Critical Computer Systems

    Science.gov (United States)

    Hill, Janice L.; Baggs, Rhoda

    2007-01-01

    Safety Standards contain technical and process-oriented safety requirements. Technical requirements are those such as "must work" and "must not work" functions in the system. Process-Oriented requirements are software engineering and safety management process requirements. Address the system perspective and some cover just software in the system > NASA-STD-8719.13B Software Safety Standard is the current standard of interest. NASA programs/projects will have their own set of safety requirements derived from the standard. Safety Cases: a) Documented demonstration that a system complies with the specified safety requirements. b) Evidence is gathered on the integrity of the system and put forward as an argued case. [Gardener (ed.)] c) Problems occur when trying to meet safety standards, and thus make retrospective safety cases, in legacy safety-critical computer systems.

  16. A comparison of the difference of requirements between functional safety and nuclear safety controllers

    Energy Technology Data Exchange (ETDEWEB)

    Chen, C.K.; Lee, C.L.; Shyu, S.S. [Inst. of Nuclear Energy Research, Taoyuan, Taiwan (China)

    2014-07-01

    In order to establish self-reliant capabilities of nuclear I&C systems in Taiwan, Taiwan's Nuclear I&C System (TNICS) project had been established by Institute of Nuclear Energy Research (INER). A Triple Modular Redundant (TMR) safety controller (SCS-2000) has been completed and gone through the IEC 61508 Safety Integrity Level 3 (SIL3) certification of Functional Safety for industries. Based on the certification processes, the difference of requirements between Functional Safety and Nuclear Safety controllers in term of hardware and software are addressed in this study. Besides, the measures used to determine and verify the reliability of the safety control system design are presented. (author)

  17. Validation of a functional model for integration of safety into process system design

    DEFF Research Database (Denmark)

    Wu, J.; Lind, M.; Zhang, X.

    2015-01-01

    with the process system functionalities as required for the intended safety applications. To provide the scientific rigor and facilitate the acceptance of qualitative modelling, this contribution focuses on developing a scientifically based validation method for functional models. The Multilevel Flow Modeling (MFM...

  18. Mathematical modelling of active safety system functions as tools for development of driverless vehicles

    Science.gov (United States)

    Ryazantsev, V.; Mezentsev, N.; Zakharov, A.

    2018-02-01

    This paper is dedicated to a solution of the issue of synthesis of the vehicle longitudinal dynamics control functions (acceleration and deceleration control) based on the element base of the vehicle active safety system (ESP) - driverless vehicle development tool. This strategy helps to reduce time and complexity of integration of autonomous motion control systems (AMCS) into the vehicle architecture and allows direct control of actuators ensuring the longitudinal dynamics control, as well as reduction of time for calibration works. The “vehicle+wheel+road” longitudinal dynamics control is complicated due to the absence of the required prior information about the control object. Therefore, the control loop becomes an adaptive system, i.e. a self-adjusting monitoring system. Another difficulty is the driver’s perception of the longitudinal dynamics control process in terms of comfort. Traditionally, one doesn’t pay a lot of attention to this issue within active safety systems, and retention of vehicle steerability, controllability and stability in emergency situations are considered to be the quality criteria. This is mainly connected to its operational limits, since it is activated only in critical situations. However, implementation of the longitudinal dynamics control in the AMCS poses another challenge for the developers - providing the driver with comfortable vehicle movement during acceleration and deceleration - while the possible highest safety level in terms of the road grip is provided by the active safety system (ESP). The results of this research are: universal active safety system - AMCS interaction interface; block diagram for the vehicle longitudinal acceleration and deceleration control as one of the active safety system’s integrated functions; ideology of adaptive longitudinal dynamics control, which enables to realize the deceleration and acceleration requested by the AMCS; algorithms synthesised; analytical experiments proving the

  19. Squale: evaluation criteria of functioning safety

    International Nuclear Information System (INIS)

    Deswarte, Y.; Kaaniche, M.; Benoit, P.

    1998-05-01

    The SQUALE (security, safety and quality evaluation for dependable systems) project is part of the ACTS (advanced communications, technologies and services) European program. Its aim is to develop confidence evaluation criteria to test the functioning safety of systems. All industrial sectors that use critical applications (nuclear, railway, aerospace..) are concerned. SQUALE evaluation criteria differ from the classical evaluation methods: they are independent of the application domains and industrial sectors, they take into account the overall functioning safety attributes, and they can progressively change according to the level of severity required. In order to validate the approach and to refine the criteria, a first experiment is in progress with the METEOR automatic underground railway and another will be carried out on a telecommunication system developed by Bouygues company. (J.S.)

  20. Concept for creating program-technical complex of safety monitoring with system of safety parameters presentation functions on the basis of routine WWER-1000 systems

    International Nuclear Information System (INIS)

    Dunaev, V.G.; Tarasov, M. V.; Povarov, P.V.

    2005-01-01

    Prerequisites of creating the software-hardware complex for reactor safety monitoring on the Volgodonsk NPP are analyzed and generalized. The concept of this complex is based on functions of the safety parameters presentation system. It will serve as an interface between operator and technological process and give to operator a possibility to estimate quickly the state of the safety of the nuclear power unit. The complex will be created on the basis of routine reactor monitoring and control systems intended for the WWER-1000 reactor. In addition to existing soft- and hard-wares for reactor monitoring and for analysis of technological archive, it is proposed to create and connect in parallel the new software-hardware complex which ensures calculation and presentation of generalized factors of reactor safety [ru

  1. Comparing performance level estimation of safety functions in three distributed structures

    International Nuclear Information System (INIS)

    Hietikko, Marita; Malm, Timo; Saha, Heikki

    2015-01-01

    The capability of a machine control system to perform a safety function is expressed using performance levels (PL). This paper presents the results of a study where PL estimation was carried out for a safety function implemented using three different distributed control system structures. Challenges relating to the process of estimating PLs for safety related distributed machine control functions are highlighted. One of these examines the use of different cabling schemes in the implementation of a safety function and its effect on the PL evaluation. The safety function used as a generic example in PL calculations relates to a mobile work machine. It is a safety stop function where different technologies (electrical, hydraulic and pneumatic) can be utilized. It was detected that by replacing analogue cables with digital communication the system structure becomes simpler with less number of failing components, which can better the PL of the safety function. - Highlights: • Integration in distributed systems enables systems with less components. • It offers high reliability and diagnostic properties. • Analogue signals create uncertainty in signal reliability and difficult diagnostics

  2. NASA System Safety Handbook. Volume 2: System Safety Concepts, Guidelines, and Implementation Examples

    Science.gov (United States)

    Dezfuli, Homayoon; Benjamin, Allan; Everett, Christopher; Feather, Martin; Rutledge, Peter; Sen, Dev; Youngblood, Robert

    2015-01-01

    This is the second of two volumes that collectively comprise the NASA System Safety Handbook. Volume 1 (NASASP-210-580) was prepared for the purpose of presenting the overall framework for System Safety and for providing the general concepts needed to implement the framework. Volume 2 provides guidance for implementing these concepts as an integral part of systems engineering and risk management. This guidance addresses the following functional areas: 1.The development of objectives that collectively define adequate safety for a system, and the safety requirements derived from these objectives that are levied on the system. 2.The conduct of system safety activities, performed to meet the safety requirements, with specific emphasis on the conduct of integrated safety analysis (ISA) as a fundamental means by which systems engineering and risk management decisions are risk-informed. 3.The development of a risk-informed safety case (RISC) at major milestone reviews to argue that the systems safety objectives are satisfied (and therefore that the system is adequately safe). 4.The evaluation of the RISC (including supporting evidence) using a defined set of evaluation criteria, to assess the veracity of the claims made therein in order to support risk acceptance decisions.

  3. Safety and interlock system for Tristan

    International Nuclear Information System (INIS)

    Takeda, S.; Kudo, K.; Katoh, T.; Akiyama, A.

    1987-01-01

    This report describes alarm and interlock system of TRISTAN, concentrating on personnel safety. The basis of TRISTAN machine-control system (TMS) is an N-to-N computer network and KEK NODAL which offers high software productivity. TMC achieves high flexibility of operation both for normal operation and for the fast commissioning. However, to assure the safety of personnel and the TRISTAN machine operation, the safety system has to continue functioning during TMC failure as well. A distributed safety and interlock system (DSIS) is used for diversification of risks in TRISTAN system. DSIS is functionally subdivided along local system lines and has a hierarchical structure of 12 programmable sequence controllers (PSCs). Optical fiber links connect the PSCs at subsystem level and a PSC at the supervisory level of TRISTAN central control room (TCCR). The subsystem PSCs provide the interlock functions between their local devices. The local PSCs interact with the central system through a limited number of summarized signals. The central PSC provides the interlock functions between the subsystems and interacts with an operator's panel. Personnel safety is based on a system of electrical interlock keys, emergency push-buttons around the tunnel, at the entrance gates or in the control room

  4. Modelling safety of multistate systems with ageing components

    Energy Technology Data Exchange (ETDEWEB)

    Kołowrocki, Krzysztof; Soszyńska-Budny, Joanna [Gdynia Maritime University, Department of Mathematics ul. Morska 81-87, Gdynia 81-225 Poland (Poland)

    2016-06-08

    An innovative approach to safety analysis of multistate ageing systems is presented. Basic notions of the ageing multistate systems safety analysis are introduced. The system components and the system multistate safety functions are defined. The mean values and variances of the multistate systems lifetimes in the safety state subsets and the mean values of their lifetimes in the particular safety states are defined. The multi-state system risk function and the moment of exceeding by the system the critical safety state are introduced. Applications of the proposed multistate system safety models to the evaluation and prediction of the safty characteristics of the consecutive “m out of n: F” is presented as well.

  5. Modelling safety of multistate systems with ageing components

    International Nuclear Information System (INIS)

    Kołowrocki, Krzysztof; Soszyńska-Budny, Joanna

    2016-01-01

    An innovative approach to safety analysis of multistate ageing systems is presented. Basic notions of the ageing multistate systems safety analysis are introduced. The system components and the system multistate safety functions are defined. The mean values and variances of the multistate systems lifetimes in the safety state subsets and the mean values of their lifetimes in the particular safety states are defined. The multi-state system risk function and the moment of exceeding by the system the critical safety state are introduced. Applications of the proposed multistate system safety models to the evaluation and prediction of the safty characteristics of the consecutive “m out of n: F” is presented as well.

  6. The operator's role and safety functions

    International Nuclear Information System (INIS)

    Corcoran, W.R.; Finnicum, D.J.; Hubbard, F.R.; Musick, C.R.; Walzer, R.F.

    1980-01-01

    A nuclear power plant can be thought of as a single system with two major subsystems: equipment and people. Both play important roles in nuclear safety. Whereas, in the past, the role of equipment had been emphasized in nuclear safety, the accident at Three Mile Island and its subsequent investigations point out the vital role of the operator. This paper outlines the operator's roles in nuclear safety and suggests how the concept of safety functions can be used to reduce economic losses and increase safety margins. (auth)

  7. Design of Safety Parameter Monitoring Function in a Research Reactor Facility

    Energy Technology Data Exchange (ETDEWEB)

    Park, Jaekwan; Suh, Yongsuk [Korea Atomic Energy Research Institute, Daejeon (Korea, Republic of)

    2014-05-15

    The primary purpose of the safety parameter monitoring system (SPDS) is to help operating personnel in the control room make quick assessments of the plant safety status. Thus, the basic function of the SPDS is a provision of a continuous indication of plant parameters or derived variables representative of the safety status of the plant. NUREG-0737 Supplement 1 provides details of the functional criteria for the SPDS, as one of the action plan requirements from TMI accident. The system provides various functions as follows: · Alerting based on safety function decision logics, · Success path analysis to achieve the integrity of the safety functions, · 3 layer display architecture - safety function, success path display for each safety function, system summary and equipment details for each safety function, · Integration with computer-based procedure. According to a Notice of the NSSC No. 2012-31, a research reactor facility generating more than 2 MW of power should also be furnished with the SPDS for emergency preparedness. Generally, a research reactor is a small size facility, and its number of instrumentations is fewer than that of NPPs. In particular, it is actually hard to have various and powerful functions from an economic perspective. Therefore, a safety parameter display system optimized for a research reactor facility must be proposed. This paper provides the requirement analysis results and proposes the design of safety parameter monitoring function for a research reactor. The safety parameter monitoring function supporting control room personnel during emergency conditions should be designed in a research reactor facility. The facility size and number of signals are smaller than that of the power plants. Also, it is actually hard to have various and powerful functions of nuclear power plants from an economic perspective. Thus, a safety parameter display system optimized to a research reactor must be proposed. First, we found important design items

  8. Design of Safety Parameter Monitoring Function in a Research Reactor Facility

    International Nuclear Information System (INIS)

    Park, Jaekwan; Suh, Yongsuk

    2014-01-01

    The primary purpose of the safety parameter monitoring system (SPDS) is to help operating personnel in the control room make quick assessments of the plant safety status. Thus, the basic function of the SPDS is a provision of a continuous indication of plant parameters or derived variables representative of the safety status of the plant. NUREG-0737 Supplement 1 provides details of the functional criteria for the SPDS, as one of the action plan requirements from TMI accident. The system provides various functions as follows: · Alerting based on safety function decision logics, · Success path analysis to achieve the integrity of the safety functions, · 3 layer display architecture - safety function, success path display for each safety function, system summary and equipment details for each safety function, · Integration with computer-based procedure. According to a Notice of the NSSC No. 2012-31, a research reactor facility generating more than 2 MW of power should also be furnished with the SPDS for emergency preparedness. Generally, a research reactor is a small size facility, and its number of instrumentations is fewer than that of NPPs. In particular, it is actually hard to have various and powerful functions from an economic perspective. Therefore, a safety parameter display system optimized for a research reactor facility must be proposed. This paper provides the requirement analysis results and proposes the design of safety parameter monitoring function for a research reactor. The safety parameter monitoring function supporting control room personnel during emergency conditions should be designed in a research reactor facility. The facility size and number of signals are smaller than that of the power plants. Also, it is actually hard to have various and powerful functions of nuclear power plants from an economic perspective. Thus, a safety parameter display system optimized to a research reactor must be proposed. First, we found important design items

  9. Descriptions and models of safety functions - a prestudy

    International Nuclear Information System (INIS)

    Harms-Ringdahl, L.

    1999-09-01

    A study has been made with the focus on different theories and applications concerning 'safety functions' and 'barriers'. In this report, a safety function is defined as a technical or organisational function with the aim to reduce probability and/or consequences associated with a hazard. The study contains a limited review of practice and theories related to safety, with a focus on applications from nuclear and industrial safety. The study is based on a literature review and interviews. A summary has been made of definitions and terminology, which shows a large variation. E.g. 'barrier' can have a precise physical and technical meaning, or it can include human, technical and organisational elements. Only a few theoretical models describing safety functions have been found. One section of the report summarises problems related to safety issues and procedures. They concern errors in procedure design and user compliance. A proposal for describing and structuring safety functions has been made. Dimensions in a description could be degree of abstraction, systems level, the different parts of the function, etc. A model for safety functions has been proposed, which includes the division of a safety function in a number connected 'safety function elements'. One conclusion is that there is a potential for improving theories and tools for safety work and procedures. Safety function could be a useful concept in such a development, and advantages and disadvantages with this is discussed. If further work should be done, it is recommended that this is made as a combination of theoretical analysis and case studies

  10. Safety system status monitoring

    International Nuclear Information System (INIS)

    Lewis, J.R.; Morgenstern, M.H.; Rideout, T.H.; Cowley, P.J.

    1984-03-01

    The Pacific Northwest Laboratory has studied the safety aspects of monitoring the preoperational status of safety systems in nuclear power plants. The goals of the study were to assess for the NRC the effectiveness of current monitoring systems and procedures, to develop near-term guidelines for reducing human errors associated with monitoring safety system status, and to recommend a regulatory position on this issue. A review of safety system status monitoring practices indicated that current systems and procedures do not adequately aid control room operators in monitoring safety system status. This is true even of some systems and procedures installed to meet existing regulatory guidelines (Regulatory Guide 1.47). In consequence, this report suggests acceptance criteria for meeting the functional requirements of an adequate system for monitoring safety system status. Also suggested are near-term guidelines that could reduce the likelihood of human errors in specific, high-priority status monitoring tasks. It is recommended that (1) Regulatory Guide 1.47 be revised to address these acceptance criteria, and (2) the revised Regulatory Guide 1.47 be applied to all plants, including those built since the issuance of the original Regulatory Guide

  11. Safety system status monitoring

    Energy Technology Data Exchange (ETDEWEB)

    Lewis, J.R.; Morgenstern, M.H.; Rideout, T.H.; Cowley, P.J.

    1984-03-01

    The Pacific Northwest Laboratory has studied the safety aspects of monitoring the preoperational status of safety systems in nuclear power plants. The goals of the study were to assess for the NRC the effectiveness of current monitoring systems and procedures, to develop near-term guidelines for reducing human errors associated with monitoring safety system status, and to recommend a regulatory position on this issue. A review of safety system status monitoring practices indicated that current systems and procedures do not adequately aid control room operators in monitoring safety system status. This is true even of some systems and procedures installed to meet existing regulatory guidelines (Regulatory Guide 1.47). In consequence, this report suggests acceptance criteria for meeting the functional requirements of an adequate system for monitoring safety system status. Also suggested are near-term guidelines that could reduce the likelihood of human errors in specific, high-priority status monitoring tasks. It is recommended that (1) Regulatory Guide 1.47 be revised to address these acceptance criteria, and (2) the revised Regulatory Guide 1.47 be applied to all plants, including those built since the issuance of the original Regulatory Guide.

  12. Design of an artificial intelligence system for safety function maintenance

    International Nuclear Information System (INIS)

    Sharma, D.D.; Miller, D.W.; Chandrasekaran, B.

    1985-01-01

    The safety function (SF) maintenance concept provides a systematic approach to mitigate the consequences of an unforeseen event. Safety functions are a set of actions for mitigating or limiting consequences of a safety threatening event. The current approach to SF maintenance of selecting a success path (SP) from a library of predefined SPs is inadequate because it includes only anticipated modes of challenging an SF. To cover all possible modes of challenging an SF, the library of success paths would be extremely large and difficult to implement on any existing computer. In this paper the authors describe a method based on artificial intelligence (AI) theory of planning to synthesize an SP using available resources to satisfy a hierarchy of safety goals. The method has been applied to SF maintenance of a boiling water reactor (BWR) using data from the Perry nuclear power plant

  13. Operation safety of complex industrial systems. Main concepts

    International Nuclear Information System (INIS)

    Zwingelstein, G.

    2009-01-01

    Operation safety consists in knowing, evaluating, foreseeing, measuring and mastering the technological system and human failures in order to avoid their impacts on health and people's safety, on productivity, and on the environment, and to preserve the Earth's resources. This article recalls the main concepts of operation safety: 1 - evolutions in the domain; 2 - failures, missions and functions of a system and of its components: functional failure, missions and functions, industrial processes, notions of probability; 3 - basic concepts and operation safety: reliability, unreliability, failure density, failure rate, relations between them, availability, maintainability, safety. (J.S.)

  14. Wind Turbine Generator System Safety and Function Test Report for the Southwest Windpower H40 Wind Turbine

    Energy Technology Data Exchange (ETDEWEB)

    van Dam, J.; Link, H.; Meadors, M.; Bianchi, J.

    2002-06-01

    The objective of this test was to evaluate the safety and function characteristics of the Whisper H40 wind turbine. The general requirements of wind turbine safety and function tests are defined in the IEC standard WT01. The testing was conducted in accordance with the National Wind Technology Center (NWTC) Quality Assurance System, including the NWTC Certification Team Certification Quality Manual and the NWTC Certification Team General Quality Manual for the Testing of Wind Turbines, as well as subordinate documents. This safety and function test was performed as part of the U.S. Department of Energy's Field Verification Program for small wind turbines.

  15. Can we use IEC 61850 for safety related functions?

    Directory of Open Access Journals (Sweden)

    Luca Rocca

    2016-08-01

    Full Text Available Safety is an essential issue for processes that present high risk for human beings and environment. An acceptable level of risk is obtained both with actions on the process itself (risk reduction and with the use of special safety systems that switch the process into safe mode when a fault or an abnormal operation mode happens. These safety systems are today based on digital devices that communicate through digital networks. The IEC 61508 series specifies the safety requirements of all the devices that are involved in a safety function, including the communication network. Also electrical generation and distribution systems are processes that may have a significant level of risk, so the criteria stated by the IEC 61508 applies. Starting from this consideration, the paper analyzes the safety requirement for the communication network and compare them with the services of the communication protocol IEC 61850 that represents the most used protocol for automation of electrical plants. The goal of this job is to demonstrate that, from the technical point of view, IEC 61850 can be used for implementing safety-related functions, even if a formal safety certification is still missing.

  16. Modem Communications Systems Development Guidelines in Function of Air Traffic Safety ...

    Directory of Open Access Journals (Sweden)

    Petar Obradović

    2007-05-01

    Full Text Available The communications requirements in air traffic control areincreasing in complexity. From the middle 90s, huge progress inairport infrastructure, especially in air traffic control systems,has been made in Bosnia and Herzegovina in damage rehabilitation,caused by war conflicts, owing, first of all, to the EuropeanUnion aid that contributed to the re-establishment of regularinternational air traffic. The current air traffic control systemhas matured in its functionality. Therefore, the phase of advancementand preparation for the technological improvementis the next logical step. However, before establishing a new communicationsstrategy, the current application trends have to beanalyzed in details according to the existing communicationsenvironment interfaces. The goal of this work is to find theguidelines of technological development that will result in moreefficiency, safety and economic benefit in the near future, butthe air traffic safety must not be compromised by economicbenefit.

  17. Intermediate probabilistic safety assessment approach for safety critical digital systems

    International Nuclear Information System (INIS)

    Taeyong, Sung; Hyun Gook, Kang

    2001-01-01

    Even though the conventional probabilistic safety assessment methods are immature for applying to microprocessor-based digital systems, practical needs force to apply it. In the Korea, UCN 5 and 6 units are being constructed and Korean Next Generation Reactor is being designed using the digital instrumentation and control equipment for the safety related functions. Korean regulatory body requires probabilistic safety assessment. This paper analyzes the difficulties on the assessment of digital systems and suggests an intermediate framework for evaluating their safety using fault tree models. The framework deals with several important characteristics of digital systems including software modules and fault-tolerant features. We expect that the analysis result will provide valuable design feedback. (authors)

  18. Transient management using the safety function approach

    International Nuclear Information System (INIS)

    Corcoran, W.R.; Barrow, J.H.; Bischoff, G.C.; Callaghan, V.M.; Pearce, R.T.

    1984-01-01

    The safety function approach is described. Its use in the development of a transient management procedures system includes optimal recovery procedures tailored to specific, anticipated symptom sets and a functional recovery procedure which is more general. Simulator evaluations are described

  19. Functional safety requirements of the propulsion and power supply equipment of the MAGLEV system; Umgang mit funktionalen Sicherheitsanforderungen bei Antrieb und Energieversorgung der Magnetbahn

    Energy Technology Data Exchange (ETDEWEB)

    Stephan, A. [IFB Inst. fuer Bahntechnik GmbH, Dresden (Germany)

    2008-07-01

    In the Transrapid high-speed MAGLEV railway system, the operating control subsystem provides for the higher-level safety function. Within the system also selected components of the stationary linear-motor drive have important safety functions. Under the approval procedure, the safety-relevant functions must be certified. This makes specific requirements on the development and integration of the components used. (orig.)

  20. Safety parameter display system for Kalinin NPP

    International Nuclear Information System (INIS)

    Andreev, V.I.; Videneev, E.N.; Tissot, J.C.; Joonekindt, D.; Davidenko, N.N.; Shaftan, G.I.; Dounaev, V.G.; Neboyan, V.T.

    1995-01-01

    The paper discusses the safety parameter display system (SPDS), which is being designed for Kalinin NPP. The assessment of the safety status of the plant is done by the continuous monitoring of six critical safety functions and the corresponding status trees. Besides, a number of additional functions are realized within the scope of KlnNPP, aimed at providing the operator and the safety engineer in the main control room with more detailed information in accidental situation as well as during the normal operation. In particular, these functions are: archiving, data logs and alarm handling, safety actions monitoring, mnemonic diagrams indicating the state of main technological equipment and basic plant parameters, reference data, etc. As compared with the traditional scope of functions of this kind of systems, the functionality of KlnNPP SPDS is significantly expanded due to the inclusion in it the operator support function ''computerized procedures''. The basic SPDS implementation platform is ADACS of SEMA GROUP design. The system architecture includes two workstations in the main control room: one is for reactor operator and the other one for safety engineer. Every station has two CRT screens which ensures computerized procedures implementation and provides for extra services for the operator. Also, the information from the SPDS is transmitted to the local crisis center and to the crisis center of the State utility organization concern ''Rosenergoatom''. (author). 3 refs, 6 figs, 1 tab

  1. Development of a safety parameter supervision system for Angra-1

    International Nuclear Information System (INIS)

    Silva, R.A. da; Thome Filho, Z.D.; Schirru, R.; Martinez, A.S.; Oliveira, L.F.S. de

    1986-01-01

    The Safety Parameter Supervision System (SSPS) which is a computerized system for monitoring essential parameters in real time, determining the safety status and emergency procedures for returning normal reactor operation, in case of an anomaly occurrence, is presented. The SSPS consists of three sub-systems: Integrated parameter monitoring system which gives to operators an integrated vision of values of a parameter set, able to detect any deviation of normal reactor operation; safety critical function system which evaluates safety status in terms of a safety critical function set appointed in advance, and in case of violation of any critical function, it initiates the adequate emergency procedure to return normal operation; and safety parameter computer system which carries out the arquirement of analogic and digital control signals of nuclear power plant. (M.C.K.) [pt

  2. Segmentation Scheme for Safety Enhancement of Engineered Safety Features Component Control System

    International Nuclear Information System (INIS)

    Lee, Sangseok; Sohn, Kwangyoung; Lee, Junku; Park, Geunok

    2013-01-01

    Common Caused Failure (CCF) or undetectable failure would adversely impact safety functions of ESF-CCS in the existing nuclear power plants. We propose the segmentation scheme to solve these problems. Main function assignment to segments in the proposed segmentation scheme is based on functional dependency and critical function success path by using the dependency depth matrix. The segment has functional independence and physical isolation. The segmentation structure is that prohibit failure propagation to others from undetectable failures. Therefore, the segmentation system structure has robustness to undetectable failures. The segmentation system structure has functional diversity. The specific function in the segment defected by CCF, the specific function could be maintained by diverse control function that assigned to other segments. Device level control signals and system level control signals are separated and also control signal and status signals are separated due to signal transmission paths are allocated independently based on signal type. In this kind of design, single device failure or failures on signal path in the channel couldn't result in the loss of all segmented functions simultaneously. Thus the proposed segmentation function is the design scheme that improves availability of safety functions. In conventional ESF-CCS, the single controller generates the signal to control the multiple safety functions, and the reliability is achieved by multiplication within the channel. This design has a drawback causing the loss of multiple functions due to the CCF (Common Cause Failure) and single failure Heterogeneous controller guarantees the diversity ensuring the execution of safety functions against the CCF and single failure, but requiring a lot of resources like manpower and cost. The segmentation technology based on the compartmentalization and functional diversification decreases the CCF and single failure nonetheless the identical types of controllers

  3. Segmentation Scheme for Safety Enhancement of Engineered Safety Features Component Control System

    Energy Technology Data Exchange (ETDEWEB)

    Lee, Sangseok; Sohn, Kwangyoung [Korea Reliability Technology and System, Daejeon (Korea, Republic of); Lee, Junku; Park, Geunok [Korea Atomic Energy Research Institute, Daejeon (Korea, Republic of)

    2013-05-15

    Common Caused Failure (CCF) or undetectable failure would adversely impact safety functions of ESF-CCS in the existing nuclear power plants. We propose the segmentation scheme to solve these problems. Main function assignment to segments in the proposed segmentation scheme is based on functional dependency and critical function success path by using the dependency depth matrix. The segment has functional independence and physical isolation. The segmentation structure is that prohibit failure propagation to others from undetectable failures. Therefore, the segmentation system structure has robustness to undetectable failures. The segmentation system structure has functional diversity. The specific function in the segment defected by CCF, the specific function could be maintained by diverse control function that assigned to other segments. Device level control signals and system level control signals are separated and also control signal and status signals are separated due to signal transmission paths are allocated independently based on signal type. In this kind of design, single device failure or failures on signal path in the channel couldn't result in the loss of all segmented functions simultaneously. Thus the proposed segmentation function is the design scheme that improves availability of safety functions. In conventional ESF-CCS, the single controller generates the signal to control the multiple safety functions, and the reliability is achieved by multiplication within the channel. This design has a drawback causing the loss of multiple functions due to the CCF (Common Cause Failure) and single failure Heterogeneous controller guarantees the diversity ensuring the execution of safety functions against the CCF and single failure, but requiring a lot of resources like manpower and cost. The segmentation technology based on the compartmentalization and functional diversification decreases the CCF and single failure nonetheless the identical types of

  4. Safety Review related to Commercial Grade Digital Equipment in Safety System

    International Nuclear Information System (INIS)

    Yu, Yeongjin; Park, Hyunshin; Yu, Yeongjin; Lee, Jaeheung

    2013-01-01

    The upgrades or replacement of I and C systems on safety system typically involve digital equipment developed in accordance with non-nuclear standards. However, the use of commercial grade digital equipment could include the vulnerability for software common-mode failure, electromagnetic interference and unanticipated problems. Although guidelines and standards for dedication methods of commercial grade digital equipment are provided, there are some difficulties to apply the methods to commercial grade digital equipment for safety system. This paper focuses on regulatory guidelines and relevant documents for commercial grade digital equipment and presents safety review experiences related to commercial grade digital equipment in safety system. This paper focuses on KINS regulatory guides and relevant documents for dedication of commercial grade digital equipment and presents safety review experiences related to commercial grade digital equipment in safety system. Dedication including critical characteristics is required to use the commercial grade digital equipment on safety system in accordance with KEPIC ENB 6370 and EPRI TR-106439. The dedication process should be controlled in a configuration management process. Appropriate methods, criteria and evaluation result should be provided to verify acceptability of the commercial digital equipment used for safety function

  5. Integration of the functional reliability of two passive safety systems to mitigate a SBLOCA+BO in a CAREM-like reactor PSA

    Energy Technology Data Exchange (ETDEWEB)

    Mezio, Federico, E-mail: federico.mezio@cab.cnea.gov.ar [CNEA, Sede Central, Av. Del Libertador 8250, CABA (Argentina); Grinberg, Mariela [CNEA, Centro Atómico Bariloche, S.C. de Bariloche, Río Negro (Argentina); Lorenzo, Gabriel [CNEA, Sede Central, Av. Del Libertador 8250, CABA (Argentina); Giménez, Marcelo [CNEA, Centro Atómico Bariloche, S.C. de Bariloche, Río Negro (Argentina)

    2014-04-01

    Highlights: • An estimation of the Functional Unreliability was performed using RMPS methodology. • The methodology uses an improved response surface in order to estimate the FU. • The FU may become relevant to be analyzed in the Passive Safety Systems. • There were proposed two ways to incorporate the FU into an APS. - Abstract: This paper describes a case study of a methodological approach for assessing the functional reliability of passive safety systems (PSS) and its treatment within a probabilistic safety assessment (PSA). The functional unreliability (FU) can be understood as the failure probability of PSS to fulfill its mission due to the impairment of the related passive safety function. The safety function accomplishment is characterized and quantified by a performance indicator (PI), which is a measure of how far the system is from verifying its mission. PI uncertainties are estimated from uncertainty propagation of selected parameters. A methodology based on the reliability methodology for passive system (RMPS) one is used to estimate the FU associated to the isolation condensers (ICs) in combination with the accumulators (medium pressure injection system) of a CAREM-like integral advanced reactor. A small break loss of coolant accident with black-out is selected as an evaluation case. This implies success of reactor shut-down (inherent) and failure of residual heat removal by active systems. The safety function to accomplish is to refill the reactor pressure vessel (RPV) in order to avoid core damage. For this case, to allow the discharge of accumulators into RPV, the pressure must be reduced by the IC. The methodology for passive safety function assessment considers uncertainties in code parameters, besides uncertainties in engineering parameters (design, construction, operation and maintenance), in order to perform Monte Carlo simulations based on best estimate (B-E) plant model. Then, response surfaces based on PI are used for improving the

  6. IR-360 nuclear power plant safety functions and component classification

    International Nuclear Information System (INIS)

    Yousefpour, F.; Shokri, F.; Soltani, H.

    2010-01-01

    The IR-360 nuclear power plant as a 2-loop PWR of 360 MWe power generation capacity is under design in MASNA Company. For design of the IR-360 structures, systems and components (SSCs), the codes and standards and their design requirements must be determined. It is a prerequisite to classify the IR-360 safety functions and safety grade of structures, systems and components correctly for selecting and adopting the suitable design codes and standards. This paper refers to the IAEA nuclear safety codes and standards as well as USNRC standard system to determine the IR-360 safety functions and to formulate the principles of the IR-360 component classification in accordance with the safety philosophy and feature of the IR-360. By implementation of defined classification procedures for the IR-360 SSCs, the appropriate design codes and standards are specified. The requirements of specific codes and standards are used in design process of IR-360 SSCs by design engineers of MASNA Company. In this paper, individual determination of the IR-360 safety functions and definition of the classification procedures and roles are presented. Implementation of this work which is described with example ensures the safety and reliability of the IR-360 nuclear power plant.

  7. IR-360 nuclear power plant safety functions and component classification

    Energy Technology Data Exchange (ETDEWEB)

    Yousefpour, F., E-mail: fyousefpour@snira.co [Management of Nuclear Power Plant Construction Company (MASNA) (Iran, Islamic Republic of); Shokri, F.; Soltani, H. [Management of Nuclear Power Plant Construction Company (MASNA) (Iran, Islamic Republic of)

    2010-10-15

    The IR-360 nuclear power plant as a 2-loop PWR of 360 MWe power generation capacity is under design in MASNA Company. For design of the IR-360 structures, systems and components (SSCs), the codes and standards and their design requirements must be determined. It is a prerequisite to classify the IR-360 safety functions and safety grade of structures, systems and components correctly for selecting and adopting the suitable design codes and standards. This paper refers to the IAEA nuclear safety codes and standards as well as USNRC standard system to determine the IR-360 safety functions and to formulate the principles of the IR-360 component classification in accordance with the safety philosophy and feature of the IR-360. By implementation of defined classification procedures for the IR-360 SSCs, the appropriate design codes and standards are specified. The requirements of specific codes and standards are used in design process of IR-360 SSCs by design engineers of MASNA Company. In this paper, individual determination of the IR-360 safety functions and definition of the classification procedures and roles are presented. Implementation of this work which is described with example ensures the safety and reliability of the IR-360 nuclear power plant.

  8. A study to develop the domestic functional requirements of the specific safety systems of CANDU

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Man Woong [Korea Institute of Nuclear Safety, Taejon (Korea, Republic of); Lee, Jae Young; Park, Kun Chul [Handong Global Univ., Pohang (Korea, Republic of)] (and others)

    2003-03-15

    The present research has been made to develop and review critically the functional requirements of the specific safety systems of CANDU such as SDS-1, SDS2, ECCS, and containment. Based on R documents for this, a systematic study was made to develop the domestic regulation statements. Also, the conventional laws are carefully reviewed to see the compatibility to CANDU. Also, the safety assessment method for CANDU was studied by reviewing C documents and recommendation of IAEA. Through the present works, the vague policy in the CANDU safety regulation is cleaning up in a systematic form and a new frame to measure the objective risk of nuclear power plants was developed.

  9. A study to develop the domestic functional requirements of the specific safety systems of CANDU

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Man Woong; Lee, Jae Young; Bang, Kwang Hyun [Handong Global Univ., Pohang (Korea, Republic of)] (and others)

    2001-03-15

    The present research has been made to develop and review critically the functional requirements of the specific safety systems of CANDU such as SOS-1, SOS-2, ECCS and containment. Based on R documents for this, a systematic study was made to develop the domestic regulation statements. Also, the conventional laws are carefully reviewed to see the compatibility to CANDU. Also, the safety assessment method for CANDU was studied by reviewing C documents and recommendation of IAEA. Through the present works, the vague policy in the CANDU safety regulation is cleaning up in a systematic form and a new frame to measure the objective risk of nuclear power plants was developed.

  10. Analysis and design on airport safety information management system

    Directory of Open Access Journals (Sweden)

    Yan Lin

    2017-01-01

    Full Text Available Airport safety information management system is the foundation of implementing safety operation, risk control, safety performance monitor, and safety management decision for the airport. The paper puts forward the architecture of airport safety information management system based on B/S model, focuses on safety information processing flow, designs the functional modules and proposes the supporting conditions for system operation. The system construction is helpful to perfecting the long effect mechanism driven by safety information, continually increasing airport safety management level and control proficiency.

  11. Design an optimum safety policy for personnel safety management - A system dynamic approach

    International Nuclear Information System (INIS)

    Balaji, P.

    2014-01-01

    Personnel safety management (PSM) ensures that employee's work conditions are healthy and safe by various proactive and reactive approaches. Nowadays it is a complex phenomenon because of increasing dynamic nature of organisations which results in an increase of accidents. An important part of accident prevention is to understand the existing system properly and make safety strategies for that system. System dynamics modelling appears to be an appropriate methodology to explore and make strategy for PSM. Many system dynamics models of industrial systems have been built entirely for specific host firms. This thesis illustrates an alternative approach. The generic system dynamics model of Personnel safety management was developed and tested in a host firm. The model was undergone various structural, behavioural and policy tests. The utility and effectiveness of model was further explored through modelling a safety scenario. In order to create effective safety policy under resource constraint, DOE (Design of experiment) was used. DOE uses classic designs, namely, fractional factorials and central composite designs. It used to make second order regression equation which serve as an objective function. That function was optimized under budget constraint and optimum value used for safety policy which shown greatest improvement in overall PSM. The outcome of this research indicates that personnel safety management model has the capability for acting as instruction tool to improve understanding of safety management and also as an aid to policy making

  12. Design an optimum safety policy for personnel safety management - A system dynamic approach

    Energy Technology Data Exchange (ETDEWEB)

    Balaji, P. [The Glocal University, Mirzapur Pole, Delhi- Yamuntori Highway, Saharanpur 2470001 (India)

    2014-10-06

    Personnel safety management (PSM) ensures that employee's work conditions are healthy and safe by various proactive and reactive approaches. Nowadays it is a complex phenomenon because of increasing dynamic nature of organisations which results in an increase of accidents. An important part of accident prevention is to understand the existing system properly and make safety strategies for that system. System dynamics modelling appears to be an appropriate methodology to explore and make strategy for PSM. Many system dynamics models of industrial systems have been built entirely for specific host firms. This thesis illustrates an alternative approach. The generic system dynamics model of Personnel safety management was developed and tested in a host firm. The model was undergone various structural, behavioural and policy tests. The utility and effectiveness of model was further explored through modelling a safety scenario. In order to create effective safety policy under resource constraint, DOE (Design of experiment) was used. DOE uses classic designs, namely, fractional factorials and central composite designs. It used to make second order regression equation which serve as an objective function. That function was optimized under budget constraint and optimum value used for safety policy which shown greatest improvement in overall PSM. The outcome of this research indicates that personnel safety management model has the capability for acting as instruction tool to improve understanding of safety management and also as an aid to policy making.

  13. Design an optimum safety policy for personnel safety management - A system dynamic approach

    Science.gov (United States)

    Balaji, P.

    2014-10-01

    Personnel safety management (PSM) ensures that employee's work conditions are healthy and safe by various proactive and reactive approaches. Nowadays it is a complex phenomenon because of increasing dynamic nature of organisations which results in an increase of accidents. An important part of accident prevention is to understand the existing system properly and make safety strategies for that system. System dynamics modelling appears to be an appropriate methodology to explore and make strategy for PSM. Many system dynamics models of industrial systems have been built entirely for specific host firms. This thesis illustrates an alternative approach. The generic system dynamics model of Personnel safety management was developed and tested in a host firm. The model was undergone various structural, behavioural and policy tests. The utility and effectiveness of model was further explored through modelling a safety scenario. In order to create effective safety policy under resource constraint, DOE (Design of experiment) was used. DOE uses classic designs, namely, fractional factorials and central composite designs. It used to make second order regression equation which serve as an objective function. That function was optimized under budget constraint and optimum value used for safety policy which shown greatest improvement in overall PSM. The outcome of this research indicates that personnel safety management model has the capability for acting as instruction tool to improve understanding of safety management and also as an aid to policy making.

  14. Nuclear reactor safety system

    International Nuclear Information System (INIS)

    Ball, R.M.; Roberts, R.C.

    1983-01-01

    The invention provides a safety system for a nuclear reactor which uses a parallel combination of computer type look-up tables each of which receives data on a particular parameter (from transducers located in the reactor system) and each of which produces the functional counterpart of that particular parameter. The various functional counterparts are then added together to form a control signal for shutting down the reactor. The functional counterparts are developed by analysis of experimental thermal and hydraulic data, which are used to form expressions that define safe conditions

  15. Functional capability of piping systems

    International Nuclear Information System (INIS)

    Terao, D.; Rodabaugh, E.C.

    1992-11-01

    General Design Criterion I of Appendix A to Part 50 of Title 10 of the Code of Federal Regulations requires, in part, that structures, systems, and components important to safety be designed to withstand the effects of earthquakes without a loss of capability to perform their safety function. ne function of a piping system is to convey fluids from one location to another. The functional capability of a piping system might be lost if, for example, the cross-sectional flow area of the pipe were deformed to such an extent that the required flow through the pipe would be restricted. The objective of this report is to examine the present rules in the American Society of Mechanical Engineers Boiler and Pressure Vessel Code, Section III, and potential changes to these rules, to determine if they are adequate for ensuring the functional capability of safety-related piping systems in nuclear power plants

  16. Safety systems and features of boiling and pressurized water reactors

    International Nuclear Information System (INIS)

    Khair, H. O. M.

    2012-06-01

    The safe operation of nuclear power plants (NPP) requires a deep understanding of the functioning of physical processes and systems involved. This study was carried out to present an overview of the features of safety systems of boiling and pressurized water reactors that are available commercially. Brief description of purposes and functions of the various safety systems that are employed in these reactors was discussed and a brief comparison between the safety systems of BWRs and PWRs was made in an effort to emphasize of safety in NPPs.(Author)

  17. Selection and verification of safety parameters in safety parameter display system for nuclear power plants

    International Nuclear Information System (INIS)

    Zhang Yuangfang

    1992-02-01

    The method and results for safety parameter selection and its verification in safety parameter display system of nuclear power plants are introduced. According to safety analysis, the overall safety is divided into six critical safety functions, and a certain amount of safety parameters which can represent the integrity degree of each function and the causes of change are strictly selected. The verification of safety parameter selection is carried out from the view of applying the plant emergency procedures and in the accident man oeuvres on a full scale nuclear power plant simulator

  18. Preliminary investigation on reliability assessment of passive safety system

    International Nuclear Information System (INIS)

    Huang Changfan; Kuang Bo

    2012-01-01

    The reliability evaluation of passive safety system plays an important part in probabilistic safety assessment (PSA) of nuclear power plant applying passive safety design, which depends quantitatively on reliabilities of passive safety system. According to the object of reliability assessment of passive safety system, relevant parameters are identified. Then passive system behavior during accident scenarios are studied. A practical example of this method is given for the case of reliability assessment of AP1000 passive heat removal system in loss of normal feedwater accident. Key and design parameters of PRHRS are identified and functional failure criteria are established. Parameter combinations acquired by Latin hyper~ cube sampling (LHS) in possible parametric ranges are input and calculations of uncertainty propagation through RELAP5/MOD3 code are carried out. Based on the calculations, sensitivity assessment on PRHRS functional criteria and reliability evaluation of the system are presented, which might provide further PSA with PRHR system reliability. (authors)

  19. Development of web-based safety review advisory system

    International Nuclear Information System (INIS)

    Kim, M. W.; Lee, H. C.; Park, S. O.; Lee, K. H.; Hur, K. Y.; Lee, S. J.; Choi, S. S.; Kang, C. M.

    2002-01-01

    For the development of an expert system supporting the safety review of nuclear power plants, the application was implemented after gathering necessary theoretical background and practical requirements. The general and the detail functional specifications were established, and they are investigated by KINS (Korea Institute of Nuclear Safety). The Safety Review Advisory System(SRAS), this application on web-server environment was developed according to the above specifications. Reviews can do their safety reviewing regardless of their speciality or reviewing experiences because SRAS is operated by the safety review plans which are converted to standardized format. When the safety reviewing is carried out by using SRAS, the results of safety reviewing are accumulated in the database and may be utilized later usefully, and we can grasp safety reviewing progress. Users of SRAS are categorized into four groups, administrator, project manager, project reviewer and general reviewer. Each user group is delegated appropriate access capability. The function and some screen shots of SRAS are described

  20. Intelligent monitoring-based safety system of massage robot

    Institute of Scientific and Technical Information of China (English)

    胡宁; 李长胜; 王利峰; 胡磊; 徐晓军; 邹雲鹏; 胡玥; 沈晨

    2016-01-01

    As an important attribute of robots, safety is involved in each link of the full life cycle of robots, including the design, manufacturing, operation and maintenance. The present study on robot safety is a systematic project. Traditionally, robot safety is defined as follows: robots should not collide with humans, or robots should not harm humans when they collide. Based on this definition of robot safety, researchers have proposed ex ante and ex post safety standards and safety strategies and used the risk index and risk level as the evaluation indexes for safety methods. A massage robot realizes its massage therapy function through applying a rhythmic force on the massage object. Therefore, the traditional definition of safety, safety strategies, and safety realization methods cannot satisfy the function and safety requirements of massage robots. Based on the descriptions of the environment of massage robots and the tasks of massage robots, the present study analyzes the safety requirements of massage robots; analyzes the potential safety dangers of massage robots using the fault tree tool; proposes an error monitoring-based intelligent safety system for massage robots through monitoring and evaluating potential safety danger states, as well as decision making based on potential safety danger states; and verifies the feasibility of the intelligent safety system through an experiment.

  1. Study on 'Safety qualification of process computers used in safety systems of nuclear power plants'

    International Nuclear Information System (INIS)

    Bertsche, K.; Hoermann, E.

    1991-01-01

    The study aims at developing safety standards for hardware and software of computer systems which are increasingly used also for important safety systems in nuclear power plants. The survey of the present state-of-the-art of safety requirements and specifications for safety-relevant systems and, additionally, for process computer systems has been compiled from national and foreign rules. In the Federal Republic of Germany the KTA safety guides and the BMI/BMU safety criteria have to be observed. For the design of future computer-aided systems in nuclear power plants it will be necessary to apply the guidelines in [DIN-880] and [DKE-714] together with [DIN-192]. With the aid of a risk graph the various functions of a system, or of a subsystem, can be evaluated with regard to their significance for safety engineering. (orig./HP) [de

  2. Design of integrated passive safety system (IPSS) for ultimate passive safety of nuclear power plants

    International Nuclear Information System (INIS)

    Chang, Soon Heung; Kim, Sang Ho; Choi, Jae Young

    2013-01-01

    Highlights: • We newly propose the design concept of integrated passive safety system (IPSS). • It has five safety functions for decay heat removal and severe accident mitigation. • Simulations for IPSS show that core melt does not occur in accidents with SBO. • IPSS can achieve the passive in-vessel retention and ex-vessel cooling strategy. • The applicability of IPSS is high due to the installation outside the containment. -- Abstract: The design concept of integrated passive safety system (IPSS) which can perform various passive safety functions is proposed in this paper. It has the various functions of passive decay heat removal system, passive safety injection system, passive containment cooling system, passive in-vessel retention and cavity flooding system, and filtered venting system with containment pressure control. The objectives of this paper are to propose the conceptual design of an IPSS and to estimate the design characters of the IPSS with accident simulations using MARS code. Some functions of the IPSS are newly proposed and the other functions are reviewed with the integration of the functions. Consequently, all of the functions are modified and integrated for simplicity of the design in preparation for beyond design based accidents (BDBAs) focused on a station black out (SBO). The simulation results with the IPSS show that the decay heat can be sufficiently removed in accidents that occur with a SBO. Also, the molten core can be retained in a vessel via the passive in-vessel retention strategy of the IPSS. The actual application potential of the IPSS is high, as numerous strong design characters are evaluated. The installation of the IPSS into the original design of a nuclear power plant requires minimal design change using the current penetrations of the containment. The functions are integrated in one or two large tanks outside the containment. Furthermore, the operation time of the IPSS can be increased by refilling coolant from the

  3. Nuclear reactor safety systems

    International Nuclear Information System (INIS)

    Ball, R.M.; Roberts, R.C.

    1980-01-01

    A safety system for shutting down a nuclear reactor under overload conditions is described. The system includes a series of parallel-connected computer memory type look-up tables each of which receives data on a particular reactor parameter and in each of which a precalculated functional value for that parameter is stored indicative of the percentage of maximum reactor load that the parameter contributes. The various functional values corresponding to the actual measured parameters are added together to provide a control signal used to shut down the reactor under overload conditions. (U.K.)

  4. Development of web-based safety review advisory system

    International Nuclear Information System (INIS)

    Kim, M. W.; Hur, K. Y.; Lee, S. J.; Choi, S. J.

    2002-01-01

    For the development of an expert system supporting the safety review of nuclear power plants, the application was implemented after gathering necessary theoretical background and practical requirements. The general and the detail functional specifications were established, and they are investigated by KINS. Safety Review Advisory System (SRAS), this application on web-server environment was developed according to the above specifications. Reviews can do their safety reviewing regardless of their speciality or reviewing experiences because SRAS is operated by the safety review plans which are converted to standardized format. When the safety reviewing is carried out by using SRAS, the results of safety reviewing are accumulated in the database and may be utilized later usefully, and we can grasp safety reviewing progress. Users of SRAS are categorized into four groups, administrator, project manager, project reviewer and general reviewer. Each user group is delegated appropriate access capability. The function and some screen shots of SRAS are described

  5. Cost benefit analysis of reactor safety systems

    International Nuclear Information System (INIS)

    Maurer, H.A.

    1984-01-01

    Cost/benefit analysis of reactor safety systems is a possibility appropriate to deal with reactor safety. The Commission of the European Communities supported a study on the cost-benefit or cost effectiveness of safety systems installed in modern PWR nuclear power plants. The following systems and their cooperation in emergency cases were in particular investigated in this study: the containment system (double containment), the leakage exhaust and control system, the annulus release exhaust system and the containment spray system. The benefit of a safety system is defined according to its contribution to the reduction of the radiological consequences for the environment after a LOCA. The analysis is so far performed in two different steps: the emergency core cooling system is considered to function properly, failure of the emergency core cooling system is assumed (with the possible consequence of core melt-down) and the results may demonstrate the evidence that striving for cost-effectiveness can produce a safer end result than the philosophy of safety at any cost. (orig.)

  6. Reliability analysis of software based safety functions

    International Nuclear Information System (INIS)

    Pulkkinen, U.

    1993-05-01

    The methods applicable in the reliability analysis of software based safety functions are described in the report. Although the safety functions also include other components, the main emphasis in the report is on the reliability analysis of software. The check list type qualitative reliability analysis methods, such as failure mode and effects analysis (FMEA), are described, as well as the software fault tree analysis. The safety analysis based on the Petri nets is discussed. The most essential concepts and models of quantitative software reliability analysis are described. The most common software metrics and their combined use with software reliability models are discussed. The application of software reliability models in PSA is evaluated; it is observed that the recent software reliability models do not produce the estimates needed in PSA directly. As a result from the study some recommendations and conclusions are drawn. The need of formal methods in the analysis and development of software based systems, the applicability of qualitative reliability engineering methods in connection to PSA and the need to make more precise the requirements for software based systems and their analyses in the regulatory guides should be mentioned. (orig.). (46 refs., 13 figs., 1 tab.)

  7. Analyzing Software Requirements Errors in Safety-Critical, Embedded Systems

    Science.gov (United States)

    Lutz, Robyn R.

    1993-01-01

    This paper analyzes the root causes of safety-related software errors in safety-critical, embedded systems. The results show that software errors identified as potentially hazardous to the system tend to be produced by different error mechanisms than non- safety-related software errors. Safety-related software errors are shown to arise most commonly from (1) discrepancies between the documented requirements specifications and the requirements needed for correct functioning of the system and (2) misunderstandings of the software's interface with the rest of the system. The paper uses these results to identify methods by which requirements errors can be prevented. The goal is to reduce safety-related software errors and to enhance the safety of complex, embedded systems.

  8. Nuclear power plant systems, structures and components and their safety classification

    International Nuclear Information System (INIS)

    2000-01-01

    The assurance of a nuclear power plant's safety is based on the reliable functioning of the plant as well as on its appropriate maintenance and operation. To ensure the reliability of operation, special attention shall be paid to the design, manufacturing, commissioning and operation of the plant and its components. To control these functions the nuclear power plant is divided into structural and functional entities, i.e. systems. A systems safety class is determined by its safety significance. Safety class specifies the procedures to be employed in plant design, construction, monitoring and operation. The classification document contains all documentation related to the classification of the nuclear power plant. The principles of safety classification and the procedures pertaining to the classification document are presented in this guide. In the Appendix of the guide, examples of systems most typical of each safety class are given to clarify the safety classification principles

  9. Technical features of ABWR safety systems

    International Nuclear Information System (INIS)

    Sugisaki, Toshihiko; Tominaga, Kenji; Horiuchi, Tetsuo

    1986-01-01

    The engineering safety facilities of ABWRs have been disigned so as to have many excellent characteristics such as safety, reliability and economy, reflecting the merit of adopting new technology such as internal pumps and new control rod driving mechanism, and coupled with the safety peculiar to BWRs. In this paper, about ECCS, containment vessels and others which compose the engineering safety facilities of ABWRs, the characteristics related to the safety owing to the adoption of internal pumps and others, and the evaluation of the performance at the time of various accidents are discussed. As the results of safety evaluation, it was clarified that due to the safety peculiar to ABWRs and the characteristics of the safety facilities, the large increases of safety, reliability and economy have been planned in the ABWRs, and for example, core flooding can be maintained even at the time of a hypothetical loss of coolant accident. BWRs have the simple system constitution, good self controllability, large natural circulation ability, simple operation control method and excellent ability of confining heat and radioactivity. BWRs have three safety functions to stop reactors, to remove heat from reactors, and to confine radioactive substances. These functions of ABWRs were evaluated, and very high safety was confirmed. (Kako, I.)

  10. Safety Evaluation Approach with Security Controls for Safety I and C Systems on Nuclear Power Plants

    International Nuclear Information System (INIS)

    Kim, D. H.; Jeong, S. Y.; Kim, Y. M.; Park, H. S.; Lee, M. S.; Kim, T. H.

    2016-01-01

    This paper addresses concepts of safety and security and relations between them for assessing effects of security features in safety systems. Also, evaluation approach for avoiding confliction with safety requirements and cyber security features which may be adopted in safety-related digital I and C system will be described. In this paper, safety-security life cycle model based confliction avoidance method was proposed to evaluate the effects when the cyber security control features are implemented in the safety I and C system. Also, safety effect evaluation results using the proposed evaluation method were described. In case of technical security controls, many of them are expected to conflict with safety requirements, otherwise operational and managerial controls are not relatively. Safety measures and cyber security measures for nuclear power plants should be implemented not to conflict with one another. Where safety function and security features are both required within the systems, and also where security features are implemented within safety systems, they should be justified

  11. Safety Evaluation Approach with Security Controls for Safety I and C Systems on Nuclear Power Plants

    Energy Technology Data Exchange (ETDEWEB)

    Kim, D. H.; Jeong, S. Y.; Kim, Y. M.; Park, H. S. [KINS, Daejeon (Korea, Republic of); Lee, M. S.; Kim, T. H. [Formal Works Inc., Seoul (Korea, Republic of)

    2016-05-15

    This paper addresses concepts of safety and security and relations between them for assessing effects of security features in safety systems. Also, evaluation approach for avoiding confliction with safety requirements and cyber security features which may be adopted in safety-related digital I and C system will be described. In this paper, safety-security life cycle model based confliction avoidance method was proposed to evaluate the effects when the cyber security control features are implemented in the safety I and C system. Also, safety effect evaluation results using the proposed evaluation method were described. In case of technical security controls, many of them are expected to conflict with safety requirements, otherwise operational and managerial controls are not relatively. Safety measures and cyber security measures for nuclear power plants should be implemented not to conflict with one another. Where safety function and security features are both required within the systems, and also where security features are implemented within safety systems, they should be justified.

  12. The critical safety functions and plant operation

    International Nuclear Information System (INIS)

    Corcoran, W.R.; Church, J.F.; Porter, N.J.; Cross, M.T.; Guinn, W.M.

    1981-01-01

    The paper outlines the operator's role in nuclear safety and introduces the concept of ''safety functions''. Safety functions are a group of actions that prevent core melt or minimize radiation releases to the general public. They can be used to provide a hierarchy of practical plant protection that an operator should use. ''An accident identical to that at Three Mile Island is not going to happen again'', said the Rogovin investigators. The concepts put forward in this paper are intended to help the operator avoid serious consequence from the next unexpected threat. On the basis of the safety evaluation, the operator has three roles in assuring that the consequences of an event will be no worse than the predicted acceptable results. These three operator roles are: first, maintain plant setup in readiness to properly respond; second, operate the plant in a manner such that fewer, milder events minimize the frequency and the severity of adverse events; third, the operator needs to monitor the plant to verify that the safety functions are accomplished. The operator needs a systematic approach to mitigating the consequences of an event. The concept of ''safety function'' introduces that systematic approach and prevents a hierarchy of protection. If the operator has difficulty in identifying an event for any reason, the systematic safety function approach allows ones to accomplish the overall path of mitigating consequences. There are ten identified functions designed to protect against core melt, preserve containment integrity, prevent indirect release of radioactivity, and maintain vital auxiliaries needed to support the other safety functions. The paper describes in detail the operator's role and the safety functions, and provides many examples of the use of alternative success paths to accomplish the safety function

  13. SBO simulations for Integrated Passive Safety System (IPSS) using MARS

    International Nuclear Information System (INIS)

    Kim, Sang Ho; Jeong, Sung Yeop; Chang, Soon Heung

    2012-01-01

    The current nuclear power plants have lots of active safety systems with some passive safety systems. The safety of current and future nuclear power plants can be enhanced by the application of additional passive safety systems for the ultimate safety. It is helpful to install the passive safety systems on current nuclear power plants without the design change for the licensibility. For solving the problem about the system complexity shown in the Fukushima accidents, the current nuclear power plants are needed to be enhanced by an additional integrated and simplified system. As a previous research, the integrated passive safety system (IPSS) was proposed to solve the safety issues related with the decay heat removal, containment integrity and radiation release. It could be operated by natural phenomena like gravity, natural circulation and pressure difference without AC power. The five main functions of IPSS are: (a) Passive decay heat removal, (b) Passive emergency core cooling, (c) Passive containment cooling, (d) Passive in vessel retention and ex-vessel cooling, and (e) Filtered venting and pressure control. The purpose of this research is to analyze the performances of each function by using MARS code. The simulated accident scenarios were station black out (SBO) and the additional accidents accompanied by SBO

  14. Risk-based rules for crane safety systems

    Energy Technology Data Exchange (ETDEWEB)

    Ruud, Stian [Section for Control Systems, DNV Maritime, 1322 Hovik (Norway)], E-mail: Stian.Ruud@dnv.com; Mikkelsen, Age [Section for Lifting Appliances, DNV Maritime, 1322 Hovik (Norway)], E-mail: Age.Mikkelsen@dnv.com

    2008-09-15

    The International Maritime Organisation (IMO) has recommended a method called formal safety assessment (FSA) for future development of rules and regulations. The FSA method has been applied in a pilot research project for development of risk-based rules and functional requirements for systems and components for offshore crane systems. This paper reports some developments in the project. A method for estimating target reliability for the risk-control options (safety functions) by means of the cost/benefit decision criterion has been developed in the project and is presented in this paper. Finally, a structure for risk-based rules is proposed and presented.

  15. Risk-based rules for crane safety systems

    International Nuclear Information System (INIS)

    Ruud, Stian; Mikkelsen, Age

    2008-01-01

    The International Maritime Organisation (IMO) has recommended a method called formal safety assessment (FSA) for future development of rules and regulations. The FSA method has been applied in a pilot research project for development of risk-based rules and functional requirements for systems and components for offshore crane systems. This paper reports some developments in the project. A method for estimating target reliability for the risk-control options (safety functions) by means of the cost/benefit decision criterion has been developed in the project and is presented in this paper. Finally, a structure for risk-based rules is proposed and presented

  16. Operation safety of complex industrial systems

    International Nuclear Information System (INIS)

    Zwingelstein, G.

    1999-01-01

    Zero fault or zero risk is an unreachable goal in industrial activities like nuclear activities. However, methods and techniques exist to reduce the risks to the lowest possible and acceptable level. The operation safety consists in the recognition, evaluation, prediction, measurement and mastery of technological and human faults. This paper analyses each of these points successively: 1 - evolution of operation safety; 2 - definitions and basic concepts: failure, missions and functions of a system and of its components, basic concepts and operation safety; 3 - forecasting analysis of operation safety: reliability data, data-banks, precautions for the use of experience feedback data; realization of an operation safety study: management of operation safety, quality assurance, critical review and audit of operation safety studies; 6 - conclusions. (J.S.)

  17. Wind Turbine Generator System Safety and Function Test Report for the Entegrity EW50 Wind Turbine

    Energy Technology Data Exchange (ETDEWEB)

    Smith, J.; Huskey, A.; Jager, D.; Hur, J.

    2012-11-01

    This report summarizes the results of a safety and function test that NREL conducted on the Entegrity EW50 wind turbine. This test was conducted in accordance with the International Electrotechnical Commissions' (IEC) standard, Wind Turbine Generator System Part 2: Design requirements for small wind turbines, IEC 61400-2 Ed.2.0, 2006-03.

  18. The passive safety systems of the Swr 1000

    International Nuclear Information System (INIS)

    Neumann, D.

    2001-01-01

    In recent years, a new boiling water reactor (BWR) plant called the SWR 1000 has been developed by Siemens on behalf of Germany's electric utilities. This new plant design concept incorporates the wide range of operating experience gained with German BWRs. The main objective behind developing the SWR 1000 was to design a plant with a rated electric output of approximately 1000 MW which would not only have a lower capital cost and lower power generating costs but would also provide a much higher level of nuclear safety compared to plants currently in operation. This safety-related goal has been met through, for example, the use of passive safety equipment. Passive systems make a significant contribution towards increasing the over-all level of plant safety due to the way in which they operate. They function solely accord-ing to basic laws of nature, such as gravity, and perform their designated functions with-out any need for electric power or other sources of external energy, or signals from instrumentation and control (I and C) equipment. The passive safety systems have been designed such that design basis accidents can be controlled using just these systems alone. However, the design concept of the SWR 1000 is nevertheless still based on the provision of active safety systems in addition to passive systems. (author)

  19. Industrial Personal Computer based Display for Nuclear Safety System

    International Nuclear Information System (INIS)

    Kim, Ji Hyeon; Kim, Aram; Jo, Jung Hee; Kim, Ki Beom; Cheon, Sung Hyun; Cho, Joo Hyun; Sohn, Se Do; Baek, Seung Min

    2014-01-01

    The safety display of nuclear system has been classified as important to safety (SIL:Safety Integrity Level 3). These days the regulatory agencies are imposing more strict safety requirements for digital safety display system. To satisfy these requirements, it is necessary to develop a safety-critical (SIL 4) grade safety display system. This paper proposes industrial personal computer based safety display system with safety grade operating system and safety grade display methods. The description consists of three parts, the background, the safety requirements and the proposed safety display system design. The hardware platform is designed using commercially available off-the-shelf processor board with back plane bus. The operating system is customized for nuclear safety display application. The display unit is designed adopting two improvement features, i.e., one is to provide two separate processors for main computer and display device using serial communication, and the other is to use Digital Visual Interface between main computer and display device. In this case the main computer uses minimized graphic functions for safety display. The display design is at the conceptual phase, and there are several open areas to be concreted for a solid system. The main purpose of this paper is to describe and suggest a methodology to develop a safety-critical display system and the descriptions are focused on the safety requirement point of view

  20. Industrial Personal Computer based Display for Nuclear Safety System

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Ji Hyeon; Kim, Aram; Jo, Jung Hee; Kim, Ki Beom; Cheon, Sung Hyun; Cho, Joo Hyun; Sohn, Se Do; Baek, Seung Min [KEPCO, Youngin (Korea, Republic of)

    2014-08-15

    The safety display of nuclear system has been classified as important to safety (SIL:Safety Integrity Level 3). These days the regulatory agencies are imposing more strict safety requirements for digital safety display system. To satisfy these requirements, it is necessary to develop a safety-critical (SIL 4) grade safety display system. This paper proposes industrial personal computer based safety display system with safety grade operating system and safety grade display methods. The description consists of three parts, the background, the safety requirements and the proposed safety display system design. The hardware platform is designed using commercially available off-the-shelf processor board with back plane bus. The operating system is customized for nuclear safety display application. The display unit is designed adopting two improvement features, i.e., one is to provide two separate processors for main computer and display device using serial communication, and the other is to use Digital Visual Interface between main computer and display device. In this case the main computer uses minimized graphic functions for safety display. The display design is at the conceptual phase, and there are several open areas to be concreted for a solid system. The main purpose of this paper is to describe and suggest a methodology to develop a safety-critical display system and the descriptions are focused on the safety requirement point of view.

  1. Stabilization with guaranteed safety using Control Lyapunov–Barrier Function

    NARCIS (Netherlands)

    Romdlony, Muhammad Zakiyullah; Jayawardhana, Bayu

    2016-01-01

    We propose a novel nonlinear control method for solving the problem of stabilization with guaranteed safety for nonlinear systems. The design is based on the merging of the well-known Control Lyapunov Function (CLF) and the recent concept of Control Barrier Function (CBF). The proposed control

  2. The critical safety functions and plant operation

    International Nuclear Information System (INIS)

    Corcoran, W.R.; Church, J.F.; Cross, M.T.; Guinn, W.M.; Porter, N.J.

    1981-01-01

    The operator's role in nuclear safety is outlined and the concept of ''safety functions'' introduced. Safety functions are a group of actions that prevent core melt or minimize radiation releases to the general public. They can be used to provide a hierarchy of practical plant protection that an operator should use. The plant safety evaluation uses four inputs in predicting the results of an event: the event initiator, the plant design, the initial plant conditions and setup, and the operator actions. If any of these inputs are not as assumed in the evaluation, confidence that the consequences will be as predicted is reduced. Based on the safety evaluation, the operator has three roles in assuring that the consequences of an event will be no worse than the predicted acceptable results: Maintain plant setup in readiness to properly respond. Operate the plant in a manner such that fewer, milder events minimize the frequency and the severity of adverse events. Monitor the plant to verify that the safety functions are accomplished. The operator needs a systematic approach to mitigating the consequences of an event. The concept of safety functions introduces this systematic approach and presents a hierarchy of protection. If the operator has difficulty identifying an event for any reason, the systematic safety function approach allows accomplishing the overall path of mitigating consequences. Ten functions designed to protect against core melt, preserve containment integrity, prevent indirect release of radioactivity, and maintain vital auxiliaries needed to support the other safety functions are identified

  3. System safety education focused on flight safety

    Science.gov (United States)

    Holt, E.

    1971-01-01

    The measures necessary for achieving higher levels of system safety are analyzed with an eye toward maintaining the combat capability of the Air Force. Several education courses were provided for personnel involved in safety management. Data include: (1) Flight Safety Officer Course, (2) Advanced Safety Program Management, (3) Fundamentals of System Safety, and (4) Quantitative Methods of Safety Analysis.

  4. Fulfillment of the long-term safety functions by the different barriers during the main time frames after repository closure

    International Nuclear Information System (INIS)

    Preter, P. de; Lalieux, Ph.

    2002-01-01

    In general terms the basis long-term safety functions of a disposal system (i.e. the engineered barrier system, including the waste forms and the host rock) are the functions that the system as a whole or its constituents must fulfill in order to assure an adequate level of long-term radiological safety. The long-term safety functions of a disposal system constitute a generic and methodological tool that can be used in a double sense. In the first place these functions provide an a priori instrument for designing the system: the implementer must ensure that these safety functions are fulfilled by a series of robust system barriers and components. These functions can also be used as an a posteriori means to describe and assess in general terms the functioning of the system. In this way they are an important qualitative element to help to support the safety case and to identify further R and D priorities. By providing a general description of system functioning they are also a communication tool to stakeholders who are less familiar with the details of a safety case. Instead of limiting the description to a multi-barrier system, the safety functions enable to better explain how the different barriers contribute to one or more safety functions and by which processes this is performed. By doing so the system description moves from multi-barrier to multi-function. The aim of this paper is to provide such a general description of the system functioning for the Belgian case of deep disposal of high-level waste (mainly spent fuel or vitrified waste from fuel reprocessing) in the Boom Clay, o poorly-indurated argillaceous formation. From the detailed safety and performance evaluations the main time frames after repository closure are identified. Each time frame relates to a period during which the successive safety functions play a key role. Also, in each time frame the radiological impact on the environment is distinctly different. (authors)

  5. Safety barriers and safety functions a comparison of different applications

    International Nuclear Information System (INIS)

    Harms-Ringdahl, L.

    1998-01-01

    A study is being made with the focus on different theories and applications concerning 'safety barriers' and 'safety functions'. One aim is to compare the characteristics of different kinds of safely functions, which can be purpose, efficiency, reliability, weak points etc. A further aim is to summarize how the combination of different barriers are described and evaluated. Of special interest are applications from nuclear and chemical process safety. The study is based on a literature review, interviews and discussions. Some preliminary conclusions are made. For example, it appears to exist a need for better tools to support the design and evaluation of procedures. There are a great number of theoretical models describing safety functions. However, it still appears to be an interest in further development of models, which might give the basis for improved practical tools. (author)

  6. Safety applications of computer based systems for the process industry

    International Nuclear Information System (INIS)

    Bologna, Sandro; Picciolo, Giovanni; Taylor, Robert

    1997-11-01

    Computer based systems, generally referred to as Programmable Electronic Systems (PESs) are being increasingly used in the process industry, also to perform safety functions. The process industry as they intend in this document includes, but is not limited to, chemicals, oil and gas production, oil refining and power generation. Starting in the early 1970's the wide application possibilities and the related development problems of such systems were recognized. Since then, many guidelines and standards have been developed to direct and regulate the application of computers to perform safety functions (EWICS-TC7, IEC, ISA). Lessons learnt in the last twenty years can be summarised as follows: safety is a cultural issue; safety is a management issue; safety is an engineering issue. In particular, safety systems can only be properly addressed in the overall system context. No single method can be considered sufficient to achieve the safety features required in many safety applications. Good safety engineering approach has to address not only hardware and software problems in isolation but also their interfaces and man-machine interface problems. Finally, the economic and industrial aspects of the safety applications and development of PESs in process plants are evidenced throughout all the Report. Scope of the Report is to contribute to the development of an adequate awareness of these problems and to illustrate technical solutions applied or being developed

  7. The ATLAS Detector Safety System

    CERN Multimedia

    Helfried Burckhart; Kathy Pommes; Heidi Sandaker

    The ATLAS Detector Safety System (DSS) has the mandate to put the detector in a safe state in case an abnormal situation arises which could be potentially dangerous for the detector. It covers the CERN alarm severity levels 1 and 2, which address serious risks for the equipment. The highest level 3, which also includes danger for persons, is the responsibility of the CERN-wide system CSAM, which always triggers an intervention by the CERN fire brigade. DSS works independently from and hence complements the Detector Control System, which is the tool to operate the experiment. The DSS is organized in a Front- End (FE), which fulfills autonomously the safety functions and a Back-End (BE) for interaction and configuration. The overall layout is shown in the picture below. ATLAS DSS configuration The FE implementation is based on a redundant Programmable Logical Crate (PLC) system which is used also in industry for such safety applications. Each of the two PLCs alone, one located underground and one at the s...

  8. Field Programmable Gate Array-based I and C Safety System

    International Nuclear Information System (INIS)

    Kim, Hyun Jeong; Kim, Koh Eun; Kim, Young Geul; Kwon, Jong Soo

    2014-01-01

    Programmable Logic Controller (PLC)-based I and C safety system used in the operating nuclear power plants has the disadvantages of the Common Cause Failure (CCF), high maintenance costs and quick obsolescence, and then it is necessary to develop the other platform to replace the PLC. The Field Programmable Gate Array (FPGA)-based Instrument and Control (I and C) safety system is safer and more economical than Programmable Logic Controller (PLC)-based I and C safety system. Therefore, in the future, FPGA-based I and C safety system will be able to replace the PLC-based I and C safety system in the operating and the new nuclear power plants to get benefited from its safety and economic advantage. FPGA-based I and C safety system shall be implemented and verified by applying the related requirements to perform the safety function

  9. Field Programmable Gate Array-based I and C Safety System

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Hyun Jeong; Kim, Koh Eun; Kim, Young Geul; Kwon, Jong Soo [KEPCO, Daejeon (Korea, Republic of)

    2014-08-15

    Programmable Logic Controller (PLC)-based I and C safety system used in the operating nuclear power plants has the disadvantages of the Common Cause Failure (CCF), high maintenance costs and quick obsolescence, and then it is necessary to develop the other platform to replace the PLC. The Field Programmable Gate Array (FPGA)-based Instrument and Control (I and C) safety system is safer and more economical than Programmable Logic Controller (PLC)-based I and C safety system. Therefore, in the future, FPGA-based I and C safety system will be able to replace the PLC-based I and C safety system in the operating and the new nuclear power plants to get benefited from its safety and economic advantage. FPGA-based I and C safety system shall be implemented and verified by applying the related requirements to perform the safety function.

  10. A new concept of safety parameter display system

    International Nuclear Information System (INIS)

    Martinez, A.S.; Oliveira, L.F.S. de; Schirru, R.; Thome Filho, Z.D.; Silva, R.A. da.

    1986-07-01

    A general description of Angra-1 Parameter Display System (SSPA), a real time and on-line computerized monitoring system for the parameters related to the power plant safety is presented. This system has the main purpose of diminish the load on the Angra-1 power plant operators at an emergency event by supplying them with the additional tools serving as the basis for a prompt identification of the accident. The SSPA is a kind of safety parameter display system whose concept was introduced after Three Mile Island accident in USA. The SSPA comprises two nuclear applications independently considered. They are included into the Parameters Monitoring Integrated System (SIMP) and the safety critical function system (SFCS). (Author) [pt

  11. The LHC personnel safety system

    International Nuclear Information System (INIS)

    Ninin, P.; Valentini, F.; Ladzinski, T.

    2011-01-01

    Large particle physics installations such as the CERN Large Hadron Collider require specific Personnel Safety Systems (PSS) to protect the personnel against the radiological and industrial hazards. In order to fulfill the French regulation in matter of nuclear installations, the principles of IEC 61508 and IEC 61513 standard are used as a methodology framework to evaluate the criticality of the installation, to design and to implement the PSS.The LHC PSS deals with the implementation of all physical barriers, access controls and interlock devices around the 27 km of underground tunnel, service zones and experimental caverns of the LHC. The system shall guarantee the absence of personnel in the LHC controlled areas during the machine operations and, on the other hand, ensure the automatic accelerator shutdown in case of any safety condition violation, such as an intrusion during beam circulation. The LHC PSS has been conceived as two separate and independent systems: the LHC Access Control System (LACS) and the LHC Access Safety System (LASS). The LACS, using off the shelf technologies, realizes all physical barriers and regulates all accesses to the underground areas by identifying users and checking their authorizations.The LASS has been designed according to the principles of the IEC 61508 and 61513 standards, starting from a risk analysis conducted on the LHC facility equipped with a standard access control system. It consists in a set of safety functions realized by a dedicated fail-safe and redundant hardware guaranteed to be of SIL3 class. The integration of various technologies combining electronics, sensors, video and operational procedures adopted to establish an efficient personnel safety system for the CERN LHC accelerator is presented in this paper. (authors)

  12. Design of agricultural product quality safety retrospective supervision system of Jiangsu province

    Science.gov (United States)

    Wang, Kun

    2017-08-01

    In store and supermarkets to consumers can trace back agricultural products through the electronic province card to query their origin, planting, processing, packaging, testing and other important information and found that the problems. Quality and safety issues can identify the responsibility of the problem. This paper designs a retroactive supervision system for the quality and safety of agricultural products in Jiangsu Province. Based on the analysis of agricultural production and business process, the goal of Jiangsu agricultural product quality safety traceability system construction is established, and the specific functional requirements and non-functioning requirements of the retroactive system are analyzed, and the target is specified for the specific construction of the retroactive system. The design of the quality and safety traceability system in Jiangsu province contains the design of the overall design, the trace code design and the system function module.

  13. Routine testing on protective and safety systems and components

    International Nuclear Information System (INIS)

    Rysy, W.

    1977-01-01

    1) In-process inspection, tests during commissioning. 2) Tests during reactor operation. 2.1) Reactor protection system, for example: continuous auto-testing by a dynamic system, check of the output signals; 2.2) safety features: selected examples: functional tests on the ECCS, trial operation of the emergency diesels. 3) Tests during refuelling phase. 3.1) Containment: Leakage rate tests, leak testing; 3.2) coolant system: selected examples: inservice inspections of the pressure vessel, eddy current testing of the steam generator, functional tests of safety valves. (orig./HP) [de

  14. DASS: A decision aid integrating the safety parameter display system and emergency functional recovery procedures. Final report

    International Nuclear Information System (INIS)

    Johnson, S.E.

    1984-08-01

    Using a stand-alone developmental test-bed consisting of a minicomputer and a high-resolution color graphics computer, displays and supporting software incorporating advanced on-line decision-aid concepts were developed and evaluated. The advanced concepts embodied in displays designed for the operating crew of a PWR plant include: (1) an integrated display format which supports a top-down approach to problem detection, recovery planning, and control; (2) introduction of nonobservable plant parameters derived from first principles mass and energy balances as part of the displayed information; and (3) systematic processing and display of key success path (plant safety system) attributes. The prototype system, referred to as the PWR-DASS (Disturbance Analysis and Surveillance System), consists of 18 displays targeted for principal use by the control room systems manager. PWR-DASS was conceived to fulfill an operational void not fully supported by safety parameter display systems or reformulated emergency procedure guidelines. The results from the evaluation by licensed operators suggest that organization and display of desired critical safety function and success path information as incorporated in the PWR-DASS prototype can support the systems manager's overview. The results also point to the need for several refinements required for a field grade system, and to the need for a simulator-based evaluation of the prototype or its successor. (author)

  15. Functional safety of health information technology.

    LENUS (Irish Health Repository)

    Chadwick, Liam

    2012-03-01

    In an effort to improve patient safety and reduce adverse events, there has been a rapid growth in the utilisation of health information technology (HIT). However, little work has examined the safety of the HIT systems themselves, the methods used in their development or the potential errors they may introduce into existing systems. This article introduces the conventional safety-related systems development standard IEC 61508 to the medical domain. It is proposed that the techniques used in conventional safety-related systems development should be utilised by regulation bodies, healthcare organisations and HIT developers to provide an assurance of safety for HIT systems. In adopting the IEC 61508 methodology for HIT development and integration, inherent problems in the new systems can be identified and corrected during their development. Also, IEC 61508 should be used to develop a healthcare-specific standard to allow stakeholders to provide an assurance of a system\\'s safety.

  16. Safety Metrics for Human-Computer Controlled Systems

    Science.gov (United States)

    Leveson, Nancy G; Hatanaka, Iwao

    2000-01-01

    The rapid growth of computer technology and innovation has played a significant role in the rise of computer automation of human tasks in modem production systems across all industries. Although the rationale for automation has been to eliminate "human error" or to relieve humans from manual repetitive tasks, various computer-related hazards and accidents have emerged as a direct result of increased system complexity attributed to computer automation. The risk assessment techniques utilized for electromechanical systems are not suitable for today's software-intensive systems or complex human-computer controlled systems.This thesis will propose a new systemic model-based framework for analyzing risk in safety-critical systems where both computers and humans are controlling safety-critical functions. A new systems accident model will be developed based upon modem systems theory and human cognitive processes to better characterize system accidents, the role of human operators, and the influence of software in its direct control of significant system functions Better risk assessments will then be achievable through the application of this new framework to complex human-computer controlled systems.

  17. Development of safety review advisory system for nuclear power plants

    International Nuclear Information System (INIS)

    Kim, M. W.; Lee, H. C.; Park, S. O.; Park, W. J.; Lee, J. I.; Hur, K. Y.; Choi, S. S.; Lee, S. J.; Kang, C. M.

    2001-01-01

    For the development of an expert system supporting the safety review of nuclear power plants, the application program was implemented after gathering necessary theoretical background and practical requirements. The general and the detail functional specifications were established, and they were investigated by the safety review experts at KINS. Safety Review Advisory System (SRAS), the windows application on client-server environment was developed according to the above specifications. Reviewers can do their safety reviewing regardless of speciality or reviewing experiences because SRAS is operated by the safety review plans which are converted to standardized format. When the safety reviewing is carried out by using SRAS, the results of safety reviewing are accumulated in the database and may be utilized later usefully, and we can grasp safety reviewing progress. Users of SRAS are categorized into three groups, administrator, project manager, and reviewer. Each user group has appropriate access capability. The function and some screen shots of SRAS are described in this paper

  18. Analysis approach for common cause failure on non-safety digital control system

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Yun Goo; Oh, Eungse [Korea Hydro and Nuclear Power Co. Ltd., Daejeon (Korea, Republic of)

    2014-05-15

    The effects of common cause failure (CCF) on safety digital instrumentation and control (I and C) system had been considered in defense in depth and diversity coping analysis with safety analysis method. For the non-safety system, single failure had been considered for safety analysis. IEEE Std. 603-1991, Clause 5.6.3.1(2), 'Isolation' states that no credible failure on the non-safety side of an isolation device shall prevent any portion of a safety system from meeting its minimum performance requirements during and following any design basis event requiring that safety function. The software CCF is one of the credible failure on the non-safety side. In advanced digital I and C system, same hardware component is used for different control system and the defect in manufacture or common external event can generate CCF. Moreover, the non-safety I and C system uses complex software for its various function and software quality assurance for the development process is less severe than safety software for the cost effective design. Therefore the potential defects in software cannot be ignored and the effect of software CCF on non-safety I and C system is needed to be evaluated. This paper proposes the general process and considerations for the analysis of CCF on non-safety I and C system.

  19. Model-based Development of Safety-critical Functions and ISO 26262 Work Products using modified EAST-ADL

    Directory of Open Access Journals (Sweden)

    Bülent Sari

    2017-07-01

    Full Text Available Safety is becoming more and more important with the ever increasing level of safety related E/E Systems built into the cars. Increasing functionality of vehicle systems through electrification of power train, in future even more by autonomous driving, leads to complexity in designing system, software and safety architecture. ISO 26262 aims to reduce the complexity and to approve the traceability of the different safety activities. This paper presents an approach about model-based development of system, software and safety architecture using Electronics Architecture and Software Technology – Architecture Description Language (EAST-ADL, being in line with the relevant standard ISO 26262. In particular, we briefly discuss how the main safety related activities, such as hazard analysis and risk assessment, developing functional and technical safety concepts and performing safety analysis can be performed model-based and how the activities can be related with system and software development. The state-of-art is also provided and compared with the proposed approach.

  20. Towards functional safety in drive-by-wire vehicles

    CERN Document Server

    Bergmiller, Peter Johannes

    2015-01-01

    This book presents approaches to address key challenges based on a vehicle level view and with a special emphasis on Drive-by-Wire systems. The design and testing of modern vehicle electronics are becoming more and more demanding due to increasing interdependencies among components and the safety criticality of tasks. The development towards Drive-by-Wire functionalities in vehicles with multiple actuators for vehicle control further increases the challenge. The book explicitly takes into account the interactions between components  and aims at bridging the gap between the need to generate additional customer benefits and the effort to achieve functional safety. The book follows a twofold approach: on the one side, it presents a toolchain to support efficient further development of novel functionalities for Drive-by-Wire vehicles. The toolchain comprises appropriate software tools and scaled and full-scale experimental vehicles. On the other side, development towards functionally safe and flexible Drive-by-W...

  1. European Workshop Industrical Computer Science Systems approach to design for safety

    Science.gov (United States)

    Zalewski, Janusz

    1992-01-01

    This paper presents guidelines on designing systems for safety, developed by the Technical Committee 7 on Reliability and Safety of the European Workshop on Industrial Computer Systems. The focus is on complementing the traditional development process by adding the following four steps: (1) overall safety analysis; (2) analysis of the functional specifications; (3) designing for safety; (4) validation of design. Quantitative assessment of safety is possible by means of a modular questionnaire covering various aspects of the major stages of system development.

  2. An aspect-oriented approach for designing safety-critical systems

    Science.gov (United States)

    Petrov, Z.; Zaykov, P. G.; Cardoso, J. P.; Coutinho, J. G. F.; Diniz, P. C.; Luk, W.

    The development of avionics systems is typically a tedious and cumbersome process. In addition to the required functions, developers must consider various and often conflicting non-functional requirements such as safety, performance, and energy efficiency. Certainly, an integrated approach with a seamless design flow that is capable of requirements modelling and supporting refinement down to an actual implementation in a traceable way, may lead to a significant acceleration of development cycles. This paper presents an aspect-oriented approach supported by a tool chain that deals with functional and non-functional requirements in an integrated manner. It also discusses how the approach can be applied to development of safety-critical systems and provides experimental results.

  3. Regulatory Oversight of Safety Culture in Finland: A Systemic Approach to Safety

    International Nuclear Information System (INIS)

    Oedewald, P.; Väisäsvaara, J.

    2016-01-01

    In Finland the Radiation and Nuclear Safety Authority STUK specifies detailed regulatory requirements for good safety culture. Both the requirements and the practical safety culture oversight activities reflect a systemic approach to safety: the interconnections between the technical, human and organizational factors receive special attention. The conference paper aims to show how the oversight of safety culture can be integrated into everyday oversight activities. The paper also emphasises that the scope of the safety culture oversight is not specific safety culture activities of the licencees, but rather the overall functioning of the licence holder or the new build project organization from safety point of view. The regulatory approach towards human and organizational factors and safety culture has evolved throughout the years of nuclear energy production in Finland. Especially the recent new build projects have highlighted the need to systematically pay attention to the non-technical aspects of safety as it has become obvious how the HOF issues can affect the design processes and quality of construction work. Current regulatory guides include a set of safety culture related requirements. The requirements are binding to the licence holders and they set both generic and specific demands on the licencee to understand, monitor and to develop safety culture of their own organization but also that of their supplier network. The requirements set for the licence holders has facilitated the need to develop the regulator’s safety culture oversight practices towards a proactive and systemic approach.

  4. Software for computer based systems important to safety in nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2004-01-01

    Computer based systems are of increasing importance to safety in nuclear power plants as their use in both new and older plants is rapidly increasing. They are used both in safety related applications, such as some functions of the process control and monitoring systems, as well as in safety critical applications, such as reactor protection or actuation of safety features. The dependability of computer based systems important to safety is therefore of prime interest and should be ensured. With current technology, it is possible in principle to develop computer based instrumentation and control systems for systems important to safety that have the potential for improving the level of safety and reliability with sufficient dependability. However, their dependability can be predicted and demonstrated only if a systematic, fully documented and reviewable engineering process is followed. Although a number of national and international standards dealing with quality assurance for computer based systems important to safety have been or are being prepared, internationally agreed criteria for demonstrating the safety of such systems are not generally available. It is recognized that there may be other ways of providing the necessary safety demonstration than those recommended here. The basic requirements for the design of safety systems for nuclear power plants are provided in the Requirements for Design issued in the IAEA Safety Standards Series.The IAEA has issued a Technical Report to assist Member States in ensuring that computer based systems important to safety in nuclear power plants are safe and properly licensed. The report provides information on current software engineering practices and, together with relevant standards, forms a technical basis for this Safety Guide. The objective of this Safety Guide is to provide guidance on the collection of evidence and preparation of documentation to be used in the safety demonstration for the software for computer based

  5. Software for computer based systems important to safety in nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2005-01-01

    Computer based systems are of increasing importance to safety in nuclear power plants as their use in both new and older plants is rapidly increasing. They are used both in safety related applications, such as some functions of the process control and monitoring systems, as well as in safety critical applications, such as reactor protection or actuation of safety features. The dependability of computer based systems important to safety is therefore of prime interest and should be ensured. With current technology, it is possible in principle to develop computer based instrumentation and control systems for systems important to safety that have the potential for improving the level of safety and reliability with sufficient dependability. However, their dependability can be predicted and demonstrated only if a systematic, fully documented and reviewable engineering process is followed. Although a number of national and international standards dealing with quality assurance for computer based systems important to safety have been or are being prepared, internationally agreed criteria for demonstrating the safety of such systems are not generally available. It is recognized that there may be other ways of providing the necessary safety demonstration than those recommended here. The basic requirements for the design of safety systems for nuclear power plants are provided in the Requirements for Design issued in the IAEA Safety Standards Series.The IAEA has issued a Technical Report to assist Member States in ensuring that computer based systems important to safety in nuclear power plants are safe and properly licensed. The report provides information on current software engineering practices and, together with relevant standards, forms a technical basis for this Safety Guide. The objective of this Safety Guide is to provide guidance on the collection of evidence and preparation of documentation to be used in the safety demonstration for the software for computer based

  6. Software for computer based systems important to safety in nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2000-01-01

    Computer based systems are of increasing importance to safety in nuclear power plants as their use in both new and older plants is rapidly increasing. They are used both in safety related applications, such as some functions of the process control and monitoring systems, as well as in safety critical applications, such as reactor protection or actuation of safety features. The dependability of computer based systems important to safety is therefore of prime interest and should be ensured. With current technology, it is possible in principle to develop computer based instrumentation and control systems for systems important to safety that have the potential for improving the level of safety and reliability with sufficient dependability. However, their dependability can be predicted and demonstrated only if a systematic, fully documented and reviewable engineering process is followed. Although a number of national and international standards dealing with quality assurance for computer based systems important to safety have been or are being prepared, internationally agreed criteria for demonstrating the safety of such systems are not generally available. It is recognized that there may be other ways of providing the necessary safety demonstration than those recommended here. The basic requirements for the design of safety systems for nuclear power plants are provided in the Requirements for Design issued in the IAEA Safety Standards Series.The IAEA has issued a Technical Report to assist Member States in ensuring that computer based systems important to safety in nuclear power plants are safe and properly licensed. The report provides information on current software engineering practices and, together with relevant standards, forms a technical basis for this Safety Guide. The objective of this Safety Guide is to provide guidance on the collection of evidence and preparation of documentation to be used in the safety demonstration for the software for computer based

  7. Evaluation of common mode failure of safety functions for limiting fault events

    International Nuclear Information System (INIS)

    Rezendes, J.P.; Hyde, A.W.

    2004-01-01

    The draft U.S. Nuclear Regulatory Commission (NRC) policy on digital protection system software requires all Advanced Light Water Reactors (ALWRs) to be evaluated assuming a hypothetical common mode failure (CMF) which incapacitates the normal automatic initiation of safety functions. The System 80 + ALWR has been evaluated for such hypothetical conditions. The results show that the diverse automatic and manual protective systems in System 80 + provide ample safety performance margins relative to core coolability, offsite radiological releases. Reactor Coolant System (RCS) pressurization and containment integrity. This deterministic evaluation served to quantify the significant inherent safety margins in the System 80 + Standard Plant design even in the event of this extremely low probability scenario of a common mode failure. (author)

  8. Safety analysis and evaluation methodology for fusion systems

    International Nuclear Information System (INIS)

    Fujii-e, Y.; Kozawa, Y.; Namba, C.

    1987-03-01

    Fusion systems which are under development as future energy systems have reached a stage that the break even is expected to be realized in the near future. It is desirable to demonstrate that fusion systems are well acceptable to the societal environment. There are three crucial viewpoints to measure the acceptability, that is, technological feasibility, economy and safety. These three points have close interrelation. The safety problem is more important since three large scale tokamaks, JET, TFTR and JT-60, start experiment, and tritium will be introduced into some of them as the fusion fuel. It is desirable to establish a methodology to resolve the safety-related issues in harmony with the technological evolution. The promising fusion system toward reactors is not yet settled. This study has the objective to develop and adequate methodology which promotes the safety design of general fusion systems and to present a basis for proposing the R and D themes and establishing the data base. A framework of the methodology, the understanding and modeling of fusion systems, the principle of ensuring safety, the safety analysis based on the function and the application of the methodology are discussed. As the result of this study, the methodology for the safety analysis and evaluation of fusion systems was developed. New idea and approach were presented in the course of the methodology development. (Kako, I.)

  9. FOOD SAFETY SYSTEMS’ FUNCTIONING IN POLISH NETWORKS OF GROCERY STORES

    Directory of Open Access Journals (Sweden)

    Paweł NOWICKI

    2013-04-01

    Full Text Available This article shows the way how the food safety systems are functioning in Polish networks of grocery stores. The study was conducted in the fourth quarter of 2012 in the south‐eastern Poland. There were chosen three organizations that meet certain conditions: medium size Polish grocery network without participation of foreign capital and up to 30 retail locations within the group. Studies based on a case study model. The research found that regular and unannounced inspections carried out to each store's, impact on increasing safety of food offered and the verification of GHP requirements on the headquarters level has a significant impact on the safety of food offered as well as on the knowledge and behavior of employees. In addition it was found that the verification and analysis of food safety management system is an effective tool for improving food safety. It was also shown that in most cases there is no formal crisis management system for the food protection in the surveyed companies and employees are only informed of what to do in case of an emergency.

  10. Design of an Active Automotive Safety System

    Directory of Open Access Journals (Sweden)

    Y. Wang

    2013-07-01

    Full Text Available With the development of the national economy, the people's standard of living got corresponding improvement, cars has been one of the indispensable traffic tools in many families. An active safety system is proposed, which can real-time detect the vehicle's running status and judge the security status of the vehicle. The system, which takes single-chip microcomputer as the controlling core and combines with millimeter-wave and ultrasonic distance measurement technology, can detect the distance from vehicle to vehicle and judge the security status of the vehicle. The hardware composition of the system and the data acquiring circuit are proposed, the mathematic model for different situation is established, and the controlling algorithm is completed. This system can accurately measure speed and distance between vehicles; the active safety control system can meet the relevant data measurement and transmission requirement; and can meet the functional requirement of the active safety control system

  11. Using system dynamics simulation for assessment of hydropower system safety

    Science.gov (United States)

    King, L. M.; Simonovic, S. P.; Hartford, D. N. D.

    2017-08-01

    Hydropower infrastructure systems are complex, high consequence structures which must be operated safely to avoid catastrophic impacts to human life, the environment, and the economy. Dam safety practitioners must have an in-depth understanding of how these systems function under various operating conditions in order to ensure the appropriate measures are taken to reduce system vulnerability. Simulation of system operating conditions allows modelers to investigate system performance from the beginning of an undesirable event to full system recovery. System dynamics simulation facilitates the modeling of dynamic interactions among complex arrangements of system components, providing outputs of system performance that can be used to quantify safety. This paper presents the framework for a modeling approach that can be used to simulate a range of potential operating conditions for a hydropower infrastructure system. Details of the generic hydropower infrastructure system simulation model are provided. A case study is used to evaluate system outcomes in response to a particular earthquake scenario, with two system safety performance measures shown. Results indicate that the simulation model is able to estimate potential measures of system safety which relate to flow conveyance and flow retention. A comparison of operational and upgrade strategies is shown to demonstrate the utility of the model for comparing various operational response strategies, capital upgrade alternatives, and maintenance regimes. Results show that seismic upgrades to the spillway gates provide the largest improvement in system performance for the system and scenario of interest.

  12. On the functional failures concept and probabilistic safety margins: challenges in application for evaluation of effectiveness of shutdown systems - 15318

    International Nuclear Information System (INIS)

    Serghiuta, D.; Tholammakkil, J.

    2015-01-01

    The use of level-3 reliability approach and the concept of functional failure probability could provide the basis for defining a safety margin metric which would include a limit for the probability of functional failure, in line with the definition of a reliability-based design. It can also allow a quantification of level of confidence, by explicit modeling and quantification of uncertainties, and provide a better framework for representation of actual design and optimization of design margins within an integrated probabilistic-deterministic model. This paper reviews the attributes and challenges in application of functional failure concept in evaluation of risk-informed safety margins using as illustrative example the case of CANDU reactors shutdown systems effectiveness. A risk-informed formulation is first introduced for estimation of a reasonable limit for the functional failure probability using a Swiss cheese model. It is concluded that more research is needed in this area and a deterministic - probabilistic approach may be a reasonable intermediate step for evaluation of functional failure probability at the system level. The views expressed in this paper are those of the authors and do not necessarily reflect those of CNSC, or any part thereof. (authors)

  13. Experimental research progress on passive safety systems of Chinese advanced PWR

    International Nuclear Information System (INIS)

    Xiao Zejun; Zhuo Wenbin; Zheng Hua; Chen Bingde; Zong Guifang; Jia Dounan

    2003-01-01

    TMI and Chernobyl accidents, having pronounced impact on nuclear industries, triggered the governments as well as interested institutions to devote much attention to the safety of nuclear power plant and public's requirements on nuclear power plant safety were also going to be stricter and stricter. It is obvious that safety level of an ordinary light water reactor is no longer satisfactory to these requirements. Recently, the safety authorities have recommended the implementation of passive system to improve the safety of nuclear reactors. Passive safety system is one of the main differences between Chinese advanced PWR and other conventional PWR. The working principle of passive safety system is to utilize the gravity, natural convection (natural circulation) and stored energy to implement the system's safety function. Reactors with passive safety systems are not only safer, but also more economical. The passive safety system of Chinese advanced PWR is composed of three independent systems, i.e. passive containment cooling system, passive residual heat removal system and passive core makeup tank injection system. This paper is a summary of experimental research progress on passive containment cooling system, passive residual heat removal system and passive core makeup tank injection system

  14. Design of reactor containment systems for nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2008-01-01

    This Safety Guide was prepared under the IAEA programme for safety standards for nuclear power plants. It is a revision of the Safety Guide on Design of the Reactor Containment Systems in Nuclear Power Plants (Safety Series No. 50-Sg-D1) issued in 1985 and supplements the Safety Requirements publication on Safety of Nuclear Power Plants: Design. The present Safety Guide was prepared on the basis of a systematic review of the relevant publications, including the Safety of Nuclear Power Plants: Design, the Safety fundamentals publication on The Safety of Nuclear Installations, Safety Guides, INSAG Reports, a Technical Report and other publications covering the safety of nuclear power plants. 1.2. The confinement of radioactive material in a nuclear plant, including the control of discharges and the minimization of releases, is a fundamental safety function to be ensured in normal operational modes, for anticipated operational occurrences, in design basis accidents and, to the extent practicable, in selected beyond design basis accidents. In accordance with the concept of defence in depth, this fundamental safety function is achieved by means of several barriers and levels of defence. In most designs, the third and fourth levels of defence are achieved mainly by means of a strong structure enveloping the nuclear reactor. This structure is called the 'containment structure' or simply the 'containment'. This definition also applies to double wall containments. 1.3. The containment structure also protects the reactor against external events and provides radiation shielding in operational states and accident conditions. The containment structure and its associated systems with the functions of isolation, energy management, and control of radionuclides and combustible gases are referred to as the containment systems

  15. Design of reactor containment systems for nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2004-01-01

    This Safety Guide was prepared under the IAEA programme for safety standards for nuclear power plants. It is a revision of the Safety Guide on Design of the Reactor Containment Systems in Nuclear Power Plants (Safety Series No. 50-Sg-D1) issued in 1985 and supplements the Safety Requirements publication on Safety of Nuclear Power Plants: Design. The present Safety Guide was prepared on the basis of a systematic review of the relevant publications, including the Safety of Nuclear Power Plants: Design, the Safety fundamentals publication on The Safety of Nuclear Installations, Safety Guides, INSAG Reports, a Technical Report and other publications covering the safety of nuclear power plants. 1.2. The confinement of radioactive material in a nuclear plant, including the control of discharges and the minimization of releases, is a fundamental safety function to be ensured in normal operational modes, for anticipated operational occurrences, in design basis accidents and, to the extent practicable, in selected beyond design basis accidents. In accordance with the concept of defence in depth, this fundamental safety function is achieved by means of several barriers and levels of defence. In most designs, the third and fourth levels of defence are achieved mainly by means of a strong structure enveloping the nuclear reactor. This structure is called the 'containment structure' or simply the 'containment'. This definition also applies to double wall containments. 1.3. The containment structure also protects the reactor against external events and provides radiation shielding in operational states and accident conditions. The containment structure and its associated systems with the functions of isolation, energy management, and control of radionuclides and combustible gases are referred to as the containment systems

  16. Critical function monitoring system algorithm development

    International Nuclear Information System (INIS)

    Harmon, D.L.

    1984-01-01

    Accurate critical function status information is a key to operator decision-making during events threatening nuclear power plant safety. The Critical Function Monitoring System provides continuous critical function status monitoring by use of algorithms which mathematically represent the processes by which an operating staff would determine critical function status. This paper discusses in detail the systematic design methodology employed to develop adequate Critical Function Monitoring System algorithms

  17. Reactor safety systems

    International Nuclear Information System (INIS)

    Kafka, P.

    1975-01-01

    The spectrum of possible accidents may become characterized by the 'maximum credible accident', which will/will not happen. Similary, the performance of safety systems in a multitude of situations is sometimes simplified to 'the emergency system will/will not work' or even 'reactors are/ are not safe'. In assessing safety, one must avoid this fallacy of reducing a complicated situation to the simple black-and-white picture of yes/no. Similarly, there is a natural tendency continually to improve the safety of a system to assure that it is 'safe enough'. Any system can be made safer and there is usually some additional cost. It is important to balance the increased safety against the increased costs. (orig.) [de

  18. Optimized Evaluation System to Athletic Food Safety

    OpenAIRE

    Shanshan Li

    2015-01-01

    This study presented a new method of optimizing evaluation function in athletic food safety information programming by particle swarm optimization. The process of food information evaluation function is to automatically adjust these parameters in the evaluation function by self-optimizing method accomplished through competition, which is a food information system plays against itself with different evaluation functions. The results show that the particle swarm optimization is successfully app...

  19. Reactor system safety assurance

    International Nuclear Information System (INIS)

    Mattson, R.J.

    1984-01-01

    The philosophy of reactor safety is that design should follow established and conservative engineering practices, there should be safety margins in all modes of plant operation, special systems should be provided for accidents, and safety systems should have redundant components. This philosophy provides ''defense in depth.'' Additionally, the safety of nuclear power plants relies on ''safety systems'' to assure acceptable response to design basis events. Operating experience has shown the need to study plant response to more frequent upset conditions and to account for the influence of operators and non-safety systems on overall performance. Defense in depth is being supplemented by risk and reliability assessment

  20. Integrated model of port oil piping transportation system safety including operating environment threats

    Directory of Open Access Journals (Sweden)

    Kołowrocki Krzysztof

    2017-06-01

    Full Text Available The paper presents an integrated general model of complex technical system, linking its multistate safety model and the model of its operation process including operating environment threats and considering variable at different operation states its safety structures and its components safety parameters. Under the assumption that the system has exponential safety function, the safety characteristics of the port oil piping transportation system are determined.

  1. Integrated model of port oil piping transportation system safety including operating environment threats

    OpenAIRE

    Kołowrocki, Krzysztof; Kuligowska, Ewa; Soszyńska-Budny, Joanna

    2017-01-01

    The paper presents an integrated general model of complex technical system, linking its multistate safety model and the model of its operation process including operating environment threats and considering variable at different operation states its safety structures and its components safety parameters. Under the assumption that the system has exponential safety function, the safety characteristics of the port oil piping transportation system are determined.

  2. Project JADE. Long-term function and safety. Comparison of repository systems

    International Nuclear Information System (INIS)

    Birgersson, Lars; Pers, K.; Wiborgh, M.

    2001-12-01

    A comparison of the KBS-3 V(ertical deposition), KBS-3 H(orizontal deposition) and MLH repository systems with regard to the long-term repository performance and the radionuclide migration is presented in the report. Several differences between the repository systems have been identified. The differences are mainly related to the: distance between canister and backfilled tunnels, excavated rock volumes, deposition hole direction. The overall conclusion is that the differences are in general quite small with regard to the repository function and safety. None of the differences are of such importance for the long-term repository performance and radionuclide migration that they discriminate any of the repository systems. The differences between the two KBS-3 systems are small. Based on this study, there is no reason to change from the reference system KBS-3 V to KBS-3 H. MLH has the potential to be a very robust system, especially in a long-term perspective. However, the MLH system will require extensive research, development, and analysis before it will be as confident as the reference repository system, KBS-3 V. Although the MLH and KBS-3 H systems are in some ways favourable compared to the reference system KBS-3 V, the overall conclusion is that the KBS-3 V system is still a very attractive system. A major advantage with KBS-3 V is that it is by far the most investigated and developed system. The JADE-project was initiated in 1996, and the main part of the study was carried out during 1997 and 1998. The JADE study is consequently based on presumptions that were valid a few years ago. Some of these presumptions have been modified since then. The new presumptions are however not judged to change the overall conclusions

  3. A Reliability Assessment Method for the VHTR Safety Systems

    International Nuclear Information System (INIS)

    Lee, Hyung Sok; Jae, Moo Sung; Kim, Yong Wan

    2011-01-01

    The Passive safety system by very high temperature reactor which has attracted worldwide attention in the last century is the reliability safety system introduced for the improvement in the safety of the next generation nuclear power plant design. The Passive system functionality does not rely on an external source of energy, but on an intelligent use of the natural phenomena, such as gravity, conduction and radiation, which are always present. Because of these features, it is difficult to evaluate the passive safety on the risk analysis methodology having considered the existing active system failure. Therefore new reliability methodology has to be considered. In this study, the preliminary evaluation and conceptualization are tried, applying the concept of the load and capacity from the reliability physics model, designing the new passive system analysis methodology, and the trial applying to paper plant.

  4. Implementation of safety parameter display system at VVER-440 NPPs

    International Nuclear Information System (INIS)

    Manninen, T.

    1997-01-01

    Furnishing WWER-440 nuclear power plant units with a safety parameter display system (SPDS) fulfilling the requirements of internationally recognized standards and guidelines has been ranked high on the lists of proposed safety improvement projects. Technically such an SPDS system can be implemented either as a separate stand-alone system or as a more or less closely integrated part of a process information system of the plant unit. In the paper examples of these approaches are presented. Functionally all these examples include the well proven SPDS concept developed by IVO Power Engineering Ltd, Finland. The functional design basis, the general requirements for the system platform, experience with implementation and expansion possibilities of the systems are discussed. (author)

  5. Operation safety of control systems. Principles and methods

    International Nuclear Information System (INIS)

    Aubry, J.F.; Chatelet, E.

    2008-01-01

    This article presents the main operation safety methods that can be implemented to design safe control systems taking into account the behaviour of the different components with each other (binary 'operation/failure' behaviours, non-consistent behaviours and 'hidden' failures, dynamical behaviours and temporal aspects etc). To take into account these different behaviours, advanced qualitative and quantitative methods have to be used which are described in this article: 1 - qualitative methods of analysis: functional analysis, preliminary risk analysis, failure mode and failure effects analyses; 2 - quantitative study of systems operation safety: binary representation models, state space-based methods, event space-based methods; 3 - application to the design of control systems: safe specifications of a control system, qualitative analysis of operation safety, quantitative analysis, example of application; 4 - conclusion. (J.S.)

  6. Towards integrated hygiene and food safety management systems: the Hygieneomic approach.

    Science.gov (United States)

    Armstrong, G D

    1999-09-15

    Integrated hygiene and food safety management systems in food production can give rise to exceptional improvements in food safety performance, but require high level commitment and full functional involvement. A new approach, named hygieneomics, has been developed to assist management in their introduction of hygiene and food safety systems. For an effective introduction, the management systems must be designed to fit with the current generational state of an organisation. There are, broadly speaking, four generational states of an organisation in their approach to food safety. They comprise: (i) rules setting; (ii) ensuring compliance; (iii) individual commitment; (iv) interdependent action. In order to set up an effective integrated hygiene and food safety management system a number of key managerial requirements are necessary. The most important ones are: (a) management systems must integrate the activities of key functions from research and development through to supply chain and all functions need to be involved; (b) there is a critical role for the senior executive, in communicating policy and standards; (c) responsibilities must be clearly defined, and it should be clear that food safety is a line management responsibility not to be delegated to technical or quality personnel; (d) a thorough and effective multi-level audit approach is necessary; (e) key activities in the system are HACCP and risk management, but it is stressed that these are ongoing management activities, not once-off paper generating exercises; and (f) executive management board level review is necessary of audit results, measurements, status and business benefits.

  7. Development of the safety evaluation system in the respects of organizational factors and workers' consciousness. Pt. 1. Study of validities of functions for necessary evaluation and results obtained

    International Nuclear Information System (INIS)

    Takano, Kenichi; Tsuge, Tadafumi; Hasegawa, Naoko; Hirose, Ayako; Sasou, Kunihide

    2002-01-01

    CRIEPI decided to develop the safety evaluation system to investigate the safety level of the industrial sites due to questionnaires of organizational climate, safety managements, and workers' safety consciousness to workers. This report describes the questionnaire survey to apply to the domestic nuclear power plant for using obtained results as a fundamental data in order to construct the safety evaluation system. This system will be used for promoting safety culture in organizations of nuclear power plants. The questionnaire survey was conducted to 14 nuclear power stations for understanding the present status relating to safety issues. This questionnaire involves 122 items classified into following three categories: (1) safety awareness and behavior of plant personnel; (2) safety management; (3) organizational climate, based on the model considering contributing factor groups to safety culture. Obtained results were analyzed by statistical method to prepare functions of evaluation. Additionally, by applying a multivariate analysis, it was possible to extract several crucial factors influencing safety performance and to find a comprehensive safety indicator representing total organizational safety level. Significant relations were identified between accident rates (both labor accidents and facility failures) and above comprehensive safety indicator. Next, 122 questionnaire items were classified into 20 major safety factors to grasp the safety profiles of each site. This profile is considered as indicating the features of each site and also indicating the direction of progress for improvement of safety situation in the site. These findings can be reflected in developing the safety evaluation system, by confirming the validity of the evaluation method and giving specific functions. (author)

  8. Passive safety systems reliability and integration of these systems in nuclear power plant PSA

    International Nuclear Information System (INIS)

    La Lumia, V.; Mercier, S.; Marques, M.; Pignatel, J.F.

    2004-01-01

    Innovative nuclear reactor concepts could lead to use passive safety features in combination with active safety systems. A passive system does not need active component, external energy, signal or human interaction to operate. These are attractive advantages for safety nuclear plant improvements and economic competitiveness. But specific reliability problems, linked to physical phenomena, can conduct to stop the physical process. In this context, the European Commission (EC) starts the RMPS (Reliability Methods for Passive Safety functions) program. In this RMPS program, a quantitative reliability evaluation of the RP2 system (Residual Passive heat Removal system on the Primary circuit) has been realised, and the results introduced in a simplified PSA (Probabilistic Safety Assessment). The scope is to get out experience of definition of characteristic parameters for reliability evaluation and PSA including passive systems. The simplified PSA, using event tree method, is carried out for the total loss of power supplies initiating event leading to a severe core damage. Are taken into account: failures of components but also failures of the physical process involved (e.g. natural convection) by a specific method. The physical process failure probabilities are assessed through uncertainty analyses based on supposed probability density functions for the characteristic parameters of the RP2 system. The probabilities are calculated by MONTE CARLO simulation coupled to the CATHARE thermalhydraulic code. The yearly frequency of the severe core damage is evaluated for each accident sequence. This analysis has identified the influence of the passive system RP2 and propose a re-dimensioning of the RP2 system in order to satisfy the safety probabilistic objectives for reactor core severe damage. (authors)

  9. Safety of High Speed Ground Transportation Systems : Analytical Methodology for Safety Validation of Computer Controlled Subsystems : Volume 2. Development of a Safety Validation Methodology

    Science.gov (United States)

    1995-01-01

    This report describes the development of a methodology designed to assure that a sufficiently high level of safety is achieved and maintained in computer-based systems which perform safety cortical functions in high-speed rail or magnetic levitation ...

  10. Safety parameter display system (SPDS) for Russian-designed NPPs

    International Nuclear Information System (INIS)

    Anikanov, S.S.; Catullo, W.J.; Pelusi, J.L.

    1997-01-01

    As part of the programs aimed at improving the safety of Russian-designed reactors, the US DoE has sponsored a project of providing a safety parameter display system (SPDS) for nuclear power plants with such reactors. The present paper is focused mostly on the system architecture design features of SPDS systems for WWER-1000 and RBMK-1000 reactors. The function and the operating modes of the SPDS are outlined, and a description of the display system is given. The system architecture and system design of both an integrated and a stand-alone IandC system is explained. (A.K.)

  11. Impacts of safety on the design of light remotely-piloted helicopter flight control systems

    International Nuclear Information System (INIS)

    Di Rito, G.; Schettini, F.

    2016-01-01

    This paper deals with the architecture definition and the safety assessment of flight control systems for light remotely-piloted helicopters for civil applications. The methods and tools to be used for these activities are standardised for conventional piloted aircraft, while they are currently a matter of discussion in case of light remotely-piloted systems flying into unsegregated airspaces. Certification concerns are particularly problematic for aerial systems weighing from 20 to 150 kgf, since the airworthiness permission is granted by national authorities. The lack of specific requirements actually requires to analyse both the existing standards for military applications and the certification guidelines for civil systems, up to derive the adequate safety objectives. In this work, after a survey on applicable certification documents for the safety objectives definition, the most relevant functional failures of a light remotely-piloted helicopter are identified and analysed via Functional Hazard Assessment. Different architectures are then compared by means of Fault-Tree Analysis, highlighting the contributions to the safety level of the main elements of the flight control system (control computers, servoactuators, antenna) and providing basic guidelines on the required redundancy level. - Highlights: • A method for architecture definition and safety assessment of light RW‐UAS flight control systems is proposed. • Relevant UAS failures are identified and analysed via Functional Hazard Assessment and Fault‐Tree Analysis. • The key safety elements are control computers, servoactuators and TX/RX system. • Single‐simplex flight control systems have inadequate safety levels. • Dual‐duplex flight control systems demonstrate to be safety compliant, with safety budgets dominated by servoactuators.

  12. Traceability of Software Safety Requirements in Legacy Safety Critical Systems

    Science.gov (United States)

    Hill, Janice L.

    2007-01-01

    How can traceability of software safety requirements be created for legacy safety critical systems? Requirements in safety standards are imposed most times during contract negotiations. On the other hand, there are instances where safety standards are levied on legacy safety critical systems, some of which may be considered for reuse for new applications. Safety standards often specify that software development documentation include process-oriented and technical safety requirements, and also require that system and software safety analyses are performed supporting technical safety requirements implementation. So what can be done if the requisite documents for establishing and maintaining safety requirements traceability are not available?

  13. Operating environment threats influence on the maritime ferry technical system safety – the numerical approach

    Directory of Open Access Journals (Sweden)

    Kuligowska Ewa

    2017-06-01

    Full Text Available The material given in this paper delivers the procedure for numerical approach that allows finding the main practically important safety characteristics of the complex technical systems at the variable operation conditions including operating environment threats. The obtained results are applied to the safety evaluation of the maritime ferry technical system. It is assumed that the conditional safety functions are different at various operation states and have the exponential forms. Using the procedure and the program written in Mathematica, the considered maritime ferry technical system main characteristics including: the conditional and the unconditional expected values and standard deviations of the system lifetimes, the unconditional safety function and the risk function are determined.

  14. Safety analysis of tritium processing system based on PHA

    International Nuclear Information System (INIS)

    Fu Wanfa; Luo Deli; Tang Tao

    2012-01-01

    Safety analysis on primary confinement of tritium processing system for TBM was carried out with Preliminary Hazard Analysis. Firstly, the basic PHA process was given. Then the function and safe measures with multiple confinements about tritium system were described and analyzed briefly, dividing the two kinds of boundaries of tritium transferring through, that are multiple confinement systems division and fluid loops division. Analysis on tritium releasing is the key of PHA. Besides, PHA table about tritium releasing was put forward, the causes and harmful results being analyzed, and the safety measures were put forward also. On the basis of PHA, several kinds of typical accidents were supposed to be further analyzed. And 8 factors influencing the tritium safety were analyzed, laying the foundation of evaluating quantitatively the safety grade of various nuclear facilities. (authors)

  15. Preliminary study on functional performance of compound type multistage safety injection tank

    International Nuclear Information System (INIS)

    Bae, Youngmin; Kim, Young In; Kim, Keung Koo

    2015-01-01

    Highlights: • Functional performance of compound type multistage safety injection tanks is studied. • Effects of key design parameters are scrutinized. • Distinctive flow features in compound type safety injection tanks are explored. - Abstract: A parametric study is carried out to evaluate the functional performance of a compound type multistage safety injection tank that would be considered one of the components for the passive safety injection systems in nuclear power plants. The effects of key design parameters such as the initial volume fraction and charging pressure of gas, tank elevation, vertical location of a sparger, resistance coefficient, and operating condition on the injection flow rate are scrutinized along with a discussion of the relevant flow features. The obtained results indicate that the compound type multistage safety injection tank can effectively control the injection flow rate in a passive manner, by switching the driving force for the safety injection from gas pressure to gravity during the refill and reflood phases, respectively

  16. IEEE standard for design qualification of safety systems equipment used in nuclear power generating stations

    International Nuclear Information System (INIS)

    Anon.

    1980-01-01

    This standard is written to serve as a general standard for qualification of all types of safety systems equipment, mechanical and instrumentation as well as electrical. It also establishes principles and procedures to be followed in preparing specific safety systems equipment standards. Guidance for qualifying specific safety systems equipment may be found in various specific equipment qualification standards that are now available or are being prepared. It is required that safety systems equipment in nuclear power generating stations meet or exceed its performance requirements throughout its installed life. This is accomplished by a disciplined program of design qualification and quality assurance of design, production, installation, maintenance and surveillance. This standard is for the design qualification section of the program only. Design qualification is intended to demonstrate the capability of the equipment design to perform its safety function(s) over the expected range of normal, abnormal, design basis event, post design basis event, and in-service test conditions. Inherent to design qualification is the requirement for demonstration, within limitations afforded by established technical state-of-the-art, that in-service aging throughout the qualified life established for the equipment will not degrade safety systems equipment from its original design condition to the point where it cannot perform its required safety function(s), upon demand. The above requirement reflects the primary role of design qualification to provide reasonable assurance that design- and age-related common failure modes will not occur during performance of safety function(s) under postulated service conditions

  17. Safety analysis of autonomous excavator functionality

    International Nuclear Information System (INIS)

    Seward, D.; Pace, C.; Morrey, R.; Sommerville, I.

    2000-01-01

    This paper presents an account of carrying out a hazard analysis to define the safety requirements for an autonomous robotic excavator. The work is also relevant to the growing generic class of heavy automated mobile machinery. An overview of the excavator design is provided and the concept of a safety manager is introduced. The safety manager is an autonomous module responsible for all aspects of system operational safety, and is central to the control system's architecture. Each stage of the hazard analysis is described, i.e. system model creation, hazard definition and hazard analysis. Analysis at an early stage of the design process, and on a system that interfaces directly to an unstructured environment, exposes certain issues relevant to the application of current hazard analysis methods. The approach taken in the analysis is described. Finally, it is explained how the results of the hazard analysis have influenced system design, in particular, safety manager specifications. Conclusions are then drawn about the applicability of hazard analysis of requirements in general, and suggestions are made as to how the approach can be taken further

  18. Cold Vacuum Drying Safety Class Instrumentation and Control System Design Description

    International Nuclear Information System (INIS)

    WHITEHURST, R.

    1999-01-01

    This document describes the Cold Vacuum Drying Facility (CVDF) Safety Class Instrumentation and Control system (SCIC). The SCIC provides safety functions and features to protect the environment, off-site and on-site personnel and equipment. The function of the SCIC is to provide automatic trip features, valve interlocks, alarms, indication and control for the cold vacuum drying process

  19. Qualification of safety-critical software for digital reactor safety system in nuclear power plants

    International Nuclear Information System (INIS)

    Kwon, Kee-Choon; Park, Gee-Yong; Kim, Jang-Yeol; Lee, Jang-Soo

    2013-01-01

    This paper describes the software qualification activities for the safety-critical software of the digital reactor safety system in nuclear power plants. The main activities of the software qualification processes are the preparation of software planning documentations, verification and validation (V and V) of the software requirements specifications (SRS), software design specifications (SDS) and codes, and the testing of the integrated software and integrated system. Moreover, the software safety analysis and software configuration management are involved in the software qualification processes. The V and V procedure for SRS and SDS contains a technical evaluation, licensing suitability evaluation, inspection and traceability analysis, formal verification, software safety analysis, and an evaluation of the software configuration management. The V and V processes for the code are a traceability analysis, source code inspection, test case and test procedure generation. Testing is the major V and V activity of the software integration and system integration phases. The software safety analysis employs a hazard operability method and software fault tree analysis. The software configuration management in each software life cycle is performed by the use of a nuclear software configuration management tool. Through these activities, we can achieve the functionality, performance, reliability, and safety that are the major V and V objectives of the safety-critical software in nuclear power plants. (author)

  20. Safety of pulmonary function testing

    DEFF Research Database (Denmark)

    Roberts, Cara; Ward, Simon; Walsted, Emil

    2017-01-01

    BACKGROUND: Pulmonary function testing (PFT) is a key investigation in the evaluation of individuals with respiratory symptoms; however, the safety of routine and specialised PFT testing has not been reported in a large data set. Using patient safety incident (PSI) records, we aimed to assess risk...... was rated using the NHS National Patient Safety Agency and any hospital admission reported. RESULTS: There were 119 PSIs reported from 186 000 PFT; that is, 0.6 PSIs per 1000 tests. Cardiopulmonary PSIs were 3.3 times more likely to occur than non-cardiopulmonary (95% CI 2.17 to 5.12). Syncope was the most...

  1. Safety Evaluation of Kartini Reactor Based on Instrumentation System Design

    International Nuclear Information System (INIS)

    Tjipta Suhaemi; Djen Djen Dj; Itjeu K; Johnny S; Setyono

    2003-01-01

    The safety of Kartini reactor has been evaluated based on instrumentation system aspect. The Kartini reactor is designed by BATAN. Design power of the reactor is 250 kW, but it is currently operated at 100 kW. Instrumentation and control system function is to monitor and control the reactor operation. Instrumentation and control system consists of safety system, start-up and automatic power control, and process information system. The linear power channel and logarithmic power channel are used for measuring power. There are 3 types of control rod for controlling the power, i.e. safety rod, shim rod, and regulating rod. The trip and interlock system are used for safety. There are instrumentation equipment used for measuring radiation exposure, flow rate, temperature and conductivity of fluid The system of Kartini reactor has been developed by introducing a process information system, start-up system, and automatic power control. It is concluded that the instrumentation of Kartini reactor has followed the requirement and standard of IAEA. (author)

  2. IAEA Safety Standards on Management Systems and Safety Culture

    International Nuclear Information System (INIS)

    Persson, Kerstin Dahlgren

    2007-01-01

    The IAEA has developed a new set of Safety Standard for applying an integrated Management System for facilities and activities. The objective of the new Safety Standards is to define requirements and provide guidance for establishing, implementing, assessing and continually improving a Management System that integrates safety, health, environmental, security, quality and economic related elements to ensure that safety is properly taken into account in all the activities of an organization. With an integrated approach to management system it is also necessary to include the aspect of culture, where the organizational culture and safety culture is seen as crucial elements of the successful implementation of this management system and the attainment of all the goals and particularly the safety goals of the organization. The IAEA has developed a set of service aimed at assisting it's Member States in establishing. Implementing, assessing and continually improving an integrated management system. (author)

  3. Vibration analysis of the Golfech 2 safety injection system

    International Nuclear Information System (INIS)

    Morilhat, P.

    1993-01-01

    The main function of the safety injection system in a PWR plant is to ensure cooling of fuel elements in the event of a loss of coolant accident. The multistage centrifugal pump mounted-on this system induces pressure fluctuations, resulting in dynamic loads on piping. In certain plant units, these loads have caused cracking in the nozzles connected to the safety injection system, whereas in others, no damage has been observed. In order to understand the differences in dynamic behavior observed from one site to another, tests were performed on a real safety injection system, that of Golfech-2. They enabled determination of the modal characteristics of the system and identification of the hydro-acoustic source of the low head safety injection pump. They also enabled assessment of the pressure fluctuation levels in the pump suction and discharge areas as well as the vibratory response of the system when operating under partial and nominal flow conditions. Finally, these test results were used to estimate fatigue damage in the safety injection system. The experimental results will later be used to validate the model of the system undertaken with the piping design code CIRCUS and define the boundary conditions to be taken into account. (author). 6 figs., 2 refs

  4. Safety functions and component classification for BWR, PWR and PTR

    International Nuclear Information System (INIS)

    1979-01-01

    The Safety Guide forms part of the IAEA programme, referred to as the NUSS programme (Nuclear Safety Standards), for establishing Codes of Practice and Safety Guides relating to thermal neutron power plants. The present Safety Guide has the following chapters: safety functions, ranking of safety functions, assignment of safety class requirements. Design requirements for structural integrity of boundaries of fluid-retaining components are also discussed

  5. Occupational Safety and Health System for Workers Engaged in Emergency Response Operations in the USA.

    Science.gov (United States)

    Toyoda, Hiroyuki; Kubo, Tatsuhiko; Mori, Koji

    2016-12-03

    To study the occupational safety and health systems used for emergency response workers in the USA, we performed interviews with related federal agencies and conducted research on related studies. We visited the Federal Emergency Management Agency (FEMA) and National Institute for Occupational Safety and Health (NIOSH) in the USA and performed interviews with their managers on the agencies' roles in the national emergency response system. We also obtained information prepared for our visit from the USA's Occupational Safety and Health Administration (OSHA). In addition, we conducted research on related studies and information on the website of the agencies. We found that the USA had an established emergency response system based on their National Incident Management System (NIMS). This enabled several organizations to respond to emergencies cooperatively using a National Response Framework (NRF) that clarifies the roles and cooperative functions of each federal agency. The core system in NIMS was the Incident Command System (ICS), within which a Safety Officer was positioned as one of the command staff supporting the commander. All ICS staff were required to complete a training program specific to their position; in addition, the Safety Officer was required to have experience. The All-Hazards model was commonly used in the emergency response system. We found that FEMA coordinated support functions, and OSHA and NIOSH, which had specific functions to protect workers, worked cooperatively under NRF. These agencies employed certified industrial hygienists that play a professional role in safety and health. NIOSH recently executed support activities during disasters and other emergencies. The USA's emergency response system is characterized by functions that protect the lives and health of emergency response workers. Trained and experienced human resources support system effectiveness. The findings provided valuable information that could be used to improve the

  6. Plant functional modelling as a basis for assessing the impact of management on plant safety

    International Nuclear Information System (INIS)

    Rasmussen, Birgitte; Petersen, Kurt E.

    1999-01-01

    A major objective of the present work is to provide means for representing a chemical process plant as a socio-technical system, so as to allow hazard identification at a high level in order to identify major targets for safety development. The main phases of the methodology are: (1) preparation of a plant functional model where a set of plant functions describes coherently hardware, software, operations, work organization and other safety related aspects. The basic principle is that any aspect of the plant can be represented by an object based upon an Intent and associated with each Intent are Methods, by which the Intent is realized, and Constraints, which limit the Intent. (2) Plant level hazard identification based on keywords/checklists and the functional model. (3) Development of incident scenarios and selection of hazardous situation with different safety characteristics. (4) Evaluation of the impact of management on plant safety through interviews. (5) Identification of safety critical ways of action in the management system, i.e. identification of possible error- and violation-producing conditions

  7. Safety logic systems of PFBR

    International Nuclear Information System (INIS)

    Sambasivan, S. Ilango

    2004-01-01

    Full text : PFBR is provided with two independent, fast acting and diverse shutdown systems to detect any abnormalities and to initiate safety action. Each system consists of sensors, signal processing systems, logics, drive mechanisms and absorber rods. The absorber rods of the first system are Control and Safety Rods (CSR) and that of the second are called as Diverse Safety Rods (DSR). There are nine CSR and three DSR. While CSR are used for startup, control of reactor power, controlled shutdown and SCRAM, the DSR are used only for SCRAM. The respective drive mechanisms are called as CSRDM and DSRDM. Each of these two systems is capable of executing the shutdown satisfactorily with single failure criteria. Two independent safety logic systems based on diverse principles have been designed for the two shut down systems. The analog outputs of the sensors of Core Monitoring Systems comprising of reactor flux monitoring, core temperature monitoring, failed fuel detection and core flow monitoring systems are processed and converted into binary signals depending on their instantaneous values. Safety logic systems receive the binary signals from these core-monitoring systems and process them logically to protect the reactor against postulated initiating events. Neutronic and power to flow (P/Q) signals form the inputs to safety logic system-I and temperature signals are inputs to the safety logic system II. Failed fuel detection signals are processed by both the shut down systems. The two logic systems to actuate the safety rods are also based on two diverse designs and implemented with solid-state devices to meet all the requirements of safety systems. Safety logic system I that caters to neutronic and P/Q signals is designed around combinational logic and has an on-line test facility to detect struck at faults. The second logic system is based on dynamic logic and hence is inherently safe. This paper gives an overview of the two logic systems that have been

  8. Diversity requirements for safety critical software-based automation systems

    International Nuclear Information System (INIS)

    Korhonen, J.; Pulkkinen, U.; Haapanen, P.

    1998-03-01

    System vendors nowadays propose software-based systems even for the most critical safety functions in nuclear power plants. Due to the nature and mechanisms of influence of software faults new methods are needed for the safety and reliability evaluation of these systems. In the research project 'Programmable automation systems in nuclear power plants (OHA)' various safety assessment methods and tools for software based systems are developed and evaluated. This report first discusses the (common cause) failure mechanisms in software-based systems, then defines fault-tolerant system architectures to avoid common cause failures, then studies the various alternatives to apply diversity and their influence on system reliability. Finally, a method for the assessment of diversity is described. Other recently published reports in OHA-report series handles the statistical reliability assessment of software based (STUK-YTO-TR 119), usage models in reliability assessment of software-based systems (STUK-YTO-TR 128) and handling of programmable automation in plant PSA-studies (STUK-YTO-TR 129)

  9. ICT support safety, health and environment management system (e-SHEMS)

    International Nuclear Information System (INIS)

    Amy Hamijah Ab Hamid; Hasfazilah Hassan; Siti Massari Amran; Norzalina Nasirudin; Azimawati Ahmad; Mohd Suhaimi Kassim; Shaharum Ramli; Musa Ibrahim; Mohd Sidek Othman

    2009-01-01

    Safety program is compulsory for a nuclear technology related research and development institution like Nuclear Malaysia. It has been implemented in various safety standard systems including Act 514, Act 304, ISO 14000, OSHAS 18001 and IAEA. This paper began with Nuclear Malaysia history in initiating our own safety standard system since 1982. Currently, Nuclear Malaysia's Safety Health and Environment Management System (SHE-MS) was stipulated for similar purpose. Furthermore, it has implemented guidelines by AELB, IAEA, DOSH, Fire Brigade and Police Force. This paper briefly describes the overall structure of SHE-MS, how it functions and being managed, and lessons learned. The findings which are based on the issues and challenges, then it can be analysed to propose a development of SHE-MS ICT-support application for future improvement and enhancement in inculcating and nurturing safety culture among Nuclear Malaysia staff. (Author)

  10. Safety of mechanical devices. Safety of automation systems

    International Nuclear Information System (INIS)

    Pahl, G.; Schweizer, G.; Kapp, K.

    1985-01-01

    The paper deals with the classic procedures of safety engineering in the sectors mechanical engineering, electrical and energy engineering, construction and transport, medicine technology and process technology. Particular stress is laid on the safety of automation systems, control technology, protection of mechanical devices, reactor safety, mechanical constructions, transport systems, railway signalling devices, road traffic and protection at work in chemical plans. (DG) [de

  11. Reactor safety: the Nova computer system

    International Nuclear Information System (INIS)

    Eisgruber, H.; Stadelmann, W.

    1991-01-01

    After instances of maloperation, the causes of defects, the effectiveness of the measures taken to control the situation, and possibilities to avoid future recurrences need to be investigated above all before the plant is restarted. The most important aspect in all these efforts is to check the sequence in time, and the completeness, of the control measures initiated automatically. For this verification, a computer system is used instead of time-consuming manual analytical techniques, which produces the necessary information almost in real time. The results are available within minutes after completion of the measures initiated automatically. As all short-term safety functions are initiated by automatic systems, their consistent and comprehensive verification results in a clearly higher level of safety. The report covers the development of the computer system, and its implementation, in the Gundremmingen nuclear power station. Similar plans are being pursued in Biblis and Muelheim-Kaerlich. (orig.) [de

  12. Interactive effects of relay and circuit breaker aging in a safety-related system

    International Nuclear Information System (INIS)

    Toman, G.J.; Bacanskas, V.P.; Shook, T.A.; Ladlow, C.C.; Gunther, W.

    1987-01-01

    This paper provides an overview of the results of a program to evaluate the aging of circuit breakers and relays and the effects of that aging on the function of a safety system used in nuclear power plants. The program was performed under the Nuclear Plant Aging Research (NPAR) Program of the US Nuclear Regulatory Commission under subcontract to Brookhaven National Laboratory. There were two primary aspects to the program. In the first, the aging and failure modes of relays and circuit breakers were determined by evaluating the construction, design, and materials and the failure data related to nuclear power plant service. In the second, the interactions between a safety system and its relays and circuit breakers were evaluated to determine the effects of relay and circuit breaker aging on the function of the safety system. The aging of relays and circuit breakers was assessed through evaluation of failure data bases, discussions with utility personnel, and evaluation of equipment operating and maintenance manuals. The interaction study was based on an analysis of the safety injection system of a pressurized water reactor. The effects of stresses from the system were analyzed for the tendency to cause deterioration of the relays and circuit breakers in the system. Then the effect of the deterioration of relays and circuit breakers on the functional capability of the safety system was evaluated

  13. Study of the Operational Safety of a Vascular Interventional Surgical Robotic System

    Directory of Open Access Journals (Sweden)

    Jian Guo

    2018-03-01

    Full Text Available This paper proposes an operation safety early warning system based on LabView (2014, National Instruments Corporation, Austin, TX, USA for vascular interventional surgery (VIS robotic system. The system not only provides intuitive visual feedback information for the surgeon, but also has a safety early warning function. It is well known that blood vessels differ in their ability to withstand stress in different age groups, therefore, the operation safety early warning system based on LabView has a vascular safety threshold function that changes in real-time, which can be oriented to different age groups of patients and a broader applicable scope. In addition, the tracing performance of the slave manipulator to the master manipulator is also an important index for operation safety. Therefore, we also transformed the slave manipulator and integrated the displacement error compensation algorithm in order to improve the tracking ability of the slave manipulator to the master manipulator and reduce master–slave tracking errors. We performed experiments “in vitro” to validate the proposed system. According to previous studies, 0.12 N is the maximum force when the blood vessel wall has been penetrated. Experimental results showed that the proposed operation safety early warning system based on LabView combined with operating force feedback can effectively avoid excessive collisions between the surgical catheter and vessel wall to avoid vascular puncture. The force feedback error of the proposed system is maintained between ±20 mN, which is within the allowable safety range and meets our design requirements. Therefore, the proposed system can ensure the safety of surgery.

  14. Evaluating safety management system implementation

    International Nuclear Information System (INIS)

    Preuss, M.

    2009-01-01

    Canada is committed to not only maintaining, but also improving upon our record of having one of the safest aviation systems in the world. The development, implementation and maintenance of safety management systems is a significant step towards improving safety performance. Canada is considered a world leader in this area and we are fully engaged in implementation. By integrating risk management systems and business practices, the aviation industry stands to gain better safety performance with less regulatory intervention. These are important steps towards improving safety and enhancing the public's confidence in the safety of Canada's aviation system. (author)

  15. Role of computers in CANDU safety systems

    International Nuclear Information System (INIS)

    Hepburn, G.A.; Gilbert, R.S.; Ichiyen, N.M.

    1985-01-01

    Small digital computers are playing an expanding role in the safety systems of CANDU nuclear generating stations, both as active components in the trip logic, and as monitoring and testing systems. The paper describes three recent applications: (i) A programmable controller was retro-fitted to Bruce ''A'' Nuclear Generating Station to handle trip setpoint modification as a function of booster rod insertion. (ii) A centralized monitoring computer to monitor both shutdown systems and the Emergency Coolant Injection system, is currently being retro-fitted to Bruce ''A''. (iii) The implementation of process trips on the CANDU 600 design using microcomputers. While not truly a retrofit, this feature was added very late in the design cycle to increase the margin against spurious trips, and has now seen about 4 unit-years of service at three separate sites. Committed future applications of computers in special safety systems are also described. (author)

  16. Research on communication system of underground safety management based on leaky feeder cable

    Institute of Scientific and Technical Information of China (English)

    CHEN Jian-hong; ZHANG Tao; CHENG Yun-cai; ZHANG Han

    2007-01-01

    According to the current working status of underground safety management and production scheduling, the importance and existed problem of underground mine radio communication were summarized, and the basic principle and classification of leaky feeder cable were introduced and the characteristics of cable were analyzed specifically in depth, and the application model of radio communication system for underground mine safety management was put forward. Meanwhile, the research explanation of the system component, function and evaluation was provided. The discussion result indicates that communication system of underground mine safety management which is integrated two-way relay amplifier and other equipment has many communication functions, and underground mine mobile communication can be achieved well.

  17. System Design and the Safety Basis

    International Nuclear Information System (INIS)

    Ellingson, Darrel

    2008-01-01

    The objective of this paper is to present the Bechtel Jacobs Company, LLC (BJC) Lessons Learned for system design as it relates to safety basis documentation. BJC has had to reconcile incomplete or outdated system description information with current facility safety basis for a number of situations in recent months. This paper has relevance in multiple topical areas including documented safety analysis, decontamination and decommissioning (D and D), safety basis (SB) implementation, safety and design integration, potential inadequacy of the safety analysis (PISA), technical safety requirements (TSR), and unreviewed safety questions. BJC learned that nuclear safety compliance relies on adequate and well documented system design information. A number of PIS As and TSR violations occurred due to inadequate or erroneous system design information. As a corrective action, BJC assessed the occurrences caused by systems design-safety basis interface problems. Safety systems reviewed included the Molten Salt Reactor Experiment (MSRE) Fluorination System, K-1065 fire alarm system, and the K-25 Radiation Criticality Accident Alarm System. The conclusion was that an inadequate knowledge of system design could result in continuous non-compliance issues relating to nuclear safety. This was especially true with older facilities that lacked current as-built drawings coupled with the loss of 'historical knowledge' as personnel retired or moved on in their careers. Walkdown of systems and the updating of drawings are imperative for nuclear safety compliance. System design integration with safety basis has relevance in the Department of Energy (DOE) complex. This paper presents the BJC Lessons Learned in this area. It will be of benefit to DOE contractors that manage and operate an aging population of nuclear facilities

  18. Determination of performance criteria of safety systems in a nuclear power plant via simulated annealing optimization method

    International Nuclear Information System (INIS)

    Jung, Woo Sik

    1993-02-01

    This study presents and efficient methodology that derives design alternatives and performance criteria of safety functions/systems in commercial nuclear power plants. Determination of design alternatives and intermediate-level performance criteria is posed as a reliability allocation problem. The reliability allocation is performed for determination of reliabilities of safety functions/systems from top-level performance criteria. The reliability allocation is a very difficult multi objective optimization problem (MOP) as well as a global optimization problem with many local minima. The weighted Chebyshev norm (WCN) approach in combination with an improved Metropolis algorithm of simulated annealing is developed and applied to the reliability allocation problem. The hierarchy of probabilistic safety criteria (PSC) may consist of three levels, which ranges from the overall top level (e.g., core damage frequency, acute fatality and latent cancer fatality) through the interlnediate level (e.g., unavailiability of safety system/function) to the low level (e.g., unavailability of components, component specifications or human error). In order to determine design alternatives of safety functions/systems and the intermediate-level PSC, the reliability allocation is performed from the top-level PSC. The intermediated level corresponds to an objective space and the top level is related to a risk space. The reliability allocation is performed by means of a concept of two-tier noninferior solutions in the objective and risk spaces within the top-level PSC. In this study, two kinds of towtier noninferior solutions are defined: intolerable intermediate-level PSC and desirable design alternatives of safety functions/systems that are determined from Sets 1 and 2, respectively. Set 1 is obtained by maximizing simultaneously not only safety function/system unavailabilities but also risks. Set 1 reflects safety function/system unavailabilities in the worst case. Hence, the

  19. Safety analyses of the electrical systems on VVER NPP

    International Nuclear Information System (INIS)

    Andel, J.

    2004-01-01

    Energoprojekt Praha has been the main entity responsible for the section on 'Electrical Systems' in the safety reports of the Temelin, Dukovany and Mochovce nuclear power plants. The section comprises 2 main chapters, viz. Offsite Power System (issues of electrical energy production in main generators and the link to the offsite transmission grid) and Onsite Power Systems (AC and DC auxiliary system, both normal and safety related). In the chapter on the off-site system, attention is paid to the analysis of transmission capacity of the 400 kV lines, analysis of transient stability, multiple fault analyses, and probabilistic analyses of the grid and NPP power system reliability. In the chapter on the on-site system, attention is paid to the power balances of the electrical sources and switchboards set for various operational and accident modes, checks of loading and function of service and backup sources, short circuit current calculations, analyses of electrical protections, and analyses of the function and sizing of emergency sources (DG sets and UPS systems). (P.A.)

  20. Safety Information System Guide

    International Nuclear Information System (INIS)

    Bullock, M.G.

    1977-03-01

    This Guide provides guidelines for the design and evaluation of a working safety information system. For the relatively few safety professionals who have already adopted computer-based programs, this Guide may aid them in the evaluation of their present system. To those who intend to develop an information system, it will, hopefully, inspire new thinking and encourage steps towards systems safety management. For the line manager who is working where the action is, this Guide may provide insight on the importance of accident facts as a tool for moving ideas up the communication ladder where they will be heard and acted upon; where what he has to say will influence beneficial changes among those who plan and control his operations. In the design of a safety information system, it is suggested that the safety manager make friends with a computer expert or someone on the management team who has some feeling for, and understanding of, the art of information storage and retrieval as a new and better means for communication

  1. Design and qualification of HPD based designs for safety systems

    International Nuclear Information System (INIS)

    Sharma, Mukesh Kr.; Chavan, Madhavi A.; Sawhney, Pratibha A.; Mohanty, Ashutos; John, Ajith K.; Ganesh, G.

    2014-01-01

    Field Programmable Gate Arrays (FPGA) and Complex Programmable Logic Devices (CPLD) are increasingly being used in C and I system of NPPs. The function of such an integrated circuit is not defined by the supplier of the physical component or micro-electronic technology but by the C and I designer. The hardware subsystems implemented in these devices typically use Hardware Description Language (HDL) like VHDL or Verilog to describe the functionality at the design entry level. These circuits are commonly known as 'HDL-Programmed Devices', (HPD). RCnD has developed a set of hardware boards to be used in next generation C and I systems. The boards have been designed based on present day technology and components. The intelligence of these boards has been implemented in HPDs (FPGA/CPLD) using VHDL. Since these boards are used in the safety and safety related systems, they have undergone a rigorous V and V process and qualification tests. This paper discusses the design attributes and qualification of these HPD based designs for nuclear class safety systems. (author)

  2. Squale: evaluation criteria of functioning safety; Squale: criteres d`evaluation de la surete de fonctionnement

    Energy Technology Data Exchange (ETDEWEB)

    Deswarte, Y; Kaaniche, M [Centre National de la Recherche Scientifique (CNRS), 31 - Toulouse (France). Laboratoire d` Analyse et d` Architecture des Systemes; Corneillie, P [CE2A-DI, 92 - Courbevoie (France); Benoit, P [Matra Transport International, 92 - Montrouge (France)

    1998-05-01

    The SQUALE (security, safety and quality evaluation for dependable systems) project is part of the ACTS (advanced communications, technologies and services) European program. Its aim is to develop confidence evaluation criteria to test the functioning safety of systems. All industrial sectors that use critical applications (nuclear, railway, aerospace..) are concerned. SQUALE evaluation criteria differ from the classical evaluation methods: they are independent of the application domains and industrial sectors, they take into account the overall functioning safety attributes, and they can progressively change according to the level of severity required. In order to validate the approach and to refine the criteria, a first experiment is in progress with the METEOR automatic underground railway and another will be carried out on a telecommunication system developed by Bouygues company. (J.S.) 15 refs.

  3. Architecture Level Safety Analyses for Safety-Critical Systems

    Directory of Open Access Journals (Sweden)

    K. S. Kushal

    2017-01-01

    Full Text Available The dependency of complex embedded Safety-Critical Systems across Avionics and Aerospace domains on their underlying software and hardware components has gradually increased with progression in time. Such application domain systems are developed based on a complex integrated architecture, which is modular in nature. Engineering practices assured with system safety standards to manage the failure, faulty, and unsafe operational conditions are very much necessary. System safety analyses involve the analysis of complex software architecture of the system, a major aspect in leading to fatal consequences in the behaviour of Safety-Critical Systems, and provide high reliability and dependability factors during their development. In this paper, we propose an architecture fault modeling and the safety analyses approach that will aid in identifying and eliminating the design flaws. The formal foundations of SAE Architecture Analysis & Design Language (AADL augmented with the Error Model Annex (EMV are discussed. The fault propagation, failure behaviour, and the composite behaviour of the design flaws/failures are considered for architecture safety analysis. The illustration of the proposed approach is validated by implementing the Speed Control Unit of Power-Boat Autopilot (PBA system. The Error Model Annex (EMV is guided with the pattern of consideration and inclusion of probable failure scenarios and propagation of fault conditions in the Speed Control Unit of Power-Boat Autopilot (PBA. This helps in validating the system architecture with the detection of the error event in the model and its impact in the operational environment. This also provides an insight of the certification impact that these exceptional conditions pose at various criticality levels and design assurance levels and its implications in verifying and validating the designs.

  4. Regulator Loss Functions and Hierarchical Modeling for Safety Decision Making.

    Science.gov (United States)

    Hatfield, Laura A; Baugh, Christine M; Azzone, Vanessa; Normand, Sharon-Lise T

    2017-07-01

    Regulators must act to protect the public when evidence indicates safety problems with medical devices. This requires complex tradeoffs among risks and benefits, which conventional safety surveillance methods do not incorporate. To combine explicit regulator loss functions with statistical evidence on medical device safety signals to improve decision making. In the Hospital Cost and Utilization Project National Inpatient Sample, we select pediatric inpatient admissions and identify adverse medical device events (AMDEs). We fit hierarchical Bayesian models to the annual hospital-level AMDE rates, accounting for patient and hospital characteristics. These models produce expected AMDE rates (a safety target), against which we compare the observed rates in a test year to compute a safety signal. We specify a set of loss functions that quantify the costs and benefits of each action as a function of the safety signal. We integrate the loss functions over the posterior distribution of the safety signal to obtain the posterior (Bayes) risk; the preferred action has the smallest Bayes risk. Using simulation and an analysis of AMDE data, we compare our minimum-risk decisions to a conventional Z score approach for classifying safety signals. The 2 rules produced different actions for nearly half of hospitals (45%). In the simulation, decisions that minimize Bayes risk outperform Z score-based decisions, even when the loss functions or hierarchical models are misspecified. Our method is sensitive to the choice of loss functions; eliciting quantitative inputs to the loss functions from regulators is challenging. A decision-theoretic approach to acting on safety signals is potentially promising but requires careful specification of loss functions in consultation with subject matter experts.

  5. Fundamental study on applicability of resilience index for system safety assessment

    International Nuclear Information System (INIS)

    Suzuki, Masaaki; Demachi, Kazuyuki; Murakami, Kenta

    2015-01-01

    We have developed a new index called Resilience index, which evaluate the reliability of system safety of nuclear power plant under severe accident by considering the capability to recover from the situation the system safety function was lost. In this paper, a detailed evaluation procedure for the Resilience index was described. System safety of a PWR plant under severe accident was then assessed according to the Resilience index concept to discuss applicability of the index. We found that the Resilience index successfully visualize the management capability, and therefore, resilience capability of a nuclear power plant. (author)

  6. Design characteristics of safety parameter display system for nuclear power plants

    International Nuclear Information System (INIS)

    Zhang Yuangfang

    1992-02-01

    The design features of safety parameter display system (SPDS) developed by Tsinghua University is introduced. Some new features have been added into the system functions and they are: (1) hierarchical display structure; (2) human factor in the display format design; (3)automatic diagnosis of safety status of nuclear power plant; (4) extension of SPDS use scope; (5) flexible hardware structure. The new approaches in the design are: (1)adopting the international design standards; (2) selecting safety parameters strictly; (3) developing software under multitask operating system; (4) using a nuclear power plant simulator to verify the SPDS design

  7. Implementation of safety parameter display system on Russian NPPs with WWER reactors

    International Nuclear Information System (INIS)

    Dounaev, V.G.; Neboyan, V.T.

    1996-01-01

    This report gives a short overview of the status of safety parameter display systems (SPDS) implementation on Russian NPPs with WWER reactors and also discusses the SPDS, which is being developed for Kalinin NPP. The assessment of the safety status of the plant is done by the continuous monitoring of six critical safety functions and the corresponding status trees. Besides, a number of additional functions are realized within the scope of KlnNPP, aimed at providing the operator and the safety engineer in the main control room with more detailed information in accidental situation as well as during the normal operation. In particular, these functions are: archiving, data logs and alarm handling, safety actions monitoring, mnemonic diagrams indicating the state of main technological equipment and basic plant parameters, reference data, etc. Also, the operator support function ''computerized procedures'' is included in the scope of SPDS. The basic SPDS implementation platform is ADACS of SEMA GROUP design. The system architecture includes two workstations in the main control room: one is for reactor operator and the other one for safety engineer. Every station has two CRT screens which ensures computerized procedures implementation and provides for extra services for the operator. Also, the information from the SPDS is transmitted to the local crisis centre and to the crisis centre of the State utility organization concern ''Rosenergoatom''. (author). 3 refs

  8. Modeling the critical safety functions status tree of a NPP using FPGA

    International Nuclear Information System (INIS)

    Farias, Marcos Santana; Oliveira, Mauro Vitor de; Jaime, Guilherme Dutra Gonzaga; Almeida, Jose Carlos Soares de; Augusto, Silas Cordeiro

    2013-01-01

    Field Programmable Gate Arrays (FPGAs) based systems and equipment are beginning to appear in new plants I and C applications, as well as in retrofits for operating plants, in particular for safety applications due to their capability to face the systems obsolescence since they are circuit independent. The circuits implemented can be portable to different FPGAs architectures. Moreover, they reduce complexity for regulatory approval as compared to conventional microprocessor-based systems. Critical safety function (CSF) is the most significant design concept for prioritize operator actions for NPP based on the potential threat to the three barriers (fuel cladding, primary coolant system boundary, and containment) and allows the operator to respond to these threats prior to event diagnosis. CSF has a hierarchical information structure that organizes the system variables affecting the plant safety in terms of goal-means relations. This paper describes the application of FPGA in the implementation of the CSFs status tree logic for a Westinghouse 3-loops NPP simulator. (author)

  9. HSI for monitoring the critical safety functions status tree of a NPP

    International Nuclear Information System (INIS)

    Oliveira, Mauro Vitor de; Almeida, Jose Carlos Soares de; Augusto, Silas Cordeiro; Jaime, Guilherme Dutra Gonzaga

    2013-01-01

    Critical safety function (CSF) is the most significant design concept for prioritize operator actions based on the potential threat to the three barriers (fuel cladding, primary coolant system boundary, and containment) and allows the operator to respond to these threats prior to event diagnosis. CSF has a hierarchical information structure that organizes the system variables affecting the plant safety in terms of goal-means relations. It is important that the operator should be aware of various success paths associated with each CSF in order to respond to unanticipated system failures quickly. When an emergency occurs in NPPs, the operator should monitor CSFs periodically and identify possible success paths as necessary, and try to stabilize or safely shut down the plant using emergency operating procedure (EOP) that includes steps to check the CSFs. This implies that safety function status check may become a cognitively burdensome task that needs to be supported by proper information display. The advanced human-system interface (HSI) in nuclear power plants provides an information environment that supports the operators' burdensome cognitive tasks. This paper describes a CSFs interface design for supporting the operator's tasks to monitor and identify the associated success path for Westinghouse 3-loops NPP. (author)

  10. Impact of proof test interval and coverage on probability of failure of safety instrumented function

    International Nuclear Information System (INIS)

    Jin, Jianghong; Pang, Lei; Hu, Bin; Wang, Xiaodong

    2016-01-01

    Highlights: • Introduction of proof test coverage makes the calculation of the probability of failure for SIF more accurate. • The probability of failure undetected by proof test is independently defined as P TIF and calculated. • P TIF is quantified using reliability block diagram and simple formula of PFD avg . • Improving proof test coverage and adopting reasonable test period can reduce the probability of failure for SIF. - Abstract: Imperfection of proof test can result in the safety function failure of safety instrumented system (SIS) at any time in its life period. IEC61508 and other references ignored or only elementarily analyzed the imperfection of proof test. In order to further study the impact of the imperfection of proof test on the probability of failure for safety instrumented function (SIF), the necessity of proof test and influence of its imperfection on system performance was first analyzed theoretically. The probability of failure for safety instrumented function resulted from the imperfection of proof test was defined as probability of test independent failures (P TIF ), and P TIF was separately calculated by introducing proof test coverage and adopting reliability block diagram, with reference to the simplified calculation formula of average probability of failure on demand (PFD avg ). Research results show that: the shorter proof test period and the higher proof test coverage indicate the smaller probability of failure for safety instrumented function. The probability of failure for safety instrumented function which is calculated by introducing proof test coverage will be more accurate.

  11. Reactor safety impact of functional test intervals: an application of Bayesian decision theory

    International Nuclear Information System (INIS)

    Buoni, F.B.

    1978-01-01

    Functional test intervals for important nuclear reactor systems can be obtained by viewing safety assessment as a decision process and functional testing as a Bayesian learning or information process. A preposterior analysis is used as the analytical model to find the preposterior expected reliability of a system as a function of test intervals. Persistent and transitory failure models are shown to yield different results. Functional tests of systems subject to persistent failure are effective in maintaining system reliability goals. Functional testing is not effective for systems subject to transitory failure; preventive maintenance must be used. A Bayesian posterior analysis of testing data can discriminate between persistent and transitory failure. The role of functional testing is seen to be an aid in assessing the future performance of reactor systems

  12. Use of digital computing devices in systems important to safety

    International Nuclear Information System (INIS)

    1986-01-01

    The incorporation of digital computing devices in systems important to safety now is progressing fast in several countries, including Canada, France, Federal Republic of Germany, Japan, USA. There are now reactors with microprocessors in some trip systems. The major functions of those systems are: reactor trip initiation, display, monitoring, testing, re-calibration of detectors. The benefits of moving to a fully computerized shut-down system should be improved reliability, greater flexibility, better man-machine interface, improved testing, higher reactor output and lower overall cost. With the introduction of computer devices in systems important to safety, plant availability and safety are improved because disturbances are treated before they lead to safety action, in this way helping the operator to avoid errors. The Meeting presentations were divided into sessions devoted to the following topics: Needs for the use of digital devices (DCD) in safety important systems (SIS) (5 papers); Problems raised by the integration SIS in the NPP control (7 papers); Description and presentation of DCD of SIS (6 papers); Results of experiences in engineering, manufacture, qualification operation of DCD hardware and software (5 papers). A separate abstract was prepared for each of these papers

  13. FOOD SAFETY CONTROL SYSTEM IN CHINA

    Institute of Scientific and Technical Information of China (English)

    Liu Wei-jun; Wei Yi-min; Han Jun; Luo Dan; Pan Jia-rong

    2007-01-01

    Most countries have expended much effort to develop food safety control systems to ensure safe food supplies within their borders. China, as one of the world's largest food producers and consumers,pays a lot of attention to food safety issues. In recent years, China has taken actions and implemented a series of plans in respect to food safety. Food safety control systems including regulatory, supervisory,and science and technology systems, have begun to be established in China. Using, as a base, an analysis of the current Chinese food safety control system as measured against international standards, this paper discusses the need for China to standardize its food safety control system. We then suggest some policies and measures to improve the Chinese food safety control system.

  14. Incorporating Traffic Control and Safety Hardware Performance Functions into Risk-based Highway Safety Analysis

    Directory of Open Access Journals (Sweden)

    Zongzhi Li

    2017-04-01

    Full Text Available Traffic control and safety hardware such as traffic signs, lighting, signals, pavement markings, guardrails, barriers, and crash cushions form an important and inseparable part of highway infrastructure affecting safety performance. Significant progress has been made in recent decades to develop safety performance functions and crash modification factors for site-specific crash predictions. However, the existing models and methods lack rigorous treatments of safety impacts of time-deteriorating conditions of traffic control and safety hardware. This study introduces a refined method for computing the Safety Index (SI as a means of crash predictions for a highway segment that incorporates traffic control and safety hardware performance functions into the analysis. The proposed method is applied in a computation experiment using five-year data on nearly two hundred rural and urban highway segments. The root-mean square error (RMSE, Chi-square, Spearman’s rank correlation, and Mann-Whitney U tests are employed for validation.

  15. A reliability assessment methodology for the VHTR passive safety system

    International Nuclear Information System (INIS)

    Lee, Hyungsuk; Jae, Moosung

    2014-01-01

    The passive safety system of a VHTR (Very High Temperature Reactor), which has recently attracted worldwide attention, is currently being considered for the design of safety improvements for the next generation of nuclear power plants in Korea. The functionality of the passive system does not rely on an external source of an electrical support system, but on the intelligent use of natural phenomena. Its function involves an ultimate heat sink for a passive secondary auxiliary cooling system, especially during a station blackout such as the case of the Fukushima Daiichi reactor accidents. However, it is not easy to quantitatively evaluate the reliability of passive safety for the purpose of risk analysis, considering the existing active system failure since the classical reliability assessment method cannot be applied. Therefore, we present a new methodology to quantify the reliability based on reliability physics models. This evaluation framework is then applied to of the conceptually designed VHTR in Korea. The Response Surface Method (RSM) is also utilized for evaluating the uncertainty of the maximum temperature of nuclear fuel. The proposed method could contribute to evaluating accident sequence frequency and designing new innovative nuclear systems, such as the reactor cavity cooling system (RCCS) in VHTR to be designed and constructed in Korea.

  16. Safety Analysis for Power Reactor Protection System

    International Nuclear Information System (INIS)

    Eisawy, E.A.; Sallam, H.

    2012-01-01

    The main function of a Reactor Protection System (RPS) is to safely shutdown the reactor and prevents the release of radioactive materials. The purpose of this paper is to present a technique and its application for used in the analysis of safety system of the Nuclear Power Plant (NPP). A more advanced technique has been presented to accurately study such problems as the plant availability assessments and Technical Specifications evaluations that are becoming increasingly important. The paper provides the Markov model for the Reactor Protection System of the NPP and presents results of model evaluations for two testing policies in technical specifications. The quantification of the Markov model provides the probability values that the system will occupy each of the possible states as a function of time.

  17. Safety integrity requirements for computer based I ampersand C systems

    International Nuclear Information System (INIS)

    Thuy, N.N.Q.; Ficheux-Vapne, F.

    1997-01-01

    In order to take into account increasingly demanding functional requirements, many instrumentation and control (I ampersand C) systems in nuclear power plants are implemented with computers. In order to ensure the required safety integrity of such equipment, i.e., to ensure that they satisfactorily perform the required safety functions under all stated conditions and within stated periods of time, requirements applicable to these equipment and to their life cycle need to be expressed and followed. On the other hand, the experience of the last years has led EDF (Electricite de France) and its partners to consider three classes of systems and equipment, according to their importance to safety. In the EPR project (European Pressurized water Reactor), these classes are labeled E1A, E1B and E2. The objective of this paper is to present the outline of the work currently done in the framework of the ETC-I (EPR Technical Code for I ampersand C) regarding safety integrity requirements applicable to each of the three classes. 4 refs., 2 figs

  18. Critical safety function guidelines for experimental fusion facilities

    International Nuclear Information System (INIS)

    Cadwallader, L.C.

    1989-01-01

    As fusion experiments proceed toward deuterium-tritium operation, more attention is being given to public safety. This paper presents the four classes of functions that fusion experiments must provide to assure safe, stable shutdown and retention of radionuclides. These functions are referred to as critical safety functions (CSFs). Selecting CSFs is an important step in probabilistic risk assessment (PRA). An example of CSF selection and usage for the Compact Ignition Tokamak (CIT) is also presented

  19. A study on optimization of the nuclear safety system

    International Nuclear Information System (INIS)

    Lee, Sang Hoon; Koh, Byung Joon; Kim, Jin Soo; Kim, Byoung Do; Cho, Seong Won; Kwon, Seog Kwon; Choi, Kwang Sik

    1986-12-01

    The number of nuclear facilities (nuclear power plants, research reactors, nuclear fuel facilities) under construction or in operation in Korea continues to increase and this has brought about increased importance and concerns toward nuclear safety in Korea. Also, domestic nuclear related organizations are increasingly carrying out the design/construction of nuclear power plants and the development /supply of nuclear fuels. In order to flexibly respond to these changes and to suggest direction to take, it is necessary to re-examine the current nuclear safety regulation system. This study is carried out in two stages and this report describes the results of the analysis and the assessment of the nuclear licencing system of such foreign countries as sweden and German, as the first of the two. In this regard, this study includes the analysis on the backgrounds on the choice of nuclear licensing system, the analysis on the licensing procedures, the analysis on the safety inspection system and the enforcement laws, the analysis on the structure and function of the regulatory, business and research organizations as well as the analysis on the relationship between the safety research and the regulatory duties. In this study, the German safety inspection system and the enforcement procedures and the Swedish nuclear licensing system are analyzed in detail. By comparing and assessing the finding with the current Korea Nuclear Licensing System, this study points out some reform measures of the Korean system that needs to improved. With the changing situations in mind, this study aims to develop the nuclear safety regulation system optimized for Korean situation by re-examining the current regulation system. (Author)

  20. Risk assessment of safety data link and network communication in digital safety feature control system of nuclear power plant

    International Nuclear Information System (INIS)

    Lee, Sang Hun; Son, Kwang Seop; Jung, Wondea; Kang, Hyun Gook

    2017-01-01

    Highlights: • Safety data communication risk assessment framework and quantitative scheme were proposed. • Fault-tree model of ESFAS unavailability due to safety data communication failure was developed. • Safety data link and network risk were assessed based on various ESF-CCS design specifications. • The effect of fault-tolerant algorithm reliability of safety data network on ESFAS unavailability was assessed. - Abstract: As one of the safety-critical systems in nuclear power plants (NPPs), the Engineered Safety Feature-Component Control System (ESF-CCS) employs safety data link and network communication for the transmission of safety component actuation signals from the group controllers to loop controllers to effectively accommodate various safety-critical field controllers. Since data communication failure risk in the ESF-CCS has yet to be fully quantified, the ESF-CCS employing data communication systems have not been applied in NPPs. This study therefore developed a fault tree model to assess the data link and data network failure-induced unavailability of a system function used to generate an automated control signal for accident mitigation equipment. The current aim is to provide risk information regarding data communication failure in a digital safety feature control system in consideration of interconnection between controllers and the fault-tolerant algorithm implemented in the target system. Based on the developed fault tree model, case studies were performed to quantitatively assess the unavailability of ESF-CCS signal generation due to data link and network failure and its risk effect on safety signal generation failure. This study is expected to provide insight into the risk assessment of safety-critical data communication in a digitalized NPP instrumentation and control system.

  1. Design Information from the PSA for Digital Safety-Critical Systems

    International Nuclear Information System (INIS)

    Kang, Hyun Gook; Jang, Seung Cheol

    2005-01-01

    Many safety-critical applications such as nuclear field application usually adopt a similar design strategy for digital safety-critical systems. Their differences from the normal design for the non-safety-critical applications could be summarized as: multiple-redundancy, highly reliable components, strengthened monitoring mechanism, verified software, and automated test procedure. These items are focusing on maintaining the capability to perform the given safety function when it is requested. For the past several decades, probabilistic safety assessment (PSA) techniques are used in the nuclear industry to assess the relative effects of contributing events on plant risk and system reliability. They provide a unifying means of assessing physical faults, recovery processes, contributing effects, human actions, and other events that have a high degree of uncertainty. The applications of PSA provide not only the analysis results of already installed system but also the useful information for the system under design. The information could be derived from the PSA experience of the various safety-critical systems. Thanks to the design flexibility, the digital system is one of the most suitable candidates for risk-informed design (RID). In this article, we will describe the feedbacks for system design and try to develop a procedure for RID. Even though the procedure is not sophisticated enough now, it could be the start point of the further investigation for developing more complete and practical methodology

  2. NASA System Safety Handbook. Volume 1; System Safety Framework and Concepts for Implementation

    Science.gov (United States)

    Dezfuli, Homayoon; Benjamin, Allan; Everett, Christopher; Smith, Curtis; Stamatelatos, Michael; Youngblood, Robert

    2011-01-01

    System safety assessment is defined in NPR 8715.3C, NASA General Safety Program Requirements as a disciplined, systematic approach to the analysis of risks resulting from hazards that can affect humans, the environment, and mission assets. Achievement of the highest practicable degree of system safety is one of NASA's highest priorities. Traditionally, system safety assessment at NASA and elsewhere has focused on the application of a set of safety analysis tools to identify safety risks and formulate effective controls.1 Familiar tools used for this purpose include various forms of hazard analyses, failure modes and effects analyses, and probabilistic safety assessment (commonly also referred to as probabilistic risk assessment (PRA)). In the past, it has been assumed that to show that a system is safe, it is sufficient to provide assurance that the process for identifying the hazards has been as comprehensive as possible and that each identified hazard has one or more associated controls. The NASA Aerospace Safety Advisory Panel (ASAP) has made several statements in its annual reports supporting a more holistic approach. In 2006, it recommended that "... a comprehensive risk assessment, communication and acceptance process be implemented to ensure that overall launch risk is considered in an integrated and consistent manner." In 2009, it advocated for "... a process for using a risk-informed design approach to produce a design that is optimally and sufficiently safe." As a rationale for the latter advocacy, it stated that "... the ASAP applauds switching to a performance-based approach because it emphasizes early risk identification to guide designs, thus enabling creative design approaches that might be more efficient, safer, or both." For purposes of this preface, it is worth mentioning three areas where the handbook emphasizes a more holistic type of thinking. First, the handbook takes the position that it is important to not just focus on risk on an individual

  3. Benefits of a systematic approach to maintenance for safety and safety related systems

    International Nuclear Information System (INIS)

    Dam, R.F.; Ayazzudin, S.; Nickerson, J.H.

    2003-01-01

    For safety and safety-related systems, nuclear plants have to balance the requirements of demonstrating the reliability of each system, while maintaining the system and plant availability. With the goal of demonstrating statistical reliability, these systems have extensive testing programs, which often results in system unavailability and this can impact the plant capacity. The inputs to the process are often safety and regulatory related, resulting in programs that provide a high level of scrutiny. In such cases, the value of the application of a Systematic Assessment of Maintenance (SAM) process, such as Reliability Centered Maintenance (RCM), is questioned. The special case of Standby-Safety systems was discussed in a previous paper, where it was demonstrated how SAM techniques provide useful insight into current system performance, the impact of testing on component and system reliability, and how PSA considerations can be integrated into a comprehensive Maintenance, Surveillance, and Inspection (MSI) strategy. Although the system reliability requirements are an important part of the strategy evaluation, SAM techniques provide a systematic assessment within a broader context. Testing is only one part of an overall strategy focused on ensuring that component function is maintained through a combination of monitoring technologies (including testing), predictive techniques, and intrusive maintenance strategies. Each strategy is targeted to known component degradation mechanisms. This thinking can be extended to safety and safety related systems in general. Over the past 6 years, AECL has been working with CANDU utilities in the development and implementation of a comprehensive and integrated Plant Life Management (PLiM) program. As part of developing a comprehensive plant asset management approach, SAM techniques are used to develop a technical basis that not only works towards ensuring reliable operation of plant systems, but also facilitates the optimization and

  4. Critical safety function guidelines for experimental fusion facilities

    International Nuclear Information System (INIS)

    Cadwallader, L.C.

    1989-01-01

    As fusion experiments proceed toward deuterium-tritium operation, more attention is being given to public safety. This paper presents the four classes of functions that fusion experiments must provide to assure safe, stable shutdown and retention of radionuclides. These functions are referred to as critical safety functions (CSFs). Selecting CSFs is an important step in probabilistic risk assessment (PRA). An example of CSF selection and usage for the Compact Ignition Tokamak (CIT) is also presented. 10 refs., 6 figs

  5. Cyber Security Risk Assessment for the KNICS Safety Systems

    International Nuclear Information System (INIS)

    Lee, C. K.; Park, G. Y.; Lee, Y. J.; Choi, J. G.; Kim, D. H.; Lee, D. Y.; Kwon, K. C.

    2008-01-01

    In the Korea Nuclear I and C Systems Development (KNICS) project the platforms for plant protection systems are developed, which function as a reactor shutdown, actuation of engineered safety features and a control of the related equipment. Those are fully digitalized through the use of safety-grade programmable logic controllers (PLCs) and communication networks. In 2006 the Regulatory Guide 1.152 (Rev. 02) was published by the U.S. NRC and it describes the application of a cyber security to the safety systems in the Nuclear Power Plant (NPP). Therefore it is required that the new requirements are incorporated into the developed platforms to apply to NPP, and a cyber security risk assessment is performed. The results of the assessment were input for establishing the cyber security policies and planning the work breakdown to incorporate them

  6. Computational methods for criticality safety analysis within the scale system

    International Nuclear Information System (INIS)

    Parks, C.V.; Petrie, L.M.; Landers, N.F.; Bucholz, J.A.

    1986-01-01

    The criticality safety analysis capabilities within the SCALE system are centered around the Monte Carlo codes KENO IV and KENO V.a, which are both included in SCALE as functional modules. The XSDRNPM-S module is also an important tool within SCALE for obtaining multiplication factors for one-dimensional system models. This paper reviews the features and modeling capabilities of these codes along with their implementation within the Criticality Safety Analysis Sequences (CSAS) of SCALE. The CSAS modules provide automated cross-section processing and user-friendly input that allow criticality safety analyses to be done in an efficient and accurate manner. 14 refs., 2 figs., 3 tabs

  7. Instrumentation and control systems important to safety in nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2005-01-01

    This Safety Guide was prepared under the IAEA programme for establishing safety standards for nuclear power plants. It supplements Safety Standards Series No. NS-R-1: Safety of Nuclear Power Plants: Design (the Requirements for Design), which establishes the design requirements for ensuring the safety of nuclear power plants. This Safety Guide describes how the requirements should be met for instrumentation and control (I and C) systems important to safety. This publication is a revision and combination of two previous Safety Guides: Safety Series Nos 50-SG-D3 and 50-SG-D8, which are superseded by this new Safety Guide. The revision takes account of developments in I and C systems important to safety since the earlier Safety Guides were published in 1980 and 1984, respectively. The objective of this Safety Guide is to provide guidance on the design of I and C systems important to safety in nuclear power plants, including all I and C components, from the sensors allocated to the mechanical systems to the actuated equipment, operator interfaces and auxiliary equipment. This Safety Guide deals mainly with design requirements for those I and C systems that are important to safety. It expands on paragraphs of Ref in the area of I and C systems important to safety. This publication is intended for use primarily by designers of nuclear power plants and also by owners and/or operators and regulators of nuclear power plants. This Safety Guide provides general guidance on I and C systems important to safety which is broadly applicable to many nuclear power plants. More detailed requirements and limitations for safe operation specific to a particular plant type should be established as part of the design process. The present guidance is focused on the design principles for systems important to safety that warrant particular attention, and should be applied to both the design of new I and C systems and the modernization of existing systems. Guidance is provided on how design

  8. Preliminary design of safety and interlock system for indian test facility of diagnostic neutral beam

    International Nuclear Information System (INIS)

    Tyagi, Himanshu; Soni, Jignesh; Yadav, Ratnakar; Bandyopadhyay, Mainak; Rotti, Chandramouli; Gahlaut, Agrajit; Joshi, Jaydeep; Parmar, Deepak; Bansal, Gourab; Pandya, Kaushal; Chakraborty, Arun

    2016-01-01

    Highlights: • Indian Test Facility being built to characterize DNB for ITER delivery. • Interlock system required to safeguard the investment incurred in building the facility and protecting ITER deliverable components. • Interlock levels upto 3IL-3 identified. • Safety instrumented system for occupational safety being designed. Safety I&C functions of SIL-2 identified. • The systems are based on ITER PIS and PSS design guidelines. - Abstract: Indian Test Facility (INTF) is being built in Institute For Plasma Research to characterize Diagnostic Neutral Beam in co-operation with ITER Organization. INTF is a complex system which consists of several plant systems like beam source, gas feed, vacuum, cryogenics, high voltage power supplies, high power RF generators, mechanical systems and diagnostics systems. Out of these, several INTF components are ITER deliverable, that is, beam source, beam line components and power supplies. To ensure successful operation of INTF involving integrated operation of all the constituent plant systems a matured Data Acquisition and Control System (DACS) is required. The INTF DACS is based on CODAC platform following on PCDH (Plant Control Design Handbook) guidelines. The experimental phases involve application of HV power supplies (100 KV) and High RF power (∼800 KW) which will produce energetic beam of maximum power 6MW within the facility for longer durations. Hence the entire facility will be exposed tohigh heat fluxes and RF radiations. To ensure investment protection and to provide occupational safety for working personnel a matured Safety and Interlock system is required for INTF. The Safety and Interlock systems are high-reliability I&C systems devoted completely to the specific functions. These systems will be separate from the conventional DACS of INTF which will handle the conventional control and acquisition functions. Both, the Safety and Interlock systems are based on IEC 61511 and IEC 61508 standards as

  9. Preliminary design of safety and interlock system for indian test facility of diagnostic neutral beam

    Energy Technology Data Exchange (ETDEWEB)

    Tyagi, Himanshu, E-mail: htyagi@iter-india.org [ITER-India, Institute For Plasma Research, Bhat, Gandhinagar, Gujarat (India); Soni, Jignesh [Institute For Plasma Research, Bhat, Gandhinagar, Gujarat (India); Yadav, Ratnakar; Bandyopadhyay, Mainak; Rotti, Chandramouli [ITER-India, Institute For Plasma Research, Bhat, Gandhinagar, Gujarat (India); Gahlaut, Agrajit [Institute For Plasma Research, Bhat, Gandhinagar, Gujarat (India); Joshi, Jaydeep; Parmar, Deepak [ITER-India, Institute For Plasma Research, Bhat, Gandhinagar, Gujarat (India); Bansal, Gourab; Pandya, Kaushal; Chakraborty, Arun [Institute For Plasma Research, Bhat, Gandhinagar, Gujarat (India)

    2016-11-15

    Highlights: • Indian Test Facility being built to characterize DNB for ITER delivery. • Interlock system required to safeguard the investment incurred in building the facility and protecting ITER deliverable components. • Interlock levels upto 3IL-3 identified. • Safety instrumented system for occupational safety being designed. Safety I&C functions of SIL-2 identified. • The systems are based on ITER PIS and PSS design guidelines. - Abstract: Indian Test Facility (INTF) is being built in Institute For Plasma Research to characterize Diagnostic Neutral Beam in co-operation with ITER Organization. INTF is a complex system which consists of several plant systems like beam source, gas feed, vacuum, cryogenics, high voltage power supplies, high power RF generators, mechanical systems and diagnostics systems. Out of these, several INTF components are ITER deliverable, that is, beam source, beam line components and power supplies. To ensure successful operation of INTF involving integrated operation of all the constituent plant systems a matured Data Acquisition and Control System (DACS) is required. The INTF DACS is based on CODAC platform following on PCDH (Plant Control Design Handbook) guidelines. The experimental phases involve application of HV power supplies (100 KV) and High RF power (∼800 KW) which will produce energetic beam of maximum power 6MW within the facility for longer durations. Hence the entire facility will be exposed tohigh heat fluxes and RF radiations. To ensure investment protection and to provide occupational safety for working personnel a matured Safety and Interlock system is required for INTF. The Safety and Interlock systems are high-reliability I&C systems devoted completely to the specific functions. These systems will be separate from the conventional DACS of INTF which will handle the conventional control and acquisition functions. Both, the Safety and Interlock systems are based on IEC 61511 and IEC 61508 standards as

  10. Nanotechnology in food science: Functionality, applicability, and safety assessment

    Directory of Open Access Journals (Sweden)

    Xiaojia He

    2016-10-01

    Full Text Available Rapid development of nanotechnology is expected to transform many areas of food science and food industry with increasing investment and market share. In this article, current applications of nanotechnology in food systems are briefly reviewed. Functionality and applicability of food-related nanotechnology are highlighted in order to provide a comprehensive view on the development and safety assessment of nanotechnology in the food industry. While food nanotechnology offers great potential benefits, there are emerging concerns arising from its novel physicochemical properties. Therefore, the safety concerns and regulatory policies on its manufacturing, processing, packaging, and consumption are briefly addressed. At the end of this article, the perspectives of nanotechnology in active and intelligent packaging applications are highlighted.

  11. How could intelligent safety transport systems enhance safety ?

    NARCIS (Netherlands)

    Wiethoff, M. Heijer, T. & Bekiaris, E.

    2017-01-01

    In Europe, many deaths and injured each years are the cost of today's road traffic. Therefore, it is wise to look for possible solutions for enhancing traffic safety. Some Advanced Driver Assistance Systems (ADAS) are expected to increase safety, but they may also evoke new safety hazards. Only

  12. Safety parameter display system: an operator support system for enhancement of safety in Indian PHWRs

    International Nuclear Information System (INIS)

    Subramaniam, K.; Biswas, T.

    1994-01-01

    Ensuring operational safety in nuclear power plants is important as operator errors are observed to contribute significantly to the occurrence of accidents. Computerized operator support systems, which process and structure information, can help operators during both normal and transient conditions, and thereby enhance safety and aid effective response to emergency conditions. An important operator aid being developed and described in this paper, is the safety parameter display system (SPDS). The SPDS is an event-independent, symptom-based operator aid for safety monitoring. Knowledge-based systems can provide operators with an improved quality of information. An information processing model of a knowledge based operator support system (KBOSS) developed for emergency conditions using an expert system shell is also presented. The paper concludes with a discussion of the design issues involved in the use of a knowledge based systems for real time safety monitoring and fault diagnosis. (author). 8 refs., 4 figs., 1 tab

  13. Automatic creation of Markov models for reliability assessment of safety instrumented systems

    International Nuclear Information System (INIS)

    Guo Haitao; Yang Xianhui

    2008-01-01

    After the release of new international functional safety standards like IEC 61508, people care more for the safety and availability of safety instrumented systems. Markov analysis is a powerful and flexible technique to assess the reliability measurements of safety instrumented systems, but it is fallible and time-consuming to create Markov models manually. This paper presents a new technique to automatically create Markov models for reliability assessment of safety instrumented systems. Many safety related factors, such as failure modes, self-diagnostic, restorations, common cause and voting, are included in Markov models. A framework is generated first based on voting, failure modes and self-diagnostic. Then, repairs and common-cause failures are incorporated into the framework to build a complete Markov model. Eventual simplification of Markov models can be done by state merging. Examples given in this paper show how explosively the size of Markov model increases as the system becomes a little more complicated as well as the advancement of automatic creation of Markov models

  14. Expanding pedestrian injury risk to the body region level: how to model passive safety systems in pedestrian injury risk functions.

    Science.gov (United States)

    Niebuhr, Tobias; Junge, Mirko; Achmus, Stefanie

    2015-01-01

    decomposable into the 3 body regions and so are the risk functions as body region-specific risk functions. The risk functions for each body region are stated explicitly for different injury severity levels and compared to the real-world accident data. The body region-specific risk functions can then be used to model the effect of improved passive safety systems. These modified body region-specific injury risk functions are aggregated to a new pedestrian injury risk function. Passive safety systems can therefore be modeled in injury risk functions for the first time. A short example on how the results can be used for assessing the effectiveness of new driver assistance systems concludes the article.

  15. Comprehensive Lifecycle for Assuring System Safety

    Science.gov (United States)

    Knight, John C.; Rowanhill, Jonathan C.

    2017-01-01

    CLASS is a novel approach to the enhancement of system safety in which the system safety case becomes the focus of safety engineering throughout the system lifecycle. CLASS also expands the role of the safety case across all phases of the system's lifetime, from concept formation to decommissioning. As CLASS has been developed, the concept has been generalized to a more comprehensive notion of assurance becoming the driving goal, where safety is an important special case. This report summarizes major aspects of CLASS and contains a bibliography of papers that provide additional details.

  16. Manufacture of Platform Prototype for Digital Safety System

    International Nuclear Information System (INIS)

    Lee, S. Y.; Kim, J. S.; Kim, J. M.

    2010-01-01

    Unit controller is a basic unit of digital safety system platform prototype. The typical unit controller is comprised of CPB(CPU board), CMB(communication board), AIB(Analog input board), AOB(Analog output board), CIB(contact input board), COB(contact output board), and a subrack. It is developed according to H/W development procedure and S/W development life cycle. A digital safety system(for example, plant protection system) is the assemblies of unit controllers. CPB performs the function of each system. DSP(digital signal processor) is built in CPB. CMB is responsible for communication between unit controllers. NSD(Network Switching Device) exchanges data between the unit controllers. Each unit controller of the platform are connected to NSD through CMB. Reliability analyses on unit controller and NSD are performed. These reliability data are used as input of technical validation

  17. Safety-related control air systems

    International Nuclear Information System (INIS)

    Anon.

    1977-01-01

    This Standard applies to those portions of the control air system that furnish air required to support, control, or operate systems or portions of systems that are safety related in nuclear power plants. This Standard relates only to the air supply system(s) for safety-related air operated devices and does not apply to the safety-related air operated device or to air operated actuators for such devices. The objectives of this Standard are to provide (1) minimum system design requirements for equipment, piping, instruments, controls, and wiring that constitute the air supply system; and (2) the system and component testing and maintenance requirements

  18. Functionality of road safety devices – identification and analysis of factors

    Directory of Open Access Journals (Sweden)

    Jeliński Łukasz

    2017-01-01

    Full Text Available Road safety devices are designed to protect road users from the risk of injury or death. The principal type of restraint is the safety barrier. Deployed on sites with the highest risk of run-off-road accidents, safety barriers are mostly found on bridges, flyovers, central reservations, and on road edges which have fixed obstacles next to them. If properly designed and installed, safety barriers just as other road safety devices, should meet a number of functional features. This report analyses factors which may deteriorate functionality, ways to prevent this from happening and the thresholds for loss of road safety device functionality.

  19. Protection and safety functions of different off-gas treatment systems in radioactive waste incineration

    International Nuclear Information System (INIS)

    Caramelle, D.; Chevalier, G.; Chevalier, G.

    1986-01-01

    Gaseous effluent cleaning installations are designed to protect workmen and environment and must be efficient enough to guarantee that the amounts of gases and dusts emitted by a furnace operating normally or accidentally are at an acceptable level in the atmosphere on the incinerator site. The process equipments necessary to operations and the monitoring devices must be reliable. The main risk in normal operation is occupational exposure close to the radioactive products accumulation points. The accidental risks are mainly related to an outage of the off-gas cleaning or a tightness failure with radioactive products dissemination resulting from either internal perturbation (filter tear, exhauster failure, ...) or external incident (electricity cut-off, furnace disarrangements, fire or explosion inside the incinerator). In view of these risks, it is interesting to examine the safety and protection functions of different components of off-gas treatment systems

  20. On the safety of aircraft systems: A case study

    Energy Technology Data Exchange (ETDEWEB)

    Martinez-Guridi, G.; Hall, R.E.; Fullwood, R.R.

    1997-05-14

    An airplane is a highly engineered system incorporating control- and feedback-loops which often, and realistically, are non-linear because the equations describing such feedback contain products of state variables, trigonometric or square-root functions, or other types of non-linear terms. The feedback provided by the pilot (crew) of the airplane also is typically non-linear because it has the same mathematical characteristics. An airplane is designed with systems to prevent and mitigate undesired events. If an undesired triggering event occurs, an accident may process in different ways depending on the effectiveness of such systems. In addition, the progression of some accidents requires that the operating crew take corrective action(s), which may modify the configuration of some systems. The safety assessment of an aircraft system typically is carried out using ARP (Aerospace Recommended Practice) 4761 (SAE, 1995) methods, such as Fault Tree Analysis (FTA) and Failure Mode and Effects Analysis (FMEA). Such methods may be called static because they model an aircraft system on its nominal configuration during a mission time, but they do not incorporate the action(s) taken by the operating crew, nor the dynamic behavior (non-linearities) of the system (airplane) as a function of time. Probabilistic Safety Assessment (PSA), also known as Probabilistic Risk Assessment (PRA), has been applied to highly engineered systems, such as aircraft and nuclear power plants. PSA encompasses a wide variety of methods, including event tree analysis (ETA), FTA, and common-cause analysis, among others. PSA should not be confused with ARP 4761`s proposed PSSA (Preliminary System Safety Assessment); as its name implies, PSSA is a preliminary assessment at the system level consisting of FTA and FMEA.

  1. Efficiency of the functioning of the state control system for the safety and quality of animal products in Ukraine

    Directory of Open Access Journals (Sweden)

    I. Kyryliuk

    2017-12-01

    Full Text Available The study reveals the results of evaluating the effectiveness of the state control system (supervision on the safety and individual indicators of the quality of livestock products in Ukraine. The necessity of application of such components of efficiency as legislation, management and its organizational structure, inspection and laboratory service, information, training and communications is substantiated. It has been determined that during a sufficiently long period of time (until 2015, the system of state control (supervision was archaic and actually focused on the principles of command and administrative economy. The modern tendencies and specifics of the improvement of the Ukrainian control system in the direction of its harmonization with the European one are shown. The emphasis was on significant volumes of work that needed to be done in a very short time, as well as in the absence of adequate funding and appropriate skilled specialists. The emergence of clarity and unambiguousness in determining the responsibility of market operators for violating the legislation requirements in the field of production and circulation of animal origin food products was emphasized. Along with the achievements, there were identified systemic problems related to the technical regulation of safety assurance processes and individual quality indicators in Ukraine. Also it was noted and revealed that legislation in the area of guaranteeing the quality and safety of livestock products in Ukraine remains incomplete and not fully developed. The necessity of development of a number of by-laws and allocation of necessary financing for effective functioning of the state control system over product safety is substantiated. Article specified on the presence of insufficient number of professional inspection and laboratory services is underlined. The mechanisms of avoiding corruption risks and excessive pressure on the subjects of the livestock production market are

  2. A sensor monitoring system for telemedicine, safety and security applications

    Science.gov (United States)

    Vlissidis, Nikolaos; Leonidas, Filippos; Giovanis, Christos; Marinos, Dimitrios; Aidinis, Konstantinos; Vassilopoulos, Christos; Pagiatakis, Gerasimos; Schmitt, Nikolaus; Pistner, Thomas; Klaue, Jirka

    2017-02-01

    A sensor system capable of medical, safety and security monitoring in avionic and other environments (e.g. homes) is examined. For application inside an aircraft cabin, the system relies on an optical cellular network that connects each seat to a server and uses a set of database applications to process data related to passengers' health, safety and security status. Health monitoring typically encompasses electrocardiogram, pulse oximetry and blood pressure, body temperature and respiration rate while safety and security monitoring is related to the standard flight attendance duties, such as cabin preparation for take-off, landing, flight in regions of turbulence, etc. In contrast to previous related works, this article focuses on the system's modules (medical and safety sensors and associated hardware), the database applications used for the overall control of the monitoring function and the potential use of the system for security applications. Further tests involving medical, safety and security sensing performed in an real A340 mock-up set-up are also described and reference is made to the possible use of the sensing system in alternative environments and applications, such as health monitoring within other means of transport (e.g. trains or small passenger sea vessels) as well as for remotely located home users, over a wired Ethernet network or the Internet.

  3. A Methodological Framework for Software Safety in Safety Critical Computer Systems

    OpenAIRE

    P. V. Srinivas Acharyulu; P. Seetharamaiah

    2012-01-01

    Software safety must deal with the principles of safety management, safety engineering and software engineering for developing safety-critical computer systems, with the target of making the system safe, risk-free and fail-safe in addition to provide a clarified differentaition for assessing and evaluating the risk, with the principles of software risk management. Problem statement: Prevailing software quality models, standards were not subsisting in adequately addressing the software safety ...

  4. Safety parameter display system functions are integrated parts of the KWU KONVOI process information system (SPDS functions are parts of the KWU-PRINS)

    International Nuclear Information System (INIS)

    Aleite, W.; Geyer, K.H.

    1984-01-01

    The desirability of having flexible overview as well as extended detail information with pictorial and abstraction features and easy and quick access throughout the large-size control rooms in German plants has been recognized. Developments over the last years now make it possible to add on extensive computer driven VDU-systems to the three German KONVOI NPPs (Isar II, Emsland and Neckarwestheim II) thereby creating the Process Information System ''PRINS''. The new system is driven by multiple computers at different locations controlling about 30 full-graphic, high resolution Video Display Units. They are arranged singly and in three ''mxn - Information Panels'' distributed about the control room and present all thinkable kinds of display formats with more than 1000 separate pictures. The display of only single ''Safety Parameters'' or even complete ''Safety Goal Information'' on single or multiple VDUs in parallel is only one aspect of this computerized part of the entire integrated Information System. (orig./HP)

  5. Study of system safety evaluation on LTO of national project. NISA safety research project on system safety of nuclear power plants

    International Nuclear Information System (INIS)

    Takizawa, Masayuki; Sekimura, Naoto; Miyano, Hiroshi; Aoyama, Katsunobu

    2012-01-01

    Japanese safety regulatory body, that is, Nuclear and Industrial Safety Agency (NISA) started a 5-year national safety research project as 'the first stage' from 2006 FY to 2010 FY whose objective is 'Improve the technical information basis in order to utilize knowledge as well as information related to ageing management and maintenance of NPPs. Fukushima disaster happened in March 2011, and the priority of research needs for ageing management dramatically changed in Japan. The second-stage national project started in October 2011 with the concept of 'system safety' of NNPs where not only ageing management on degradation phenomena of important components but also safety management on total plant systems are paid attention to. The second-stage project is so called 'Japanese Ageing Management Program for System Safety (JAMPSS)'. (author)

  6. Perceived Neighborhood Safety and Adolescent School Functioning

    Science.gov (United States)

    Martin-Storey, Alexa; Crosnoe, Robert

    2014-01-01

    This study examined the association between adolescents' perceptions of their neighborhoods' safety and multiple elements of their functioning in school with data on 15 year olds from the NICHD Study of Early Child Care and Youth Development (n = 924). In general, perceived neighborhood safety was more strongly associated with aspects of schooling…

  7. Status of the EU test blanket systems safety studies

    International Nuclear Information System (INIS)

    Panayotov, Dobromir; Poitevin, Yves; Ricapito, Italo; Zmitko, Milan

    2015-01-01

    Highlights: • TBS safety demonstration files. • Safety functions and related design features – detailed TBS components classifications. • Nuclear analyses, radiation shielding and protection. • TBS radiological waste management strategy and categorization. • Selection and definition of reference accidents scenarios and accidents analyses. - Abstract: The European joint undertaking for ITER and the development of fusion energy (‘Fusion for Energy’ – F4E) provides the European contributions to the ITER international fusion energy research project. Among others it includes also the development, design, technological demonstration and implementation of the European test blanket systems (TBS) in ITER. Currently two EU TBS designs are in the phase of conceptual design – helium-cooled lithium-lead (HCLL) and helium-cooled pebble-bed (HCPB). Safety demonstration is an important part of the work devoted to the achievement of the next key project milestone the conceptual design review. The paper reveals the details of the work on EU TBS safety performed in the last couple of years: update of the TBS safety demonstration files; safety functions and related design features; detailed TBS components classifications; nuclear analyses, radiation shielding and protection; TBS radiological waste management strategy and categorization; selection and definition of reference accidents scenarios, and accidents analyses. Finally the authors share the information on on-going and planned future EU TBS safety activities.

  8. Status of the EU test blanket systems safety studies

    Energy Technology Data Exchange (ETDEWEB)

    Panayotov, Dobromir, E-mail: dobromir.panayotov@f4e.europa.eu; Poitevin, Yves; Ricapito, Italo; Zmitko, Milan

    2015-10-15

    Highlights: • TBS safety demonstration files. • Safety functions and related design features – detailed TBS components classifications. • Nuclear analyses, radiation shielding and protection. • TBS radiological waste management strategy and categorization. • Selection and definition of reference accidents scenarios and accidents analyses. - Abstract: The European joint undertaking for ITER and the development of fusion energy (‘Fusion for Energy’ – F4E) provides the European contributions to the ITER international fusion energy research project. Among others it includes also the development, design, technological demonstration and implementation of the European test blanket systems (TBS) in ITER. Currently two EU TBS designs are in the phase of conceptual design – helium-cooled lithium-lead (HCLL) and helium-cooled pebble-bed (HCPB). Safety demonstration is an important part of the work devoted to the achievement of the next key project milestone the conceptual design review. The paper reveals the details of the work on EU TBS safety performed in the last couple of years: update of the TBS safety demonstration files; safety functions and related design features; detailed TBS components classifications; nuclear analyses, radiation shielding and protection; TBS radiological waste management strategy and categorization; selection and definition of reference accidents scenarios, and accidents analyses. Finally the authors share the information on on-going and planned future EU TBS safety activities.

  9. Preliminary safety evaluation for CSR1000 with passive safety system

    International Nuclear Information System (INIS)

    Wu, Pan; Gou, Junli; Shan, Jianqiang; Zhang, Bo; Li, Xiang

    2014-01-01

    Highlights: • The basic information of a Chinese SCWR concept CSR1000 is introduced. • An innovative passive safety system is proposed for CSR1000. • 6 Transients and 3 accidents are analysed with system code SCTRAN. • The passive safety systems greatly mitigate the consequences of these incidents. • The inherent safety of CSR1000 is enhanced. - Abstract: This paper describes the preliminary safety analysis of the Chinese Supercritical water cooled Reactor (CSR1000), which is proposed by Nuclear Power Institute of China (NPIC). The two-pass core design applied to CSR1000 decreases the fuel cladding temperature and flattens the power distribution of the core at normal operation condition. Each fuel assembly is made up of four sub-assemblies with downward-flow water rods, which is favorable to the core cooling during abnormal conditions due to the large water inventory of the water rods. Additionally, a passive safety system is proposed for CSR1000 to increase the safety reliability at abnormal conditions. In this paper, accidents of “pump seizure”, “loss of coolant flow accidents (LOFA)”, “core depressurization”, as well as some typical transients are analysed with code SCTRAN, which is a one-dimensional safety analysis code for SCWRs. The results indicate that the maximum cladding surface temperatures (MCST), which is the most important safety criterion, of the both passes in the mentioned incidents are all below the safety criterion by a large margin. The sensitivity analyses of the delay time of RCPs trip in “loss of offsite power” and the delay time of RMT actuation in “loss of coolant flowrate” were also included in this paper. The analyses have shown that the core design of CSR1000 is feasible and the proposed passive safety system is capable of mitigating the consequences of the selected abnormalities

  10. Nanotechnology in food science: Functionality, applicability, and safety assessment.

    Science.gov (United States)

    He, Xiaojia; Hwang, Huey-Min

    2016-10-01

    Rapid development of nanotechnology is expected to transform many areas of food science and food industry with increasing investment and market share. In this article, current applications of nanotechnology in food systems are briefly reviewed. Functionality and applicability of food-related nanotechnology are highlighted in order to provide a comprehensive view on the development and safety assessment of nanotechnology in the food industry. While food nanotechnology offers great potential benefits, there are emerging concerns arising from its novel physicochemical properties. Therefore, the safety concerns and regulatory policies on its manufacturing, processing, packaging, and consumption are briefly addressed. At the end of this article, the perspectives of nanotechnology in active and intelligent packaging applications are highlighted. Copyright © 2016. Published by Elsevier B.V.

  11. Experience of creating a multifunctional safety system at the coal mining enterprise

    Science.gov (United States)

    Reshetnikov, V. V.; Davkaev, K. S.; Korolkov, M. V.; Lyakhovets, M. V.

    2018-05-01

    The principles of creating multifunctional safety systems (MFSS) based on mathematical models with Markov properties are considered. The applicability of such models for the analysis of the safety of the created systems and their effectiveness is substantiated. The method of this analysis and the results of its testing are discussed. The variant of IFSB implementation in the conditions of the operating coal-mining enterprise is given. The functional scheme, data scheme and operating modes of the MFSS are given. The automated workplace of the industrial safety controller is described.

  12. A Regulatory Perspective on the Performance and Reliability of Nuclear Passive Safety Systems

    International Nuclear Information System (INIS)

    Quan, Pham Trung; Lee, Sukho

    2016-01-01

    Passive safety systems have been proven to enhance the safety of NPPs. When an accident such as station blackout occurs, these systems can perform the following functions: the decay heat removal, passive safety injection, containment cooling, and the retention of radioactive materials. Following the IAEA definitions, using passive safety systems reduces reliance on active components to achieve proper actuation and not requiring operator intervention in accident conditions. That leads to the deviations in boundary conditions of the critical process or geometric parameters, which activate and operate the system to perform accident prevention and mitigation functions. The main difficulties in evaluation of functional failure of passive systems arise because of (a) lack of plant operational experience; (b) scarcity of adequate experimental data from integral test facilities or from separate effect tests in order to understand the performance characteristics of these passive systems, not only at normal operation but also during accidents and transients; (c) lack of accepted definitions of failure modes for these systems; and (d) difficulty in modeling certain physical behavior of these systems. Reliability assessment of the PSS is still one of the important issues. Several reliability methodologies such as REPAS, RMPS and ASPRA have been applied to the reliability assessments. However, some issues are remained unresolved due to lack of understanding of the treatment of dynamic failure characteristics of components of the PSS, the treatment of dynamic variation of independence process parameters such as ambient temperature and the functional failure criteria of the PSS. Dynamic reliability methodologies should be integrated in the PSS reliability analysis to have a true estimate of system failure probability. The methodology should estimate the physical variation of the parameters and the frequency of the accident sequences when the dynamic effects are considered

  13. Railway automatic safety protection system based on GPS

    Directory of Open Access Journals (Sweden)

    Fu Hai Juan

    2016-01-01

    Full Text Available The automatic protection system of railway safety is designed for the railway construction workers to protect alarm, and the safety protection device by using GPS satellite positioning system to acquire location information of the operating point, through the CTC/TDCS system and computer monitoring system for the running of the train position and the arithmetic distance. Achieving timely and continuously forecasts about the distance of the train which is apart from the operating point to prompt the voice alarm of the approaching train. Using digital technology to realize the function of the traditional analog interphone, eliminates the quality problems of the call. With the GSM-R, mobile wireless transmission channel and terminal technology, it overcomes the restrictions of the analog interphone which influenced by communication distance and more problems of blind areas. Finally to achieve practical, convenient, applicable and adaptable design goals.

  14. Survey and evaluation of inherent safety characteristics and passive safety systems for use in probabilistic safety analyses

    International Nuclear Information System (INIS)

    Wetzel, N.; Scharfe, A.

    1998-01-01

    The present report examines the possibilities and limits of a probabilistic safety analysis to evaluate passive safety systems and inherent safety characteristics. The inherent safety characteristics are based on physical principles, that together with the safety system lead to no damage. A probabilistic evaluation of the inherent safety characteristic is not made. An inventory of passive safety systems of accomplished nuclear power plant types in the Federal Republic of Germany was drawn up. The evaluation of the passive safety system in the analysis of the accomplished nuclear power plant types was examined. The analysis showed that the passive manner of working was always assumed to be successful. A probabilistic evaluation was not performed. The unavailability of the passive safety system was determined by the failure of active components which are necessary in order to activate the passive safety system. To evaluate the passive safety features in new concepts of nuclear power plants the AP600 from Westinghouse, the SBWR from General Electric and the SWR 600 from Siemens, were selected. Under these three reactor concepts, the SWR 600 is specially attractive because the safety features need no energy sources and instrumentation in this concept. First approaches for the assessment of the reliability of passively operating systems are summarized. Generally it can be established that the core melt frequency for the passive concepts AP600 and SBWR is advantageous in comparison to the probabilistic objectives from the European Pressurized Water Reactor (EPR). Under the passive concepts is the SWR 600 particularly interesting. In this concept the passive systems need no energy sources and instrumentation, and has active operational systems and active safety equipment. Siemens argues that with this concept the frequency of a core melt will be two orders of magnitude lower than for the conventional reactors. (orig.) [de

  15. Assessing nuclear power plant safety and recovery from earthquakes using a system-of-systems approach

    International Nuclear Information System (INIS)

    Ferrario, E.; Zio, E.

    2014-01-01

    We adopt a ‘system-of-systems’ framework of analysis, previously presented by the authors, to include the interdependent infrastructures which support a critical plant in the study of its safety with respect to the occurrence of an earthquake. We extend the framework to consider the recovery of the system of systems in which the plant is embedded. As a test system, we consider the impacts produced on a nuclear power plant (the critical plant) embedded in the connected power and water distribution, and transportation networks which support its operation. The Seismic Probabilistic Risk Assessment of such system of systems is carried out by Hierarchical modeling and Monte Carlo simulation. First, we perform a top-down analysis through a hierarchical model to identify the elements that at each level have most influence in restoring safety, adopting the criticality importance measure as a quantitative indicator. Then, we evaluate by Monte Carlo simulation the probability that the nuclear power plant enters in an unsafe state and the time needed to recover its safety. The results obtained allow the identification of those elements most critical for the safety and recovery of the nuclear power plant; this is relevant for determining improvements of their structural/functional responses and supporting the decision-making process on safety critical-issues. On the test system considered, under the given assumptions, the components of the external and internal water systems (i.e., pumps and pool) turn out to be the most critical for the safety and recovery of the plant. - Highlights: • We adopt a system-of-system framework to analyze the safety of a critical plant exposed to risk from external events, considering also the interdependent infrastructures that support the plant. • We develop a hierarchical modeling framework to represent the system of systems, accounting also for its recovery. • Monte Carlo simulation is used for the quantitative evaluation of the

  16. Fundamental philosophy on the safety design of the HTTR-IS hydrogen production system

    International Nuclear Information System (INIS)

    Ohashi, Kazutaka; Nishihara, Tetsuo; Kunitomi, Kazuhiko

    2007-01-01

    Japan Atomic Energy Agency (JAEA) has been conducting an R and D work on the VHTR reactor system and IS hydrogen production system to realize hydrogen production using nuclear heat. As a part of this activity, JAEA is planning to connect an IS test system to the High Temperature Engineering Test Reactor (HTTR) to demonstrate its technical feasibility. This paper proposes a fundamental philosophy on the safety design of the HTTR-IS hydrogen production system including the methodology to select postulated abnormal events and its event sequences and to define safety functions of the IS system to ensure the reactor safety. Also the measure to clarify the IS system as non-reactor system is proposed. (author)

  17. Definition and means of maintaining the supply ventilation system seismic shutdown portion of the PFP safety envelope. Revision 2

    International Nuclear Information System (INIS)

    Keck, R.D.

    1995-01-01

    This report describes the modifications to the ventilation system for the Plutonium Finishing Plant. Topics discussed in this report include; system functional requirements, evaluations of equipment, a list of drawings showing the safety envelope boundaries; list of safety envelope equipment, functional requirements for individual safety envelope equipment, and a list of the operational, maintenance and surveillance procedures necessary to operate and maintain the system equipment

  18. Cyber Security Penetration Test for Digital Safety I and C Systems

    International Nuclear Information System (INIS)

    Lee, C. K.; Kim, D. H.; Kwon, K. C.; Joo, H. K.; Song, J. S.

    2010-01-01

    In the Korea Nuclear I and C Systems Development project the platforms for plant protection systems are developed, which function as a reactor shutdown, actuation of engineered safety features and a control of the related equipment. Those are fully digitalized through the use of safety-grade programmable logic controllers (PLCs) and few types of communication network. However the Regulatory Guide 1.152 (Rev. 02) was published by the U.S. NRC in 2006 and it recommended the application of a cyber security to the safety systems in the Nuclear Power Plant (NPP). Therefore to incorporate the new licensing requirement, a cyber security risk assessment is performed for the platforms. Then the vulnerabilities identified by the risk assessment are validated by penetration test. This paper summarizes test scenario, test results and their incorporation into system design

  19. Nuclear safety considerations with emphasis on instrumentation and control systems

    International Nuclear Information System (INIS)

    Beare, J.W.

    1978-01-01

    The conceptual model of a nuclear power plant in Canada is that it consists basically of two kinds of systems. The first kind is the process systems, that is, those structures and components associated with the production of nuclear energy and its conversion to other forms of energy. The second kind is the special safety systems, whose purpose it is to protect the public in the event of a serious failure in the process systems which might otherwise lead to unacceptable radiological consequences. Quantitative limits are set on the unavailability of the special safety systems. These limits are low enough to be consistent with low overall risk and yet can be demonstrated by test during operation of the plant. Low unavailability is an important but not the only condition required for low unrealiability for the special safety systems. The special safety systems minimize the chance of a cross-linked failure particularly under the conditions experienced as a result of the more severe types of postulated serious process failures. Nuclear power plants must also withstand, without a major hazard to the public, certain rare events associated with natural phenomena or man-made activities off-site and also certain in-plant events such as fire or break-up of a turbine-generator which might have a cross-linking effect on process and safety systems. In the latest designs, Canadian nuclear power plants have emergency systems to deal with such events. The emergency systems have an enhanced degree of physical and functional separation from other plant systems. (author)

  20. System and software safety analysis for the ERA control computer

    International Nuclear Information System (INIS)

    Beerthuizen, P.G.; Kruidhof, W.

    2001-01-01

    The European Robotic Arm (ERA) is a seven degrees of freedom relocatable anthropomorphic robotic manipulator system, to be used in manned space operation on the International Space Station, supporting the assembly and external servicing of the Russian segment. The safety design concept and implementation of the ERA is described, in particular with respect to the central computer's software design. A top-down analysis and specification process is used to down flow the safety aspects of the ERA system towards the subsystems, which are produced by a consortium of companies in many countries. The user requirements documents and the critical function list are the key documents in this process. Bottom-up analysis (FMECA) and test, on both subsystem and system level, are the basis for safety verification. A number of examples show the use of the approach and methods used

  1. Operation and safety decision-making support expert system in NPP

    International Nuclear Information System (INIS)

    Wei Yanhui; Su Desong; Chen Weihua; Zhang Jianbo

    2014-01-01

    The article first reviewed three operation support systems currently used in NPP: real-time information surveillance system, important equipment surveillance system and plant process control and monitoring system, then presents the structure and function of three expert support sub-systems (intelligent alarm monitoring system, computer-based operating procedure support system, safety information expert decision support system). Finally the article discussed the meaning of a kind of operation decision making support system. (authors)

  2. Does the concept of safety culture help or hinder systems thinking in safety?

    Science.gov (United States)

    Reiman, Teemu; Rollenhagen, Carl

    2014-07-01

    The concept of safety culture has become established in safety management applications in all major safety-critical domains. The idea that safety culture somehow represents a "systemic view" on safety is seldom explicitly spoken out, but nevertheless seem to linger behind many safety culture discourses. However, in this paper we argue that the "new" contribution to safety management from safety culture never really became integrated with classical engineering principles and concepts. This integration would have been necessary for the development of a more genuine systems-oriented view on safety; e.g. a conception of safety in which human, technological, organisational and cultural factors are understood as mutually interacting elements. Without of this integration, researchers and the users of the various tools and methods associated with safety culture have sometimes fostered a belief that "safety culture" in fact represents such a systemic view about safety. This belief is, however, not backed up by theoretical or empirical evidence. It is true that safety culture, at least in some sense, represents a holistic term-a totality of factors that include human, organisational and technological aspects. However, the departure for such safety culture models is still human and organisational factors rather than technology (or safety) itself. The aim of this paper is to critically review the various uses of the concept of safety culture as representing a systemic view on safety. The article will take a look at the concepts of culture and safety culture based on previous studies, and outlines in more detail the theoretical challenges in safety culture as a systems concept. The paper also presents recommendations on how to make safety culture more systemic. Copyright © 2013 Elsevier Ltd. All rights reserved.

  3. The aviation safety reporting system

    Science.gov (United States)

    Reynard, W. D.

    1984-01-01

    The aviation safety reporting system, an accident reporting system, is presented. The system identifies deficiencies and discrepancies and the data it provides are used for long term identification of problems. Data for planning and policy making are provided. The system offers training in safety education to pilots. Data and information are drawn from the available data bases.

  4. A SIL quantification approach based on an operating situation model for safety evaluation in complex guided transportation systems

    International Nuclear Information System (INIS)

    Beugin, J.; Renaux, D.; Cauffriez, L.

    2007-01-01

    Safety analysis in guided transportation systems is essential to avoid rare but potentially catastrophic accidents. This article presents a quantitative probabilistic model that integrates Safety Integrity Levels (SIL) for evaluating the safety of such systems. The standardized SIL indicator allows the safety requirements of each safety subsystem, function and/or piece of equipment to be specified, making SILs pivotal parameters in safety evaluation. However, different interpretations of SIL exist, and faced with the complexity of guided transportation systems, the current SIL allocation methods are inadequate for the task of safety assessment. To remedy these problems, the model developed in this paper seeks to verify, during the design phase of guided transportation system, whether or not the safety specifications established by the transport authorities allow the overall safety target to be attained (i.e., if the SIL allocated to the different safety functions are sufficient to ensure the required level of safety). To meet this objective, the model is based both on the operating situation concept and on Monte Carlo simulation. The former allows safety systems to be formalized and their dynamics to be analyzed in order to show the evolution of the system in time and space, and the latter make it possible to perform probabilistic calculations based on the scenario structure obtained

  5. Reliability analysis of repairable safety systems of a reprocessing plant allowing for tolerable system downtimes

    International Nuclear Information System (INIS)

    Schaefer, H.

    1987-01-01

    GRS has been engaged in safety analysises of the German Reprocessing Plant for several years. The development and verification of appropriate reliability analysis methods, the generation of data as well as the search for an adequate structural presentation of the results to form a basis of recommendations for technical or administrative measures or contributions to risk oriented evaluations have been or are in the process of being established. In contrast to NPP-studies, the reliability assessment of safety systems of a reprocessing plant is applied to repairable and often relatively small systems allowing for tolerable system downtimes. A sketch of the diverse cooling systems of a vessel containing a selfheating solution is given. The interruption of the cooling function for about one day might be tolerable before boiling will be reached. This interval is suitable for transfer of the solution to a spare vessel or for repairing the failed components, thus restoring the cooling function

  6. NASA Aviation Safety Reporting System (ASRS)

    Science.gov (United States)

    Connell, Linda J.

    2017-01-01

    The NASA Aviation Safety Reporting System (ASRS) collects, analyzes, and distributes de-identified safety information provided through confidentially submitted reports from frontline aviation personnel. Since its inception in 1976, the ASRS has collected over 1.4 million reports and has never breached the identity of the people sharing their information about events or safety issues. From this volume of data, the ASRS has released over 6,000 aviation safety alerts concerning potential hazards and safety concerns. The ASRS processes these reports, evaluates the information, and provides selected de-identified report information through the online ASRS Database at http:asrs.arc.nasa.gov. The NASA ASRS is also a founding member of the International Confidential Aviation Safety Systems (ICASS) group which is a collection of other national aviation reporting systems throughout the world. The ASRS model has also been replicated for application to improving safety in railroad, medical, fire fighting, and other domains. This presentation will discuss confidential, voluntary, and non-punitive reporting systems and their advantages in providing information for safety improvements.

  7. Rosatom's Crisis Response Centre within the national nuclear safety system

    International Nuclear Information System (INIS)

    Smirnov, S.N.; Komarovskij, A.V.; Moskalev, V.A.

    2011-01-01

    The Rosatom Corporation includes a number of subsidiaries associated with nuclear energy use as well as with the military, scientific, technological, nuclear and radiation safety management aspects. The Rosatom Corporation has a well-established and efficient industry-wide system of emergency prevention and response, whose purpose is to ensure safe functioning of the nuclear industry, protection of personnel, the public and nature from potential dangers; it is also a functional subsystem of the unified national system of emergency prevention and response. Overall management of the system is performed by Director General of the Rosatom Corporation, overall methodological management - by the Department of Licensing, Nuclear and Radiation Safety; everyday management of the emergency prevention and response system, round-the-clock monitoring and informational support - by the Rosatom Crisis and Response Centre (CRC). CRC acts as the national focal point for warning and communication in Russia, which provides continuous round-the-clock preparedness to cooperate with the IAEA's Incident and Emergency Centre using the formats of the ENATOM international emergency response system, similar national crisis response centres abroad [ru

  8. Jefferson Lab IEC 61508/61511 Safety PLC Based Safety System

    International Nuclear Information System (INIS)

    Mahoney, Kelly; Robertson, Henry

    2009-01-01

    This paper describes the design of the new 12 GeV Upgrade Personnel Safety System (PSS) at the Thomas Jefferson National Accelerator Facility (TJNAF). The new PSS design is based on the implementation of systems designed to meet international standards IEC61508 and IEC 61511 for programmable safety systems. In order to meet the IEC standards, TJNAF engineers evaluated several SIL 3 Safety PLCs before deciding on an optimal architecture. In addition to hardware considerations, software quality standards and practices must also be considered. Finally, we will discuss R and D that may lead to both high safety reliability and high machine availability that may be applicable to future accelerators such as the ILC.

  9. Technical self reliance of digital safety systems

    Energy Technology Data Exchange (ETDEWEB)

    Kwon, Kee Choon; Lee, Dong Young [Korea Atomic Energy Research Institute, Daejeon (Korea, Republic of); Kim, Kook Hun [Doosan Heavy Industries and Construction, Changwon (Korea, Republic of); Choi, Seung Gap [POSCON, Pohang (Korea, Republic of)

    2009-04-15

    This paper summarizes the development results of the Korea Nuclear Instrumentation and Control System (KNICS) project sponsored by the Korean government. In this project, Man Machine Interface System (MMIS) architecture, two digital platforms, and several control systems are developed. One platform is a programmable Logic Controller (PLC) for a safety system and another platform is a Distributed Control System (DCS) for a non safety system. With the POSAFE Q PLC, a Reactor Protection System (RPS) and an Engineered Safety Feature Component Control System (ESF CCS) are developed. A Power Control System (PCS) is developed based on the DCS. The safety grade platform and the digital safety systems obtained approval for the Topical Report from the Korean regulatory body in February of 2009. Also a Korean utility and a vendor company determined KNICS results to apply them to the planned Nuclear Power Plant (NPP) in March 2009. This paper introduces the technical self reliance experiences of the safety grade platform and the digital safety systems developed in the KNICS R and D project.

  10. Comparison, with regard to safety, between a hard-wired reactor protection system and a computerized protection system. Pt. 1

    International Nuclear Information System (INIS)

    Buettner, W.E.

    1976-07-01

    The study compares a conventional hard-wired dynamic reactor protection system with a computerized protection system. In the comparison, only the unequivocally safety-oriented protection actions are considered. In the first part, the different structures of both systems and the method of verification for their functional safety will be described. In the second part, the mean unavailability in case of demand for both systems under defined conditions will be determined. (orig.) [de

  11. Cold Vacuum Drying Safety Class Instrumentation and Control System Design Description SYS 93-2

    International Nuclear Information System (INIS)

    WHITEHURST, R.

    1999-01-01

    This document describes the Cold Vacuum Drying Facility (CVDF) Safety Class Instrumentation and Control system (SCIC). The SCIC provides safety functions and features to protect the environment, off-site and on-site personnel and equipment. The function of the SCIC is to provide automatic trip features, valve interlocks, alarms, indication and control for the cold vacuum drying process

  12. Ageing study of the engineered safety features actuation system of the Loviisa NPP

    International Nuclear Information System (INIS)

    Simola, K.; Maskuniitty, M.

    1995-06-01

    An ageing study of the engineered safety features actuation system of the Loviisa nuclear power plant has been performed. The operating experience, including failure and maintenance histories of analog measuring devices, logics for safety signal formation and individual control electronics of pumps and valves, has been collected and analysed. The safety importance of system components has been studied with a fault tree analysis of a selected safety function. Based on the results of the analysis of operating experiences and the fault tree analysis, some components were selected for deeper analyses. According to the operating experience, the amount of failures in the Loviisa plant safety system has been low and no increasing trend in the failure history can yet be observed. Only a few failures had prohibited the propagation of the safety signal, mostly the failures have caused a false alarm. The failures reported have concerned mainly limit signal units, transmitters, and priority units. According to the fault tree analysis of one safety function, the most important components of this subsystem are individual control units and pulse/DC converters. Failure modes and effect analyses were performed for priority and individual control unit, limit signal unit and comparator and pulse/DC converter in order to identify the critical failure modes of these devices. (orig.) (15 refs., 26 figs., 9 tabs.)

  13. Integrating system safety into the basic systems engineering process

    Science.gov (United States)

    Griswold, J. W.

    1971-01-01

    The basic elements of a systems engineering process are given along with a detailed description of what the safety system requires from the systems engineering process. Also discussed is the safety that the system provides to other subfunctions of systems engineering.

  14. A Framework for Function Allocation in Intelligent Driver Interface Design for Comfort and Safety

    Directory of Open Access Journals (Sweden)

    Wuhong Wang

    2010-11-01

    Full Text Available This paper presents a conceptual framework for ecological function allocation and optimization matching solution for a human-machine interface with intelligent characteristics by lwho does what and when and howr consideration. As a highlighted example in nature-social system, intelligent transportation system has been playing increasingly role in keeping traffic safety, our research is concerned with identifying human factors problem of In-vehicle Support Systems (ISSs and revealing the consequence of the effects of ISSs on driver cognitive interface. The primary objective is to explore some new ergonomics principals that will be able to use to design an intelligent driver interface for comfort and safety, which will address the impact of driver interfaces layouts, traffic information types, and driving behavioral factors on the advanced vehicles safety design.

  15. Programmable Electronic Safety Systems

    International Nuclear Information System (INIS)

    Parry, R.

    1993-05-01

    Traditionally safety systems intended for protecting personnel from electrical and radiation hazards at particle accelerator laboratories have made extensive use of electromechanical relays. These systems have the advantage of high reliability and allow the designer to easily implement failsafe circuits. Relay based systems are also typically simple to design, implement, and test. As systems, such as those presently under development at the Superconducting Super Collider Laboratory (SSCL), increase in size, and the number of monitored points escalates, relay based systems become cumbersome and inadequate. The move toward Programmable Electronic Safety Systems is becoming more widespread and accepted. In developing these systems there are numerous precautions the designer must be concerned with. Designing fail-safe electronic systems with predictable failure states is difficult at best. Redundancy and self-testing are prime examples of features that should be implemented to circumvent and/or detect failures. Programmable systems also require software which is yet another point of failure and a matter of great concern. Therefore the designer must be concerned with both hardware and software failures and build in the means to assure safe operation or shutdown during failures. This paper describes features that should be considered in developing safety systems and describes a system recently installed at the Accelerator Systems String Test (ASST) facility of the SSCL

  16. Context-aware system for pre-triggering irreversible vehicle safety actuators.

    Science.gov (United States)

    Böhmländer, Dennis; Dirndorfer, Tobias; Al-Bayatti, Ali H; Brandmeier, Thomas

    2017-06-01

    New vehicle safety systems have led to a steady improvement of road safety and a reduction in the risk of suffering a major injury in vehicle accidents. A huge leap forward in the development of new vehicle safety systems are actuators that have to be activated irreversibly shortly before a collision in order to mitigate accident consequences. The triggering decision has to be based on measurements of exteroceptive sensors currently used in driver assistance systems. This paper focuses on developing a novel context-aware system designed to detect potential collisions and to trigger safety actuators even before an accident occurs. In this context, the analysis examines the information that can be collected from exteroceptive sensors (pre-crash data) to predict a certain collision and its severity to decide whether a triggering is entitled or not. A five-layer context-aware architecture is presented, that is able to collect contextual information about the vehicle environment and the actual driving state using different sensors, to perform reasoning about potential collisions, and to trigger safety functions upon that information. Accident analysis is used in a data model to represent uncertain knowledge and to perform reasoning. A simulation concept based on real accident data is introduced to evaluate the presented system concept. Copyright © 2017 Elsevier Ltd. All rights reserved.

  17. Improvement of standards on functional reliability of electric power systems

    International Nuclear Information System (INIS)

    Barinov, V.A.; Volkov, G.A.; Kalita, V.V.; Kogan, F.L.; Makarov, S.F.; Manevich, A.S.; Mogirev, V.V.; Sin'chugov, F.I.; Skopintsev, V.A.; Khvoshchinskaya, Z.G.

    1993-01-01

    Analysis of the most principal aspects of the existing standards and requirements on assuring safety and stability of electric power systems (EPS) and effective (reliable and economical) power supply of consumers is given. The reliability is determined as ability to accomplish the assigned functions. Basic recommendations on improving the standards regulating the safety and reliability of the NPP functioning are formulated

  18. Research on the development of advanced system safety assessment procedures. 2

    International Nuclear Information System (INIS)

    Suzuki, Kazuhiko

    2004-02-01

    The past research reports in the area of safety engineering proposed the Computer-aided HAZOP system to be applied to Nuclear Reprocessing Facilities. Automated HAZOP system has great advantage compared with human analysts in terms of accuracy of the results, and time required to conduct HAZOP studies. However, it also became clear that the disadvantages are difficulty in analyzing the detailed information about a substance and a reaction peculiar to each plant or a process. And the outputted results may contain excess and deficiency compared with the HAZOP results performed by specialists. To improve HAZOP System, function of interventions by human is added to the system. Database-Bridge, which applies information management technology such as SQL operation, Query, is developed to perform intervention function. As the result the HAZOP system can give appropriate measures information to protect accidents to uses. Such HAZOP data is applied to safety management of Nuclear Reprocessing Facilities. (author)

  19. Generative Programming for Functional Safety in Mobile Robots

    DEFF Research Database (Denmark)

    Adam, Marian Sorin

    2018-01-01

    execution environment. The effective usage of DeRoS to specify safetyrelated properties of mobile robots and generation of a runtime verification infrastructure for the different controllers has been experimentally demonstrated on ROS-based systems, safety PLCs and microcontrollers. The key issue of making......Safety is a major challenge in robotics, in particular for mobile robots operating in an open and unpredictable environment. Safety certification is desired for commercial robots, but the existing approaches for addressing safety do not provide a clearly defined and isolated programmatic safety...... layer, with an easily understandable specification for facilitating safety certification. Moreover, mobile robots are advanced systems often implemented using a distributed architecture where software components are deployed on heterogeneous hardware modules. Many components are key to the overall...

  20. Definition and means of maintaining the process vacuum liquid detection interlock systems portion of the PFP safety envelope

    International Nuclear Information System (INIS)

    LINTHO, J.E.

    2003-01-01

    The purpose of this document is to record the technical evaluation of the Technical Safety Requirements described in the Plutonium Finishing Plant (PFP) Safety Technical Requirements, HNF-SD-CP-OSR-010/Rev.1, Section 3.1.1, ''Criticality Prevention System.'' This document also defines the Safety Envelope (SE) for the liquid detection interlock system in the Process Vacuum System. The SE is derived FR-om information in the Plutonium Finishing Plant Final Safety Analysis Report (PFP FSAR), HNF-SD-CP-SAR-021, Rev 4, and the Criticality Safety Analysis Report (CSAR) for the 26-inch Hg Vacuum System, WHC-SD-SQA-CSA-20159, Rev 0-A. This document, with its appendices, provides the following: (1) The system functional requirements for determining system operability (Section 3). (2) Evaluations of equipment to determine the safety envelope boundary for the system (Section 4 list of SE boundary drawings). (3) A list of the safety envelope equipment (Appendix B). (4) Functional requirements for the individual safety envelope equipment, including appropriate set points and process parameters (Section 4). (5) A list of the operational and surveillance procedures necessary to operate and maintain the system equipment within the safety envelope (Sections 5 and 6 and Appendix A)

  1. DOE-RL Integrated Safety Management System Description

    International Nuclear Information System (INIS)

    SHOOP, D.S.

    2000-01-01

    The purpose of this Integrated Safety Management System Description (ISMSD) is to describe the U.S. Department of Energy (DOE), Richland Operations Office (RL) ISMS as implemented through the RL Integrated Management System (RIMS). This ISMSD does not impose additional requirements but rather provides an overview describing how various parts of the ISMS fit together. Specific requirements for each of the core functions and guiding principles are established in other implementing processes, procedures, and program descriptions that comprise RIMS. RL is organized to conduct work through operating contracts; therefore, it is extremely difficult to provide an adequate ISMS description that only addresses RL functions. Of necessity, this ISMSD contains some information on contractor processes and procedures which then require RL approval or oversight. This ISMSD does not purport to contain a full description of the contractors' ISM System Descriptions

  2. DOE-RL Integrated Safety Management System Description

    CERN Document Server

    Shoop, D S

    2000-01-01

    The purpose of this Integrated Safety Management System Description (ISMSD) is to describe the U.S. Department of Energy (DOE), Richland Operations Office (RL) ISMS as implemented through the RL Integrated Management System (RIMS). This ISMSD does not impose additional requirements but rather provides an overview describing how various parts of the ISMS fit together. Specific requirements for each of the core functions and guiding principles are established in other implementing processes, procedures, and program descriptions that comprise RIMS. RL is organized to conduct work through operating contracts; therefore, it is extremely difficult to provide an adequate ISMS description that only addresses RL functions. Of necessity, this ISMSD contains some information on contractor processes and procedures which then require RL approval or oversight. This ISMSD does not purport to contain a full description of the contractors' ISM System Descriptions.

  3. Assessing Risk-Based Performance Indicators in Safety-Critical Systems for Nuclear Power Plants

    OpenAIRE

    TONT Gabriela

    2011-01-01

    The paper proposes framework for a multidisciplinary nuclear risk and safety assessment by modeling uncertainty and combining diverse evidence provided in such a way that it could be used to represent an entire argument about a system's dependability. The identified safety issues are being treated by means of probabilistic safety assessment (PSA). The behavior simulation of power plant in thepresence of risk factors is analyzed from the vulnerability, risk and functional safety viewpoints, hi...

  4. Reliability study: digital engineered safety feature actuation system of Korean Standard Nuclear Power Plant

    International Nuclear Information System (INIS)

    Sudarno; Kang, H. G.; Jang, S. C.; Eom, H. S.; Ha, J. J.

    2003-04-01

    The usage of digital Instrumentation and Control (I and C) in a nuclear power plant becomes more extensive, including safety related systems. The PSA application of these new designs are very important in order to evaluate their reliability. In particular, Korean Standard Nuclear Power Plants (KSNPPs), typically Ulchin 5 and 6 (UCN 5 and 6) reactor units, adopted the digital safety-critical systems such as Digital Plant Protection System (DPPS) and Digital Engineered Safety Feature Actuation System (DESFAS). In this research, we developed fault tree models for assessing the unavailability of the DESFAS functions. We also performed an analysis of the quantification results. The unavailability results of different DESFAS functions showed that their values are comprised from 5.461E-5 to 3.14E-4. The system unavailability of DESFAS AFAS-1 is estimated as 5.461E-5, which is about 27% less than that of analog system if we consider the difference of human failure probability estimation between both analyses. The results of this study could be utilized in risk-effect analysis of KSNPP. We expect that the safety analysis result will contribute to design feedback

  5. Nuclear power plants - Instrumentation and control systems important for safety - Classification (International Electrotechnical Commission Standard Publication 1226:1993)

    International Nuclear Information System (INIS)

    Stefanik, J.

    1996-01-01

    This international standard established a method of classification of the information and command functions for nuclear power plants, and the I and C and equipment that provide those functions, into categories that designate the importance for safety of the functions, and the associated systems and equipment. The resulting classification then determines relevant design criteria. The design criteria are the measures of quality by which the adequacy of each functions, and the associated systems and equipment in relation to its importance to plant safety is ensured. In this standard, the criteria are those of functionality, reliability, performance, environmental durability and quality assurance. This standard is applicable to all the information and command functions, and the instrumentation and control systems and equipment that provide those functions. The functions, systems and equipment under consideration provide automated protection, closed or open loop control, and information to the operating staff. They keep the NPP conditions inside the safe operating envelope and provide automatic actions, or enable manual actions, that mitigate accidents or prevent or minimize radioactive releases to the site or wider environment. The functions, and the associated systems and equipment that fulfill these roles safeguard the health and safety of the NPP operators and the public. This standard complements, and does not replace or supersede, the Safety Guides and Codes of Practice published by the International Atomic Energy Agency

  6. JACoW Safety instrumented systems and the AWAKE plasma control as a use case

    CERN Document Server

    Blanco Viñuela, Enrique; Fernández Adiego, Borja; Speroni, Roberto

    2018-01-01

    Safety is likely the most critical concern in many process industries, yet there is a general uncertainty on the proper engineering to reduce the risks and ensure the safety of persons or material at the same time as providing the process control system. Some of the reasons for this misperception are unclear requirements, lack of functional safety engineering knowledge or incorrect protection functionalities attributed to the BPCS (Basic Process Control System). Occasionally the control engineers are not aware of the hazards inherent to an industrial process and this causes an incorrect design of the overall controls. This paper illustrates the engineering of the SIS (Safety Instrumented System) and the BPCS of the plasma vapour controls of the AWAKE R&D; project, the first proton-driven plasma wakefield acceleration experiment in the world. The controls design and implementation refers to the IEC61511/ISA84 standard, including technological choices, design, operation and maintenance. Finally, the publica...

  7. Considerations on nuclear reactor passive safety systems

    International Nuclear Information System (INIS)

    2016-01-01

    After having indicated some passive safety systems present in electronuclear reactors (control bars, safety injection system accumulators, reactor cooling after stoppage, hydrogen recombination systems), this report recalls the main characteristics of passive safety systems, and discusses the main issues associated with the assessment of new passive systems (notably to face a sustained loss of electric supply systems or of cold water source) and research axis to be developed in this respect. More precisely, the report comments the classification of safety passive systems as it is proposed by the IAEA, outlines and comments specific aspects of these systems regarding their operation and performance. The next part discusses the safety approach, the control of performance of safety passive systems, issues related to their reliability, and the expected contribution of R and D (for example: understanding of physical phenomena which have an influence of these systems, capacities of simulation of these phenomena, needs of experimentations to validate simulation codes)

  8. System Coordination of Survivability and Safety of Complex Engineering Objects Operation

    Directory of Open Access Journals (Sweden)

    Nataliya Pankratova

    2014-11-01

    Full Text Available A system strategy to estimation the guaranteed survivability and safety of complex engineering objects (CEO operation is proposed. The principles that underlie the strategy of the guaranteed safety of CEO operation provide a flexible approach to timely detection, recognition, forecast, and system diagnostics of risk factors and situations, to formulation and implementation of a rational decision in a practicable time within an unremovable time constraint. Implementation of the proposed strategy is shown on example of diagnostics of electromobile-refrigerator functioning in real mode.

  9. System safety engineering analysis handbook

    Science.gov (United States)

    Ijams, T. E.

    1972-01-01

    The basic requirements and guidelines for the preparation of System Safety Engineering Analysis are presented. The philosophy of System Safety and the various analytic methods available to the engineering profession are discussed. A text-book description of each of the methods is included.

  10. Preliminary safety evaluation for the spent nuclear fuel project`s cold vacuum drying system

    Energy Technology Data Exchange (ETDEWEB)

    Garvin, L.J., Westinghouse Hanford

    1996-07-01

    This preliminary safety evaluation (PSE) considers only the Cold Vacuum Drying System (CVDS) facility and its mission as it relates to the integrated process strategy (WHC 1995). The purpose of the PSE is to identify those CBDS design functions that may require safety- class and safety-significant accident prevention and mitigation features.

  11. Safety approach to the selection of design criteria for the CRBRP reactor refueling system

    International Nuclear Information System (INIS)

    Meisl, C.J.; Berg, G.E.; Sharkey, N.F.

    1979-01-01

    The selection of safety design criteria for Liquid Metal Fast Breeder Reactor (LMFBR) refueling systems required the extrapolation of regulations and guidelines intended for Light Water Reactor refueling systems and was encumbered by the lack of benefit from a commercially licensed predecessor other than Fermi. The overall approach and underlying logic are described for developing safety design criteria for the reactor refueling system (RRS) of the Clinch River Breeder Reactor Plant (CRBRP). The complete selection process used to establish the criteria is presented, from the definition of safety functions to the finalization of safety design criteria in the appropriate documents. The process steps are illustrated by examples

  12. Safety performance monitoring of autonomous marine systems

    International Nuclear Information System (INIS)

    Thieme, Christoph A.; Utne, Ingrid B.

    2017-01-01

    The marine environment is vast, harsh, and challenging. Unanticipated faults and events might lead to loss of vessels, transported goods, collected scientific data, and business reputation. Hence, systems have to be in place that monitor the safety performance of operation and indicate if it drifts into an intolerable safety level. This article proposes a process for developing safety indicators for the operation of autonomous marine systems (AMS). The condition of safety barriers and resilience engineering form the basis for the development of safety indicators, synthesizing and further adjusting the dual assurance and the resilience based early warning indicator (REWI) approaches. The article locates the process for developing safety indicators in the system life cycle emphasizing a timely implementation of the safety indicators. The resulting safety indicators reflect safety in AMS operation and can assist in planning of operations, in daily operational decision-making, and identification of improvements. Operation of an autonomous underwater vehicle (AUV) exemplifies the process for developing safety indicators and their implementation. The case study shows that the proposed process leads to a comprehensive set of safety indicators. It is expected that application of the resulting safety indicators consequently will contribute to safer operation of current and future AMS. - Highlights: • Process for developing safety indicators for autonomous marine systems. • Safety indicators based on safety barriers and resilience thinking. • Location of the development process in the system lifecycle. • Case study on AUV demonstrating applicability of the process.

  13. 78 FR 29392 - Embedded Digital Devices in Safety-Related Systems, Systems Important to Safety, and Items Relied...

    Science.gov (United States)

    2013-05-20

    ... NUCLEAR REGULATORY COMMISSION [NRC-2013-0098] Embedded Digital Devices in Safety-Related Systems, Systems Important to Safety, and Items Relied on for Safety AGENCY: Nuclear Regulatory Commission. ACTION... (NRC) is issuing for public comment Draft Regulatory Issue Summary (RIS) 2013-XX, ``Embedded Digital...

  14. The Evolution of System Safety at NASA

    Science.gov (United States)

    Dezfuli, Homayoon; Everett, Chris; Groen, Frank

    2014-01-01

    The NASA system safety framework is in the process of change, motivated by the desire to promote an objectives-driven approach to system safety that explicitly focuses system safety efforts on system-level safety performance, and serves to unify, in a purposeful manner, safety-related activities that otherwise might be done in a way that results in gaps, redundancies, or unnecessary work. An objectives-driven approach to system safety affords more flexibility to determine, on a system-specific basis, the means by which adequate safety is achieved and verified. Such flexibility and efficiency is becoming increasingly important in the face of evolving engineering modalities and acquisition models, where, for example, NASA will increasingly rely on commercial providers for transportation services to low-earth orbit. A key element of this objectives-driven approach is the use of the risk-informed safety case (RISC): a structured argument, supported by a body of evidence, that provides a compelling, comprehensible and valid case that a system is or will be adequately safe for a given application in a given environment. The RISC addresses each of the objectives defined for the system, providing a rational basis for making informed risk acceptance decisions at relevant decision points in the system life cycle.

  15. Software Quality Assurance for Nuclear Safety Systems

    International Nuclear Information System (INIS)

    Sparkman, D R; Lagdon, R

    2004-01-01

    The US Department of Energy has undertaken an initiative to improve the quality of software used to design and operate their nuclear facilities across the United States. One aspect of this initiative is to revise or create new directives and guides associated with quality practices for the safety software in its nuclear facilities. Safety software includes the safety structures, systems, and components software and firmware, support software and design and analysis software used to ensure the safety of the facility. DOE nuclear facilities are unique when compared to commercial nuclear or other industrial activities in terms of the types and quantities of hazards that must be controlled to protect workers, public and the environment. Because of these differences, DOE must develop an approach to software quality assurance that ensures appropriate risk mitigation by developing a framework of requirements that accomplishes the following goals: (sm b ullet) Ensures the software processes developed to address nuclear safety in design, operation, construction and maintenance of its facilities are safe (sm b ullet) Considers the larger system that uses the software and its impacts (sm b ullet) Ensures that the software failures do not create unsafe conditions Software designers for nuclear systems and processes must reduce risks in software applications by incorporating processes that recognize, detect, and mitigate software failure in safety related systems. It must also ensure that fail safe modes and component testing are incorporated into software design. For nuclear facilities, the consideration of risk is not necessarily sufficient to ensure safety. Systematic evaluation, independent verification and system safety analysis must be considered for software design, implementation, and operation. The software industry primarily uses risk analysis to determine the appropriate level of rigor applied to software practices. This risk-based approach distinguishes safety

  16. Application of Safety Instrumented System (SIS) approach in older nuclear power plants

    Energy Technology Data Exchange (ETDEWEB)

    Nasimi, Elnara; Gabbar, Hossam A., E-mail: hossam.gabbar@uoit.ca

    2016-05-15

    Highlights: • Study Safety Instrumented System (SIS) design for older nuclear power plant. • Apply SIS on Reheater Drains (RD) system. • Apply IEC 61508/61511 to design safety system. • Evaluate risk reduction based on proposed SIS design. - Abstract: In order to remain economically effective and financially profitable, the modern industries have to take their safety culture to a higher level and consider production losses in addition to simple accident prevention techniques. Ideally, compliance with safety requirements start during early design stages, but in some older facilities provisions for Safety Instrumented Systems (SIS) may not have been originally included. In this paper, a case study of a Reheater Drains (RD) system is used to illustrate such an example. Frequent failures of tank level controller lead to transients where the operation of shutting down RD pumps requires operators to manually isolate the quenching water and to close the main steam admission valves. Water in this system is at saturation temperature for the reheater steam side pressure, and any manual operation of the system is highly undesirable due to hazards of working with wet steam at approximately 758 kPa(g) pressure, preheated to 237 °C. Additionally, losses of inventory are highly undesirable as well and challenge other systems in the plant. In this paper, it is suggested that RD system can benefit from installation of an independent SIS system in order to address current challenges. This idea is being explored using IEC 61508 framework for “Functional safety of electrical/electronic/programmable electronic safety-related systems” to provide assurance that the SIS will offer the necessary risk reduction required to achieve required safety for the equipment.

  17. 77 FR 70409 - System Safety Program

    Science.gov (United States)

    2012-11-26

    ...-0060, Notice No. 2] 2130-AC31 System Safety Program AGENCY: Federal Railroad Administration (FRA... rulemaking (NPRM) published on September 7, 2012, FRA proposed regulations to require commuter and intercity passenger railroads to develop and implement a system safety program (SSP) to improve the safety of their...

  18. Preliminary Performance Analysis Program Development for Safety System with Safeguard Vessel

    International Nuclear Information System (INIS)

    Kang, Han-Ok; Lee, Jun; Park, Cheon-Tae; Yoon, Ju-Hyeon; Park, Keun-Bae

    2007-01-01

    SMART is an advanced modular integral type pressurized water reactor for a seawater desalination and an electricity production. Major components of the reactor coolant system such as the pressurizer, Reactor Coolant Pump (RCP), and steam generators are located inside the reactor vessel. The SMART can fundamentally eliminate the possibility of large break loss of coolant accidents (LBLOCAs), improve the natural circulation capability, and better accommodate and thus enhance a resistance to a wide range of transients and accidents. The safety goals of the SMART are enhanced through highly reliable safety systems such as the passive residual heat removal system (PRHRS) and the safeguard vessel coupled with the passive safety injection feature. The safeguard vessel is a steel-made, leak-tight pressure vessel housing the RPV, SIT, and the associated valves and pipelines. A primary function of the safeguard vessel is to confine any radioactive release from the primary circuit within the vessel under DBAs related to loss of the integrity of the primary system. A preliminary performance analysis program for a safety system using the safeguard vessel is developed in this study. The developed program is composed of several subroutines for the reactor coolant system, passive safety injection system, safeguard vessel including the pressure suppression pool, and PRHRS. A small break loss of coolant accident at the upper part of a reactor is analyzed and the results are discussed

  19. Programmable electronic safety systems

    International Nuclear Information System (INIS)

    Parry, R.R.

    1993-01-01

    Traditionally safety systems intended for protecting personnel from electrical and radiation hazards at particle accelerator laboratories have made extensive use of electromechanical relays. These systems have the advantage of high reliability and allow the designer to easily implement fail-safe circuits. Relay based systems are also typically simple to design, implement, and test. As systems, such as those presently under development at the Superconducting Super Collider Laboratory (SSCL), increase in size, and the number of monitored points escalates, relay based systems become cumbersome and inadequate. The move toward Programmable Electronic Safety Systems is becoming more widespread and accepted. In developing these systems there are numerous precautions the designer must be concerned with. Designing fail-safe electronic systems with predictable failure states is difficult at best. Redundancy and self-testing are prime examples of features that should be implemented to circumvent and/or detect failures. Programmable systems also require software which is yet another point of failure and a matter of great concern. Therefore the designer must be concerned with both hardware and software failures and build in the means to assure safe operation or shutdown during failures. This paper describes features that should be considered in developing safety systems and describes a system recently installed at the Accelerator Systems String Test (ASST) facility of the SSCL

  20. Nuclear Power Safety Reporting System. Final evaluation results

    International Nuclear Information System (INIS)

    Finlayson, F.C.; Newton, R.D.

    1986-02-01

    This document presents the results of a study conducted by the US Nuclear Regulatory Commission of an unobtrusive, voluntary, anonymous third-party managed, nonpunitive human factors data gathering system (the Nuclear power Safety Reporting System - NPSRS) for the nuclear electric power production industry. The data to be gathered by the NPSRS are intended for use in identifying and quantifying the factors that contribute to the occurrence of significant safety incidents involving humans in nuclear power plants. The NPSRS has been designed to encourage participation in the System through guarantees of reporter anonymity provided by a third-party organization that would be responsible for NPSRS management. As additional motivation to reporters for contributing data to the NPSRS, conditional waivers of NRC disciplinary action would be provided to individuals. These conditional waivers of immunity would apply to potential violations of NRC regulations that might be disclosed through reports submitted to the System about inadvertent, noncriminal incidents in nuclear plants. This document summarizes the overall results of the study of the NPSRS concept. In it, a functional description of the NPSRS is presented together with a review and assessment of potential problem areas that might be met if the System were implemented. Conclusions and recommendations resulting from the study are also presented. A companion volume (NUREG/CR-4133, Nuclear Power Safety Reporting System: Implementation and Operational Specifications'') presented in detail the elements, requirements, forms, and procedures for implementing and operating the System. 13 refs

  1. System safety education focused on industrial engineering

    Science.gov (United States)

    Johnston, W. L.; Morris, R. S.

    1971-01-01

    An educational program, designed to train students with the specific skills needed to become safety specialists, is described. The discussion concentrates on application, selection, and utilization of various system safety analytical approaches. Emphasis is also placed on the management of a system safety program, its relationship with other disciplines, and new developments and applications of system safety techniques.

  2. RESI-1 and RESI-2: pPrototypes of an information system on reactor safety

    International Nuclear Information System (INIS)

    Schultheiss, G.F.; Eglin, W.; Katz, F.W.; Krings, T.; Pee, A.; Schlechtendahl, E.G.

    1975-04-01

    To demonstrate by practical experience the feasibility of the information system elaborated in the 'Study of an Information System on Reactor Safety RESI' (KFK 1900), the prototype systems RESI-1 and RESI-2 were developed and tested in operation. The two systems have been considerably reduced both in extent and contents as compared to the information system described in the study. The RESI-1 prototype system is a paper version established for verification of all the individual functions before passing over to the computer-aided interactive version RESI-2. RESI-2 is based on the GOLEM system of Siemens. Both protoype systems have proved that the essential features: 1) documentation, 2) formulation of and answering to safety questions, which are relevant with respect to particular licensing cases, 3) formulation of safety questions related to individual reactor types can be managed satisfactorily. All the functions of information retrieval have been tested carefully over several months. Particularities of project development and of the methods elaborated are described in detail and presented in this report. (orig.) [de

  3. Information systems in food safety management.

    Science.gov (United States)

    McMeekin, T A; Baranyi, J; Bowman, J; Dalgaard, P; Kirk, M; Ross, T; Schmid, S; Zwietering, M H

    2006-12-01

    Information systems are concerned with data capture, storage, analysis and retrieval. In the context of food safety management they are vital to assist decision making in a short time frame, potentially allowing decisions to be made and practices to be actioned in real time. Databases with information on microorganisms pertinent to the identification of foodborne pathogens, response of microbial populations to the environment and characteristics of foods and processing conditions are the cornerstone of food safety management systems. Such databases find application in: Identifying pathogens in food at the genus or species level using applied systematics in automated ways. Identifying pathogens below the species level by molecular subtyping, an approach successfully applied in epidemiological investigations of foodborne disease and the basis for national surveillance programs. Predictive modelling software, such as the Pathogen Modeling Program and Growth Predictor (that took over the main functions of Food Micromodel) the raw data of which were combined as the genesis of an international web based searchable database (ComBase). Expert systems combining databases on microbial characteristics, food composition and processing information with the resulting "pattern match" indicating problems that may arise from changes in product formulation or processing conditions. Computer software packages to aid the practical application of HACCP and risk assessment and decision trees to bring logical sequences to establishing and modifying food safety management practices. In addition there are many other uses of information systems that benefit food safety more globally, including: Rapid dissemination of information on foodborne disease outbreaks via websites or list servers carrying commentary from many sources, including the press and interest groups, on the reasons for and consequences of foodborne disease incidents. Active surveillance networks allowing rapid dissemination

  4. Safety philosophy and design principles for systems and components of nuclear power plant: external event

    International Nuclear Information System (INIS)

    Lopes, J.P.G.

    1986-01-01

    In nuclear power plants, some systems and components are designed to withstand external impacts. Such systems and components are those which have to perform their functions even during and after the occurrences of an earthquake, for example, fulfilling the safety objectives and avoiding the release of radioactive material to the environment. The aim of this report is to introduce the safety philosophy and design principles for systems/components to perform their functions during and after the occurrence of an earthquake, as applied by NUCLEN for Angra 2 and 3. (Author) [pt

  5. An approach for assessing ALWR passive safety system reliability

    International Nuclear Information System (INIS)

    Hake, T.M.

    1991-01-01

    Many of the advanced light water reactor (ALWR) concepts proposed for the next generation of nuclear power plants rely on passive rather than active systems to perform safety functions. Despite the reduced redundancy of the passive systems as compared to active systems in current plants, the assertion is that the overall safety of the plant is enhanced due to the much higher expected reliability of the passive systems. In order to investigate this assertion, a study is being conducted at Sandia National Laboratories to evaluate the reliability of ALWR passive safety features in the context of probabilistic risk assessment (PRA). The purpose of this paper is to provide a brief overview of the approach to this study. The quantification of passive system reliability is not as straightforward as for active systems, due to the lack of operating experience, and to the greater uncertainty in the governing physical phenomena. Thus, the adequacy of current methods for evaluating system reliability must be assessed, and alternatives proposed if necessary. For this study, the Westinghouse Advanced Passive 600 MWe reactor (AP600) was chosen as the advanced reactor for analysis, because of the availability of AP600 design information. This study compares the reliability of AP600 emergency cooling system with that of corresponding systems in a current generation reactor

  6. Radiation safety systems at the NSLS

    International Nuclear Information System (INIS)

    Dickinson, T.

    1987-04-01

    This report describes design principles that were used to establish the radiation safety systems at the National Synchrotron Light Source. The author described existing safety systems and the history of partial system failures. 1 fig

  7. The study of system function analysis method for success path alarm design

    International Nuclear Information System (INIS)

    Kang, S. K.; Shin, Y. C.

    1999-01-01

    The key benefit to the common use of the critical function approach for safety and mission functions is that monitoring methods expected to be used by operaotrs during emergency condition are used continuously during normal operation. For each critical safety function there exists two or more success paths. Information Processing System monitors the availability, operation state and performance of the critical function success paths. In this paper, We have studied System Function Analysis(SFA) for the design of Success Path Alarm(SPA) for applying in KNGR. In here, we thought that SFA will help the design of SPA. The SFA can be applicable to the design of SPA according to NUREG-0711, also can induce the algorithm for alarm of system, train and flow path. We present a method of system function analysis for designing Success Path Alarm

  8. Radiation safety system (RSS) backbones: Design, engineering, fabrication and installation

    International Nuclear Information System (INIS)

    Wilmarth, J.E.; Sturrock, J.C.; Gallegos, F.R.

    1998-01-01

    The Radiation Safety System (RSS) Backbones are part of an electrical/electronic/mechanical system insuring safe access and exclusion of personnel to areas at the Los Alamos Neutron Science Center (LANSCE) accelerator. The RSS Backbones control the safety fusible beam plugs which terminate transmission of accelerated ion beams in response to predefined conditions. Any beam or access fault of the backbone inputs will cause insertion of the beam plugs in the low energy beam transport. The Backbones serve the function of tying the beam plugs to the access control systems, beam spill monitoring systems and current-level limiting systems. In some ways the Backbones may be thought of as a spinal column with beam plugs at the head and nerve centers along the spinal column. The two Linac Backbone segments and experimental area segments form a continuous cable plant over 3,500 feet from beam plugs to the tip on the longest tail. The Backbones were installed in compliance with current safety standards, such as installation of the two segments in separate conduits or tray. Monitoring for ground-faults and input wiring verification was an added enhancement to the system. The system has the capability to be tested remotely

  9. Process Control Systems in the Chemical Industry: Safety vs. Security

    Energy Technology Data Exchange (ETDEWEB)

    Jeffrey Hahn; Thomas Anderson

    2005-04-01

    Traditionally, the primary focus of the chemical industry has been safety and productivity. However, recent threats to our nation’s critical infrastructure have prompted a tightening of security measures across many different industry sectors. Reducing vulnerabilities of control systems against physical and cyber attack is necessary to ensure the safety, security and effective functioning of these systems. The U.S. Department of Homeland Security has developed a strategy to secure these vulnerabilities. Crucial to this strategy is the Control Systems Security and Test Center (CSSTC) established to test and analyze control systems equipment. In addition, the CSSTC promotes a proactive, collaborative approach to increase industry's awareness of standards, products and processes that can enhance the security of control systems. This paper outlines measures that can be taken to enhance the cybersecurity of process control systems in the chemical sector.

  10. Role of systems safety in maintaining affordable safety in the 1980's

    International Nuclear Information System (INIS)

    Hollister, H.; Trauth, C.A. Jr.

    1979-01-01

    Historically, the Department of Energy and its predecessors have used and supported the development of systems safety programs, practices, and principles, finding them by and large adequate, effective, and managerially efficient. Today, attempts are bing made to resolve increasingly complex environmental, safety, and health problems by turning to increasingly complex and detailed regulation as the primary governmental answer. It is increasingly doubtful that such an approach will provide management of these issues and problems that is either effective or efficient. Challenge is issued to those in systems safety to develop and apply systems safety principles and practices more broadly to total operational systems and not just to hardware and to environmental and health protection and not just to safety, so that the total universe of environmental, safety, and health can be managed effectively and efficiently with encouragement of innovation and creativity, using a relatively brief and concise, but adequate, regulatory base

  11. Nitric Acid Revamp and Upgrading of the Alarm & Protection Safety System at Petrokemija, Croatia

    Directory of Open Access Journals (Sweden)

    Hoško, I.

    2012-04-01

    Full Text Available Every industrial production, particularly chemical processing, demands special attention in conducting the technological process with regard to the security requirements. For this reason, production processes should be continuously monitored by means of control and alarm safety instrumented systems. In the production of nitric acid at Petrokemija d. d., the original alarm safety system was designed as a combination of an electrical relay safety system and transistorized alarm module system. In order to increase safety requirements and modernize the technological process of nitric acid production, revamping and upgrading of the existing alarm safety system was initiated with a new microprocessor system. The newly derived alarm safety system, Simatic PCS 7, links the function of "classically" distributed control (DCS and logical systems in a common hardware and software platform with integrated engineering tools and operator interface to meet the minimum safety standards with safety integrity level 2 (SIL2 up to level 3 (SIL3, according to IEC 61508 and IEC 61511. This professional paper demonstrates the methodology of upgrading the logic of the alarm safety system in the production of nitric acid in the form of a logical diagram, which was the basis for a further step in its design and construction. Based on the mentioned logical diagram and defined security requirements, the project was implemented in three phases: analysis and testing, installation of the safety equipment and system, and commissioning. Developed also was a verification system of all safety conditions, which could be applied to other facilities for production of nitric acid. With the revamped and upgraded interlock alarm safety system, a new and improved safety boundary in the production of nitric acid was set, which created the foundation for further improvement of the production process in terms of improved analysis.

  12. Licensing process for safety-critical software-based systems

    Energy Technology Data Exchange (ETDEWEB)

    Haapanen, P. [VTT Automation, Espoo (Finland); Korhonen, J. [VTT Electronics, Espoo (Finland); Pulkkinen, U. [VTT Automation, Espoo (Finland)

    2000-12-01

    System vendors nowadays propose software-based technology even for the most critical safety functions in nuclear power plants. Due to the nature of software faults and the way they cause system failures new methods are needed for the safety and reliability evaluation of these systems. In the research project 'Programmable automation systems in nuclear power plants (OHA)', financed together by the Radiation and Nuclear Safety Authority (STUK), the Ministry of Trade and Industry (KTM) and the Technical Research Centre of Finland (VTT), various safety assessment methods and tools for software based systems are developed and evaluated. As a part of the OHA-work a reference model for the licensing process for software-based safety automation systems is defined. The licensing process is defined as the set of interrelated activities whose purpose is to produce and assess evidence concerning the safety and reliability of the system/application to be licensed and to make the decision about the granting the construction and operation permissions based on this evidence. The parties of the licensing process are the authority, the licensee (the utility company), system vendors and their subcontractors and possible external independent assessors. The responsibility about the production of the evidence in first place lies at the licensee who in most cases rests heavily on the vendor expertise. The evaluation and gauging of the evidence is carried out by the authority (possibly using external experts), who also can acquire additional evidence by using their own (independent) methods and tools. Central issue in the licensing process is to combine the quality evidence about the system development process with the information acquired through tests, analyses and operational experience. The purpose of the licensing process described in this report is to act as a reference model both for the authority and the licensee when planning the licensing of individual applications

  13. Licensing process for safety-critical software-based systems

    International Nuclear Information System (INIS)

    Haapanen, P.; Korhonen, J.; Pulkkinen, U.

    2000-12-01

    System vendors nowadays propose software-based technology even for the most critical safety functions in nuclear power plants. Due to the nature of software faults and the way they cause system failures new methods are needed for the safety and reliability evaluation of these systems. In the research project 'Programmable automation systems in nuclear power plants (OHA)', financed together by the Radiation and Nuclear Safety Authority (STUK), the Ministry of Trade and Industry (KTM) and the Technical Research Centre of Finland (VTT), various safety assessment methods and tools for software based systems are developed and evaluated. As a part of the OHA-work a reference model for the licensing process for software-based safety automation systems is defined. The licensing process is defined as the set of interrelated activities whose purpose is to produce and assess evidence concerning the safety and reliability of the system/application to be licensed and to make the decision about the granting the construction and operation permissions based on this evidence. The parties of the licensing process are the authority, the licensee (the utility company), system vendors and their subcontractors and possible external independent assessors. The responsibility about the production of the evidence in first place lies at the licensee who in most cases rests heavily on the vendor expertise. The evaluation and gauging of the evidence is carried out by the authority (possibly using external experts), who also can acquire additional evidence by using their own (independent) methods and tools. Central issue in the licensing process is to combine the quality evidence about the system development process with the information acquired through tests, analyses and operational experience. The purpose of the licensing process described in this report is to act as a reference model both for the authority and the licensee when planning the licensing of individual applications. Many of the

  14. Using fuzzy self-organising maps for safety critical systems

    International Nuclear Information System (INIS)

    Kurd, Zeshan; Kelly, Tim P.

    2007-01-01

    This paper defines a type of constrained artificial neural network (ANN) that enables analytical certification arguments whilst retaining valuable performance characteristics. Previous work has defined a safety lifecycle for ANNs without detailing a specific neural model. Building on this previous work, the underpinning of the devised model is based upon an existing neuro-fuzzy system called the fuzzy self-organising map (FSOM). The FSOM is type of 'hybrid' ANN which allows behaviour to be described qualitatively and quantitatively using meaningful expressions. Safety of the FSOM is argued through adherence to safety requirements-derived from hazard analysis and expressed using safety constraints. The approach enables the construction of compelling (product-based) arguments for mitigation of potential failure modes associated with the FSOM. The constrained FSOM has been termed a 'safety critical artificial neural network' (SCANN). The SCANN can be used for non-linear function approximation and allows certified learning and generalisation for high criticality roles. A discussion of benefits for real-world applications is also presented

  15. Systems Safety and Engineering Division

    Data.gov (United States)

    Federal Laboratory Consortium — Volpe's Systems Safety and Engineering Division conducts engineering, research, and analysis to improve transportation safety, capacity, and resiliency. We provide...

  16. Design for safety: theoretical framework of the safety aspect of BIM system to determine the safety index

    Directory of Open Access Journals (Sweden)

    Ai Lin Evelyn Teo

    2016-12-01

    Full Text Available Despite the safety improvement drive that has been implemented in the construction industry in Singapore for many years, the industry continues to report the highest number of workplace fatalities, compared to other industries. The purpose of this paper is to discuss the theoretical framework of the safety aspect of a proposed BIM System to determine a Safety Index. An online questionnaire survey was conducted to ascertain the current workplace safety and health situation in the construction industry and explore how BIM can be used to improve safety performance in the industry. A safety hazard library was developed based on the main contributors to fatal accidents in the construction industry, determined from the formal records and existing literature, and a series of discussions with representatives from the Workplace Safety and Health Institute (WSH Institute in Singapore. The results from the survey suggested that the majority of the firms have implemented the necessary policies, programmes and procedures on Workplace Safety and Health (WSH practices. However, BIM is still not widely applied or explored beyond the mandatory requirement that building plans should be submitted to the authorities for approval in BIM format. This paper presents a discussion of the safety aspect of the Intelligent Productivity and Safety System (IPASS developed in the study. IPASS is an intelligent system incorporating the buildable design concept, theory on the detection, prevention and control of hazards, and the Construction Safety Audit Scoring System (ConSASS. The system is based on the premise that safety should be considered at the design stage, and BIM can be an effective tool to facilitate the efforts to enhance safety performance. IPASS allows users to analyse and monitor key aspects of the safety performance of the project before the project starts and as the project progresses.

  17. Improved safety of the system 80+TM standard plants design through increased diversity and redundancy of safety systems

    International Nuclear Information System (INIS)

    Matzie, Regis A.; Carpentino, Frederick L.; Robertson, James E.

    1996-01-01

    Safely systems in the System 80+ TM Standard Plant are designed with more redundancy, diversity and simplicity than earlier nuclear power plant designs. These gains were accomplished by an evolutionary process that preserved the desirable and proven features in currently operating nuclear plants, while improving reliability and defense-in-depth. The System 80+ safety systems are the primary contributors to a core damage frequency that is more than 100 times lower than 1980's vintage U. S. designs, including the predecessor System 80 R standard nuclear steam supply system (NSSS) design. The System 80+ design includes significant improvements to the safety injection system, emergency feedwater system, shutdown cooling system, containment spray system, reactor coolant gas vent system, and to their vital support systems. These improvements enhance performance for traditional design basis events and significantly reduce the probability of a severe accident. The System 80+ design also incorporates safety systems to mitigate a severe accident. The added systems include the rapid depressurization system, the in-containment refueling water storage tank, the cavity flooding system. These systems fully address the U. S. Nuclear Regulatory Commission's (US NRC) severe accident policy. The System 80+ safety systems are integrated with the System 80+ Nuclear Island (NI) design. The NI general arrangement provides quadrant separation of the safety systems for protection from fire and flooding, and large equipment pull spaces and lay down areas for maintenance. This paper will describe the System 80+ safety systems advanced design features, the improved accident prevention and mitigation capabilities, and startup, operating and maintenance benefits

  18. Optimal replacement policy for safety-related multi-component multi-state systems

    International Nuclear Information System (INIS)

    Xu Ming; Chen Tao; Yang Xianhui

    2012-01-01

    This paper investigates replacement scheduling for non-repairable safety-related systems (SRS) with multiple components and states. The aim is to determine the cost-minimizing time for replacing SRS while meeting the required safety. Traditionally, such scheduling decisions are made without considering the interaction between the SRS and the production system under protection, the interaction being essential to formulate the expected cost to be minimized. In this paper, the SRS is represented by a non-homogeneous continuous time Markov model, and its state distribution is evaluated with the aid of the universal generating function. Moreover, a structure function of SRS with recursive property is developed to evaluate the state distribution efficiently. These methods form the basis to derive an explicit expression of the expected system cost per unit time, and to determine the optimal time to replace the SRS. The proposed methodology is demonstrated through an illustrative example.

  19. Product Engineering Class in the Software Safety Risk Taxonomy for Building Safety-Critical Systems

    Science.gov (United States)

    Hill, Janice; Victor, Daniel

    2008-01-01

    When software safety requirements are imposed on legacy safety-critical systems, retrospective safety cases need to be formulated as part of recertifying the systems for further use and risks must be documented and managed to give confidence for reusing the systems. The SEJ Software Development Risk Taxonomy [4] focuses on general software development issues. It does not, however, cover all the safety risks. The Software Safety Risk Taxonomy [8] was developed which provides a construct for eliciting and categorizing software safety risks in a straightforward manner. In this paper, we present extended work on the taxonomy for safety that incorporates the additional issues inherent in the development and maintenance of safety-critical systems with software. An instrument called a Software Safety Risk Taxonomy Based Questionnaire (TBQ) is generated containing questions addressing each safety attribute in the Software Safety Risk Taxonomy. Software safety risks are surfaced using the new TBQ and then analyzed. In this paper we give the definitions for the specialized Product Engineering Class within the Software Safety Risk Taxonomy. At the end of the paper, we present the tool known as the 'Legacy Systems Risk Database Tool' that is used to collect and analyze the data required to show traceability to a particular safety standard

  20. Safety analysis for the use of new digital safety I and C systems

    International Nuclear Information System (INIS)

    Buehler, Cornelia

    2012-01-01

    Age-induced replacement or modernization of safety I and C systems by digital equipment technology has been one of the topical subjects in nuclear technology for more than a decade. Digital equipment technology in this case means microcontroller- or microprocessor-based systems which implement I and C functions in software (SW) and, on the other hand, systems with programmed hardware (HW) components, such as Application-specific Integrated Circuits (ASIC), Field Programmable Gate Arrays (FPGA) or Programmable Logic Devices (PLS), which can be developed only by means of sophisticated SW development environments. The switch to digital equipment technology is more than a mere change in equipment technology even though the I and C functions remain almost identical in most cases. The switch not only leads to a different approach in equipment qualification, but also requires new focal points in plant design when it comes to assessing plant design, and needs new or adapted methods of analysis and evaluation. The main reason lies in the greater possibilities of systematic errors caused mainly by software-based development, manufacture and maintenance. New and adapted methods of analysis and evaluation for I and C systems are presented and explained. It is safe to say that safety I and C technology in the highest category of requirements necessitates a very far reaching realignment in design and evaluation as well as the use of new analytical techniques. This meets the claim of an I and C technology fit for use, reliable and comparable to the technology it replaces. (orig.)

  1. Software system safety

    Science.gov (United States)

    Uber, James G.

    1988-01-01

    Software itself is not hazardous, but since software and hardware share common interfaces there is an opportunity for software to create hazards. Further, these software systems are complex, and proven methods for the design, analysis, and measurement of software safety are not yet available. Some past software failures, future NASA software trends, software engineering methods, and tools and techniques for various software safety analyses are reviewed. Recommendations to NASA are made based on this review.

  2. Concept of safety subsystem for RF system for the VINCY Cyclotron; Koncept sigurnosnog podsistema radiofrekventnog sistema ciklotrona VINCY

    Energy Technology Data Exchange (ETDEWEB)

    Spasojevic, S; Djuric, D [Institute of Nuclear Sciences VINCA, Belgrade (Yugoslavia)

    1996-07-01

    The concept of the safety subsystem of the RF system of cyclotron VINCY is described. By applying the principle of separation of the control and safety functions and the fail-safe concept, an autonomous and reliable safety subsystem has been designed. A combination of the traditional relay technology, often applied in safety systems, and a modern, industrial PC based, acquisition system resulted into a solution meeting all design requirements. (author)

  3. Reactor Safety Assessment System

    International Nuclear Information System (INIS)

    Sebo, D.E.; Bray, M.A.; King, M.A.

    1987-01-01

    The Reactor Safety Assessment System (RSAS) is an expert system under development for the United States Nuclear Regulatory Commission (USNRC). RSAS is designed for use at the USNRC Operations Center in the event of a serious incident at a licensed nuclear power plant. RSAS is a situation assessment expert system which uses plant parametric data to generate conclusions for use by the NRC Reactor Safety Team. RSAS uses multiple rule bases and plant specific setpoint files to be applicable to all licensed nuclear power plants in the United States. RSAS currently covers several generic reactor categories and multiple plants within each category

  4. Reactor safety assessment system

    International Nuclear Information System (INIS)

    Sebo, D.E.; Bray, M.A.; King, M.A.

    1987-01-01

    The Reactor Safety Assessment System (RSAS) is an expert system under development for the United States Nuclear Regulatory Commission (USNRC). RSA is designed for use at the USNRC Operations Center in the event of a serious incident at a licensed nuclear power plant. RSAS is a situation assessment expert system which uses plant parametric data to generate conclusions for use by the NRC Reactor Safety Team. RSAS uses multiple rule bases and plant specific setpoint files to be applicable to all licensed nuclear power plants in the United States. RSAS currently covers several generic reactor categories and multiple plants within each category

  5. Safety systems and safety analysis of the Qinshan phase III CANDU nuclear power plant

    International Nuclear Information System (INIS)

    Cai Jianping; Shen Sen; Barkman, N.

    1999-01-01

    The author introduces the Canadian nuclear reactor safety philosophy and the Qinshan Phase III CANDU NPP safety systems and safety analysis, which are designed and performed according to this philosophy. The concept of 'defence-in-depth' is a key element of the Canadian nuclear reactor safety philosophy. The design concepts of redundancy, diversity, separation, equipment qualification, quality assurance, and use of appropriate design codes and standards are adopted in the design. Four special safety systems as well as a set of reliable safety support systems are incorporated in the design of Qinshan phase III CANDU for accident mitigation. The assessment results for safety systems performance show that the fundamental safety criteria for public dose, and integrity of fuel, channels and the reactor building, are satisfied

  6. Quality and safety implications of emergency department information systems.

    Science.gov (United States)

    Farley, Heather L; Baumlin, Kevin M; Hamedani, Azita G; Cheung, Dickson S; Edwards, Michael R; Fuller, Drew C; Genes, Nicholas; Griffey, Richard T; Kelly, John J; McClay, James C; Nielson, Jeff; Phelan, Michael P; Shapiro, Jason S; Stone-Griffith, Suzanne; Pines, Jesse M

    2013-10-01

    The Health Information Technology for Economic and Clinical Health Act of 2009 and the Centers for Medicare & Medicaid Services "meaningful use" incentive programs, in tandem with the boundless additional requirements for detailed reporting of quality metrics, have galvanized hospital efforts to implement hospital-based electronic health records. As such, emergency department information systems (EDISs) are an important and unique component of most hospitals' electronic health records. System functionality varies greatly and affects physician decisionmaking, clinician workflow, communication, and, ultimately, the overall quality of care and patient safety. This article is a joint effort by members of the Quality Improvement and Patient Safety Section and the Informatics Section of the American College of Emergency Physicians. The aim of this effort is to examine the benefits and potential threats to quality and patient safety that could result from the choice of a particular EDIS, its implementation and optimization, and the hospital's or physician group's approach to continuous improvement of the EDIS. Specifically, we explored the following areas of potential EDIS safety concerns: communication failure, wrong order-wrong patient errors, poor data display, and alert fatigue. Case studies are presented that illustrate the potential harm that could befall patients from an inferior EDIS product or suboptimal execution of such a product in the clinical environment. The authors have developed 7 recommendations to improve patient safety with respect to the deployment of EDISs. These include ensuring that emergency providers actively participate in selection of the EDIS product, in the design of processes related to EDIS implementation and optimization, and in the monitoring of the system's ongoing success or failure. Our recommendations apply to emergency departments using any type of EDIS: custom-developed systems, best-of-breed vendor systems, or enterprise systems

  7. Issues regarding Risk Effect Analysis of Digitalized Safety Systems and Main Risk Contributors

    International Nuclear Information System (INIS)

    Kang, Hyun Gook; Jang, Seung-Cheol

    2008-01-01

    Risk factors of safety-critical digital systems affect overall plant risk. In order to assess this risk effect, a risk model of a digitalized safety system is required. This article aims to provide an overview of the issues when developing a risk model and demonstrate their effect on plant risk quantitatively. Research activities in Korea for addressing these various issues, such as the software failure probability and the fault coverage of self monitoring mechanism are also described. The main risk contributors related to the digitalized safety system were determined in a quantitative manner. Reactor protection system and engineered safety feature component control system designed as part of the Korean Nuclear I and C System project are used as example systems. Fault-tree models were developed to assess the failure probability of a system function which is designed to generate an automated signal for actuating both of the reactor trip and the complicated accident-mitigation actions. The developed fault trees were combined with a plant risk model to evaluate the effect of a digitalized system's failure on the plant risk. (authors)

  8. Toward the modelling of safety violations in healthcare systems.

    Science.gov (United States)

    Catchpole, Ken

    2013-09-01

    When frontline staff do not adhere to policies, protocols, or checklists, managers often regard these violations as indicating poor practice or even negligence. More often than not, however, these policy and protocol violations reflect the efforts of well intentioned professionals to carry out their work efficiently in the face of systems poorly designed to meet the diverse demands of patient care. Thus, non-compliance with institutional policies and protocols often signals a systems problem, rather than a people problem, and can be influenced among other things by training, competing goals, context, process, location, case complexity, individual beliefs, the direct or indirect influence of others, job pressure, flexibility, rule definition, and clinician-centred design. Three candidates are considered for developing a model of safety behaviour and decision making. The dynamic safety model helps to understand the relationship between systems designs and human performance. The theory of planned behaviour suggests that intention is a function of attitudes, social norms and perceived behavioural control. The naturalistic decision making paradigm posits that decisions are based on a wider view of multiple patients, expertise, systems complexity, behavioural intention, individual beliefs and current understanding of the system. Understanding and predicting behavioural safety decisions could help us to encourage compliance to current processes and to design better interventions.

  9. Food safety performance indicators to benchmark food safety output of food safety management systems.

    Science.gov (United States)

    Jacxsens, L; Uyttendaele, M; Devlieghere, F; Rovira, J; Gomez, S Oses; Luning, P A

    2010-07-31

    There is a need to measure the food safety performance in the agri-food chain without performing actual microbiological analysis. A food safety performance diagnosis, based on seven indicators and corresponding assessment grids have been developed and validated in nine European food businesses. Validation was conducted on the basis of an extensive microbiological assessment scheme (MAS). The assumption behind the food safety performance diagnosis is that food businesses which evaluate the performance of their food safety management system in a more structured way and according to very strict and specific criteria will have a better insight in their actual microbiological food safety performance, because food safety problems will be more systematically detected. The diagnosis can be a useful tool to have a first indication about the microbiological performance of a food safety management system present in a food business. Moreover, the diagnosis can be used in quantitative studies to get insight in the effect of interventions on sector or governmental level. Copyright 2010 Elsevier B.V. All rights reserved.

  10. Seismic simulation and functional performance evaluation of a safety related, seismic category I control room emergency air cleaning system

    International Nuclear Information System (INIS)

    Manley, D.K.; Porco, R.D.; Choi, S.H.

    1985-01-01

    Under a nuclear contract MSA was required to design, manufacture, seismically test and functionally test a complete Safety Related, Seismic Category I, Control Room Emergency Air Cleaning System before shipment to the Yankee Atomic Electric Company, Yankee Nuclear Station in Rowe, Massachusetts. The installation of this system was required to satisfy the NRC requirements of NUREG-0737, Section III, D.3.4, ''Control Room Habitability''. The filter system tested was approximately 3 ft. wide by 8 ft. high by 18 ft. long and weighed an estimated 8300 pounds. It had a design flow rate of 3000 SCFM and contained four stages of filtration - prefilters, upstream and downstream HEPA filters and Type II sideload charcoal adsorber cells. The filter train design followed the guidelines set forth by ANSI/ASME N509-1980. Seismic Category I Qualification Testing consisted of resonance search testing and triaxial random multifrequency testing. In addition to ANSI/ASME N510-1980 testing, triaxial response accelerometers were placed at specific locations on designated prefilters, HEPA filters, charcoal adsorbers and test canisters along with accelerometers at the corresponding filter seal face locations. The purpose of this test was to demonstrate the integrity of the filters, filter seals, and monitor seismic response levels which is directly related to the system's ability to function during a seismic occurrence. The Control Room Emergency Air Cleaning System demonstrated the ability to withstand the maximum postulated earthquake for the plant site by remaining structurally sound and functional

  11. Normal people working in normal organizations with normal equipment: system safety and cognition in a mid-air collision.

    Science.gov (United States)

    de Carvalho, Paulo Victor Rodrigues; Gomes, José Orlando; Huber, Gilbert Jacob; Vidal, Mario Cesar

    2009-05-01

    A fundamental challenge in improving the safety of complex systems is to understand how accidents emerge in normal working situations, with equipment functioning normally in normally structured organizations. We present a field study of the en route mid-air collision between a commercial carrier and an executive jet, in the clear afternoon Amazon sky in which 154 people lost their lives, that illustrates one response to this challenge. Our focus was on how and why the several safety barriers of a well structured air traffic system melted down enabling the occurrence of this tragedy, without any catastrophic component failure, and in a situation where everything was functioning normally. We identify strong consistencies and feedbacks regarding factors of system day-to-day functioning that made monitoring and awareness difficult, and the cognitive strategies that operators have developed to deal with overall system behavior. These findings emphasize the active problem-solving behavior needed in air traffic control work, and highlight how the day-to-day functioning of the system can jeopardize such behavior. An immediate consequence is that safety managers and engineers should review their traditional safety approach and accident models based on equipment failure probability, linear combinations of failures, rules and procedures, and human errors, to deal with complex patterns of coincidence possibilities, unexpected links, resonance among system functions and activities, and system cognition.

  12. The hierarchy of essential CANDU reactor control functions in a distributed system

    International Nuclear Information System (INIS)

    Mercier, P.

    1980-01-01

    Control functions in CANDU nuclear generating stations are programmed within two centralized and redundant minicomputers while safety functions are covered by conventional analog systems. This set-up is a product of standards, economic and technical considerations which are now being modified by the maturing of microprocessors, the progress in digital communications and the development of mathematical process models. Starting from the control and safety systems installed in Gentilly-2, this paper analyses trends that will affect the implementation of essential control functions within a distributed system. In particular, it emphasizes the characteristics of future software systems that must be built-in in order to comply with important operational requirements of nuclear generating stations. (auth) [fr

  13. Development of the safety PLC for plant protection system

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Chang Hwoi; Lee, Dong Young [Korea Atomic Energy Research Institute, Taejeon (Korea, Republic of)

    2005-11-15

    The safety PLC (POSAFE-Q) is developing in the Korea Nuclear Instrumentation and Control System (KNICS) R and D project. The PLC satisfies Safety Class 1E, Quality Class 1, and Seismic Category I. The software such as RTOS and firmware are developed according to safety critical software life cycle. Especially, the formal method is applied to design SRS (Software Requirement Spec.) and SDS (Software Design Specification.) for error-free. The developed software according to software life cycle is verified by independent software V and V team. The overall response time from an input to the outputs shall be 50ms or less. The prototype for the POSAFE-Q was developed and functional testing and equipment qualification tests have been underway.

  14. Safety-critical Java for embedded systems

    DEFF Research Database (Denmark)

    Schoeberl, Martin; Dalsgaard, Andreas Engelbredt; Hansen, René Rydhof

    2016-01-01

    This paper presents the motivation for and outcomes of an engineering research project on certifiable Javafor embedded systems. The project supports the upcoming standard for safety-critical Java, which defines asubset of Java and libraries aiming for development of high criticality systems....... The outcome of this projectinclude prototype safety-critical Java implementations, a time-predictable Java processor, analysis tools formemory safety, and example applications to explore the usability of safety-critical Java for this applicationarea. The text summarizes developments and key contributions...

  15. A study of software safety analysis system for safety-critical software

    International Nuclear Information System (INIS)

    Chang, H. S.; Shin, H. K.; Chang, Y. W.; Jung, J. C.; Kim, J. H.; Han, H. H.; Son, H. S.

    2004-01-01

    The core factors and requirements for the safety-critical software traced and the methodology adopted in each stage of software life cycle are presented. In concept phase, Failure Modes and Effects Analysis (FMEA) for the system has been performed. The feasibility evaluation of selected safety parameter was performed and Preliminary Hazards Analysis list was prepared using HAZOP(Hazard and Operability) technique. And the check list for management control has been produced via walk-through technique. Based on the evaluation of the check list, activities to be performed in requirement phase have been determined. In the design phase, hazard analysis has been performed to check the safety capability of the system with regard to safety software algorithm using Fault Tree Analysis (FTA). In the test phase, the test items based on FMEA have been checked for fitness guided by an accident scenario. The pressurizer low pressure trip algorithm has been selected to apply FTA method to software safety analysis as a sample. By applying CASE tool, the requirements traceability of safety critical system has been enhanced during all of software life cycle phases

  16. Safety assessment for Generation IV nuclear systems

    International Nuclear Information System (INIS)

    Leahy, T.J.

    2012-01-01

    The Generation IV International Forum (GIF) Risk and Safety Working Group (RSWG) was created to develop an effective approach for the safety of Generation IV advanced nuclear energy systems. Recent RSWG work has focused on the definition of an integrated safety assessment methodology (ISAM) for evaluating the safety of Generation IV systems. ISAM is an integrated 'tool-kit' consisting of 5 analytical techniques that are available and matched to appropriate stages of Generation IV system concept development: 1) qualitative safety features review - QSR, 2) phenomena identification and ranking table - PIRT, 3) objective provision tree - OPT, 4) deterministic and phenomenological analyses - DPA, and 5) probabilistic safety analysis - PSA. The integrated methodology is intended to yield safety-related insights that help actively drive the evolving design throughout the technology development cycle, potentially resulting in enhanced safety, reduced costs, and shortened development time

  17. Problems of Rural Food Safety and Strategies of Constructing Supervision System

    Institute of Scientific and Technical Information of China (English)

    2011-01-01

    This paper expounds the practical necessity of constructing diversified rural food safety supervision system as follows: it is the necessary requirements of guaranteeing people’s health and life safety; it is an important component of governmental function of social management and the logical extension of administrative responsibilities; it is the basis of maintaining order of rural society and constructing harmonious society. The main problems existing in the supervision of rural food safety are analyzed as follows: first, the legislative work of rural food safety lags behind to some extent; second, the supervision of governmental departments on rural food safety is insufficient; third, the industrial supervision mechanism of rural food security is not perfect; fourth, the role of rural social organizations in supervising food safety is limited; fifth, the farmers’ awareness of food safety supervision is not strong. Based on these problems, the targeted strategies of constructing diversified rural food safety supervision system are put forward as follows: accelerate the legislation of rural food safety, and ensure that there are laws to go by; give play to the dominant role of government, and strengthen administrative supervision on rural food safety; perfect industrial convention of rural food safety, and improve industrial supervision mechanism; actively support the fostering of social organizations, and give play to the role of supervision of organizations; cultivate correct concept of rights and obligations of farmers, and form awareness of food safety supervision.

  18. Interaction between systems and software engineering in safety-critical systems

    International Nuclear Information System (INIS)

    Knight, J.

    1994-01-01

    There are three areas of concern: when is software to be considered safe; what, exactly, is the role of the software engineer; and how do systems, or sometimes applications, engineers and software engineers interact with each other. The author presents his perspective on these questions which he feels differ from those of many in the field. He argues for a clear definition of safety in the software arena, so the engineer knows what he is engineering toward. Software must be viewed as part of the entire system, since it does not function on its own, or isolation. He argues for the establishment of clear specifications in this area

  19. Analysis Method of Common Cause Failure on Non-safety Digital Control System

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Yun Goo; Oh, Eun Gse [KHNP, Daejeon (Korea, Republic of)

    2014-08-15

    The effects of common cause failure on safety digital instrumentation and control system had been considered in defense in depth analysis with safety analysis method. However, the effects of common cause failure on non-safety digital instrumentation and control system also should be evaluated. The common cause failure can be included in credible failure on the non-safety system. In the I and C architecture of nuclear power plant, many design feature has been applied for the functional integrity of control system. One of that is segmentation. Segmentation defenses the propagation of faults in the I and C architecture. Some of effects from common cause failure also can be limited by segmentation. Therefore, in this paper there are two type of failure mode, one is failures in one control group which is segmented, and the other is failures in multiple control group because that the segmentation cannot defense all effects from common cause failure. For each type, the worst failure scenario is needed to be determined, so the analysis method has been proposed in this paper. The evaluation can be qualitative when there is sufficient justification that the effects are bounded in previous safety analysis. When it is not bounded in previous safety analysis, additional analysis should be done with conservative assumptions method of previous safety analysis or best estimation method with realistic assumptions.

  20. Operation safety of control systems. Principles and methods; Surete de fonctionnement des systemes de commande. Principes et methodes

    Energy Technology Data Exchange (ETDEWEB)

    Aubry, J.F. [Institut National Polytechnique, 54 - Nancy (France); Chatelet, E. [Universite de Technologie de Troyes, 10 (France)

    2008-09-15

    This article presents the main operation safety methods that can be implemented to design safe control systems taking into account the behaviour of the different components with each other (binary 'operation/failure' behaviours, non-consistent behaviours and 'hidden' failures, dynamical behaviours and temporal aspects etc). To take into account these different behaviours, advanced qualitative and quantitative methods have to be used which are described in this article: 1 - qualitative methods of analysis: functional analysis, preliminary risk analysis, failure mode and failure effects analyses; 2 - quantitative study of systems operation safety: binary representation models, state space-based methods, event space-based methods; 3 - application to the design of control systems: safe specifications of a control system, qualitative analysis of operation safety, quantitative analysis, example of application; 4 - conclusion. (J.S.)

  1. OBTAINING FOOD SAFETY BY APPLYING HACCP SYSTEM

    Directory of Open Access Journals (Sweden)

    ION CRIVEANU

    2012-01-01

    Full Text Available In order to increase the confidence of the trading partners and consumers in the products which are sold on the market, enterprises producing food are required to implement the food safety system HACCP,a particularly useful system because the manufacturer is not able to fully control finished products . SR EN ISO 22000:2005 establishes requirements for a food safety management system where an organization in the food chain needs to proove its ability to control food safety hazards in order to ensure that food is safe at the time of human consumption. This paper presents the main steps which ensure food safety using the HACCP system, and SR EN ISO 20000:2005 requirements for food safety.

  2. ASIC-based design of NMR system health monitor for mission/safety-critical applications.

    Science.gov (United States)

    Balasubramanian, P

    2016-01-01

    N-modular redundancy (NMR) is a generic fault tolerance scheme that is widely used in safety-critical circuit/system designs to guarantee the correct operation with enhanced reliability. In passive NMR, at least a majority (N + 1)/2 out of N function modules is expected to operate correctly at any time, where N is odd. Apart from a conventional realization of the NMR system, it would be useful to provide a concurrent indication of the system's health so that an appropriate remedial action may be initiated depending upon an application's safety criticality. In this context, this article presents the novel design of a generic NMR system health monitor which features: (i) early fault warning logic, that is activated upon the production of a conflicting result by even one output of any arbitrary function module, and (ii) error signalling logic, which signals an error when the number of faulty function modules unfortunately attains a majority and the system outputs may no more be reliable. Two sample implementations of NMR systems viz. triple modular redundancy and quintuple modular redundancy with the proposed system health monitoring are presented in this work, with a 4-bit ALU used for the function modules. The simulations are performed using a 32/28 nm CMOS process technology.

  3. Functional safety for road vehicles new challenges and solutions for e-mobility and automated driving

    CERN Document Server

    Ross, Hans-Leo

    2016-01-01

    This book highlights the current challenges for engineers involved in product development and the associated changes in procedure they make necessary. Methods for systematically analyzing the requirements for safety and security mechanisms are described using examples of how they are implemented in software and hardware, and how their effectiveness can be demonstrated in terms of functional and design safety are discussed. Given today’s new E-mobility and automated driving approaches, new challenges are arising and further issues concerning “Road Vehicle Safety” and “Road Traffic Safety” have to be resolved. To address the growing complexity of vehicle functions, as well as the increasing need to accommodate interdisciplinary project teams, previous development approaches now have to be reconsidered, and system engineering approaches and proven management systems need to be supplemented or wholly redefined. The book presents a continuous system development process, starting with the basic requiremen...

  4. Safer Systems: A NextGen Aviation Safety Strategic Goal

    Science.gov (United States)

    Darr, Stephen T.; Ricks, Wendell R.; Lemos, Katherine A.

    2008-01-01

    The Joint Planning and Development Office (JPDO), is charged by Congress with developing the concepts and plans for the Next Generation Air Transportation System (NextGen). The National Aviation Safety Strategic Plan (NASSP), developed by the Safety Working Group of the JPDO, focuses on establishing the goals, objectives, and strategies needed to realize the safety objectives of the NextGen Integrated Plan. The three goal areas of the NASSP are Safer Practices, Safer Systems, and Safer Worldwide. Safer Practices emphasizes an integrated, systematic approach to safety risk management through implementation of formalized Safety Management Systems (SMS) that incorporate safety data analysis processes, and the enhancement of methods for ensuring safety is an inherent characteristic of NextGen. Safer Systems emphasizes implementation of safety-enhancing technologies, which will improve safety for human-centered interfaces and enhance the safety of airborne and ground-based systems. Safer Worldwide encourages coordinating the adoption of the safer practices and safer systems technologies, policies and procedures worldwide, such that the maximum level of safety is achieved across air transportation system boundaries. This paper introduces the NASSP and its development, and focuses on the Safer Systems elements of the NASSP, which incorporates three objectives for NextGen systems: 1) provide risk reducing system interfaces, 2) provide safety enhancements for airborne systems, and 3) provide safety enhancements for ground-based systems. The goal of this paper is to expose avionics and air traffic management system developers to NASSP objectives and Safer Systems strategies.

  5. Development of digital safety system logic and control

    International Nuclear Information System (INIS)

    Nishikawa, H.; Sakamoto, H.

    1995-01-01

    Advanced-BWR (ABWR) uses total digital control and instrumentation (C and I) system. In particular, ABWR adopts a newly developed safety system using advanced digital technology. In the presentation the digital safety system design, manufacturing and factory validation test method are shortly overviewed. The digital safety system consists of micro-processor based digital controllers, data and information transmission by optical fibers and human-machine interface using color flat displays. This new developed safety system meet the nuclear safety requirements such as high reliability, independence of divisions, operability and maintainability. (2 refs., 4 figs., 1 tab.)

  6. Probable variations of a passive safety containment for a 1700 MWe class PWR with passive safety systems

    International Nuclear Information System (INIS)

    Sato, Takashi; Fujiki, Yasunobu; Oikawa, Hirohide; Ofstun, Richard P.

    2009-01-01

    The paper presents probable variations of a passive safety containment for a PWR. The passive safety containment is named Mark P containment tentatively. It is a pressure suppression type containment for a large scale PWR with a BWR type passive containment cooling system (PCCS). More than 3-day grace period can be achieved even for a 1700 MWe class large scale PWR owing to the PCCS. The containment is a reinforced concrete containment vessel (RCCV). The design pressure of the RCCV can be low owing to the suppression pool (S/P) and no prestressed tendon is necessary. It is a single barrier CV that can withstand a large airplane crash by itself. This simple configuration results in good economy and short construction term. The BWR type passive safety systems also include the Passive Cooling and Depressurization System (PCDS). The PCDS has 3-day grace period for the SBO induced by a giant earthquake and can practically eliminate the residual risk of a giant earthquake beyond the design basis earthquake of Ss. It also has a safety function to automatically depressurize the primary system at accidents such as SGTR and eliminate the need for operator actions. It is a large 1700 MWe passive safety PWR that has more than 3-day grace period for extremely severe natural disasters including a giant earthquake, a mega hurricane, tsunami and so on; no containment failure at a SA establishing a no evacuation plant; protection for a large airplane crash with the RCCV single barrier; good economy and short construction term. (author)

  7. Safety monitoring in process and control

    International Nuclear Information System (INIS)

    Esparza, V. Jr.; Sebo, D.E.

    1984-01-01

    Safety Functions provide a method of ensuring the safe operation of any large-scale processing plant. Successful implementation of safety functions requires continuous monitoring of safety function values and trends. Because the volume of information handled by a plant operator occassionally can become overwhelming, attention may be diverted from the primary concern of maintaining plant safety. With this in mind EG and G, Idaho developed various methods and techniques for use in a computerized Safety Function Monitoring System and tested the application of these techniques using a simulated nuclear power plant, the Loss-of-Fluid Test Facility (LOFT) at the Idaho National Engineering Laboratory (INEL). This paper presents the methods used in the development of a Safety Function Monitoring System

  8. Operating function tests of the PWR type RHR pump for engineering safety system under simulated strong ground excitation

    International Nuclear Information System (INIS)

    Uga, Takeo; Shiraki, Kazuhiro; Homma, Toshiaki; Inazuka, Hisashi; Nakajima, Norifumi.

    1979-08-01

    Results are described of operating function verification tests of a PWR RHR pump during an earthquake. Of the active reactor components, the PWR residual heat removal pump was chosen from view points of aseismic classification, safety function, structural complexity and past aseismic tests. Through survey of the service conditions and structure of this pump, seismic test conditions such as acceleration level, simulated seismic wave form and earthquake duration were decided for seismicity of the operating pump. Then, plans were prepared to evaluate vibration chracteristics of the pump and to estimate its aseismic design margins. Subsequently, test facility and instrumentation system were designed and constructed. Experimental results could thus be acquired on vibration characteristics of the pump and its dynamic behavior during different kinds and levels of simulated earthquake. In conclusion: (1) Stiffeners attached to the auxiliary system piping do improve aseismic performance of the pump. (2) The rotor-shaft-bearing system is secure unless it is subjected to transient disturbunces having high frequency content. (3) The motor and pump casing having resonance frequencies much higher than frequency content of the seismic wave show only small amplifications. (4) The RHR pump possesses an aseismic design margin more than 2.6 times the expected ultimate earthquake on design basis. (author)

  9. Technical considerations for the development of an engineering safety features control system with PLC

    International Nuclear Information System (INIS)

    Lee, C. K.; Kim, C. H.; Han, J. B.; Kim, H.; Lee, S. S.

    2002-01-01

    Technical considerations are summarized for the development of an ESFCS(Engineered Safety Features Control System) with PLC (Programmable Logic Controller). The ESFCS is required for the mitigation of plant accident conditions and therefore developed in conformance with the design requirements applied to the safety critical system. The design of ESFCS primarily considered its safety, and the system has an architecture that will be able to minimize spurious actuation. The PLC based functional distribution and redundant design features are adopted, and the fieldbus is applied in the communication of information and control signals between PLC processors. It is expected that the ESFCS will have several advanced design features compared with the conventional systems supplied by foreign vendors

  10. Safety features of subcritical fluid fueled systems

    International Nuclear Information System (INIS)

    Bell, C.R.

    1995-01-01

    Accelerator-driven transmutation technology has been under study at Los Alamos for several years for application to nuclear waste treatment, tritium production, energy generation, and recently, to the disposition of excess weapons plutonium. Studies and evaluations performed to date at Los Alamos have led to a current focus on a fluid-fuel, fission system operating in a neutron source-supported subcritical mode, using molten salt reactor technology and accelerator-driven proton-neutron spallation. In this paper, the safety features and characteristics of such systems are explored from the perspective of the fundamental nuclear safety objectives that any reactor-type system should address. This exploration is qualitative in nature and uses current vintage solid-fueled reactors as a baseline for comparison. Based on the safety perspectives presented, such systems should be capable of meeting the fundamental nuclear safety objectives. In addition, they should be able to provide the safety robustness desired for advanced reactors. However, the manner in which safety objectives and robustness are achieved is very different from that associated with conventional reactors. Also, there are a number of safety design and operational challenges that will have to be addressed for the safety potential of such systems to be credible

  11. Safety features of subcritical fluid fueled systems

    International Nuclear Information System (INIS)

    Bell, C.R.

    1994-01-01

    Accelerator-driven transmutation technology has been under study at Los Alamos for several years for application to nuclear waste treatment, tritium production, energy generation, and recently, to the disposition of excess weapons plutonium. Studies and evaluations performed to date at Los Alamos have led to a current focus on a fluid-fuel, fission system operating in a neutron source-supported subcritical mode, using molten salt reactor technology and accelerator-driven proton-neutron spallation. In this paper, the safety features and characteristics of such systems are explored from the perspective of the fundamental nuclear safety objectives that any reactor-type system should address. This exploration is qualitative in nature and uses current vintage solid-fueled reactors as a baseline for comparison. Based on the safety perspectives presented, such systems should be capable of meeting the fundamental nuclear safety objectives. In addition, they should be able to provide the safety robustness desired for advanced reactors. However, the manner in which safety objectives and robustness are achieved in very different from that associated with conventional reactors. Also, there are a number of safety design and operational challenges that will have to be addressed for the safety potential of such systems to be credible

  12. Safety features of subcritical fluid fueled systems

    Energy Technology Data Exchange (ETDEWEB)

    Bell, C.R. [Los Alamos National Laboratory, NM (United States)

    1995-10-01

    Accelerator-driven transmutation technology has been under study at Los Alamos for several years for application to nuclear waste treatment, tritium production, energy generation, and recently, to the disposition of excess weapons plutonium. Studies and evaluations performed to date at Los Alamos have led to a current focus on a fluid-fuel, fission system operating in a neutron source-supported subcritical mode, using molten salt reactor technology and accelerator-driven proton-neutron spallation. In this paper, the safety features and characteristics of such systems are explored from the perspective of the fundamental nuclear safety objectives that any reactor-type system should address. This exploration is qualitative in nature and uses current vintage solid-fueled reactors as a baseline for comparison. Based on the safety perspectives presented, such systems should be capable of meeting the fundamental nuclear safety objectives. In addition, they should be able to provide the safety robustness desired for advanced reactors. However, the manner in which safety objectives and robustness are achieved is very different from that associated with conventional reactors. Also, there are a number of safety design and operational challenges that will have to be addressed for the safety potential of such systems to be credible.

  13. 77 FR 11120 - Patient Safety Organizations: Voluntary Relinquishment From UAB Health System Patient Safety...

    Science.gov (United States)

    2012-02-24

    ... Organizations: Voluntary Relinquishment From UAB Health System Patient Safety Organization AGENCY: Agency for... notification of voluntary relinquishment from the UAB Health System Patient Safety Organization of its status as a Patient Safety Organization (PSO). The Patient Safety and Quality Improvement Act of 2005...

  14. Design of safety-critical systems using the complementarities of success and failure domains with a case study

    International Nuclear Information System (INIS)

    Ahmed, Rizwan; Koo, June Mo; Jeong, Yong Hoon; Heo, Gyunyoung

    2011-01-01

    A safety-critical system has to qualify the performance-related requirements and the safety-related requirements simultaneously. Conceptually, design processes should consider both of them simultaneously but the practices do not and/or cannot follow such a theoretical approach due to the limitation of design resources. From our experience, we found that safety-related functions must be simultaneously resolved with the development of performance-related functions, particularly, in case of safety-critical systems. Since, success and failure domain analyses are essential for the investigation of performance-related and safety-related requirements, respectively, we articulated our perception to Axiomatic Design (AD), Fault Tree Analysis (FTA), and TRIZ. A design evolution procedure considering feedbacks from AD to identify functional couplings, TRIZ methodology to explore uncoupling solutions and FTA to improve reliability in a systematic way is presented here. A case study regarding design of safety injection tank installed in a nuclear power plant is also included to illustrate the proposed framework. It is expected that several iterations between AD-TRIZ-FTA would result into an optimized design which could be tested against the desired performance and safety criteria.

  15. Design of safety-critical systems using the complementarities of success and failure domains with a case study

    Energy Technology Data Exchange (ETDEWEB)

    Ahmed, Rizwan; Koo, June Mo [Department of Nuclear Engineering, Kyung Hee University, Yongin-si, Gyeonggi-do 446-701 (Korea, Republic of); Jeong, Yong Hoon [Korea Advanced Institute of Science and Technology, 373-1 Guseong-dong, Yuseong-gu, Daejeon 305-701 (Korea, Republic of); Heo, Gyunyoung, E-mail: gheo@khu.ac.k [Department of Nuclear Engineering, Kyung Hee University, Yongin-si, Gyeonggi-do 446-701 (Korea, Republic of)

    2011-01-15

    A safety-critical system has to qualify the performance-related requirements and the safety-related requirements simultaneously. Conceptually, design processes should consider both of them simultaneously but the practices do not and/or cannot follow such a theoretical approach due to the limitation of design resources. From our experience, we found that safety-related functions must be simultaneously resolved with the development of performance-related functions, particularly, in case of safety-critical systems. Since, success and failure domain analyses are essential for the investigation of performance-related and safety-related requirements, respectively, we articulated our perception to Axiomatic Design (AD), Fault Tree Analysis (FTA), and TRIZ. A design evolution procedure considering feedbacks from AD to identify functional couplings, TRIZ methodology to explore uncoupling solutions and FTA to improve reliability in a systematic way is presented here. A case study regarding design of safety injection tank installed in a nuclear power plant is also included to illustrate the proposed framework. It is expected that several iterations between AD-TRIZ-FTA would result into an optimized design which could be tested against the desired performance and safety criteria.

  16. Cognitive functioning differentially predicts different dimensions of older drivers' on-road safety.

    Science.gov (United States)

    Aksan, Nazan; Anderson, Steve W; Dawson, Jeffrey; Uc, Ergun; Rizzo, Matthew

    2015-02-01

    The extent to which deficits in specific cognitive domains contribute to older drivers' safety risk in complex real-world driving tasks is not well understood. We selected 148 drivers older than 70 years of age both with and without neurodegenerative diseases (Alzheimer disease-AD and Parkinson disease-PD) from an existing driving database of older adults. Participant assessments included on-road driving safety and cognitive functioning in visuospatial construction, speed of processing, memory, and executive functioning. The standardized on-road drive test was designed to examine multiple facets of older driver safety including navigation performance (e.g., following a route, identifying landmarks), safety errors while concurrently performing secondary navigation tasks ("on-task" safety errors), and safety errors in the absence of any secondary navigation tasks ("baseline" safety errors). The inter-correlations of these outcome measures were fair to moderate supporting their distinctiveness. Participants with diseases performed worse than the healthy aging group on all driving measures and differences between those with AD and PD were minimal. In multivariate analyses, different domains of cognitive functioning predicted distinct facets of driver safety on road. Memory and set-shifting predicted performance in navigation-related secondary tasks, speed of processing predicted on-task safety errors, and visuospatial construction predicted baseline safety errors. These findings support broad assessments of cognitive functioning to inform decisions regarding older driver safety on the road and suggest navigation performance may be useful in evaluating older driver fitness and restrictions in licensing. Copyright © 2014 Elsevier Ltd. All rights reserved.

  17. Challenges in the management of gas voids in safety related systems

    International Nuclear Information System (INIS)

    Ezekoye, L.I.; Turkowski, W.M.; Ferraraccio, F.P.; Swartz, M.M.

    2009-01-01

    Gas intrusion into Safety Related Systems, such as the Emergency Core Cooling System (ECCS), Decay Heat Removal (DHR) and Containment Spray (CS) in nuclear power plants is undesirable and can lead to pump binding (depending on the void fraction and flow rate) and damaging water hammer events. Gas ingestion in pumps can result in total or momentary loss of hydraulic performance resulting in possible pump shaft seizure rendering the pumps unable to perform their safety functions or reduce the pump discharge pressure and flow capacity to the point that the system cannot perform its design function. Extreme cases of gas water hammer can result in physical damage to system piping, components and supports, and possible relief valve lifting events with consequential loss of inventory. NRC Generic Letter GL 2008 01, 'Managing Gas Accumulation in Emergency Core Cooling, Decay Heat Removal, and Containment Spray Systems,' requires US utilities to demonstrate that suitable design, operational and testing measures are in place to maintain licensing commitments. The Generic Letter (GL 2008 01) outlines a number of actions that are detailed in nature, such as establishing pump void tolerance limits; establishing limits on pump suction void fractions, assuring adequate system venting capability, identification of all possible sources of gas intrusion, preventing vortex formation in tanks, and determining acceptable limits of gas in system discharge piping.. Regarding one of these issues, GL 2008 01 indicates that the amount of gas that can be ingested without significant impact on pump design, gas dispersion and flow rate. Each US nuclear power plant licensee is required to evaluate their ECCS, DHR and CS system design, operation and test procedures to assure that gas intrusion is minimized and monitored in order to maintain system operability and compliance with the requirements of 10 CFR 50 Appendix B. Typically, gas pockets get into the safety related systems through a number

  18. Challenges in the management of gas voids in safety related systems

    Energy Technology Data Exchange (ETDEWEB)

    Ezekoye, L.I.; Turkowski, W.M.; Ferraraccio, F.P.; Swartz, M.M. [Westinghouse Electric Company LLC, Pittsburgh (United States)

    2009-04-15

    Gas intrusion into Safety Related Systems, such as the Emergency Core Cooling System (ECCS), Decay Heat Removal (DHR) and Containment Spray (CS) in nuclear power plants is undesirable and can lead to pump binding (depending on the void fraction and flow rate) and damaging water hammer events. Gas ingestion in pumps can result in total or momentary loss of hydraulic performance resulting in possible pump shaft seizure rendering the pumps unable to perform their safety functions or reduce the pump discharge pressure and flow capacity to the point that the system cannot perform its design function. Extreme cases of gas water hammer can result in physical damage to system piping, components and supports, and possible relief valve lifting events with consequential loss of inventory. NRC Generic Letter GL 2008 01, 'Managing Gas Accumulation in Emergency Core Cooling, Decay Heat Removal, and Containment Spray Systems,' requires US utilities to demonstrate that suitable design, operational and testing measures are in place to maintain licensing commitments. The Generic Letter (GL 2008 01) outlines a number of actions that are detailed in nature, such as establishing pump void tolerance limits; establishing limits on pump suction void fractions, assuring adequate system venting capability, identification of all possible sources of gas intrusion, preventing vortex formation in tanks, and determining acceptable limits of gas in system discharge piping.. Regarding one of these issues, GL 2008 01 indicates that the amount of gas that can be ingested without significant impact on pump design, gas dispersion and flow rate. Each US nuclear power plant licensee is required to evaluate their ECCS, DHR and CS system design, operation and test procedures to assure that gas intrusion is minimized and monitored in order to maintain system operability and compliance with the requirements of 10 CFR 50 Appendix B. Typically, gas pockets get into the safety related systems through

  19. Functional safety measurement in the automotive domain : adaptation of PSM

    NARCIS (Netherlands)

    Luo, Y.; Stelma, J.; Brand, van den M.G.J.

    2015-01-01

    In the safety domain, safety standards are used as a development guideline to keep the risk at an acceptable level. Safety of the safety-critical systems can be assessed according to those safety standards. This assessment process is called safety assurance. Due to the manual work, the safety

  20. Safety Justification and Safety Case for Safety-critical Software in Digital Reactor Protection System

    International Nuclear Information System (INIS)

    Kwon, Kee-Choon; Lee, Jang-Soo; Jee, Eunkyoung

    2016-01-01

    Nuclear safety-critical software is under strict regulatory requirements and these regulatory requirements are essential for ensuring the safety of nuclear power plants. The verification & validation (V and V) and hazard analysis of the safety-critical software are required to follow regulatory requirements through the entire software life cycle. In order to obtain a license from the regulatory body through the development and validation of safety-critical software, it is essential to meet the standards which are required by the regulatory body throughout the software development process. Generally, large amounts of documents, which demonstrate safety justification including standard compliance, V and V, hazard analysis, and vulnerability assessment activities, are submitted to the regulatory body during the licensing process. It is not easy to accurately read and evaluate the whole documentation for the development activities, implementation technology, and validation activities. The safety case methodology has been kwon a promising approach to evaluate the level and depth of the development and validation results. A safety case is a structured argument, supported by a body of evidence that provides a compelling, comprehensible, and valid case that a system is safe for a given application in a given operating environment. It is suggested to evaluate the level and depth of the results of development and validation by applying safety case methodology to achieve software safety demonstration. A lot of documents provided as evidence are connected to claim that corresponds to the topic for safety demonstration. We demonstrated a case study in which more systematic safety demonstration for the target system software is performed via safety case construction than simply listing the documents

  1. Safety Justification and Safety Case for Safety-critical Software in Digital Reactor Protection System

    Energy Technology Data Exchange (ETDEWEB)

    Kwon, Kee-Choon; Lee, Jang-Soo [Korea Atomic Energy Research Institute, Daejeon (Korea, Republic of); Jee, Eunkyoung [KAIST, Daejeon (Korea, Republic of)

    2016-10-15

    Nuclear safety-critical software is under strict regulatory requirements and these regulatory requirements are essential for ensuring the safety of nuclear power plants. The verification & validation (V and V) and hazard analysis of the safety-critical software are required to follow regulatory requirements through the entire software life cycle. In order to obtain a license from the regulatory body through the development and validation of safety-critical software, it is essential to meet the standards which are required by the regulatory body throughout the software development process. Generally, large amounts of documents, which demonstrate safety justification including standard compliance, V and V, hazard analysis, and vulnerability assessment activities, are submitted to the regulatory body during the licensing process. It is not easy to accurately read and evaluate the whole documentation for the development activities, implementation technology, and validation activities. The safety case methodology has been kwon a promising approach to evaluate the level and depth of the development and validation results. A safety case is a structured argument, supported by a body of evidence that provides a compelling, comprehensible, and valid case that a system is safe for a given application in a given operating environment. It is suggested to evaluate the level and depth of the results of development and validation by applying safety case methodology to achieve software safety demonstration. A lot of documents provided as evidence are connected to claim that corresponds to the topic for safety demonstration. We demonstrated a case study in which more systematic safety demonstration for the target system software is performed via safety case construction than simply listing the documents.

  2. INTEGRATED SAFETY MANAGEMENT SYSTEM IN AIR TRAFFIC SERVICES

    Directory of Open Access Journals (Sweden)

    Volodymyr Kharchenko

    2014-06-01

    Full Text Available The article deals with the analysis of the researches conducted in the field of safety management systems.Safety management system framework, methods and tools for safety analysis in Air Traffic Control have been reviewed.Principles of development of Integrated safety management system in Air Traffic Services have been proposed.

  3. Technical feasibility and reliability of passive safety systems of AC600

    International Nuclear Information System (INIS)

    Niu, W.; Zeng, X.

    1996-01-01

    The first step conceptual design of the 600 MWe advanced PWR (AC-600) has been finished by the Nuclear Power Institute of China. Experiments on the passive system of AC-600 are being carried out, and are expected to be completed next year. The main research emphases of AC-600 conceptual design include the advanced core, the passive safety system and simplification. The design objective of AC-600 is that the safety, reliability, maintainability, operation cost and construction period are all improved upon compared to those of PWR plant. One of important means to achieve the objective is using a passive system, which has the following functions whenever its operation is required: providing the reactor core with enough coolant when others fail to make up the lost coolant; reactor residual heat removal; cooling and reducing pressure in the containment and preventing radioactive substances from being released into the environment after occurrence of accident (e.g. LOCA). The system should meet the single failure criterion, and keep operating when a single active component or passive component breaks down during the first 72 hour period after occurrence of accident, or in the long period following the 72 hour period. The passive safety system of AC-600 is composed of the primary safety injection system, the secondary emergency core residual heat removal system and the containment cooling system. The design of the system follows some relevant rules and criteria used by current PWR plant. The system has the ability to bear single failure, two complete separate subsystems are considered, each designed for 100% working capacity. Normal operation is separate from safety operation and avoids cross coupling and interference between systems, improves the reliability of components, and makes it easy to maintain, inspect and test the system. The paper discusses the technical feasibility and reliability of the passive safety system of AC-600, and some issues and test plans are also

  4. Technical feasibility and reliability of passive safety systems of AC600

    Energy Technology Data Exchange (ETDEWEB)

    Niu, W; Zeng, X [Nuclear Power Inst. of China, Chendu (China)

    1996-12-01

    The first step conceptual design of the 600 MWe advanced PWR (AC-600) has been finished. Experiments on the passive system of AC-600 are being carried out, and are expected to be completed next year. The main research emphases of AC-600 conceptual design include the advanced core, the passive safety system and simplification. The design objective of AC-600 is that the safety, reliability, maintainability, operation cost and construction period are all improved upon compared to those of PWR plant. One of important means to achieve the objective is using a passive system, which has the following functions whenever its operation is required: providing the reactor core with enough coolant when others fail to make up the lost coolant; reactor residual heat removal; cooling and reducing pressure in the containment and preventing radioactive substances from being released into the environment after occurrence of accident (e.g. LOCA). The system should meet the single failure criterion, and keep operating when a single active component or passive component breaks down during the first 72 hour period after occurrence of accident, or in the long period following the 72 hour period. The passive safety system of AC-600 is composed of the primary safety injection system, the secondary emergency core residual heat removal system and the containment cooling system. The design of the system follows some relevant rules and criteria used by current PWR plant. The system has the ability to bear single failure, two complete separate subsystems are considered, each designed for 100% working capacity. Normal operation is separate from safety operation and avoids cross coupling and interference between systems, improves the reliability of components, and makes it easy to maintain, inspect and test the system. The paper discusses the technical feasibility and reliability of the passive safety system of AC-600, and some issues and test plans are also involved. (author). 3 figs, 1 tab.

  5. System theory and safety models in Swedish, UK, Dutch and Australian road safety strategies.

    Science.gov (United States)

    Hughes, B P; Anund, A; Falkmer, T

    2015-01-01

    Road safety strategies represent interventions on a complex social technical system level. An understanding of a theoretical basis and description is required for strategies to be structured and developed. Road safety strategies are described as systems, but have not been related to the theory, principles and basis by which systems have been developed and analysed. Recently, road safety strategies, which have been employed for many years in different countries, have moved to a 'vision zero', or 'safe system' style. The aim of this study was to analyse the successful Swedish, United Kingdom and Dutch road safety strategies against the older, and newer, Australian road safety strategies, with respect to their foundations in system theory and safety models. Analysis of the strategies against these foundations could indicate potential improvements. The content of four modern cases of road safety strategy was compared against each other, reviewed against scientific systems theory and reviewed against types of safety model. The strategies contained substantial similarities, but were different in terms of fundamental constructs and principles, with limited theoretical basis. The results indicate that the modern strategies do not include essential aspects of systems theory that describe relationships and interdependencies between key components. The description of these strategies as systems is therefore not well founded and deserves further development. Copyright © 2014 Elsevier Ltd. All rights reserved.

  6. Safeguarding the functions and performance of instrumentation and control systems

    International Nuclear Information System (INIS)

    Koehler, M.; Schoerner, O.

    1996-01-01

    Based on an analysis of the existing nuclear power plant control technology, the necessity of providing in the medium-term advanced and future-oriented, digital control system, both for normal operation and for safety-relevant tasks of the reactor and safety control systems. Siemens KWU has been promoting the development, review and marketing of the digital instrumentation and control systems called TELEPERM XS and TELEPERM XP in addition to the measures taken for safeguarding the functions of existing, wired systems. The paper briefly explains the performance and advantages of digital systems and the progress in approval and pioneering of the TELEPERM XS safety control system. Many examples discussed show the diversity of applications of the systems both in new reactor plants and as retrofitting measures, for KWU power plants and those of other manufacturers. (orig.) [de

  7. Survey of the passive safety systems of the BWR 1000 concept from SIEMENS

    Energy Technology Data Exchange (ETDEWEB)

    Mattern, J; Brettschuh, W; Palavecino, C [SIEMENS, Energieerzeugung, Offenbach (Germany)

    1996-12-01

    Through the use of passive safety systems and components for accident control in addition to the active systems required for plant operation, a higher degree of safety against core-endangering conditions is achieved which is no longer ruled by complex system engineering dependent on power supply and activation by I and C systems. A low core power density and large water inventories stored inside the reactor pressure vessel as well as inside and outside the containment ensure good plant behaviour in the event of transients or accidents. These passive safety systems - which required neither electric power to function nor I and C systems for actuation, being activated solely on the basis of changes in process variables such as water level, pressure and temperature - provide a grace period of more than 5 days after the onset of accident conditions before manual intervention becomes necessary. 8 figs.

  8. A task management system for compliance with health, safety, and environmental regulations

    International Nuclear Information System (INIS)

    Crump, J.J.; O'Gorman, T.P.

    1992-01-01

    Shell Western E and P Inc. (SWEPI) has developed a new computer system to help it comply with health, safety, and environmental (HS and E) regulations. It is a task management system that functions at the detailed inventory level. It schedules work, instructs operations, and records compliance status. This article discusses design and development of the system

  9. Meeting the maglev system's safety requirements

    Energy Technology Data Exchange (ETDEWEB)

    Pierick, K

    1983-12-01

    The author shows how the safety requirements of the maglev track system derive from the general legal conditions for the safety of tracked transport. It is described how their compliance beyond the so-called ''development-accompanying'' and ''acceptance-preparatory'' safety work can be assured for the Transrapid test layout (TVE) now building in Emsland and also for later application as public transport system in Germany within the meaning of the General Railway Act.

  10. An overview of process instrumentation, protective safety interlocks and alarm system at the JET facilities active gas handling system

    International Nuclear Information System (INIS)

    Skinner, N.; Brennan, P.; Brown, K.; Gibbons, C.; Jones, G.; Knipe, S.; Manning, C.; Perevezentsev, A.; Stagg, R.; Thomas, R.; Yorkshades, J.

    2003-01-01

    The Joint European Torus (JET) Facilities Active Gas Handling System (AGHS) comprises ten interconnected processing sub-systems that supply, process and recover tritium from gases used in the JET Machine. Operations require a diverse range of process instrumentation to carry out a multiplicity of monitoring and control tasks and approximately 500 process variables are measured. The different types and application of process instruments are presented with specially adapted or custom-built versions highlighted. Forming part of the Safety Case for tritium operations, a dedicated hardwired interlock and alarm system provides an essential safety function. In the event of failure modes, each hardwired interlock will back-up software interlocks and shutdown areas of plant to a failsafe condition. Design of the interlock and alarm system is outlined and general methodology described. Practical experience gained during plant operations is summarised and the methods employed for routine functional testing of essential instrument systems explained

  11. Computer-aided safety systems of industrial high energy objects

    International Nuclear Information System (INIS)

    Topolsky, N.G.; Gordeev, S.G.

    1995-01-01

    Modern objects of fuel and energy, chemical industries are characterized by high power consumption; by presence of large quantities of combustible and explosive substances used in technological processes; by advanced communications of submission systems of initial liquid and gasiform reagents, lubricants and coolants, the products of processing, and wastes of production; by advanced ventilation and pneumatic transport; and by complex control systems of energy, material and information flows. Such objects have advanced infrastructures, including a significant quantity of engineering buildings intended for storage, transportation, and processing of combustible liquids, gasiform fuels and materials, and firm materials. Examples of similar objects are nuclear and thermal power stations, chemical plants, machine-building factories, iron and steel industry enterprises, etc. Many tasks and functions characterizing the problem of fire safety of these objects can be accomplished only upon the development of special Computer-Aided Fire Safety Systems (CAFSS). The CAFSS for these objects are intended to reduce the hazard of disastrous accidents both causing fires and caused by them. The tasks of fire prevention and rescue work of large-scale industrial objects are analyzed within the bounds of the recommended conception. A functional structure of CAFSS with a list of the main subsystems forming a part of its composition has been proposed

  12. Color Functionality Used in Visual Display for Occupational and Environmental Safety and Managing Color Vision Deficiency.

    Science.gov (United States)

    Ochiai, Nobuhisa; Kondo, Hiroyuki

    2017-01-01

    The effects of color perception are utilized in visual displays for the purpose of safety in the workplace and in daily life. These effects, generally known as color functionality, are divided into four classifications: visibility, legibility, conspicuity and discriminability. This article focuses on the relationship between the color functionality of color schemes used in visual displays for occupational and environmental safety and color vision deficiency (particularly congenital red-green color deficiency), a critical issue in ophthalmology, and examines the effects of color functionality on the perception of the color red in individuals with protan defects. Due to abrupt system reforms, current Japanese clinical ophthalmology finds itself in a situation where it is insufficiently prepared to handle congenital red-green color deficiencies. Indeed, occupational problems caused by color vision deficiencies have been almost completely neglected, and are an occupational safety and health concern that will need to be solved in the future. This report will present the guidelines for the color vision testing established by the British Health and Safety Executive (HSE), a pioneering example of a model meant to solve these problems. Issues relating to the creation of guidelines adapted to Japanese clinical ophthalmology will also be examined, and we will discuss ways to utilize color functionality used in visual displays for occupational and environmental safety to help manage color vision deficiency.

  13. Safety classification of systems, structures, and components for pool-type research reactors

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Tae Ryong [KEPCO International Nuclear Graduate School, Ulsan (Korea, Republic of)

    2016-08-15

    Structures, systems, and components (SSCs) important to safety of nuclear facilities shall be designed, fabricated, erected, and tested to quality standards commensurate with the importance of the safety functions. Although SSC classification guidelines for nuclear power plants have been well established and applied, those for research reactors have been only recently established by the International Atomic Energy Agency (IAEA). Korea has operated a pool-type research reactor (the High Flux Advanced Neutron Application Reactor) and has recently exported another pool-type reactor (Jordan Research and Training Reactor), which is being built in Jordan. Korea also has a plan to build one more pool-type reactor, the Kijang Research Reactor, in Kijang, Busan. The safety classification of SSCs for pool-type research reactors is proposed in this paper based on the IAEA methodology. The proposal recommends that the SSCs of pool-type research reactors be categorized and classified on basis of their safety functions and safety significance. Because the SSCs in pool-type research reactors are not the pressure-retaining components, codes and standards for design of the SSCs following the safety classification can be selected in a graded approach.

  14. Strategy to safety grade systems replacements

    International Nuclear Information System (INIS)

    Stimler, M.; Sullivan, K.E.; Trebincevic, I.

    1993-01-01

    The introduction of digital instrumentation and control systems in nuclear power plants is characterized by the need to satisfy the requirements of safety, reliability and man-machine ergonomics. Today digital instrumentation and control systems meet these requirements and the trend in Europe is towards full digital based nuclear power plant control systems. This paper describes Siemens (KWU) experience in nuclear power plants and development in trends within Europe. Topics which are the subject of major concern to NPP operators addressed in this paper are: human performance factors - man-machine interface; operating philosophy; safety, availability and reliability. Other aspects addressed are: Siemens open-quotes defense in depthclose quotes concept, description of Siemens digital I ampersand C systems, safety requirements and systems, I ampersand C qualification, control room ergonomics, information systems and retrofitting experience

  15. Test Results of a Platform for Safety I and C Systems of SMART MMIS

    International Nuclear Information System (INIS)

    Suh, Yong Suk; Keum, Jong Yong; Jeong, Kwang Il; Lee, Joon Ku; Lee, Sang Seok; Kim, Kwan Woong

    2011-01-01

    SMART (System-integrated Modular Advanced ReacTor), a 330MWt integral pressurized light water reactor that integrates four reactor coolant pumps, one pressurizer, eight steam generators, and one reactor core into a reactor vessel, has been under development at KAERI since 1997. A standard design safety analysis report of the SMART prepared by KAERI was submitted to Korea institute of nuclear safety (KINS) at the end of 2010. KAERI aims to achieve standard design approval (SDA) from KINS by the end of 2011. SMART MMIS has been designed using digital systems. It has digital-based compact control rooms. Its instrumentation and control (I and C) systems are designed using modular equipment connected through datalinks. Non-safety I and C systems are designed based on the commercial distributed control systems. Safety I and C systems are based on a new platform developed by KAERI. The platform is a high-speed digital signal processor (DSP)-based control unit. It plays the role of a module that provides control functions of the safety I and C systems. The test facilities have been developed at KAERI since 2009. This paper presents the development and test results of the platform

  16. System safety education focused on system management

    Science.gov (United States)

    Grose, V. L.

    1971-01-01

    System safety is defined and characteristics of the system are outlined. Some of the principle characteristics include role of humans in hazard analysis, clear language for input and output, system interdependence, self containment, and parallel analysis of elements.

  17. Design of safety monitor system for operation sintering furnace ME-06

    International Nuclear Information System (INIS)

    Sugeng Rianto; Triarjo; Djoko Kisworo; Agus Sartono

    2013-01-01

    Design of safety monitoring system for safety operation of sinter furnace ME-06 has been done. Parameters monitored during this operation include: temperature, gas pressure, flow rate of gas, voltage and current furnace. For sintering furnace temperature system that monitored were the temperature of the furnace temperature, the temperature of the cooling water system inlet and outlet, temperature of flow hydrogen gas inlet and outlet. For pressure system and flow rate gas sinter furnace which monitored the pressure and flow rate of hydrogen gas inlet and outlet. The system also monitors current and voltage applied to the sinter furnace heating system. Monitor system hardware consists of: the system temperature sensor, pressure, rate and data acquisition systems. While software systems using the labview driver interface that connects the hard and software systems. Function test results during sintering operation for setting the temperature 1700 °C sintering temperature increases the ramp function by 250 °C/hour average measurements obtained when the sintering time 1707.016 °C with a standard deviation of 0.38 °C. The maximum temperature of the hydrogen gas temperature 35.4 °C. The maximum temperature of the cooling water system 27.4 °C. The maximum pressure of 1,911 bar Gas Inlet and outlet of 0,051 bar. Maximum inlet gas flow 12.996 L / min and outlet 14.086 L / min. (author)

  18. Status and topics of thermal-hydraulic analysis for next-generation LWRs with passive safety systems

    International Nuclear Information System (INIS)

    Aritomi, Masanori; Ohnuki, Akira; Arai, Kenji; Kikuta, Michitaka; Yonomoto, Taisuke; Araya, Fumimasa; Akimoto, Hajime

    1999-01-01

    For increasing of electric power demand and reducing of carbon dioxide exhaust in the 21st century, studies of the next-generation light water reactor (LWR) with passive safety systems are developing in the world: AP-600 (by Westing House Co.); SBWR (by General Electric Co.); SWR1000 (by Siemens Co.); NP21 (by Mitsubishi Heavy Industry Co., et al.); JPSR (by JAERI). The passive equipment using natural circulation and natural convection are installed in the passive safety system, instead of active safety equipment, such as pumps, etc. It remains still as a important issue, however, to verify the reliability on the functions of the passive equipment, since that the driving forces of the passive equipment are small at comparison with the active safety equipment. The various subjects of thermal-hydraulic analysis for the next-generation light water reactors, such as temperature stratification in the passive safety systems, vapor condensation in the mixture of non-condensable gases and the interactions of the passive safety system with the primary cooling system, are illustrated and discussed in the paper. (M. Suetake)

  19. Development of the JNC geological disposal technical information integration system subjected for repository design and safety assessment

    International Nuclear Information System (INIS)

    Ishihara, Yoshinao; Ito, Takashi; Kobayashi, Shigeki; Neyama, Atsushi

    2004-02-01

    On this work, system manufacture about disposal technology and safety assessment field was performed towards construction of the JNC Geological Disposal Technical Information Integration System which systematized three fields of technical information acquired in investigation (site characteristic investigation) of geology environmental conditions, disposal technology (design of deep repository), and performance/safety assessment. The technical information database managed focusing on the technical information concerning individual research of an examination, analysis, etc. and the parameter set database managed focusing on the set up data set used in case of comprehensive evaluation are examined. In order to support and promote share and use of the technical information registered and managed by the database, utility functions, such as a technical information registration function, technical information search/browse function, analysis support function, and visualization function, are considered, and the system realized in these functions is built. The built system is installed in the server of JNC, and the functional check examination is carried out. (author)

  20. Safety Management System in Croatia Control Ltd.

    OpenAIRE

    Pavlin, Stanislav; Sorić, Vedran; Bilać, Dragan; Dimnik, Igor; Galić, Daniel

    2009-01-01

    International Civil Aviation Organization and other international aviation organizations regulate the safety in civil aviation. In the recent years the International Civil Aviation Organization has introduced the concept of the safety management system through several documents among which the most important is the 2006 Safety Management Manual. It treats the safety management system in all the segments of civil aviation, from carriers, aerodromes and air traffic control to design, constructi...

  1. System study application to the safety analysis of the exhaust and the tritium systems of a fusion reactor

    International Nuclear Information System (INIS)

    Djerassi, H.; Rouillard, J.; Leger, D.; Zappellini, G.; Gambi, G.

    1988-01-01

    An applicative example of the general methodology system study to the safety analysis of the exhaust and tritium systems, in a tokamak device, is shown. The framework of the study is split into the following tasks: initial information collection, functional analysis, failure scenarios identification and description, reliability data assessment, accident sequence quantification, consequence seriousness evaluation, risk assessment. Results concerning risk contribution from direct failures show that, in the exhaust system and in the tritium system, the risk contribution to public is rather smaller than the safety design targets. Nevertheless, if the reactor building is not taken into account, the risk contribution from the exhaust system can be significant. Risk contribution to the workers seems to be not to heavy

  2. Safety-related control air systems - approved 1977

    International Nuclear Information System (INIS)

    Anon.

    1978-01-01

    This standard applies to those portions of the control air system that furnish air required to support, control, or operate systems or portions of systems that are safety related in nuclear power plants. This standard relates only to the air supply system(s) for safety-related air operated devices and does not apply to the safety-related air operated device or to air operated actuators for such devices. The objectives of this standard are to provide (1) minimum system design requirements for equipment, piping, instruments, controls, and wiring that constitute the air supply system; and (2) the system and component testing and maintenance requirements

  3. Qualification of FPGA-Based Safety-Related PRM System

    International Nuclear Information System (INIS)

    Miyazaki, Tadashi; Oda, Naotaka; Goto, Yasushi; Hayashi, Toshifumi

    2011-01-01

    Toshiba has developed Non-rewritable (NRW) Field Programmable Gate Array (FPGA)-based safety-related Instrumentation and Control (I and C) system. Considering application to safety-related systems, nonvolatile and non-rewritable FPGA which is impossible to be changed after once manufactured has been adopted in Toshiba FPGA-based system. FPGA is a device which consists only of basic logic circuits, and FPGA performs defined processing which is configured by connecting the basic logic circuit inside the FPGA. FPGA-based system solves issues existing both in the conventional systems operated by analog circuits (analog-based system) and the systems operated by central processing unit (CPU-based system). The advantages of applying FPGA are to keep the long-life supply of products, improving testability (verification), and to reduce the drift which may occur in analog-based system. The system which Toshiba developed this time is Power Range Neutron Monitor (PRM). Toshiba is planning to expand application of FPGA-based technology by adopting this development process to the other safety-related systems such as RPS from now on. Toshiba developed a special design process for NRW-FPGA-based safety-related I and C systems. The design process resolves issues for many years regarding testability of the digital system for nuclear safety application. Thus, Toshiba NRW-FPGA-based safety-related I and C systems has much advantage to be a would standard of the digital systems for nuclear safety application. (author)

  4. Safety climate and culture: Integrating psychological and systems perspectives.

    Science.gov (United States)

    Casey, Tristan; Griffin, Mark A; Flatau Harrison, Huw; Neal, Andrew

    2017-07-01

    Safety climate research has reached a mature stage of development, with a number of meta-analyses demonstrating the link between safety climate and safety outcomes. More recently, there has been interest from systems theorists in integrating the concept of safety culture and to a lesser extent, safety climate into systems-based models of organizational safety. Such models represent a theoretical and practical development of the safety climate concept by positioning climate as part of a dynamic work system in which perceptions of safety act to constrain and shape employee behavior. We propose safety climate and safety culture constitute part of the enabling capitals through which organizations build safety capability. We discuss how organizations can deploy different configurations of enabling capital to exert control over work systems and maintain safe and productive performance. We outline 4 key strategies through which organizations to reconcile the system control problems of promotion versus prevention, and stability versus flexibility. (PsycINFO Database Record (c) 2017 APA, all rights reserved).

  5. Passive safety systems and natural circulation in water cooled nuclear power plants

    International Nuclear Information System (INIS)

    2009-11-01

    Nuclear power produces 15% of the world's electricity. Many countries are planning to either introduce nuclear energy or expand their nuclear generating capacity. Design organizations are incorporating both proven means and new approaches for reducing the capital costs of their advanced designs. In the future most new nuclear plants will be of evolutionary design, often pursuing economies of scale. In the longer term, innovative designs could help to promote a new era of nuclear power. Since the mid-1980s it has been recognized that the application of passive safety systems (i.e. those whose operation takes advantage of natural forces such as convection and gravity), can contribute to simplification and potentially improve economics of new nuclear power plant designs. The IAEA Conference on The Safety of Nuclear Power: Strategy for the Future, which was convened in 1991, noted that for new plants 'the use of passive safety features is a desirable method of achieving simplification and increasing the reliability of the performance of essential safety functions, and should be used wherever appropriate'. Some new designs also utilize natural circulation as a means to remove core power during normal operation. The use of passive systems can eliminate the costs associated with the installation, maintenance, and operation of active systems that require multiple pumps with independent and redundant electric power supplies. However, considering the weak driving forces of passive systems based on natural circulation, careful design and analysis methods must be employed to ensure that the systems perform their intended functions. To support the development of advanced water cooled reactor designs with passive systems, investigations of natural circulation are conducted in several IAEA Member States with advanced reactor development programmes. To foster international collaboration on the enabling technology of passive systems that utilize natural circulation, the IAEA

  6. Safety assessment of high consequence robotics system

    International Nuclear Information System (INIS)

    Robinson, D.G.; Atcitty, C.B.

    1996-01-01

    This paper outlines the use of a failure modes and effects analysis for the safety assessment of a robotic system being developed at Sandia National Laboratories. The robotic system, the weigh and leak check system, is to replace a manual process for weight and leakage of nuclear materials at the DOE Pantex facility. Failure modes and effects analyses were completed for the robotics process to ensure that safety goals for the systems have been met. Due to the flexible nature of the robot configuration, traditional failure modes and effects analysis (FMEA) were not applicable. In addition, the primary focus of safety assessments of robotics systems has been the protection of personnel in the immediate area. In this application, the safety analysis must account for the sensitivities of the payload as well as traditional issues. A unique variation on the classical FMEA was developed that permits an organized and quite effective tool to be used to assure that safety was adequately considered during the development of the robotic system. The fundamental aspects of the approach are outlined in the paper

  7. A formal safety analysis for PLC software-based safety critical system using Z

    International Nuclear Information System (INIS)

    Koh, Jung Soo

    1997-02-01

    This paper describes a formal safety analysis technique which is demonstrated by performing empirical formal safety analysis with the case study of beamline hutch door Interlock system that is developed by using PLC (Programmable Logic Controller) systems at the Pohang Accelerator Laboratory. In order to perform formal safety analysis, we have built the Z formal specifications representation from user requirement written in ambiguous natural language and target PLC ladder logic, respectively. We have also studied the effective method to express typical PLC timer component by using specific Z formal notation which is supported by temporal history. We present a formal proof technique specifying and verifying that the hazardous states are not introduced into ladder logic in the PLC-based safety critical system. And also, we have found that some errors or mismatches in user requirement and final implemented PLC ladder logic while analyzing the process of the consistency and completeness of Z translated formal specifications. In the case of relatively small systems like Beamline hutch door interlock system, a formal safety analysis including explicit proof is highly recommended so that the safety of PLC-based critical system may be enhanced and guaranteed. It also provides a helpful benefits enough to comprehend user requirement expressed by ambiguous natural language

  8. A Framework Based on a Systems Approach to Developing Safety Indicators in Fish Farming

    Directory of Open Access Journals (Sweden)

    Siri Mariane Holen

    2018-05-01

    Full Text Available The fish farming industry is one of the industries in Norway with the highest occupational fatality and injury rate. Despite the serious health, safety, and environmental issues in the industry, little is done to measure changes in safety over time beyond the traditional Lost Time Injury (LTI registrations. In this article the objective is twofold; (i to propose a framework for developing safety indicators based on Systems-Theoretic Process Analysis (STPA, and (ii to apply the framework to find indicators relevant for hazards in operations where subcontractors participate. STPA uses a hierarchical portrayal of the system in focus, in contrast to sequential models, and views safety as a control problem. It is believed that a systemic approach to indicator development better captures the complex safety challenges in aquaculture. Thirteen indicators are identified within areas such as maintenance, training, and planning. The indicators identified may function as a basis for decisions and actions that must be undertaken to ensure safe operations.

  9. Quantitative safety assessment of air traffic control systems through system control capacity

    Science.gov (United States)

    Guo, Jingjing

    Quantitative Safety Assessments (QSA) are essential to safety benefit verification and regulations of developmental changes in safety critical systems like the Air Traffic Control (ATC) systems. Effectiveness of the assessments is particularly desirable today in the safe implementations of revolutionary ATC overhauls like NextGen and SESAR. QSA of ATC systems are however challenged by system complexity and lack of accident data. Extending from the idea "safety is a control problem" in the literature, this research proposes to assess system safety from the control perspective, through quantifying a system's "control capacity". A system's safety performance correlates to this "control capacity" in the control of "safety critical processes". To examine this idea in QSA of the ATC systems, a Control-capacity Based Safety Assessment Framework (CBSAF) is developed which includes two control capacity metrics and a procedural method. The two metrics are Probabilistic System Control-capacity (PSC) and Temporal System Control-capacity (TSC); each addresses an aspect of a system's control capacity. And the procedural method consists three general stages: I) identification of safety critical processes, II) development of system control models and III) evaluation of system control capacity. The CBSAF was tested in two case studies. The first one assesses an en-route collision avoidance scenario and compares three hypothetical configurations. The CBSAF was able to capture the uncoordinated behavior between two means of control, as was observed in a historic midair collision accident. The second case study compares CBSAF with an existing risk based QSA method in assessing the safety benefits of introducing a runway incursion alert system. Similar conclusions are reached between the two methods, while the CBSAF has the advantage of simplicity and provides a new control-based perspective and interpretation to the assessments. The case studies are intended to investigate the

  10. Radiological safety system based on real-time tritium-in-air monitoring indoors and in effluents

    International Nuclear Information System (INIS)

    Bidica, N.; Sofalca, N; Balteanu, O.; Srefan, I.

    2006-01-01

    Exposure to tritium is an important health hazard in any tritium processing facility so that implementing a real-time tritium monitoring system is necessary for its operation in safety conditions. The tritium processing facility operators need to be informed at any time about the in-air tritium concentration indoors or in the stack effluents, in order to detect immediately any leaks in tritium containments, or any releases inside the buildings or to the environment. This information is very important for adopting if necessary protection measures and correcting actions as quickly as possible. In this paper we describe an improved real-time tritium monitoring system designed for the Heavy Water Detritiation Pilot Plant of National Institute for Cryogenics and Isotopes Separation, Rm. Valcea, Romania. The design of the Radiological Safety System implemented for the ICIT Water Detritiation Pilot Plant is intended to provide the maximum safety level based on the ALARA concept. The main functions of tritium monitoring system are: - monitoring the working areas and gaseous effluents by determination of the tritium-in-air activity concentration; - local and remote data display; - assessing of environment dose equivalent rates and dose equivalents in the working environment (for personnel exposure control and work planning); - assessing the total tritium activity released to the environment through ventilation exhaust stack; - safety functions, i.e., local and remote, locking/unlocking personnel access, process shut-down in emergency conditions and start of the air cleaning systems. With all these features our tritium monitoring system is really a safety system adequate for personnel and environmental protection. (authors)

  11. Upgrading safety systems of industrial irradiation facilities

    International Nuclear Information System (INIS)

    Gomes, R.S.; Gomes, J.D.R.L.; Costa, E.L.C.; Costa, M.L.L.; Thomé, Z.D.

    2017-01-01

    The first industrial irradiation facility in operation in Brazil was designed in the 70s. Nowadays, twelve commercial and research facilities are in operation and two already decommissioned. Minor modifications and upgrades, as sensors replacement, have been introduced in these facilities, in order to reduce the technological gap in the control and safety systems. The safety systems are designed in agreement with the codes and standards at the time. Since then, new standards, codes and recommendations, as well as lessons learned from accidents, have been issued by various international committees or regulatory bodies. The rapid advance of the industry makes the safety equipment used in the original construction become obsolete. The decreasing demand for these older products means that they are no longer produced, which can make it impossible or costly to obtain spare parts and the expansion of legacy systems to include new features. This work aims to evaluate existing safety systems at Brazilian irradiation facilities, mainly the oldest facilities, taking into account the recommended IAEA's design requirements. Irrespective of the fact that during its operational period no event with victims have been recorded in Brazilian facilities, and that the regulatory inspections do not present any serious deviations regarding the safety procedures, it is necessary an assessment of safety system with the purpose of bringing their systems to 'the state of the art', avoiding their rapid obsolescence. This study has also taken into account the knowledge, concepts and solutions developed to upgrading safety system in irradiation facilities throughout the world. (author)

  12. Upgrading safety systems of industrial irradiation facilities

    Energy Technology Data Exchange (ETDEWEB)

    Gomes, R.S.; Gomes, J.D.R.L.; Costa, E.L.C.; Costa, M.L.L., E-mail: rogeriog@cnen.gov.br, E-mail: jlopes@cnen.gov.br, E-mail: evaldo@cnen.gov.br, E-mail: mara@cnen.gov.br [Comissão Nacional de Energia Nuclear (CNEN), Rio de Janeiro, RJ (Brazil). Diretoria de Radioproteção e Segurança Nuclear; Thomé, Z.D., E-mail: zielithome@gmail.com [Instituto Militar de Engenharia (IME), Rio de Janeiro, RJ (Brazil). Seção de Engenharia Nuclear

    2017-07-01

    The first industrial irradiation facility in operation in Brazil was designed in the 70s. Nowadays, twelve commercial and research facilities are in operation and two already decommissioned. Minor modifications and upgrades, as sensors replacement, have been introduced in these facilities, in order to reduce the technological gap in the control and safety systems. The safety systems are designed in agreement with the codes and standards at the time. Since then, new standards, codes and recommendations, as well as lessons learned from accidents, have been issued by various international committees or regulatory bodies. The rapid advance of the industry makes the safety equipment used in the original construction become obsolete. The decreasing demand for these older products means that they are no longer produced, which can make it impossible or costly to obtain spare parts and the expansion of legacy systems to include new features. This work aims to evaluate existing safety systems at Brazilian irradiation facilities, mainly the oldest facilities, taking into account the recommended IAEA's design requirements. Irrespective of the fact that during its operational period no event with victims have been recorded in Brazilian facilities, and that the regulatory inspections do not present any serious deviations regarding the safety procedures, it is necessary an assessment of safety system with the purpose of bringing their systems to 'the state of the art', avoiding their rapid obsolescence. This study has also taken into account the knowledge, concepts and solutions developed to upgrading safety system in irradiation facilities throughout the world. (author)

  13. Plasma, a plant safety monitoring and assessment system for VVER-440 reactors

    Energy Technology Data Exchange (ETDEWEB)

    Hornaes, A.; Hulsund, J. E. [Institutt for energiteknikk (IFE), OECD Halden Reactor Project, Halden (Norway); Lipcsei, S.; Major, Cs.; Racz, A.; Vegh, J. [KFKI, Atomic Energy Research Institute, Budapest (Hungary); Eiler, J. [Paks, Nuclear Power Plant Ltd, Paks (Hungary)

    1999-05-15

    The objective with the Plant Safety Monitoring and Assessment System (PLASMA) is to develop an operator support system to support the execution of new symptom-based Emergency Operating Procedures for application in VVER reactors, with the Paks NPP in Hungary as the target plant. Many of the VVER reactors are rewriting their EOPs to comply more with Western standards of symptom-based EOPs. In this connection it is desirable to improve the data validation, information integration and presentation for operators when executing the EOPs. The entry-point to a symptom-oriented procedure is defined by the occurrence of a well-defined reactor operation status, with all its symptoms. However, the application of the EOF benefits from an operator support system, which performs plant status and symptom identification reliably and accurately. The development of the PLASMA system is a joint venture between Institutt for energiteknikk (IFE) and KFKI with the NPP Paks as the target plant. The project has been initiated and partly funded by the Science and Technology Agency (STA), Japan through the OECD NEA assistance program. In Hungary, considerable effort has concentrated on the safety reassessment of the Paks NPP and new EOPs are being written, but no comprehensive Operator Support System (OSS) for plant safety assessment is installed. Some safety parameter display functions are incorporated into diverse operator support systems, but an online 'plant safety monitoring and assessment system' is still missing. The present project comprises designing, constructing, testing and installing such an OSS, which to a great extent could support plant operators in their safety assessment work (author) (ml)

  14. Safety status system for operating room devices.

    Science.gov (United States)

    Guédon, Annetje C P; Wauben, Linda S G L; Overvelde, Marlies; Blok, Joleen H; van der Elst, Maarten; Dankelman, Jenny; van den Dobbelsteen, John J

    2014-01-01

    Since the increase of the number of technological aids in the operating room (OR), equipment-related incidents have come to be a common kind of adverse events. This underlines the importance of adequate equipment management to improve the safety in the OR. A system was developed to monitor the safety status (periodic maintenance and registered malfunctions) of OR devices and to facilitate the notification of malfunctions. The objective was to assess whether the system is suitable for use in an busy OR setting and to analyse its effect on the notification of malfunctions. The system checks automatically the safety status of OR devices through constant communication with the technical facility management system, informs the OR staff real-time and facilitates notification of malfunctions. The system was tested for a pilot period of six months in four ORs of a Dutch teaching hospital and 17 users were interviewed on the usability of the system. The users provided positive feedback on the usability. For 86.6% of total time, the localisation of OR devices was accurate. 62 malfunctions of OR devices were reported, an increase of 12 notifications compared to the previous year. The safety status system was suitable for an OR complex, both from a usability and technical point of view, and an increase of reported malfunctions was observed. The system eases monitoring the safety status of equipment and is a promising tool to improve the safety related to OR devices.

  15. Plant air systems safety study: Portsmouth Gaseous Diffusion Plant

    International Nuclear Information System (INIS)

    1982-05-01

    The Portsmouth Gaseous Diffusion Plant Air System facilities and operations are reviewed for potential safety problems not covered by standard industrial safety procedures. Information is presented under the following section headings: facility and process description (general); air plant equipment; air distribution system; safety systems; accident analysis; plant air system safety overview; and conclusion

  16. A philosophy for space nuclear systems safety

    International Nuclear Information System (INIS)

    Marshall, A.C.

    1992-01-01

    The unique requirements and contraints of space nuclear systems require careful consideration in the development of a safety policy. The Nuclear Safety Policy Working Group (NSPWG) for the Space Exploration Initiative has proposed a hierarchical approach with safety policy at the top of the hierarchy. This policy allows safety requirements to be tailored to specific applications while still providing reassurance to regulators and the general public that the necessary measures have been taken to assure safe application of space nuclear systems. The safety policy used by the NSPWG is recommended for all space nuclear programs and missions

  17. Influence of Non-safety Important Component on Maintenance Rule

    International Nuclear Information System (INIS)

    Ju, Tae Young; Kim, Wang Bae

    2016-01-01

    The Maintenance Rule (MR) programs in KHNP have been implemented since Jan 2009. KHNP is currently developing MR program for new built plant which has been constructed from December 2011. It is required to utilize plant-specific probabilistic safety analysis (PSA) result as risk significant criteria to determine which components are significantly important to safety. The criteria consist of three PSA risk values which are risk reduction worth (RRW), risk achievement worth (RAW) and core damage frequency (CDF) contribution. Most safety related components are classified as high risk significant, and non-safety related components as low safety significant in MR program. This paper presents the influence of the non-safety related component which has high PSA risk value on MR program of new built plant. It is considered that safety related system has at least one or more safety functions and some non-safety functions, but non-safety system doesn't have any safety function. The safety functions are defined as three functions which are required to maintain 1) integrity of reactor coolant pressure boundary, 2) capability to shut-down the reactor and maintain it in a safe shutdown, and 3) capability to prevent or mitigate the accident that could result in potential offsite exposure. The Maintenance Rule program is developed based on PSA result. Safety functions have high risk value in PSA program and considered HSS function in MR program. On the contrary, non-safety functions are generally has low risk value in PSA program and they are determined as LSS function in MR program. The AAC DG and its supporting systems are designed as non-safety systems which mean they don't have any safety function. But, AAC DG is treated as an important measure to mitigate accident in PSA program. It is determined as HSS function in MR program because it has high risk value in PSA program. AAC DG supporting systems does not have high risk value in operating plant's PSA program

  18. CCF analysis of high redundancy systems safety/relief valve data analysis and reference BWR application

    International Nuclear Information System (INIS)

    Mankamo, T.; Bjoere, S.; Olsson, Lena

    1992-12-01

    Dependent failure analysis and modeling were developed for high redundancy systems. The study included a comprehensive data analysis of safety and relief valves at the Finnish and Swedish BWR plants, resulting in improved understanding of Common Cause Failure mechanisms in these components. The reference application on the Forsmark 1/2 reactor relief system, constituting of twelve safety/relief lines and two regulating relief lines, covered different safety criteria cases of reactor depressurization and overpressure protection function, and failure to re close sequences. For the quantification of dependencies, the Alpha Factor Model, the Binomial Probability Model and the Common Load Model were compared for applicability in high redundancy systems

  19. Demonstration Advanced Avionics System (DAAS) function description

    Science.gov (United States)

    Bailey, A. J.; Bailey, D. G.; Gaabo, R. J.; Lahn, T. G.; Larson, J. C.; Peterson, E. M.; Schuck, J. W.; Rodgers, D. L.; Wroblewski, K. A.

    1982-01-01

    The Demonstration Advanced Avionics System, DAAS, is an integrated avionics system utilizing microprocessor technologies, data busing, and shared displays for demonstrating the potential of these technologies in improving the safety and utility of general aviation operations in the late 1980's and beyond. Major hardware elements of the DAAS include a functionally distributed microcomputer complex, an integrated data control center, an electronic horizontal situation indicator, and a radio adaptor unit. All processing and display resources are interconnected by an IEEE-488 bus in order to enhance the overall system effectiveness, reliability, modularity and maintainability. A detail description of the DAAS architecture, the DAAS hardware, and the DAAS functions is presented. The system is designed for installation and flight test in a NASA Cessna 402-B aircraft.

  20. The safety interlocking system at the NAC

    International Nuclear Information System (INIS)

    Visser, K.; Mostert, H.

    1984-01-01

    The central safety interlocking system (CSIS) controls the higher level of interlocking between the various cyclotron subsystems. It ensures the safe operation of the entire cyclotron facility as regards personnel safety and proper instrument operation. The system consists of a micro-processor with a ROM-based safety interlocking program, relay output modules providing ''safety OK'' instructions to all interlocked apparatus, alarm input modules connected to transducers providing binary alarm status signals and an interface to the central control computer. All solid state electronic components of the system are situated in a low level radiation area and are interfaced to cyclotron equipment by means of 24 V relays

  1. Safety Verification for Probabilistic Hybrid Systems

    DEFF Research Database (Denmark)

    Zhang, Lijun; She, Zhikun; Ratschan, Stefan

    2010-01-01

    The interplay of random phenomena and continuous real-time control deserves increased attention for instance in wireless sensing and control applications. Safety verification for such systems thus needs to consider probabilistic variations of systems with hybrid dynamics. In safety verification o...... on a number of case studies, tackled using a prototypical implementation....

  2. Operating experience and systems analysis at Trillo NPP: A program intended for systematic review of plant safety systems to assess design basis requirements compliance

    International Nuclear Information System (INIS)

    Vega, R. de la

    1996-01-01

    The program was defined to apply to all plant safety systems and/or systems included in plant Technical Specifications. The goal of the program was to ensure, by systematic design, construction, and commissioning review, the adequacy of safety systems, structures and components to fulfill their safety functions. Also, as a result of the program, it was established that a complete, unambiguous, systematic, design basis definition shall take place. And finally, a complete documental review of the plant design shall result from the program execution

  3. A management system integrating radiation protection and safety supporting safety culture in the hospital

    International Nuclear Information System (INIS)

    Almen, A.; Lundh, C.

    2015-01-01

    Quality assurance has been identified as an important part of radiation protection and safety for a considerable time period. A rational expansion and improvement of quality assurance is to integrate radiation protection and safety in a management system. The aim of this study was to explore factors influencing the implementing strategy when introducing a management system including radiation protection and safety in hospitals and to outline benefits of such a system. The main experience from developing a management system is that it is possible to create a vast number of common policies and routines for the whole hospital, resulting in a cost-efficient system. One of the key benefits is the involvement of management at all levels, including the hospital director. Furthermore, a transparent system will involve staff throughout the organisation as well. A management system supports a common view on what should be done, who should do it and how the activities are reviewed. An integrated management system for radiation protection and safety includes key elements supporting a safety culture. (authors)

  4. Nuclear safety and regulation

    International Nuclear Information System (INIS)

    Kim, Hho Jung

    2000-03-01

    This book contains 12 chapters, which are atom and radiation, nuclear reactor and kinds of nuclear power plant, safeguard actuation system and stability evaluation for rock foundation of nuclear power plant, nuclear safety and principle, safety analysis and classification of incident, probabilistic safety assessment and major incident, nuclear safety regulation, system of nuclear safety regulation, main function and subject of safety regulation in nuclear facilities, regulation of fuel cycle and a nuclear dump site, protection of radiation and, safety supervision and, safety supervision and measurement of environmental radioactivity.

  5. Risk and Work Configuration Management as a Function of Integrated Safety Management

    International Nuclear Information System (INIS)

    Lana Buehrer; Michele Kelly; Fran Lemieux; Fred Williams

    2007-01-01

    National Security Technologies, LLC (NSTec), has established a work management program and corresponding electronic Facilities and Operations Management Information System (e-FOM) to implement Integrated Safety Management (ISM). The management of work scopes, the identification of hazards, and the establishment of implementing controls are reviewed and approved through electronic signatures. Through the execution of the program and the implementation of the electronic system, NSTec staff work within controls and utilize feedback and improvement process. The Integrated Work Control Manual further implements the five functions of ISM at the Activity level. By adding the Risk and Work Configuration Management program, NSTec establishes risk acceptance (business and physical) for liabilities within the performance direction and work management processes. Requirements, roles, and responsibilities are specifically identified in the program while e-FOM provides the interface and establishes the flowdown from the Safety Chain to work and facilities management processes to company work-related directives, and finally to Subject Matter Expert concurrence. The Program establishes, within the defined management structure, management levels for risk identification, risk mitigation (controls), and risk acceptance (business and physical) within the Safety Chain of Responsibility. The Program also implements Integrated Safeguards and Security Management within the NSTec Safety Chain of Responsibility. Once all information has been entered into e-FOM, approved, and captured as data, the information becomes searchable and sortable by hazard, location, organization, mitigating controls, etc

  6. The achievement and assessment of safety in systems containing software

    International Nuclear Information System (INIS)

    Ball, A.; Dale, C.J.; Butterfield, M.H.

    1986-01-01

    In order to establish confidence in the safe operation of a reactor protection system, there is a need to establish, as far as it is possible, that: (i) the algorithms used are correct; (ii) the system is a correct implementation of the algorithms; and (iii) the hardware is sufficiently reliable. This paper concentrates principally on the second of these, as it applies to the software aspect of the more accurate and complex trip functions to be performed by modern reactor protection systems. In order to engineer safety into software, there is a need to use a development strategy which will stand a high chance of achieving a correct implementation of the trip algorithms. This paper describes three broad methodologies by which it is possible to enhance the integrity of software: fault avoidance, fault tolerance and fault removal. Fault avoidance is concerned with making the software as fault free as possible by appropriate choice of specification, design and implementation methods. A fault tolerant strategy may be advisable in many safety critical applications, in order to guard against residual faults present in the software of the installed system. Fault detection and removal techniques are used to remove as many faults as possible of those introduced during software development. The paper also discusses safety and reliability assessment as it applies to software, outlining the various approaches available. Finally, there is an outline of a research project underway in the UKAEA which is intended to assess methods for developing and testing safety and protection systems involving software. (author)

  7. Safety philosophy in upgrading the EBR-II plant protection system

    International Nuclear Information System (INIS)

    Sackett, J.I.

    1976-01-01

    The EBR-II plant protection system (PPS) has been substantially modified, upgrading its performance to more fully comply with modern safety philosophy and criteria. The upgrading effort required that the total reactor system be evaluated for possible faults and that a PPS be designed to accommodate them. The result was deletion of a number of existing trip functions and upgrading of others. Particular attention was given to loss of primary pumping power and reactivity insertion events. The design and performance criteria for the PPS has been more firmly established, understanding of the PPS function has been improved and the reactor has been subjected to fewer spurious trips, improving operational reliability

  8. CERN safety system monitoring - SSM

    International Nuclear Information System (INIS)

    Hakulinen, T.; Ninin, P.; Valentini, F.; Gonzalez, J.; Salatko-Petryszcze, C.

    2012-01-01

    CERN SSM (Safety System Monitoring) is a system for monitoring state-of-health of the various access and safety systems of the CERN site and accelerator infrastructure. The emphasis of SSM is on the needs of maintenance and system operation with the aim of providing an independent and reliable verification path of the basic operational parameters of each system. Included are all network-connected devices, such as PLCs (local purpose control unit), servers, panel displays, operator posts, etc. The basic monitoring engine of SSM is a freely available system-monitoring framework Zabbix, on top of which a simplified traffic-light-type web-interface has been built. The web-interface of SSM is designed to be ultra-light to facilitate access from hand-held devices over slow connections. The underlying Zabbix system offers history and notification mechanisms typical of advanced monitoring systems. (authors)

  9. Vault Safety and Inventory System users manual, PRIME 2350. Revision 1

    International Nuclear Information System (INIS)

    Downey, N.J.

    1994-01-01

    This revision is issued to request review of the attached document: VSIS User Manual, PRIME 2350, which provides user information for the operation of the VSIS (Vault Safety and Inventory System). It describes operational aspects of Prime 2350 minicomputer and vault data acquisition equipment. It also describes the User's Main Menu and menu functions, including REPORTS. Also, system procedures for the Prime 2350 minicomputer are covered

  10. Vault Safety and Inventory System users manual, PRIME 2350. Revision 1

    Energy Technology Data Exchange (ETDEWEB)

    Downey, N.J.

    1994-12-14

    This revision is issued to request review of the attached document: VSIS User Manual, PRIME 2350, which provides user information for the operation of the VSIS (Vault Safety and Inventory System). It describes operational aspects of Prime 2350 minicomputer and vault data acquisition equipment. It also describes the User`s Main Menu and menu functions, including REPORTS. Also, system procedures for the Prime 2350 minicomputer are covered.

  11. The advantages of reliability centered maintenance for standby safety systems

    International Nuclear Information System (INIS)

    Dam, R.F.; Ayazzudin, S.; Nickerson, J.H.; DeLong, A.I.

    2002-01-01

    Full text: On standby safety systems, nuclear plants have to balance the requirements of demonstrating the reliability of each system, while maintaining the system and plant availability. With the goal of demonstrating statistical reliability, these systems have extensive testing programs, which often makes the system unavailable and this can impact the plant capacity. The inputs to the process are often safety and regulatory related, resulting in programs that provide a high level of scrutiny on the systems being considered. In such cases, the value of the application of a maintenance optimization strategy, such as Reliability Centered Maintenance (RCM), is questioned. Part of the question stems from the use of the word 'Reliability' in RCM, which implies a level of redundancy when applied to a system maintenance program driven by reliability requirements. A deeper look at the RCM process, however, shows that RCM has the goal of ensuring that the system operates 'reliably' through the application of an integrated maintenance strategy. This is a subtle, but important distinction. Although the system reliability requirements are an important part of the strategy evaluation, RCM provides a broader context where testing is only one part of an overall strategy focused on ensuring that component function is maintained through a combination of monitoring technologies (including testing), predictive techniques, and intrusive maintenance strategies. Each strategy is targeted to identify known component degradation mechanisms. The conclusion is that a maintenance program driven by reliability requirements will tend to have testing defined at a frequency intended to support the needed statistics. The testing demonstrates that the desired function is available today. Maintenance driven by functional requirements and known failure causes, as developed through an RCM assessment, will have frequencies tied to industry experience with components and rely on a higher degree of

  12. Computer-based systems important to safety (COMPSIS) - Reporting guidelines

    International Nuclear Information System (INIS)

    1999-07-01

    The objective of this procedure is to help the user to prepare an COMPSIS report on an event so that important lessons learned are most efficiently transferred to the database. This procedure focuses on the content of the information to be provided in the report rather than on its format. The established procedure follows to large extend the procedure chosen by the IRS incident reporting system. However this database is built for I and C equipment with the purpose of the event report database to collect and disseminate information on events of significance involving Computer-Based Systems important to safety in nuclear power plants, and feedback conclusions and lessons learnt from such events. For events where human performance is dominant to draw lessons, more detailed guidance on the specific information that should be supplied is spelled out in the present procedure. This guidance differs somewhat from that for the provision of technical information, and takes into account that the engineering world is usually less familiar with human behavioural analysis than with technical analysis. The events to be reported to the COMPSIS database should be based on the national reporting criteria in the participating member countries. The aim is that all reports including computer based systems that meet each country reporting criteria should be reported. The database should give a broad picture of events/incidents occurring in operation with computer control systems. As soon as an event has been identified, the insights and lessons learnt to be conveyed to the international nuclear community shall be clearly identified. On the basis of the description of the event, the event shall be analyzed in detail under the aspect of direct and potential impact to plant safety functions. The first part should show the common involvement of operation and safety systems and the second part should show the special aspects of I and C functions, hardware and software

  13. Systems engineered health and safety criteria for safety analysis reports

    International Nuclear Information System (INIS)

    Beitel, G.A.; Morcos, N.

    1993-01-01

    The world of safety analysis is filled with ambiguous words: codes and standards, consequences and risks, hazard and accident, and health and safety. These words have been subject to disparate interpretations by safety analysis report (SAR) writers, readers, and users. open-quotes Principal health and safety criteriaclose quotes has been one of the most frequently misused phrases; rarely is it used consistently or effectively. This paper offers an easily understood definition for open-quotes principal health and safety criteriaclose quotes and uses systems engineering to convert an otherwise mysterious topic into the primary means of producing an integrated SAR. This paper is based on SARs being written for environmental restoration and waste management activities for the U.S. Department of Energy (DOE). Requirements for these SARs are prescribed in DOE Order 5480-23, open-quotes Nuclear Safety Analysis Reports.close quotes

  14. LOFT integral test system final safety analysis report

    International Nuclear Information System (INIS)

    1974-03-01

    Safety analyses are presented for the following LOFT Reactor systems: engineering safety features; support buildings and facilities; instrumentation and controls; electrical systems; and auxiliary systems. (JWR)

  15. The function of specialized organization in work safety engineering for nuclear installations

    International Nuclear Information System (INIS)

    Salvatore, J.E.L.

    1989-01-01

    The attributions of Brazilian CNEN in the licensing procedures of any nuclear installation are discussed. It is shown that the work safety engineering and industrial safety constitute important functions for nuclear safety. (M.C.K.) [pt

  16. An efficient method for evaluating the effect of input parameters on the integrity of safety systems

    International Nuclear Information System (INIS)

    Tang, Zhang-Chun; Zuo, Ming J.; Xiao, Ningcong

    2016-01-01

    Safety systems are significant to reduce or prevent risk from potentially dangerous activities in industry. Probability of failure to perform its functions on demand (PFD) for safety system usually exhibits variation due to the epistemic uncertainty associated with various input parameters. This paper uses the complementary cumulative distribution function of the PFD to define the exceedance probability (EP) that the PFD of the system is larger than the designed value. Sensitivity analysis of safety system is further investigated, which focuses on the effect of the variance of an individual input parameter on the EP resulting from epistemic uncertainty associated with the input parameters. An available numerical technique called finite difference method is first employed to evaluate the effect, which requires extensive computational cost and needs to select a step size. To address these difficulties, this paper proposes an efficient simulation method to estimate the effect. The proposed method needs only an evaluation to estimate the effects corresponding to all input parameters. Two examples are used to demonstrate that the proposed method can obtain more accurate results with less computation time compared to reported methods. - Highlights: • We define a sensitivity index to measure effect of a parameter for safety system. • We analyze the physical meaning of the sensitivity index. • We propose an efficient simulation method to assess the sensitivity index. • We derive the formulations of this index for lognormal and beta distributions. • Results identify important parameters on exceedance probability of safety system.

  17. Five-year safety and performance results from the Argus II Retinal Prosthesis System clinical trial

    Science.gov (United States)

    da Cruz, Lyndon; Dorn, Jessy D.; Humayun, Mark S.; Dagnelie, Gislin; Handa, James; Barale, Pierre-Olivier; Sahel, José-Alain; Stanga, Paulo E.; Hafezi, Farhad; Safran, Avinoam B.; Salzmann, Joel; Santos, Arturo; Birch, David; Spencer, Rand; Cideciyan, Artur V.; de Juan, Eugene; Duncan, Jacque L.; Eliott, Dean; Fawzi, Amani; Olmos de Koo, Lisa C.; Ho, Allen C.; Brown, Gary; Haller, Julia; Regillo, Carl; Del Priore, Lucian V.; Arditi, Aries; Greenberg, Robert J.

    2016-01-01

    Purpose The Argus® II Retinal Prosthesis System (Second Sight Medical Products, Inc., Sylmar, CA) was developed to restore some vision to patients blind from retinitis pigmentosa (RP) or outer retinal degeneration. A clinical trial was initiated in 2006 to study the long-term safety and efficacy of the Argus II System in patients with bare or no light perception due to end-stage RP. Design The study is a prospective, multicenter, single-arm, clinical trial. Within-patient controls included the non-implanted fellow eye and patients' native residual vision compared to their vision when using the System. Subjects There were 30 subjects in 10 centers in the U.S. and Europe. Methods The worse-seeing eye of blind patients was implanted with the Argus II System. Patients wore glasses mounted with a small camera and a video processor that converted images into stimulation patterns sent to the electrode array on the retina. Main Outcome Measures The primary outcome measures were safety (the number, seriousness, and relatedness of adverse events) and visual function, as measured by three computer-based, objective tests. Secondary measures included functional vision performance on objectively-scored real-world tasks. Results Twenty-four out of 30 patients remained implanted with functioning Argus II Systems at 5 years post-implant. Only one additional serious adverse event was experienced since the 3-year time point. Patients performed significantly better with the System ON than OFF on all visual function tests and functional vision tasks. Conclusions The five-year results of the Argus II trial support the long-term safety profile and benefit of the Argus II System for patients blind from RP. The Argus II is the first and only retinal implant to have market approval in the European Economic Area, the United States, and Canada. PMID:27453256

  18. Preliminary assessment of a combined passive safety system for typical 3-loop PWR CPR1000

    Energy Technology Data Exchange (ETDEWEB)

    Yang, Zijiang; Shan, Jianqiang, E-mail: jqshan@mail.xjtu.edu.cn; Gou, Junli

    2017-03-15

    Highlights: • A combined passive safety system was placed on a typical 3-loop PWR CPR1000. • Three accident analyses show the three different accident mitigation methods of the passive safety system. • The three mitigation methods were proved to be useful. - Abstract: As the development of the nuclear industry, passive technology turns out to be a remarkable characteristic of advanced nuclear power plants. Since the 20th century, much effort has been given to the passive technology, and a number of evolutionary passive systems have developed. Thoughts have been given to upgrade the existing reactors with passive systems to meet stricter safety demands. In this paper, the CPR1000 plant, which is one kind of mature pressurized water reactor plants in China, is improved with some passive systems to enhance safety. The passive systems selected are as follows: (1) the reactor makeup tank (RMT); (2) the advanced accumulator (A-ACC); (3) the in-containment refueling water storage tank (IRWST); (4) the passive emergency feed water system (PEFS), which is installed on the secondary side of SGs; (5) the passive depressurization system (PDS). Although these passive components is based on the passive technology of some advanced reactors, their structural and trip designs are adjusted specifically so that it could be able to mitigate accidents of the CPR1000. Utilizing the RELAP5/MOD3.3 code, accident analyses (small break loss of coolant accident, large break loss of coolant accident, main feed water line break accident) of this improved CPR1000 plant were presented to demonstrate three different accident mitigation methods of the safety system and to test whether the passive safety system preformed its function well. In the SBLOCA, all components of the passive safety system were put into work sequentially, which prevented the core uncover. The LBLOCA analysis illustrates the contribution of the A-ACCs whose small-flow-rate injection can control the maximum cladding

  19. Interdisciplinary safety analysis of complex socio-technological systems based on the functional resonance accident model: An application to railway trafficsupervision

    International Nuclear Information System (INIS)

    Belmonte, Fabien; Schoen, Walter; Heurley, Laurent; Capel, Robert

    2011-01-01

    This paper presents an application of functional resonance accident models (FRAM) for the safety analysis of complex socio-technological systems, i.e. systems which include not only technological, but also human and organizational components. The supervision of certain industrial domains provides a good example of such systems, because although more and more actions for piloting installations are now automatized, there always remains a decision level (at least in the management of degraded modes) involving human behavior and organizations. The field of application of the study presented here is railway traffic supervision, using modern automatic train supervision (ATS) systems. Examples taken from railway traffic supervision illustrate the principal advantage of FRAM in comparison to classical safety analysis models, i.e. their ability to take into account technical as well as human and organizational aspects within a single model, thus allowing a true multidisciplinary cooperation between specialists from the different domains involved. A FRAM analysis is used to interpret experimental results obtained from a real ATS system linked to a railway simulator that places operators (experimental subjects) in simulated situations involving incidents. The first results show a significant dispersion in performances among different operators when detecting incidents. Some subsequent work in progress aims to make these 'performance conditions' more homogeneous, mainly by ergonomic modifications. It is clear that the current human-machine interface (HMI) in ATS systems (a legacy of past technologies that used LED displays) has reached its limits and needs to be improved, for example, by highlighting the most pertinent information for a given situation (and, conversely, by removing irrelevant information likely to distract operators).

  20. Interdisciplinary safety analysis of complex socio-technological systems based on the functional resonance accident model: An application to railway trafficsupervision

    Energy Technology Data Exchange (ETDEWEB)

    Belmonte, Fabien, E-mail: fabien.belmonte@transport.alstom.co [Alstom Transport, 48 rue Albert Dhalenne, 93482 Saint-Ouen cedex (France); Schoen, Walter [Universite de Technologie de Compiegne, Laboratoire Heudiasyc, Centre de Recherches de Royallieu, BP20529, 60205 Compiegne cedex (France); Heurley, Laurent [Universite de Picardie Jules Verne, Equipe Cognition, Langage, Emotion et Acquisition (CLEA), EA 4296, UFR de Philosophie, Sciences Humaines et Sociales, Chemin du Thil, 80025 Amiens, Cedex 1 (France); Capel, Robert [Alstom Transport, 48 rue Albert Dhalenne, 93482 Saint-Ouen cedex (France)

    2011-02-15

    This paper presents an application of functional resonance accident models (FRAM) for the safety analysis of complex socio-technological systems, i.e. systems which include not only technological, but also human and organizational components. The supervision of certain industrial domains provides a good example of such systems, because although more and more actions for piloting installations are now automatized, there always remains a decision level (at least in the management of degraded modes) involving human behavior and organizations. The field of application of the study presented here is railway traffic supervision, using modern automatic train supervision (ATS) systems. Examples taken from railway traffic supervision illustrate the principal advantage of FRAM in comparison to classical safety analysis models, i.e. their ability to take into account technical as well as human and organizational aspects within a single model, thus allowing a true multidisciplinary cooperation between specialists from the different domains involved. A FRAM analysis is used to interpret experimental results obtained from a real ATS system linked to a railway simulator that places operators (experimental subjects) in simulated situations involving incidents. The first results show a significant dispersion in performances among different operators when detecting incidents. Some subsequent work in progress aims to make these 'performance conditions' more homogeneous, mainly by ergonomic modifications. It is clear that the current human-machine interface (HMI) in ATS systems (a legacy of past technologies that used LED displays) has reached its limits and needs to be improved, for example, by highlighting the most pertinent information for a given situation (and, conversely, by removing irrelevant information likely to distract operators).

  1. Data concentrator requirements for a safety parameter display system

    International Nuclear Information System (INIS)

    Brewer, C.R.

    1983-01-01

    To comply with NUREG 0696 several nuclear plants are being fitted with new facilities and data systems; specifically a Technical Support Center (TSC), Operational Support Center (OSC), Emergency Operational Facility (EOF), and Backup Safety Parameter Display System (SPDS), Emergency Response Computer System (ERCS) and Nuclear Data Link (NDL). The TSC, OSC, and EOF are physical locations while the SPDS, ERCS, and NDL are Systems. The SPDS and ERCS are usually separate and independent systems, however, they may share a common front end data acquisition system that acquires and sends SPDS related data to both the SPDS and to the ERCS. In the situation just described an SPDS system must depend upon input data from a source that is SPDS host computer independent. To achieve this independence the front end data acquisition system may employ a concept of intelligent distributed processing. This concept essentially takes functional capabilities that were once found only in realtime host computers and distributes it to front end data acquisition systems. Thus by expanding the functionality of the data acquisition system in a manner that provides more capability, independence from the computer vendor, links to multiple computer systems, processing power and redundancy, the concept of a data concentrator evolved. This paper will define this new distributed functionality, and its related requirements. It will also examine different system configuration approaches

  2. Time Based Workload Analysis Method for Safety-Related Operator Actions in Safety Analysis

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Yun Goo; Oh, Eung Se [Korea Hydro and Nuclear Power Co., Daejeon (Korea, Republic of)

    2016-05-15

    During the design basis event, the safety system performs safety functions to mitigate the event. The most of safety system is actuated by automatic system however, there are operator manual actions that are needed for the plant safety. These operator actions are classified as important human actions in human factors engineering design. The human factors engineering analysis and evaluation is needed for these important human actions to assure that operator successfully perform their tasks for plant safety and operational goals. The work load analysis is one of the required analysis for the important human actions.

  3. Time Based Workload Analysis Method for Safety-Related Operator Actions in Safety Analysis

    International Nuclear Information System (INIS)

    Kim, Yun Goo; Oh, Eung Se

    2016-01-01

    During the design basis event, the safety system performs safety functions to mitigate the event. The most of safety system is actuated by automatic system however, there are operator manual actions that are needed for the plant safety. These operator actions are classified as important human actions in human factors engineering design. The human factors engineering analysis and evaluation is needed for these important human actions to assure that operator successfully perform their tasks for plant safety and operational goals. The work load analysis is one of the required analysis for the important human actions.

  4. The Research on Safety Management Information System of Railway Passenger Based on Risk Management Theory

    Science.gov (United States)

    Zhu, Wenmin; Jia, Yuanhua

    2018-01-01

    Based on the risk management theory and the PDCA cycle model, requirements of the railway passenger transport safety production is analyzed, and the establishment of the security risk assessment team is proposed to manage risk by FTA with Delphi from both qualitative and quantitative aspects. The safety production committee is also established to accomplish performance appraisal, which is for further ensuring the correctness of risk management results, optimizing the safety management business processes and improving risk management capabilities. The basic framework and risk information database of risk management information system of railway passenger transport safety are designed by Ajax, Web Services and SQL technologies. The system realizes functions about risk management, performance appraisal and data management, and provides an efficient and convenient information management platform for railway passenger safety manager.

  5. Analysis of Aviation Safety Reporting System Incident Data Associated with the Technical Challenges of the System-Wide Safety and Assurance Technologies Project

    Science.gov (United States)

    Withrow, Colleen A.; Reveley, Mary S.

    2015-01-01

    The Aviation Safety Program (AvSP) System-Wide Safety and Assurance Technologies (SSAT) Project asked the AvSP Systems and Portfolio Analysis Team to identify SSAT-related trends. SSAT had four technical challenges: advance safety assurance to enable deployment of NextGen systems; automated discovery of precursors to aviation safety incidents; increasing safety of human-automation interaction by incorporating human performance, and prognostic algorithm design for safety assurance. This report reviews incident data from the NASA Aviation Safety Reporting System (ASRS) for system-component-failure- or-malfunction- (SCFM-) related and human-factor-related incidents for commercial or cargo air carriers (Part 121), commuter airlines (Part 135), and general aviation (Part 91). The data was analyzed by Federal Aviation Regulations (FAR) part, phase of flight, SCFM category, human factor category, and a variety of anomalies and results. There were 38 894 SCFM-related incidents and 83 478 human-factorrelated incidents analyzed between January 1993 and April 2011.

  6. Soft systems methodology as a systemic approach to nuclear safety management

    International Nuclear Information System (INIS)

    Vieira Neto, Antonio S.; Guilhen, Sabine N.; Rubin, Gerson A.; Caldeira Filho, Jose S.; Camargo, Iara M.C.

    2017-01-01

    Safety approach currently adopted by nuclear installations is built almost exclusively upon analytical methodologies based, mainly, on the belief that the properties of a system, such as its safety, are given by its constituent parts. This approach, however, does not properly address the complex dynamic interactions between technical, human and organizational factors occurring within and outside the organization. After the accident at Fukushima Daiichi nuclear power plant in March 2011, experts of the International Atomic Energy Agency (IAEA) recommended a systemic approach as a complementary perspective to nuclear safety. The aim of this paper is to present an overview of the systems thinking approach and its potential use for structuring socio technical problems involved in the safety of nuclear installations, highlighting the methodologies related to the soft systems thinking, in particular the Soft Systems Methodology (SSM). The implementation of a systemic approach may thus result in a more holistic picture of the system by the complex dynamic interactions between technical, human and organizational factors. (author)

  7. Soft systems methodology as a systemic approach to nuclear safety management

    Energy Technology Data Exchange (ETDEWEB)

    Vieira Neto, Antonio S.; Guilhen, Sabine N.; Rubin, Gerson A.; Caldeira Filho, Jose S.; Camargo, Iara M.C., E-mail: asvneto@ipen.br, E-mail: snguilhen@ipen.br, E-mail: garubin@ipen.br, E-mail: jscaldeira@ipen.br, E-mail: icamargo@ipen.br [Instituto de Pesquisas Energeticas e Nucleares (IPEN/CNE-SP), Sao Paulo, SP (Brazil)

    2017-07-01

    Safety approach currently adopted by nuclear installations is built almost exclusively upon analytical methodologies based, mainly, on the belief that the properties of a system, such as its safety, are given by its constituent parts. This approach, however, does not properly address the complex dynamic interactions between technical, human and organizational factors occurring within and outside the organization. After the accident at Fukushima Daiichi nuclear power plant in March 2011, experts of the International Atomic Energy Agency (IAEA) recommended a systemic approach as a complementary perspective to nuclear safety. The aim of this paper is to present an overview of the systems thinking approach and its potential use for structuring socio technical problems involved in the safety of nuclear installations, highlighting the methodologies related to the soft systems thinking, in particular the Soft Systems Methodology (SSM). The implementation of a systemic approach may thus result in a more holistic picture of the system by the complex dynamic interactions between technical, human and organizational factors. (author)

  8. A preliminary study on the design in architecture of nuclear and radiation safety standard system

    International Nuclear Information System (INIS)

    Song Dahu; Zhang Chi; Yang Lili; Li Bin; Liu Yingwei; An Hongzhen; Gao Siyi; Liu Ting; Meng De

    2014-01-01

    The connotation and function of nuclear and radiation safety standards are analyzed, and their relationships with the relevant laws and regulations are discussed in the paper. Some suggestions and blue print of overall architecture to build nuclear and radiation safety standard system are proposed, on the basis of researching the application status quo, existing problems and needs for nuclear and radiation safety standards in China. This work is a beneficial exploration and attempt to establish China's nuclear and radiation safety standards. (authors)

  9. Spallation Neutron Source Accelerator Facility Target Safety and Non-safety Control Systems

    International Nuclear Information System (INIS)

    Battle, Ronald E.; DeVan, B.; Munro, John K. Jr.

    2006-01-01

    The Spallation Neutron Source (SNS) is a proton accelerator facility that generates neutrons for scientific researchers by spallation of neutrons from a mercury target. The SNS became operational on April 28, 2006, with first beam on target at approximately 200 W. The SNS accelerator, target, and conventional facilities controls are integrated by standardized hardware and software throughout the facility and were designed and fabricated to SNS conventions to ensure compatibility of systems with Experimental Physics Integrated Control System (EPICS). ControlLogix Programmable Logic Controllers (PLCs) interface to instruments and actuators, and EPICS performs the high-level integration of the PLCs such that all operator control can be accomplished from the Central Control room using EPICS graphical screens that pass process variables to and from the PLCs. Three active safety systems were designed to industry standards ISA S84.01 and IEEE 603 to meet the desired reliability for these safety systems. The safety systems protect facility workers and the environment from mercury vapor, mercury radiation, and proton beam radiation. The facility operators operated many of the systems prior to beam on target and developed the operating procedures. The safety and non-safety control systems were tested extensively prior to beam on target. This testing was crucial to identify wiring and software errors and failed components, the result of which was few problems during operation with beam on target. The SNS has continued beam on target since April to increase beam power, check out the scientific instruments, and continue testing the operation of facility subsystems

  10. Understanding Nuclear Safety Culture: A Systemic Approach

    International Nuclear Information System (INIS)

    Afghan, A.N.

    2016-01-01

    The Fukushima accident was a systemic failure (Report by Director General IAEA on the Fukushima Daiichi Accident). Systemic failure is a failure at system level unlike the currently understood notion which regards it as the failure of component and equipment. Systemic failures are due to the interdependence, complexity and unpredictability within systems and that is why these systems are called complex adaptive systems (CAS), in which “attractors” play an important role. If we want to understand the systemic failures we need to understand CAS and the role of these attractors. The intent of this paper is to identify some typical attractors (including stakeholders) and their role within complex adaptive system. Attractors can be stakeholders, individuals, processes, rules and regulations, SOPs etc., towards which other agents and individuals are attracted. This paper will try to identify attractors in nuclear safety culture and influence of their assumptions on safety culture behavior by taking examples from nuclear industry in Pakistan. For example, if the nuclear regulator is an attractor within nuclear safety culture CAS then how basic assumptions of nuclear plant operators and shift in-charges about “regulator” affect their own safety behavior?

  11. Development of a methodology for assessing the safety of embedded software systems

    Science.gov (United States)

    Garrett, C. J.; Guarro, S. B.; Apostolakis, G. E.

    1993-01-01

    A Dynamic Flowgraph Methodology (DFM) based on an integrated approach to modeling and analyzing the behavior of software-driven embedded systems for assessing and verifying reliability and safety is discussed. DFM is based on an extension of the Logic Flowgraph Methodology to incorporate state transition models. System models which express the logic of the system in terms of causal relationships between physical variables and temporal characteristics of software modules are analyzed to determine how a certain state can be reached. This is done by developing timed fault trees which take the form of logical combinations of static trees relating the system parameters at different point in time. The resulting information concerning the hardware and software states can be used to eliminate unsafe execution paths and identify testing criteria for safety critical software functions.

  12. Safety standards of IAEA for management systems

    International Nuclear Information System (INIS)

    Vincze, P.

    2005-01-01

    IAEA has developed a new series of safety standards which are assigned for constitution of the conditions and which give the instruction for setting up the management systems that integrate the aims of safety, health, life environment and quality. The new standard shall replace IAEA 50-C-Q - Requirements for security of the quality for safety in nuclear power plants and other nuclear facilities as well as 14 related safety instructions mentioned in the Safety series No. 50-C/SG-Q (1996). When developing of this complex, integrated set of requirements for management systems, the IAEA requirements 50-C-Q (1996) were taken into consideration as well as the publications developed within the International organisation for standardization (ISO) ISO 9001:2000 and ISO14001: 1996. The experience of European Union member states during the development, implementation and improvement of the management systems were also taken into consideration

  13. Model-based safety architecture framework for complex systems

    NARCIS (Netherlands)

    Schuitemaker, Katja; Rajabali Nejad, Mohammadreza; Braakhuis, J.G.; Podofillini, Luca; Sudret, Bruno; Stojadinovic, Bozidar; Zio, Enrico; Kröger, Wolfgang

    2015-01-01

    The shift to transparency and rising need of the general public for safety, together with the increasing complexity and interdisciplinarity of modern safety-critical Systems of Systems (SoS) have resulted in a Model-Based Safety Architecture Framework (MBSAF) for capturing and sharing architectural

  14. Is Model-Based Development a Favorable Approach for Complex and Safety-Critical Computer Systems on Commercial Aircraft?

    Science.gov (United States)

    Torres-Pomales, Wilfredo

    2014-01-01

    A system is safety-critical if its failure can endanger human life or cause significant damage to property or the environment. State-of-the-art computer systems on commercial aircraft are highly complex, software-intensive, functionally integrated, and network-centric systems of systems. Ensuring that such systems are safe and comply with existing safety regulations is costly and time-consuming as the level of rigor in the development process, especially the validation and verification activities, is determined by considerations of system complexity and safety criticality. A significant degree of care and deep insight into the operational principles of these systems is required to ensure adequate coverage of all design implications relevant to system safety. Model-based development methodologies, methods, tools, and techniques facilitate collaboration and enable the use of common design artifacts among groups dealing with different aspects of the development of a system. This paper examines the application of model-based development to complex and safety-critical aircraft computer systems. Benefits and detriments are identified and an overall assessment of the approach is given.

  15. ERC Safety and Hygiene Programs functional organization structure and mission statement

    International Nuclear Information System (INIS)

    Coleman, S.R.

    2000-01-01

    This document provides a description of the functions, structure, commitments, and goals of the Environmental Restoration Contractor Safety and Hygiene Program. The current structure of the ERC Safety and Hygiene organization is described herein

  16. A formal safety analysis for PLC software-based safety critical system using Z

    International Nuclear Information System (INIS)

    Koh, Jung Soo; Seong, Poong Hyun

    1997-01-01

    This paper describes a formal safety analysis technique which is demonstrated by performing empirical formal safety analysis with the case study of beamline hutch door Interlock system that is developed by using PLC (Programmable Logic Controller) systems at the Pohang Accelerator Laboratory. In order to perform formed safety analysis, we have built the Z formal specifications representation from user requirement written in ambiguous natural language and target PLC ladder logic, respectively. We have also studied the effective method to express typical PLC timer component by using specific Z formal notation which is supported by temporal history. We present a formal proof technique specifying and verifying that the hazardous states are not introduced into ladder logic in the PLC-based safety critical system

  17. The reliability of nuclear power plant safety systems

    International Nuclear Information System (INIS)

    Susnik, J.

    1978-01-01

    A criterion was established concerning the protection that nuclear power plant (NPP) safety systems should afford. An estimate of the necessary or adequate reliability of the total complex of safety systems was derived. The acceptable unreliability of auxiliary safety systems is given, provided the reliability built into the specific NPP safety systems (ECCS, Containment) is to be fully utilized. A criterion for the acceptable unreliability of safety (sub)systems which occur in minimum cut sets having three or more components of the analysed fault tree was proposed. A set of input MTBF or MTTF values which fulfil all the set criteria and attain the appropriate overall reliability was derived. The sensitivity of results to input reliability data values was estimated. Numerical reliability evaluations were evaluated by the programs POTI, KOMBI and particularly URSULA, the last being based on Vesely's kinetic fault tree theory. (author)

  18. Framework conditions and requirements to ensure the technical functional safety of reprocessed medical devices.

    Science.gov (United States)

    Kraft, Marc

    2008-09-03

    Testing and restoring technical-functional safety is an essential part of medical device reprocessing. Technical functional tests have to be carried out on the medical device in the course of the validation of reprocessing procedures. These ensure (in addition to the hygiene tests) that the reprocessing procedure is suitable for the medical device. Functional tests are, however, also a part of reprocessing procedures. As a stage in the reprocessing, they ensure for the individual medical device that no damage or other changes limit the performance. When determining which technical-functional tests are to be carried out, the current technological standard has to be taken into account in the form of product-specific and process-oriented norms. Product-specific norms primarily define safety-relevant requirements. The risk management method described in DIN EN ISO 14971 is the basis for recognising hazards; the likelihood of such hazards arising can be minimised through additional technical-functional tests, which may not yet have been standardised. Risk management is part of a quality management system, which must be bindingly certified for manufacturers and processors of critical medical devices with particularly high processing demands by a body accredited by the competent authority.

  19. Cyber Security Test Strategy for Non-safety Display System

    International Nuclear Information System (INIS)

    Son, Han Seong; Kim, Hee Eun

    2016-01-01

    Cyber security has been a big issue since the instrumentation and control (I and C) system of nuclear power plant (NPP) is digitalized. A cyber-attack on NPP should be dealt with seriously because it might cause not only economic loss but also the radioactive material release. Researches on the consequences of cyber-attack onto NPP from a safety point of view have been conducted. A previous study shows the risk effect brought by initiation of event and deterioration of mitigation function by cyber terror. Although this study made conservative assumptions and simplifications, it gives an insight on the effect of cyber-attack. Another study shows that the error on a non-safety display system could cause wrong actions of operators. According to this previous study, the failure of the operator action caused by a cyber-attack on a display system might threaten the safety of the NPP by limiting appropriate mitigation actions. This study suggests a test strategy focusing on the cyber-attack on the information and display system, which might cause the failure of operator. The test strategy can be suggested to evaluate and complement security measures. Identifying whether a cyber-attack on the information and display system can affect the mitigation actions of operator, the strategy to obtain test scenarios is suggested. The failure of mitigation scenario is identified first. Then, for the test target in the scenario, software failure modes are applied to identify realistic failure scenarios. Testing should be performed for those scenarios to confirm the integrity of data and to assure effectiveness of security measures

  20. Cyber Security Test Strategy for Non-safety Display System

    Energy Technology Data Exchange (ETDEWEB)

    Son, Han Seong [Joongbu University, Geumsan (Korea, Republic of); Kim, Hee Eun [KAIST, Daejeon (Korea, Republic of)

    2016-10-15

    Cyber security has been a big issue since the instrumentation and control (I and C) system of nuclear power plant (NPP) is digitalized. A cyber-attack on NPP should be dealt with seriously because it might cause not only economic loss but also the radioactive material release. Researches on the consequences of cyber-attack onto NPP from a safety point of view have been conducted. A previous study shows the risk effect brought by initiation of event and deterioration of mitigation function by cyber terror. Although this study made conservative assumptions and simplifications, it gives an insight on the effect of cyber-attack. Another study shows that the error on a non-safety display system could cause wrong actions of operators. According to this previous study, the failure of the operator action caused by a cyber-attack on a display system might threaten the safety of the NPP by limiting appropriate mitigation actions. This study suggests a test strategy focusing on the cyber-attack on the information and display system, which might cause the failure of operator. The test strategy can be suggested to evaluate and complement security measures. Identifying whether a cyber-attack on the information and display system can affect the mitigation actions of operator, the strategy to obtain test scenarios is suggested. The failure of mitigation scenario is identified first. Then, for the test target in the scenario, software failure modes are applied to identify realistic failure scenarios. Testing should be performed for those scenarios to confirm the integrity of data and to assure effectiveness of security measures.

  1. Dynamic modeling of the tradeoff between productivity and safety in critical engineering systems

    International Nuclear Information System (INIS)

    Cowing, Michelle M.; Elisabeth Pate-Cornell, M.; Glynn, Peter W.

    2004-01-01

    Short-term tradeoffs between productivity and safety often exist in the operation of critical facilities such as nuclear power plants, offshore oil platforms, or simply individual cars. For example, interruption of operations for maintenance on demand can decrease short-term productivity but may be needed to ensure safety. Operations are interrupted for several reasons: scheduled maintenance, maintenance on demand, response to warnings, subsystem failure, or a catastrophic accident. The choice of operational procedures (e.g. timing and extent of scheduled maintenance) generally affects the probabilities of both production interruptions and catastrophic failures. In this paper, we present and illustrate a dynamic probabilistic model designed to describe the long-term evolution of such a system through the different phases of operation, shutdown, and possibly accident. The model's parameters represent explicitly the effects of different components' performance on the system's safety and reliability through an engineering probabilistic risk assessment (PRA). In addition to PRA, a Markov model is used to track the evolution of the system and its components through different performance phases. The model parameters are then linked to different operations strategies, to allow computation of the effects of each management strategy on the system's long-term productivity and safety. Decision analysis is then used to support the management of the short-term trade-offs between productivity and safety in order to maximize long-term performance. The value function is that of plant managers, within the constraints set by local utility commissions and national (e.g. energy) agencies. This model is illustrated by the case of outages (planned and unplanned) in nuclear power plants to show how it can be used to guide policy decisions regarding outage frequency and plant lifetime, and more specifically, the choice of a reactor tripping policy as a function of the state of the

  2. Safety management systems and their role in achieving high standards of operational safety

    International Nuclear Information System (INIS)

    Coulston, D.J.; Baylis, C.C.

    2000-01-01

    Achieving high standards of operational safety requires a robust management framework that is visible to all personnel with responsibility for its implementation. The structure of the management framework must ensure that all processes used to manage safety interlink in a logical and coherent manner, that is, they form a management system that leads to continuous improvement in safety performance. This Paper describes BNFL's safety management system (SMS). The SMS has management processes grouped within 5 main elements: 1. Policy, 2. Organisation, 3. Planning and Implementation, 4. Measuring and Reviewing Performance, 5. Audit. These elements reflect the overall process of setting safety objective (from Policy), measuring success and reviewing the performance. Effective implementation of the SMS requires senior managers to demonstrate leadership through their commitment and accountability. However, the SMS as a whole reflects that every employee at every level within BNFL is responsible for safety of operations under their control. The SMS therefore promotes a proactive safety culture and safe operations. The system is formally documented in the Company's Environmental, Health and Safety (EHS) Manual. Within in BNFL Group, the Company structures enables the Manual to provide overall SMS guidance and co-ordination to its range of nuclear businesses. Each business develops the SMS to be appropriate at all levels of its organisation, but ensuring that each level is consistent with the higher level. The Paper concludes with a summary of BNFL's safety performance. (author)

  3. Safety of huge systems

    International Nuclear Information System (INIS)

    Kondo, Jiro.

    1995-01-01

    Recently accompanying the development of engineering technology, huge systems tend to be constructed. The disaster countermeasures of huge cities become large problems as the concentration of population into cities is conspicuous. To make the expected value of loss small, the knowledge of reliability engineering is applied. In reliability engineering, even if a part of structures fails, the safety as a whole system must be ensured, therefore, the design having margin is carried out. The degree of margin is called redundancy. However, such design concept makes the structure of a system complex, and as the structure is complex, the possibility of causing human errors becomes high. At the time of huge system design, the concept of fail-safe is effective, but simple design must be kept in mind. The accident in Mihama No. 2 plant of Kansai Electric Power Co. and the accident in Chernobyl nuclear power station, and the accident of Boeing B737 airliner and the fatigue breakdown are described. The importance of safety culture was emphasized as the method of preventing human errors. Man-system interface and management system are discussed. (K.I.)

  4. On the Safety of Machine Learning: Cyber-Physical Systems, Decision Sciences, and Data Products.

    Science.gov (United States)

    Varshney, Kush R; Alemzadeh, Homa

    2017-09-01

    Machine learning algorithms increasingly influence our decisions and interact with us in all parts of our daily lives. Therefore, just as we consider the safety of power plants, highways, and a variety of other engineered socio-technical systems, we must also take into account the safety of systems involving machine learning. Heretofore, the definition of safety has not been formalized in a machine learning context. In this article, we do so by defining machine learning safety in terms of risk, epistemic uncertainty, and the harm incurred by unwanted outcomes. We then use this definition to examine safety in all sorts of applications in cyber-physical systems, decision sciences, and data products. We find that the foundational principle of modern statistical machine learning, empirical risk minimization, is not always a sufficient objective. We discuss how four different categories of strategies for achieving safety in engineering, including inherently safe design, safety reserves, safe fail, and procedural safeguards can be mapped to a machine learning context. We then discuss example techniques that can be adopted in each category, such as considering interpretability and causality of predictive models, objective functions beyond expected prediction accuracy, human involvement for labeling difficult or rare examples, and user experience design of software and open data.

  5. System Safety in an IT Service Organization

    Science.gov (United States)

    Parsons, Mike; Scutt, Simon

    Within Logica UK, over 30 IT service projects are considered safetyrelated. These include operational IT services for airports, railway infrastructure asset management, nationwide radiation monitoring and hospital medical records services. A recent internal audit examined the processes and documents used to manage system safety on these services and made a series of recommendations for improvement. This paper looks at the changes and the challenges to introducing them, especially where the service is provided by multiple units supporting both safety and non-safety related services from multiple locations around the world. The recommendations include improvements to service agreements, improved process definitions, routine safety assessment of changes, enhanced call logging, improved staff competency and training, and increased safety awareness. Progress is reported as of today, together with a road map for implementation of the improvements to the service safety management system. A proposal for service assurance levels (SALs) is discussed as a way forward to cover the wide variety of services and associated safety risks.

  6. Discussion on the safety classification of nuclear safety mechanical equipment

    International Nuclear Information System (INIS)

    Shen Wei

    2010-01-01

    The purpose and definition of the equipment safety classification in nuclear plant are introduced. The differences of several safety classification criterions are compared, and the object of safety classification is determined. According to the regulation, the definition and category of the safety functions are represented. The safety classification method, safety classification process, safety class interface, and the requirement for the safety class mechanical equipment are explored. At last, the relation of the safety classification between the mechanical and electrical equipment is presented, and the relation of the safety classification between mechanical equipment and system is also presented. (author)

  7. Aviation Safety Reporting System: Process and Procedures

    Science.gov (United States)

    Connell, Linda J.

    1997-01-01

    The Aviation Safety Reporting System (ASRS) was established in 1976 under an agreement between the Federal Aviation Administration (FAA) and the National Aeronautics and Space Administration (NASA). This cooperative safety program invites pilots, air traffic controllers, flight attendants, maintenance personnel, and others to voluntarily report to NASA any aviation incident or safety hazard. The FAA provides most of the program funding. NASA administers the program, sets its policies in consultation with the FAA and aviation community, and receives the reports submitted to the program. The FAA offers those who use the ASRS program two important reporting guarantees: confidentiality and limited immunity. Reports sent to ASRS are held in strict confidence. More than 350,000 reports have been submitted since the program's beginning without a single reporter's identity being revealed. ASRS removes all personal names and other potentially identifying information before entering reports into its database. This system is a very successful, proof-of-concept for gathering safety data in order to provide timely information about safety issues. The ASRS information is crucial to aviation safety efforts both nationally and internationally. It can be utilized as the first step in safety by providing the direction and content to informed policies, procedures, and research, especially human factors. The ASRS process and procedures will be presented as one model of safety reporting feedback systems.

  8. Developing and maintaining national food safety control systems ...

    African Journals Online (AJOL)

    The establishment of effective food safety systems is pivotal to ensuring the safety of the national food supply as well as food products for regional and international trade. The development, structure and implementation of modern food safety systems have been driven over the years by a number of developments.

  9. COMPRESS - a computerized reactor safety system

    International Nuclear Information System (INIS)

    Vegh, E.

    1986-01-01

    The computerized reactor safety system, called COMPRESS, provides the following services: scram initiation; safety interlockings; event recording. The paper describes the architecture of the system and deals with reliability problems. A self-testing unit checks permanently the correct operation of the independent decision units. Moreover the decision units are tested by short pulses whether they can initiate a scram. The self-testing is described in detail

  10. Nitrogen-system safety study: Portsmouth Gaseous Diffusion Plant

    International Nuclear Information System (INIS)

    1982-07-01

    The Department of Energy has primary responsibility for the safety of operations at DOE-owned nuclear facilities. The guidelines for the analysis of credible accidents are outlined in DOE Order 5481.1. DOE has requested that existing plant facilities and operations be reviewed for potential safety problems not covered by standard industrial safety procedures. This review is being conducted by investigating individual facilities and documenting the results in Safety Study Reports which will be compiled to form the Existing Plant Final Safety Analysis Report which is scheduled for completion in September, 1984. This Safety Study documents the review of the Plant Nitrogen System facilities and operations and consists of Section 4.0, Facility and Process Description, and Section 5.0, Accident Analysis, of the Final Safety Analysis Report format. The existing nitrogen system consists of a Superior Air Products Company Type D Nitrogen Plant, nitrogen storage facilities, vaporization facilities and a distribution system. The system is designed to generate and distribute nitrogen gas used in the cascade for seal feed, buffer systems, and for servicing equipment when exceptionally low dew points are required. Gaseous nitrogen is also distributed to various process auxiliary buildings. The average usage is approximately 130,000 standard cubic feet per day

  11. Integrated therapy safety management system.

    Science.gov (United States)

    Podtschaske, Beatrice; Fuchs, Daniela; Friesdorf, Wolfgang

    2013-09-01

    The aim is to demonstrate the benefit of the medico-ergonomic approach for the redesign of clinical work systems. Based on the six layer model, a concept for an 'integrated therapy safety management' is drafted. This concept could serve as a basis to improve resilience. The concept is developed through a concept-based approach. The state of the art of safety and complexity research in human factors and ergonomics forms the basis. The findings are synthesized to a concept for 'integrated therapy safety management'. The concept is applied by way of example for the 'medication process' to demonstrate its practical implementation. The 'integrated therapy safety management' is drafted in accordance with the six layer model. This model supports a detailed description of specific work tasks, the corresponding responsibilities and related workflows at different layers by using the concept of 'bridge managers'. 'Bridge managers' anticipate potential errors and monitor the controlled system continuously. If disruptions or disturbances occur, they respond with corrective actions which ensure that no harm results and they initiate preventive measures for future procedures. The concept demonstrates that in a complex work system, the human factor is the key element and final authority to cope with the residual complexity. The expertise of the 'bridge managers' and the recursive hierarchical structure results in highly adaptive clinical work systems and increases their resilience. The medico-ergonomic approach is a highly promising way of coping with two complexities. It offers a systematic framework for comprehensive analyses of clinical work systems and promotes interdisciplinary collaboration. © 2013 The Authors. British Journal of Clinical Pharmacology © 2013 The British Pharmacological Society.

  12. Integrated therapy safety management system

    Science.gov (United States)

    Podtschaske, Beatrice; Fuchs, Daniela; Friesdorf, Wolfgang

    2013-01-01

    Aims The aim is to demonstrate the benefit of the medico-ergonomic approach for the redesign of clinical work systems. Based on the six layer model, a concept for an ‘integrated therapy safety management’ is drafted. This concept could serve as a basis to improve resilience. Methods The concept is developed through a concept-based approach. The state of the art of safety and complexity research in human factors and ergonomics forms the basis. The findings are synthesized to a concept for ‘integrated therapy safety management’. The concept is applied by way of example for the ‘medication process’ to demonstrate its practical implementation. Results The ‘integrated therapy safety management’ is drafted in accordance with the six layer model. This model supports a detailed description of specific work tasks, the corresponding responsibilities and related workflows at different layers by using the concept of ‘bridge managers’. ‘Bridge managers’ anticipate potential errors and monitor the controlled system continuously. If disruptions or disturbances occur, they respond with corrective actions which ensure that no harm results and they initiate preventive measures for future procedures. The concept demonstrates that in a complex work system, the human factor is the key element and final authority to cope with the residual complexity. The expertise of the ‘bridge managers’ and the recursive hierarchical structure results in highly adaptive clinical work systems and increases their resilience. Conclusions The medico-ergonomic approach is a highly promising way of coping with two complexities. It offers a systematic framework for comprehensive analyses of clinical work systems and promotes interdisciplinary collaboration. PMID:24007448

  13. From Safe Systems to Patient Safety

    DEFF Research Database (Denmark)

    Aarts, J.; Nøhr, C.

    2010-01-01

    for the third conference with the theme: The ability to design, implement and evaluate safe, useable and effective systems within complex health care organizations. The theme for this conference was "Designing and Implementing Health IT: from safe systems to patient safety". The contributions have reflected...... and implementation of safe systems and thus contribute to the agenda of patient safety? The contributions demonstrate how the health informatics community has contributed to the performance of significant research and to translating research findings to develop health care delivery and improve patient safety......This volume presents the papers from the fourth International Conference on Information Technology in Health Care: Socio-technical Approaches held in Aalborg, Denmark in June 2010. In 2001 the first conference was held in Rotterdam, The Netherlands with the theme: Sociotechnical' approaches...

  14. Blanket safety by GEMSAFE methodology

    International Nuclear Information System (INIS)

    Sawada, Tetsuo; Saito, Masaki

    2001-01-01

    General Methodology of Safety Analysis and Evaluation for Fusion Energy Systems (GEMSAFE) has been applied to a number of fusion system designs, such as R-tokamak, Fusion Experimental Reactor (FER), and the International Thermonuclear Experimental Reactor (ITER) designs in the both stages of Conceptual Design Activities (CDA) and Engineering Design Activities (EDA). Though the major objective of GEMSAFE is to reasonably select design basis events (DBEs) it is also useful to elucidate related safety functions as well as requirements to ensure its safety. In this paper, we apply the methodology to fusion systems with future tritium breeding blankets and make clear which points of the system should be of concern from safety ensuring point of view. In this context, we have obtained five DBEs that are related to the blanket system. We have also clarified the safety functions required to prevent accident propagations initiated by those blanket-specific DBEs. The outline of the methodology is also reviewed. (author)

  15. Declarative Rule-based Safety for Robotic Perception Systems

    DEFF Research Database (Denmark)

    Mogensen, Johann Thor Ingibergsson; Kraft, Dirk; Schultz, Ulrik Pagh

    2017-01-01

    Mobile robots are used across many domains from personal care to agriculture. Working in dynamic open-ended environments puts high constraints on the robot perception system, which is critical for the safety of the system as a whole. To achieve the required safety levels the perception system needs...... to be certified, but no specific standards exist for computer vision systems, and the concept of safe vision systems remains largely unexplored. In this paper we present a novel domain-specific language that allows the programmer to express image quality detection rules for enforcing safety constraints...

  16. A study on a reliability assessment methodology for the VHTR safety systems

    International Nuclear Information System (INIS)

    Lee, Hyung Sok

    2012-02-01

    The passive safety system of a 300MWt VHTR (Very High Temperature Reactor)which has attracted worldwide attention recently is actively considered for designing the improvement in the safety of the next generation nuclear power plant. The passive system functionality does not rely on an external source of the electrical support system,but on an intelligent use of the natural phenomena, such as convection, conduction, radiation, and gravity. It is not easy to evaluate quantitatively the reliability of the passive safety for the risk analysis considering the existing active system failure since the classical reliability assessment method could not be applicable. Therefore a new reliability methodology needs to be developed and applied for evaluating the reliability of the conceptual designed VHTR in this study. The preliminary evaluation and conceptualization are performed using the concept of the load and capacity theory related to the reliability physics model. The method of response surface method (RSM) is also utilized for evaluating the maximum temperature of nuclear fuel in this study. The significant variables and their correlation are considered for utilizing the GAMMA+ code. The proposed method might contribute to designing the new passive system of the VHTR

  17. Safety assessment of HLW geological disposal system

    International Nuclear Information System (INIS)

    Naito, Morimasa

    2006-01-01

    In accordance with the Japanese nuclear program, the liquid waste with a high level of radioactivity arising from reprocessing is solidified in a stable glass matrix (vitrification) in stainless steel fabrication containers. The vitrified waste is referred to as high-level radioactive waste (HLW), and is characterized by very high initial radioactivity which, even though it decreases with time, presents a potential long-term risk. It is therefore necessary to thoroughly manage HLW from human and his environment. After vitrification, HLW is stored for a period of 30 to 50 years to allow cooling, and finally disposed of in a stable geological environment at depths greater than 300 m below surface. The deep underground environment, in general, is considered to be stable over geological timescales compared with surface environment. By selecting an appropriate disposal site, therefore, it is considered to be feasible to isolate the waste in the repository from man and his environment until such time as radioactivity levels have decayed to insignificance. The concept of geological disposal in Japan is similar to that in other countries, being based on a multibarrier system which combines the natural geological environment with engineered barriers. It should be noted that geological disposal concept is based on a passive safety system that does not require any institutional control for assuring long term environmental safety. To demonstrate feasibility of safe HLW repository concept in Japan, following technical steps are essential. Selection of a geological environment which is sufficiently stable for disposal (site selection). Design and installation of the engineered barrier system in a stable geological environment (engineering measures). Confirmation of the safety of the constructed geological disposal system (safety assessment). For site selection, particular consideration is given to the long-term stability of the geological environment taking into account the fact

  18. Safety assessment for the passive system of the nuclear power plants (NPPs) using safety margin estimation

    International Nuclear Information System (INIS)

    Woo, Tae-Ho; Lee, Un-Chul

    2010-01-01

    The probabilistic safety assessment (PSA) for gas-cooled nuclear power plants has been investigated where the operational data are deficient, because there is not any commercial gas-cooled nuclear power plant. Therefore, it is necessary to use the statistical data for the basic event constructions. Several estimations for the safety margin are introduced for the quantification of the failure frequency in the basic event, which is made by the concept of the impact and affordability. Trend of probability of failure (TPF) and fuzzy converter (FC) are introduced using the safety margin, which shows the simplified and easy configurations for the event characteristics. The mass flow rate in the natural circulation is studied for the modeling. The potential energy in the gravity, the temperature and pressure in the heat conduction, and the heat transfer rate in the internal stored energy are also investigated. The values in the probability set are compared with those of the fuzzy set modeling. Non-linearity of the safety margin is expressed by the fuzziness of the membership function. This artificial intelligence analysis of the fuzzy set could enhance the reliability of the system comparing to the probabilistic analysis.

  19. 33 CFR 147.847 - Safety Zone; BW PIONEER Floating Production, Storage, and Offloading System Safety Zone.

    Science.gov (United States)

    2010-07-01

    ... Production, Storage, and Offloading System Safety Zone. 147.847 Section 147.847 Navigation and Navigable... ZONES § 147.847 Safety Zone; BW PIONEER Floating Production, Storage, and Offloading System Safety Zone. (a) Description. The BW PIONEER, a Floating Production, Storage and Offloading (FPSO) system, is in...

  20. Methodologies for verification and validation of expert systems as a function of component, criticality and life-cycle phase

    International Nuclear Information System (INIS)

    Miller, L.

    1992-01-01

    The review of verification and validation (V and V) methods presented here is based on results of the initial two tasks of a contract with the US Nuclear Regulatory Commission and the Electric Power Research Institute to Develop and Document Guidelines for Verifying and Validating Expert Systems. The first task was to review the applicability of conventional software techniques to expert systems; the second was to directly survey V and V practices associated with development of expert systems. Subsequent tasks will focus on selecting, synthesizing or developing V and V methods appropriate for the overall system, for specific expert systems components, and for different phases of the life-cycle. In addition, final guidelines will most likely be developed for each of three levels of expert systems: safety-related (systems whose functions directly relate to system safety, so-called safety-critical systems), important-to-safety (systems which support the critical safety functions), and non-safety (systems which are unrelated to safety functions). For the present purposes of categorizing and discussing various types of V and V methods, the authors simplify the life-cycle and consider only two aspects - systems validation phase. The authors identified a number of techniques for the first, combined, phase and two general classes of V and V techniques for the latter phase: static testing techniques, which do not involve execution of the system code, and dynamic testing techniques, which do. In the next two sections the author reviews first the applicability to expert systems of conventional V and V techniques and, second, the techniques expert system developers actually use. In the last section the authors make some general observations

  1. Study concerning the power plant control and safety equipment by integrated distributed systems

    International Nuclear Information System (INIS)

    Optea, I.; Oprea, M.; Stanescu, P.

    1995-01-01

    The paper deals with the trends existing in the field of nuclear control and safety equipment and systems, proposing a high-efficiency integrated system. In order to enhance the safety of the plant and reliability of the structure system and components, we present a concept based on the latest computer technology with an open, distributed system, connected by a local area network with high redundancy. A modern conception for the control and safety system is to integrate all the information related to the reactor protection, active engineered safeguard and auxiliary systems parameters, offering a fast flow of information between all the agencies concerned so that situations can be quickly assessed. The integrated distributed control is based on a high performance operating system for realtime applications, flexible enough for transparent networking and modular for demanding configurations. The general design considerations for nuclear reactors instrumentation reliability and testing methods for real-time functions under dynamic regime are presented. Taking into account the fast progress in information technology, we consider the replacement of the old instrumentation of Cernavoda-1 NPP by a modern integrated system as an economical and efficient solution for the next units. (Author) 20 Refs

  2. IDENTIFICATION AND ASSESSMENT OF THE AIRCRAFT FUNCTIONAL SYSTEMS IN THE FLIGHT SAFETY MANAGEMENT SYSTEMS

    Directory of Open Access Journals (Sweden)

    I. D. Dashkov

    2014-01-01

    Full Text Available The article discusses issues related to determining the technical states of aircraft functional systems (FS. Mathematical formulas are given for expressing the relationship between the main parameters characterizing the model.

  3. VDMA contribution to functional safety of turbomachinery. Required risk reduction by safety functions for steam turbines; VDMA-Beitrag zur Funktionalen Sicherheit von Turbomaschinen. Notwendige Risikoreduktion durch Schutzfunktionen fuer Dampfturbinen

    Energy Technology Data Exchange (ETDEWEB)

    Wuest, Bernhard [Alstom Power Systems GmbH, Mannheim (Germany); Zelinger, Matthias [VDMA Power Systems, Frankfurt am Main (Germany); Havemann, Juergen [Siemens AG, Muelheim an der Ruhr (Germany). Energy Sector; Potten, Christian [MAN Diesel und Turbo SE, Oberhausen (Germany)

    2011-07-01

    Turbomachinery in power plants and industrial plants has to satisfy high safety standards. To meet these requirements, mechanical, hydraulic and electromechanical components have been used, most of them well-established already for decades. In recent years new standards for functional safety have been developed which address different target groups (IEC 61 528/511 for process industry IEC 62061 and ISO 13849 for mechanical engineering). The Working Panel 'Functional Safety of Turbomachinery' of VDMA defines rules for turbomachinery that will be presented with their background. (orig.)

  4. Safety-related instrumentation and control systems for nuclear power plants

    International Nuclear Information System (INIS)

    1984-01-01

    This Safety Guide deals mainly with design requirements for those I and C systems that are important to safety but are not safety systems. The Guide is intended to expand paragraphs 3.1, 3.2 and 3.3 of the Code of Practice on Design for Safety of Nuclear Power Plants (IAEA Safety Series No.50-C-D) in the area of I and C systems important to safety and refers to them as safety-related I and C systems. It also gives guidance and enumerates requirements for multiplexing and the use of the digital computers employed in this area

  5. Sophisticated Calculation of the 1oo4-architecture for Safety-related Systems Conforming to IEC61508

    International Nuclear Information System (INIS)

    Hayek, A; Al Bokhaiti, M; Schwarz, M H; Boercsoek, J

    2012-01-01

    With the publication and enforcement of the standard IEC 61508 of safety related systems, recent system architectures have been presented and evaluated. Among a number of techniques and measures to the evaluation of safety integrity level (SIL) for safety-related systems, several measures such as reliability block diagrams and Markov models are used to analyze the probability of failure on demand (PFD) and mean time to failure (MTTF) which conform to IEC 61508. The current paper deals with the quantitative analysis of the novel 1oo4-architecture (one out of four) presented in recent work. Therefore sophisticated calculations for the required parameters are introduced. The provided 1oo4-architecture represents an advanced safety architecture based on on-chip redundancy, which is 3-failure safe. This means that at least one of the four channels have to work correctly in order to trigger the safety function.

  6. Evaluating Safety Culture Under the Socio-Technical Complex Systems Perspective

    International Nuclear Information System (INIS)

    Lemos, F. L. de

    2016-01-01

    Since the term “safety culture” was coined, it has gained more and more attention as an effort to achieve higher levels of system safety. A good deal of effort has been done in order to better define, evaluate and implement safety culture programs in organizations throughout all industries, and especially in the Nuclear Industry. Unfortunately, despite all those efforts, we continue to witness accidents that are, in great part, attributed to flaws in the safety culture of the organization. Fukushima nuclear accident is one example of a serious accident in which flaws in the safety culture has been pointed to as one of the main contributors. In general, the definitions of safety culture emphasise the social aspect of the system. While the definitions also include the relations with the technical aspects, it does so in a general sense. For example, the International Nuclear Safety Advisory Group (INSAG) defines safety culture as: “The assembly of characteristics and attitudes in organizations and individuals which establishes that, as an overriding priority, nuclear plant safety issues receives the attention warranted by their significance.” By the way safety culture is defined we can infer that it represents a property of a social system, or a property of the social aspect of the system. In this sense, the social system is a component of the whole system. Where, “system” is understood to be comprised of a social (humans) and technical (equipment) aspects, as a Nuclear Power Plant, for example. Therefore, treating safety culture as an identity on its own right, finding and fixing flaws in the safety culture may not be enough to improve safety of the system. We also needed to evaluate all the interactions between the components that comprise all the aspects of the system. In some cases a flaw in the safety culture can easily be detected, such as an employee not wearing appropriate individual protection equipment, e.g., dosimeter, or when basic safety

  7. Development and implementation of setpoint tolerances for special safety systems

    International Nuclear Information System (INIS)

    Oliva, A.F.; Balog, G.; Parkinson, D.G.; Archinoff, G.H.

    1991-01-01

    The establishment of tolerances and impairment limits for special safety system setpoints is part of the process whereby the plant operator demonstrates to the regulatory authority that the plant operates safely and within the defined plant licensing envelope. The licensing envelope represents the set of limits and plant operating state and for which acceptably safe plant operation has been demonstrated by the safety analysis. By definition, operation beyond this envelope contributes to overall safety system unavailability. Definition of the licensing envelope is provided in a wide range of documents including the plant operating licence, the safety report, and the plant operating policies and principles documents. As part of the safety analysis, limits are derived for each special safety system initiating parameter such that the relevant safety design objectives are achieved for all design basis events. If initiation on a given parameter occurs at a level beyond its limit, there is a potential reduction in safety system effectiveness relative to the performance credited in the plant safety analysis. These safety system parameter limits, when corrected for random and systematic instrument errors and other errors inherent in the process of periodic testing or calibration, are then used to derive parameter impairment levels and setpoint tolerances. This paper describes the methodology that has evolved at Ontario Hydro for developing and implementing tolerances for special safety system parameters (i.e., the shutdown systems, emergency coolant injection system and containment system). Tolerances for special safety system initiation setpoints are addressed specifically, although many of the considerations discussed here will apply to performance limits for other safety system components. The first part of the paper deals with the approach that has been adopted for defining and establishing setpoint limits and tolerances. The remainder of the paper addresses operational

  8. Ergonomics in the context of system safety

    International Nuclear Information System (INIS)

    Donnelly, K.E.

    1984-01-01

    In a complex industrial environment, ergonomics must be combined with management science and systems analysis to produce a program which can create effective change and improve safety performance. We give an overview of such an approach, namely System Safety, so that its ergonomic content may be seen

  9. Identifying behaviour patterns of construction safety using system archetypes.

    Science.gov (United States)

    Guo, Brian H W; Yiu, Tak Wing; González, Vicente A

    2015-07-01

    Construction safety management involves complex issues (e.g., different trades, multi-organizational project structure, constantly changing work environment, and transient workforce). Systems thinking is widely considered as an effective approach to understanding and managing the complexity. This paper aims to better understand dynamic complexity of construction safety management by exploring archetypes of construction safety. To achieve this, this paper adopted the ground theory method (GTM) and 22 interviews were conducted with participants in various positions (government safety inspector, client, health and safety manager, safety consultant, safety auditor, and safety researcher). Eight archetypes were emerged from the collected data: (1) safety regulations, (2) incentive programs, (3) procurement and safety, (4) safety management in small businesses (5) production and safety, (6) workers' conflicting goals, (7) blame on workers, and (8) reactive and proactive learning. These archetypes capture the interactions between a wide range of factors within various hierarchical levels and subsystems. As a free-standing tool, they advance the understanding of dynamic complexity of construction safety management and provide systemic insights into dealing with the complexity. They also can facilitate system dynamics modelling of construction safety process. Copyright © 2015 Elsevier Ltd. All rights reserved.

  10. The adaptive safety analysis and monitoring system

    Science.gov (United States)

    Tu, Haiying; Allanach, Jeffrey; Singh, Satnam; Pattipati, Krishna R.; Willett, Peter

    2004-09-01

    The Adaptive Safety Analysis and Monitoring (ASAM) system is a hybrid model-based software tool for assisting intelligence analysts to identify terrorist threats, to predict possible evolution of the terrorist activities, and to suggest strategies for countering terrorism. The ASAM system provides a distributed processing structure for gathering, sharing, understanding, and using information to assess and predict terrorist network states. In combination with counter-terrorist network models, it can also suggest feasible actions to inhibit potential terrorist threats. In this paper, we will introduce the architecture of the ASAM system, and discuss the hybrid modeling approach embedded in it, viz., Hidden Markov Models (HMMs) to detect and provide soft evidence on the states of terrorist network nodes based on partial and imperfect observations, and Bayesian networks (BNs) to integrate soft evidence from multiple HMMs. The functionality of the ASAM system is illustrated by way of application to the Indian Airlines Hijacking, as modeled from open sources.

  11. Analysis of Critical Characteristics for Safety Graded Personnel Computers in the KNICS Architecture

    International Nuclear Information System (INIS)

    Lee, Hyun Chul; Lee, Dong Young

    2009-01-01

    Critical characteristics analysis of a safety related item is to identify characteristics to be verified to replace an original item with the dedicated item. It is sure that the dedicated item meeting critical characteristics would perform its intended safety function instead of the specified item. KNICS project developed two safety systems: IDiPS RPS (Reactor Protection System) and IDiPS ESF-CCS (Engineered Safety Features-Component Control System). Two safety systems of IDiPS are equipped with personnel computers, so-called COMs (Cabinet Operator Modules), in their cabinets. The personnel computers, COMs, are responsible for safety system monitoring, testing, and maintaining. Even though two safety systems are safety critical system, the personnel computers of two systems, i.e. COMs, are not graded as safety-graded items. Regulation requirements are expected to be strengthened, and the functions of the personnel computer may be enhanced to include safety-related functions and safety functions, it would be necessary that the grade of the personnel computers is adjusted to a higher level, the safety grade. To try to upgrade a non safety system, i.e. COMs, to a safety system, its safety functions and requirements, i.e. critical characteristics, must be identified and verified. This paper describes the process of the identification of critical characteristics and the results of analysis

  12. Classification of Aeronautics System Health and Safety Documents

    Data.gov (United States)

    National Aeronautics and Space Administration — Most complex aerospace systems have many text reports on safety, maintenance, and associated issues. The Aviation Safety Reporting System (ASRS) spans several...

  13. Survey of electronic safety systems in accelerator applications

    International Nuclear Information System (INIS)

    Mahoney, K.

    1997-01-01

    This paper presents the preliminary results and analysis of a comprehensive survey of the implementation of accelerator safety interlock systems from over 30 international labs. At the present time there is not a self consistent means to evaluate both the experiences and level of protection provided by electronic safety interlock systems. This research is intended to analyze the strength and weaknesses of several different types of interlock system implementation methodologies. Research, medical, and industrial accelerators are compared. Thomas Jefferson National Accelerator Facility (TJNAF) was one of the first large particle accelerators to implement a safety interlock system using programmable logic controllers. Since that time all of the major new U.S. accelerator construction projects plan to use some form of programmable electronics as part of a safety interlock system in some capacity

  14. Automation for System Safety Analysis

    Science.gov (United States)

    Malin, Jane T.; Fleming, Land; Throop, David; Thronesbery, Carroll; Flores, Joshua; Bennett, Ted; Wennberg, Paul

    2009-01-01

    This presentation describes work to integrate a set of tools to support early model-based analysis of failures and hazards due to system-software interactions. The tools perform and assist analysts in the following tasks: 1) extract model parts from text for architecture and safety/hazard models; 2) combine the parts with library information to develop the models for visualization and analysis; 3) perform graph analysis and simulation to identify and evaluate possible paths from hazard sources to vulnerable entities and functions, in nominal and anomalous system-software configurations and scenarios; and 4) identify resulting candidate scenarios for software integration testing. There has been significant technical progress in model extraction from Orion program text sources, architecture model derivation (components and connections) and documentation of extraction sources. Models have been derived from Internal Interface Requirements Documents (IIRDs) and FMEA documents. Linguistic text processing is used to extract model parts and relationships, and the Aerospace Ontology also aids automated model development from the extracted information. Visualizations of these models assist analysts in requirements overview and in checking consistency and completeness.

  15. Bonus systems and their effects on safety: an interview-based pilot study at the Swedish nuclear power plants

    International Nuclear Information System (INIS)

    Torbioern, Ingemar; Mattson, Malin

    2009-03-01

    The aim of this pilot study has been to describe and analyse potential effects on safety-related behaviour and risks associated with the bonus systems currently used at Swedish nuclear plants. To this end and in order to establish a frame of reference several theories on motivation were consulted regarding the relevance of monetary rewards. In addition empirical evidence on effects upon behaviours in general and safety behaviours in particular was taken into consideration, as well as a systems and a rationalist perspective on organisations. The resulting frame of reference was used for a descriptive mapping of the bonus systems and for the formulation of a semi-structured interview schedule intended to capture the experiences of those concerned by the systems. A total of 15 interviews were performed with staff of different functions and organisational positions. Results of the study do not indicate any negative effects on safety-related behaviours. Rather they indicate that safety-behaviours may be promoted insofar as bonus rewards are linked to performance goals concerning safety. All of the bonus-systems may be characterised as low in incentive intensity, i.e. produce small effects on motivation and performance. Still, as the systems differ in design and in the way they are perceived, they also represent different challenges in order to function more efficiently as parameters

  16. Development and application of digital safety system in NPPs

    International Nuclear Information System (INIS)

    Kwon, Keechoon; Kim, Changhwoi; Lee, Dongyoung

    2012-01-01

    This paper describes the development of digital safety system in NPPs based on safety- grade programmable logic controller (PLC) platform and its application to real NPP construction. The digital safety system consists of a reactor protection system and an engineered safety feature-component control system. The safety-grade PLC platform was developed so that it meets the requirements of the regulation. The PLC consists of various modules such as a power module, a processor module, communication modules, digital input/output modules, analog input/output modules, a LOCA bus extension module, and a high-speed pulse counter module. The reactor protection system is designed with a redundant 4-channel architecture, and every channel is implemented with the same architecture. A single channel consists of a redundant bi-stable processor, a redundant coincidence processor, an automatic test and interface processor, and a cabinet operator module. The engineered safety feature-component control system is designed with four redundant divisions, and implemented with the PLC platform. The principal components of an individual division are fault tolerant group controllers, loop controllers, a test and interface processor, a cabinet operator module and a control channel gateway. The topical report is submitted to the regulatory body, and got safety evaluation report from the regulatory body. Also, the developed system is tested in the integrated performance validation facility. It is decided that the digital safety system applied to Shin-Uljin unit 1 and 2 after a topical report approval and validation test. Design changes occur in the digital safety system that is applied to an actual nuclear power plant construction, and the PLC has also been upgraded

  17. Development and application of digital safety system in NPPs

    Energy Technology Data Exchange (ETDEWEB)

    Kwon, Keechoon; Kim, Changhwoi; Lee, Dongyoung [Korea Atomic Energy Research Institute, Daejeon (Korea, Republic of)

    2012-03-15

    This paper describes the development of digital safety system in NPPs based on safety- grade programmable logic controller (PLC) platform and its application to real NPP construction. The digital safety system consists of a reactor protection system and an engineered safety feature-component control system. The safety-grade PLC platform was developed so that it meets the requirements of the regulation. The PLC consists of various modules such as a power module, a processor module, communication modules, digital input/output modules, analog input/output modules, a LOCA bus extension module, and a high-speed pulse counter module. The reactor protection system is designed with a redundant 4-channel architecture, and every channel is implemented with the same architecture. A single channel consists of a redundant bi-stable processor, a redundant coincidence processor, an automatic test and interface processor, and a cabinet operator module. The engineered safety feature-component control system is designed with four redundant divisions, and implemented with the PLC platform. The principal components of an individual division are fault tolerant group controllers, loop controllers, a test and interface processor, a cabinet operator module and a control channel gateway. The topical report is submitted to the regulatory body, and got safety evaluation report from the regulatory body. Also, the developed system is tested in the integrated performance validation facility. It is decided that the digital safety system applied to Shin-Uljin unit 1 and 2 after a topical report approval and validation test. Design changes occur in the digital safety system that is applied to an actual nuclear power plant construction, and the PLC has also been upgraded.

  18. RSAS: a Reactor Safety Assessment System

    International Nuclear Information System (INIS)

    Sebo, D.E.; Dixon, B.W.; Bray, M.A.

    1985-01-01

    The Reactor Safety Assessment System (RSAS) is an expert system under development for the United States Nuclear Regulatory Commission (NRC). RSAS is being developed for use at the NRC's Operations Center in the event of a serious incident at a licensed nuclear power plant. The system generates situation assessments for the NRC Reactor Safety Team based on a limited number of plant parameters, known operator actions, and plant status data. The RSAS rule base currently covers one reactor type. The extension of the rule base to other reactor types is also discussed

  19. Safety design requirements for safety systems and components of JSFR

    International Nuclear Information System (INIS)

    Kubo, Shigenobu; Shimakawa, Yoshio; Yamano, Hidemasa; Kotake, Shoji

    2011-01-01

    Safety design requirements for JSFR were summarized taking the development targets of the FaCT project and design feature of JSFR into account. The related safety principle and requirements for Monju, CRBRP, PRISM, SPX, LWRs, IAEA standards, goals of GIF, basic principle of INPRO etc. were also taken into account so that the safety design requirements can be a next-generation global standard. The development targets for safety and reliability are set based on those of FaCT, namely, ensuring safety and reliability equal to future LWR and related fuel cycle facilities. In order to achieve these targets, the defence-in-depth concept is used as the basic safety design principle. General features of the safety design requirements are 1) Achievement of higher reliability, 2) Achievement of higher inspectability and maintainability, 3) Introduction of passive safety features, 4) Reduction of operator action needs, 5) Design consideration against Beyond Design Basis Events, 6) In-Vessel Retention of degraded core materials, 7) Prevention and mitigation against sodium chemical reactions, and 8) Design against external events. The current specific requirements for each system and component are summarized taking the basic design concept of JSFR into account, which is an advanced loop-type large-output power plant with a mixed-oxide-fuelled core. (author)

  20. New design of engineered safety features-component control system to improve performance and reliability

    International Nuclear Information System (INIS)

    Kim, S.T.; Jung, H.W.; Lee, S.J.; Cho, C.H.; Kim, D.H.; Kim, H.

    2006-01-01

    Full text: Full text: The Engineered Safety Features-Component Control System (ESF-CCS) controls the engineered safety features of a Nuclear Power Plant such as Solenoid Operated Valves (SOV), Motor Operated Valves (MOV), pumps, dampers, etc. to mitigate the effects of a Design Basis Accident (DBA) or an abnormal operation. ESF-CCS serves as an interface system between the Plant Protection System (PPS) and remote actuation devices. ESF-CCS is composed of fault tolerant Group Controllers GC, Loop Controllers (LC), ESF-CCS Test and Interface Processor (ETIP) and Cabinet Operator Module (COM) and Control Channel Gateway (CCG) etc. GCs in each division are designed to be fully independent triple configuration, which perform system level NSSS and BOP ESFAS logic (2-out-of-4 logic and l-out-of-2 logic, respectively) making it possible to test each GC individually during normal operation. In the existing configuration, the safety-related plant component control is part of the Plant Control System (PCS) non-safety system. For increased safety and reliability, this design change incorporates this part into the LCs, and is therefore designed according to the safety-critical system procedures. The test and diagnosis capabilities of ETIP and COM are reinforced. By means of an automatic periodic test for all main functions of the system, it is possible to quickly determine an abnormal status of the system, and to decrease the elapsed time for tests, thus effectively increasing availability. ESF-CCS consists of four independent divisions (A, B, C, and D) in the Advanced Power Reactor 1400 (APR1400). One prototype division is being manufactured and will be tested

  1. Reliability analysis of diverse safety logic systems of fast breeder reactor

    International Nuclear Information System (INIS)

    Ravi Kumar, Bh.; Apte, P.R.; Srivani, L.; Ilango Sambasivan, S.; Swaminathan, P.

    2006-01-01

    Safety Logic for Fast Breeder Reactor (FBR) is designed to initiate safety action against Design Basis Events. Based on the outputs of various processing circuits, Safety logic system drives the control rods of the shutdown system. So, Safety Logic system is classified as safety critical system. Therefore, reliability analysis has to be performed. This paper discusses the Reliability analysis of Diverse Safety logic systems of FBRs. For this literature survey on safety critical systems, system reliability approach and standards to be followed like IEC-61508 are discussed in detail. For Programmable Logic device based systems, Hardware Description Languages (HDL) are used. So this paper also discusses the Verification and Validation for HDLs. Finally a case study for the Reliability analysis of Safety logic is discussed. (author)

  2. A study on LAN applications in nuclear safety systems

    International Nuclear Information System (INIS)

    Kim, Sung; Lee, Young Ryul; Koo, Jun Mo; Han, Jai Bok

    1995-01-01

    It is a general tendency to digitalize the conventional relay based I and C systems in nuclear power plant. But, the digitalisation of nuclear safety systems has many a difficulty to surmount. The typical one thing of many difficulties is the data communication problem between local controllers and systems. The network architecture built with LAN (Local Area Network) in digital systems of the other industries are general. But in case of nuclear safety systems many considerations in point of safety and license are required to implement it in the field. In this parer, some considerations for applying LAN in nuclear safety systems were reviewed

  3. Safety assessment of automated vehicle functions by simulation-based fault injection

    OpenAIRE

    Juez, Garazi; Amparan, Estibaliz; Lattarulo, Ray; Rastelli, Joshue Perez; Ruiz, Alejandra; Espinoza, Huascar

    2017-01-01

    As automated driving vehicles become more sophisticated and pervasive, it is increasingly important to assure its safety even in the presence of faults. This paper presents a simulation-based fault injection approach (Sabotage) aimed at assessing the safety of automated vehicle functions. In particular, we focus on a case study to forecast fault effects during the model-based design of a lateral control function. The goal is to determine the acceptable fault detection interval for pe...

  4. Research on advanced system safety assessment procedures (4)

    International Nuclear Information System (INIS)

    Suzuki, Kazuhiko; Shimada, Yukiyasu

    2001-03-01

    The past research reports in the area of safety engineering proposed the Computer-aided HAZOP system to be applied to Nuclear Reprocessing Facilities. Automated HAZOP system has great advantage compared with human analysts in terms of accuracy of the results, and time required to conduct HAZOP studies. This report surveys the literature on risk assessment and safety design based on the concept of independent protection layers (IPLs). Furthermore, to improve HAZOP System, tool is proposed to construct the basic model and the internal state model. Such HAZOP system is applied to analyze two kinds of processes, where the ability of the proposed system is verified. In addition, risk assessment support system is proposed to integrate safety design environment and assessment result to be used by other plants as well as to enable the underline plant to use other plants' information. This technique can be implemented using web-based safety information systems. (author)

  5. Visual function, driving safety, and the elderly.

    Science.gov (United States)

    Keltner, J L; Johnson, C A

    1987-09-01

    The authors have conducted a survey of the Departments of Motor Vehicles in all 50 states, the District of Columbia, and Puerto Rico requesting information about the visual standards, accidents, and conviction rates for different age groups. In addition, we have reviewed the literature on visual function and traffic safety. Elderly drivers have a greater number of vision problems that affect visual acuity and/or peripheral visual fields. Although the elderly are responsible for a small percentage of the total number of traffic accidents, the types of accidents they are involved in (e.g., failure to yield the right-of-way, intersection collisions, left turns onto crossing streets) may be related to peripheral and central visual field problems. Because age-related changes in performance occur at different rates for various individuals, licensing of the elderly driver should be based on functional abilities rather than age. Based on information currently available, we can make the following recommendations: (1) periodic evaluations of visual acuity and visual fields should be performed every 1 to 2 years in the population over age 65; (2) drivers of any age with multiple accidents or moving violations should have visual acuity and visual fields evaluated; and (3) a system should be developed for physicians to report patients with potentially unsafe visual function. The authors believe that these recommendations may help to reduce the number of traffic accidents that result from peripheral visual field deficits.

  6. ABWR (K-6/7) construction experience (computer-based safety system)

    International Nuclear Information System (INIS)

    Yokomura, T.

    1998-01-01

    TEPCO applied a digital safety system to Kashiwazaki-Kariwa Nuclear Power Station Unit Nos. 6 and 7, the world's first ABWR plant. Although this was the first time to apply a digital safety logic system in Japan, we were able to complete construction of K-6/7 very successfully and without any delay. TEPCO took a approach of developing a substantial amount of experience in digital non- safety systems before undertaking the design of the safety protection system. This paper describes the history, techniques and experience behind achieving a highly reliable digital safety system. (author)

  7. Manual of functions, assignments, and responsibilities for nuclear safety: Revision 2

    Energy Technology Data Exchange (ETDEWEB)

    1994-10-15

    The FAR Manual is a convenient easy-to-use collection of the functions, assignments, and responsibilities (FARs) of DOE nuclear safety personnel. Current DOE directives, including Orders, Secretary of Energy Notices, and other assorted policy memoranda, are the source of this information and form the basis of the FAR Manual. Today, the majority of FARs for DOE personnel are contained in DOE`s nuclear safety Orders. As these Orders are converted to rules in the Code of Federal Regulations, the FAR Manual will become the sole source for information relating to the functions, assignments, responsibilities of DOE nuclear safety personnel. The FAR Manual identifies DOE directives that relate to nuclear safety and the specific DOE personnel who are responsible for implementing them. The manual includes only FARs that have been extracted from active directives that have been approved in accordance with the procedures contained in DOE Order 1321.1B.

  8. SACS2: Dynamic and Formal Safety Analysis Method for Complex Safety Critical System

    International Nuclear Information System (INIS)

    Koh, Kwang Yong; Seong, Poong Hyun

    2009-01-01

    Fault tree analysis (FTA) is one of the most widely used safety analysis technique in the development of safety critical systems. However, over the years, several drawbacks of the conventional FTA have become apparent. One major drawback is that conventional FTA uses only static gates and hence can not capture dynamic behaviors of the complex system precisely. Although several attempts such as dynamic fault tree (DFT), PANDORA, formal fault tree (FFT) and so on, have been made to overcome this problem, they can not still do absolute or actual time modeling because they adapt relative time concept and can capture only sequential behaviors of the system. Second drawback of conventional FTA is its lack of rigorous semantics. Because it is informal in nature, safety analysis results heavily depend on an analyst's ability and are error-prone. Finally reasoning process which is to check whether basic events really cause top events is done manually and hence very labor-intensive and timeconsuming for the complex systems. In this paper, we propose a new safety analysis method for complex safety critical system in qualitative manner. We introduce several temporal gates based on timed computational tree logic (TCTL) which can represent quantitative notion of time. Then, we translate the information of the fault trees into UPPAAL query language and the reasoning process is automatically done by UPPAAL which is the model checker for time critical system

  9. Method and practice on safety software verification and validation for digital reactor protection system

    International Nuclear Information System (INIS)

    Li Duo; Zhang Liangju; Feng Junting

    2010-01-01

    The key issue arising from digitalization of reactor protection system for Nuclear Power Plant (NPP) is in essence, how to carry out Verification and Validation (V and V), to demonstrate and confirm the software is reliable enough to perform reactor safety functions. Among others the most important activity of software V and V process is unit testing. This paper discusses the basic concepts on safety software V and V and the appropriate technique for software unit testing, focusing on such aspects as how to ensure test completeness, how to establish test platform, how to develop test cases and how to carry out unit testing. The technique discussed herein was successfully used in the work of unit testing on safety software of a digital reactor protection system. (author)

  10. Technique of research of severe accidents and substantiation of safety of nuclear systems

    International Nuclear Information System (INIS)

    Ivanov, E.A.; Tchenov, S.V.

    2001-01-01

    Work is devoted to development of possible ways of solution of the problems of nuclear safety substantiation. We believe that safety in severe accidents is one of significant factors, which restrict value of nuclear industry in future power production. In connection with it we can conclude followed items: -) Substantiation of safety in severe accidents in nuclear system should be built on a deterministic way of guaranteed exception of heavy consequences; -) It is easy that this aim can be achieved by modeling in functions of common type; -) Main purpose of this work is to show that it is possible to estimate physical allowed state of system in emergency and find of trajectory of heaviest scenarios by optimization procedure; and -) In this work we have developed new method and computer code purposed for study of accident conditions of water cooled un-managed nuclear systems such as cooling ponds of spent fuel, experimental facilities etc. (authors)

  11. Analysis of Aviation Safety Reporting System Incident Data Associated With the Technical Challenges of the Vehicle Systems Safety Technology Project

    Science.gov (United States)

    Withrow, Colleen A.; Reveley, Mary S.

    2014-01-01

    This analysis was conducted to support the Vehicle Systems Safety Technology (VSST) Project of the Aviation Safety Program (AVsP) milestone VSST4.2.1.01, "Identification of VSST-Related Trends." In particular, this is a review of incident data from the NASA Aviation Safety Reporting System (ASRS). The following three VSST-related technical challenges (TCs) were the focus of the incidents searched in the ASRS database: (1) Vechicle health assurance, (2) Effective crew-system interactions and decisions in all conditions; and (3) Aircraft loss of control prevention, mitigation, and recovery.

  12. Preliminary thermal-hydraulic and safety analysis of China DFLL-TBM system

    Energy Technology Data Exchange (ETDEWEB)

    Li, Wei [School of Nuclear Science and Technology, Xi’an Jiaotong University, No. 28, Xianning West Road, Xi’an, Shanxi 710049 (China); Tian, Wenxi, E-mail: wxtian@mail.xjtu.edu.cn [School of Nuclear Science and Technology, Xi’an Jiaotong University, No. 28, Xianning West Road, Xi’an, Shanxi 710049 (China); Qiu, Suizheng; Su, Guanghui; Jiao, Hong [School of Nuclear Science and Technology, Xi’an Jiaotong University, No. 28, Xianning West Road, Xi’an, Shanxi 710049 (China); Bai, Yunqing; Chen, Hongli [Institute of Nuclear Energy Safety Technology, Chinese Academy of Sciences, Hefei, Anhui 230031 (China); Wu, Yican, E-mail: yican.Wu@Fds.Org.Cn [Institute of Nuclear Energy Safety Technology, Chinese Academy of Sciences, Hefei, Anhui 230031 (China)

    2013-06-15

    Highlights: • Thermal-hydraulic and safety analysis on DFLL-TBM system is performed. • The TBM FW maximum temperature is 541 °C under steady state condition. • The TBM FW maximum temperature does not exceed the melt point of CLAM steel 1500 °C. • Neither the VV pressurization nor vault pressure build-up goes beyond 0.2 MPa. -- Abstract: China has proposed the dual-functional lithium-lead (DFLL) tritium breeding blanket concept for testing in ITER as a test blanket module (TBM), to demonstrate the technologies of tritium self-sufficiency, high-grade heat extraction and efficient electricity production which are needed for DEMO and fusion power plant. Safety assessment of the TBM and its auxiliary system should be conducted to deal with ITER safety issues directly caused by the TBM system failure during the design process. In this work, three potential initial events (PIEs) – in-vessel loss of helium (He) coolant and ex-vessel loss of He coolant and loss of flow without scram (LOFWS) – were analyzed for the TBM system with a modified version of the RELAP5/MOD3 code containing liquid lithium-lead eutectic (LiPb). The code also comprised an empirical expression for MHD pressure drop relevant to three-dimensional (3D) effect, the Lubarsky–Kaufman convective heat transfer correlation for LiPb flow and the Gnielinski convective heat transfer correlation for He flow. Since both LiPb and He serve as TBM coolants, the LiPb and He ancillary cooling systems were modeled to investigate the thermal-hydraulic characteristic of the TBM system and its influence on ITER safety under those accident conditions. The TBM components and the coolants flow within the TBM were simulated with one-dimensional heat structures and their associated hydrodynamic components. ITER enclosures including vacuum vessel (VV), port cell and TCWS vault were also covered in the model for accident analyses. Through this best estimate approach, the calculation indicated that the current

  13. Safety balance: Analysis of safety systems

    International Nuclear Information System (INIS)

    Delage, M.; Giroux, C.

    1990-12-01

    Safety analysis, and particularly analysis of exploitation of NPPs is constantly affected by EDF and by the safety authorities and their methodologies. Periodic safety reports ensure that important issues are not missed on daily basis, that incidents are identified and that relevant actions are undertaken. French safety analysis method consists of three principal steps. First type of safety balance is analyzed at the normal start-up phase for each unit including the final safety report. This enables analysis of behaviour of units ten years after their licensing. Second type is periodic operational safety analysis performed during a few years. Finally, the third step consists of safety analysis of the oldest units with the aim to improve the safety standards. The three steps of safety analysis are described in this presentation in detail with the aim to present the objectives and principles. Examples of most recent exercises are included in order to illustrate the importance of such analyses

  14. Improving safety margin of LWRs by rethinking the emergency core cooling system criteria and safety system capacity

    Energy Technology Data Exchange (ETDEWEB)

    Lee, Youho, E-mail: euo@kaist.ac.kr; Kim, Bokyung, E-mail: bkkim2@kaist.ac.kr; NO, Hee Cheon, E-mail: hcno@kaist.ac.kr

    2016-10-15

    Highlights: • Zircaloy embrittlement criteria can increase to 1370 °C for CP-ECR lower than 13%. • The draft ECCS criteria of U.S. NRC allow less than 5% in power margin. • The Japanese fracture-based criteria allow around 5% in power margin. • Increasing SIT inventory is effective in assuring safety margin for power uprates. - Abstract: This study investigates the engineering compatibility between emergency core cooling system criteria and safety water injection systems, in the pursuit of safety margin increase of light water reactors. This study proposes an acceptable temperature increase to 1370 °C as long as equivalent cladding reacted calculated by the Cathcart–Pawel equation is below 13%, after an extensive literature review. The influence of different ECCS criteria on the safety margin during large break loss of coolant accident is investigated for OPR-1000 by the system code MARS-KS, implemented with the KINS-REM method. The fracture-based emergency core cooling system (ECCS) criteria proposed in this study are shown to enable power margins up to 10%. In the meantime, the draft U.S. NRC’s embrittlement criteria (burnup-sensitive) and Japanese fracture-based criteria are shown to allow less than 5%, and around 5% of power margins, respectively. Increasing safety injection tank (SIT) water inventory is the key, yet convenient, way of assuring safety margin for power increase. More than 20% increase in the SIT water inventory is required to allow 15% power margins, for the U.S. NRC’s burnup-dependent embrittlement criteria. Controlling SIT water inventory would be a useful option that could allow the industrial desire to pursue power margins even under the recent atmosphere of imposing stricter ECCS criteria for the considerable burnup effects.

  15. Safety issues of botanicals and botanical preparations in functional foods

    International Nuclear Information System (INIS)

    Kroes, R.; Walker, R.

    2004-01-01

    Although botanicals have played a role in the marketing of health products for ages, there is an increased interest today due to their perceived health benefits. Not only do consumers increasingly take charge of their health, but the scientific information and understanding of the beneficial health effects of bioactive substances in food, functional foods and food supplements have improved. Increasing use of these products has also led to concerns about their actual safety. Recorded cases of intoxications have triggered such concerns. The safety assessment of these substances is complicated by, amongst others, the variability of composition. Furthermore, consumption of such functional products is expected to produce physiological effects, which may lead to low margins of safety as the margin between exposure of such products and the safe level of intake are likely to be small. The safety assessment of botanicals and botanical preparations in food and food supplement should at least involve: - the characterisation and quality of the material, its quality control; - the intended use and consequent exposure; - history of use and exposure; - product comparison(s); - toxicological information gathering; - Risk characterisation/safety assessment; As a guidance tool, a decision tree approach is proposed to assist in determining the extent of data requirements based on the nature of the such product. This guidance tool in safety assessment was developed by an expert group of the International Life Sciences Institute (ILSI), European Branch, and is currently in press. In this paper a summarised version of this tool is presented

  16. An overview of review guidelines for HDL programmable devices in nuclear safety systems

    International Nuclear Information System (INIS)

    Komanduri, Raghavan; Srivani, L.; Thirugnana Murthy, D.

    2013-01-01

    HDL programmable devices viz. CPLDs and FPGAs are increasingly being used to implement digital designs in the I and C systems performing safety functions of nuclear power plants. Synthesizable RTL descriptions manually written in HDLs are the first step in developing industry standard large scale digital designs. The reliability of the implementation is determined by the methodologies followed by the designer during development. Very few guidelines on HPD design practices, specific to nuclear industry are available. This paper presents an overview of the existing guidelines such as IEC 62566 and U.S. NRC's 'Review guidelines for FPGAs in nuclear power plant safety systems'. (author)

  17. Integrated environment, safety, and health management system description

    International Nuclear Information System (INIS)

    Zoghbi, J. G.

    2000-01-01

    The Integrated Environment, Safety, and Health Management System Description that is presented in this document describes the approach and management systems used to address integrated safety management within the Richland Environmental Restoration Project

  18. On the applicability of the critical safety function concept to a uranium hexafluoride conversion unit

    International Nuclear Information System (INIS)

    Santos, F.C.; Goncalves, J.S.; Melo, P.F. Frutuoso e; Medeiros, J.A.C.C.

    2013-01-01

    This paper presents a discussion on the applicability on the critical safety function (CSF) concept as a design criterion for the new UF 6 conversion plant of Industrias Nucleares do Brazil (INB). This discussion is in the context of accident management, under the safety function oriented management. Safety functions may be understood as those whose loss may lead to releases of radioactive material or highly toxic chemicals, having possible radiological and/or occupational consequences for workers, the public or the environment. They should be designed to prevent criticality and to ensure adequate process confinement, thus preventing radioactive material releases that might lead to internal or external exposure and highly toxic chemical releases and exposure. The main hazards is the potential release of chemicals, especially HF and UF 6 . A criticality hazard exists only if the conversion facility processes uranium with a 235 U concentration greater than 1% Industrial activities for UF 6 production include handling and processing explosive, toxic and lethal chemicals, such as HF, H 2 and elemental F 2 , besides intermediate compounds containing uranium. State trees and definition of logical arrangements to construct an annunciation system are the next development stages, resulting form the establishment of applicable CSFs as representative of the next development stages, resulting from the establishment of applicable CSFs as representative of the various systems that make up the conversion plant. Discussed also in the biggest challenge of the development of this innovation, that is, the uncertainties related to the impact of human factors (not subject to monitoring by sensors or process conventional instrumentation). (author)

  19. A Nuclear Safety System based on Industrial Computer

    International Nuclear Information System (INIS)

    Kim, Ji Hyeon; Oh, Do Young; Lee, Nam Hoon; Kim, Chang Ho; Kim, Jae Hack

    2011-01-01

    The Plant Protection System(PPS), a nuclear safety Instrumentation and Control (I and C) system for Nuclear Power Plants(NPPs), generates reactor trip on abnormal reactor condition. The Core Protection Calculator System (CPCS) is a safety system that generates and transmits the channel trip signal to the PPS on an abnormal condition. Currently, these systems are designed on the Programmable Logic Controller(PLC) based system and it is necessary to consider a new system platform to adapt simpler system configuration and improved software development process. The CPCS was the first implementation using a micro computer in a nuclear power plant safety protection system in 1980 which have been deployed in Ulchin units 3,4,5,6 and Younggwang units 3,4,5,6. The CPCS software was developed in the Concurrent Micro5 minicomputer using assembly language and embedded into the Concurrent 3205 computer. Following the micro computer based CPCS, PLC based Common-Q platform has been used for the ShinKori/ShinWolsong units 1,2 PPS and CPCS, and the POSAFE-Q PLC platform is used for the ShinUlchin units 1,2 PPS and CPCS. In developing the next generation safety system platform, several factors (e.g., hardware/software reliability, flexibility, licensibility and industrial support) can be considered. This paper suggests an Industrial Computer(IC) based protection system that can be developed with improved flexibility without losing system reliability. The IC based system has the advantage of a simple system configuration with optimized processor boards because of improved processor performance and unlimited interoperability between the target system and development system that use commercial CASE tools. This paper presents the background to selecting the IC based system with a case study design of the CPCS. Eventually, this kind of platform can be used for nuclear power plant safety systems like the PPS, CPCS, Qualified Indication and Alarm . Pami(QIAS-P), and Engineering Safety

  20. A Nuclear Safety System based on Industrial Computer

    Energy Technology Data Exchange (ETDEWEB)

    Kim, Ji Hyeon; Oh, Do Young; Lee, Nam Hoon; Kim, Chang Ho; Kim, Jae Hack [Korea Electric Power Corporation Engineering and Construction, Daejeon (Korea, Republic of)

    2011-05-15

    The Plant Protection System(PPS), a nuclear safety Instrumentation and Control (I and C) system for Nuclear Power Plants(NPPs), generates reactor trip on abnormal reactor condition. The Core Protection Calculator System (CPCS) is a safety system that generates and transmits the channel trip signal to the PPS on an abnormal condition. Currently, these systems are designed on the Programmable Logic Controller(PLC) based system and it is necessary to consider a new system platform to adapt simpler system configuration and improved software development process. The CPCS was the first implementation using a micro computer in a nuclear power plant safety protection system in 1980 which have been deployed in Ulchin units 3,4,5,6 and Younggwang units 3,4,5,6. The CPCS software was developed in the Concurrent Micro5 minicomputer using assembly language and embedded into the Concurrent 3205 computer. Following the micro computer based CPCS, PLC based Common-Q platform has been used for the ShinKori/ShinWolsong units 1,2 PPS and CPCS, and the POSAFE-Q PLC platform is used for the ShinUlchin units 1,2 PPS and CPCS. In developing the next generation safety system platform, several factors (e.g., hardware/software reliability, flexibility, licensibility and industrial support) can be considered. This paper suggests an Industrial Computer(IC) based protection system that can be developed with improved flexibility without losing system reliability. The IC based system has the advantage of a simple system configuration with optimized processor boards because of improved processor performance and unlimited interoperability between the target system and development system that use commercial CASE tools. This paper presents the background to selecting the IC based system with a case study design of the CPCS. Eventually, this kind of platform can be used for nuclear power plant safety systems like the PPS, CPCS, Qualified Indication and Alarm . Pami(QIAS-P), and Engineering Safety

  1. Safety critical FPGA-based NPP instrumentation and control systems: assessment, development and implementation

    International Nuclear Information System (INIS)

    Bakhmach, E. S.; Siora, A. A.; Tokarev, V. I.; Kharchenko, V. S.; Sklyar, V. V.; Andrashov, A. A.

    2010-10-01

    The stages of development, production, verification, licensing and implementation methods and technologies of safety critical instrumentation and control systems for nuclear power plants (NPP) based on FPGA (Field Programmable Gates Arrays) technologies are described. A life cycle model and multi-version technologies of dependability and safety assurance of FPGA-based instrumentation and control systems are discussed. An analysis of NPP instrumentation and control systems construction principles developed by Research and Production Corporation Radiy using FPGA-technologies and results of these systems implementation and operation at Ukrainian and Bulgarian NPP are presented. The RADIY TM platform has been designed and developed by Research and Production Corporation Radiy, Ukraine. The main peculiarity of the RADIY TM platform is the use of FPGA as programmable components for logic control operation. The FPGA-based RADIY TM platform used for NPP instrumentation and control systems development ensures sca lability of system functions types, volume and peculiarities (by changing quantity and quality of sensors, actuators, input/output signals and control algorithms); sca lability of dependability (safety integrity) (by changing a number of redundant channel, tiers, diagnostic and reconfiguration procedures); sca lability of diversity (by changing types, depth and method of diversity selection). (Author)

  2. Functional analysis for complex systems of nuclear fusion plant

    International Nuclear Information System (INIS)

    Pinna, Tonio; Dongiovanni, Danilo Nicola; Iannone, Francesco

    2016-01-01

    Highlights: • Functional analysis for complex systems. • Functional Flow Block Diagrams (FFBD). • IDEFØ diagrams. • Petri Net algorithm - Abstract: In system engineering context, a functional analysis is the systematic process of identifying, describing and correlating the functions a system must perform in order to be successful at any foreseen life-cycle phase or operational state/mode. By focusing on what the system must do disregarding the implementation, the functional analysis supports an unbiased system requirement allocation analysis. The system function architecture is defined in terms of process, protection (interlock) or nuclear safety functions. Then, the system functions are analyzed from several points of view in order to highlight the various pieces of information defining the way the system is designed to accomplish its mission as defined in the system requirement documents. The process functional flow is identified and represented by Functional Flow Block Diagrams (FFBD) while the system function interfaces are identified and represented by IDEFØ diagrams. Function interfaces are defined as relationships across identified functions in terms of function input (from other functions or requirements), output (added value or outcome of the function), controls (from other functions or systems) and mechanisms necessary to fulfill the function. The function architecture is further detailed by considering for each function: a) the phase of application, b) the actions performed c) the controlled variable and control actions to be foreseen in the implementation of the functions, d) the system involved in the control action, e) the equipment involved in the function, f) the requirements allocated to the function. The methodology here presented are suggested for the designing of fusion facilities and reactors already from the first phases of the pre-conceptual design, as it is now for DEMO.

  3. Reliability analysis of Angra I safety systems

    International Nuclear Information System (INIS)

    Oliveira, L.F.S. de; Soto, J.B.; Maciel, C.C.; Gibelli, S.M.O.; Fleming, P.V.; Arrieta, L.A.

    1980-07-01

    An extensive reliability analysis of some safety systems of Angra I, are presented. The fault tree technique, which has been successfully used in most reliability studies of nuclear safety systems performed to date is employed. Results of a quantitative determination of the unvailability of the accumulator and the containment spray injection systems are presented. These results are also compared to those reported in WASH-1400. (E.G.) [pt

  4. Design of the reactor coolant system and associated systems in nuclear power plants. Safety guide

    International Nuclear Information System (INIS)

    2008-01-01

    This Safety Guide was prepared under the IAEA programme for establishing safety standards for nuclear power plants. The basic requirements for the design of safety systems for nuclear power plants are established in the Safety Requirements publication, Safety Standards Series No. NS-R-1 on Safety of Nuclear Power Plants: Design, which it supplements. This Safety Guide describes how the requirements for the design of the reactor coolant system (RCS) and associated systems in nuclear power plants should be met. 1.2. This publication is a revision and combination of two previous Safety Guides, Safety Series No. 50-SG-D6 on Ultimate Heat Sink and Directly Associated Heat Transport Systems for Nuclear Power Plants (1981), and Safety Series No. 50-SG-D13 on Reactor Coolant and Associated Systems in Nuclear Power Plants (1986), which are superseded by this new Safety Guide. 1.3. The revision takes account of developments in the design of the RCS and associated systems in nuclear power plants since the earlier Safety Guides were published in 1981 and 1986, respectively. The other objectives of the revision are to ensure consistency with Ref., issued in 2000, and to update the technical content. In addition, an appendix on pressurized heavy water reactors (PHWRs) has been included

  5. DESIGN PACKAGE 1E SYSTEM SAFETY ANALYSIS

    Energy Technology Data Exchange (ETDEWEB)

    M. Salem

    1995-06-23

    The purpose of this analysis is to systematically identify and evaluate hazards related to the Yucca Mountain Project Exploratory Studies Facility (ESF) Design Package 1E, Surface Facilities, (for a list of design items included in the package 1E system safety analysis see section 3). This process is an integral part of the systems engineering process; whereby safety is considered during planning, design, testing, and construction. A largely qualitative approach was used since a radiological System Safety Analysis is not required. The risk assessment in this analysis characterizes the accident scenarios associated with the Design Package 1E structures/systems/components(S/S/Cs) in terms of relative risk and includes recommendations for mitigating all identified risks. The priority for recommending and implementing mitigation control features is: (1) Incorporate measures to reduce risks and hazards into the structure/system/component design, (2) add safety devices and capabilities to the designs that reduce risk, (3) provide devices that detect and warn personnel of hazardous conditions, and (4) develop procedures and conduct training to increase worker awareness of potential hazards, on methods to reduce exposure to hazards, and on the actions required to avoid accidents or correct hazardous conditions.

  6. The design and validation of advanced operator support systems for a role in plant safety

    International Nuclear Information System (INIS)

    Hughes, G.

    1989-06-01

    Advanced operator support systems have the potential of making a significant contribution to plant safety. This note reviews the different support functions required, the specification of performance criteria and possible approaches for system validation. The importance of the different functions that can be provided is related to the stage of the accident sequence. Also, because of the restricted reliability of any single system, subdivision of the systems is suggested in order to make the maximum contribution at a number of sequential stages. In this way it should be possible to make a significant claim for reduced operator error over the full accident progression, from incipient fault to disaster. The use of performance criteria currently associated with the classification of safety-grade trip systems (e.g. detection failure probability) would seem to provide a sound basis for validation. The validation of systems is seen as a significant task which will rely on the use of design and training-simulator data together with specific plant measurements. Expert systems appear to present particular problems for validation. (author)

  7. Innovation research on the safety supervision system of nuclear and radiation safety in Jiangsu province

    International Nuclear Information System (INIS)

    Zhang Qihong; Lu Jigen; Zhang Ping; Wang Wanping; Dai Xia

    2012-01-01

    As the rapid development of nuclear technology, the safety supervision of nuclear and radiation becomes very important. The safety radiation frame system should be constructed, the safety super- vision ability for nuclear and radiation should be improved. How to implement effectively above mission should be a new subject of Provincial environmental protection department. Through investigating the innovation of nuclear and radiation supervision system, innovation of mechanism, innovation of capacity, innovation of informatization and so on, the provincial nuclear and radiation safety supervision model is proposed, and the safety framework of nuclear and radiation in Jiangsu is elementally established in the paper. (authors)

  8. Development of the Advanced Nuclear Safety Information Management (ANSIM) System

    Energy Technology Data Exchange (ETDEWEB)

    Sohn, Jae Min; Ko, Young Cheol; Song, Tai Gil [Korea Atomic Energy Research Institute, Daejeon (Korea, Republic of)

    2012-05-15

    Korea has become a technically independent nuclear country and has grown into an exporter of nuclear technologies. Thus, nuclear facilities are increasing in significance at KAERI (Korea Atomic Energy Research Institute), and it is time to address the nuclear safety. The importance of nuclear safety cannot be overemphasized. Therefore, a management system is needed urgently to manage the safety of nuclear facilities and to enhance the efficiency of nuclear information. We have established ISP (Information Strategy Planning) for the Integrated Information System of nuclear facility and safety management. The purpose of this paper is to develop a management system for nuclear safety. Therefore, we developed the Advanced Nuclear Safety Information Management system (hereinafter referred to as the 'ANSIM system'). The ANSIM system has been designed and implemented to computerize nuclear safety information for standardization, integration, and sharing in real-time. Figure 1 shows the main home page of the ANSIM system. In this paper, we describe the design requirements, contents, configurations, and utilizations of the ANSIM system

  9. Software Dependability and Safety Evaluations ESA's Initiative

    Science.gov (United States)

    Hernek, M.

    ESA has allocated funds for an initiative to evaluate Dependability and Safety methods of Software. The objectives of this initiative are; · More extensive validation of Safety and Dependability techniques for Software · Provide valuable results to improve the quality of the Software thus promoting the application of Dependability and Safety methods and techniques. ESA space systems are being developed according to defined PA requirement specifications. These requirements may be implemented through various design concepts, e.g. redundancy, diversity etc. varying from project to project. Analysis methods (FMECA. FTA, HA, etc) are frequently used during requirements analysis and design activities to assure the correct implementation of system PA requirements. The criticality level of failures, functions and systems is determined and by doing that the critical sub-systems are identified, on which dependability and safety techniques are to be applied during development. Proper performance of the software development requires the development of a technical specification for the products at the beginning of the life cycle. Such technical specification comprises both functional and non-functional requirements. These non-functional requirements address characteristics of the product such as quality, dependability, safety and maintainability. Software in space systems is more and more used in critical functions. Also the trend towards more frequent use of COTS and reusable components pose new difficulties in terms of assuring reliable and safe systems. Because of this, its dependability and safety must be carefully analysed. ESA identified and documented techniques, methods and procedures to ensure that software dependability and safety requirements are specified and taken into account during the design and development of a software system and to verify/validate that the implemented software systems comply with these requirements [R1].

  10. Critical Characteristics of Radiation Detection System Components to be Dedicated for use in Safety Class and Safety Significant System

    International Nuclear Information System (INIS)

    DAVIS, S.J.

    2000-01-01

    This document identifies critical characteristics of components to be dedicated for use in Safety Significant (SS) Systems, Structures, or Components (SSCs). This document identifies the requirements for the components of the common, radiation area, monitor alarm in the WESF pool cell. These are procured as Commercial Grade Items (CGI), with the qualification testing and formal dedication to be performed at the Waste Encapsulation Storage Facility (WESF) for use in safety significant systems. System modifications are to be performed in accordance with the approved design. Components for this change are commercially available and interchangeable with the existing alarm configuration This document focuses on the operational requirements for alarm, declaration of the safety classification, identification of critical characteristics, and interpretation of requirements for procurement. Critical characteristics are identified herein and must be verified, followed by formal dedication, prior to the components being used in safety related applications

  11. LOCA analysis of SCWR-M with passive safety system

    Energy Technology Data Exchange (ETDEWEB)

    Liu, X.J., E-mail: xiaojingliu@sjtu.edu.cn [School of Nuclear Science and Engineering, Shanghai Jiao Tong University, 800 Dong Chuan Road, Shanghai 200240 (China); Fu, S.W. [Navy University of Engineering, Wuhan, Hubei (China); Xu, Z.H. [Shanghai Nuclear Engineering Research and Design Institute, Shanghai (China); Yang, Y.H. [School of Nuclear Science and Engineering, Shanghai Jiao Tong University, 800 Dong Chuan Road, Shanghai 200240 (China); Cheng, X. [Institute of Fusion and Nuclear Technology, Karlsruhe Institute of Technology (KIT), Kaiserstr. 12, 76131 Karlsruhe (Germany)

    2013-06-15

    Highlights: • Application of the ATHLET-SC code to the trans-critical analysis for SCWR. • Development of a passive safety system for SCWR-M. • Analysis of hot/cold leg LOCA behaviour with different break size. • Introduction of some mitigation measures for SCWR-M -- Abstract: A new SCWR conceptual design (mixed spectrum supercritical water cooled reactor: SCWR-M) is proposed by Shanghai Jiao Tong University (SJTU). R and D activities covering core design, safety system design and code development of SCWR-M are launched at SJTU. Safety system design and analysis is one of the key tasks during the development of SCWR-M. Considering the current advanced reactor design, a new passive safety system for SCWR-M including isolation cooling system (ICS), accumulator injection system (ACC), gravity driven cooling system (GDCS) and automatic depressurization system (ADS) is proposed. Based on the modified and preliminarily assessed system code ATHLET-SC, loss of coolant accident (LOCA) analysis for hot and cold leg is performed in this paper. Three different break sizes are analyzed to clarify the hot and cold LOCA characteristics of the SCWR-M. The influence of the break location and break size on the safety performance of SCWR-M is also concluded. Several measures to induce the core coolant flow and to mitigate core heating up are also discussed. The results achieved so far demonstrate the feasibility of the proposed passive safety system to keep the SCWR-M core at safety condition during loss of coolant accident.

  12. Applicability of object-oriented design methods and C++ to safety-critical systems

    International Nuclear Information System (INIS)

    Cuthill, B.B.

    1994-01-01

    This paper reports on a study identifying risks and benefits of using a software development methodology containing object-oriented design (OOD) techniques and using C++ as a programming language relative to selected features of safety-critical systems development. These features are modularity, functional diversity, removing ambiguous code, traceability, and real-time performance

  13. Passive safety systems for integral reactors

    International Nuclear Information System (INIS)

    Kuul, V.S.; Samoilov, O.B.

    1996-01-01

    In this paper, a wide range of passive safety systems intended for use on integral reactors is considered. The operation of these systems relies on natural processes and does not require external power supplies. Using these systems, there is the possibility of preventing serious consequences for all classes of accidents including reactivity, loss-of-coolant and loss of heat sink as well as severe accidents. Enhancement of safety system reliability has been achieved through the use of self-actuating devices, capable of providing passive initiation of protective and isolation systems, which respond immediately to variations in the physical parameters of the fluid in the reactor or in a guard vessel. For beyond design base accidents accompanied by complete loss of heat removal capability, autonomous self-actuated ERHR trains have been proposed. These trains are completely independent of the secondary loops and need no action to isolate them from the steam turbine plant. Passive safety principles have been consistently implemented in AST-500, ATETS-200 and VPBER 600 which are new generation NPPs developed by OKBM. Their main characteristic is enhanced stability over a wide range of internal and external emergency initiators. (author). 10 figs

  14. Passive safety systems for integral reactors

    Energy Technology Data Exchange (ETDEWEB)

    Kuul, V S; Samoilov, O B [OKB Mechanical Engineering (Russian Federation)

    1996-12-01

    In this paper, a wide range of passive safety systems intended for use on integral reactors is considered. The operation of these systems relies on natural processes and does not require external power supplies. Using these systems, there is the possibility of preventing serious consequences for all classes of accidents including reactivity, loss-of-coolant and loss of heat sink as well as severe accidents. Enhancement of safety system reliability has been achieved through the use of self-actuating devices, capable of providing passive initiation of protective and isolation systems, which respond immediately to variations in the physical parameters of the fluid in the reactor or in a guard vessel. For beyond design base accidents accompanied by complete loss of heat removal capability, autonomous self-actuated ERHR trains have been proposed. These trains are completely independent of the secondary loops and need no action to isolate them from the steam turbine plant. Passive safety principles have been consistently implemented in AST-500, ATETS-200 and VPBER 600 which are new generation NPPs developed by OKBM. Their main characteristic is enhanced stability over a wide range of internal and external emergency initiators. (author). 10 figs.

  15. Safety of emerging nuclear energy systems

    International Nuclear Information System (INIS)

    Novikov, V.M.; Slesarev, I.S.

    1989-01-01

    The first stage of world nuclear power development based on light water fission reactors has demonstrated not only rather high rate but at the same time too optimistic attitude to safety problems. Large accidents at Three Mile Island and Chernobyl essentially affects the concept of NP development. As a result the safety and social acceptance of NP became of absolute priority among other problems. That's why emerging nuclear power systems should be first of all estimated from this point of view. In the paper some quantitative criteria of safety derived from estimations of social risk and economic-ecological damage from hypothetical accidents are formulated. On the base of these criteria we define two stages of possible way to meet safety demands: first--development of high safety fission reactors and second--that of asymptotic high safety ENEs. The limits of tolorated expenses for safety are regarded. The basis physical factors determining hazards of NES accidents are considered. This permits to classify the ways of safety demands fulfillment due to physical principals used

  16. Development of Network Protocol for the Integrated Safety System

    Energy Technology Data Exchange (ETDEWEB)

    Park, S. W.; Baek, J. I.; Lee, S. H.; Park, C. S.; Park, K. H.; Shin, J. M. [Hannam Univ., Daejeon (Korea, Republic of)

    2007-06-15

    Communication devices in the safety system of nuclear power plants are distinguished from those developed for commercial purposes in terms of a strict requirement of safety. The concept of safety covers the determinability, the reliability, and the separation/isolation to prevent the undesirable interactions among devices. The safety also requires that these properties be never proof less. Most of the current commercialized communication products rarely have the safety properties. Moreover, they can be neither verified nor validated to satisfy the safety property of implementation process. This research proposes the novel architecture and protocol of a data communication network for the safety system in nuclear power plants.

  17. Development of Network Protocol for the Integrated Safety System

    International Nuclear Information System (INIS)

    Park, S. W.; Baek, J. I.; Lee, S. H.; Park, C. S.; Park, K. H.; Shin, J. M.

    2007-06-01

    Communication devices in the safety system of nuclear power plants are distinguished from those developed for commercial purposes in terms of a strict requirement of safety. The concept of safety covers the determinability, the reliability, and the separation/isolation to prevent the undesirable interactions among devices. The safety also requires that these properties be never proof less. Most of the current commercialized communication products rarely have the safety properties. Moreover, they can be neither verified nor validated to satisfy the safety property of implementation process. This research proposes the novel architecture and protocol of a data communication network for the safety system in nuclear power plants

  18. Advances in safety related maintenance

    International Nuclear Information System (INIS)

    2000-03-01

    The maintenance of systems, structures and components in nuclear power plants (NPPs) plays an important role in assuring their safe and reliable operation. Worldwide, NPP maintenance managers are seeking to reduce overall maintenance costs while maintaining or improving the levels of safety and reliability. Thus, the issue of NPP maintenance is one of the most challenging aspects of nuclear power generation. There is a direct relation between safety and maintenance. While maintenance alone (apart from modifications) will not make a plant safer than its original design, deficient maintenance may result in either an increased number of transients and challenges to safety systems or reduced reliability and availability of safety systems. The confidence that NPP structures, systems and components will function as designed is ultimately based on programmes which monitor both their reliability and availability to perform their intended safety function. Because of this, approaches to monitor the effectiveness of maintenance are also necessary. An effective maintenance programme ensures that there is a balance between the improvement in component reliability to be achieved and the loss of component function due to maintenance downtime. This implies that the safety level of an NPP should not be adversely affected by maintenance performed during operation. The nuclear industry widely acknowledges the importance of maintenance in NPP safety and operation and therefore devotes great efforts to develop techniques, methods and tools to aid in maintenance planning, follow-up and optimization, and in assuring the effectiveness of maintenance

  19. Five-Year Safety and Performance Results from the Argus II Retinal Prosthesis System Clinical Trial.

    Science.gov (United States)

    da Cruz, Lyndon; Dorn, Jessy D; Humayun, Mark S; Dagnelie, Gislin; Handa, James; Barale, Pierre-Olivier; Sahel, José-Alain; Stanga, Paulo E; Hafezi, Farhad; Safran, Avinoam B; Salzmann, Joel; Santos, Arturo; Birch, David; Spencer, Rand; Cideciyan, Artur V; de Juan, Eugene; Duncan, Jacque L; Eliott, Dean; Fawzi, Amani; Olmos de Koo, Lisa C; Ho, Allen C; Brown, Gary; Haller, Julia; Regillo, Carl; Del Priore, Lucian V; Arditi, Aries; Greenberg, Robert J

    2016-10-01

    The Argus II Retinal Prosthesis System (Second Sight Medical Products, Inc, Sylmar, CA) was developed to restore some vision to patients blind as a result of retinitis pigmentosa (RP) or outer retinal degeneration. A clinical trial was initiated in 2006 to study the long-term safety and efficacy of the Argus II System in patients with bare or no light perception resulting from end-stage RP. Prospective, multicenter, single-arm clinical trial. Within-patient controls included the nonimplanted fellow eye and patients' native residual vision compared with their vision with the Argus II. Thirty participants in 10 centers in the United States and Europe. The worse-seeing eye of blind patients was implanted with the Argus II. Patients wore glasses mounted with a small camera and a video processor that converted images into stimulation patterns sent to the electrode array on the retina. The primary outcome measures were safety (the number, seriousness, and relatedness of adverse events) and visual function, as measured by 3 computer-based, objective tests. Secondary measures included functional vision performance on objectively scored real-world tasks. Twenty-four of 30 patients remained implanted with functioning Argus II Systems at 5 years after implantation. Only 1 additional serious adverse event was experienced after the 3-year time point. Patients performed significantly better with the Argus II on than off on all visual function tests and functional vision tasks. The 5-year results of the Argus II trial support the long-term safety profile and benefit of the Argus II System for patients blind as a result of RP. The Argus II is the first and only retinal implant to have market approval in the European Economic Area, the United States, and Canada. Copyright © 2016 American Academy of Ophthalmology. Published by Elsevier Inc. All rights reserved.

  20. Finite mixture models for sensitivity analysis of thermal hydraulic codes for passive safety systems analysis

    Energy Technology Data Exchange (ETDEWEB)

    Di Maio, Francesco, E-mail: francesco.dimaio@polimi.it [Energy Department, Politecnico di Milano, Via La Masa 34, 20156 Milano (Italy); Nicola, Giancarlo [Energy Department, Politecnico di Milano, Via La Masa 34, 20156 Milano (Italy); Zio, Enrico [Energy Department, Politecnico di Milano, Via La Masa 34, 20156 Milano (Italy); Chair on System Science and Energetic Challenge Fondation EDF, Ecole Centrale Paris and Supelec, Paris (France); Yu, Yu [School of Nuclear Science and Engineering, North China Electric Power University, 102206 Beijing (China)

    2015-08-15

    Highlights: • Uncertainties of TH codes affect the system failure probability quantification. • We present Finite Mixture Models (FMMs) for sensitivity analysis of TH codes. • FMMs approximate the pdf of the output of a TH code with a limited number of simulations. • The approach is tested on a Passive Containment Cooling System of an AP1000 reactor. • The novel approach overcomes the results of a standard variance decomposition method. - Abstract: For safety analysis of Nuclear Power Plants (NPPs), Best Estimate (BE) Thermal Hydraulic (TH) codes are used to predict system response in normal and accidental conditions. The assessment of the uncertainties of TH codes is a critical issue for system failure probability quantification. In this paper, we consider passive safety systems of advanced NPPs and present a novel approach of Sensitivity Analysis (SA). The approach is based on Finite Mixture Models (FMMs) to approximate the probability density function (i.e., the uncertainty) of the output of the passive safety system TH code with a limited number of simulations. We propose a novel Sensitivity Analysis (SA) method for keeping the computational cost low: an Expectation Maximization (EM) algorithm is used to calculate the saliency of the TH code input variables for identifying those that most affect the system functional failure. The novel approach is compared with a standard variance decomposition method on a case study considering a Passive Containment Cooling System (PCCS) of an Advanced Pressurized reactor AP1000.

  1. National Food Safety Systems in the European Union: A Comparative Survey

    Directory of Open Access Journals (Sweden)

    Andreas Hadjigeorgiou

    2013-04-01

    Full Text Available This paper is a comparative survey of the National Food Safety Systems (NFSS of the European Union (EU Member-States (MS and the Central EU level. The main organizational structures of the NFSS, their legal frameworks, their responsibilities, their experiences, and challenges relating to food safety are discussed. Growing concerns about food safety have led the EU itself, its MS and non-EU countries, which are EU trade-partners, to review and modify their food safety systems. Our study suggests that the EU and 22 out of 27 Member States (MS have reorganized their NFSS by establishing a single food safety authority or a similar organization on the national or central level. In addition, the study analyzes different approaches towards the establishment of such agencies. Areas where marked differences in approaches were seen included the division of responsibilities for risk assessment (RA, risk management (RM, and risk communication (RC. We found that in 12 Member States, all three areas of activity (RA, RM, and RC are kept together, whereas in 10 Member States, risk management is functionally or institutionally separate from risk assessment and risk communication. No single ideal model for others to follow for the organization of a food safety authority was observed; however, revised NFSS, either in EU member states or at the EU central level, may be more effective from the previous arrangements, because they provide central supervision, give priority to food control programs, and maintain comprehensive risk analysis as part of their activities.

  2. Survey of systems safety analysis methods and their application to nuclear waste management systems

    International Nuclear Information System (INIS)

    Pelto, P.J.; Winegardner, W.K.; Gallucci, R.H.V.

    1981-11-01

    This report reviews system safety analysis methods and examines their application to nuclear waste management systems. The safety analysis methods examined include expert opinion, maximum credible accident approach, design basis accidents approach, hazard indices, preliminary hazards analysis, failure modes and effects analysis, fault trees, event trees, cause-consequence diagrams, G0 methodology, Markov modeling, and a general category of consequence analysis models. Previous and ongoing studies on the safety of waste management systems are discussed along with their limitations and potential improvements. The major safety methods and waste management safety related studies are surveyed. This survey provides information on what safety methods are available, what waste management safety areas have been analyzed, and what are potential areas for future study

  3. Survey of systems safety analysis methods and their application to nuclear waste management systems

    Energy Technology Data Exchange (ETDEWEB)

    Pelto, P.J.; Winegardner, W.K.; Gallucci, R.H.V.

    1981-11-01

    This report reviews system safety analysis methods and examines their application to nuclear waste management systems. The safety analysis methods examined include expert opinion, maximum credible accident approach, design basis accidents approach, hazard indices, preliminary hazards analysis, failure modes and effects analysis, fault trees, event trees, cause-consequence diagrams, G0 methodology, Markov modeling, and a general category of consequence analysis models. Previous and ongoing studies on the safety of waste management systems are discussed along with their limitations and potential improvements. The major safety methods and waste management safety related studies are surveyed. This survey provides information on what safety methods are available, what waste management safety areas have been analyzed, and what are potential areas for future study.

  4. An Online Risk Monitor System (ORMS) to Increase Safety and Security Levels in Industry

    International Nuclear Information System (INIS)

    Zubair, M; Ur Rahman, Khalil; Ul Hassan, Mehmood

    2013-01-01

    The main idea of this research is to develop an Online Risk Monitor System (ORMS) based on Living Probabilistic Safety Assessment (LPSA). The article highlights the essential features and functions of ORMS. The basic models and modules such as, Reliability Data Update Model (RDUM), running time update, redundant system unavailability update, Engineered Safety Features (ESF) unavailability update and general system update have been described in this study. ORMS not only provides quantitative analysis but also highlights qualitative aspects of risk measures. ORMS is capable of automatically updating the online risk models and reliability parameters of equipment. ORMS can support in the decision making process of operators and managers in Nuclear Power Plants

  5. An Online Risk Monitor System (ORMS) to Increase Safety and Security Levels in Industry

    Science.gov (United States)

    Zubair, M.; Rahman, Khalil Ur; Hassan, Mehmood Ul

    2013-12-01

    The main idea of this research is to develop an Online Risk Monitor System (ORMS) based on Living Probabilistic Safety Assessment (LPSA). The article highlights the essential features and functions of ORMS. The basic models and modules such as, Reliability Data Update Model (RDUM), running time update, redundant system unavailability update, Engineered Safety Features (ESF) unavailability update and general system update have been described in this study. ORMS not only provides quantitative analysis but also highlights qualitative aspects of risk measures. ORMS is capable of automatically updating the online risk models and reliability parameters of equipment. ORMS can support in the decision making process of operators and managers in Nuclear Power Plants.

  6. Overview of Risk Mitigation for Safety-Critical Computer-Based Systems

    Science.gov (United States)

    Torres-Pomales, Wilfredo

    2015-01-01

    This report presents a high-level overview of a general strategy to mitigate the risks from threats to safety-critical computer-based systems. In this context, a safety threat is a process or phenomenon that can cause operational safety hazards in the form of computational system failures. This report is intended to provide insight into the safety-risk mitigation problem and the characteristics of potential solutions. The limitations of the general risk mitigation strategy are discussed and some options to overcome these limitations are provided. This work is part of an ongoing effort to enable well-founded assurance of safety-related properties of complex safety-critical computer-based aircraft systems by developing an effective capability to model and reason about the safety implications of system requirements and design.

  7. Simplified safety and containment systems for the iris reactor

    International Nuclear Information System (INIS)

    Conway, L.E.; Lombardi, C.; Ricotti, M.; Oriani, L.

    2001-01-01

    The IRIS (International Reactor Innovative and Secure) is a 100 - 300 MW modular type pressurized water reactor supported by the U.S. DOE NERI Program. IRIS features a long-life core to provide proliferation resistance and to reduce the volume of spent fuel, as well as reduce maintenance requirements. IRIS utilizes an integral reactor vessel that contains all major primary system components. This integral reactor vessel makes it possible to reduce containment size; making the IRIS more cost competitive. IRIS is being designed to enhance reactor safety, and therefore a key aspect of the IRIS program is the development of the safety and containment systems. These systems are being designed to maximize containment integrity, prevent core uncover following postulated accidents, minimize the probability and consequences of severe accidents, and provide a significant simplification over current safety system designs. The design of the IRIS containment and safety systems has been identified and preliminary analyses have been completed. The IRIS safety concept employs some unique features that minimize the consequences of postulated design basis events. This paper will provide a description of the containment design and safety systems, and will summarize the analysis results. (author)

  8. Autonomous system for launch vehicle range safety

    Science.gov (United States)

    Ferrell, Bob; Haley, Sam

    2001-02-01

    The Autonomous Flight Safety System (AFSS) is a launch vehicle subsystem whose ultimate goal is an autonomous capability to assure range safety (people and valuable resources), flight personnel safety, flight assets safety (recovery of valuable vehicles and cargo), and global coverage with a dramatic simplification of range infrastructure. The AFSS is capable of determining current vehicle position and predicting the impact point with respect to flight restriction zones. Additionally, it is able to discern whether or not the launch vehicle is an immediate threat to public safety, and initiate the appropriate range safety response. These features provide for a dramatic cost reduction in range operations and improved reliability of mission success. .

  9. System code improvements for modelling passive safety systems and their validation

    Energy Technology Data Exchange (ETDEWEB)

    Buchholz, Sebastian; Cron, Daniel von der; Schaffrath, Andreas [Gesellschaft fuer Anlagen- und Reaktorsicherheit (GRS) gGmbH, Garching (Germany)

    2016-11-15

    GRS has been developing the system code ATHLET over many years. Because ATHLET, among other codes, is widely used in nuclear licensing and supervisory procedures, it has to represent the current state of science and technology. New reactor concepts such as Generation III+ and IV reactors and SMR are using passive safety systems intensively. The simulation of passive safety systems with the GRS system code ATHLET is still a big challenge, because of non-defined operation points and self-setting operation conditions. Additionally, the driving forces of passive safety systems are smaller and uncertainties of parameters have a larger impact than for active systems. This paper addresses the code validation and qualification work of ATHLET on the example of slightly inclined horizontal heat exchangers, which are e. g. used as emergency condensers (e. g. in the KERENA and the CAREM) or as heat exchanger in the passive auxiliary feed water systems (PAFS) of the APR+.

  10. Using field feedback to estimate failure rates of safety-related systems

    International Nuclear Information System (INIS)

    Brissaud, Florent

    2017-01-01

    The IEC 61508 and IEC 61511 functional safety standards encourage the use of field feedback to estimate the failure rates of safety-related systems, which is preferred than generic data. In some cases (if “Route 2_H” is adopted for the 'hardware safety integrity constraints”), this is even a requirement. This paper presents how to estimate the failure rates from field feedback with confidence intervals, depending if the failures are detected on-line (called 'detected failures', e.g. by automatic diagnostic tests) or only revealed by proof tests (called 'undetected failures'). Examples show that for the same duration and number of failures observed, the estimated failure rates are basically higher for “undetected failures” because, in this case, the duration observed includes intervals of time where it is unknown that the elements have failed. This points out the need of using a proper approach for failure rates estimation, especially for failures that are not detected on-line. Then, this paper proposes an approach to use the estimated failure rates, with their uncertainties, for PFDavg and PFH assessment with upper confidence bounds, in accordance with IEC 61508 and IEC 61511 requirements. Examples finally show that the highest SIL that can be claimed for a safety function can be limited by the 90% upper confidence bound of PFDavg or PFH. The requirements of the IEC 61508 and IEC 61511 relating to the data collection and analysis should therefore be properly considered for the study of all safety-related systems. - Highlights: • This paper deals with requirements of the IEC 61508 and IEC 61511 for using field feedback to estimate failure rates of safety-related systems. • This paper presents how to estimate the failure rates from field feedback with confidence intervals for failures that are detected on-line. • This paper presents how to estimate the failure rates from field feedback with confidence intervals for failures that are only revealed by

  11. A cloud medication safety support system using QR code and Web services for elderly outpatients.

    Science.gov (United States)

    Tseng, Ming-Hseng; Wu, Hui-Ching

    2014-01-01

    Drug is an important part of disease treatment, but medication errors happen frequently and have significant clinical and financial consequences. The prevalence of prescription medication use among the ambulatory adult population increases with advancing age. Because of the global aging society, outpatients need to improve medication safety more than inpatients. The elderly with multiple chronic conditions face the complex task of medication management. To reduce the medication errors for the elder outpatients with chronic diseases, a cloud medication safety supporting system is designed, demonstrated and evaluated. The proposed system is composed of a three-tier architecture: the front-end tier, the mobile tier and the cloud tier. The mobile tier will host the personalized medication safety supporting application on Android platforms that provides some primary functions including reminders for medication, assistance with pill-dispensing, recording of medications, position of medications and notices of forgotten medications for elderly outpatients. Finally, the hybrid technology acceptance model is employed to understand the intention and satisfaction level of the potential users to use this mobile medication safety support application system. The result of the system acceptance testing indicates that this developed system, implementing patient-centered services, is highly accepted by the elderly. This proposed M-health system could assist elderly outpatients' homecare in preventing medication errors and improving their medication safety.

  12. Aviation Safety Hotline Information System -

    Data.gov (United States)

    Department of Transportation — The Aviation Safety Hotline Information System (ASHIS) collects, stores, and retrieves reports submitted by pilots, mechanics, cabin crew, passengers, or the public...

  13. Total Quality Management and the System Safety Secretary

    Science.gov (United States)

    Elliott, Suzan E.

    1993-01-01

    The system safety secretary is a valuable member of the system safety team. As downsizing occurs to meet economic constraints, the Total Quality Management (TQM) approach is frequently adopted as a formula for success and, in some cases, for survival.

  14. Guards: An approach safety-related systems using cots example of MMI and reactor automation in nuclear submarine application

    International Nuclear Information System (INIS)

    Brun, M.

    1998-01-01

    For at least 10 years, the nuclear industry designs and licences specific digital safety-critical systems (IEC 1226 class A). One key issue for future programs is to design and licence safety-related systems providing more complex functions and using Commercial-Off-The-Shelf components. This issue is especially raised for Reactor automation and Man-Machine-Interface. The usual I and C (Instrumentation and Control) organisation for these functions is based on redundancy between a commercial, up-to-date, unclassified > system and a simplified classified > system using traditional technologies. It clearly appears that such organisation is not satisfying from the point of view of people who have actually to operate these systems: The operator is supposed not to trust the normal system and rely on the back-up system which is less helpful and that he use very few. This paper presents a new approach to that problem using COTS components in low-level layers, safety architecture and mechanisms at medium level layer (GUARDS architecture developed in the current ESPRIT project number 20716), and a pre-validated functional layer. The aim of this solution is to comply with the > IEC 1226 class B requirements, at lower overall cost (design, implementation, licensing, long term confidence). This approach is illustrated by its application in Man-Machine-Interface (MMI) for our future program of Nuclear submarine. (author)

  15. Reactivity requirements and safety systems for heavy water reactors

    International Nuclear Information System (INIS)

    Kati, S.L.; Rustagi, R.S.

    1977-01-01

    The natural uranium fuelled pressurised heavy water reactors are currently being installed in India. In the design of nuclear reactors, adequate attention has to be given to the safety systems. In recent years, several design modifications having bearing on safety, in the reactor processes, protective and containment systems have been made. These have resulted either from new trends in safety and reliability standards or as a result of feed-back from operating reactors of this type. The significant areas of modifications that have been introduced in the design of Indian PHWR's are: sophisticated theoretical modelling of reactor accidents, reactivity control, two independent fast acting systems, full double containment and improved post-accident depressurisation and building clean-up. This paper brings out the evolution of design of safety systems for heavy water reactors. A short review of safety systems which have been used in different heavy water reactors, of varying sizes, has been made. In particular, the safety systems selected for the latest 235 MWe twin reactor unit station in Narora, in Northern India, have been discussed in detail. Research and Development efforts made in this connection are discussed. The experience of design and operation of the systems in Rajasthan and Kalpakkam reactors has also been outlined

  16. Safety implications of control systems

    International Nuclear Information System (INIS)

    Smith, O.L.

    1983-01-01

    The Safety Implications of Control Systems Program has three major activities in support of USI-A47. The first task is a failure mode and effects analysis of all plant systems which may potentially induce control system disturbance that have safety implications. This task has made a preliminary study of overfill events and recommended cases for further analysis on the hybrid simulator. Work continues on overcooling and undercooling. A detailed investigation of electric power network is in progress. LERs are providing guidance on important failure modes that will provide initial conditions for further simulator studies. The simulator taks is generating a detailed model of the control system supported by appropriate neutronics, hydraulics, and thermodynamics submodels of all other principal plant components. The simulator is in the last stages of development. Checkout calculations are in progress to establish model stability, robustness, and qualitative credibility. Verification against benchmark codes and plant data will follow

  17. The micro-processor controlled process radiation monitoring system for reactor safety systems

    International Nuclear Information System (INIS)

    Mizuno, K.; Noguchi, A.; Kumagami, S.; Gotoh, Y.; Kumahara, T.; Arita, S.

    1986-01-01

    Digital computers are soon expected to be applied to various real-time safety and safety-related systems in nuclear power plants. Hitachi is now engaged in the development of a micro-processor controlled process radiation monitoring system, which operates on digital processing methods employed with a log ratemeter. A newly defined methodology of design and test procedures is being applied as a means of software program verification for these safety systems. Recently implemented micro-processor technology will help to achieve an advanced man-machine interface and highly reliable performance. (author)

  18. Developing safety performance functions incorporating reliability-based risk measures.

    Science.gov (United States)

    Ibrahim, Shewkar El-Bassiouni; Sayed, Tarek

    2011-11-01

    Current geometric design guides provide deterministic standards where the safety margin of the design output is generally unknown and there is little knowledge of the safety implications of deviating from these standards. Several studies have advocated probabilistic geometric design where reliability analysis can be used to account for the uncertainty in the design parameters and to provide a risk measure of the implication of deviation from design standards. However, there is currently no link between measures of design reliability and the quantification of safety using collision frequency. The analysis presented in this paper attempts to bridge this gap by incorporating a reliability-based quantitative risk measure such as the probability of non-compliance (P(nc)) in safety performance functions (SPFs). Establishing this link will allow admitting reliability-based design into traditional benefit-cost analysis and should lead to a wider application of the reliability technique in road design. The present application is concerned with the design of horizontal curves, where the limit state function is defined in terms of the available (supply) and stopping (demand) sight distances. A comprehensive collision and geometric design database of two-lane rural highways is used to investigate the effect of the probability of non-compliance on safety. The reliability analysis was carried out using the First Order Reliability Method (FORM). Two Negative Binomial (NB) SPFs were developed to compare models with and without the reliability-based risk measures. It was found that models incorporating the P(nc) provided a better fit to the data set than the traditional (without risk) NB SPFs for total, injury and fatality (I+F) and property damage only (PDO) collisions. Copyright © 2011 Elsevier Ltd. All rights reserved.

  19. Mathematical Safety Assessment Approaches for Thermal Power Plants

    Directory of Open Access Journals (Sweden)

    Zong-Xiao Yang

    2014-01-01

    Full Text Available How to use system analysis methods to identify the hazards in the industrialized process, working environment, and production management for complex industrial processes, such as thermal power plants, is one of the challenges in the systems engineering. A mathematical system safety assessment model is proposed for thermal power plants in this paper by integrating fuzzy analytical hierarchy process, set pair analysis, and system functionality analysis. In the basis of those, the key factors influencing the thermal power plant safety are analyzed. The influence factors are determined based on fuzzy analytical hierarchy process. The connection degree among the factors is obtained by set pair analysis. The system safety preponderant function is constructed through system functionality analysis for inherence properties and nonlinear influence. The decision analysis system is developed by using active server page technology, web resource integration, and cross-platform capabilities for applications to the industrialized process. The availability of proposed safety assessment approach is verified by using an actual thermal power plant, which has improved the enforceability and predictability in enterprise safety assessment.

  20. The Detector Safety System of the ATLAS experiment

    International Nuclear Information System (INIS)

    Beltramello, O; Burckhart, H J; Franz, S; Jaekel, M; Jeckel, M; Lueders, S; Morpurgo, G; Santos Pedrosa, F dos; Pommes, K; Sandaker, H

    2009-01-01

    The ATLAS detector at the Large Hadron Collider at CERN is one of the most advanced detectors for High Energy Physics experiments ever built. It consists of the order of ten functionally independent sub-detectors, which all have dedicated services like power, cooling, gas supply. A Detector Safety System has been built to detect possible operational problems and abnormal and potentially dangerous situations at an early stage and, if needed, to bring the relevant part of ATLAS automatically into a safe state. The procedures and the configuration specific to ATLAS are described in detail and first operational experience is given.