REINFORCEMENT OF DEFENCE-IN-DEPTH: MODIFICATION PRACTICE AFTER THE FUKUSHIMA NUCLEAR ACCIDENT
3. ELEMENTS OF THE OPT
3.1. Levels of the Defence in depth (DiD)
According to [5] Defence in depth is generally structured in five levels. Should one level fail, the subsequent level comes into play.
The objective of the first level of protection is the prevention of abnormal operation and system failures. If the first level fails, abnormal operation is controlled or failures are detected by the second level of protection. Should the second level fail, the third level ensures that safety functions are further performed by activating specific safety systems and other safety features. Should the third level fail, the fourth level limits accident progression through accident management, so as to prevent or mitigate severe accident conditions with external releases of radioactive materials. The last objective (fifth level of protection) is the mitigation of the radiological consequences of significant external releases through the off-site emergency response.”
3.2. Safety Functions
Safe design in general is characterized by the simultaneous control of the following safety functions (SF): a) Containment of hazardous materials; b) Control of chain reactions;
c) Control of removal of the energy produced; d) Control of radiation protection; e) Control of non-nuclear risks. Other functions are implicit in that their compliance is ensured by the compliance with functions a) to d) above, e.g.: f) Control of public health and environmental protection (see for example the Article 28 of the French TSN law - 2006).
3.3. Safety objectives
As indicated above, the rationale for the safety architecture, after a given initiating event, is to maintain or bring back the plant to a safe state, i.e. to achieve a consistent set of safety functions while meeting the safety objectives.
The initiating events, once identified, are categorized following their estimated frequency of occurrence. For each category, quantitative safety objectives are usually suggested by the designer and endorsed by the regulators; this allows defining the space of acceptable risk: frequency of occurrence – allowable consequences (i.e. the so called “Farmer curve”8).
7 i.e. Safety requirements and objectives will be specific of the level of the DiD.
8 The latter is obviously perfectly coherent with the IAEA Technical Safety Objective: …. to ensure with a high level of confidence that, for all possible accidents taken into account in the design of the installation, including those of very low probability, any radiological consequences would be minor and below prescribed limits; and to ensure that the likelihood of accidents with serious radiological consequences is extremely low (Safety of Nuclear Power Plants: Design, IAEA Publication NS-R-1, Page 4.)
48
The proposal of WENRA/RHWG [6] shows that there is a direct relationship between the defence in depth and the “allowable risk domain”. This is essential for the designer who can so superpose the levels of defence in depth within the area of allowable risk, and simultaneously, to give explicit targets (success criteria, both in terms of performances and reliability) for these levels. These targets are essential to size the provisions that are associated with each level of the DiD. Under these conditions, for a given SF, the objectives corresponding to a given level of DiD are translated into physical parameters or “decoupling criteria” that reflect the allowable consequences associated with this level of DiD9. So, for each of the safety functions, representative parameters (Figures of Merit - FoM, or decoupling criteria) can be identified with associated values that reflect compliance with safety objectives.
One can point out that, in the early phases, which correspond to the preliminary identification of Challenges Mechanisms Provisions, it is not necessary to have precise quantitative targets; orders of magnitude will be sufficient to select the provisions that designer feels able to comply with objectives. These quantitative values are nonetheless required later in the design process for the exact sizing of the implemented provisions10.
3.4. Challenges
As indicated above a challenge represents a potential mode of aggression to a safety function, which could lead to exceeded allowable values for FoM and therefore non-compliance with safety objectives.
One may wonder to what extent it is possible to define "challenges" that are independent of technology and dependent only on the safety function under consideration. In practice this seems feasible:
• For the "Containment of hazardous materials", challenges result in possible aggressions on barriers; the parameters that characterize these aggressions are those that materialize the loads on barriers (harsh environment, e.g., pressure, temperature, radiation, missiles, etc.). An example of a challenge for this function is, for example, the “abnormal thermal and or mechanical stresses on first barrier”
• For the “Control of chain reactions” the challenges reflect the potential for alterations of the core/fuel keff (excessive variation of keff through local or global reactivity injection).
Opportunities for positive or negative reactivity insertions must be considered. The representative parameters are those characterizing the reactivity in the core / fuel (reactivity introduced, counter reactions coefficients, etc.). In this case, an example of a challenge is “insertion of positive reactivity”.
• For the “Control of removal of the energy produced” the challenges correspond to possible loss of integrity of the facility structures, e.g. fuel matrix, cladding, primary circuit structures, etc.. The representative parameters are loads on these structures (pressures, temperatures, etc.). An example of challenge to this function is the
“degradation of the residual heat removal path”
9 For example, for the “Control of removal of the energy produced”, and the third level DiD applicable to a nuclear reactor - Prevention of the core deterioration and the potential aggression of containment - the decoupling criteria are represented by the fuel temperature and / or the temperature of the core structures which determine the beginning of the loss of geometry (e.g. in the case of conventional solid fuel: the fuel / cladding melting temperature).
10 Example: for the Decay Heat Removal (DHR) the designer asks for an order of magnitude for the required coolant’s flow. This order of magnitude is sufficient to choose the nature of the "provision" that will be implemented (e.g. for an SFR: mechanical pump or electromagnetic pump). During the detailed design phase the designer will size precisely the selected provision
49
• For the “Control of Radiation protection” challenges reflect alterations for protection measures against ionising radiation and in particular of the conditions under which operators are required to work. Potential for internal and / or external exposures should be considered. The first (internal exposures, e.g. after inhalation) would be caused by a prior loss of containment function. Concerning the external exposure, the parameters that characterize protection against sources are the distance, the activity, the time and the screens11. Under these conditions one can consider that alterations - or misconceptions - that would affect one or more of these parameters represent the potential challenges to the function. An example is the “Abnormal exposure under maintenance conditions”.
• For the “Control of Non-nuclear risks” challenges reflect changes in environmental conditions that alter the loading conditions on the facility structures and / or, where applicable, the operating conditions. They may be due to chemical or thermodynamic reactions12. The representative parameters are loads on structures and possible abnormal conditions the operator intervention (pressure, temperature, humidity, visibility, etc.) 13. An example of challenge for this function is the “Explosion”.
Following the examples cited above it seems that the process of identifying the challenges could be neutral versus the technology, i.e., the identified challenges will be neutral vis-à-vis of the reviewed technology. Needless to say that, for the OPT methodology effectiveness, the effort to identify challenges needs to be explicit and as comprehensive as practicable.
3.5. Initiating events (mechanisms)
For the technology and the concept under examination (e.g. Sodium cooled Fast Reactor - SFR, pool concept), each challenge is materialized by a set of mechanisms / initiating events. These initiating events are obviously specific for the concept, and even specific for a given type of concept (e.g. SFR with or without intermediate circuit). The designer shall seek systematically mechanisms / initiating events among the plausible phenomena that are either related to the specific technology under consideration (e.g. sodium fires), or induced by the provisions already implemented (e.g. withdrawal of a control rod). Finally it should be noted that in case of application of deterministic rules (e.g., single failure criterion) the design of the needed provisions may postulate degradations without direct and explicit link to a specific challenge. However, despite this prescriptive approach the mechanism should be correlated, a posteriori, to a challenges among those identified; nothing changes in the process for the identification of provisions needed for its control and the mitigation of its consequences.
3.6. Provisions & LOP
Once the initiating events are identified, the designer must specify, for each event, the provisions that are integrated into the architecture to manage their advent and control /mitigate their consequences. All provisions which collectively perform the required duties are grouped in a line of protection (LOP) whose overall performance in terms of reliability and efficiency, allow the realization of the mission requirements and the meeting of the safety objectives. It is important to note that, in terms of overall LOP performance, for example with
11 In French: Distance, Activité, Temps & Ecrans (DATE)
12 e.g. sodium fires for the sodium cooled fast reactor (SFR)
13 e.g. the presence of aerosols that would impede a given intervention. These conditions are considered reflecting the functional aspects.
50
the search for the LOP reliability that is needed to prepare a Probabilistic Safety Analysis (PSA), it is the characteristics of the lower reliability provision (i.e. the “weakest link”) that will define the representative value for the reliability14.
3.7. The OPT: an interesting tool to address the security concerns
It is interesting to point out that, as indicated for example by WENRA [7]15, the integration of safety and security concerns (i.e. physical protection and proliferation resistance) should be searched at the design level. This integration could be done, with logic similar to that of OPT, i.e. searching and organizing synergistically specific security provisions for the control of these concerns, through the consideration of “security functions”
such as, for example:
• control of flows of hazardous materials;
• protection against malevolent hazards.
As for the function f) above (cf. § 3.2), one can consider that the “protection against malevolent hazards” is implicitly performed by the respect of safety functions listed above (“a” to “e”) with, if necessary, the implementation of specific provisions16.
Downstream the definition of the security function, the logic for the identification of the provisions, which will be specific to ensure the security of the plant, can be analogous to that for the safety functions. So, the comparable representation of the safety and the security