REINFORCEMENT OF DEFENCE-IN-DEPTH: MODIFICATION PRACTICE AFTER THE FUKUSHIMA NUCLEAR ACCIDENT
2. OBJECTIVE PROVISION TREE: OBJECTIVES AND SCOPE 1. The logic of the OPT
The approach recommended via the OPT method [1] structures the construction of the safety architecture through the systematic identification, for a given level of defence in depth (DiD), and for each of the safety functions (SF) and the corresponding objectives, of the challenges to the SF under consideration. For each of these challenges, the designer must identify the mechanisms / initiating events which, considering the process and the architecture already in place, materialize the challenge.
For conceptual High Temperature Reactors or existing Light Water Reactors, examples of detailed OPTs have been developed within the context of the IAEA [2, 3]. However, since this is a relatively new tool, an educational effort is needed, in particular, to further understand its objectives, scope, strengths and limitations.
The OPT steps are resumed as follow (cf. Fig.1):
Safety Function: e.g. reactivity control to be performed successfully Challenge: e.g. injection of reactivity to cope with
Mechanism: e.g. control rod withdrawal to be prevented or controlled Once determined the acceptability criteria which, in relation to a given mechanism, guarantee the satisfaction of the safety objectives, the last step is to identify, for each initiating event, the provisions which, collectively, allow to manage the appearance of the event and/or to minimize its consequences.
Provisions: e.g. a limiting removal device & associated I&C
For a given initiating event, these provisions are grouped in a so called “Line of protection” (LOP) whose overall performance, in terms of efficiency and reliability, ensures the achievement of the mission requested to meet the allowable operational criteria (limiting withdrawal device + the I&C for detection, the control and the actuation of the device). It may be noted that, for a given level of defence in depth, the concept of LOP is similar to that of
"layers of provisions" as it is defined in Ref. [4].
The steps described above illustrate how the OPT structures the process of identification of initiating events to be considered in the design, as well as the necessary steps to identify the provisions and so the safety architecture which will allow to control these events and to limit their consequences.
That said a remark may be raised: the events are identified by examining the challenges of a given safety function and, consequently, the related provisions are those that act to control the safety function under consideration. The provisions to be implemented for the simultaneous control of the other safety functions do not appear explicitly and one could wonders if they will appear when reviewing these functions. The objective being to bring
45 back the plant in safe condition2, the mission to be achieved is composite and, of course, the objective is the simultaneous realization of all the safety functions. Considering the remark above, two scenarios are considered:
• If a mechanism / initiating event does disturb / challenges only a safety function (e.g. fuel failure function “Confinement”3), the realization of other SFs, to achieve a safe state, will be done normally, and therefore the “normal” provisions will be requested. Under these conditions it is not necessary to identify specific provisions.
• If, instead, a given mechanism disrupts / challenges simultaneously several safety functions (e.g. injection of positive reactivity power increase), the same mechanism - through induced effects (i.e. fuel and cladding overheating) - necessarily appear among those which will be considered for the challenged functions (control reactivity, heat removal and confinement). Appropriate provisions will therefore be identified, provisions whose performance will necessarily be compatible with the conditions created by the initiating event (e.g. increase of the heat flux, possible localized deformation of the clad, possible clad failure, etc.)
FIG. 1. Objective Provision Tree (OPT): Standard Structure.
2 The safe state is characterized by the mastery of all the safety functions. This is what, within the IAEA documents (e.g. NSSR2-1, [4]) is defined as “Safe state: Plant state, following an anticipated operational occurrence or accident conditions, in which the reactor is subcritical and the fundamental safety functions can be ensured and maintained stable for a long time”.
3Before, of course, a possible degradation of the hydraulic channel around the pin which will disturb the cooling of the fuel element and that will so affect the others safety functions.
Level X of the DiD to meet the specific acceptance criterion.
Together they materialize the notion of
46
2.2. The implementation of the OPT
Regarding the field for the implementation, the OPT method is applicable to concepts that would be at different stages of development:
• To design a concept which is at a preliminary stage (e.g. the Molten Salt Reactor - MSR), the OPT is used to identify initiators and to build - from scratch - the safety architecture.
• To finalize the design of a concept that is advanced or completed (e.g. the JSFR), the OPT can be used to check:
o that all the initiators are adequately addressed;
o that all levels of DiD are properly structured and organized (i.e. the necessary provisions are in place and are sufficient) to achieve the required missions;
o that the mutual independence of the levels of DiD is guaranteed.
According to this last point, coherently with the principles of the DiD, the provisions associated with each level of the DiD must be independent and, if possible, diversified from those allocated to the other levels of the DiD. The objective is to ensure that the failure of a DiD level does not affect the efficiency and the performance of the next level. This must obviously be the case when studying a given event and the sequence(s) generated by the needs of its control (i.e. including the possible failures of the implemented provisions).
More generally one can raise the question of the acceptability of an architecture in which a given provision would be used for different initiating events and / or at different levels of the DiD, i.e. the provision is part of LOPs allocated to different levels of the DiD, depending on the requesting initiating event. This should be possible and allowed if the events which require the provision under consideration are completely independent. One must for example ensure that the solicitation of a provision by a given event, does not affect irreversibly its good behaviour if, once a safety state for system is restored, this provision can be sought for the management of another independent event4.
This can be, for example, the case for shutdown provisions (incorporated within the shutdown system) that can be requested for initiating events which belong to the second level of the DiD (e.g. anticipated operational occurrences) or to the third level for others initiating events (design basis accidents).
Under these conditions one must not hastily conclude that the shutdown system should be doubled and diversified. The architecture must be such that a first failure5, which would occur within the context of the control/management of an initiating event, and that would correspond to the effective deletion of a line of protection which is integral part of the shutdown system, i.e. the failure of a given level of the DiD (n), must be covered by the intervention of functionally redundant provisions; the latter shall guarantee, within the context of the next level of the DiD (n+1) 6, but still as an integral part of the shutdown system, the achievement of the "reactivity control" for the overall sequence: "initiating event + LOP(n) failure."
It remains to check that there are no conflicting implementations for the provisions under examination. From this perspective one can stress that, thanks to its comprehensive
4 It would be, for example the case of a water tank used to remove residual heat under accident conditions and / or to inject water into the primary circuit under analogous or different accident conditions (this was the case for the architecture of an innovative “integrated” PWR in the ‘90ies).
5 This situation does not address the case of the Single Failure Criterion (SFC) which is considered as a rule for the design of a specific LOP (e.g. the blockage of a control rod)
6 i.e., with safety requirements and objectives which are specific of the new level of the DiD.
47 view of the safety architecture, the OPT facilitates the identification of possible conflicts and allows to verify the acceptability of the final architecture.
Finally, one can note that, the safety objectives being variable and dependent upon the category of the initiating event as, a fortiori, upon the DiD level within which the abnormal situation has to be managed, the same provision, implemented at different levels of the DiD for others specific events, will not necessarily be requested to meet the same functional specifications for those different levels7.