Model checking reveals design issues leading to spurious actuation of nuclear instrumentation and control systems
Creators
- 1. VTT Technical Research Centre of Finland Ltd., P.O. Box 1000, FI-02044 VTT (Finland)
- 2. Computer Technologies Laboratory, ITMO University, 197101 St. Petersburg (Russian Federation)
- 3. Department of Electrical Engineering and Automation, Aalto University, P.O. Box 11000, FI-00076 Aalto (Finland)
Description
Highlights: • Model checking revealed 57 I&C software design issues in nuclear power plants. • 37% of the detected issues could have led to spurious actuation of I&C functions. • Spurious actuation can be detected under the presence of injected hardware failures. • Analysts need to focus on specifying properties for unwanted system behaviour. A spurious actuation of an industrial instrumentation and control (I&C) system is a failure mode where the system or its component inadvertently produces an operation without a justified reason to do so. Design issues leading to spurious failures are difficult to analyse, but pose a high risk for safety. Model checking is a formal verification method that can be used for exhaustive analysis of I&C systems. In this paper, we explain how formal properties that address spurious failures can be specified, and how model checking can then be used to verify I&C application logic designs based on vendor-specific function block diagrams. Based on over ten years of successful practical projects in the Finnish nuclear industry, we present 21 real-world design issues (representing 37% of all detected issues), each involving a systemic failure that could lead to spurious actuation of nuclear safety I&C. We then describe how random failures of the underlying hardware architecture—another cause for spurious actuation—can also be included in the models. With an experimental evaluation based on real-world nuclear industry models, we demonstrate that our method can be effectively used for the verification of single failure tolerance.
Availability note (English)
Available from http://dx.doi.org/10.1016/j.ress.2020.107237Additional details
Identifiers
- DOI
- 10.1016/j.ress.2020.107237;
- PII
- S0951832020307377;
Publishing Information
- Journal Title
- Reliability Engineering and System Safety
- Journal Volume
- 205
- Journal Page Range
- vp.
- ISSN
- 0951-8320
- CODEN
- RESSEP
INIS
- Country of Publication
- United Kingdom
- Country of Input or Organization
- International Atomic Energy Agency (IAEA)
- INIS RN
- 54018547
- Subject category
- S22: GENERAL STUDIES OF NUCLEAR REACTORS; S46: INSTRUMENTATION RELATED TO NUCLEAR SCIENCE AND TECHNOLOGY;
- Descriptors DEI
- COMPUTER CODES; CONTROL SYSTEMS; NUCLEAR INDUSTRY; NUCLEAR POWER PLANTS; RADIATION PROTECTION; RANDOMNESS; REACTOR OPERATION; REACTOR SAFETY
- Descriptors DEC
- INDUSTRY; NUCLEAR FACILITIES; OPERATION; POWER PLANTS; REACTOR LIFE CYCLE; SAFETY; THERMAL POWER PLANTS
Optional Information
- Copyright
- Copyright (c) 2020 The Authors. Published by Elsevier Ltd.