WO2017101031A1 - 核电站反应堆保护系统及其中的安全控制方法 - Google Patents

核电站反应堆保护系统及其中的安全控制方法 Download PDF

Info

Publication number
WO2017101031A1
WO2017101031A1 PCT/CN2015/097513 CN2015097513W WO2017101031A1 WO 2017101031 A1 WO2017101031 A1 WO 2017101031A1 CN 2015097513 W CN2015097513 W CN 2015097513W WO 2017101031 A1 WO2017101031 A1 WO 2017101031A1
Authority
WO
WIPO (PCT)
Prior art keywords
protection
shutdown
dedicated
esfas
instruction
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/097513
Other languages
English (en)
French (fr)
Inventor
周叶翔
任立永
田亚杰
史觊
汪伟
梁玲
谭国成
王巧燕
杨震
彭华清
陈卫华
黄伟军
江辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China General Nuclear Power Corp
China Nuclear Power Engineering Co Ltd
Original Assignee
China General Nuclear Power Corp
China Nuclear Power Engineering Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China General Nuclear Power Corp, China Nuclear Power Engineering Co Ltd filed Critical China General Nuclear Power Corp
Priority to PCT/CN2015/097513 priority Critical patent/WO2017101031A1/zh
Publication of WO2017101031A1 publication Critical patent/WO2017101031A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G21NUCLEAR PHYSICS; NUCLEAR ENGINEERING
    • G21CNUCLEAR REACTORS
    • G21C9/00Emergency protection arrangements structurally associated with the reactor, e.g. safety valves provided with pressure equalisation devices
    • GPHYSICS
    • G21NUCLEAR PHYSICS; NUCLEAR ENGINEERING
    • G21DNUCLEAR POWER PLANT
    • G21D3/00Control of nuclear power plant
    • G21D3/04Safety arrangements
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02EREDUCTION OF GREENHOUSE GAS [GHG] EMISSIONS, RELATED TO ENERGY GENERATION, TRANSMISSION OR DISTRIBUTION
    • Y02E30/00Energy generation of nuclear origin
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02EREDUCTION OF GREENHOUSE GAS [GHG] EMISSIONS, RELATED TO ENERGY GENERATION, TRANSMISSION OR DISTRIBUTION
    • Y02E30/00Energy generation of nuclear origin
    • Y02E30/30Nuclear fission reactors

Definitions

  • the present invention relates to the field of nuclear power plants, and in particular, to a nuclear power plant reactor protection system and a safety control method therefor.
  • a protection system In order to ensure the safe operation of the nuclear power plant reactor, a protection system is required.
  • the structural design of the protection system is closely related to the overall design of the nuclear power plant, safety grading, and nuclear DCS (Digital Control System) platform design.
  • the protection system is used to bring the reactor to a safe shutdown state.
  • the design basis accident refers to the accident condition in which the nuclear power plant adopts targeted measures in the design according to the determined design criteria.
  • the safe shutdown state refers to the state in which the reactor is stopped in a controlled manner.
  • the reactor first enters a controllable state, where the controllable state means that the fission chain reaction of the reactor is in a controlled state.
  • the protection system from the occurrence of a design basis accident at the nuclear power plant to the process in which the reactor reaches a controllable state, and the process from the controllable state to the safe shutdown state of the reactor, in addition to realizing the automatic emergency shutdown function of the reactor, It is necessary to perform system-level automatic control processing on the dedicated safety facilities according to the protection parameters. On the other hand, it is necessary to perform equipment-level manual operation processing on the dedicated safety facilities.
  • the special safety facilities refer to the general name of various safety systems specially set up by nuclear power plants that are put into use under accident conditions and perform safety functions to control the consequences of accidents and achieve a stable and acceptable state after the accident. .
  • the present invention provides a nuclear power plant reactor protection system and a safety control method in a nuclear power plant reactor protection system, which can reduce the complexity of the protection system maintenance and periodic test.
  • a nuclear power plant reactor protection system comprising:
  • the emergency shutdown system RTS is divided into N protection channels, N is an even number and N ⁇ 2, and each protection channel is correspondingly connected to a column of signal preprocessing systems, wherein each protection channel is from a corresponding one.
  • the signal preprocessing system obtains the protection parameter, and performs threshold comparison according to the protection parameter to obtain a threshold comparison result.
  • a dedicated drive system ESFAS is connected to the N protection channels for receiving a threshold comparison result of each protection channel, and performing dedicated drive logic processing according to the threshold comparison result, and outputting the first special design a driving instruction, wherein the first dedicated driving instruction is used to drive an actuator before the reactor reaches a controllable state;
  • a safety automation system SAS connected to the dedicated drive system ESFAS via a safety level ring network for generating a first device level control command, the first device level control command being used to control the slave reactor The state is controlled by the actuator in the safe shutdown state.
  • the FAS is divided into three ESFAS sequences, each of which is connected to the N protection channels by point-to-point communication.
  • each of the ESFAS sequences is configured with two parallel, redundant operational processors.
  • the operation processor is configured to receive the N thresholds for each of the ESFAS sequences The comparison result is logically processed, and after some of the N protection channels fail, processing is performed according to the principle of logical degradation.
  • an emergency control panel ECP is further provided, and the manual dedicated drive button is connected to the dedicated drive system ESFAS through a hard wire for outputting the second dedicated drive command according to an operation instruction of the operator.
  • the operation processor is further configured to perform logic processing on the first dedicated driving instruction and the second dedicated driving instruction, and output a third dedicated driving instruction, the third dedicated driving instruction
  • the actuator that is required to operate before the reactor is brought to a controlled state.
  • the SAS is divided into three SAS sequences, and the security level ring network is divided into three SAS sequences.
  • each SAS sequence is connected to one of the ESFAS sequences in a one-to-one correspondence through one of the security-level sub-ring networks.
  • the security level control display device SCID is further configured to be divided into three groups, each group of SCIDs being passed through one
  • the security level sub-ring network is connected in one-to-one correspondence with one of the ESFAS sequence and one of the SAS sequences;
  • each set of SCIDs outputs a second device level control instruction according to an operation instruction of an operator
  • the SAS sequence receives the second device level control instruction, and controls the first device level control instruction and the second device
  • the level control command performs or logically processes, and outputs a third device level control command for controlling an actuator that needs to operate from a controllable state to a safe shutdown state.
  • the N protection channels are connected in a point-to-point manner, and each protection channel acquires the information from another N-1 protection channels. Threshold comparison result
  • each of the protection channels is provided with a hot standby redundant processor, and the hot standby redundant processor obtains a third partial shutdown according to the N comparison results of the thresholds from the N protection channels.
  • each of the protection channels is connected to a shutdown circuit breaker, the shutdown circuit breaker acquires the third partial shutdown signal from each protection channel, and performs the third partial shutdown signal control The nuclear power plant was shut down.
  • each protection channel is divided into a first sub-group and a second sub-group, and the N pieces of the first sub-groups are connected point-to-point, and the N pieces are separated. Point-to-point connection between groups; [0025] each of the first subgroups obtains the threshold comparison result from another N1 first subgroups, each of the first subgroups has a first hot standby redundant processor, and the first hot standby redundancy
  • the processor is configured to logically process the N threshold comparison results from the N first subgroups, and disable the partial protection channels in the N protection channels, perform logical processing according to the degradation principle, and output the first a partial shutdown signal;
  • each of the second subgroups obtains the threshold comparison result from another N-1 second subgroups, each second subgroup is provided with a second hot standby redundant processor, and the second hot standby And the redundant processor is configured to logically process the N threshold comparison results from the N second subgroups, and after the partial protection channels in the N protection channels are invalid, perform logical processing according to the degradation principle. Outputting a second partial shutdown signal;
  • each protection channel of the emergency shutdown system RTS is further provided with an RTS or a logic processing circuit, and the RT S or logic processing circuit is connected to the first subgroup and the second subgroup, and is used for Performing or logically processing the first partial shutdown signal and the second partial shutdown signal, and outputting the third partial shutdown signal
  • the emergency control panel ECP is further provided, and the manual shutdown control button of the emergency control panel passes the hard
  • the wiring is directly connected to the shutdown circuit breaker, and outputs a fourth partial shutdown signal to the shutdown circuit breaker, the shutdown circuit breaker acquiring and executing the fourth partial shutdown signal to control nuclear power plant shutdown.
  • a diversified drive system KDS which implements a function of a system ATWS of a desired transient non-stop system for In the case where the protection system fails in common mode, the protection parameter is obtained from the signal pre-processing system or the field instrument or the third-party monitoring system, and the shutdown control instruction is output according to the protection parameter.
  • the diversified drive system is coupled to a bar control system that receives the shutdown control command from the diversified drive system and executes the shutdown control command to control nuclear power plant shutdown.
  • the diversified driving system is further configured to output a third special setting according to the protection parameter A drive command, the third dedicated drive command is used to drive an actuator that needs to operate before the reactor reaches a controllable state.
  • the device interface and the priority module CIM are further provided, and the safety automation system SAS And the plurality of driving system connections, configured to acquire the first device level control instruction and the third special drive And the first instruction driving instruction outputted by the dedicated drive system ESFAS is obtained by the safety level ring network and the safety automation system SAS, and the obtained multiple instructions are prioritized.
  • a security control method in a nuclear power plant reactor protection system including the following steps
  • a threshold comparison step wherein the plurality of protection channels of the emergency shutdown system RTS obtain protection parameters from the corresponding signal pre-processing system, and perform threshold comparison on the protection parameters to obtain a threshold comparison result;
  • a dedicated driving step wherein the dedicated driving system ESFAS receives the threshold comparison result of each protection channel, and performs dedicated driving logic processing according to the threshold comparison result, and outputs a first dedicated driving instruction, where the A dedicated drive command is used to drive the actuator that needs to be operated before the reactor reaches a controllable state;
  • a safety automation step wherein the safety automation system SAS generates a first device level control command for controlling an actuator that needs to operate from a controllable state to a safe shutdown state.
  • the dedicated drive system ES FAS is divided into three ESFAS sequences, and each ESFAS sequence communicates with multiple protection channels through point-to-point communication.
  • each of the ESFAS sequences is configured with two parallel and redundant operational processors
  • the operation processor performs logical processing on a plurality of the threshold comparison results received by each of the ESFAS sequences, and partially protects the plurality of protection channels After the channel fails, it is processed according to the principle of logical degradation.
  • the nuclear power plant reactor protection system further includes an emergency control panel ECP, where the emergency control panel ECP is a manual drive button is connected to the dedicated drive system ESFAS, and outputs a second dedicated drive command according to an operation instruction of the operator;
  • the operation processor pairs the first dedicated driving instruction and the second A dedicated drive command or logic process is output, and a third dedicated drive command is output, and the third dedicated drive command is used to drive an actuator that needs to be operated before the reactor reaches a controllable state.
  • the SAS is divided into three SAS sequences, and the security level ring network is divided into three SAS sequences.
  • each SAS sequence is connected to one of the ESFAS sequences in one-to-one correspondence through one of the security-level sub-ring networks;
  • the nuclear power plant reactor protection system further includes a security level control display device SCID, which is divided into three groups, each group corresponding to one of the ESFAS sequence and one of the SAS sequences through one of the security level sub-ring networks. Connected, each set of SCID outputs a second device level control command according to an operation instruction of the operator;
  • SCID security level control display device
  • the SAS sequence receives the second device level control instruction, and performs or logically processes the first device level control instruction and the second device level control instruction, and outputs A third device level control command is used to control an actuator that needs to operate from a controllable state to a safe shutdown state.
  • the protection function before the reactor reaches the controllable state and the control state to the safe shutdown state is distinguished, specifically, the safety level ring is adopted.
  • the function of reducing the two with the safety automation system is mixed in the same subsystem, and the invention can reduce the complexity of the scheme for protecting the system maintenance and periodic testing.
  • 1 is a schematic structural view of a nuclear power plant reactor protection system provided by the present invention
  • 2 is a flow chart of a safety control method in a nuclear power plant reactor protection system provided by the present invention.
  • FIG. 1 is a schematic structural view of a nuclear power plant reactor protection system according to Embodiment 1 of the present invention.
  • the nuclear power plant reactor protection system 100 mainly includes an Emergency Shutdown System (RTS) 10, an Engineering Safety Features Actuation System (ESFAS) 20, and a safety automation system ( Safety Automation System, SAS 30 and Safety System Bus SB 40.
  • RTS Emergency Shutdown System
  • EFAS Engineering Safety Features Actuation System
  • SB 40 Safety Automation System
  • the emergency shutdown system 10 has the following functions: When a design basis accident occurs in the reactor operation, the reactor reactor is triggered to stop the reactor, to control the reactivity of the reactor, the residual heat of the primary circuit, and the radioactive containment of the reactor.
  • the emergency shutdown system 10 is divided into redundant N protection channels, each having the same structure.
  • N is an even number and N ⁇ 2.
  • the four protection channels are RTS IP, RTS IIP, RTS ⁇ and RTS IVP.
  • each protection channel is mainly composed of a Reactor Protection Cabinet (RPC).
  • RPC Reactor Protection Cabinet
  • the four protection channels correspond to RPC-I, RPC-II, and RPC-III, respectively.
  • RPC-IV Reactor Protection Cabinet
  • the nuclear power plant reactor protection system 100 further includes an N-signal signal pre-processing system SPS (Signal Processing System) 11.
  • SPS Signal Processing System
  • the signal preprocessing system 11 mainly has a sensor S for collecting protection parameters and a signal processing cabinet (SPC) for isolating, conditioning, and distributing the protection parameters collected by the sensor S.
  • the protection parameter refers to various parameters related to the safety state in the nuclear power plant, for example, the water level of the regulator, the pressure of the regulator, and the like.
  • the signal pre-processing system 11 has a one-to-one correspondence with the protection channels.
  • the protection channel is divided into 4
  • the signal pre-processing system 11 is also divided into 4 columns
  • the corresponding 4 signal pre-processing cabinets are SPC-I, SPC-II, SPC-III, SPC-IV.
  • Each protection channel is connected to a column of signal pre-processing system 11.
  • the protection channel RTS IP is connected to the signal preprocessing system corresponding to the signal preprocessing cabinet SPC-I
  • the protection channel RTS IIP is connected to the signal preprocessing system corresponding to the signal preprocessing cabinet SPC-II.
  • Each protection channel acquires the pre-processed protection parameters from the corresponding signal pre-processing system 11.
  • the corresponding threshold can be set.
  • the protection channel compares the protection parameters with a threshold to obtain a threshold comparison result. For example, for the water level of the regulator (not shown) in the first loop, set a threshold to the safe water level. When the water level of the regulator is higher than the safe water level, the threshold comparison result is "1", which is used to characterize the stability.
  • the water level of the pressure device is in an unsafe state; when the water level of the regulator is lower than the safe water level, a threshold comparison result of "0" is obtained, which is used to characterize that the water level of the voltage regulator is in a safe state.
  • the threshold comparison results are processed on the one hand by the dedicated drive system 20 and on the other hand by the emergency shutdown system 10.
  • the dedicated drive system 20 is used to bring the nuclear power plant to a controllable state after a design basis accident occurs in the nuclear power plant. Specifically, it can trigger a special safety facility action corresponding to the design basis accident, such as safety injection, starting emergency water supply. Wait.
  • the dedicated drive system 20 can be divided into redundant multiple sequences, ie, ESFAS sequences.
  • ESFAS sequences Each ESFAS sequence has the same structure, mainly consisting of a dedicated drive cabinet (Engineering Safety Features Actuation)
  • ESFAC Cabinet, ESFAC
  • ESFAC is used to implement the functions of the dedicated drive system 20, in which parallel and redundant two arithmetic processors can be configured.
  • ESFAS A ESFAS A
  • ESFAS B ESFAC
  • ESFAC-A is equipped with two arithmetic processors Al and A2.
  • the ESFAC-B is equipped with two arithmetic processors B 1 and B 2.
  • the ESFAC-C is equipped with two arithmetic processors CI and C2.
  • the dedicated drive system 20 is connected to the N protection channels of the emergency shutdown system 10, and more specifically, each ESFA S sequence is connected to the N protection channels by point-to-point communication.
  • ESFAS A corresponding to ESFAC-A is connected to RTS IP, RTS IIP, RTS HIP, and RTS IVP corresponding to each of four RPC-I, RPC-II, RPC-III, and RPC-IV.
  • the dedicated drive system 20 can receive a threshold comparison result obtained by each of the protection channels, that is, N threshold comparison results.
  • the dedicated drive system 20 specifically sets the N threshold comparison results.
  • the dedicated drive logic processing outputting a first dedicated drive command, and the first dedicated drive command is used to drive a dedicated safety facility (a type of actuator) corresponding to the design basis accident before the controllable state, so that the reactor reaches a controllable state . Therefore, the dedicated drive logic processing refers to determining the dedicated safety facilities to be driven and the driving methods thereof according to the threshold comparison result. As will be described later, the first dedicated drive command will be transmitted over the secure level ring network 40.
  • the safety automation system 30 is used to bring the reactor from a controllable state to a safe shutdown state. Moreover, the dedicated drive system 20 performs system level drive control of the dedicated safety facility based on the protection parameters, and the safety automation system 30 performs device level drive control of the dedicated safety facility based on the manual input operation of the operator.
  • the safety automation system 30 can also be divided into multiple sequences, namely SAS sequences.
  • Each SAS sequence has the same structure, mainly composed of Safety Automation Cabinet (SAC).
  • SAC is used to implement the functions of the safety automation system 30.
  • Each SAS sequence can be configured with a hot standby redundant computing processor (not shown). Show).
  • FIG 1 three SAS sequences ij ijSAS A, SAS B, and SAS C are taken as examples.
  • the safety automation system 30 outputs a first device level control command according to an instruction input by an operator, and the first device level control command is a control command for a single device, and is required for the reactor to be in a controllable state to a safe shutdown state.
  • the actuator of the operation is controlled.
  • the security level ring network 40 is provided in the protection system 100 for connecting the dedicated drive system 20 and the safety automation system 30, and is configured to deliver the first dedicated drive command and the first device level control command to the corresponding execution. mechanism.
  • the safety level ring network 40 can also be redundantly arranged, i.e., the safety level ring network 40 is divided into groups.
  • the security-level ring network 40 is divided into three sets of security-level sub-ring networks, namely Train A, Train B, and Train C. Each set of security sub-rings is used to connect an ESFAS sequence and a SAS sequence.
  • each SAS sequence is connected to an ESFAS sequence in a one-to-one correspondence through a secure sub-ring network.
  • the SAS sequence SAS A is connected to the ESFAS sequence ijESFAS A through the security level sub-ring Train A
  • the SAS sequence ij ijSAS B is connected to the ESFAS sequence IjESFAS B through the security level sub-ring Train B.
  • the protection function before the reactor reaches the controllable state and the control state to the safe shutdown state is differentiated, specifically, the security level is adopted.
  • Ring network 40, dedicated drive system for implementing important system level automatic control functions 2 0, and the safety automation system 30 for implementing equipment-level safety assistance and support functions is implemented in a distributed manner, and the functions of the two are not mixed in the prior art, and the functions of the two are mixed in the same subsystem.
  • the invention can reduce the complexity of the protection system maintenance and periodic test
  • This embodiment further improves the nuclear power plant reactor protection system in the prior art on the basis of the first embodiment.
  • the control sequence for the second-generation PWR nuclear power plant is generally divided into two columns, B, and the nuclear-level DC S platform is correspondingly designed for the two columns A and B.
  • the three-generation PWR nuclear power plant is divided into three control sequences. Therefore, the two-row control sequence design of the nuclear power plant reactor protection system in the prior art cannot meet the requirements of the third-generation pressurized water reactor nuclear power plant. Claim.
  • the dedicated drive system 20 provided in this embodiment is divided into three or more ESFAS sequences, preferably three ESFAS sequences. As described in the first embodiment, each ESFAS sequence is connected to N protection channels.
  • the dedicated drive system 20 as three ESFAS sequences, it is possible to meet the process control requirements of the nuclear power station. Moreover, the three control sequences can further optimize the redundancy and independence of the nuclear power plant control functions compared to the two control sequences, thereby improving the reliability of the instrument control implementation of the protection system.
  • each ESFAS sequence is mainly composed of ESFAC.
  • the arithmetic processor in ESFAC can also be used to logically process the N threshold comparison results received by each ESFAS sequence.
  • the logically processed output results are provided by the dedicated drive logic circuit for dedicated drive logic processing.
  • the processing is performed according to the principle of logical degradation.
  • the so-called logical degradation principle means that when one of the N protection channels fails, the logical processing degenerates to N-1, one logically, N-1, two logically, etc.; when N-1 protections A certain protection channel in the channel fails, and the logical processing is further degraded to N-2 to take a logic, N-2 to take two logic, and so on.
  • the ESFAS compliant logic circuit initially performs four-to-two logical processing from the four threshold comparison results from the four protection channels. When a protection channel fails, it degenerates to Three take two logical processing, when there is another protection channel failure, further degenerate into two logical ones.
  • the initial ⁇ is taken as an example of N taking two logics, the initial ⁇ may also be N-one logically or N-1 second-order.
  • the embodiment is used to further explain the emergency shutdown system 10.
  • the N protection channels of the emergency shutdown system 10 are connected point-to-point, and each protection channel acquires a threshold comparison result from another N-1 protection channels. As shown in Figure 1, RPC-I obtains threshold comparison results from RPC-II ⁇ RPC-IV.
  • Each protection channel has a hot standby redundant processor (not shown), and the hot standby redundant processor obtains a third partial shutdown signal based on N threshold comparison results from the N protection channels.
  • Each protection channel is connected to a shutdown circuit breaker, the shutdown circuit breaker obtains a third partial shutdown signal from each protection channel, and performs a third local shutdown signal to control the nuclear power plant shutdown.
  • each protection channel of the emergency shutdown system 10 is divided into a first subgroup and a second subgroup, and further includes RTS or logic processing circuits connected to the first subgroup and the second subgroup.
  • Each subgroup is equipped with a hot standby redundant processor (not shown), a first hot standby redundant processor in the first subgroup, and a second hot standby redundant processor in the second subgroup. .
  • the point-to-point connections between the N first subsets are divided, and the N second subsets are connected point-to-point.
  • the RPC-I of the protection channel RTS IP is divided into a first subgroup Subl and a second subgroup Sub2.
  • Other protection channels The RTS IIP-RTS IVP is also divided into a first subgroup Subl and a second subgroup Sub2.
  • the four first subgroups Sub1 are connected by two or two, and the four second subgroups Sub2 are connected by two.
  • each of the first subgroups obtains a threshold comparison result from the other N-1 first subgroups.
  • the first hot standby redundant processor is configured to logically process the N threshold comparison results from the N first subgroups, that is, a threshold comparison result of the first subgroup corresponding to the first RTS matching logic circuit and In addition, the N-1 threshold comparison results of the N-1 first subgroups are logically processed. And, in N protections When some of the protection channels in the channel fail, they are processed according to the principle of logical degradation, and the first partial shutdown signal is output. Similar to the third partial shutdown signal, the first partial shutdown signal is also used to control the nuclear power plant shutdown, but the first partial shutdown signal belongs to the intermediate signal.
  • each of the second subgroups obtains a threshold comparison result from the other N-1 second subgroups.
  • the second hot standby redundant processor is configured to logically process the N threshold comparison results from the N second subgroups, and after the partial protection channels in the N protection channels are invalid, processing according to the logical degradation principle,
  • the second partial shutdown signal is output.
  • the second partial shutdown signal belongs to the intermediate signal.
  • the first subgroup Sub1 and the second subgroup Sub2 can respectively process different types of protection parameters and their threshold comparison results, and perform different protection functions. .
  • Each of the protection channels of the emergency shutdown system 10 is also provided with an RTS or logic processing circuit, which is indicated by the symbol " ⁇ 1" in FIG.
  • the RTS or logic processing circuit is coupled to the first subgroup Sub1 and the second subgroup Sub2. And according to the connection relationship with the first subgroup and the second subgroup, the RTS or logic processing circuit performs logical processing on the first partial shutdown signal and the second partial shutdown signal to output a third partial shutdown signal.
  • the emergency shutdown system 10 is used to trigger an emergency shutdown when a design basis accident occurs in the operation of the reactor.
  • the third partial shutdown signal can be transmitted to the shutdown circuit breaker RTB via hard wiring, thereby triggering an emergency shutdown.
  • the shutdown circuit breaker RTB can also be set to N pairs, and the N pairs of shutdown circuit breakers can be hardwired to achieve two logical alignments, ie, at least two An emergency shutdown can be achieved by slamming the shutdown circuit breaker. If there is a fault or failure of the protection channel, the hardwire of the shutdown breaker is degraded in logic to three to two and two to one.
  • the normal implementation of the function of the emergency shutdown system 10 can be ensured even if the protection channel portion fails.
  • the nuclear power plant reactor protection system 100 may also be provided with an emergency control panel ECP (Emergency Control Panel) 70.
  • ECP Emergency Control Panel
  • the manual dedicated drive button of the emergency control panel 70 is connected to the dedicated drive system 20 by hard wiring for outputting the second dedicated drive command according to an operation command of the operator. Similar to the first dedicated drive command, the second dedicated drive command is also used to drive the actuator that needs to be operated before the reactor reaches a controllable state.
  • the dedicated drive system 20 can receive the second dedicated drive command output by the emergency control panel 70, wherein the operation processor can also be used to perform or logically process the first dedicated drive command and the second dedicated drive command.
  • the third dedicated drive command is output.
  • the third dedicated drive command is used to drive the actuator that needs to be operated before the reactor reaches a controllable state. It can be understood that, in the case where the emergency control panel 70 is set, under the control of the arithmetic processor or the logic processing, the first dedicated drive command and the second dedicated drive command are converted into the third dedicated drive command, only The third dedicated drive command is delivered to the actuator.
  • emergency drive to the dedicated safety facility can be implemented in place of the dedicated drive system 20 by the provision of the emergency control panel 70.
  • the drive of the dedicated drive system 20 and the emergency control panel 70 to the dedicated safety facility can be coordinated by the arithmetic processor or by logical processing.
  • the emergency control panel 70 can also directly implement the emergency control nuclear power plant shutdown.
  • the emergency control panel 70 directly connects the shutdown circuit breaker RTB through hard wiring and outputs a fourth partial shutdown signal to the shutdown circuit breaker RTB.
  • the shutdown circuit breaker R TB can acquire and execute a fourth partial shutdown signal to control the nuclear power plant shutdown.
  • the nuclear power plant reactor protection system 100 can also be provided with a visualized safety level control display device SCID (Safety Control and Information Device) 80 for replacing the safety automation system 30 emergency drive actuator.
  • SCID Safety Control and Information Device
  • the security level control display device 80 is divided into three groups, and each group is connected to an ESFAS sequence and a SAS sequence in a one-to-one correspondence through a security level sub-ring network.
  • group SCID A is connected to ESFAC-A and SAS A via Train A.
  • the safety level control display device 80 is coupled to the safety automation system 30 for outputting a second device level control command in accordance with an operator's operation command.
  • each group outputs a second device level control instruction according to an operation instruction of the operator, the corresponding SAS sequence receives the second device level control instruction, and controls the first device level control instruction and the second device level control instruction Performing or logical processing, outputting a third device level control instruction.
  • a third device level control command is used to control the actuators that need to operate the reactor from a controlled state to a safe shutdown state.
  • Embodiment 4 [0095] Based on any of the above embodiments 1 to 3, the present embodiment further improves the nuclear power plant reactor protection system 100 of the prior art.
  • This embodiment relates to an expected transient non-stop system (Anticipated Transient Without Trip)
  • ATWS responds to functions such as emergency water supply through diversified shutdown control and tripping, and mitigates the consequences of failure to achieve emergency shutdown.
  • a diverse driving system KDS (Diversity Actuation System) 50 is also provided, which is used to implement the functions of the ATWS system.
  • the diversified drive system 50 can be coupled to each of the column signal pre-processing systems 11 for obtaining protection parameters from the signal pre-processing system 11 in the event of a common mode failure of the emergency shutdown system 10 and the ad hoc drive system 20, and
  • the protection parameter outputs a shutdown control command.
  • the diversified drive system 50 is also connected to a Full Length Rod Control System (RGG)
  • the stick control system receives the shutdown control command from the diversified drive system 50 and executes the shutdown control command to control the nuclear power plant shutdown. Therefore, the diversified drive system 50 is capable of ensuring critical protection functions in the event of a common mode failure of the nuclear power plant reactor protection system 100.
  • the diversified drive system 50 is connected to each column of the signal pre-processing system 11 to obtain the protection parameters from the signal pre-processing system 11, but the present invention is not limited thereto, and the diversified drive system 50 can be hardwired and A third-party system (not shown) is connected to obtain protection parameters from a third-party system directly through hard-wired or to obtain protection parameters from the field instrument.
  • the diversified drive system 50 can also be used to output a third dedicated drive command according to the protection parameter, and the third dedicated drive command is also used to drive the actuator that needs to operate before the reactor reaches the controllable state.
  • the third dedicated drive command can be transmitted to the interface and priority module CIM 60 described later.
  • the functions implemented in the diversified drive system 50 generally do not belong to the protection functions implemented in the nuclear power plant reactor protection system 100, but in the present invention, in view of the nuclear power plant reactor protection system 100 and the diversified drive system
  • the setting of 50 has a close relationship, and the functions of the ATWS system are diversified.
  • the system 50 is implemented so that the diverse drive system 50 can be considered part of the nuclear power plant reactor protection system 100.
  • the design of the dedicated drive system 20 and the safety automation system 30 is not differentiated, and therefore, the first dedicated drive command and the first device level control command are not distinguished.
  • the first dedicated drive command is more important than the protection system 100. Without prioritizing the two commands, the function of the protection system 100 cannot be efficiently implemented.
  • the nuclear power plant reactor protection system 100 also provides a device interface and priority module CIM 60.
  • the device interface and priority module 60 is coupled to the safety automation system 30 and the diverse drive system 50.
  • the device interface and priority module 60 can be divided into three sequences, each of which is mainly composed of a device interface and a priority cabinet CIC. As shown in Figure 1, CIM is divided into CIC A, CIC B, and CIC.
  • the device interface and priority module 60 is configured to acquire the first device level control command and the third dedicated drive command.
  • the device interface and priority module 60 also acquires a dedicated drive system 20.
  • the first dedicated drive command is output, wherein the first dedicated drive command passes through the safety level ring network 40 and the safety automation system 30.
  • the first device level control command, the third dedicated drive command, and the first dedicated drive command are directly sent to the corresponding actuator, but the device interface is set and prioritized.
  • these instructions may first be processed by the priority of the setup device interface and priority module 60 before being sent to the actuator. That is, the device interface and priority module 60 can prioritize the received multiple instructions, determine the instruction with the highest priority, and enable the executing agency to preferentially execute the instruction with the highest priority. Therefore, the protection system can be implemented efficiently.
  • the nuclear power plant reactor protection system 100 provided in this embodiment does not need to design a redundant relay hard logic for the diverse design requirements of the protection system, that is, does not require large-scale Functional redundant relay cabinet.
  • the nuclear power plant reactor protection system 100 since the nuclear power plant reactor protection system 100 provided in this embodiment adopts a diversified driving system, the protection system 100 does not need to add a set of relay logic for important protection functions, thereby greatly reducing safety.
  • the number of stage relay cabinets has reduced the number of cables, which has made it difficult to arrange the electrical plant.
  • the reduction of relay logic greatly simplifies the requirements of periodic testing of power plants and reduces the risk of failure caused by equipment aging.
  • This embodiment provides a safety control method in a nuclear power plant reactor protection system, which is applied to any of the nuclear power plant reactor protection systems 100 provided in the above embodiments 1 to 4. as shown in picture 2
  • the method includes the following steps:
  • Threshold comparison step S1 which is executed by the emergency shutdown system RTS, the emergency shutdown system is divided into N protection channels, N is even and N ⁇ 2, and each protection channel is correspondingly connected with a column of signal preprocessing system, wherein Each protection channel obtains a protection parameter from a corresponding signal preprocessing system, and performs threshold comparison according to the protection parameter to obtain a threshold comparison result;
  • the driving step S2 is specifically performed by the dedicated driving system ESFAS, and the dedicated driving system is connected with the N protection channels for receiving the threshold comparison result of each protection channel, and performing the dedicated driving according to the threshold comparison result.
  • Logic processing outputting a first dedicated drive command, and the first dedicated drive command is used to drive an actuator that needs to be operated before the reactor reaches a controllable state;
  • Safety automation step S3 which is executed by the safety automation system SAS, which is connected to the dedicated drive system through the safety level ring network to generate a first device level control command, and the first device level control command is used for the reactor
  • the controllable state to the safe shutdown state requires control by the operating actuator.
  • the complexity of the protection system maintenance and periodic test can be reduced.
  • the dedicated drive system is divided into three ESFAS sequences, each
  • the ESFAS sequence is connected to the N protection channels by point-to-point communication;
  • Each ESFAS sequence is configured with two parallel, redundant operational processors;
  • the arithmetic processor performs logical processing on the N threshold comparison results received by each ESFAS sequence, and the partial protection channels in the N protection channels are invalid, according to the principle of logical degradation. Process it.
  • the nuclear power plant reactor protection system also has emergency control The ECP, the manual control drive button of the emergency control panel ECP is connected with the dedicated drive system, and outputs the second dedicated drive command according to the operation instruction of the operator;
  • the arithmetic processor performs or logically processes the first dedicated driving instruction and the second dedicated driving instruction, and outputs a third dedicated driving instruction, and the third dedicated driving instruction is used for driving.
  • the actuator that needs to be operated before the reactor reaches a controlled state.
  • the security automation system is divided into three SAS sequences, and the security level ring network is divided into three sets of security level sub-ring networks, and each SAS sequence passes through a security level sub-ring. Net with one E
  • the nuclear power plant reactor protection system also has a safety level control display device SCID, which is divided into three groups, each group is connected to an ESFAS sequence and a SAS sequence in a one-to-one correspondence through a safety level sub-ring network, each group S
  • the CID outputs a second device level control instruction according to an operation instruction of the operator
  • the SAS sequence receives the second device level control instruction, and performs or logically processes the first device level control instruction and the second device level control instruction, and outputs a third device level control instruction, third.
  • Device level control commands are used to control the actuators that need to operate the reactor from a controlled state to a safe shutdown state.
  • N protection channels are connected point-to-point, each protection channel has a hot standby redundant processor, and each protection channel is connected to the shutdown circuit breaker.
  • the method further includes a shutdown control step S4.
  • each protection channel acquires a threshold comparison result from the other N-1 protection channels, and the hot standby redundant processor is based on the slave protection channels from the N protection channels.
  • the N threshold comparison results result in a third partial shutdown signal
  • the shutdown circuit breaker obtains a third partial shutdown signal from each protection channel, and performs a third partial shutdown signal to control the nuclear power plant shutdown.

Landscapes

  • Physics & Mathematics (AREA)
  • Engineering & Computer Science (AREA)
  • Plasma & Fusion (AREA)
  • General Engineering & Computer Science (AREA)
  • High Energy & Nuclear Physics (AREA)
  • Business, Economics & Management (AREA)
  • Emergency Management (AREA)
  • Testing And Monitoring For Control Systems (AREA)
  • Safety Devices In Control Systems (AREA)
  • Monitoring And Testing Of Nuclear Reactors (AREA)

Abstract

一种核电站反应堆保护系统(100)及其中的安全控制方法,所述保护系统(100)具备:分为N个保护通道的紧急停堆系统(10),每个保护通道从信号预处理系统(11)获取保护参数,进行阈值比较;与N个保护通道连接的专设驱动系统(20),接收阈值比较结果,并根据阈值比较结果进行专设驱动逻辑处理,输出第一专设驱动指令用于驱动核电厂设计基准事故发生后,反应堆达到可控状态前需要操作的执行机构;通过安全级环网(40)与专设驱动系统(20)连接的安全自动化系统(30),产生第一设备级控制指令,用于对核电厂设计基准事故发生后,反应堆从可控状态到安全停堆状态过程中需要操作的执行机构进行控制。所述系统和方法能够降低保护系统维护、定期试验的方案复杂程度。

Description

核电站反应堆保护系统及其中的安全控制方法 技术领域
[0001] 本发明涉及核电站领域, 尤其涉及一种核电站反应堆保护系统及其中的安全控 制方法。
背景技术
为了确保核电站反应堆安全运行, 需设置保护系统。 保护系统的结构设计与核 电站的总体设计、 安全分级、 核级 DCS (Digital Control System, 数字化计算机 控制系统) 平台设计密切相关。
[0003] 在核电站发生设计基准事故的情况下, 保护系统用于将反应堆带至安全停堆状 态。 其中, 设计基准事故是指, 核电站按确定的设计准则在设计中采取了针对 性措施的事故工况。 安全停堆状态是指反应堆以受控的方式停止的状态。 此外 , 在安全停堆状态之前, 反应堆先进入可控状态, 这里的可控状态是指, 反应 堆的裂变链式反应处于可控状态。
[0004] 在保护系统中, 从核电站发生设计基准事故后到反应堆达到可控状态的过程, 以及反应堆从可控状态至安全停堆状态的过程, 除实现反应堆自动紧急停堆功 能外, 一方面, 需要根据保护参数进行对专设安全设施进行系统级的自动控制 处理, 另一方面, 还需要对专设安全设施进行设备级的手动操作处理。 其中, 专设安全设施是指, 核电厂在事故工况下投入使用并执行安全功能, 以控制事 故后果, 使反应堆在事故后达到稳定的、 可接受状态而专门设置的各种安全系 统的总称。
[0005] 在实现上述现有保护系统的过程中, 发明人发现现有技术中至少存在如下问题 : 现有的保护系统中, 系统级专设驱动功能与设备级专设驱动功能被混杂在同 一个子系统中实现, 这样的子系统中, 对于系统级专设驱动功能所使用的保护 参数的控制处理等, 以及对于设备级专设驱动功能所使用的用户输入指令的控 制处理等, 很多由同一设备实现, 也即, 实现两种功能的系统之间重合度较高 , 这导致保护系统维护、 定期试验的方案较为复杂。 技术问题
[0006] 本发明提供一种核电站反应堆保护系统及核电站反应堆保护系统中的安全控制 方法, 能够降低保护系统维护、 定期试验的方案复杂程度。
问题的解决方案
技术解决方案
[0007] 为达到上述目的, 本发明的实施例采用如下技术方案:
[0008] 第一方面, 提供一种核电站反应堆保护系统, 具备:
[0009] 紧急停堆系统 RTS, 其分为 N个保护通道, N为偶数且N≥2, 每个保护通道均对 应连接一列信号预处理系统, 其中, 所述每个保护通道从对应的所述信号预处 理系统获取保护参数, 并根据所述保护参数进行阈值比较, 得到阈值比较结果
[0010] 专设驱动系统 ESFAS , 其与所述 N个保护通道连接, 用于接收每个保护通道的 阈值比较结果, 并根据所述阈值比较结果进行专设驱动逻辑处理, 输出第一专 设驱动指令, 所述第一专设驱动指令用于驱动反应堆达到可控状态前的执行机 构;
[0011] 安全自动化系统 SAS, 其通过安全级环网与所述专设驱动系统 ESFAS连接, 用 于产生第一设备级控制指令, 所述第一设备级控制指令用于对从反应堆达到可 控状态到安全停堆状态的执行机构进行控制。
[0012] 结合第一方面, 在第一方面的第一种可能的实现方式中, 所述专设驱动系统 ES
FAS分为三个 ESFAS序列, 每个 ESFAS序列均与所述 N个保护通道通过点对点通 讯连接。
[0013] 结合第一方面的第一种可能的实现方式, 在第一方面的第二种可能的实现方式 中, 所述每个 ESFAS序列均配置并行的、 冗余的两个运算处理器。
[0014] 结合第一方面的第二种可能的实现方式, 在第一方面的第三种可能的实现方式 中, 所述运算处理器用于对所述每个 ESFAS序列接收的 N个所述阈值比较结果进 行符合逻辑处理, 并且在所述 N个保护通道中的部分保护通道失效吋, 按照符合 逻辑退化原则进行处理。
[0015] 结合第一方面的第二种或第三种可能的实现方式, 在第一方面的第四种可能的 实现方式中, 还具备紧急控制盘 ECP, 其手动专设驱动按钮与所述专设驱动系统 ESFAS通过硬接线连接, 用于根据操作人员的操作指令输出第二专设驱动指令
[0016] 所述运算处理器还用于对所述第一专设驱动指令与所述第二专设驱动指令进行 或逻辑处理, 输出第三专设驱动指令, 所述第三专设驱动指令用于驱动反应堆 达到可控状态前需要操作的执行机构。
[0017] 结合第一方面的第一种可能的实现方式, 在第一方面的第五种可能的实现方式 中, 所述安全自动化系统 SAS分为三个 SAS序列, 所述安全级环网分为三组安全 级子环网, 每个 SAS序列通过一个所述安全级子环网与一个所述 ESFAS序列一一 对应连接。
[0018] 结合第一方面的第五种可能的实现方式, 在第一方面的第六种可能的实现方式 中, 还具备安全级控制显示设备 SCID, 其分为三组, 每组 SCID通过一个所述安 全级子环网与一个所述 ESFAS序列及一个所述 SAS序列一一对应连接;
[0019] 每组 SCID根据操作人员的操作指令输出第二设备级控制指令, 所述 SAS序列接 收所述第二设备级控制指令, 并对所述第一设备级控制指令与所述第二设备级 控制指令进行或逻辑处理, 输出第三设备级控制指令, 所述第三设备级控制指 令用于对反应堆从可控状态到安全停堆状态需要操作的执行机构进行控制。
[0020] 结合第一方面, 在第一方面的第七种可能的实现方式中, 所述 N个保护通道之 间点对点连接, 所述每个保护通道从另外 N-1个保护通道获取所述阈值比较结果
[0021] 所述每个保护通道均具备热备冗余处理器, 所述热备冗余处理器根据来自所述 N个保护通道的所述 N个所述阈值比较结果得到第三局部停堆信号,
[0022] 所述每个保护通道均连接停堆断路器, 所述停堆断路器从所述每个保护通道获 取所述第三局部停堆信号, 并执行所述第三局部停堆信号控制核电站停堆。
[0023] 结合第一方面的第七种可能的实现方式, 在第一方面的第八种可能的实现方式 中,
[0024] 所述每个保护通道均分为第一子组与第二子组, 所分得的 N个所述第一子组之 间点对点连接, 所分得的 N个所述第二子组之间点对点连接; [0025] 每个第一子组均从另外 N-l个第一子组获取所述阈值比较结果, 每个第一子组 均具备第一热备冗余处理器, 所述第一热备冗余处理器用于对来自所述 N个第一 子组的 N个所述阈值比较结果进行符合逻辑处理, 并且在 N个保护通道中的部分 保护通道失效吋, 按照退化原则进行符合逻辑处理, 输出第一局部停堆信号;
[0026] 每个第二子组均从另外 N-1个第二子组获取所述阈值比较结果, 每个第二子组 均具备第二热备冗余处理器, 所述第二热备冗余处理器用于对来自所述 N个第二 子组的 N个所述阈值比较结果进行符合逻辑处理, 并且在 N个保护通道中的部分 保护通道失效吋, 按照退化原则进行符合逻辑处理, 输出第二局部停堆信号;
[0027] 所述紧急停堆系统 RTS的每个保护通道还均具备 RTS或逻辑处理电路, 所述 RT S或逻辑处理电路与所述第一子组及所述第二子组连接, 用于对所述第一局部停 堆信号与所述第二局部停堆信号进行或逻辑处理, 输出所述第三局部停堆信号
[0028] 结合第一方面的第七种可能的实现方式, 在第一方面的第九种可能的实现方式 中, 还具备紧急控制盘 ECP, 所述紧急控制盘的手动停堆控制按钮通过硬接线直 接连接所述停堆断路器, 并向所述停堆断路器输出第四局部停堆信号, 所述停 堆断路器获取并执行所述第四局部停堆信号控制核电站停堆。
[0029] 结合第一方面, 在第一方面的第十种可能的实现方式中, 还具备多样化驱动系 统 KDS, 其实现预期瞬态不停堆系统的系统 ATWS的功能, 用于在所述保护系统 发生共模失效的情况下, 从所述信号预处理系统或现场仪表或第三方监测系统 获取保护参数, 并根据所述保护参数输出停堆控制指令,
[0030] 所述多样化驱动系统与棒控系统连接, 所述棒控系统从所述多样化驱动系统接 收所述停堆控制指令, 并执行所述停堆控制指令控制核电站停堆。
[0031] 结合第一方面的第十种可能的实现方式, 在第一方面的第十一种可能的实现方 式中, 所述多样化驱动系统还用于根据所述保护参数输出第三专设驱动指令, 所述第三专设驱动指令用于驱动反应堆达到可控状态前需要操作的执行机构。
[0032] 结合第一方面的第十一种可能的实现方式, 在第一方面的第十二种可能的实现 方式中, 还具备设备接口及优先级模块 CIM, 其与所述安全自动化系统 SAS及所 述多样化驱动系统连接, 用于获取所述第一设备级控制指令及所述第三专设驱 动指令, 还通过所述安全级环网及所述安全自动化系统 SAS获取所述专设驱动系 统 ESFAS输出的所述第一专设驱动指令, 并对获取到的多个指令进行优先级处 理。
[0033] 结合第一方面的第十种可能的实现方式, 在第一方面的第十三种可能的实现方 式中, 当所述紧急停堆系统 RTS、 所述专设驱动系统 ESFAS正常吋, 所述多样化 驱动系统的自动逻辑功能正常运行, 手动操作指令闭锁。
[0034] 第二方面, 提供一种核电站反应堆保护系统中的安全控制方法, 包括如下步骤
[0035] 阈值比较步骤, 其中, 紧急停堆系统 RTS的多个保护通道均从对应的信号预处 理系统获取保护参数, 并对所述保护参数进行阈值比较, 得到阈值比较结果;
[0036] 专设驱动步骤, 其中, 专设驱动系统 ESFAS接收每个保护通道的阈值比较结果 , 并根据所述阈值比较结果进行专设驱动逻辑处理, 输出第一专设驱动指令, 所述第一专设驱动指令用于驱动反应堆达到可控状态前需要操作的执行机构;
[0037] 安全自动化步骤, 其中, 安全自动化系统 SAS产生第一设备级控制指令, 所述 第一设备级控制指令用于对反应堆从可控状态到安全停堆状态需要操作的执行 机构进行控制。
[0038] 结合第二方面, 在第二方面的第一种可能的实现方式中, 所述专设驱动系统 ES FAS分为三个 ESFAS序列, 每个 ESFAS序列均与多个保护通道通过点对点通讯连 接;
[0039] 所述每个 ESFAS序列均配置并行的、 冗余的两个运算处理器;
[0040] 在所述专设驱动步骤中, 所述运算处理器对所述每个 ESFAS序列接收的多个所 述阈值比较结果进行符合逻辑处理, 并且在所述多个保护通道中的部分保护通 道失效吋, 按照符合逻辑退化原则进行处理。
[0041] 结合第二方面的第一种可能的实现方式, 在第二方面的第二种可能的实现方式 中, 所述核电站反应堆保护系统还具备紧急控制盘 ECP, 所述紧急控制盘 ECP的 手动专设驱动按钮与所述专设驱动系统 ESFAS连接, 根据操作人员的操作指令 输出第二专设驱动指令;
[0042] 在所述专设驱动步骤中, 所述运算处理器对所述第一专设驱动指令与所述第二 专设驱动指令进行或逻辑处理, 输出第三专设驱动指令, 所述第三专设驱动指 令用于驱动反应堆达到可控状态前需要操作的执行机构。
[0043] 结合第二方面的第一种可能的实现方式, 在第二方面的第三种可能的实现方式 中, 所述安全自动化系统 SAS分为三个 SAS序列, 所述安全级环网分为三组安全 级子环网, 每个 SAS序列通过一个所述安全级子环网与一个所述 ESFAS序列一一 对应连接;
[0044] 所述核电站反应堆保护系统还具备安全级控制显示设备 SCID, 其分为三组, 每组通过一个所述安全级子环网与一个所述 ESFAS序列及一个所述 SAS序列一一 对应连接, 每组 SCID根据操作人员的操作指令输出第二设备级控制指令;
[0045] 在所述安全自动化步骤中, 所述 SAS序列接收所述第二设备级控制指令, 并对 所述第一设备级控制指令与所述第二设备级控制指令进行或逻辑处理, 输出第 三设备级控制指令, 所述第三设备级控制指令用于对反应堆从可控状态到安全 停堆状态需要操作的执行机构进行控制。
发明的有益效果
有益效果
[0046] 在本发明提供的核电站反应堆保护系统及其安全控制方法中, 对反应堆达到可 控状态前与达到可控状态至安全停堆状态的保护功能进行区分处理, 具体地, 通过安全级环网, 对用于实现重要的系统级自动控制功能的专设驱动系统, 以 及用于实现设备级安全辅助、 支持功能的安全自动化系统分幵实现, 相对于现 有技术中没有区分专设驱动系统与安全自动化系统而降两者的功能混杂在同一 个子系统中, 本发明能够降低保护系统维护、 定期试验的方案复杂程度。
对附图的简要说明
附图说明
[0047] 为了更清楚的说明本发明实施例或现有技术中的技术方案, 下面将对实施例或 现有技术中所需要使用的附图作简单地介绍, 显而易见地, 下面描述中的附图 仅仅是本发明的一些实施例, 对于本领域普通技术人员来讲, 在不付出创造性 劳动的前提下, 还可以根据这些附图获得其他的附图。
[0048] 图 1为本发明提供的核电站反应堆保护系统的结构示意图; [0049] 图 2为本发明提供的核电站反应堆保护系统中的安全控制方法的流程图。
实施该发明的最佳实施例
本发明的最佳实施方式
[0050] 下面结合附图对本发明实施例的技术方案进行清楚、 完整地描述, 显然, 所描 述的实施例仅仅是本发明的一部分实施例, 而不是全部的实施例。 基于本发明 中的实施例, 本领域普通技术人员在没有做出创造性劳动的前提下所获得的所 有其他实施例, 都属于本发明保护的范围。
[0051] 实施例一
[0052] 以下, 结合附图对本实施例提供的核电站反应堆保护系统进行说明。 图 1为本 发明实施例一提供的核电站反应堆保护系统的结构示意图。
[0053] 如图 1所示, 核电站反应堆保护系统 100主要具备紧急停堆系统 (Reactor Trip System, RTS) 10、 专设驱云力系统 (Engineering Safety Features Actuation System , ESFAS) 20、 安全自动化系统 (Safety Automation System, SAS) 30及安全级 环网 SB (Safety System Bus) 40。
[0054] 紧急停堆系统 10具有如下功能: 当反应堆运行中出现设计基准事故吋, 触发反 应堆停堆, 以实现对反应堆反应性的控制, 一回路余热排出, 反应堆放射性包 容等保护功能。
[0055] 紧急停堆系统 10分为冗余的 N个保护通道, 每个保护通道内具有相同的结构。
其中, N为偶数且N≥2。 在本实施例中, 以 N=4为例进行说明。 4个保护通道分别 为 RTS IP、 RTS IIP、 RTS ΠΙΡ及 RTS IVP。 如后文所述, 每个保护通道主要由停 堆保护控制柜 (Reactor Protection Cabinet, RPC) 组成, 如图 1所示, 4个保护通 道分别对应 RPC-I、 RPC-II、 RPC-III、 RPC-IV。
[0056] 核电站反应堆保护系统 100还包括 N列信号预处理系统 SPS (Signal Processing System) 11。 信号预处理系统 11主要具备用于采集保护参数的传感器 S及对传感 器 S采集的保护参数进行隔离、 调理、 分配等预处理的信号预处理柜 (Signal Processing Cabinet, SPC) 。 保护参数是指核电站中与安全状态相关的各种参数 , 例如, 稳压器的水位、 稳压器的压力等。
[0057] 信号预处理系统 11与保护通道一一对应。 在本实施例中, 对应于保护通道分为 4个, 信号预处理系统 11同样分为 4列, 对应的 4个信号预处理柜为 SPC-I、 SPC-II 、 SPC-III、 SPC-IV。 每个保护通道均对应连接一列信号预处理系统 11。 例如, 保护通道 RTS IP连接信号预处理柜 SPC-I对应的信号预处理系统, 保护通道 RTS IIP连接信号预处理柜 SPC-II对应的信号预处理系统。
[0058] 每个保护通道 (RTS IP、 RTS IIP、 RTS ΠΙΡ及 RTS IVP) 从对应的信号预处理 系统 11获取被预处理之后的保护参数。 为了判断保护参数是否满足安全状态的 要求, 可设置相应的阈值。 保护通道可将保护参数与阈值进行比较, 得到阈值 比较结果。 举例而言, 对于一回路中稳压器 (未图示) 的水位, 设置一个阈值 为安全水位, 当稳压器的水位高于安全水位吋, 得到阈值比较结果 "1", 用于表 征稳压器的水位处于非安全状态; 当稳压器的水位低于安全水位吋, 得到阈值 比较结果 "0", 用于表征稳压器的水位处于安全状态。 如后文所述, 阈值比较结 果一方面供专设驱动系统 20处理, 另一方面供紧急停堆系统 10处理。
[0059] 专设驱动系统 20用于在核电站发生设计基准事故后将核电站带至可控状态, 具 体地, 其可触发与设计基准事故相应的专设安全设施动作, 例如安全注入、 启 动应急给水等。
[0060] 专设驱动系统 20可分为冗余的多个序列, 即 ESFAS序列。 每个 ESFAS序列具有 相同的结构, 主要由专设驱动柜 (Engineering Safety Features Actuation
Cabinet, ESFAC) 构成, ESFAC用于实现专设驱动系统 20的功能, 其中可配置 并行的、 冗余的两个运算处理器。 在此, 以 3个 ESFAS序列 ESFAS A、 ESFAS B 、 ESFAS
C为例。 如图 1所示, 3个 ESFAS序列分别对应 ESFAC-A、 ESFAC-B、 ESFAC-C 。 ESFAC-A配置有两个运算处理器 Al、 A2, ESFAC- B配置有两个运算处理器 B 1、 B 2, ESFAC-C配置有两个运算处理器 CI、 C2。
[0061] 专设驱动系统 20与紧急停堆系统 10的 N个保护通道连接, 更具体地, 每个 ESFA S序列均与 N个保护通道通过点对点通讯连接。 例如, ESFAC-A对应的 ESFAS A 与 4个 RPC-I、 RPC-II、 RPC-III、 RPC-IV各自对应的 RTS IP、 RTS IIP、 RTS HIP 、 RTS IVP均连接。 专设驱动系统 20可接收每个保护通道各自得到的阈值比较结 果, 即 N个阈值比较结果。 在此, 专设驱动系统 20对 N个阈值比较结果进行专设 驱动逻辑处理, 输出第一专设驱动指令, 第一专设驱动指令用于在可控状态前 驱动与设计基准事故相应的专设安全设施 (执行机构的一种) , 使得反应堆达 到可控状态。 因此, 专设驱动逻辑处理是指, 根据阈值比较结果确定需驱动的 专设安全设施及其驱动方式。 如后文所述, 第一专设驱动指令将通过安全级环 网 40传输。
[0062] 区别于专设驱动系统 20, 安全自动化系统 30用于将反应堆从可控状态带至安全 停堆状态。 而且, 专设驱动系统 20基于保护参数进行对专设安全设施进行系统 级的驱动控制, 而安全自动化系统 30基于操作人员的手动输入操作对专设安全 设施进行设备级的驱动控制。
[0063] 安全自动化系统 30同样可分为多个序列, 即 SAS序列。 每个 SAS序列具有相同 的结构, 主要由安全自动化柜 (Safety Automation Cabinet, SAC) 构成, SAC用 于实现安全自动化系统 30的功能, 每个 SAS序列可配置热备冗余运算处理器 (未 图示) 。 如图 1所示, 以 3个 SAS序歹 ijSAS A、 SAS B、 SAS C为例。 在此, 安全 自动化系统 30根据操作人员输入的指令, 输出第一设备级控制指令, 第一设备 级控制指令是针对单个设备的控制指令, 用于对反应堆从可控状态到安全停堆 状态需要操作的执行机构进行控制。
[0064] 安全级环网 40是保护系统 100中为连接专设驱动系统 20及安全自动化系统 30而 设置的, 用于将第一专设驱动指令与第一设备级控制指令输送至相应的执行机 构。 对应于专设驱动系统 20与安全自动化系统 30的冗余化设置, 安全级环网 40 同样可以进行冗余化设置, 即, 安全级环网 40分为多组。 如图 1所示, 安全级环 网 40分为三组安全级子环网, 分别为 Train A、 Train B、 Train C。 每组安全级子 环网用于连接一个 ESFAS序列及一个 SAS序列, 即, 每个 SAS序列通过一个安全 级子环网与一个 ESFAS序列一一对应连接。 例如, SAS序列 SAS A通过安全级子 环网 Train A与 ESFAS序歹 ijESFAS A连接, SAS序歹 ijSAS B通过安全级子环网 Train B与 ESFAS序歹 IjESFAS B连接。
[0065] 由以上可知, 在本实施例提供的核电站反应堆保护系统 100中, 对反应堆达到 可控状态前与达到可控状态至安全停堆状态的保护功能进行区分处理, 具体地 , 通过安全级环网 40, 对用于实现重要的系统级自动控制功能的专设驱动系统 2 0, 以及用于实现设备级安全辅助、 支持功能的安全自动化系统 30分幵实现, 相 对于现有技术中没有区分专设驱动系统与安全自动化系统而降两者的功能混杂 在同一个子系统中, 本发明能够降低保护系统维护、 定期试验的方案复杂程度
[0066] 实施例二
[0067] 本实施例在实施例一的基础上, 对现有技术中的核电站反应堆保护系统进行进 一步改进。
[0068] 现有技术中, 针对二代压水堆核电站控制序列一般只分为 、 B两列, 核级 DC S平台相应地做 A、 B两列的结构设计。 然而, 随着三代压水堆核电站的引入, 而 三代压水堆核电站分为三个控制序列, 因此, 现有技术中的核电站反应堆保护 系统的两列控制序列设计无法满足三代压水堆核电站的要求。
[0069] 为此, 本实施例提供的专设驱动系统 20分为三个以上的 ESFAS序列, 优选为三 个 ESFAS序列。 如实施例一所述, 每个 ESFAS序列均与 N个保护通道连接。
[0070] 在本实施例中, 通过将专设驱动系统 20设计为三个 ESFAS序列, 能够满足核电 站的工艺控制需求。 而且, 三个控制序列相比两个控制序列能够进一步优化核 电站控制功能的冗余性及独立性, 进而提高保护系统仪控实现的可靠性。
[0071] 如上所述, 每个 ESFAS序列主要由 ESFAC构成。 ESFAC中的运算处理器除了用 于实现专设驱动逻辑处理外, 还可用于对每个 ESFAS序列接收的 N个阈值比较结 果进行符合逻辑处理。 符合逻辑处理包括 N取一符合逻辑、 N取二符合逻辑等。 以 N=4为例, 每个 ESFAS符合逻辑电路可对来自 4个保护通道的 4个阈值比较结果 进行四取二符合逻辑处理。 符合逻辑处理的输出结果供专设驱动逻辑电路进行 专设驱动逻辑处理。
[0072] 并且, 当 N个保护通道中的部分保护通道失效吋, 按照符合逻辑退化原则进行 处理。 所谓符合逻辑退化原则是指, 当 N个保护通道中的某个保护通道失效吋, 符合逻辑处理退化为 N-1取一符合逻辑、 N-1取二符合逻辑等; 当 N-1个保护通道 中的某个保护通道失效吋, 符合逻辑处理进一步退化为 N-2取一符合逻辑、 N-2 取二符合逻辑等。 举例而言, ESFAS符合逻辑电路初始吋对从来自 4个保护通道 的 4个阈值比较结果进行四取二符合逻辑处理, 当某个保护通道失效吋, 退化为 三取二符合逻辑处理, 当又有一个保护通道失效吋, 进一步退化为二取一符合 逻辑处理。
[0073] 另外, 虽然在上述说明中初始吋以 N取二符合逻辑为例进行说明, 但初始吋也 可进行 N取一符合逻辑或 N-1取二等。
[0074] 另外, 在本实施例中, 通过设置 ESFAS符合逻辑电路, 使得在保护通道部分失 效的情况下也能够确保专设驱动系统 20功能的正常实现。
[0075] 实施例三
[0076] 在上述实施例一或实施例二的基础上, 本实施例用于对紧急停堆系统 10进行进 一步说明。
[0077] 紧急停堆系统 10的 N个保护通道之间点对点连接, 每个保护通道从另外 N-1个 保护通道获取阈值比较结果。 如图 1所示, RPC-I从 RPC-II~RPC-IV获取阈值比较 结果。
[0078] 每个保护通道均具备热备冗余处理器 (未图示) , 热备冗余处理器根据来自 N 个保护通道的 N个阈值比较结果得到第三局部停堆信号。 每个保护通道均连接停 堆断路器, 停堆断路器从每个保护通道获取第三局部停堆信号, 并执行第三局 部停堆信号控制核电站停堆。
[0079] 更具体地, 紧急停堆系统 10的每个保护通道均分为第一子组与第二子组, 还包 括与第一子组、 第二子组连接的 RTS或逻辑处理电路。 每个子组内配热备冗余处 理器 (未图示) , 第一子组内的称为第一热备冗余处理器, 第二子组内的称为 第二热备冗余处理器。
[0080] 所分得的 N个第一子组之间点对点连接, 所分得的 N个第二子组之间点对点连 接。 如图 1所示, 保护通道 RTS IP的停堆保护控制柜 RPC-I分为第一子组 Subl与 第二子组 Sub2。 其他保护通道 RTS IIP-RTS IVP同样分为第一子组 Subl与第二子 组 Sub2。 4个第一子组 Subl之间两两连接, 4个第二子组 Sub2之间两两连接。
[0081] 根据两两连接的关系, 每个第一子组均从另外 N-1个第一子组获取阈值比较结 果。 第一热备冗余处理器用于对来自 N个第一子组的 N个阈值比较结果进行符合 逻辑处理, 即对该第一 RTS符合逻辑电路所在的第一子组的 1个阈值比较结果及 另外 N-1个第一子组的 N-1个阈值比较结果进行符合逻辑处理。 并且, 在 N个保护 通道中的部分保护通道失效吋, 按照符合逻辑退化原则进行处理, 输出第一局 部停堆信号。 类似于第三局部停堆信号, 第一局部停堆信号同样用于控制核电 站停堆, 但是, 第一局部停堆信号属于中间信号。
[0082] 同样地, 根据两两连接的关系, 每个第二子组均从另外 N-1个第二子组获取阈 值比较结果。 第二热备冗余处理器用于对来自 N个第二子组的 N个阈值比较结果 进行符合逻辑处理, 并且在 N个保护通道中的部分保护通道失效吋, 按照符合逻 辑退化原则进行处理, 输出第二局部停堆信号。 第二局部停堆信号属于中间信 号。
[0083] 需要说明的是, 在本实施例中, 根据多样化设计需求, 第一子组 Subl及第二子 组 Sub2可分别处理不同类型的保护参数及其阈值比较结果, 执行不同的保护功 能。
[0084] 紧急停堆系统 10的每个保护通道还均具备 RTS或逻辑处理电路, 在图 1中用符 号"≥1"表示。 RTS或逻辑处理电路与第一子组 Subl及第二子组 Sub2连接。 根据 与第一子组及第二子组的连接关系, RTS或逻辑处理电路对第一局部停堆信号与 第二局部停堆信号进行或逻辑处理, 输出第三局部停堆信号。
[0085] 如上所述, 紧急停堆系统 10用于当反应堆运行中出现设计基准事故吋触发紧急 停堆。 在此, 第三局部停堆信号可通过硬接线传输至停堆断路器 RTB, 从而触发 紧急停堆。 需要说明的是, 与 N个第三局部停堆信号相对应, 停堆断路器 RTB同 样可设置为 N对, N对停堆断路器可通过硬接线实现 N取二符合逻辑等, 即至少 两对停堆断路器打幵才可实现紧急停堆。 如有保护通道故障或失效, 则停堆断 路器硬接线符合逻辑依次退化为三取二、 二取一。
[0086] 在本实施例中, 通过第一子组 Subl及第二子组 Sub2的设置, 使得在保护通道部 分失效的情况下也能够确保紧急停堆系统 10功能的正常实现。
[0087] 在实施例二及三的一个更具体的实施方式中, 核电站反应堆保护系统 100还可 设置紧急控制盘 ECP (Emergency Control Panel) 70。 紧急控制盘 70的手动专设 驱动按钮与专设驱动系统 20通过硬接线连接, 用于根据操作人员的操作指令输 出第二专设驱动指令。 类似于第一专设驱动指令, 第二专设驱动指令同样用于 驱动反应堆达到可控状态前需要操作的执行机构。 [0088] 专设驱动系统 20可接收紧急控制盘 70输出的第二专设驱动指令, 其中的运算处 理器还可用于对第一专设驱动指令与第二专设驱动指令进行或逻辑处理, 输出 第三专设驱动指令。 类似地, 第三专设驱动指令用于驱动反应堆达到可控状态 前需要操作的执行机构。 可以理解的是, 在设置紧急控制盘 70的情况下, 在运 算处理器的或逻辑处理的控制下, 第一专设驱动指令与第二专设驱动指令转换 为第三专设驱动指令, 仅第三专设驱动指令输送至执行机构。
[0089] 在该更具体的实施方式中, 通过紧急控制盘 70的设置, 能够代替专设驱动系统 20实现对专设安全设施的紧急驱动。 通过运算处理器的或逻辑处理, 能够协调 专设驱动系统 20与紧急控制盘 70对专设安全设施的驱动。
[0090] 除了代替专设驱动系统 20实现对专设安全设施的紧急驱动外, 紧急控制盘 70还 可直接手动实现紧急控制核电站停堆。 在此, 紧急控制盘 70通过硬接线直接连 接停堆断路器 RTB, 并向停堆断路器 RTB输出第四局部停堆信号。 停堆断路器 R TB可获取并执行第四局部停堆信号控制核电站停堆。
[0091] 与紧急控制盘 70相对, 核电站反应堆保护系统 100还可设置可视化的安全级控 制显示设备 SCID (Safety Control and Information Device) 80, 其用于代替安全自 动化系统 30紧急驱动执行机构。 在此, 安全级控制显示设备 80分为三组, 每组 通过一个安全级子环网与一个 ESFAS序列及一个 SAS序列一一对应连接。 例如, 组 SCID A通过 Train A与 ESFAC-A及 SAS A连接。 并且, 安全级控制显示设备 80 与安全自动化系统 30连接, 用于根据操作人员的操作指令输出第二设备级控制 指令。
[0092] 每组根据操作人员的操作指令输出第二设备级控制指令, 对应的 SAS序列接收 该第二设备级控制指令, 并对自身的第一设备级控制指令与该第二设备级控制 指令进行或逻辑处理, 输出第三设备级控制指令。 类似地, 第三设备级控制指 令用于对反应堆从可控状态到安全停堆状态需要操作的执行机构进行控制。
[0093] 通过安全级控制显示设备 80的设置, 同样能够实现对专设安全设施的紧急驱动 。 通过 SAS或逻辑处理电路的设置, 能够协调安全自动化系统 30与安全级控制显 示设备 80对专设安全设施的驱动。
[0094] 实施例四 [0095] 在上述实施例一至实施例三中任一实施例的基础上, 本实施例对现有技术中的 核电站反应堆保护系统 100进行进一步改进。
[0096] 本实施例涉及预期瞬态不停堆系统 (Anticipated Transient Without Trip
System, ATWS), ATWS对应通过多样化停堆控制及跳机, 启动应急给水等功能 缓解保护系统未能实现紧急停堆情况下的后果。
[0097] 在本实施例中, 还设置多样化驱动系统 KDS (Diversity Actuation System) 50, 其用于实现 ATWS系统的功能。 多样化驱动系统 50可与每列信号预处理系统 11连 接, 用于在紧急停堆系统 10与专设驱动系统 20发生共模失效的情况下, 从信号 预处理系统 11获取保护参数, 并根据所述保护参数输出停堆控制指令。
[0098] 多样化驱动系统 50还与棒控系统 (Full Length Rod Control System, RGL) 连接
, 棒控系统从多样化驱动系统 50接收该停堆控制指令, 并执行该停堆控制指令 控制核电站停堆。 因此, 多样化驱动系统 50能够在核电站反应堆保护系统 100共 模失效情况下, 保证关键的保护功能实现。
[0099] 并且, 由于 ATWT的功能被放在多样化驱动系统 50中实现, 因而不需要再单独 设计一套 ATWT实体机柜来实现该多样化功能, 从而精简了核电站反应堆保护系 统 100。
[0100] 在上述说明中, 多样化驱动系统 50与每列信号预处理系统 11连接, 从信号预处 理系统 11获取保护参数, 但本发明不仅限于此, 多样化驱动系统 50可通过硬接 线与第三方系统 (未图示) 连接, 直接通过硬接线从第三方系统获取保护参数 , 或者, 从现场仪表获取保护参数。
[0101] 另外, 多样化驱动系统 50还可用于根据保护参数输出第三专设驱动指令, 第三 专设驱动指令同样用于驱动反应堆达到可控状态前需要操作的执行机构。 第三 专设驱动指令可传输至后述的接口及优先级模块 CIM 60。
[0102] 另外, 当紧急停堆系统 10、 专设驱动系统 20正常吋, 多样化驱动系统 50的自动 逻辑功能正常运行, 但手动操作指令闭锁。
[0103] 需要说明的是, 多样化驱动系统 50中实现的功能一般不属于核电站反应堆保护 系统 100中实现的保护功能, 但是, 在本发明中, 鉴于核电站反应堆保护系统 10 0与多样化驱动系统 50的设置具有密切的关系, 且 ATWS系统功能在多样化驱动 系统 50中实现, 因此, 可将多样化驱动系统 50看作核电站反应堆保护系统 100的 一部分。
[0104] 另外, 在现有技术中, 没有对专设驱动系统 20与安全自动化系统 30进行区分设 计, 因此, 第一专设驱动指令与第一设备级控制指令也没有被区分幵来。 然而 , 第一专设驱动指令相对于保护系统 100而言更为重要, 若不对两种指令进行优 先级划分, 将无法高效地实现保护系统 100的功能。
[0105] 为此, 核电站反应堆保护系统 100还设置设备接口及优先级模块 CIM 60。 设备 接口及优先级模块 60与安全自动化系统 30及多样化驱动系统 50连接。 设备接口 及优先级模块 60可分为三个序列, 每个序列主要由设备接口及优先级柜 CIC构成 。 如图 1所示, CIM分为 CIC A、 CIC B、 CIC
C这 3个序列。 并且, 3个序列与 3个 SAS序歹 ijSAS A、 SAS B、 SAS C——对应连 接。 设备接口及优先级模块 60用于获取第一设备级控制指令及第三专设驱动指 令。 此外, 设备接口及优先级模块 60还获取专设驱动系统 20。 输出的第一专设 驱动指令, 其中第一专设驱动指令通过安全级环网 40及安全自动化系统 30。
[0106] 可以理解的是, 虽然在上述说明中, 第一设备级控制指令、 第三专设驱动指令 及第一专设驱动指令直接送至对应的执行机构, 但是, 在设置设备接口及优先 级模块 60的情况下, 这些指令可先经过设置设备接口及优先级模块 60的优先级 处理之后再送至执行机构。 也即, 设备接口及优先级模块 60可对接收到的多个 指令进行优先级处理, 确定优先级最高的指令, 使得执行机构优先执行优先级 最高的指令, 因此, 能够高效地实现保护系统的功能。
[0107] 另外, 通过图 1可以看出, 本实施例提供的核电站反应堆保护系统 100中不需要 针对保护系统多样化设计要求另外设计一套冗余继电器硬逻辑, 也即, 不在需 要大规模的功能冗余继电器机柜。
[0108] 与此相对, 在现有的核电站反应堆保护系统中, 为了满足保护系统多样化设计 要求, 除采用数字化技术实 ¾A、 B两列监控功能外, 另外设计一套继电器硬接 线逻辑设计, 实现数字化平台中重要的系统级控制功能的多样化冗余设计。
[0109] 本实施例提供的核电站反应堆保护系统 100中由于采用了多样化驱动系统, 因 此, 保护系统 100不需针对重要保护功能增配一套继电器逻辑, 大量减少了安全 级继电器机柜数量, 精简了电缆数量, 同吋给电气厂房的布置降低了难度。 另 夕卜, 继电器逻辑的减少大大简化了电厂定期试验的要求, 也降低了设备老化造 成的故障风险。
[0110] 实施例五
[0111] 本实施例提供一种核电站反应堆保护系统中的安全控制方法, 应用于对应于上 述实施例一至实施例四所提供的任一核电站反应堆保护系统 100中。 如图 2所示
, 所述方法包括如下步骤:
[0112] 阈值比较步骤 Sl, 其由紧急停堆系统 RTS执行, 紧急停堆系统分为 N个保护通 道, N为偶数且N≥2, 每个保护通道均对应连接一列信号预处理系统, 其中, 每 个保护通道从对应的信号预处理系统获取保护参数, 并根据保护参数进行阈值 比较, 得到阈值比较结果;
[0113] 专设驱动步骤 S2, 其由专设驱动系统 ESFAS执行, 专设驱动系统与 N个保护通 道连接, 用于接收每个保护通道的阈值比较结果, 并根据阈值比较结果进行专 设驱动逻辑处理, 输出第一专设驱动指令, 第一专设驱动指令用于驱动反应堆 达到可控状态前需要操作的执行机构;
[0114] 安全自动化步骤 S3, 其由安全自动化系统 SAS执行, 安全自动化系统通过安全 级环网与专设驱动系统连接, 产生第一设备级控制指令, 第一设备级控制指令 用于对反应堆从可控状态到安全停堆状态需要操作的执行机构进行控制。
[0115] 关于各步骤的具体说明, 可参照实施例一至实施例四的说明, 在此不再赘述。
根据本实施例提供的核电站反应堆保护系统中的安全控制方法, 能够降低保护 系统维护、 定期试验的方案复杂程度。
[0116] 在实施例五的一个更具体实施例中, 专设驱动系统分为三个 ESFAS序列, 每个
ESFAS序列均与 N个保护通道通过点对点通讯连接;
[0117] 每个 ESFAS序列均配置并行的、 冗余的两个运算处理器;
[0118] 在专设驱动步骤 S2中, 运算处理器对每个 ESFAS序列接收的 N个阈值比较结果 进行符合逻辑处理, 并且在 N个保护通道中的部分保护通道失效吋, 按照符合逻 辑退化原则进行处理。
[0119] 在实施例五的另一个更具体实施例中, 核电站反应堆保护系统还具备紧急控制 盘 ECP, 紧急控制盘 ECP的手动专设驱动按钮与专设驱动系统连接, 根据操作人 员的操作指令输出第二专设驱动指令;
[0120] 在专设驱动步骤 S2中, 运算处理器对第一专设驱动指令与第二专设驱动指令进 行或逻辑处理, 输出第三专设驱动指令, 第三专设驱动指令用于驱动反应堆达 到可控状态前需要操作的执行机构。
[0121] 在实施例五的又一个更具体实施例中, 安全自动化系统分为三个 SAS序列, 安 全级环网分为三组安全级子环网, 每个 SAS序列通过一个安全级子环网与一个 E
SFAS序列 对应连接;
[0122] 核电站反应堆保护系统还具备安全级控制显示设备 SCID, 其分为三组, 每组 通过一个安全级子环网与一个 ESFAS序列及一个 SAS序列一一对应连接, 每组 S
CID根据操作人员的操作指令输出第二设备级控制指令;
[0123] 在安全自动化步骤 S3中, SAS序列接收第二设备级控制指令, 并对第一设备级 控制指令与第二设备级控制指令进行或逻辑处理, 输出第三设备级控制指令, 第三设备级控制指令用于对反应堆从可控状态到安全停堆状态需要操作的执行 机构进行控制。
[0124] 在实施例五的又一个更具体实施例中, N个保护通道之间点对点连接, 每个保 护通道均具备热备冗余处理器, 每个保护通道均连接停堆断路器,
[0125] 方法还包括停堆控制步骤 S4, 在停堆控制步骤 S4中, 每个保护通道从另外 N-1 个保护通道获取阈值比较结果, 热备冗余处理器根据来自 N个保护通道的 N个阈 值比较结果得到第三局部停堆信号, 停堆断路器从每个保护通道获取第三局部 停堆信号, 并执行第三局部停堆信号控制核电站停堆。
[0126] 关于实施例五的各个更具体实施例中各步骤的具体说明, 同样可参照实施例一 至实施例四的说明, 在此不再赘述。
[0127] 以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易想到变化 或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护范围应以权 利要求的保护范围为准。

Claims

权利要求书
[权利要求 1] 一种核电站反应堆保护系统, 其特征在于, 具备:
紧急停堆系统 RTS, 其分为 N个保护通道, N为偶数且N≥2, 每个保 护通道均对应连接一列信号预处理系统, 其中, 所述每个保护通道从 对应的所述信号预处理系统获取保护参数, 并根据所述保护参数进行 阈值比较, 得到阈值比较结果;
专设驱动系统 ESFAS , 其与所述 N个保护通道连接, 用于接收每个保 护通道的阈值比较结果, 并根据所述阈值比较结果进行专设驱动逻辑 处理, 输出第一专设驱动指令, 所述第一专设驱动指令用于驱动反应 堆达到可控状态前的执行机构;
安全自动化系统 SAS, 其通过安全级环网与所述专设驱动系统 ESFAS 连接, 用于产生第一设备级控制指令, 所述第一设备级控制指令用于 对从反应堆达到可控状态到安全停堆状态的执行机构进行控制。
[权利要求 2] 根据权利要求 1所述的保护系统, 其特征在于, 所述专设驱动系统 ES
FAS分为三个 ESFAS序列, 每个 ESFAS序列均与所述 N个保护通道通 过点对点通讯连接。
[权利要求 3] 根据权利要求 2所述的保护系统, 其特征在于,
所述每个 ESFAS序列均配置并行的、 冗余的两个运算处理器。
[权利要求 4] 根据权利要求 3所述的保护系统, 其特征在于,
所述运算处理器用于对所述每个 ESFAS序列接收的 N个所述阈值比较 结果进行符合逻辑处理, 并且在所述 N个保护通道中的部分保护通道 失效吋, 按照符合逻辑退化原则进行处理。
[权利要求 5] 根据权利要求 3或 4所述的保护系统, 其特征在于,
还具备紧急控制盘 ECP, 其手动专设驱动按钮与所述专设驱动系统 ES FAS通过硬接线连接, 用于根据操作人员的操作指令输出第二专设驱 动指令;
所述运算处理器还用于对所述第一专设驱动指令与所述第二专设驱动 指令进行或逻辑处理, 输出第三专设驱动指令, 所述第三专设驱动指 令用于驱动反应堆达到可控状态前需要操作的执行机构。
[权利要求 6] 根据权利要求 2所述的保护系统, 其特征在于,
所述安全自动化系统 SAS分为三个 SAS序列, 所述安全级环网分为三 组安全级子环网, 每个 SAS序列通过一个所述安全级子环网与一个所 述 ESFAS序列 对应连接。
[权利要求 7] 根据权利要求 6所述的保护系统, 其特征在于,
还具备安全级控制显示设备 SCID, 其分为三组, 每组 SCID通过一个 所述安全级子环网与一个所述 ESFAS序列及一个所述 SAS序列一一对 应连接;
每组 SCID根据操作人员的操作指令输出第二设备级控制指令, 所述 S AS序列接收所述第二设备级控制指令, 并对所述第一设备级控制指 令与所述第二设备级控制指令进行或逻辑处理, 输出第三设备级控制 指令, 所述第三设备级控制指令用于对反应堆从可控状态到安全停堆 状态需要操作的执行机构进行控制。
[权利要求 8] 根据权利要求 1所述的保护系统, 其特征在于,
所述 N个保护通道之间点对点连接, 所述每个保护通道从另外 N-1个 保护通道获取所述阈值比较结果,
所述每个保护通道均具备热备冗余处理器, 所述热备冗余处理器根据 来自所述 N个保护通道的所述 N个所述阈值比较结果得到第三局部停 堆信号,
所述每个保护通道均连接停堆断路器, 所述停堆断路器从所述每个保 护通道获取所述第三局部停堆信号, 并执行所述第三局部停堆信号控 制核电站停堆。
[权利要求 9] 根据权利要求 8所述的保护系统, 其特征在于,
所述每个保护通道均分为第一子组与第二子组, 所分得的 N个所述第 一子组之间点对点连接, 所分得的 N个所述第二子组之间点对点连接 每个第一子组均从另外 N-1个第一子组获取所述阈值比较结果, 每个 第一子组均具备第一热备冗余处理器, 所述第一热备冗余处理器用于 对来自所述 N个第一子组的 N个所述阈值比较结果进行符合逻辑处理 , 并且在 N个保护通道中的部分保护通道失效吋, 按照退化原则进行 符合逻辑处理, 输出第一局部停堆信号;
每个第二子组均从另外 N-1个第二子组获取所述阈值比较结果, 每个 第二子组均具备第二热备冗余处理器, 所述第二热备冗余处理器用于 对来自所述 N个第二子组的 N个所述阈值比较结果进行符合逻辑处理 , 并且在 N个保护通道中的部分保护通道失效吋, 按照退化原则进行 符合逻辑处理, 输出第二局部停堆信号;
所述紧急停堆系统 RTS的每个保护通道还均具备 RTS或逻辑处理电路 , 所述 RTS或逻辑处理电路与所述第一子组及所述第二子组连接, 用 于对所述第一局部停堆信号与所述第二局部停堆信号进行或逻辑处理 , 输出所述第三局部停堆信号。
[权利要求 10] 根据权利要求 8所述的保护系统, 其特征在于,
还具备紧急控制盘 ECP, 所述紧急控制盘的手动停堆控制按钮通过硬 接线直接连接所述停堆断路器, 并向所述停堆断路器输出第四局部停 堆信号, 所述停堆断路器获取并执行所述第四局部停堆信号控制核电 站停堆。
[权利要求 11] 根据权利要求 1所述的保护系统, 其特征在于,
还具备多样化驱动系统 KDS, 其实现预期瞬态不停堆系统的系统 AT WS的功能, 用于在所述保护系统发生共模失效的情况下, 从所述信 号预处理系统或现场仪表或第三方监测系统获取保护参数, 并根据所 述保护参数输出停堆控制指令,
所述多样化驱动系统与棒控系统连接, 所述棒控系统从所述多样化驱 动系统接收所述停堆控制指令, 并执行所述停堆控制指令控制核电站 停堆。
[权利要求 12] 根据权利要求 11所述的保护系统, 其特征在于,
所述多样化驱动系统还用于根据所述保护参数输出第三专设驱动指令 , 所述第三专设驱动指令用于驱动反应堆达到可控状态前需要操作的 执行机构。
[权利要求 13] 根据权利要求 12所述的保护系统, 其特征在于,
还具备设备接口及优先级模块 CIM, 其与所述安全自动化系统 SAS及 所述多样化驱动系统连接, 用于获取所述第一设备级控制指令及所述 第三专设驱动指令, 还通过所述安全级环网及所述安全自动化系统 S AS获取所述专设驱动系统 ESFAS输出的所述第一专设驱动指令, 并 对获取到的多个指令进行优先级处理。
[权利要求 14] 根据权利要求 11所述的保护系统, 其特征在于,
当所述紧急停堆系统 RTS、 所述专设驱动系统 ESFAS正常吋, 所述多 样化驱动系统的自动逻辑功能正常运行, 手动操作指令闭锁。
[权利要求 15] —种核电站反应堆保护系统中的安全控制方法, 其特征在于, 包括如 下步骤:
阈值比较步骤, 其中, 紧急停堆系统 RTS的多个保护通道均从对应的 信号预处理系统获取保护参数, 并对所述保护参数进行阈值比较, 得 到阈值比较结果;
专设驱动步骤, 其中, 专设驱动系统 ESFAS接收每个保护通道的阈值 比较结果, 并根据所述阈值比较结果进行专设驱动逻辑处理, 输出第 一专设驱动指令, 所述第一专设驱动指令用于驱动反应堆达到可控状 态前需要操作的执行机构;
安全自动化步骤, 其中, 安全自动化系统 SAS产生第一设备级控制指 令, 所述第一设备级控制指令用于对反应堆从可控状态到安全停堆状 态需要操作的执行机构进行控制。
[权利要求 16] 根据权利要求 15所述的方法, 其特征在于,
所述专设驱动系统 ESFAS分为三个 ESFAS序列, 每个 ESFAS序列均与 多个保护通道通过点对点通讯连接;
所述每个 ESFAS序列均配置并行的、 冗余的两个运算处理器; 在所述专设驱动步骤中, 所述运算处理器对所述每个 ESFAS序列接收 的多个所述阈值比较结果进行符合逻辑处理, 并且在所述多个保护通 道中的部分保护通道失效吋, 按照符合逻辑退化原则进行处理。
[权利要求 17] 根据权利要求 16所述的方法, 其特征在于,
所述核电站反应堆保护系统还具备紧急控制盘 ECP, 所述紧急控制盘 ECP的手动专设驱动按钮与所述专设驱动系统 ESFAS连接, 根据操作 人员的操作指令输出第二专设驱动指令;
在所述专设驱动步骤中, 所述运算处理器对所述第一专设驱动指令与 所述第二专设驱动指令进行或逻辑处理, 输出第三专设驱动指令, 所 述第三专设驱动指令用于驱动反应堆达到可控状态前需要操作的执行 机构。
[权利要求 18] 根据权利要求 16所述的方法, 其特征在于,
所述安全自动化系统 SAS分为三个 SAS序列, 所述安全级环网分为三 组安全级子环网, 每个 SAS序列通过一个所述安全级子环网与一个所 述 ESFAS序列 对应连接;
所述核电站反应堆保护系统还具备安全级控制显示设备 SCID, 其分 为三组, 每组通过一个所述安全级子环网与一个所述 ESFAS序列及一 个所述 SAS序列一一对应连接, 每组 SCID根据操作人员的操作指令 输出第二设备级控制指令;
在所述安全自动化步骤中, 所述 SAS序列接收所述第二设备级控制指 令, 并对所述第一设备级控制指令与所述第二设备级控制指令进行或 逻辑处理, 输出第三设备级控制指令, 所述第三设备级控制指令用于 对反应堆从可控状态到安全停堆状态需要操作的执行机构进行控制。
PCT/CN2015/097513 2015-12-15 2015-12-15 核电站反应堆保护系统及其中的安全控制方法 Ceased WO2017101031A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/097513 WO2017101031A1 (zh) 2015-12-15 2015-12-15 核电站反应堆保护系统及其中的安全控制方法

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2015/097513 WO2017101031A1 (zh) 2015-12-15 2015-12-15 核电站反应堆保护系统及其中的安全控制方法

Publications (1)

Publication Number Publication Date
WO2017101031A1 true WO2017101031A1 (zh) 2017-06-22

Family

ID=59055384

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/097513 Ceased WO2017101031A1 (zh) 2015-12-15 2015-12-15 核电站反应堆保护系统及其中的安全控制方法

Country Status (1)

Country Link
WO (1) WO2017101031A1 (zh)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108962405A (zh) * 2018-07-27 2018-12-07 中国核动力研究设计院 一种应用于核电厂保护系统的ptr水位信号处理方法
CN109920562A (zh) * 2019-03-25 2019-06-21 北京广利核系统工程有限公司 一种用于核电站的保护系统控制装置
CN110556189A (zh) * 2018-05-31 2019-12-10 华龙国际核电技术有限公司 一种核电站多样性保护系统和核电站
US11105526B1 (en) 2017-09-29 2021-08-31 Integrated Global Services, Inc. Safety shutdown systems and methods for LNG, crude oil refineries, petrochemical plants, and other facilities
CN115171937A (zh) * 2022-06-30 2022-10-11 中广核研究院有限公司 反应堆失流保护控制方法、装置、计算机设备和存储介质
CN119905285A (zh) * 2025-01-03 2025-04-29 深圳中广核工程设计有限公司 一种核电厂设备驱动控制优先级管理系统及方法
WO2025192779A1 (ko) * 2024-03-14 2025-09-18 한국수력원자력 주식회사 우회채널을 이용한 다수의 원자로에 대한 보호계통의 시험방법

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102426863A (zh) * 2011-10-31 2012-04-25 中广核工程有限公司 核电站反应堆停堆信号传输系统和方法
CN101783192B (zh) * 2009-10-23 2012-07-18 中广核工程有限公司 一种核电站公用控制网
CN101968974B (zh) * 2010-08-09 2013-01-02 中广核工程有限公司 一种核电站反应堆保护系统
CN102157208B (zh) * 2010-11-12 2013-03-27 中广核工程有限公司 一种核电站反应堆保护系统
WO2015112304A2 (en) * 2013-12-31 2015-07-30 Nuscale Power, Llc Nuclear reactor protection systems and methods

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101783192B (zh) * 2009-10-23 2012-07-18 中广核工程有限公司 一种核电站公用控制网
CN101968974B (zh) * 2010-08-09 2013-01-02 中广核工程有限公司 一种核电站反应堆保护系统
CN102157208B (zh) * 2010-11-12 2013-03-27 中广核工程有限公司 一种核电站反应堆保护系统
CN102426863A (zh) * 2011-10-31 2012-04-25 中广核工程有限公司 核电站反应堆停堆信号传输系统和方法
WO2015112304A2 (en) * 2013-12-31 2015-07-30 Nuscale Power, Llc Nuclear reactor protection systems and methods

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11105526B1 (en) 2017-09-29 2021-08-31 Integrated Global Services, Inc. Safety shutdown systems and methods for LNG, crude oil refineries, petrochemical plants, and other facilities
US12007132B2 (en) 2017-09-29 2024-06-11 Integrated Global Services, Inc. Safety shutdown systems and methods for LNG, crude oil refineries, petrochemical plants, and other facilities
CN110556189A (zh) * 2018-05-31 2019-12-10 华龙国际核电技术有限公司 一种核电站多样性保护系统和核电站
CN108962405A (zh) * 2018-07-27 2018-12-07 中国核动力研究设计院 一种应用于核电厂保护系统的ptr水位信号处理方法
CN109920562A (zh) * 2019-03-25 2019-06-21 北京广利核系统工程有限公司 一种用于核电站的保护系统控制装置
CN115171937A (zh) * 2022-06-30 2022-10-11 中广核研究院有限公司 反应堆失流保护控制方法、装置、计算机设备和存储介质
WO2025192779A1 (ko) * 2024-03-14 2025-09-18 한국수력원자력 주식회사 우회채널을 이용한 다수의 원자로에 대한 보호계통의 시험방법
CN119905285A (zh) * 2025-01-03 2025-04-29 深圳中广核工程设计有限公司 一种核电厂设备驱动控制优先级管理系统及方法

Similar Documents

Publication Publication Date Title
CN105575448B (zh) 核电站反应堆保护系统及其中的安全控制方法
WO2017101031A1 (zh) 核电站反应堆保护系统及其中的安全控制方法
US9997265B2 (en) Safety system for a nuclear power plant and method for operating the same
US20110202163A1 (en) Plant protection system and method using field programmable gate array
EP3316262B1 (en) Safety control system for a nuclear power plant
EP2573636B1 (en) Multi-channel control switchover logic
KR100848881B1 (ko) 디지털 원자로 보호 시스템
CN85109748A (zh) 基于对复杂过程的传感器信号处理系统的分布式微处理机
CN105448368A (zh) 一种核电站多样性驱动系统及方法和多样性保护系统
EP3316261A1 (en) Control system for the safety of nuclear power plant
US9627877B2 (en) Control system and method for nuclear power facility
CN104538072A (zh) 核电站安全级dcs多功能接口和控制方法
CN110767338A (zh) 一种核动力堆dcs架构
EP2602794B1 (en) Control system for nuclear power plant
KR101681978B1 (ko) 이종 제어기기를 포함하는 원자로 보호계통
US6473479B1 (en) Dual optical communication network for class 1E reactor protection systems
Oh et al. Fault-tolerant design for advanced diverse protection system
KR101631631B1 (ko) 보호계전기의 고장진단 및 복구방법
CN110324224A (zh) 一种核电机组安全级dcs网络结构
WO2017079950A1 (zh) 一种核电站多样性驱动系统及方法和多样性保护系统
KR102291654B1 (ko) 발전소 사고 상황에 맞게 최적화된 계측 제어 시스템 및 계측 제어 방법
Hwang et al. System and software design for the plant protection system for Shin-Hanul nuclear power plant units 1 and 2
KR20240139444A (ko) 다양성을 이용한 발전소 보호 계통
Suh et al. Developing architecture for upgrading I&C systems of an operating nuclear power plant using a quality attribute-driven design method
He et al. Design and Application of VVER Reactor Type Pre-protection System Based on Domestic DCS

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15910504

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15910504

Country of ref document: EP

Kind code of ref document: A1