Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
01 POWER ISLAND / Overview of Light Water.docx
Скачиваний:
0
Добавлен:
01.04.2025
Размер:
8.88 Mб
Скачать

frequencies of the safety protection system.

The safety protection system detects any anomalies in the reactor system and, if necessary, activates necessary actions to shut down the reactor or other appropriate safety functions. The safety protection system activates the reactor shutdown systems and the ESFs.

The safety protection system has many reactor trip circuits which, upon detection of reactor excessive power level and/or abnormal power increase, automatically actuate the emergency reactor shutdown system. The system also actuates, in an accident, the ECCS, the PCV isolation valves and other necessary systems in order to protect the reactor core and the PCV boundary.

The safety protection system is designed to have necessary redundancy and independency to assure its functions under the single failure criterion. That is, the safety protection system consists of redundant channels, and maintains its integrity of safety protection functions even when a single failure is assumed or a single channel is removed from the system for test and maintenance purposes during reactor operation. Further, the system has a "one-out-of-two-twice"*2 or a "two-out-of-four"*3 logic matrix structure, to prevent system malfunctions caused by false signals.

The channels of the safety protection system are made physically and electrically separated each other for independency, as thoroughly as practically possible. Each channel has its own cable tray and instrument board rack.

Furthermore, the safety protection system is designed on the "fail-safe" philosophy, so that the system stays either actuated or in a safe state, in case its power is lost or the circuit is disconnected. The safety protection system is independent from the reactor control system. This ensures that the safety protection system is not spuriously actuated by the failures of the reactor control system circuits, such as short circuits or disconnections. The safety protection system is designed to be testable, during reactor operation, for its instrumentation channels and logical circuit trains.

The main control room accommodates, for centralized plant management under any plant conditions, all kinds of indicators, recorders, monitoring systems, control/maneuvering systems

and other operation support systems for normal, shutdown and accident management operations of the reactor. The main control room is designed to allow the operators in an accident to continue their work without over-exposure to radiation.

To minimize the risk of fire in and around the main control room, the control panels, main cables and other components are composed, in principle, of non-combustible and/or flame-retardant materials. Fire prevention measures are also provided.

  1. Other Systems

There are other safety design features, too, against natural phenomena (earthquakes, floods, tsunamis, etc.), external human-caused phenomena (aircraft crashes, etc.), internal missiles, fires, etc. In aseismic design, for example, all the systems are classified into groups according to their safety importance and individual systems are designed according to their importance of the level of earthquake-proof requirements.

Radiation exposures of the public around a plant as well as the plant employees are kept sufficiently low. Design precautions and operation management are practiced to achieve the target dose equivalent limits of 0.05 mSv/y for the public outside the radiation monitoring area. This value is even lower than the legally regulated value of 1 mSv/y determined according to the recommendations of the International Commission on Radiological Protection (ICRP).

; A "oneout-of-two" logic matrix means that, if one of the two detection systems is actuated, a pre-specified event follows. In a "one-out-of-two-twice" logic matrix, the pre-specified event occurs only when both of the "one-out-of-two" logic matrices are actuated.

(*3) In a "two-out-of-four" logic matrix, the pre-specified event occurs if two of four detection systems are actuated. This matrix ensures necessary on-demand operability of the matrix, while preventing spurious malfunctions due to a wrong signal unnecessary to any detection systems.

NSRA, Japan

2-4