Mirror, Mirror on the Wall Do You See Me at All? The Cyber-Physical Gap and its Implications on Risks: Modeling Nuclear Hazards Mitigation

Size: px
Start display at page:

Download "Mirror, Mirror on the Wall Do You See Me at All? The Cyber-Physical Gap and its Implications on Risks: Modeling Nuclear Hazards Mitigation"

Transcription

1 Mirror, Mirror on the Wall Do You See Me at All? The Cyber-Physical Gap and its Implications on Risks: Modeling Nuclear Hazards Mitigation Dov Dori Massachusetts Institute of Technology (visiting) Technion, Israel Institute of Technology UTSA Nov. 7, 2014

2 Multiple engineering professionals talk different languages Mechanical Engineers Civil Engineers Electronics Engineers Software Engineers Systems engineers are supposed to design systems and integrate these languages What language do they talk? 2

3 Systems Engineers Do Have Languages Systems Modeling Language SysML OMG Standard since 2007 Object-Process Methodology OPM OPM book published in 2002 ISO Standard as of Aug (formally: Publically Available Specification) OPM software: OPCAT, freely downloadable from Along with papers and other resources 3

4 The Six Leading MBSE Methodologies (INCOSE Task Force, Estefan, 2008 p 43) IBM Telelogic Harmony-SE INCOSE Object-Oriented Systems Engineering Method (OOSEM) IBM Rational Unified Process for Systems Engineering (RUP SE) for Model-Driven Systems Development (MDSD) Vitech Model-Based System Engineering (MBSE) Methodology JPL State Analysis (SA) Object-Process Methodology (OPM): 2014 ISO Standard (PAS) SysML was not surveyed since it is a language, not a methodology 4

5 The idea behind conceptual modeling conceived reality Is modeled by modeled reality Object is a Aircraft is a Vehicle Is modeled by Is modeled by Bus Gas Filling is Energy Replenishing Process Using graphical symbols, the model expresses physical things objects and processes and relations among them. Car 5 5

6 The Object-Process Theorem Stateful objects, processes, and relations among them constitute a necessary and sufficient universal ontology Corollary Using stateful objects, processes, and relations among them, one can model systems in any domain 6

7 Compact Ontology: OPM as a language with minimal alphabet OPM uses the smallest alphabet: Two types of things: (1) stateful objects (2) processes Two families of links: (1) structural link: connects two objects (2) procedural link: connects a processes with an object or object state 7

8 Object-Process Methodology (OPM) Things: Objects and Processes A thing that exists or might exist physically or informatically A thing that transforms one or more objects 8

9 Processes transform objects by (1) Consuming them: 9

10 Processes transform objects by (2) Creating them: 10

11 Processes transform objects by (3) Changing their state: 11

12 Any OPM Thing is one of: 1. Stateful Object 2. Process All the other elements are relations between things, expressed graphically as links 12

13 OPM Unifies the three main system aspects: Function (why the system is built), Structure (static aspect: what is the system made of), and Behavior (dynamic aspect: how the system changes over time) These aspects are expressed bi-modally, in graphics and equivalent text in a single model 13

14 Thing s Essence and Affiliation Attributes In OPM, a Thing (Object or Process) has two key attributes: Essence and Affiliation Essence pertains to the thing s nature Denotes whether the thing is physical or informatical. Affiliation pertains to the thing s scope Denotes whether the thing is systemic, i.e. part of the system, or environmental, i.e. part of the system s environment The Essence- Affiliation attribute value combinations 14

15 Cyber-Physical Systems: Characteristics Software-controlled physical systems Include physical and cybernetic components An agent a human decision-maker or an information & decision-making system is the cybernetic component Hardware (motors, actuators, VLSI chips ) is the physical component Physical processes signal and induce cybernetic events and vice versa 15

16 Essence is key to the Cyber-Physical Gap Thing s Essence is key to understanding and modeling the cyber-physical gap physical objects in the OPM model represent what is really out there actual states and values of objects informatical objects in the OPM model represent information about their corresponding physical objects available to a decision making agent (human or artificial) A cyber-physical gap exists when the state of the informatical object incorrectly indicates the state of the physical object is supposed to represent 16

17 Two main sources of cyber-physical gaps Incorrect instrument reading causes agents to create a different world view than what is really out there Agent s misconception or incorrect assumption possibly triggered or supported by incorrect measurement reading 17

18 Modeling the cyber-physical gap with OPM: The Three-Mile Island 2 Accident March 28,

19 2:00 2:15 We start with an OPM model of normal operation of Electric Energy Generating system by a Pressurized Water Reactor 19

20 Three OPM Models First OPM Model: We start with an OPM model of normal operation of Electric Energy Generating system by a Pressurized Water Reactor Second OPM Model: We continue with an OPM model of the reactor with the particular chain of faults with no human involvement, which culminated in the reactor core meltdown but could be prevented if humans stayed out Third OPM Model: We end with an OPM model of the reactor with the particular chain of faults, accounting for the cyberphysical gap that worked against the built-in security measures, ensuring the reactor core meltdown 20

21 First OPM Model: Electric Energy Generating by a Pressurized Water Reactor 21

22 Electric Energy Generating In-Zoomed: Animated Simulation 22

23 Turbine Spinning In-Zoomed: Animated Simulation 23

24 Electric Energy Successfully Generated 24

25 Auto-generated Object-Process Language (OPL) Example Feedwater can be cooling tower, condensor, or steam generator. cooling tower is initial. Pressurized Water Reactor consists of Reactor Secondary Unit, Reactor Primary Unit, and Cooling Tower. Reactor Secondary Unit consists of Turbine, Generator, and Main Feedwater Pump. Turbine consists of Condensate Pump. Condensate Pump can be operational or tripped. operational is initial. Main Feedwater Pump can be operational or tripped. operational is initial. Reactor Primary Unit consists of Reactor Core and Steam Generator. Cooling Tower consists of Circulating Water Pump. Electric Energy Generating is physical. Electric Energy Generating consists of Controlled Nuclear Reaction, Steam Generating, Turbine Spinning, and Electricity Generating. Electric Energy Generating requires Pressurized Water Reactor and Cooling Tower. Electric Energy Generating yields Electric Energy. Electric Energy Generating zooms into Controlled Nuclear Reaction, Steam Generating, Turbine Spinning, and Electricity Generating. Controlled Nuclear Reaction affects Reactor Core. Controlled Nuclear Reaction yields Heat Energy. Steam Generating affects Steam Generator. Steam Generating consumes Heat Energy. Steam Generating yields Steam. Turbine Spinning consists of Turbine Water Circulating, Water Cooling, Turbine Heat Removing, and Steam Generator Water Circulating. Turbine Spinning affects Turbine. Turbine Spinning consumes Steam. Turbine Spinning yields Mechanical Energy. Turbine Spinning zooms into Water Cooling, Turbine Water Circulating, Turbine Heat Removing, and Steam Generator Water Circulating. Water Cooling consumes Steam. Water Cooling yields cooling tower Feedwater. Turbine Water Circulating requires Circulating Water Pump. Turbine Water Circulating changes Feedwater from cooling tower to condensor. Turbine Heat Removing requires condensor Feedwater. Turbine Heat Removing yields Mechanical Energy. Steam Generator Water Circulating occurs if Main Feedwater Pump is operational and Condensate Pump is operational. Steam Generator Water Circulating changes Feedwater from condensor to steam generator. Electricity Generating requires Generator. Electricity Generating consumes Mechanical Energy. Electricity Generating yields Electric Energy. 25

26 When Things Start Going Wrong: Summary of Events The [TMI2] accident began about 4 a.m. on Wednesday, March 28, 1979, when the plant experienced a failure in the secondary, non-nuclear section of the plant (one of two reactors on the site). Either a mechanical or electrical failure prevented the main feedwater pumps from sending water to the steam generators that remove heat from the reactor core. This caused the plant's turbine-generator and then the reactor itself to automatically shut down. Immediately, the pressure in the primary system (the nuclear portion of the plant) began to increase. In order to control that pressure, the pilot-operated relief valve [PORV] (a valve located at the top of the pressurizer) opened. The valve should have closed when the pressure fell to proper levels, but it became stuck open. 26

27 Second OPM Model: Failing Pressurized Water Reactor Operation: no cyber-physical gap 27

28 Pump Failing Changes Pump from operational to tripped 28

29 Tripped Pumps Cause too high Pressure 29

30 Too High Pressure Causes PORV to open normally 30

31 PORV Mechanical Failing causes POPV stuck open 31

32 Due to POPV stuck open Primary Cooling Water Escape! 32

33 Reactor Core is melted 33

34 As if this is not bad enough - The Cyber-Physical Gap The valve should have closed when the pressure fell to proper levels, but it became stuck open. Instruments in the control room, however, indicated to the plant staff that the valve was closed. As a result, the plant staff was unaware that cooling water was pouring out of the stuck-open valve. As coolant flowed from the primary system through the valve, other instruments available to reactor operators provided inadequate information. There was no instrument that showed how much water covered the core. As a result, plant staff assumed that as long as the pressurizer water level was high, the core was properly covered with water. As alarms rang and warning lights flashed, the operators did not realize that the plant was experiencing a loss-of-coolant accident. They took a series of actions that made conditions worse. The water escaping through the stuck valve reduced primary system pressure so much that the reactor coolant pumps had to be turned off to prevent dangerous vibrations. To prevent the pressurizer from filling up completely, the staff reduced how much emergency cooling water was being pumped in to the primary system. These actions starved the reactor core of coolant, causing it to overheat. 34

35 Third OPM Model: The Cyber-Physical Model Version 35

36 Secondary pumps are tripped; Problems start 36

37 Pressure builds; PORV opens to relieve the too high pressure 37

38 PORV Closing fails due to sticky PORV; PORV gets stuck open 38

39 Crew uses false indication to determine that PORV is closed Physical object shaded First cyber-physical gap Incorrect instrument reading: PORV is (stuck) open, but due to the false PORV closed indication, the Crew determines PORV is closed! Informatical object not shaded 39

40 Since PORV is closed Crew determines Core Water Level high Physical object shaded Second cyber-physical gap Agent misconception: Since PORV is believed to be closed, the Crew determines That Core Water Level is too high while in reality they are low and still Depleting! Informatical object not shaded Informatical object not shaded Physical object shaded 40

41 When Pressure is too high Emergency Water is supplied Second cyber-physical gap: Since PORV is believed to be closed, the Crew determines That Core Water Level is too high while in reality they are low and Depleting! 41

42 but the Crew stops the water supply, starving the reactor core of coolant, causing it to overheat Final blow due to the second cyber-physical gap: Crew applies Emergency Water Supply Stopping since it determined Core Water Level to be too high, making it too low 42

43 Summary 1/2 The cyber-physical gap is a critical factor It must be accounted for when designing systems, notably safetycritical ones OPM is suitable for modeling cyberphysical gaps This is due to its notion of essence physical vs. informatical things 43

44 Summary 2/2 The model can be instrumental in helping designers consider how hazardous situations might arise This still leaves us with the hard state explosion problem: How to consider the exponential number of system states (combinations of all object states) How to test the sheer number of system states to determine the potential hazard of each 44

45 Questions and (hopefully) Answers Contact: Dov Dori 45

Operational Reactor Safety 22.091/22.903

Operational Reactor Safety 22.091/22.903 Operational Reactor Safety 22.091/22.903 Professor Andrew C. Kadak Professor of the Practice Lecture 19 Three Mile Island Accident Primary system Pilot operated relief valve Secondary System Emergency

More information

FIRE RISK ASSESSMENT IN GERMANY - PROCEDURE, DATA, RESULTS -

FIRE RISK ASSESSMENT IN GERMANY - PROCEDURE, DATA, RESULTS - International Conference Nuclear Energy in Central Europe 2000 Golf Hotel, Bled, Slovenia, September 11-14, 2000 FIRE RISK ASSESSMENT IN GERMANY - PROCEDURE, DATA, RESULTS - H.P. Berg Bundesamt für Strahlenschutz

More information

THREE MILE ISLAND ACCIDENT

THREE MILE ISLAND ACCIDENT THREE MILE ISLAND ACCIDENT M. Ragheb 4/12/2011 1. INTRODUCTION The Three Mile Island (TMI) Accident at Harrisburg, Pennsylvania in the USA is a severe and expensive incident that has seriously affected,

More information

INTRODUCTION. Three Mile Island Unit 2

INTRODUCTION. Three Mile Island Unit 2 INTRODUCTION here was an accident at Three Mile Island Unit 2 on March 28,1979. It caused extensive damage to the plant's nuclear fuel core. Most of the plant's major systems were relatively undamaged.

More information

Application of Nuclear and Aerospace Industry Experience to Offshore Barrier Integrity Management

Application of Nuclear and Aerospace Industry Experience to Offshore Barrier Integrity Management Application of Nuclear and Aerospace Industry Experience to Offshore Barrier 8 th International Conference on Integrated Operations in the Petroleum Industry Bill Nelson, Mariana Dionisio, Sondre Øie,

More information

Model Based Systems Engineering (MBSE) Media Study. Prepared by: Julia Murray

Model Based Systems Engineering (MBSE) Media Study. Prepared by: Julia Murray Model Based Systems Engineering (MBSE) Media Study Prepared by: Julia Murray May 2, 2012 TABLE OF CONTENTS 1.0 MODEL-BASED SYSTEMS ENGINEERING (MBSE) INITIATIVE... 5 2.0 MBSE DEFINITIONS & ADVANTAGES...

More information

Dynamic Behavior of BWR

Dynamic Behavior of BWR Massachusetts Institute of Technology Department of Nuclear Science and Engineering 22.06 Engineering of Nuclear Systems Dynamic Behavior of BWR 1 The control system of the BWR controls the reactor pressure,

More information

7.1 General 5 7.2 Events resulting in pressure increase 5

7.1 General 5 7.2 Events resulting in pressure increase 5 GUIDE YVL 2.4 / 24 Ma r ch 2006 Primary and secondary circuit pressure control at a nuclear power plant 1 Ge n e r a l 3 2 General design requirements 3 3 Pressure regulation 4 4 Overpressure protection

More information

Nuclear power plant systems, structures and components and their safety classification. 1 General 3. 2 Safety classes 3. 3 Classification criteria 3

Nuclear power plant systems, structures and components and their safety classification. 1 General 3. 2 Safety classes 3. 3 Classification criteria 3 GUIDE 26 June 2000 YVL 2.1 Nuclear power plant systems, structures and components and their safety classification 1 General 3 2 Safety classes 3 3 Classification criteria 3 4 Assigning systems to safety

More information

Nuclear Energy: Nuclear Energy

Nuclear Energy: Nuclear Energy Introduction Nuclear : Nuclear As we discussed in the last activity, energy is released when isotopes decay. This energy can either be in the form of electromagnetic radiation or the kinetic energy of

More information

This occurrence is considered to be of no significance with respect to the health and safety of the public.

This occurrence is considered to be of no significance with respect to the health and safety of the public. Serial No. MNS-15-072 September 10, 2015,. DUKESteven Vice D. President Capps, ENERGYMcGuire Nuclear Station Duke Energy MGOIVP 1 12700 Hagers Ferry Road Huntersville, NC 28078 0: 980.875.4805 f: 980.875.4809

More information

Factory owners must ensure the boiler is:

Factory owners must ensure the boiler is: Factory owners must ensure the boiler is: * Registered with the Boilers and Pressure Vessels Division, Labour Department * Examined by an appointed examiner and has a valid certificate of fitness * Supervised

More information

Object-Process Methodology as a basis for the Visual Semantic Web

Object-Process Methodology as a basis for the Visual Semantic Web Object-Process Methodology as a basis for the Visual Semantic Web Dov Dori Technion, Israel Institute of Technology, Haifa 32000, Israel dori@ie.technion.ac.il, and Massachusetts Institute of Technology,

More information

FULL ELECTRICAL LNG PLANTS: HIGHEST AVAILABILITY AND ENERGY EFFICIENCY THROUGH OVERALL SYSTEM DESIGN

FULL ELECTRICAL LNG PLANTS: HIGHEST AVAILABILITY AND ENERGY EFFICIENCY THROUGH OVERALL SYSTEM DESIGN FULL ELECTRICAL LN PLANTS: HIHEST AVAILABILITY AND ENERY EFFICIENCY THROUH OVERALL SYSTEM DESIN Dr. Edwin Lerch Siemens A Infrastructure and Cities Sector, IC S SE PTI, ermany Phone: 49-9131-7-34052 Fax:

More information

10 Nuclear Power Reactors Figure 10.1

10 Nuclear Power Reactors Figure 10.1 10 Nuclear Power Reactors Figure 10.1 89 10.1 What is a Nuclear Power Station? The purpose of a power station is to generate electricity safely reliably and economically. Figure 10.1 is the schematic of

More information

UNITED STATES NUCLEAR REGULATORY COMMISSION OFFICE OF NUCLEAR REACTOR REGULATION WASHINGTON, DC 20555-0001. June 16, 2011

UNITED STATES NUCLEAR REGULATORY COMMISSION OFFICE OF NUCLEAR REACTOR REGULATION WASHINGTON, DC 20555-0001. June 16, 2011 UNITED STATES NUCLEAR REGULATORY COMMISSION OFFICE OF NUCLEAR REACTOR REGULATION WASHINGTON, DC 20555-0001 June 16, 2011 NRC INFORMATION NOTICE 2011-12: REACTOR TRIPS RESULTING FROM WATER INTRUSION INTO

More information

Alain Nifenecker - General Electric Manager Controls Engineering

Alain Nifenecker - General Electric Manager Controls Engineering GE Energy Benefits of Integrating a Single Plant-Wide Control System Into a Standard Plant Design Philosophy Authors: Luis Cerrada Duque - Empresarios Agrupados Director of I&C Department Charles Weidner

More information

KU DESIGN GUIDELINES APPENDIX XVI RECOMMENDED BAS I/O CONTROL POINTS BY EQUIPMENT / SYSTEM

KU DESIGN GUIDELINES APPENDIX XVI RECOMMENDED BAS I/O CONTROL POINTS BY EQUIPMENT / SYSTEM KU DESIGN GUIDELINES APPENDIX XVI RECOMMENDED BAS I/O CONTROL POINTS BY EQUIPMENT / SYSTEM AIR HANDLING UNITS... 1 CHILLERS... 2 COOLING TOWERS... 2 CLOSED LOOP COOLERS... 2 MISCELLANEOUS SUPPLY FANS...

More information

MAINTENANCE INSTRUCTIONS. Thermia Robust heat pump

MAINTENANCE INSTRUCTIONS. Thermia Robust heat pump MAINTENANCE INSTRUCTIONS Thermia Robust heat pump 9 6 8 0-5 4 7 4 5 0 0 1 R e v. 3 Table of contents 1 Important information.................. 2 1.1 Product description....................... 2 1.2 General................................

More information

Introductions: Dr. Stephen P. Schultz

Introductions: Dr. Stephen P. Schultz Introductions: Dr. Stephen P. Schultz Vienna, Austria 1 3 September 2015 Work Experience Current Member Advisory Committee on Reactor Safeguards, U.S. Nuclear Regulatory Commission, 12/2011 Chair, Fukushima

More information

HOW DOES A NUCLEAR POWER PLANT WORK?

HOW DOES A NUCLEAR POWER PLANT WORK? HOW DOES A NUCLEAR POWER PLANT WORK? O n t a r i o P o w e r G e n e r a t i o n P U T T I N G O U R E N E R G Y T O U S G O O D E O N T A R I O P O W E R G E N E R A T I O N What a Nuclear Reactor Does

More information

Boiling Water Reactor Systems

Boiling Water Reactor Systems Boiling Water (BWR) s This chapter will discuss the purposes of some of the major systems and components associated with a boiling water reactor (BWR) in the generation of electrical power. USNRC Technical

More information

Safety Requirements Specification Guideline

Safety Requirements Specification Guideline Safety Requirements Specification Comments on this report are gratefully received by Johan Hedberg at SP Swedish National Testing and Research Institute mailto:johan.hedberg@sp.se -1- Summary Safety Requirement

More information

Preventing Overheated Boiler Incidents

Preventing Overheated Boiler Incidents Preventing Overheated Boiler Incidents PSE&G Appliance Service October 2012 Runaway Boiler Explosion Review Items Hazard Background Past Incidents PSE&G Emergency Response Future Process Improvements What

More information

Westinghouse AP1000 PWR and the Growing Market for New Nuclear Power Plants

Westinghouse AP1000 PWR and the Growing Market for New Nuclear Power Plants Westinghouse AP1000 PWR and the Growing Market for New Nuclear Power Plants Westinghouse Electric Company & The Nuclear Fuel Cycle Royal Commission - South Australia November 4, 2015 1 AP1000 is a trademark

More information

Enhancing Business Performance using Integrated Visibility and Big Data

Enhancing Business Performance using Integrated Visibility and Big Data Enhancing Business Performance using Integrated Visibility and Big Data Manish Sharma Marketing Leader GE Energy Management Manish.Sharma1@ge.com Photograph of Speaker ARC Advisory Group GE Energy Management

More information

System Aware Cyber Security

System Aware Cyber Security System Aware Cyber Security Application of Dynamic System Models and State Estimation Technology to the Cyber Security of Physical Systems Barry M. Horowitz, Kate Pierce University of Virginia April, 2012

More information

The Price-Anderson Act and the Three Mile Island Accident

The Price-Anderson Act and the Three Mile Island Accident The Price-Anderson Act and the Three Mile Island Accident OECD/NEA Workshop Nuclear Damages, Liability Issues, and Compensation Schemes Overview Overview of Nuclear Liability in U.S. Three Mile Island

More information

The Piping System Model a New Life Cycle Document. Elements of the Piping System Model

The Piping System Model a New Life Cycle Document. Elements of the Piping System Model Piping System Model as a Life Cycle Document White Paper Introduction When designing piping systems, a variety of documents are created providing the details necessary to design, purchase, build, and test

More information

ON-LINE MONITORING OF POWER PLANTS

ON-LINE MONITORING OF POWER PLANTS ON-LINE MONITORING OF POWER PLANTS Dr. Hans-Gerd Brummel Siemens Power Generation (PG), Huttenstrasse 12-16, 10553 Berlin, Germany Phone: +49 30 3464 4158, E-mail: hans-gerd.brummel@siemens.com Table of

More information

IAEA Training Course on Safety Assessment of NPPs to Assist Decision Making. System Analysis. Lecturer. Workshop Information IAEA Workshop

IAEA Training Course on Safety Assessment of NPPs to Assist Decision Making. System Analysis. Lecturer. Workshop Information IAEA Workshop IAEA Training Course on Safety Assessment of NPPs to Assist Decision Making System Analysis Lecturer Lesson Lesson IV IV 3_2.3 3_2.3 Workshop Information IAEA Workshop City, XX XX - City -XX, Country Month,

More information

How To Clean Up A Reactor Water Cleanup

How To Clean Up A Reactor Water Cleanup General Electric Systems Technology Manual Chapter 2.8 Reactor Water Cleanup System TABLE OF CONTENTS 2.8 REACTOR CLEANUP SYSTEM... 1 2.8.1 Introduction... 2 2.8.2 System Description... 2 2.8.3 Component

More information

FIELD TRIP TO A POWER PLANT - A Reading Guide

FIELD TRIP TO A POWER PLANT - A Reading Guide TITLE: TOPIC: FIELD TRIP TO A POWER PLANT - A Reading Guide Energy and the sources of energy used in power plants GRADE LEVEL: Secondary CONTENT STANDARD: Earth and Space Science CONTENT OBJECTIVE: For

More information

The Role of Automation Systems in Management of Change

The Role of Automation Systems in Management of Change The Role of Automation Systems in Management of Change Similar to changing lanes in an automobile in a winter storm, with change enters risk. Everyone has most likely experienced that feeling of changing

More information

May 23, 2011 Tokyo Electric Power Company

May 23, 2011 Tokyo Electric Power Company Analysis and evaluation of the operation record and accident record of Fukushima Daiichi Nuclear Power Station at the time of Tohoku-Chihou-Taiheiyou-Oki-Earthquake (summary) May 23, 2011 Tokyo Electric

More information

Best Practices and Approaches to Supply Chain Management

Best Practices and Approaches to Supply Chain Management Best Practices and Approaches to Supply Chain Management ATOMEX Forum 2012 Moscow 12.12. 14.12.2012 AF-Consult Switzerland Ltd Jan Kocourek 1 Objectives Provide information available regarding both the

More information

Roles and Responsibilities of Plant Commissioning, Hydrocarbon Introduction and Acceptance Test Run

Roles and Responsibilities of Plant Commissioning, Hydrocarbon Introduction and Acceptance Test Run Page 1 of 8 Introduction Roles and Responsibilities of Plant Commissioning, Hydrocarbon Introduction and Acceptance Test Run There are many parts of a grass root chemical plant construction. They include

More information

Functional Architectures with SysML

Functional Architectures with SysML Functional Architectures with SysML Jesko Lamm Senior Systems Engineer jla@bernafon.ch Tim Weilkiens Managing Director tim.weilkiens@de by Bernafon AG We believe in a world, in which people with restricted

More information

Failure to comply with the following cautions and warnings could cause equipment damage and personal injury.

Failure to comply with the following cautions and warnings could cause equipment damage and personal injury. 1.0 IMPORTANT RECEIVING INSTRUCTIONS Visually inspect all components for shipping damage. Shipping Damage is not covered by warranty. If shipping damage is found, notify carrier at once. The carrier is

More information

SOA for services or UML for objects: Reconciliation of the battle of giants with Object-Process Methodology

SOA for services or UML for objects: Reconciliation of the battle of giants with Object-Process Methodology SOA for services or UML for objects: Reconciliation of the battle of giants with Object-Process Methodology Dov Dori Technion, Israel Institute of Technology, Haifa, Israel Massachusetts Institute of Technology,

More information

EMERGENCY RESPONSE FOR THE AREA SURROUNDING THE CATTENOM NUCLEAR POWER PLANT

EMERGENCY RESPONSE FOR THE AREA SURROUNDING THE CATTENOM NUCLEAR POWER PLANT EMERGENCY RESPONSE FOR THE AREA SURROUNDING THE CATTENOM NUCLEAR POWER PLANT Information for the population in Rhineland-Palatinate Issued by: Supervision and Service Directorate (ADD) Willy- Brandt- Platz

More information

CDS TROUBLESHOOTING SECTION I. VACUUM. 1.0. Weak vacuum at wand. Gauge reads normal (10hg to 14hg)

CDS TROUBLESHOOTING SECTION I. VACUUM. 1.0. Weak vacuum at wand. Gauge reads normal (10hg to 14hg) CDS TROUBLESHOOTING SECTION I. VACUUM 1.0. Weak vacuum at wand. Gauge reads normal (10hg to 14hg) 1.1. Clogged hoses or wand tube. Disconnect hoses and carefully check for an obstruction. 1.2. Excessive

More information

Survey of Model-Based Systems Engineering (MBSE) Methodologies

Survey of Model-Based Systems Engineering (MBSE) Methodologies Survey of Model-Based Systems Engineering (MBSE) Methodologies Jeff A. Estefan Jet Propulsion Laboratory California Institute of Technology Pasadena, California, U.S.A. Jeffrey.A.Estefan@jpl.nasa.gov 1.

More information

Routine and Emergency Boiler Operation

Routine and Emergency Boiler Operation Routine and Emergency Boiler Operation Learning Outcome When you complete this module you will be able to: Describe the routine safe and efficient operation of a packaged boiler. Learning Objectives Here

More information

SysML Modelling Language explained

SysML Modelling Language explained Date: 7 th October 2010 Author: Guillaume FINANCE, Objet Direct Analyst & Consultant UML, the standard modelling language used in the field of software engineering, has been tailored to define a modelling

More information

Pressurized Water Reactor B&W Technology Crosstraining Course Manual. Chapter 9.0. Integrated Control System

Pressurized Water Reactor B&W Technology Crosstraining Course Manual. Chapter 9.0. Integrated Control System Pressurized Water Reactor B&W Technology Crosstraining Course Manual Chapter 9.0 Integrated Control System TABLE OF CONTENTS 9.0 INTEGRATED CONTROL SYSTEM... 1 9.1 Introduction... 1 9.2 General Description...

More information

Elements Elements describe the essential outcomes. 1. Prepare to diagnose and repair air conditioning and HVAC system

Elements Elements describe the essential outcomes. 1. Prepare to diagnose and repair air conditioning and HVAC system AURETU004 Application Competency Field Unit Sector Elements Elements describe the essential outcomes. 1. Prepare to diagnose and repair air conditioning and HVAC system 2. Diagnose air conditioning and

More information

543-0032-00, 943-0032-00. User s Manual

543-0032-00, 943-0032-00. User s Manual 543-0032-00, 943-0032-00 User s Manual 1 Comfort Alert Diagnostics Faster Service And Improved Accuracy The Comfort Alert diagnostics module is a breakthrough innovation for troubleshooting heat pump and

More information

Safety Integrated. SIMATIC Safety Matrix. The Management Tool for all Phases of the Safety Lifecycle. Brochure September 2010. Answers for industry.

Safety Integrated. SIMATIC Safety Matrix. The Management Tool for all Phases of the Safety Lifecycle. Brochure September 2010. Answers for industry. SIMATIC Safety Matrix The Management Tool for all Phases of the Safety Lifecycle Brochure September 2010 Safety Integrated Answers for industry. Functional safety and Safety Lifecycle Management Hazard

More information

Impact of Control System Technologies on Industrial Energy Savings

Impact of Control System Technologies on Industrial Energy Savings Impact of Control System Technologies on Industrial Energy Savings Priyam Parikh Industrial Assessment Center Texas A&M University Bryan P. Rasmussen Industrial Assessment Center Texas A&M University http://farolconsulting.com/?page_id=110

More information

Your Boiler Room: A Time Bomb?

Your Boiler Room: A Time Bomb? Your Boiler Room: A Time Bomb? Is you boiler room a potential Time Bomb? A few basics you need to know to work safely in the boiler room: Two potentials for explosions in a boiler room: Water/steam side

More information

Boiler & Pressure Vessel Inspection discrepancies and failures

Boiler & Pressure Vessel Inspection discrepancies and failures Boiler & Pressure Vessel Inspection discrepancies and failures Water Heaters / Pressure Vessels Pressure Vessels are inspected once every three years. This requires a test of A: safety relief devices B:

More information

INCOSE OOSEM Working Group Charter

INCOSE OOSEM Working Group Charter PURPOSE GOAL Advance the use of the Object Oriented Systems Engineering Method (OOSEM) in support of Model Based Systems Engineering (MBSE), while providing input to the ongoing development of the Systems

More information

This document is the property of and contains Proprietary Information owned by Westinghouse Electric Company LLC and/or its subcontractors and

This document is the property of and contains Proprietary Information owned by Westinghouse Electric Company LLC and/or its subcontractors and This document is the property of and contains Proprietary Information owned by Westinghouse Electric Company LLC and/or its subcontractors and suppliers. It is transmitted to you in confidence and trust,

More information

Development Study of Nuclear Power Plants for the 21st Century

Development Study of Nuclear Power Plants for the 21st Century Development Study of Nuclear Power Plants for the 21st Century Hitachi Review Vol. 50 (2001), No. 3 61 Kumiaki Moriya Masaya Ohtsuka Motoo Aoyama, D.Eng. Masayoshi Matsuura OVERVIEW: Making use of nuclear

More information

NUCLEAR POWER PLANT SYSTEMS and OPERATION

NUCLEAR POWER PLANT SYSTEMS and OPERATION Revision 4 July 2005 NUCLEAR POWER PLANT SYSTEMS and OPERATION Reference Text Professor and Dean School of Energy Systems and Nuclear Science University of Ontario Institute of Technology Oshawa, Ontario

More information

C. starting positive displacement pumps with the discharge valve closed.

C. starting positive displacement pumps with the discharge valve closed. KNOWLEDGE: K1.04 [3.4/3.6] P78 The possibility of water hammer in a liquid system is minimized by... A. maintaining temperature above the saturation temperature. B. starting centrifugal pumps with the

More information

Bradlee Boilers Ltd. Instruction Manual for starting up Bradlee Hire Boiler from Cold

Bradlee Boilers Ltd. Instruction Manual for starting up Bradlee Hire Boiler from Cold Bradlee Boilers Ltd Instruction Manual for starting up Bradlee Hire Boiler from Cold To be read in conjunction with Bradlee Boiler guide to Commissioning Boilers Document Ref: HM001 1. Ensure that all

More information

Three Myths of the Three Mile Island Accident

Three Myths of the Three Mile Island Accident Three Myths of the Three Mile Island Accident Presented by: Arnie Gundersen The Three Myths 1. Should an evacuation have been ordered? 2. Did the Contaminant Leak? 3. How much radiation was really released?

More information

Cyber-physical Systems Security An Experimental Approach

Cyber-physical Systems Security An Experimental Approach Cyber-physical Systems Security An Experimental Approach Dieter Gollmann, Marina Krotofil Security in Distributed Applications, Hamburg University of Technology helped by Pavel Gurikov, Alexander Isakov,

More information

Conventional Energy Sources

Conventional Energy Sources 9.2 Conventional Energy Sources Key Question: What benefits and problems come with common sources of energy? Hints The word plant here is not the kind that grows out of the ground. In this section, plants

More information

HEAT PUMP FREQUENTLY ASKED QUESTIONS HEAT PUMP OUTDOOR UNIT ICED-UP DURING COLD WEATHER:

HEAT PUMP FREQUENTLY ASKED QUESTIONS HEAT PUMP OUTDOOR UNIT ICED-UP DURING COLD WEATHER: HEAT PUMP FREQUENTLY ASKED QUESTIONS HEAT PUMP OUTDOOR UNIT ICED-UP DURING COLD WEATHER: It is normal for a heat pump to have a build up of white frost on the outside coil during cold damp weather. The

More information

Safety of New Nuclear Power Plants

Safety of New Nuclear Power Plants Safety of New Nuclear Power Plants Example: VVER-1200/V491 H. Hirsch A. Y. Indradiningrat Workshop on the Paks II NPP Project Budapest, Energiaklub, 08.10.2014 New NPP in Paks: Reactor Type In the EIA

More information

Nuclear Emergency Response Program

Nuclear Emergency Response Program Nuclear Emergency Response Program NUCLEAR POWER PLANTS In California, there are two operating nuclear power plant sites: Diablo Canyon in San Luis Obispo County has two active units and San Onofre Nuclear

More information

Electric Power Systems An Overview. Y. Baghzouz Professor of Electrical Engineering University of Nevada, Las Vegas

Electric Power Systems An Overview. Y. Baghzouz Professor of Electrical Engineering University of Nevada, Las Vegas Electric Power Systems An Overview Y. Baghzouz Professor of Electrical Engineering University of Nevada, Las Vegas Overview Power Generation Conventional power generation Power generation from renewables

More information

INCIDENT INVESTIGATION BASED ON CAUSALITY NETWORKS

INCIDENT INVESTIGATION BASED ON CAUSALITY NETWORKS IChemE SYMPOSIUM SERIES NO. 153 INCIDENT INVESTIGATION BASED ON CAUSALITY NETWORKS Yukiyasu Shimada 1, Rafael Batres 2, Tetsuo Fuchino 3 and Toshinori Kawabata 1 1 Chemical Safety Research Group, National

More information

Explosives Safety Initial Training. Course # 5.01 Rev. 08041-TO

Explosives Safety Initial Training. Course # 5.01 Rev. 08041-TO Explosives Safety Initial Training Course # 5.01 Rev. 08041-TO Terminal Objective: Identify safe practices for work on or around explosives in accordance with the DOE Explosives Safety Manual, DOE M 440.1-1A,

More information

Intelligent Vibration Monitoring

Intelligent Vibration Monitoring Diagnostic Systems Condition Based Monitoring Diagnostic Systems Condition Based Monitoring Intelligent Vibration Monitoring efector Octavis for real-time vibration monitoring Solutions for Predictive

More information

CAST Analysis. 2013 John Thomas and Nancy Leveson. All rights reserved.

CAST Analysis. 2013 John Thomas and Nancy Leveson. All rights reserved. CAST Analysis 1 CAST Process Identify the Accident (Loss) Identify the Hazards Identify the Safety Constraints Identify the Proximal Events Draw the Safety Control Structure Analyze each component 2 CAST

More information

The public and the media (perceptions) The industry: understanding the accident and

The public and the media (perceptions) The industry: understanding the accident and Recalibrating Risk: Reactions to Three-Mile Island, Chernobyl and Fukushima Elisabeth Paté-Cornell Management Science and Engineering Stanford University Duke University September 20, 2013 Three reaction

More information

AIR COOLED CHILLER CHILLED WATER PUMP CONTROL: The chilled water pump with the lowest runtime will automatically start when the outside air temperature rises above the system enable setpoint. When the

More information

Nuclear Power Station Control and Instrumentation Safety Systems Architecture An Overview

Nuclear Power Station Control and Instrumentation Safety Systems Architecture An Overview Nuclear Power Station Control and Instrumentation Safety Systems Architecture An Overview Jim Thomson, v.2 1. Introduction 1.1. Why are the architectures of safety systems different in nuclear, oil and

More information

Loviisa 3 unique possibility for large scale CHP generation and CO 2 reductions. Nici Bergroth, Fortum Oyj FORS-seminar 26.11.

Loviisa 3 unique possibility for large scale CHP generation and CO 2 reductions. Nici Bergroth, Fortum Oyj FORS-seminar 26.11. Loviisa 3 unique possibility for large scale CHP generation and CO 2 reductions Nici Bergroth, Fortum Oyj FORS-seminar 26.11.2009, Otaniemi Loviisa 3 CHP Basis for the Loviisa 3 CHP alternative Replacement

More information

THIS ENDORSEMENT CHANGES THE POLICY. PLEASE READ IT CAREFULLY COMMERCIAL PROPERTY EXTENSION

THIS ENDORSEMENT CHANGES THE POLICY. PLEASE READ IT CAREFULLY COMMERCIAL PROPERTY EXTENSION ENDORSEMENT NO. ATTACHED TO AND FORMING A PART OF POLICY NUMBER ENDORSEMENT EFFECTIVE DATE (12:01 A.M. STANDARD TIME) NAMED INSURED AGENT NO. THIS ENDORSEMENT CHANGES THE POLICY. PLEASE READ IT CAREFULLY

More information

Software Safety Hazard Analysis

Software Safety Hazard Analysis UCRL-ID-122514 Software Safety Hazard Analysis Version 2.0 Prepared by J. Dennis Lawrence Prepared for U.S. Nuclear Regulatory Commission Disclaimer This document was prepared as an account of work sponsored

More information

The main steam enters the building in the basement mechanical room; this is where the condensate line also leaves the building.

The main steam enters the building in the basement mechanical room; this is where the condensate line also leaves the building. MSV: Square Footage: 24,844 No. of Floors: 1 Year Built: 1963 Type of Use: Lounge and dining area open all night for snacks Steam Water-cooled condenser, 50-Ton York unit with a 6 cylinder-reciprocating

More information

Results and Insights of Internal Fire and Internal Flood Analyses of the Surry Unit 1 Nuclear Power Plant during Mid-Loop Operations*

Results and Insights of Internal Fire and Internal Flood Analyses of the Surry Unit 1 Nuclear Power Plant during Mid-Loop Operations* BNL-NUREG-61792 Results and Insights of Internal Fire and Internal Flood Analyses of the Surry Unit 1 Nuclear Power Plant during Mid-Loop Operations* Tsong-Lun Chu, Zoran Musicki, and Peter Kohut Brookhaven

More information

Safety issues of hydrogen in vehicles Frano Barbir Energy Partners 1501 Northpoint Pkwy, #102 West Palm Beach, FL 33407, U.S.A.

Safety issues of hydrogen in vehicles Frano Barbir Energy Partners 1501 Northpoint Pkwy, #102 West Palm Beach, FL 33407, U.S.A. Safety issues of hydrogen in vehicles Frano Barbir Energy Partners 1501 Northpoint Pkwy, #102 West Palm Beach, FL 33407, U.S.A. Properties of hydrogen Hydrogen is an odorless, colorless gas. With molecular

More information

13 Model-based Requirements Engineering Framework for Systems Lifecycle Support

13 Model-based Requirements Engineering Framework for Systems Lifecycle Support 13 Model-based Requirements Engineering Framework for Systems Lifecycle Support A. Soffer, D. Dori Abstract: The recent migration from traditional sequential development process models to the more modern

More information

Basic Fundamentals Of Safety Instrumented Systems

Basic Fundamentals Of Safety Instrumented Systems September 2005 DVC6000 SIS Training Course 1 Basic Fundamentals Of Safety Instrumented Systems Overview Definitions of basic terms Basics of safety and layers of protection Basics of Safety Instrumented

More information

TECHNICAL ADVISORY BULLETIN

TECHNICAL ADVISORY BULLETIN RISK CONTROL AND CLAIM ADVOCACY PRACTICE TECHNICAL ADVISORY BULLETIN November 2014 www.willis.com FIRE PUMP TESTING Fire pumps are a critical part of a fire protection system, especially when they are

More information

Indoor coil is too warm in cooling mode or too cold in heating mode. Reversing valve or coil thermistor is faulty

Indoor coil is too warm in cooling mode or too cold in heating mode. Reversing valve or coil thermistor is faulty Codes Room Air Conditioner range: Indoor unit alarm s If timer lamp flashes for 1 second on, 1 second off, this indicates pre heating on the coil during heating mode and is not an error. If timer lamp

More information

Functional safety. Essential to overall safety

Functional safety. Essential to overall safety Functional safety Essential to overall safety What is Functional safety? In public spaces, factories, offi ces or homes; we are surrounded by an increasing number of electric and electronic devices and

More information

Risk Matrix as a Tool for Risk Assessment in the Chemical Process Industry

Risk Matrix as a Tool for Risk Assessment in the Chemical Process Industry Risk Matrix as a Tool for Risk Assessment in the Chemical Process Industry Content 1. BASF Process Safety 2. Qualitative risk assessment 3. Semi-quantitative risk assessment Description of the BASF Risk

More information

PREFAULT MONITOR FOR AIR COOLED GENERATORS

PREFAULT MONITOR FOR AIR COOLED GENERATORS PREFAULT MONITOR FOR AIR COOLED GENERATORS Steve Kilmartin Utility Products Specialist Environment One Corporation 2773 Balltown Road Schenectady, NY 129 518 346-6161 George F. Skala Senior Engineer Environment

More information

RVL470. Heating Controller. Building Technologies HVAC Products. Series B

RVL470. Heating Controller. Building Technologies HVAC Products. Series B 2 522 Heating Controller Series B RVL470 Multifunctional heating controller for use in residential and non-residential buildings; suitable for weather-dependent flow temperature control of heating zones

More information

A Unified Product and Project Lifecycle Model. for Systems Engineering

A Unified Product and Project Lifecycle Model. for Systems Engineering A Unified Product and Project Lifecycle Model for Systems Engineering Research Thesis In Partial Fulfilment of the Requirements for the Degree of Doctor of Philosophy Amira Sharon Submitted to the Senate

More information

Flowserve - Edward Valves Quick Closing Isolation Valves -The Equiwedge Alternative

Flowserve - Edward Valves Quick Closing Isolation Valves -The Equiwedge Alternative Flowserve - Edward Valves Quick Closing Isolation Valves -The Equiwedge Alternative Problem Fast isolation of a large bore main steam or feedwater line during a pipe rupture that seals flow in both directions.

More information

The Technology and Business of Power Andrew Valencia, P.E. Lower Colorado River Authority

The Technology and Business of Power Andrew Valencia, P.E. Lower Colorado River Authority The Technology and Business of Power Andrew Valencia, P.E. Lower Colorado River Authority 1 2 What is Efficiency? Efficiency: What you get divided by what you pay for Heatrate is a measure of plant efficiency

More information

IGEMA BOILER LEVEL & TDS CONTROLS

IGEMA BOILER LEVEL & TDS CONTROLS IGEMA BOILER LEVEL & TDS CONTROLS IGEMA offers boiler level and TDS control products of the highest quality standard, being certified to ISO 9001. Made in Germany, IGEMA products are manufactured in compliance

More information

Propulsion Gas Path Health Management Task Overview. Donald L. Simon NASA Glenn Research Center

Propulsion Gas Path Health Management Task Overview. Donald L. Simon NASA Glenn Research Center Propulsion Gas Path Health Management Task Overview Donald L. Simon NASA Glenn Research Center Propulsion Controls and s Research Workshop December 8-10, 2009 Cleveland, OH www.nasa.gov 1 National Aeronautics

More information

310 Exam Questions. 1) Discuss the energy efficiency, and why increasing efficiency does not lower the amount of total energy consumed.

310 Exam Questions. 1) Discuss the energy efficiency, and why increasing efficiency does not lower the amount of total energy consumed. 310 Exam Questions 1) Discuss the energy efficiency, and why increasing efficiency does not lower the amount of total energy consumed. 2) What are the three main aspects that make an energy source sustainable?

More information

5-Minute Refresher: RENEWABLE ENERGY

5-Minute Refresher: RENEWABLE ENERGY 5-Minute Refresher: RENEWABLE ENERGY Renewable Energy Key Ideas Renewable energy is a source of energy that can be used and replenished naturally in a relatively short period of time. Non renewable energy

More information

Equipment Performance Monitoring

Equipment Performance Monitoring Equipment Performance Monitoring Web-based equipment monitoring cuts costs and increases equipment uptime This document explains the process of how AMS Performance Monitor operates to enable organizations

More information

Tips for burner modulation, air/fuel cross-limiting, excess-air regulation, oxygen trim and total heat control

Tips for burner modulation, air/fuel cross-limiting, excess-air regulation, oxygen trim and total heat control Boiler control Tips for burner modulation, air/fuel cross-limiting, excess-air regulation, oxygen trim and total heat control Boilers are often the principal steam or hot-water generators in industrial

More information

Equipment Breakdown. The extended property coverage you need for the equipment you rely on.

Equipment Breakdown. The extended property coverage you need for the equipment you rely on. Equipment Breakdown The extended property coverage you need for the equipment you rely on. Equipment Breakdown When it comes to protecting the equipment and machinery you need to keep your business operating

More information

SAFETY STANDARDS. of the. Nuclear Safety Standards Commission (KTA) KTA 3301. Residual Heat Removal Systems of Light Water Reactors.

SAFETY STANDARDS. of the. Nuclear Safety Standards Commission (KTA) KTA 3301. Residual Heat Removal Systems of Light Water Reactors. SAFETY STANDARDS of the Nuclear Safety Standards Commission (KTA) KTA 3301 Residual Heat Removal Systems of Light Water Reactors (November 1984) Editor: Geschäftsstelle des Kerntechnischen Ausschusses

More information

Basics of Kraft Pulping & Recovery Process. Art J. Ragauskas Institute of Paper Science and Technology Georgia Institute of Technology

Basics of Kraft Pulping & Recovery Process. Art J. Ragauskas Institute of Paper Science and Technology Georgia Institute of Technology Basics of Kraft Pulping & Recovery Process Art J. Ragauskas Institute of Paper Science and Technology Georgia Institute of Technology Outline History Goals Process Overview Kraft Pulping Process Kraft

More information

Power Plant Electrical Distribution Systems

Power Plant Electrical Distribution Systems PDH Course E184 Power Plant Electrical Distribution Systems Gary W Castleberry, PE 2008 PDH Center 2410 Dakota Lakes Drive Herndon, VA 20171-2995 Phone: 703-478-6833 Fax: 703-481-9535 www.pdhcenter.com

More information

USER MANUAL OPERATION AND USE OF CAR WITH. Diego G3 / NEVO SEQUENTIAL GAS INJECTION SYSTEM

USER MANUAL OPERATION AND USE OF CAR WITH. Diego G3 / NEVO SEQUENTIAL GAS INJECTION SYSTEM USER MANUAL OPERATION AND USE OF CAR WITH Diego G3 / NEVO SEQUENTIAL GAS INJECTION SYSTEM Page 2 z 7 Table of contents 1. STARTING THE ENGINE... 3 2. CONTROL PANEL... 3 2.1 Indication of the current level

More information