120 likes | 389 Views
CEMSIS FIKS-CT-2000-00109. C ost- E ffective M odernisation of S ystems I mportant to S afety Deryk Pavey,. CEMSIS Objectives. Programmable Instrumentation and Control (I&C) safety systems (e.g. protection) safety-related systems (e.g. control, data presentation)
E N D
CEMSISFIKS-CT-2000-00109 Cost-Effective Modernisation of Systems Important to Safety Deryk Pavey, wp6_beg010_v0_1_fisa slides.ppt
CEMSIS Objectives • Programmable Instrumentation and Control (I&C) • safety systems (e.g. protection) • safety-related systems (e.g. control, data presentation) • Common approach to development and safety justification • maximise safety • minimise cost • Modernisation/Refurbishment • analogue/discrete logic replacement with computer-based systems wp6_beg010_v0_1_fisa slides.ppt
‘Stakeholders’ in CEMSIS • Nuclear Plant Operator • British Energy (co-ord.) UK electricity generation • Electricite de France F electricity generation • British Nuclear Fuels UK nuclear fuel processing • Suppliers & System Integrators • Framatome ANP DE C&I supplier • Sycon International SE system developer • Safety Authorities & Assessors • AV Nuclear B inspection and licensing • Adelard UK safety consultancy • Software Reliability Specialist • TU Lund SE research & education wp6_beg010_v0_1_fisa slides.ppt
Key Issues • Harmonisation & Structuring of Safety Justification approaches • Definition of Requirements for Systems Important to Safety • Use of Pre-Existing Software in Systems Important to Safety • potentially including class A systems • Use of Graphical Languages in Systems Important to Safety wp6_beg010_v0_1_fisa slides.ppt
Safety Justification Survey and Framework Safety Justification Framework WP1 Requirements Capture Survey and Lifecycle Requirements Capture Guidelines WP2 Case Studies: UK: fuel reprocessing F: PWR I&C replacement SE: safety monitoring WP5 Pre-Existing S/W Strategy & Techniques Pre-Existing S/W Guidelines WP3 Graphical Languages Review and Evaluate Graphical Languages Report WP4 WP0,6 Management and Dissemination Work Package Tasks wp6_beg010_v0_1_fisa slides.ppt
Safety Justification Framework • Take account of current EU experience • EC NRWG Task Force on Safety Critical Software (ARMONIA) • Survey of practices in CEMSIS Member States • Synthesis of survey responses • Main trends and consensus • Problem areas to address in CEMSIS work packages • methods for structuring software safety cases • clarification of concepts such as ‘COTS’ • safety justification should take account of plant level risk analysis • how to make best use of diversity • how to evaluate software reliability (CMF the major factor) wp6_beg010_v0_1_fisa slides.ppt
(existing system, new needs, regulations, standards) (stakeholders: sponsors, users, designers, regulators etc.) (specification + rationale) • Taxonomy criticality, complexity, reuse, novelty, cost, timescales etc. Refurbishment levels Requirements Capture • Requirements Lifecycle • Discovery • Analysis • Negotiation • Definition and Validation • Survey of requirements techniques, research and experience. wp6_beg010_v0_1_fisa slides.ppt
Pre-existing Software • Including “COTS” (Commercial Off The Shelf) • Strategy: Two phases • “Pre-qualification” - reduce uncertainty and delay • provide evidence in advance for all applications • Application Qualification - some always needed • provide evidence specific to one application • Types of assessment • Functional - ensure features of product are adequate for safe use • Dependability - evidence that the product is sufficiently reliable • taking account of its safety class wp6_beg010_v0_1_fisa slides.ppt
White box without Experience White box with Experience Grey box without Experience Grey box with Experience Black box with Experience Black box without Experience A - Complex AW A - Medium A - Simple AW / AB AB B - Complex BG B - Medium BG / BB BB B - Simple BB • AW: white-box assessment of class A products • AB: black-box assessment of class A products • BG: grey-box assessment of class B products • BB: black-box assessment of class B products Pre-existing Software (2) • Taxonomy & Strategies for Dependability Assessments wp6_beg010_v0_1_fisa slides.ppt
Temp Press & Trip Graphical Specification Languages • Functional Requirements - safety risk of: • error in formulation • omission • misunderstanding etc. • Integrity - safety risk of: • underlying inconsistency or ambiguity • invalid verification results or reasoning • incorrect transformation into code • Reports: • evaluation of available languages • advice on safety justification wp6_beg010_v0_1_fisa slides.ppt
Application and Evaluation • Three Case Studies: • UK Nuclear fuel reprocessing plant control BNFL • I&C replacement on a French PWR EDF • Safety monitoring system on a Swedish NPP Sycon • Identify safety and cost-relevant aspects • safety requirements • implementation options • example arguments for safety justification • Evaluate and refine guidance documents wp6_beg010_v0_1_fisa slides.ppt
Conclusion • On target to provide practical guidance illustrated with realistic examples. • Key audience: • Senior I&C engineers and managers of refurbishment projects • Development engineers and managers in the supply industry • SMEs and service companies in the refurbishment market • Regulators and policy makers • Impact on strategy: • Accelerate inter working in member states • between utilities, suppliers and regulators • Help to focus national R&D efforts wp6_beg010_v0_1_fisa slides.ppt