ML17332A851: Difference between revisions

From kanterella
Jump to navigation Jump to search
(Created page by program invented by StriderTol)
(Created page by program invented by StriderTol)
Line 17: Line 17:


=Text=
=Text=
{{#Wiki_filter:wnu-7306NUCLEARENERGYSYSTEMSCLASS3REACTORPROTECTION SYSTEMDIVERSITY ZNWESTINGHOUSE PRESSURIZED WATERREACTORSApril1969Author:T.Q.T.BurnettContributors:
{{#Wiki_filter:wnu-7306 NUCLEAR ENERGY SYSTEMS CLASS 3 REACTOR PROTECTION SYSTEM DIVERSITY ZN WESTINGHOUSE PRESSURIZED WATER REACTORS April 1969 Author: T.Q.T.Burnett Contributors:
J.W.Dorrycott A.C.HallD.H.RisherAPPROVED:
J.W.Dorrycott A.C.Hall D.H.Risher APPROVED: S.ore, Manager Core Engineering Westinghouse Electric Corporation Nuclear Energy Systems Division P.O.Box 355 Pittsburgh, Pennsylvania 15230 9507180151 950707 PDR ADQCK 05000315 9 PDR<3RZ Restintthouse Electric Corp./
S.ore,ManagerCoreEngineering Westinghouse ElectricCorporation NuclearEnergySystemsDivisionP.O.Box355Pittsburgh, Pennsylvania 152309507180151 950707PDRADQCK050003159PDR<3RZRestintthouse ElectricCorp./
FOREWORD Over the past four years, considerable attention has been focused on design cx'iteria and methods of implementation for nuclear power plant protection systems.Of paxticular difficulty has been che"establishment of suitable criteria to deal with the problems of single and multiple failures, channel independence, Control and Proteccion System independence, and the'eviation of Protection System inputs..A key factor in this difficulty has b'een the conflict between the goal to minimize the number of redundant measurements fox'ny single process variable, with regaxd to the overall nuclear plane requirements, and the goal to establish a auucbnum degree of separation between the Protection System and the Control System.Obtaining an accurate and reliable measuxement of a particular process variable is one of the most difficult aspects of an instrumentacdon system.There are significant problems associated with the physical mounting of the measurement devices including optimum location, supporting structuxes, access to che equipment for maintenance, and protection against adverse environmental factors.In the case of nuclear power plants, there is also the problem of transmitting the signals fxom the containment to the control room equipment.
FOREWORDOverthepastfouryears,considerable attention hasbeenfocusedondesigncx'iteria andmethodsofimplementation fornuclearpowerplantprotection systems.Ofpaxticular difficulty hasbeenche"establishment ofsuitablecriteriatodealwiththeproblemsofsingleandmultiplefailures, channelindependence, ControlandProteccion Systemindependence, andthe'eviation ofProtection Systeminputs..Akeyfactorinthisdifficulty hasb'eentheconflictbetweenthegoaltominimizethenumberofredundant measurements fox'nysingleprocessvariable, withregaxdtotheoverallnuclearplanerequirements, andthegoaltoestablish aauucbnumdegreeofseparation betweentheProtection SystemandtheControlSystem.Obtaining anaccurateandreliablemeasuxement ofaparticular processvariableisoneofthemostdifficult aspectsofaninstrumentacdon system.Therearesignificant problemsassociated withthephysicalmountingofthemeasurement devicesincluding optimumlocation, supporting structuxes, accesstocheequipment formaintenance, andprotection againstadverseenvironmental factors.Inthecaseofnuclearpowerplants,thereisalsotheproblemoftransmitting thesignalsfxomthecontainment tothecontrolroomequipment.
All of these factors provide arguments for minimizing the number of separate measuremencs.
Allofthesefactorsprovidearguments forminimizing thenumberofseparatemeasuremencs.
Most of the functions performed by the plant Control System require the same process information as the Protection System.In these cases, Westinghouse provides Control System inputs from Protection System channels.The"Proposed IEEE Criteria for Nuclear Power Plant Protection Systems," IEEE No.279, permits this design approach, sub)ect to certain restrictions.
Mostofthefunctions performed bytheplantControlSystemrequirethesameprocessinformation astheProtection System.Inthesecases,Westinghouse providesControlSysteminputsfromProtection Systemchannels.
However, this proposed resolution was not unanimously accepted by members of other United States standards and regulatory agencies, in particular, USASX Sectional Committee N3 (N42), and the AEC-ACRS.Westinghouse held meetings with members of the AEC to clarify the Westinghouse design approach and to identify the additional design criteria applied by Westinghouse, which go beyond the proposed IEEE criteria.These additional criteria require separation and identification of control and protection equipment and the use of isolation devices to transmit signals from the Protection System to the Control System.It is the position of Westinghouse that these additional criteria offer a resolution to the'tated design conflict.Westinghouse has demonstrated by actual implementation of these criteria that a high degree of separation, including proper identification, can be achieved between Protection System equipment and Control System equipment.
The"Proposed IEEECriteriaforNuclearPowerPlantProtection Systems,"
More recently, the question of the failure mode changed from that of a single random failure to common-mode failure-a failure mode which would adversely affect all, redundant channels of a particular protective function in the Protection System.It is generally recognized that separation of control and protection does not provide defense against the common-mode failures.
IEEENo.279,permitsthisdesignapproach, sub)ecttocertainrestrictions.
The nuclear power plant Control and Protection System design employed by Westinghouse was evaluated in detail with respect to the commonmode failure and presented in a series of meetings to members of the AEC.This report documents the information transmitted in these meetings and provides a technical basis for the development of criteria for design of Protection Systems with adequate consideration for common-mode failures.The conclusion of Westinghouse based>upon actual experience, previous work, and reinforced by the results presented herein, is that design criteria for nuclear power plant protection systems should permit magnum effective use of process measurements both for control and protection functions including the use of Protection System measurements in the Control.System.Such criteria significantly enhance the designer's capability to provide a system with adequate capability to deal with the majority of common~ode failures t as well as to provide redundancy for critical control functions.
However,thisproposedresolution wasnotunanimously acceptedbymembersofotherUnitedStatesstandards andregulatory
: agencies, inparticular, USASXSectional Committee N3(N42),andtheAEC-ACRS.
Westinghouse heldmeetingswithmembersoftheAECtoclarifytheWestinghouse designapproachandtoidentifytheadditional designcriteriaappliedbyWestinghouse, whichgobeyondtheproposedIEEEcriteria.
Theseadditional criteriarequireseparation andidentification ofcontrolandprotection equipment andtheuseofisolation devicestotransmitsignalsfromtheProtection SystemtotheControlSystem.ItisthepositionofWestinghouse thattheseadditional criteriaofferaresolution tothe'tated designconflict.
Westinghouse hasdemonstrated byactualimplementation ofthesecriteriathatahighdegreeofseparation, including properidentification, canbeachievedbetweenProtection Systemequipment andControlSystemequipment.
Morerecently, thequestionofthefailuremodechangedfromthatofasinglerandomfailuretocommon-mode failure-afailuremodewhichwouldadversely affectall,redundant channelsofaparticular protective functionintheProtection System.Itisgenerally recognized thatseparation ofcontrolandprotection doesnotprovidedefenseagainstthecommon-mode failures.
ThenuclearpowerplantControlandProtection SystemdesignemployedbyWestinghouse wasevaluated indetailwithrespecttothecommonmode failureandpresented inaseriesofmeetingstomembersoftheAEC.Thisreportdocuments theinformation transmitted inthesemeetingsandprovidesatechnical basisforthedevelopment ofcriteriafordesignofProtection Systemswithadequateconsideration forcommon-mode failures.
Theconclusion ofWestinghouse based>upon actualexperience, previouswork,andreinforced bytheresultspresented herein,isthatdesigncriteriafornuclearpowerplantprotection systemsshouldpermitmagnumeffective useofprocessmeasurements bothforcontrolandprotection functions including theuseofProtection Systemmeasurements intheControl.System.Suchcriteriasignificantly enhancethedesigner's capability toprovideasystemwithadequatecapability todealwiththemajorityofcommon~ode failurestaswellastoprovideredundancy forcriticalcontrolfunctions.
J.M.Gallagher,'Jr.
J.M.Gallagher,'Jr.
Consulting Engineer-ControlTechnology Vestinghouse designphilosophy forReactorProtection andControlSystemsistomakemaxiunaause,forbothprotection andcontrolfunctions, ofawiderangeofmeasurements.
Consulting Engineer-Control Technology Vestinghouse design philosophy for Reactor Protection and Control Systems is to make maxiunaa use, for both protection and control functions, of a wide range of measurements.
TheProtection andControlSystemsareseparateandidentifiable.
The Protection and Control Systems are separate and identifiable.
Thedesignapproachpermitsnotonlyredundancy ofcontrol,providing itsowndesirable increment tooverallplantsafety,butalsoprovidesaProtection Systemwhichcontinuously monitorsnumeroussystemvariables bydifferent means;i.e.,protection systemdiversity.
The design approach permits not only redundancy of control, providing its own desirable increment to overall plant safety, but also provides a Protection System which continuously monitors numerous system variables by different means;i.e., protection system diversity.
TheextentofProtection Systemdiversity hasbeenevaluated forawidevarietyofpostulated accidents.
The extent of Protection System diversity has been evaluated for a wide variety of postulated accidents.
Inmostcases,twoormore=diversepro-tectivefunctions.
In most cases, two or more=diverse pro-tective functions.
wouldterminate anaccidentbeforeintolerable consequences couldoccur.  
would terminate an accident before intolerable consequences could occur.  


teetiee11.11.2233.13.1.13.1.23.1.33.1.43.1.53.23.2.3.,3.2.23.3TABLEOFCONTENTSTitleABSTRACTINTRODUCTION COMMONMODE FAILURESAND.DIVERSITY PROTECTION SYSTEMEVALUATION QjMMARYFUNCTIONAL DESCRIPTION, REACTORCONTROLANDPROTECTION SYSTEMREACTORPROTECTION SYSTEMGENERALREACTORTRIPSManualTripHighNuclearPower(PowerRange)HighNuclearPower(Intermediate Range)HighNuclearPower(SourceRange)Overtemperature 4TTripOverpower 4TTrip'LowPressureTripHighPressureTripHighPressurizer WaterLevelTripLowReactorCoolantFlowSafetyIn)ection SystemActuation Trip(SIS)TurbineTripLowFeedwater FlowReactorTripLowSteamGenerator WaterLevelTripPERMISSIVE CIRCUITSListofPermissive CircuitsRODSTOPSRodStopListINDICATION ControlBoardIndicators andRecorderCentralBoardAnnunciator PanelControlBoardStatusPanelSTEAMDUMPCONTROLSYSTEMCONDENSER STEAMDUMPSYSTEMSystemDesignControlSystemLoadRefection ControlTurbineTripControlPressureControlATMOSPHERIC STEAMRELIEFSYSTEMREACTORCONTROLTheTemperature ChanelThePowerMismatchChannelThePressureChannelTheRodSpeedProgram~Paeiv1>>1l-l1-5213.1-13.1-13.1>>13.1-13.1-13.1-13.1-23.1-23.1-33.1-33.1-43.1W3.1-53.1>>53.1-63.1-73.1-73.1-73.1-83.1-83.1-93.1-93.1-103.1-103.'1-103.1-113.2-13.2-13.2-13e2~33e2~33.2-43.2-53.2-63.3-13.3-13.3-13'~23~32 Seetiet3,4'.53.5.13.5.23.5.344.14.24.34.44.4.14.4.24.4.34.4.44.4.54.4.655.l.5.1.15.1.25.1.35.1.45.25.2.1~5.2.2.;:!.5.35.3-15-3.2TABLEOPCONTENTS(Cont'd)TitleSTEAMGENERATOR LEVELCONTROLSTEAMBREAKPROTECTION SYSTEMSAFETYINJECTION SYSTEMACTUATION FEEDWATER LINEXSOLATION STEAMLINEISOLATION PROTECTION ANDCONTROLSYSTEMSDESXGNPRINCIPLES PROTECTION SYSTEMFUNCTIONAL DESIGNCONTROLSYSTEMPJNCTIONAL DESXGNCONTROLANDPROTECTION INTERRELATION SPECIFICCONTROLANDPROTECTION INTERACTIONS NUCLEARFLUXCOOLANTTEMPERATURE PRESSURIZER PRESSUREControlofRodMotionPressureControlLowPressureHighPressurePRESSURIZER LEVELHighLevelLowLevelSTEAMGENERATOR WATERLEVELFEEDWATER PLO..Feedwater FlowSteamFlowLevelSTEAMLINEPRESSUREACCIDENTEVALUATXON RODWITHDRAWAL ACCIDENTIPROBABLECONSEOUENCES OFACCIDENTPROBABILITY OFACCIDENTMANUALINTERVENTION DIVERSXTY OFREACTORTRIPSLOSSOFFEEDWATER LOSSOFFEEDWATER
teetiee 1 1.1 1.2 2 3 3.1 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.2 3.2.3., 3.2.2 3.3 TABLE OF CONTENTS Title ABSTRACT INTRODUCTION COMMONMODE FAILURES AND.DIVERSITY PROTECTION SYSTEM EVALUATION QjMMARY FUNCTIONAL DESCRIPTION, REACTOR CONTROL AND PROTECTION SYSTEM REACTOR PROTECTION SYSTEM GENERAL REACTOR TRIPS Manual Trip High Nuclear Power (Power Range)High Nuclear Power (Intermediate Range)High Nuclear Power (Source Range)Overtemperature 4T Trip Overpower 4T Trip'Low Pressure Trip High Pressure Trip High Pressurizer Water Level Trip Low Reactor Coolant Flow Safety In)ection System Actuation Trip (SIS)Turbine Trip Low Feedwater Flow Reactor Trip Low Steam Generator Water Level Trip PERMISSIVE CIRCUITS List of Permissive Circuits ROD STOPS Rod Stop List INDICATION Control Board Indicators and Recorder Central Board Annunciator Panel Control Board Status Panel STEAM DUMP CONTROL SYSTEM CONDENSER STEAM DUMP SYSTEM System Design Control System Load Refection Control Turbine Trip Control Pressure Control ATMOSPHERIC STEAM RELIEF SYSTEM REACTOR CONTROL The Temperature Chanel The Power Mismatch Channel The Pressure Channel The Rod Speed Program~Pa e iv 1>>1 l-l 1-5 2 1 3.1-1 3.1-1 3.1>>1 3.1-1 3.1-1 3.1-1 3.1-2 3.1-2 3.1-3 3.1-3 3.1-4 3.1W 3.1-5 3.1>>5 3.1-6 3.1-7 3.1-7 3.1-7 3.1-8 3.1-8 3.1-9 3.1-9 3.1-10 3.1-10 3.'1-10 3.1-11 3.2-1 3.2-1 3.2-1 3e2~3 3e2~3 3.2-4 3.2-5 3.2-6 3.3-1 3.3-1 3.3-1 3'~2 3~3 2 Seetiet 3,4'.5 3.5.1 3.5.2 3.5.3 4 4.1 4.2 4.3 4.4 4.4.1 4.4.2 4.4.3 4.4.4 4.4.5 4.4.6 5 5.l.5.1.1 5.1.2 5.1.3 5.1.4 5.2 5.2.1~5.2.2.;:!.5.3 5.3-1 5-3.2 TABLE OP CONTENTS (Cont'd)Title STEAM GENERATOR LEVEL CONTROL STEAM BREAK PROTECTION SYSTEM SAFETY INJECTION SYSTEM ACTUATION FEEDWATER LINE XSOLATION STEAM LINE ISOLATION PROTECTION AND CONTROL SYSTEMS DESXGN PRINCIPLES PROTECTION SYSTEM FUNCTIONAL DESIGN CONTROL SYSTEM PJNCTIONAL DESXGN CONTROL AND PROTECTION INTERRELATION SPECIFIC CONTROL AND PROTECTION INTERACTIONS NUCLEAR FLUX COOLANT TEMPERATURE PRESSURIZER PRESSURE Control of Rod Motion Pressure Control Low Pressure High Pressure PRESSURIZER LEVEL High Level Low Level STEAM GENERATOR WATER LEVEL FEEDWATER PLO..Feedwater Flow Steam Flow Level STEAM LINE PRESSURE ACCIDENT EVALUATXON ROD WITHDRAWAL ACCIDENT I PROBABLE CONSEOUENCES OF ACCIDENT PROBABILITY OF ACCIDENT MANUAL INTERVENTION DIVERSXTY OF REACTOR TRIPS LOSS OF FEEDWATER LOSS OF FEEDWATER-TRANSIENT ANALYSIS TYPXCAL SYSTEM DESIGN REOUIR1M2KS Auxiliary Feedwater System Main Steam and Feedwater Piping LOSS OF COOLANT PLOW ANALYSIS ZNTRODUCTION AND
-TRANSIENT ANALYSISTYPXCALSYSTEMDESIGNREOUIR1M2KS Auxiliary Feedwater SystemMainSteamandFeedwater PipingLOSSOFCOOLANTPLOWANALYSISZNTRODUCTION ANDSUMMARYPROTECTION SYSTEMDESCRIPTXON LowReactorCoolantPlowReactorCoolantPumpLowVoltageReactorCoolantPumpLowFrequency PumpCircuitBreakerPositionOverpower Delta-TReactorTripInterlocks
~Pae3.4-13.5-13.5-13-5-13.5-14.1<<14.1-14.2-14.3-14.4-14.4-14e4-24.4-34.4-34.M34.4-34.4-44.4-44.4-54.4-54.4>>64.4>>74.4-84.4-84.4-85.3.-15.1-15.1-25.1-45.1-45.1-65.2-15.2-25.2-45.2-45.2-65.3-15.3-15.3-15.3-25.3-25.3-25.3-35.3-35.3-4 14C Sectice5.3.35.3.45.3.55.45.4.15.4.25.4.35.55.5.15.5.25.5.35.5.45.65.75.85.95.10:5.115.12TABLEOFCONTENTS(Cont'd)TitleMULTILOOP LOSSOFFLOWSINGLELOOPLOSSOFFLOWLOCKEDROTORACCIDENTRODEJECTIONANALYSISINTRODUCTION ANDSUMMARYCASESCONSIDERED INDETAILZeroPowerCaseFullPowerEndofLifeCozeBACK-UPTRIPPROTECTION LOSSOFSTEAMLOADINTRODUCTION ANDSUMMARYLOSSOFLOADPROTECTION ANDDESIGNCRITERIASteamDumptoCondenser Pressurizer PressureReliefSteamSystemPressureReliefDirectReactorTripHighPressurizer PressureTripOvertemperature 4THighPressurizer LevelTripEVALUATION OF'PROTECTION SYSTEMFORLOSSOFLOADInitiation ofAccidentAnalysisandDiscussion CONCLUSIONS RODWITHDRAWAL DURINGSTARTUPCONTROLRODDROPENGINEERED SAFEGUARDS ACTUATION CONTAINMENT PRESSUREPROTECTION EXCESSIVE MADEXCESSZVE FEEDWATER PLOWSTATIONBLACKOUTCONTROLANDPROTECTION FUNCTIONS
~Pae5.3-45.3-65.3-75.4-15.4-15.4-15.415.4-25.4-35.5-15.5-15.5-25.5-25.5-35.5-35.5-35,5~45.5W5.5-45.5-55.5-55.5-75.5-95.615.7-15.8-15.9-15.10-15.11-15.12-1


LISTOFFIGURES~FgureNo.2-1Illustration ofControlandProtection Design3.1-13.1-23.2-13.3-23.3-1Overtemperature dTChannelOverpower dTChannelSteamCycleValveArrangement Condenser SteamDumpControlSchemeReactorControlSystem4.2-14.3-15.1-15.1-25.1-35.1-45.1-55.1-65.1-75.1-85.1-95.1-1052-1522.~5.2-35.2-45.2-55.2-65.2-75.2-85.2-95.3-I.5-3-25+335.3-45.3-55.3-6SteamGenerator LevelContxolandProtection SystemPressurizer PressureProtection andContxolSystemsDesignIFaultTreefoxRodWithdrawal AccidentFaultTreeforRodWithdrawal AccidentInsertedRodWox'thandReactivity RequiredtoReachDNBR~1.0inHotAssemblyVersusCoreLifeCompleteRodWithdrawal fromMaximumFullPowerCompleteRodWithdrawal fromMaximumFullPowerSteadyStateCoreLimitsandReactorTripandAlarmPointsBeginning ofLife,RodWithdrawal from102XPower,MinimumDNBRBeginning ofLife,RodWithdrawal from102XPower,TimeofEventBeginning ofLife,RodWithdrawal from80XPower,Resulting MinimumDNBRBeginning ofLife,RodWithdrawal from80XPower,TimeofEventFaultTreeforLossofFeedwater FlowFaultTreeforLossofFeedwater FlowFaultTreeforLossofFeedwater FlowLevelResponsetoLossofSteamFlowSignalLossofFeedwater FlowtoOneSteamGenerator atT~OneSecond,TypicalTwo-LoopPlantLossofFeedwater FlowtoOneSteamGenerator atT~OneSecond,TypicalTwo-LoopPlantCompleteLossofFeedwater CompleteLossofFeedwater Auxiliary Feedwater SystemSchematic, Two-LoopPlantFaultTreeforMulti-Loop LossofFlowFaultTreeforSingleLoopLossofFlowFaultTreeforLockedRotorAccidentMulti-Loop LossofFlow,TypicalPlantSingleLoopLossofFlow,TwoLoopPlantLockedRotorLossofFlow,TwoLoopPlant
==SUMMARY==
~e+lyIA'I'I'lhPl0V0 LISTOFFIGURES(Cont'd)FiureNo-5.4-15.4-25.4-35.4-45.5-15.5>>25.5-35.6-15.6-25.7-1.5.725.8-1ZeroPowerEndofLifeRodEjection, NoTripFullPowerEndofLifeRodEjection, NoTripIllustration ofSafetyLimitsandTripPointsforRodEjectionAccidents, NoTripIllustration ofTransient Trajectories forRodEjectionAccidents, WithNoTripFaultTreeforLossofLoadAccidentFaultTreeforCoreDamage,LossofSteamLoadLossofLoadAccidentUncontrolled RodWithdrawal fromSubcritical, FractionofNuclearPowerUncontrolled RodWithdrawal fromSubcritical Condition, Temperature ResponsetoaDroppedControlRodResponsetoaDroppedControlRodSafetyInjection Actuation SignalvsBreakArea
PROTECTION SYSTEM DESCRIPTXON Low Reactor Coolant Plow Reactor Coolant Pump Low Voltage Reactor Coolant Pump Low Frequency Pump Circuit Breaker Position Overpower Delta-T Reactor Trip Interlocks
~emme~e'~'%qelt*49~*t 1.INTRODUCTION poophyforReactorProtection andCooltomaemaxaumuseforbothprotection andcontrolfunctions ofawiderangeofmeasurements.
~Pa e 3.4-1 3.5-1 3.5-1 3-5-1 3.5-1 4.1<<1 4.1-1 4.2-1 4.3-1 4.4-1 4.4-1 4e 4-2 4.4-3 4.4-3 4.M3 4.4-3 4.4-4 4.4-4 4.4-5 4.4-5 4.4>>6 4.4>>7 4.4-8 4.4-8 4.4-8 5.3.-1 5.1-1 5.1-2 5.1-4 5.1-4 5.1-6 5.2-1 5.2-2 5.2-4 5.2-4 5.2-6 5.3-1 5.3-1 5.3-1 5.3-2 5.3-2 5.3-2 5.3-3 5.3-3 5.3-4 1 4 C Sectice 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.5 5.5.1 5.5.2 5.5.3 5.5.4 5.6 5.7 5.8 5.9 5.10: 5.11 5.12 TABLE OF CONTENTS (Cont'd)Title MULTILOOP LOSS OF FLOW SINGLE LOOP LOSS OF FLOW LOCKED ROTOR ACCIDENT ROD EJECTION ANALYSIS INTRODUCTION AND
Thisresultsinabroadspectrumofredundant protection andcontrolfunctions.
Thedesignapproachusedpermitsallequipment components tobeidentified asprotection orcontrolandlocatedaccordingly, withelectrical isolation andphysicalseparation betweenthem.Thedesignapproachthuspermitsnotonlyreduncancy ofcontx'ol, providing asignificant anddesirable increment tooverallplantsafety,butalsoprovidesaProtection Systemwhichcontinuously monitorsnumeroussystemvax'iables bydifferent means;i.e.,Protection Systemdiversity.
AlthoughtheProtection SystemdesignbasisrequiresonlythatrandomsinglefailuresnotnegatetheProtection System,aconsiderable depthofprotection IisachievedbytheWestinghouse designapproach.
Systemsdesigners andre-viewershavexecentlyemphaaLzed theimportance ofachieving asuitablebalanceofdesignobfectives inregardtofunctional andequipment diversity.
"'nteraction ofcontrolandprotection functions, testing,andsurveillance to~thieveaProtection Systemdesignthathasadequatecapability tocopewithbothrandomandsystematic failuremodes.(Systematic failuresarealsoknownascommon-mode, ornonrandom failures.)
1.1COMMONWODE FAILURESANDDIVERSITY Common-mode, orsystematic
: failures, arethosethatpartially orcompletely preventidentical, instrument channelsfromperforming theirfunction-p'~.4*/I dundancyisnotananswertothistyPeoffailure,sinceallchannelsareassume~edtobeaffected.
Further,thesefailurescannotbeevaluated byproao~bability analysisorreliability data;indeed,theyarecharacterized byoversights ordeficiencies whichpresumably wouldbecorrected whenfirstdetected.
Thegeneralcategories ofcommon~ode failuresare:a)Functional deficiency
-Thevariablebeingmonitored doesnotprovidetheinformation intendedduringthecourseofanaccident.
Thisdeficiency couldbecausedbytheaccident's following adifferent course/thancalcu1ated bythedesigners, orbyachangeintheplantcharacteristics whichchangestherelationbetweenthepxocessandthevariablebeingmonitored.
b)Maintenance error-Thisfailureincludesconsistent miscalibration ofallchannelsofatype,andalsocircuitmodification oxrepqirwhichinadvertently rendersthechannelsfunctionally inoperative.'esign deficiency
-Pailuxeoftheequipment asinstalled tomeetfunctional requirements.
Thiscouldarisethxoughunrecognized dependence onasingle,commonelement.,
suchasventilation; byanunexpected charpcteristic (suchassaturation orslowresponse) inallcontrollers ofatype;orbytheinstrumentation beingdisabledasaresultoftheaccident-d)~<<malcatastrophe
-Withproperisolation andseparation betweenredundant
: channels, thisisconfinedtoma)ordisasters suchasflood,<<rthquake, fire,etc.Whereseparation isnotcomplete, lessdrastic~ventscanhavethesameresult.Forexample,afallingob)ectcouldconceivably severallcablesinasmallarea.1-2 t+J~~N Considerable effortisbeingmadeinReactorProtection Systemsdesignpreventthesecommon-mode
: failures, asillustrated bytheexamplesbelow.Howeverremote,thepossibility ofacommonmode failuremustnevertheless beconsidered.
Thelikelihood ofmaintenance errorscanbeminimized byproperadministrative procedures, identificationofProtection Systemcomponents, andcompletedocumentation oftheas-supplied Protection System,including thedesignbasis.Designdeficiencies canbelargely.eliminated byequipment qualification testingandbycaxefulreviewofallpotential commonelements.
Redundancy isanaccepteddefenseagainstx'andomfailureswhichaffectonlyonecomponent orchannelatatime.Similarly, "cliversity isadefenseagainstcommon~de failureswhichcouldaffectmultiplechannels.
Suchprotective diversity canbeachievedineitheroftwoways:equipment diversity, byproviding different typesofinstrumentat'ion'to monitorthesamevariable, orfunctional diversity, bymonitoring different plantvariables.
Functional diversity entailssomedegreeofequipment diversity, P~rilywithrespecttosensorsandsetpoints.
Moreimportantly, however,functional diversity isnotdependent onthecalculated respenseofanyone"ariableduringanaccident.
Asaconvex'se ofthis,functional diversity ismorecomplextodemonstrate sincetheresponseofseveralvariables mustbeanalyzedforeachtypeofaccidentevaluated.
TheWestinghouse Pxotection Systemistherefore evaluated inthisreportwithrespecttofunctional divexsity.
Todemonstrate diversity whereprotective actionisneeded,itisnecessary toshowcombinations oftwoormoreofthe1-3 e4 fo1lowingbarriers" foreachaccident.
Someoftheseareaddressed totheneedforprotective action,ratherthantotheInstrumentation Systemitself.Thisisconsidered areasonable approachtojudgingtheadequacyofaProtection System.a)Tolerable consequences forexpectedconditions
-Althoughcase"analysismightfailtoprovethatprotection isnotvastmajorityofcasesmayhaveacceptable consequences.
worstneeded,theWhetherornotthisisasuitablebarrierdependsontheprobability ofadverseconditions (suchasexcessive insertedrodworth)andthedesignandoperating precautions takentopreventthem.b)Lowprobability ofaccident-Probability oftheinitiating faultmightbeconsidered, butonlyinconjunction withtheprobableconsequences.
Thatis,aloss-of-coolant accidentdoesnotrequirelessprotection tthanalossofflowaccidentsimplybecauseitislesslikelytooccur.c)Controlinterlocks
-RodstopsorotherdeviceswhicharrestormodifyspuriouscontrolactionshortofreactortripcanbepartoftheProtection System.Protection Systemdesignstandards, equipment testing,andTechnical Specification limitswouldtherefore beapplied.nualaction-Manualactioncanbeconsidered areliablebackuptoautomatic protection, depending ontheaccidentrate,thecomplextytheproblemandcorrective action,andthealarmsandindication provided.
1-4


Automatic reactortrip-Eachaccidentmayhavea"principle" reactortripassociated withit..)BackuPreactortrip-Asecondreactortripfunctionofisanadditional barrier.InallbutafewcasesintheWestinghouse design,aspecificreactortripisnotcategorically either"principle" or"backup":
==SUMMARY==
itservesastheprinciple protection againstsomeaccidents, andasbackupprotection againstothers.1.ZPROTECTION SYSTEM-EVALUATION Anaccident-by>>accident evaluation hasbeenperformed inordertoevaluatethe"depth"ordegreeofdiversity providedbycurrentWestinghouse design.Asexpected, diversity couldnotbedemonstrated forallaccidents.
CASES CONSIDERED IN DETAIL Zero Power Case Full Power End of Life Coze BACK-UP TRIP PROTECTION LOSS OF STEAM LOAD INTRODUCTION AND
Thexesultsingenex'al, however,indicateaconsiderable degreeofprotection Systemdivexsity.
Theevaluation, reportedin-.Section 5ofthisreport,analyzedeachpostulated
~ccidentwithoutcreditforprotective actiontothepointatwhichoneofthethreefollowing eventsoccurs:Inherentplantcharactex'istics terminated theaccident; b)Theconsequences areclearlyintolex'able',
orc)=<<<tinganalytical methodsarenolongervalid(forexample,systemalculations cannotbeperfoxmed withanydegx'eeofconfidence ifseverecoredamageoccurs).1-5 tyneofevaluation, theamountofanalytical rigormustbereducedKathistypeoascontonsbecomeincreasingly remoteandsafetylhaitsareexceededisbecausepresenttechnology cannotrigorously supportassumptions assystembehaviorfortheseremotecases.Inlargepart,thisfactexplainsthereasonwhysuchconservative safetylimitsareselectedfordesignpurposes.
1-6 I
SL~5ARYIntheWestingoutinhouseReactorControlandProtectionSystemstheControlSystemisseoara'sseoarateanddistinctfromtheProtection SystP"orection Systemisindependent oftheContro]heProtectonS"ste-"Lishighlydependent uponsignalsderivedfromtheProtectio Sthroughisolation amplifiers; Thisinterre].ationship isillustdininure-1.hedesignoftheControlandProtection Syst~dthinteractions betweenthemarediscussed indetailiSectio'd4ofthisreport.Thedesignphilosophy istomakemaxianunusage,forbothcontrolandprotection
: purposes, ofallmeasurements ofplantvariables.
Foreachvariablemonitored, thebesttypeofequipment available isselectedasthevehicleofmeasurement.
Clearly,therequirements formeasurements forcontrolorprotection purposessonearlyoverlapthattheoptimumequipment foronepurposeisalsotheoptimumfortheother,.It'srecognized bythoseresponsible forProtection Systemdesignandreviewthatlittleifanyadditional safetyisachievedbyutilizing independent, butidentical, measurements forcontrolandprotection.
Infa<<,itisWestinghouse's positionthatadditional identical channelsareseriously disadvantageous jnthatmorepenetrations, maintenance, andcontrolroomreadoutsarerequired.
porexample,operatorsurveiU.ance ofprotection channels'isnecessarily dilutedwhenplantoperation isdependent onotherindications.


pressurized waterreactorplant,itisalmostaxiomatic that-.naLargePresrturbation whichencroaches onsafetylimitssignificantly affects~vperturaForexample,areactivity excursion
==SUMMARY==
-suchasaccidental rodvt.thrawdrawal-causesnotonlyanincreaseinneutronfluxandcorepower,~soanincreaseincoolanttemperatures andinpressurizer pressurebutandlevel.Reliablecontrolisobviously'he bestapproachtoplantsafety.Theprime,purposeofacontrolsystemistolimitexcursions beforeprotective actionisnecessary.
LOSS OF LOAD PROTECTION AND DESIGN CRITERIA Steam Dump to Condenser Pressurizer Pressure Relief Steam System Pressure Relief Direct Reactor Trip High Pressurizer Pressure Trip Overtemperature 4T High Pressurizer Level Trip EVALUATION OF'PROTECTION SYSTEM FOR LOSS OF LOAD Initiation of Accident Analysis and Discussion CONCLUSIONS ROD WITHDRAWAL DURING STARTUP CONTROL ROD DROP ENGINEERED SAFEGUARDS ACTUATION CONTAINMENT PRESSURE PROTECTION EXCESSIVE MAD EXCESSZVE FEEDWATER PLOW STATION BLACKOUT CONTROL AND PROTECTION FUNCTIONS~Pa e 5.3-4 5.3-6 5.3-7 5.4-1 5.4-1 5.4-1 5.4 1 5.4-2 5.4-3 5.5-1 5.5-1 5.5-2 5.5-2 5.5-3 5.5-3 5.5-3 5,5~4 5.5W 5.5-4 5.5-5 5.5-5 5.5-7 5.5-9 5.6 1 5.7-1 5.8-1 5.9-1 5.10-1 5.11-1 5.12-1
SincethecontroldevicesmustbecapableofLimitingexcursions, theyarealsocapableofcausinganexcursion
 
-perhapsinthe,oppositedirection
LIST OF FIGURES~Fg ure No.2-1 Illustration of Control and Protection Design 3.1-1 3.1-2 3.2-1 3.3-2 3.3-1 Overtemperature dT Channel Overpower dT Channel Steam Cycle Valve Arrangement Condenser Steam Dump Control Scheme Reactor Control System 4.2-1 4.3-1 5.1-1 5.1-2 5.1-3 5.1-4 5.1-5 5.1-6 5.1-7 5.1-8 5.1-9 5.1-10 5 2-1 5 2 2.~5.2-3 5.2-4 5.2-5 5.2-6 5.2-7 5.2-8 5.2-9 5.3-I.5-3-2 5+3 3 5.3-4 5.3-5 5.3-6 Steam Generator Level Contxol and Protection System Pressurizer Pressure Protection and Contxol Systems Design I Fault Tree fox Rod Withdrawal Accident Fault Tree for Rod Withdrawal Accident Inserted Rod Wox'th and Reactivity Required to Reach DNBR~1.0 in Hot Assembly Versus Core Life Complete Rod Withdrawal from Maximum Full Power Complete Rod Withdrawal from Maximum Full Power Steady State Core Limits and Reactor Trip and Alarm Points Beginning of Life, Rod Withdrawal from 102X Power, Minimum DNBR Beginning of Life, Rod Withdrawal from 102X Power, Time of Event Beginning of Life, Rod Withdrawal from 80X Power, Resulting Minimum DNBR Beginning of Life, Rod Withdrawal from 80X Power, Time of Event Fault Tree for Loss of Feedwater Flow Fault Tree for Loss of Feedwater Flow Fault Tree for Loss of Feedwater Flow Level Response to Loss of Steam Flow Signal Loss of Feedwater Flow to One Steam Generator at T~One Second, Typical Two-Loop Plant Loss of Feedwater Flow to One Steam Generator at T~One Second, Typical Two-Loop Plant Complete Loss of Feedwater Complete Loss of Feedwater Auxiliary Feedwater System Schematic, Two-Loop Plant Fault Tree for Multi-Loop Loss of Flow Fault Tree for Single Loop Loss of Flow Fault Tree for Locked Rotor Accident Multi-Loop Loss of Flow, Typical Plant Single Loop Loss of Flow, Two Loop Plant Locked Rotor Loss of Flow, Two Loop Plant
-ifspuriously actuated.
~e+l y I A'I'I'lh P l 0 V 0 LIST OF FIGURES (Cont'd)Fi ure No-5.4-1 5.4-2 5.4-3 5.4-4 5.5-1 5.5>>2 5.5-3 5.6-1 5.6-2 5.7-1.5.7 2 5.8-1 Zero Power End of Life Rod Ejection, No Trip Full Power End of Life Rod Ejection, No Trip Illustration of Safety Limits and Trip Points for Rod Ejection Accidents, No Trip Illustration of Transient Trajectories for Rod Ejection Accidents, With No Trip Fault Tree for Loss of Load Accident Fault Tree for Core Damage, Loss of Steam Load Loss of Load Accident Uncontrolled Rod Withdrawal from Subcritical, Fraction of Nuclear Power Uncontrolled Rod Withdrawal from Subcritical Condition, Temperature Response to a Dropped Control Rod Response to a Dropped Control Rod Safety Injection Actuation Signal vs Break Area
FailureoftheControlSystem,eitherbynotactingwhenneeded,oractingwhennotneeded,decreases theleve1ofsafety.Redundancy-ofcontrol,whereapplicable, istherefore highlydesirable.
~e mme~e'~'%q el t*4 9~*t 1.INTRODUCTION p o ophy for Reactor Protection and Co ol tomaema xaum use for both protection and control functions of a wide range of measurements.
Pressurizer pressurecontrolisaprimeexampleofefficient useofredundant measurements forsafeoperation viaareliableControlSystem.Twooower-operated pneumatic reliefvalvesareprovidedtolimitpressureexcursions withinthenormaloperating range.Althoughnotessential to-safety,thesevalvesincreasesafetymarginsforsystemoverpressure
This results in a broad spectrum of redundant protection and control functions.
~overpressure protection isprovidedbythehighpressurereactortrip~safetyvalves).Shouldeithervalvebeactuatedspuriously, however,p~tection againstthereduction inpressuremightalsoberequired.
The design approach used permits all equipment components to be identified as protection or control and located accordingly, with electrical isolation and physical separation between them.The design approach thus permits not only reduncancy of contx'ol, providing a significant and desirable increment to overall plant safety, but also provides a Protection System which continuously monitors numerous system vax'iables by different means;i.e., Protection System diversity.
2~2  
Although the Protection System design basis requires only that random single failures not negate the Protection System, a considerable depth of protection I is achieved by the Westinghouse design approach.Systems designers and re-viewers have xecently emphaaLzed the importance of achieving a suitable balance of design obfectives in regard to functional and equipment diversity.
'P''h contro3.channels, derivedformthefourpressureprotection
"'nteraction of control and protection functions, testing, and surveillance to~thieve a Protection System design that has adequate capability to cope with both random and systematic failure modes.(Systematic failures are also known as common-mode, or nonrandom failures.)
."-ourpressurecontnosing3.eins-hanne3.s, areuse-el'eiwhenneeded,norcananysingleiQt~tfailducepressuretothepointatwhichprotection wouldbeneededressurechannelsareusedtocontro1eachvalve.OnepressurechannelMopressureservesasaninterlock, blockingtheairsupplytothevalveonalowpressurea3.arm.Sincethepneumatic valverequiresairtoopen,thi'slowpressurealarmclosesthevalve(ifopen)andholdsitclosed.Intheabsenceofalowpressurealarmonthefirstchannel,ahighpressurealarmonthesecondchannelopensthevalve.."-romtheprotection Systemviewpoint, thecorollary tomaxbaumusageofallmeasurements isthatprotection againstanygivenaccidentisnotnecessarily confinedtomeasurement ofjustonevariable.
 
Thusthereactivity excursion notedpreviously, thereactortriponhighpressurizer wagerleve3,alsoprovidesadegreeofprotection, eventhoughthebasicpurposeofthistripistoprotectthepressurizer reliefpipingfromwaterreliefsurge,throughthesafetyvalves.Sincecompletely different.
===1.1 COMMONWODE===
typesofmeasurement areused<<rneutronfluxandpressurizer waterlevel,diversity doesexistintheProtection System.Lheextentofsuchdiversity isevaluated inSection5forawidevarietyotaccidents.
FAILURES AND DIVERSITY Common-mode, or systematic failures, are those that partially or completely prevent identical, instrument channels from performing their function-p'~.4*/I dundancy is no t an answer to this tyPe o f f ailure, since all channels are assume~ed to be affected.Further, these failures cannot be evaluated by pro ao~bability analysis or reliability data;indeed, they are characterized by oversights or deficiencies which presumably would be corrected when first detected.The general categories of common~ode failures are: a)Functional deficiency
Inmostcases,twoormorediversereactortripsterminate
-The variable being monitored does not provide the information intended during the course of an accident.This deficiency could be caused by the accident's following a different course/than calcu1ated by the designers, or by a change in the plant characteristics which changes the relation between the pxocess and the variable being monitored.
~accidentbeforecatastrophic consequences canoccur.However,thesecondtripreached(the"backup")generally doesnotpreventthedesignsateylimitfrombeingexceeded.
b)Maintenance error-This failure includes consistent miscalibration of all channels of a type, and also circuit modification ox repqir which inadvertently renders the channels functionally inoperative.'esign deficiency
Inthiscontext,thedesignsaiety2-3 h
-Pailuxe of the equipment as installed to meet functional requirements.
hasaDNgratioof1.30,isitselfahighlyconservative such~,.exceeding thislimitdoesnotimplyintolerable consequences.
This could arise thxough unrecognized dependence on a single, common element., such as ventilation; by an unexpected charpcteristic (such as saturation or slow response)in all controllers of a type;or by the instrumentation being disabled as a result of the accident-d)~<<mal catastrophe
~onecaseevaluated
-With proper isolation and separation between redundant channels, this is confined to ma)or disasters such as flood,<<rthquake, fire, etc.Where separation is not complete, less drastic~vents can have the same result.For example, a falling ob)ect could conceivably sever all cables in a small area.1-2 t+J~~N Considerable effort is being made in Reactor Protection Systems design prevent these common-mode failures, as illustrated by the examples below.However remote, the possibility of a commonmode failure must nevertheless be considered.
-thehypothetical rodejectionaccident-protection systememdiversity couldnotbeadequately demonstrated fortheworstcase.~eyerarodejectionisconsidered tobeanextremely unlikelyaccidentonecausedbycompleteandinstantaneous mechanical failureofacontrolrodpressurehousing.Further,theprobableconsequences, asdistinctfromtheworstcase,aretolerable sincemostcontrolrodsarefullywithdrawn fromthecore.Eventhoserodsthatremaininsertedareseldominsertedtotheirinsertion limits.."-oranothertypeofaccident-completelossoffeedwater
The likelihood of maintenance errors can be minimized by proper administrative procedures, identif ication of Protection System components, and complete documentation of the as-supplied Protection System, including the design basis.Design deficiencies can be largely.eliminated by equipment qualification testing and by caxeful review of all potential common elements.Redundancy is an accepted defense against x'andom failures which affect only one component or channel at a time.Similarly,"cliversity is a defense against common~de failures which could affect multiple channels.Such protective diversity can be achieved in either of two ways: equipment diversity, by providing different types of instrumentat'ion'to monitor the same variable, or functional diversity, by monitoring different plant variables.
-diversity ofreactortripsdoesexist.Ho~ever,automatic actuation oftheauxiliary feedwater systemisnotdiverseforallof'hewaysinwhichfeedwater flowcouldbelost.Forthosecases,itisshownthatmanualactuation consti-rutesareliableback-uptoautomatic actuation.
Functional diversity entails some degree of equipment diversity, P~rily with respect to sensors and setpoints.
More importantly, however, functional diversity is not dependent on the calculated respense of any one"ariable during an accident.As a convex'se of this, functional diversity is more complex to demonstrate since the response of several variables must be analyzed for each type of accident evaluated.
The Westinghouse Pxotection System is therefore evaluated in this report with respect to functional divexsity.
To demonstrate diversity where protective action is needed, it is necessary to show combinations of two or more of the 1-3 e 4 f o 1 lowing barriers" for each accident.Some of these are addressed to the need for protective action, rather than to the Instrumentation System itself.This is considered a reasonable approach to judging the adequacy of a Protection System.a)Tolerable consequences for expected conditions
-Although case" analysis might fail to prove that protection is not vast majority of cases may have acceptable consequences.
worst needed, the Whether or not this is a suitable barrier depends on the probability of adverse conditions (such as excessive inserted rod worth)and the design and operating precautions taken to prevent them.b)Low probability of accident-Probability of the initiating fault might be considered, but only in conjunction with the probable consequences.
That is, a loss-of-coolant accident does not require less protection t than a loss of flow accident simply because it is less likely to occur.c)Control interlocks
-Rod stops or other devices which arrest or modify spurious control action short of reactor trip can be part of the Protection System.Protection System design standards, equipment testing, and Technical Specification limits would therefore be applied.nual action-Manual action can be considered a reliable backup to automatic protection, depending on the accident rate, the complex ty the problem and corrective action, and the alarms and indication provided.1-4
 
Automatic reactor trip-Each accident may have a"principle" reactor trip associated with it..)BackuP reactor trip-A second reactor trip function of is an additional barrier.In all but a few cases in the Westinghouse design, a specific reactor trip is not categorically either"principle" or"backup": it serves as the principle protection against some accidents, and as backup protection against others.1.Z PROTECTION SYSTEM-EVALUATION An accident-by>>accident evaluation has been performed in order to evaluate the"depth" or degree of diversity provided by current Westinghouse design.As expected, diversity could not be demonstrated for all accidents.
The xesults in genex'al, however, indicate a considerable degree of protection System divexsity.
The evaluation, reported in-.Section 5 of this report, analyzed each postulated
~ccident without credit for protective action to the point at which one of the three following events occurs: Inherent plant charactex'istics terminated the accident;b)The consequences are clearly intolex'able', or c)=<<<ting analytical methods are no longer valid (for example, system alculations cannot be perfoxmed with any degx'ee of confidence if severe core damage occurs).1-5 tyne of evaluation, the amount of analytical rigor must be reduced Ka this type o as con t on s become increasingly remote and safety lhaits are exceeded is because present technology cannot rigorously support assumptions as system behavior for these remote cases.In large part, this fact explains the reason why such conservative safety limits are selected for design purposes.1-6 I
SL~5ARY In the Westing ou tin house Reactor Control and Pro tection Systems the Control System is seoara's seoarate and distinct from the Protection Syst P"orection System is independent of the Contro]he Protect on S"ste-"L is highly dependent upon signals derived from the Protectio S through isolation amplifiers; This interre].ationship is illust d in inure-1.he design of the Control and Protection Syst~d th interactions between them are discussed in detail i Sectio'd 4 of this report.The design philosophy is to make maxianun usage, for both control and protection purposes, of all measurements of plant variables.
For each variable monitored, the best type of equipment available is selected as the vehicle of measurement.
Clearly, the requirements for measurements for control or protection purposes so nearly overlap that the optimum equipment for one purpose is also the optimum for the other,.It's recognized by those responsible for Protection System design and review that little if any additional safety is achieved by utilizing independent, but identical, measurements for control and protection.
In fa<<, it is Westinghouse's position that additional identical channels are seriously disadvantageous jn that more penetrations, maintenance, and control room readouts are required.por example, operator surveiU.ance of protection channels'is necessarily diluted when plant operation is dependent on other indications.
 
pressurized water reactor plant, it is almost axiomatic that-.n a Large Pre s rturbation which encroaches on safety limits significantly affects~v pertur a For example, a reactivity excursion-such as accidental rod vt.th raw drawal-causes not only an increase in neutron flux and core power,~so an increase in coolant temperatures and in pressurizer pressure but and level.Reliable control is obviously'he best approach to plant safety.The prime, purpose of a control system is to limit excursions before protective action is necessary.
Since the control devices must be capable of Limiting excursions, they are also capable of causing an excursion-perhaps in the, opposite direction-if spuriously actuated.Failure of the Control System, either by not acting when needed, or acting when not needed, decreases the leve1 of safety.Redundancy-of control, where applicable, is therefore highly desirable.
Pressurizer pressure control is a prime example of efficient use of redundant measurements for safe operation via a reliable Control System.Two oower-operated pneumatic relief valves are provided to limit pressure excursions within the normal operating range.Although not essential to-safety, these valves increase safety margins for system overpressure
~overpressure protection is provided by the high pressure reactor trip~safety valves).Should either valve be actuated spuriously, however, p~tection against the reduction in pressure might also be required.2~2  
'P''h contro3.channels, derived form the four pressure protection
."-our pressure con t no sing3.e ins-hanne3.s, are use-el'ei when needed, nor can any single i Qt~t fail duce pressure to the point at which protection would be needed ressure channels are used to contro1 each valve.One pressure channel Mo pressure serves as an interlock, blocking the air supply to the valve on a low pressure a3.arm.Since the pneumatic valve requires air to open, thi's low pressure alarm closes the valve (if open)and holds it closed.In the absence of a low pressure alarm on the first channel, a high pressure alarm on the second channel opens the valve.."-rom the protection System viewpoint, the corollary to maxbaum usage of all measurements is that protection against any given accident is not necessarily confined to measurement of just one variable.Thus the reactivity excursion noted previously, the reactor trip on high pressurizer wager leve3, also provides a degree of protection, even though the basic purpose of this trip is to protect the pressurizer relief piping from water relief surge, through the safety valves.Since completely different.
types of measurement are used<<r neutron flux and pressurizer water level, diversity does exist in the Protection System.Lhe extent of such diversity is evaluated in Section 5 for a wide variety ot accidents.
In most cases, two or more diverse reactor trips terminate~accident before catastrophic consequences can occur.However, the second trip reached (the"backup")generally does not prevent the design satey limit from being exceeded.In this context, the design saiety 2-3 h
h as a DNg ratio of 1.30, is itself a highly conservative such~,.exceeding this limit does not imply intolerable consequences.
~one case evaluated-the hypothetical rod ejection accident-protection system em diversity could not be adequately demonstrated for the worst case.~eyer a rod ej ection is considered to be an extremely unlikely accident one caused by complete and instantaneous mechanical failure of a control rod pressure housing.Further, the probable consequences, as distinct from the worst case, are tolerable since most control rods are fully withdrawn from the core.Even those rods that remain inserted are seldom inserted to their insertion limits.."-or another type of accident-complete loss of feedwater-diversity of reactor trips does exist.Ho~ever, automatic actuation of the auxiliary feedwater system is not diverse for all of'he ways in which feedwater flow could be lost.For those cases, it is shown that manual actuation consti-rutes a reliable back-up to automatic actuation.
2-4  
2-4  
'P7"IHtI0 ILLUSTRATION OFCONT."d)L
'P 7"I H t I 0 ILLUSTRATION OF CONT."d)L'lND PROTECTION DESIGN CONTROL SYSTEM l (Signal con~itionins, controllers,~I interlocks, and defeat switches)t.otection
'lNDPROTECTION DESIGNCONTROLSYSTEMl(Signalcon~itionins, controllers,
{test signa.ague)(test r adout)~est CONTROL PROTECTION Channel'Sensor I\I Cabling and Penetrations
~Iinterlocks, anddefeatswitches) t.otection
~I!P ewer Suoply!Isolation I;ihmplifier I Bistable l I (From other protection channels)".harm el Channel 2 3 f" 1 I In8icatio Channel 4 C C CJ o 4k IJ CO C IH g~g O Cl~+I cd 0 C cC CJ PROTECTION LOGIC a&CKS TRAIN TO REACTOR TRIP BREAKERS FIGURE 2-l  
{testsigna.ague)(testradout)~estCONTROLPROTECTION Channel'SensorI\ICablingandPenetrations
~,'I 1"k 0 P CTIONAL DESCRIPTION REACTOR CONTROL AND PROTECTION SYSTEH~~CTIONAL REACTOR PROTECTION SYSTEH 3.1 3.1.1 GENERAL'r'1 and Protection Szstm functi~di , , based on the Robert Emmett Ginna Nuclear Station of the Rochester Gas and Electric Co.(RGBE).It is representative of Westinghouse design practice.All reactor trips meet the following criteria: a)A single fai1ure shall not negate a reactor trip b)All channels are capable of calibration and maintenance at power.3.1.2 REACTOR TRIPS 4 A resume of reactor trips, means of actuation and coincident circuit requirements is given in Table 3.1-1.i~fllnual Trig Depressing either of two manual push buttons on the main control board actuates a reactor trip.Hi h Nuclear Power (Power Ran e)Dual trip settings=are provided: 3.1 1
~I!PewerSuoply!Isolation I;ihmplifier IBistablelI(Fromotherprotection channels)
" ca.l\"1~  
".harmelChannel23f"1IIn8icatio Channel4CCCJo4kIJCOCIHg~gOCl~+Icd0CcCCJPROTECTION LOGICa&CKSTRAINTOREACTORTRIPBREAKERSFIGURE2-l  
)Low (approximately 25X)b)High (approximately 110X).The low setting can be manually blocked when power increases above P-10*(approximately 10X power)and is automatically reinstated when power decreases below P-10.These circuits trip the reactor when two of the four external ion chamber average flux signals are above the trip setpoint.Hi h Nuclear Power (Intermediate Ran e)This circuit trips the reactor when either of the two intermediate channels indicate above the trip setpoint, Et may be manual1y blocked when power is above P-10 and is automatically reset when power decreases-below P-10.Expected trip setpoint is 25X.HL h Nuclear Power (Source Ran e)This circuit trips the reactor when either of the two intermediate P range channels indicate above the trip setpoint.It may be manua11y blocked when two intermediate range channels reads a value above P-6 and is automatically reinstated when both intermediate range channels decrease below P-6.Trip setting is between P-6 and the maximum source range power level.*P-()designates a permissive circuit to block or activate a trip function.These circuits are defined in Section 3.1.3.
~,'I1"k0P CTIONALDESCRIPTION REACTORCONTROLANDPROTECTION SYSTEH~~CTIONAL REACTORPROTECTION SYSTEH3.13.1.1GENERAL'r'1andProtection Szstmfuncti~di,,basedontheRobertEmmettGinnaNuclearStationoftheRochester GasandElectricCo.(RGBE).Itisrepresentative ofWestinghouse designpractice.
Allreactortripsmeetthefollowing criteria:
a)Asinglefai1ureshallnotnegateareactortripb)Allchannelsarecapableofcalibration andmaintenance atpower.3.1.2REACTORTRIPS4Aresumeofreactortrips,meansofactuation andcoincident circuitrequirements isgiveninTable3.1-1.i~fllnual TrigDepressing eitheroftwomanualpushbuttonsonthemaincontrolboardactuatesareactortrip.HihNuclearPower(PowerRane)Dualtripsettings=
areprovided:
3.11 "ca.l\"1~  
)Low(approximately 25X)b)High(approximately 110X).Thelowsettingcanbemanuallyblockedwhenpowerincreases aboveP-10*(approximately 10Xpower)andisautomatically reinstated whenpowerdecreases belowP-10.Thesecircuitstripthereactorwhentwoofthefourexternalionchamberaveragefluxsignalsareabovethetripsetpoint.
HihNuclearPower(Intermediate Rane)Thiscircuittripsthereactorwheneitherofthetwointermediate channelsindicateabovethetripsetpoint, Etmaybemanual1yblockedwhenpowerisaboveP-10andisautomatically resetwhenpowerdecreases-below P-10.Expectedtripsetpointis25X.HLhNuclearPower(SourceRane)Thiscircuittripsthereactorwheneitherofthetwointermediate Prangechannelsindicateabovethetripsetpoint.
Itmaybemanua11yblockedwhentwointermediate rangechannelsreadsavalueaboveP-6andisautomatically reinstated whenbothintermediate rangechannelsdecreasebelowP-6.TripsettingisbetweenP-6andthemaximumsourcerangepowerlevel.*P-()designates apermissive circuittoblockoractivateatripfunction.
ThesecircuitsaredefinedinSection3.1.3.
4~I'  
4~I'  
~Fjtyvertemoe temperature 4TTrioofthistripistoprotectthecorepurposeopo,pssure,temperature,
~Fj t yvertemoe temperature 4T Trio of this trip is to protect the core purpose o po , p ssure, temperature,'cion Two out~f four oop~For each channel per eactor c lative measure of reactor power and is compared with a continu ously calculated setpoint of the form: 4T~K+K xPressure-K x T>>f(4I)setpoint L 2 J avg~en the reactor coolant loop 4T exceeds the calculated setpoint, the r atfected channel is tripped.Zn the above equation, 4Z is the difference'between the top and bottom power-range ion chamber signals..This compensation signal automat-ically reduces the trip setpoint if adverse axial core power I distribution exists.Dynamic compensation of the T signal is avg also provided to compensate for instrument and piping delays between the reactor core and the'loop temperature sensors..A schematic representation of this circuit is shown on Figure 3.1-1.An illustration of the setpoint is shown on Figure 5.1-6.Overoower 4T Tri The purpose of this trip is to protect against excessive power (fuel<<d power density).Two-out-of-four trip logic is used;there are two channels per reactor coolant loop.3.1-3 i for each channel is calculated as: Ne setpoint tor e~K-K-T-K (T-T)-f(II)4 5 dt avg 6 avg avg~'quation>f (41)is the same function as used in the overtemperature equat o-serpo nt e tpoint equation.The term K5 compensates for the piping and instrument delay.The term K6 compensates for the change in density and heat t~ac ty o ity of water with temperature (T's the nominal T at full power).avg avg 6~th K and K are limited such that the rate and/or magnitude of T can avg only decrease the 4T trip setpoint from its normal value at full power.ected steady-state trip setpoint is llOX of the indicated hT at full poMer;i.e., llOX power.A schematic representation of this cricuit is shown on Figure 3.1-2.~Pressure Tri.he purpose of'this trip is to protect against excessive boiling in the core and to limit the pressure range in which coze DNB protection is required for the overtempezature aT zeactor trip.This circuit trips the:eactor on coincidence of twmf-four channels.It is automatically blocked below P-7.The expected setpoint is 1715 psig.-"-'-h Pressure Tri=he purpose of this trip is to protect against overpressure and to limit the es<<<<range in which core DNB protection is required of the overtemperature Wected setpoint is 2385 psig.-a<<circuit trips the reactor on coincidence of two~f-three channels.3.1-4  
'cionTwoout~ffouroop~Foreachchannelpereactorclativemeasureofreactorpowerandiscomparedwithacontinuouslycalculated setpointoftheform:4T~K+KxPressure-K xT>>f(4I)setpointL2Javg~enthereactorcoolantloop4Texceedsthecalculated
~h Pressurizer Water Level Tri tzip provides a backup to the high pressure trip and also prevents the pzessuz zessuzizer safety and relief valves from relieving water for credible accident conditions.
: setpoint, theratfectedchannelistripped.Zntheaboveequation, 4Zisthedifference'between thetopandbottompower-range ionchambersignals..
Expected setpoint is 92X of span.This circuit trips the reactor on coincidence of two-of-three channels.Xt is automatically blocked.below P-7.Low Reactor Coolant Flow This circuit is provided to protect the core from DUB following a loss of coolant flow accident.The means of sensing a loss of coolant flow accident aze as follows: a)Measured low flow tn the reactor coolant piping b)Reactor coolant pump circuit breaker open c)Undervoltage on reactor coolant pump bus d)Underfrequency on reactor coolant pump bus The low flow trip signal is actuated by the coincidence of two-of-three signals per loop.Above P-7, reactor trip occurs for a loss of flow in both loops;above P-S, reactor trip occurs for a loss of few in either loop.Expected setpoint is 90K of indicated full flow.The reactor trip signal derived from reactor coolant pump breaker position is actuated by a single auxiliary contact'or each reactor coolant pump breaker.Trip logic is similar to the low flow trip;above P-7 reactor trip occurs for a"breaker open" signal from any two breakers;above P8.a signal fzom any one breaker actuates a reactor trip.  
Thiscompensation signalautomat-icallyreducesthetripsetpointifadverseaxialcorepowerIdistribution exists.Dynamiccompensation oftheTsignalisavgalsoprovidedtocompensate forinstrument andpipingdelaysbetweenthereactorcoreandthe'looptemperature sensors..
~wg a~~V~~tor trip provides additonal reactor protection against~undervoltage reactor powers 4 coaplete loss o o~t pump buses as~d b oa Lcw voltage on o ected setpoint is 70Z of~crvoltage se a~t a r t j rapid decrease in electrical frequency can decelerate th~princip e, a~tor coolant pumps faster than a complete loss of power.An underfrequency condition on both reactor coolant buses, as sensed by either of two under>>frequency relays on'ach bus, trips the reactor and opens both reactor coolant pump circuit breakers.Expected setpoint is approximately 58 cps.a Safety Xn ection S stem Actuation Tri (SIS)"pon actuation of the Safety Infection System, the reactor fs tripped to decrease the severity of the accident condition.
Aschematic representation ofthiscircuitisshownonFigure3.1-1.Anillustration ofthesetpointisshownonFigure5.1-6.Overoower 4TTriThepurposeofthistripistoprotectagainstexcessive power(fuel<<dpowerdensity).
The means of actuating the Safety In)ection System and thus tripping the reactor are as follows: l a)Low pressurizer pressure (1715 psig)in coincidence with low pressurizer water.level (5Z span).Any one of the three circuits La actuates the SIS.This function may be manually bypassed below 2000 psig.~Pressure (500 psig)in any steam line.A coincidence of two~f-three signals for any steam line actuates this function.This function can be manually bypassed when reactor coolant pr~ssure is below 2000 psig.c)"igh containment pressure (6 psig).A coincidence of two-of-three signals actuates the SIS.d)Manual Actuatj on f~~
Two-out-of-four triplogicisused;therearetwochannelsperreactorcoolantloop.3.1-3 iforeachchanneliscalculated as:Nesetpointtore~K-K-T-K(T-T)-f(II)45dtavg6avgavg~'quation>
Trio~trip sensed by loss of autostop oi 1 pressure or by turbine stop g turbine tr ps losure actuates a reactor trip during high power operation.
f(41)isthesamefunctionasusedintheovertemperature equato-serpontetpointequation.
Trip<s~o~r-three for the autostop oil pressure switches and two~f-two pic is sor the stop valve position switches.This trip is in coincidence with~r~sszve ci~ssiye circuit P-7 (blocked below 10X power)and permissive circuit P-9~blocked below 50X power unless condenser steam dump is blocked).Low."-eedvater Plow Reactor Tri For either steam generator, low feedwater flow (compared to steam flow)in coincidence with low steam generator vater level actuates a reactor trip.'Ms protects the reactor against a sudden loss of heat sink.This condition is sensed for either steam generator if e'ither of: two steam flow~feedvater flov channels indicate a difference greater than a setpoint and either of tvo steam generator narrow-range level channels indicate less 6 than a setpoint.Expected setpoints are 0.7 x.10 lbs/hr and 30X of span respectively.
ThetermK5compensates forthepipingandinstrument delay.ThetermK6compensates forthechangeindensityandheatt~actyoityofwaterwithtemperature (T'sthenominalTatfullpower).avgavg6~thKandKarelimitedsuchthattherateand/ormagnitude ofTcanavgonlydecreasethe4Ttripsetpointfromitsnormalvalueatfullpower.ectedsteady-state tripsetpointisllOXoftheindicated hTatfullpoMer;i.e.,llOXpower.Aschematic representation ofthiscricuitisshownonFigure3.1-2.~PressureTri.hepurposeof'thistripistoprotectagainstexcessive boilinginthecoreandtolimitthepressurerangeinwhichcozeDNBprotection isrequiredfortheovertempezature aTzeactortrip.Thiscircuittripsthe:eactoroncoincidence oftwmf-four channels.
Low Steam Generator Water Level Tri~e purpose of this trip is to protect the reactor from a'1oss of heat sink-<<the case of a sustained steam/feedwater flow mismatch which is too ll<<actuate the low feedwater flow trip.~h~s~~-s trip is actuated on coincidence of two-of-three lov-lov level signals~n steam generator.
Itisautomatically blockedbelowP-7.Theexpectedsetpointis1715psig.-"-'-hPressureTri=hepurposeofthistripistoprotectagainstoverpressure andtolimitthees<<<<rangeinwhichcoreDNBprotection isrequiredoftheovertemperature Wectedsetpointis2385psig.-a<<circuittripsthereactoroncoincidence oftwo~f-three channels.
Expected setpoint, is 15X of narrow range level span-3.1-7  
3.1-4  
/t 6.,.t;>)0 C 3>MQSSIVE CIRCUITS 3.'.3 p ously to permissive circuits Reference has been ma o k certain activities as well-~~its are use to ac'vfties.t of Permissive Circuits nunbnc Funccfnn Rod withdrawal stop on overpower (Automatic and manual)~Xn uc One~f-four high nuclear power (power range)*;one-of-two high nuclear power (intermediate range*l;one-of-four overtemperature AW;or one-of-four overpower AT*.Automatic rod with-drawal stop at low power.Automatic rod with-drawal stop on rod drop Selection of steam dump controller mode Permit manual block of source range high nuclear power trip One-of-one turbine first stage steam pressure I Oneof-four rapid decrease of nuclear power or rod bottom indication h Turbine trip signal One~f-two high intermediate range nuclear power allows manual block, twomf-two low intermediate range nuclear power automatically reinstates trip.~bypass on individual channels.."~y e~ally blocked if peanissive circuit P-10 is cleared.  
~hPressurizer WaterLevelTritzipprovidesabackuptothehighpressuretripandalsopreventsthepzessuzzessuzizer safetyandreliefvalvesfromrelieving waterforcredibleaccidentconditions.
Expectedsetpointis92Xofspan.Thiscircuittripsthereactoroncoincidence oftwo-of-three channels.
Xtisautomatically blocked.belowP-7.LowReactorCoolantFlowThiscircuitisprovidedtoprotectthecorefromDUBfollowing alossofcoolantflowaccident.
Themeansofsensingalossofcoolantflowaccidentazeasfollows:a)Measuredlowflowtnthereactorcoolantpipingb)Reactorcoolantpumpcircuitbreakeropenc)Undervoltage onreactorcoolantpumpbusd)Underfrequency onreactorcoolantpumpbusThelowflowtripsignalisactuatedbythecoincidence oftwo-of-three signalsperloop.AboveP-7,reactortripoccursforalossofflowinbothloops;aboveP-S,reactortripoccursforalossoffewineitherloop.Expectedsetpointis90Kofindicated fullflow.Thereactortripsignalderivedfromreactorcoolantpumpbreakerpositionisactuatedbyasingleauxiliary contact'or eachreactorcoolantpumpbreaker.Triplogicissimilartothelowflowtrip;aboveP-7reactortripoccursfora"breakeropen"signalfromanytwobreakers; aboveP8.asignalfzomanyonebreakeractuatesareactortrip.  
~wga~~V~~tortripprovidesadditonal reactorprotection against~undervoltage reactorpowers4coapletelossoo~tpumpbusesas~dboaLcwvoltageonoectedsetpointis70Zof~crvoltage sea~tartjrapiddecreaseinelectrical frequency candecelerate th~principe,a~torcoolantpumpsfasterthanacompletelossofpower.Anunderfrequency condition onbothreactorcoolantbuses,assensedbyeitheroftwounder>>frequency relayson'achbus,tripsthereactorandopensbothreactorcoolantpumpcircuitbreakers.
Expectedsetpointisapproximately 58cps.aSafetyXnectionSstemActuation Tri(SIS)"ponactuation oftheSafetyInfection System,thereactorfstrippedtodecreasetheseverityoftheaccidentcondition.
Themeansofactuating theSafetyIn)ection Systemandthustrippingthereactorareasfollows:la)Lowpressurizer pressure(1715psig)incoincidence withlowpressurizer water.level(5Zspan).AnyoneofthethreecircuitsLaactuatestheSIS.Thisfunctionmaybemanuallybypassedbelow2000psig.~Pressure(500psig)inanysteamline.Acoincidence oftwo~f-three signalsforanysteamlineactuatesthisfunction.
Thisfunctioncanbemanuallybypassedwhenreactorcoolantpr~ssureisbelow2000psig.c)"ighcontainment pressure(6psig).Acoincidence oftwo-of-three signalsactuatestheSIS.d)ManualActuatjon f~~
Trio~tripsensedbylossofautostopoi1pressureorbyturbinestopgturbinetrpslosureactuatesareactortripduringhighpoweroperation.
Trip<s~o~r-three fortheautostopoilpressureswitchesandtwo~f-two picissorthestopvalvepositionswitches.
Thistripisincoincidence with~r~sszveci~ssiyecircuitP-7(blockedbelow10Xpower)andpermissive circuitP-9~blockedbelow50Xpowerunlesscondenser steamdumpisblocked).
Low."-eedvater PlowReactorTriForeithersteamgenerator, lowfeedwater flow(compared tosteamflow)incoincidence withlowsteamgenerator vaterlevelactuatesareactortrip.'Msprotectsthereactoragainstasuddenlossofheatsink.Thiscondition issensedforeithersteamgenerator ife'itherof:twosteamflow~feedvater flovchannelsindicateadifference greaterthanasetpointandeitheroftvosteamgenerator narrow-range levelchannelsindicateless6thanasetpoint.
Expectedsetpoints are0.7x.10lbs/hrand30Xofspanrespectively.
LowSteamGenerator WaterLevelTri~epurposeofthistripistoprotectthereactorfroma'1ossofheatsink-<<thecaseofasustained steam/feedwater flowmismatchwhichistooll<<actuatethelowfeedwater flowtrip.~h~s~~-stripisactuatedoncoincidence oftwo-of-three lov-lovlevelsignals~nsteamgenerator.
Expectedsetpoint, is15Xofnarrowrangelevelspan-3.1-7  
/t6.,.t;>)0C 3>MQSSIVECIRCUITS3.'.3pouslytopermissive circuitsReference hasbeenmaokcertainactivities aswell-~~itsareusetoac'vfties.tofPermissive CircuitsnunbncFunccfnnRodwithdrawal stoponoverpower (Automatic andmanual)~XnucOne~f-fourhighnuclearpower(powerrange)*;one-of-two highnuclearpower(intermediate range*l;one-of-four overtemperature AW;orone-of-four overpower AT*.Automatic rodwith-drawalstopatlowpower.Automatic rodwith-drawalstoponroddropSelection ofsteamdumpcontroller modePermitmanualblockofsourcerangehighnuclearpowertripOne-of-one turbinefirststagesteampressureIOneof-four rapiddecreaseofnuclearpowerorrodbottomindication hTurbinetripsignalOne~f-two highintermediate rangenuclearpowerallowsmanualblock,twomf-two lowintermediate rangenuclearpowerautomatically reinstates trip.~bypassonindividual channels.
."~ye~allyblockedifpeanissive circuitP-10iscleared.  
~'  
~'  
~ssiveCircuits(Cont'd)tofPessluabaapuaaaiaa~Xauapermissive power(blockvarioustripsatlowpower)BlocksingleprimarylooplossofflowtripBlockreactortriponturbinetripThreemf-four lownuclearpowerandonemf-two lowturbineimpulsestagepressureThreeof-four lownuclearpowerThree~f-four lownuclearpowerandcondenser steamdumpavaQ-able(notlockedoutbyhighcondenser pressureorbylossofbothcirculating waterpumps)103.1.>>RODSTOPSPermitmanualblockofintermediate rangepowerleveltripandrodstopandlowpowerrangetripTwo-of-four highnuclearpowerallowsmanualblock,thre~f-fourlownuclearpowerautomatically reinstates thetripsAcompletelistofrodstopsisnotedbelow.RdStopListFuaaataaa)Roddropb)NuclearOverpower Actuation SinalOne~f-four rapidpowerrangenuclearpowerdecreaseoranyrodbottomsignalOneof-four highpowerrangenuclearpowerorRodMotiontobeBlockedAutomatic withdrawal (redundant, contacts)
~ssive Circuits (Cont'd)t of Pe ss luabaa puaaaiaa~Xa ua permissive power (block various trips at low power)Block single primary loop loss of flow trip Block reactor trip on turbine trip Threemf-four low nuclear power and onemf-two low turbine impulse stage pressure Threeof-four low nuclear power Three~f-four low nuclear power and condenser steam dump avaQ-able (not locked out by high condenser pressure or by loss of both circulating water pumps)10 3.1.>>ROD STOPS Permit manual block of intermediate range power level trip and rod stop and low power range trip Two-of-four high nuclear power allows manual block, thre~f-four low nuclear power automatically reinstates the trips A complete list of rod stops is noted below.Rd Stop List Fuaaataa a)Rod drop b)Nuclear Overpower Actuation Si nal One~f-four rapid power range nuclear power decrease or any rod bottom signal Oneof-four high power range nuclear power or Rod Motion to be Blocked Automatic withdrawal (redundant, contacts)Automatic and manual withdrawal one-of-two high intermediate range nuclear power 3.1-9 t~g 4-top~st (Cont d)UjjCj:Xjjn c)iU.gh 4T Actuation Si nal One-of-four overpower 4T or one-of-four Rod Motion to be Blocked Automatic and manual withdrawal overtemperature 4T (Manual bypass on indi-vidual 4T channels)(Actuation of this rod stop initiates a continuous turbine load reduction until the actuation signal is'emoved)
Automatic andmanualwithdrawal one-of-two highintermediate rangenuclearpower3.1-9 t~g 4-top~st(Contd)UjjCj:Xjjn c)iU.gh4TActuation SinalOne-of-four overpower 4Torone-of-four RodMotiontobeBlockedAutomatic andmanualwithdrawal overtemperature 4T(Manualbypassonindi-vidual4Tchannels)
.d)Low power e)T avg deviation One-ofmne low turbine impulse stage pressure One-of-four T devia-avg tion from average T avg Automatic withdrawal H Automatic withdrawal and insertion 3.1.5 LQXCATION F Control Board Xndicators and Recorder-All transmitted analog signals which actuate reactor trips, rod stops, oz permissive circuits are either indicated or recorded for every.channel-Also.variable trip setpoints (overpower 4T and overtemperature 4T)are icated or recorded for every channel.Central Board Annunciator Panel~y of the following conditions actuate an alarm: Reactor trip (first out annunciator) b).aztial reactortrip (any channel)~wi oz~i<<deviation of any control variable (pressure, T, pressurizer level avg'li nuclear power, and steam generator level)for any channel.3.1-10  
(Actuation ofthisrodstopinitiates acontinuous turbineloadreduction untiltheactuation signalis'emoved)
~>>~t'lvl%1~y W C~ns'r, zy~\~  
.d)Lowpowere)Tavgdeviation One-ofmne lowturbineimpulsestagepressureOne-of-four Tdevia-avgtionfromaverageTavgAutomatic withdrawal HAutomatic withdrawal andinsertion 3.1.5LQXCATION FControlBoardXndicators andRecorder-Alltransmitted analogsignalswhichactuatereactortrips,rodstops,ozpermissive circuitsareeitherindicated orrecordedforevery.channel-Also.variabletripsetpoints (overpower 4Tandovertemperature 4T)areicatedorrecordedforeverychannel.CentralBoardAnnunciator Panel~yofthefollowing conditions actuateanalarm:Reactortrip(firstoutannunciator) b).aztialreactortrip(anychannel)~wioz~i<<deviation ofanycontrolvariable(pressure, T,pressurizer levelavg'linuclearpower,andsteamgenerator level)foranychannel.3.1-10  
';t"o>.3oard Status Pm&status of each reactor trip'c" on the trip status panel'-'.channel is continuously displayed I status o f each permissive circuit is continuously displayed on th pe~sive stat panel~~'reactor trip channel;bypass is.continuously indicated on the hypos status pmn-'I 17~a 3.1-11 s P k
~>>~t'lvl%1~yWC~ns'r,zy~\~  
.,y ll+~~l IE~Tgtp I.fluuual 2.High nuclear flux CplHClUEHCY.
';t"o>.3oard StatusPm&statusofeachreactortrip'c"onthetripstatuspanel'-'.
ClRCULTRY b lHTERIXKKS 1/2, no interlocks 2/4, no interlocks for high setting P-10 for low setting l.'ON 1 k l)1 S High and low setttngs;manual block and automatic reset of low setting 3.', lligh nuclear flux (inter>>mediate range)High nuclear flux (source range)1/2q P-10 I 2/4;no interlocks 2/4, no interlocks 2/4>blocked by P-7 2/3>no interlocks 2/3, blocked by P-7 5, Overtemperature LiT 6.Overpower hT 7.Low'ressure 8.9.High pressure High pressurizer water level 10a.Low Flop 10b.Pump breaker trip 10c.Undervoltage 10d.Underfrequency SIS actuation 12.Turbine trip 13, Low feedwater flow 14.Low-low S.G.water level 2/3 per loop~p 7~P>>S 1/1 per loop]P 7)P+S 1/2 t'1/2~P-7 1/2+1/2 P-7 1/3,.(low pressurizer pressure and low pressurizer level);2/3 Low pressure in any steam line;or 2/3 high containment pressure 2/3 autostop oil or 2/2 stop valves>P;7]P-9 1/2+1/2 per loop, (flow mismatch in coincidence with low leyel)2/3$per loop h 0 Tayg n>AYO K4 T38 8 AT setpoint 1 Comparator C3.C3 C 4 2/4 ogic hot T c Comparator Rod Stop 0~POWER AT CHANNEL (ONE CHANNEL OF FOUR SROHH)FIGURE 3.1-2 l.l CONTROL SYSTEH t am dumP are available:
channeliscontinuously displayed Istatusofeachpermissive circuitiscontinuously displayed onthpe~sivestatpanel~~'reactor tripchannel;bypass is.continuously indicated onthehyposstatuspmn-'I17~a3.1-11 sPk
condensex'umP and atmosPheric
.,yll+~~lIE~TgtpI.fluuual2.HighnuclearfluxCplHClUEHCY.
<cle valve arrangement is shown on Figure 3-2-1-yq steam cy C0gDENSER S~QUMP SYSTEM Svs ea Desi steam lines are installed to dump steam from the steam generators directly co the condenser, bypassing the turbine.Connections with the steam mains axe downstream of the stea'm main isolation valves.ralves and LLnes are sized to pass 35X of turbine auuctunan calculated steam flow at full load steam pressure.Condenser steam dump performs three functions:
ClRCULTRY blHTERIXKKS 1/2,nointerlocks 2/4,nointerlocks forhighsettingP-10forlowsettingl.'ON1kl)1SHighandlowsetttngs; manualblockandautomatic resetoflowsetting3.',llighnuclearflux(inter>>mediaterange)Highnuclearflux(sourcerange)1/2qP-10I2/4;nointerlocks 2/4,nointerlocks 2/4>blockedbyP-72/3>nointerlocks 2/3,blockedbyP-75,Overtemperature LiT6.Overpower hT7.Low'ressure 8.9.HighpressureHighpressurizer waterlevel10a.LowFlop10b.Pumpbreakertrip10c.Undervoltage 10d.Underfrequency SISactuation 12.Turbinetrip13,Lowfeedwater flow14.Low-lowS.G.waterlevel2/3perloop~p7~P>>S1/1perloop]P7)P+S1/2t'1/2~P-71/2+1/2P-71/3,.(lowpressurizer pressureandlowpressurizer level);2/3Lowpressureinanysteamline;or2/3highcontainment pressure2/3autostopoilor2/2stopvalves>P;7]P-91/2+1/2perloop,(flowmismatchincoincidence withlowleyel)2/3$perloop h0Taygn>AYOK4T388ATsetpoint1Comparator C3.C3C42/4ogichotTcComparator RodStop0~POWERATCHANNEL(ONECHANNELOFFOURSROHH)FIGURE3.1-2 l.l CONTROLSYSTEHtamdumPareavailable:
Following a sudden loss of load of up to 210 MRe{about 45X of=aximum calculated turbine load), condenser dump acts as an artificial load removing excess power and stored energy while the reactor power is decreased to match the xeduced turbine\In this manner, the condenser steam dump acts to prevent a reactor trip.Condenser steam dump, together with feedwater addition, removes stored energy in the Reactor Coolant System following a plant trip, bringing the plant ro equilibrium no load condition without 3.2-1 r o f the s team generator saf ety valves.It also maintains~tuation o 1 t at hot shutdown by removing residual heat.gg pJ.ant at ser steam dump is used for plant cooldown to cold shutdown.condenser ste~~er steam dump is used to improve operational flexibility.
condensex'umP andatmosPheric
For a plant trip may occur following a large load reduction if~le, ap an~4.user steam dump is not available.
<clevalvearrangement isshownonFigure3-2-1-yqsteamcyC0gDENSER S~QUMPSYSTEMSvseaDesisteamlinesareinstalled todumpsteamfromthesteamgenerators directlycothecondenser, bypassing theturbine.Connections withthesteammainsaxedownstream ofthestea'mmainisolation valves.ralvesandLLnesaresizedtopass35Xofturbineauuctunan calculated steamflowatfullloadsteampressure.
~condenser steam dump system uses modulating, Unear-characteristics,~~crated valves (air to open).Their stroke time is approximately 5 aecaads.Xn addition, they can be tripped from the fully closed to tate fu11 open position within 3 seconds after receiving an input eLectric trip signal.While this trip signal exists, the valves are bahf~the fully open position.When the trip signal does not exist, che valve position is determined by a variable input electrical signal-For condenser protection, condenser steam dump is blocked by high~enser pressure.Other interlocks'described below)are used~~e same manner to avoid spurious operation.
Condenser steamdumpperformsthreefunctions:
~pur'<<ous actuation of steam dump may cause a plant trip In addition,'-the ralves stay open, an uncontrolled cooldown results.For these the steam dump control system is required to meet the criterion signal failure shall cause spurious actuation-3~2~2  
Following asuddenlossofloadofupto210MRe{about45Xof=aximumcalculated turbineload),condenser dumpactsasanartificial loadremovingexcesspowerandstoredenergywhilethereactorpowerisdecreased tomatchthexeducedturbine\Inthismanner,thecondenser steamdumpactstopreventareactortrip.Condenser steamdump,togetherwithfeedwater
: addition, removesstoredenergyintheReactorCoolantSystemfollowing aplanttrip,bringingtheplantroequilibrium noloadcondition without3.2-1 rofthesteamgenerator safetyvalves.Italsomaintains
~tuationo1tathotshutdownbyremovingresidualheat.ggpJ.antatsersteamdumpisusedforplantcooldowntocoldshutdown.
condenser ste~~ersteamdumpisusedtoimproveoperational flexibility.
Foraplanttripmayoccurfollowing alargeloadreduction if~le,apan~4.usersteamdumpisnotavailable.
~condenser steamdumpsystemusesmodulating, Unear-characteristics,
~~cratedvalves(airtoopen).Theirstroketimeisapproximately 5aecaads.Xnaddition, theycanbetrippedfromthefullyclosedtotatefu11openpositionwithin3secondsafterreceiving aninputeLectrictripsignal.Whilethistripsignalexists,thevalvesarebahf~thefullyopenposition.
Whenthetripsignaldoesnotexist,chevalvepositionisdetermined byavariableinputelectrical signal-Forcondenser protection, condenser steamdumpisblockedbyhigh~enserpressure.
Otherinterlocks'described below)areused~~esamemannertoavoidspuriousoperation.
~pur'<<ous actuation ofsteamdumpmaycauseaplanttripInaddition,
'-theralvesstayopen,anuncontrolled cooldownresults.Forthesethesteamdumpcontrolsystemisrequiredtomeetthecriterion signalfailureshallcausespuriousactuation-3~2~2  


ControlSystemalblockdiagramfortheCondenser SteamDumpControl~efunctonSvstemisshownonFigure3.2-2.LoadReectionControl."-orpartiallossofturbineload,steamdumpiscontrolled bytheerrorsignalbetweenTandTf,whereTistheaverageoffouravgref'vgreactorcoolantaverage.temperatures and.T"istheprogz~ed, se~ref,pointforTasafunctionofturbineload.(ThesesignalsaretheavgsameasthoseusedintheReactorControlSystem.)Following aturbineloaddecrease, Tisimm'ediately resettoalowervalue,causinganreferrorsignal.Iftheerrorsignalexceedsthedeadbandfortheload.re)ection controller, thedumpvalvesaremodulated open.IftheerrorsignalexceedstheHIsetpoint, atrip.signalisgenerated whichrapidlyopensfouroftheeightvalvestotheirfully~~en position.
Control System al block diagram for the Condenser Steam Dump Control~e funct on Svstem is shown on Figure 3.2-2.Load Re ection Control."-or partial loss of turbine load, steam dump is controlled by the error signal between T and T f, where T is the average of four avg ref'vg reactor coolant average.temperatures and.T" is the progz~ed, se~ref, point for T as a function of turbine load.(These signals are the avg same as those used in the Reactor Control System.)Following a turbine load decrease, T is imm'ediately reset to a lower value, causing an ref error signal.If the error signal exceeds the deadband for the load.re)ection controller, the dump valves are modulated open.If the error signal exceeds the HI setpoint, a trip.signal is generated which rapidly opens four of the eight valves to their fully~~en position.At'he occurrence of a HZ-HI trip signal, all eight valves trip open.The distinction between modulating and tripping valves open is made because of the difference in required time for both of these actions.If valves are already modulated open corresponding to the error signal<<the time a trip open signal is generated, no additional trip action takes place.Sin~e the steam dump system requires a finite time to, act, an increase is to be expected.Lead/lag compensation for T increases avg avg 3~2 3 g f T on the error, thereby compensating f or the legs~gcect of l response and valve positioning.
At'heoccurrence ofaHZ-HItripsignal,alleightvalvestripopen.Thedistinction betweenmodulating andtrippingvalvesopenismadebecauseofthedifference inrequiredtimeforbothoftheseactions.Ifvalvesarealreadymodulated opencorresponding totheerrorsignal<<thetimeatripopensignalisgenerated, noadditional tripactiontakesplace.Sin~ethesteamdumpsystemrequiresafinitetimeto,act,anincreaseistobeexpected.
s reactor power by control rod insertion.
Lead/lagcompensation forTincreases avgavg3~23 gfTontheerror,therebycompensating forthelegs~gcectoflresponseandvalvepositioning.
reduces reac tpoint steam dump is redu appx'oaches avg valves are f ully seated M en ough to be handledoontroL system alone.~~d contra trol system also acting on the T-T f errox'ignal
sreactorpowerbycontrolrodinsertion.
~avg ref Ln order to prevent actuation of steam dump on small load perturbations, ,r a block is provided which prevents valve response to either the trip~modulate signal unless a turbine load reduction has occurred.AIl elcaents of this channel, including the turbine impulse chamber pressure tap, are independent of the steam dump control system described above.4 rate/lag unit in this channel generates an output proportional to~rare of decrease in turbine load;This output, when indicating a Load rejection gxeater than lOX step or 5X/mLnute ramp, removes the Once unblocked, this block is manually xeset.Minual-contxol of~team dump also removes this block.7uxb inc Tri Control~~e of the laxge heat capacity of the Reactox Coolant System and~~high T at full load the steam generator safety valves would avg~'~owing a turbine trip if there were no other means of removing ed heat.'ondenser steam dump and subcooled feedwater flow 3.2-4  
reducesreactpointsteamdumpisreduappx'oaches avgvalvesarefullyseatedMenoughtobehandledoontroLsystemalone.~~dcontratrolsystemalsoactingontheT-Tferrox'ignal
~avgrefLnordertopreventactuation ofsteamdumponsmallloadperturbations,
,rablockisprovidedwhichpreventsvalveresponsetoeitherthetrip~modulatesignalunlessaturbineloadreduction hasoccurred.
AIlelcaentsofthischannel,including theturbineimpulsechamberpressuretap,areindependent ofthesteamdumpcontrolsystemdescribed above.4rate/lagunitinthischannelgenerates anoutputproportional to~rareofdecreaseinturbineload;Thisoutput,whenindicating aLoadrejection gxeaterthanlOXstepor5X/mLnute ramp,removestheOnceunblocked, thisblockismanuallyxeset.Minual-contxolof~teamdumpalsoremovesthisblock.7uxbincTriControl~~eofthelaxgeheatcapacityoftheReactoxCoolantSystemand~~highTatfullloadthesteamgenerator safetyvalveswouldavg~'~owingaturbinetripiftherewerenoothermeansofremovingedheat.'ondenser steamdumpandsubcooled feedwater flow3.2-4  


planttothermalno-loadequilibrium without~~edtobring-leasetoatmosphere.
plant to thermal no-load equilibrium without~~ed to bring-lease to atmosphere.
eeaIetrip,monitored bylossofturbineautostopoilteoheloadre]ection steamdumpcontroller isdefeatedandplanttrptripcontroller becomesactive.IntheTcontrolmode,avgrsignalisT-Td'ndsteamdumpisproportional
e ea I e trip, monitored by loss of turbine autostop oil t e o he load re]ection steam dump controller is defeated and plant tr p trip controller becomes active.In the T control mode, avg r signal is T-T d'nd steam dump is proportional
~errorsgnavgno-Load'he sameerrorsignalisusedforon-offcontrolof~fe~>>tercontrolvalve,asdescribed in3.4,SteamGenerator
~error s gn avg no-Load'he same error signal is used for on-off control of~fe~>>ter control valve, as described in 3.4, Steam Generator~L Control.As T.is reduced to its no>>load setpoint, steam'vg reduced and feedwater is shut off.As in the case of p load re)ection, if the error signal exceeds the HX setpoint, a trip asgaaL w generated which trips open four of the eight valves to their iull~pen position.At the occurrence of a HI-Hl trip signal, all~ght valves trip open.GeneraUy, the valves are not closed completely l~use of decay heat.No-load conditions are established within mo minutes.pressure Control'or><<g term removal of residual heat at hot shutdown, o~during plant it>rtup or cooldown, the plant operator can manually switch to steam der pressure control.In this control mode, condenser steam dump o maintain a preset pressure in the steam header.A manual~tion is provided so that the operator can ad)ust the setpoint~<<ssure or manually position the valves.3.2-5  
~LControl.AsT.isreducedtoitsno>>loadsetpoint, steam'vgreducedandfeedwater isshutoff.Asinthecaseofploadre)ection, iftheerrorsignalexceedstheHXsetpoint, atripasgaaLwgenerated whichtripsopenfouroftheeightvalvestotheiriull~penposition.
~pbbs j, S>H~ZC S~RELIEF SYSTEH steam relief valves are mounted on the steam mains upstream uoayher'c steam ves.At the set pre 4g~>o steam (about 1050 psig), f low calcu'c have provisgon f e s less than Z0 Provided to reduce d to permit a plant oold s'cedia dump is not available.
Attheoccurrence ofaHI-Hltripsignal,all~ghtvalvestripopen.GeneraUy, thevalvesarenotclosedcompletely l~useofdecayheat.No-loadconditions areestablished withinmominutes.pressureControl'or><<gtermremovalofresidualheatathotshutdown, o~duringplantit>rtuporcooldown, theplantoperatorcanmanuallyswitchtosteamderpressurecontrol.Inthiscontrolmode,condenser steamdumpomaintainapresetpressureinthesteamheader.Amanual~tionisprovidedsothattheoperatorcanad)ustthesetpoint~<<ssureormanuallypositionthevalves.3.2-5  
These functions are explained below.a)If a plant trip is caused by loss of condenser vacuum, condenser dump m bIocked.The'steam generator safety valves are available to remove stored energy from the Reactor Coolant System.Atmos-@heroic steam relief reduces the steam pressure below the safety valve set pressure within two minutes after the trip.This prevents'ontinuous chattering of the safety valves as residual beat m removed from the reactor.Plant coo]down is accomplished by steam dump.If condens<<dump not available, the atmospheric relief is adequate to cool d~to the temperature and pressure at which the residual heat removal system can be used.3.2-6  
~pbbsj, S>H~ZCS~RELIEFSYSTEHsteamreliefvalvesaremountedonthesteammainsupstreamuoayher'c steamves.Atthesetpre4g~>osteam(about1050psig),flowcalcu'chaveprovisgon feslessthanZ0Providedtoreducedtopermitaplantoolds'cediadumpisnotavailable.
Thesefunctions areexplained below.a)Ifaplanttripiscausedbylossofcondenser vacuum,condenser dumpmbIocked.The'steamgenerator safetyvalvesareavailable toremovestoredenergyfromtheReactorCoolantSystem.Atmos-@heroicsteamreliefreducesthesteampressurebelowthesafetyvalvesetpressurewithintwominutesafterthetrip.Thisprevents'ontinuous chattering ofthesafetyvalvesasresidualbeatmremovedfromthereactor.Plantcoo]downisaccomplished bysteamdump.Ifcondens<<dump notavailable, theatmospheric reliefisadequatetocoold~tothetemperature andpressureatwhichtheresidualheatremovalsystemcanbeused.3.2-6  


C)Zntheeventofaplanttripcausedbyanoverpower/overtemperature condition orbyafaU.ureinthefeedwater system,theatmospheric steamdumpprovidesadditidhal reliefcapacity, reducingthepro-babDityofsafetyvalveactuation.
C)Zn the event of a plant trip caused by an overpower/overtemperature condition or by a faU.ure in the feedwater system, the atmospheric steam dump provides additidhal relief capacity, reducing the pro-babDity of safety valve actuation.
Separatecontrollers areprovidedfortheatmospheric dumpvalvesonthetwosteamgenerators, permitting independent pressureregu-lationifthesteamgenerators areisolated.
Separate controllers are provided for the atmospheric dump valves on the two steam generators, permitting independent pressure regu-lation if the steam generators are isolated.3e 2~7 T cold AVG T~at 1 V2 Swl K3 P K2 AT setpoi t E Comparator 2 2]4 Logic 3 C 4 hot cold'/Comparator Rod Stop 0$EBTEMPEBATURE AT CHANNEL (ONE CHANNEL OF POUR SHOWN)P1GVRE 3.1-1 F~.~~'I rl EnM lEHEl/ATOR Nntrr.)VAl VN ISAtIM YAllg l J IOOla'nON VALVE BYPASS.VALVE HAIN FEEDWATEE kLN.IQ'AI.VL I IA)I AT I lNli Olla:K TO TURBINE CON1'AINMENT AUXILIARY FEEUHATER+P go I i CONDENSER STEAM DUMP VALVES<<TEAM IEHERATOR B MAIN FEEWATER TO CONDENSER AUXILIARY FEEOHATER Figure 3.2-1 STEAM CYCLE VALVE ARRAMEMENT I i
3e2~7 TcoldAVGT~at1V2SwlK3PK2ATsetpoitEComparator 22]4Logic3C4hotcold'/Comparator RodStop0$EBTEMPEBATURE ATCHANNEL(ONECHANNELOFPOURSHOWN)P1GVRE3.1-1 F~.~~'IrlEnMlEHEl/ATOR Nntrr.)VAlVNISAtIMYAllglJIOOla'nON VALVEBYPASS.VALVEHAINFEEDWATEE kLN.IQ'AI.VL IIA)IATIlNliOlla:KTOTURBINECON1'AINMENT AUXILIARY FEEUHATER
~en/LAG COMPENSATION STEAM DUMP)ER PRESSURE CONTROLLER r RATE+RESET AUTO"MAN STATION PROP.ANALOG SWITCH OPERA-TING ON TURBIHE TRIP SIGHAL STEAM DUMP SELECTOR SWITCH MODULATE COHDEHSER DUMP VALVES LEAD/LAG COMPENSATION
+PgoIiCONDENSER STEAMDUMPVALVES<<TEAMIEHERATOR BMAINFEEWATERTOCONDENSER AUXILIARY FEEOHATER Figure3.2-1STEAMCYCLEVALVEARRAMEMENT Ii
((<>>s).I Jf<Sgl+fg$)L TRZ I COmZROLIhR Hi-TURB ZHE TRIP INTER-LOCK LOGIC TURBINE-TRIP SIGNAL TRIP OPEH GROUP A VALVES OR TRIP OPEN GROUP A 8c B VAL~STEAM DUMP VALVES.TRIP OPEH ONLY IF UHBLOCK SIGNAL IS PRESENT (SEE BELOW)Hj E LOSS OF LOAD INTERLOCK r:J+A--ROPRIATE POSITION OH SKZCTOR SWITCH ZHTKGDCK Figure 3.2-2 CONDENSER STEAM EUMP CONTROL SC1HHE UHB LOCK STEAM DUMP VALVES SIGHAL TURBINE TRIP SIGNAL BYPASSES LOSS OF LOAD INTERLOCK AHD UHBLOCKS STEAM DUMP VALVES 1 f'V (Y+gpQ+g+q+gl Y f" Al+J 1l 3 3 REACTOR CONTROL The basic Reactor Control System consists of three channels, which are re temperature (T), powez'ismatch (QT-Q)and reactor coolant avg'x'essure (P)~The output'of these three channels is used to drive the control rods via the rod program.A schematic representation of the control system is given in Figure 3.3>>1.The functions of each of these channels are as foU.ows: a)To maintain the programmed T as accurately as possible avg b)To be responsive to load perturbations without causing undue movement and reactor trips c)To take corrective action in the case of large load changes if the pressure exceeds the limits of the noxma1 pressure control.The T erature Channel The temperature channel functions to maintain the programmed temperature
~en/LAGCOMPENSATION STEAMDUMP)ERPRESSURECONTROLLER rRATE+RESETAUTO"MANSTATIONPROP.ANALOGSWITCHOPERA-TINGONTURBIHETRIPSIGHALSTEAMDUMPSELECTORSWITCHMODULATECOHDEHSER DUMPVALVESLEAD/LAGCOMPENSATION
-(T)as accurately as possible.The main requirements of this channel avg are that it should be accuxate, stable and repeatable.
((<>>s).IJf<Sgl+fg
This is the dominant contx'ol channel in steady-state conditions.'he Power Mismatch Channel The power mismatch channels provide control stability and fast response t>>oad pertuxbations.
$)LTRZICOmZROLIhR Hi-TURBZHETRIPINTER-LOCKLOGICTURBINE-TRIP SIGNALTRIPOPEHGROUPAVALVESORTRIPOPENGROUPA8cBVAL~STEAMDUMPVALVES.TRIPOPEHONLYIFUHBLOCKSIGNALISPRESENT(SEEBELOW)HjELOSSOFLOADINTERLOCK r:J+A--ROPRIATEPOSITIONOHSKZCTORSWITCHZHTKGDCKFigure3.2-2CONDENSER STEAMEUMPCONTROLSC1HHEUHBLOCKSTEAMDUMPVALVESSIGHALTURBINETRIPSIGNALBYPASSESLOSSOFLOADINTERLOCK AHDUHBLOCKSSTEAMDUMPVALVES 1f'V(Y+gpQ+g+q+gl Yf"Al+J1l 33REACTORCONTROLThebasicReactorControlSystemconsistsofthreechannels, whichareretemperature (T),powez'ismatch (QT-Q)andreactorcoolantavg'x'essure (P)~Theoutput'ofthesethreechannelsisusedtodrivethecontrolrodsviatherodprogram.Aschematic representation ofthecontrolsystemisgiveninFigure3.3>>1.Thefunctions ofeachofthesechannelsareasfoU.ows:a)Tomaintaintheprogrammed Tasaccurately aspossibleavgb)Toberesponsive toloadperturbations withoutcausingunduemovementandreactortripsc)Totakecorrective actioninthecaseoflargeloadchangesifthepressureexceedsthelimitsofthenoxma1pressurecontrol.TheTeratureChannelThetemperature channelfunctions tomaintaintheprogrammed temperature
The output is proportional to the mismatch between turbine power and nucleax power.A high-pass filter in this channel ensures that steady-state calibration errors in the input power signals"as no effect on steady-state control.3.3-1  
-(T)asaccurately aspossible.
.at I ,'g l~jl  
Themainrequirements ofthischannelavgarethatitshouldbeaccuxate, stableandrepeatable.
~other requirement of this channel is that its steady-state output should be zero even though a Axed offset in power signals may exist.The Pressure Channel This channel is provided to prevent large pressure changes foU.owing a large change in power.It retards the rate at which the controller changes T to its new programmed set point.(If T were to be changed avg avg too rapidly, pressurizer pressure contxol might not be able to maintain pressure within the normal operating range.)The pressure control channel has an adjustable deadband, so that only large pressure changes have an effect on rod motion.This channel is not required for initial plant.operation.
Thisisthedominantcontx'olchannelinsteady-state conditions.'he PowerMismatchChannelThepowermismatchchannelsprovidecontrolstability andfastresponset>>oadpertuxbations.
The Rod S eed Pro am The rod speed program is made up of four parts: ari adjustable deadband, a minimum speed, a proportional speed, and a maxLmum speed.The auucLannn speed is dictated by the mechanism design.A11 the other settings are ad)ustable.
Theoutputisproportional tothemismatchbetweenturbinepowerandnucleaxpower.Ahigh-pass filterinthischannelensuresthatsteady-state calibration errorsintheinputpowersignals"asnoeffectonsteady-state control.3.3-1  
Expected set points are+1.5 F for the deadband, and+5 F for amximum rod speed demand.The outputs from the three channe1s mentioned above feed into the summing amplifier associated with the rod program.3a3~2 Ijgg~gi 4t'~s~A)t l(~<lI>I l.(I~')F~As)u AVO l Turbine Im ulse Pressure~gS+1 Speed 4n+E T S t6S+1 0 ariable Gain+Pressurizer Pressure E tyS+1~88+1 Pressure Set oint REACTOR CONTROL SYSTEH Figure 3.3-'1  
.atI,'gl~jl  
~I~I 4 j~
~otherrequirement ofthischannelisthatitssteady-state outputshouldbezeroeventhoughaAxedoffsetinpowersignalsmayexist.ThePressureChannelThischannelisprovidedtopreventlargepressurechangesfoU.owing alargechangeinpower.Itretardstherateatwhichthecontroller changesTtoitsnewprogrammed setpoint.(IfTweretobechangedavgavgtoorapidly,pressurizer pressurecontxolmightnotbeabletomaintainpressurewithinthenormaloperating range.)Thepressurecontrolchannelhasanadjustable
CINERATOR LEVEL CONTROL M operation, the position of the main f eedwater control valve is ope 11ed by the three-element controller (feedwater flow, steam flow, At low loads a bypass control valve is used.>+tpoint o f the 1 evel contro 1 1 er is a f unct ion of load, programned ise with load between OX and-2OX load.A deviation alarm provides~ti~uous monitoring of the level channel used for contxol versus the programmed level.~>narrow-range level channels are indicated.
: deadband, sothatonlylargepressurechangeshaveaneffectonrodmotion.Thischannelisnotrequiredforinitialplant.operation.
The wide-range level channel is recorded..he steam flow and feedwater flow signals aze supplied by either of two transmitters as selected by a contxol board mounted selector switch.The steam and feedwater flow signals used for control are recorded on a two pen recorder.":ollowing a turbine trip, automatic control of the feedwater valve is switched from the three mode level controller to on off T control.avg<1<<edwater control valves under automatic control are fully opened to admit auucbnum feedwater, then fully closed as no-load T avg approached to avoid excessive cooldown of the Reactor Coolant System.~<<1 contzol of feedwater control valve position is available at the ontrol board.This mode o f control overrides automatic contzol on either level or T avg 3.4-1 tO~+~~'"'=*4%-4'ft'%41''V~~k/+''t p i t' order to prevent excessive'moisture cazxyover caused by high steam~erator water lev~.a sig al of high water level ove~des a3.Other tzol and closes the feedwater control valve.The signal is obtained from coincidence of two-of-three level channeLs above a preset value.This override is automatically removed from the main control valves as the water level drops below Che set value.Manual reset is required for the bypass control valve.The signals affecting feedwater valve control, in increasing the order of priority, are listed below: a)Three-element level control or on-off T control (dependent on avg whethez or not'turbine is tripped)b)Manual control c)High level override (closes feedwater valves)d)Safety Injection System actuation (closes feedwater valves).A wide-range level channeL, calibrated for no-load conditions, fa provided co allow manual control at hot shutdown and is also useful at cold shutdown This channel includes a recorder.3.4-2  
TheRodSeedProamTherodspeedprogramismadeupoffourparts:ariadjustable
~PROTECTION SYSTEM~~q BR IN JECTION SYSTEM ACTUATION QEEIY f actuating the Safety Injection System have been noted in o act Those particularly concerned with steam line break pro-~~4 3~~~a are low steam 1 ine pressure and hi gh containment pressure.~An are o low steam~steam line pressure signal is generated by the coincidence of~f three channels below approximately 500 psig for either steam line.~~high containment pressure signal is generated by the coincidence of~f-three channels above approximately ten per cent of containment
: deadband, aminimumspeed,aproportional speed,andamaxLmumspeed.TheauucLannn speedisdictatedbythemechanism design.A11theothersettingsaread)ustable.
~ign pressure.3.5.2 FEEDWATER LINE ISOLATION Any safety infection signal isolates the main feedwater lines by closing all four main control valves, tripping the main feedwater pumps, and closing the pump discharge valves.3.5-3 STEAM LINE ISOLATION a)High steam flow in coincidence with any safety in)ection signa1 closes the isolation valve in that steam Une.One-out-of-two steam flow signals above a HI-HI~p p (approximately 120X of fuLl load steam flow)One-out-of-two steam flow signals above a HI trip point (approx-imately 20X of full load steam flow)in coincidence with two-out-of-four low T signals (below approximately 540'7)avg 3.5-1 ll IJ, J,=" 4~1'~~"J bi~e coincidence of tv~f-three high contaf.nment pressure signaLs Rctustion~
Expectedsetpointsare+1.5Fforthedeadband, and+5Fforamximumrodspeeddemand.Theoutputsfromthethreechanne1smentioned abovefeedintothesummingamplifier associated withtherodprogram.3a3~2 Ijgg~gi4t'~s~A)tl(~<lI>Il.(I~')F~As)uAVOlTurbineImulsePressure~gS+1Speed4n+ETSt6S+10ariableGain+Pressurizer PressureEtyS+1~88+1PressureSetointREACTORCONTROLSYSTEHFigure3.3-'1  
~I~I4j~
CINERATOR LEVELCONTROLMoperation, thepositionofthemainfeedwatercontrolvalveisope11edbythethree-element controller (feedwater flow,steamflow,Atlowloadsabypasscontrolvalveisused.>+tpointofthe1evelcontro11erisafunctionofload,programned isewithloadbetweenOXand-2OXload.Adeviation alarmprovides~ti~uousmonitoring ofthelevelchannelusedforcontxolversustheprogrammed level.~>narrow-range levelchannelsareindicated.
Thewide-range levelchannelisrecorded.
.hesteamflowandfeedwater flowsignalsazesuppliedbyeitheroftwotransmitters asselectedbyacontxolboardmountedselectorswitch.Thesteamandfeedwater flowsignalsusedforcontrolarerecordedonatwopenrecorder.
":ollowing aturbinetrip,automatic controlofthefeedwater valveisswitchedfromthethreemodelevelcontroller toonoffTcontrol.avg<1<<edwatercontrolvalvesunderautomatic controlarefullyopenedtoadmitauucbnumfeedwater, thenfullyclosedasno-loadTavgapproached toavoidexcessive cooldownoftheReactorCoolantSystem.~<<1contzoloffeedwater controlvalvepositionisavailable attheontrolboard.Thismodeofcontroloverrides automatic contzoloneitherlevelorTavg3.4-1 tO~+~~'"'=*4%-4'ft'%41''V~~k/+''tpit' ordertopreventexcessive'moisture cazxyover causedbyhighsteam~eratorwaterlev~.asigalofhighwaterlevelove~desa3.Othertzolandclosesthefeedwater controlvalve.Thesignalisobtainedfromcoincidence oftwo-of-three levelchanneLsaboveapresetvalue.Thisoverrideisautomatically removedfromthemaincontrolvalvesasthewaterleveldropsbelowChesetvalue.Manualresetisrequiredforthebypasscontrolvalve.Thesignalsaffecting feedwater valvecontrol,inincreasing theorderofpriority, arelistedbelow:a)Three-element levelcontroloron-offTcontrol(dependent onavgwhethezornot'turbine istripped)b)Manualcontrolc)Highleveloverride(closesfeedwater valves)d)SafetyInjection Systemactuation (closesfeedwater valves).Awide-range levelchanneL,calibrated forno-loadconditions, faprovidedcoallowmanualcontrolathotshutdownandisalsousefulatcoldshutdownThischannelincludesarecorder.
3.4-2  
~PROTECTION SYSTEM~~qBRINJECTIONSYSTEMACTUATION QEEIYfactuating theSafetyInjection SystemhavebeennotedinoactThoseparticularly concerned withsteamlinebreakpro-~~43~~~aarelowsteam1inepressureandhighcontainment pressure.
~Anareolowsteam~steamlinepressuresignalisgenerated bythecoincidence of~fthreechannelsbelowapproximately 500psigforeithersteamline.~~highcontainment pressuresignalisgenerated bythecoincidence of~f-threechannelsaboveapproximately tenpercentofcontainment
~ignpressure.
3.5.2FEEDWATER LINEISOLATION Anysafetyinfection signalisolatesthemainfeedwater linesbyclosingallfourmaincontrolvalves,trippingthemainfeedwater pumps,andclosingthepumpdischarge valves.3.5-3STEAMLINEISOLATION a)Highsteamflowincoincidence withanysafetyin)ection signa1closestheisolation valveinthatsteamUne.One-out-of-two steamflowsignalsaboveaHI-HI~pp(approximately 120XoffuLlloadsteamflow)One-out-of-two steamflowsignalsaboveaHItrippoint(approx-imately20Xoffullloadsteamflow)incoincidence withtwo-out-of-four lowTsignals(belowapproximately 540'7)avg3.5-1 llIJ,J,="4~1'~~"J bi~ecoincidence oftv~f-three highcontaf.nment pressuresignaLsRctustion~
3.5-2 A'~8)  
3.5-2 A'~8)  
.OV<VDCONTROLSYSTEMSDESIGNPRINCIPLES PUNCTIONAL DESIGNphilosoohyforfunctional designProtection Systemistoderiveposon~rewirectlyfromtheprocessvariables ofinterestwheneverpossible.
.OV<VD CONTROL SYSTEMS DESIGN PRINCIPLES PUNCTIONAL DESIGN p hi los oohy f or f unctional design Protection System is to derive p os on~re wirectly from the process variables of interest whenever possible.~oner, safety limit protection is assured independent of the ting acc'dent..~ertemperature high delta-T trip protects the core against Departure nucleate Boiling (DNB)for all combinations of pressure, temperature,~r.and axial power distribution.
~oner,safetylimitprotection isassuredindependent ofthetingacc'dent.
Thus, this single trip prevents DNB!'r.-cd<<ithdrawal accidents, boron dilution, xenon oscillations, and cxcessire load variations.
.~ertemperature highdelta-TtripprotectsthecoreagainstDeparture nucleateBoiling(DNB)forallcombinations ofpressure, temperature,
Protection against other limits, such as excess ve power, density and system overpressure, is also provided by close~itorinz of the variable of direct interest.;c ce="ain cases, however, these general protection functions are not rapid enough, or complete enough, to assure protection against a specific accident, such as loss of coo~~nt flow.In these cases, specific trip functions are orovidec, such as reactor coolant pump bus undervoltage and reactor coolant~or ce""ain more cre"'ble transients, such as turbine trip, a reactor trip 4-s derived from the.nitiating event-even though safety limf.ts would not oe exceeded if a reac":=trip were delayed until an overpressure or over-tempera=ure rri" oc""red.1n this manner, undesirable excursions are preven=ed, rathe t"..sc terminated.
~r.andaxialpowerdistribution.
4.1-1 certain protective functions are provided primarily to ensure the F~~lly, ce ufng integrity of plant component and piping systems.Examples include-or trip on high pressurizer water level to protect safety valve relief.eac or@fan Co and reactor trip on loss of feedwater to any steam generator.(The@clear'oss of safety requirement is to prevent complete loss of heat sink;i.e., feedwater to all steam generators.)
Thus,thissingletrippreventsDNB!'r.-cd<<ithdrawal accidents, borondilution, xenonoscillations, andcxcessire loadvariations.
."-or equipment design purposes, no distinction is made between the various categories of protection mentioned above.The same criteria and design oractice are appLied to all channels.Other alternatives are neither defensible nor practical, since all of these protective functions enhance nuclear safety and complement or supplement one another.:his approach requires an instrumentation system that measures, on a timely, accurate, and reLiable basis, dominate nuclear plant process variables.
Protection againstotherlimits,suchasexcessvepower,densityandsystemoverpressure, isalsoprovidedbyclose~itorinzofthevariableofdirectinterest.
instrument ranges, sensitivity, and time response must be selected consistent Wth the range and variation of each variable monitored.
;cce="aincases,however,thesegeneralprotection functions arenotrapidenough,orcompleteenough,toassureprotection againstaspecificaccident, suchaslossofcoo~~ntflow.Inthesecases,specifictripfunctions areorovidec, suchasreactorcoolantpumpbusundervoltage andreactorcoolant~orce""ainmorecre"'bletransients, suchasturbinetrip,areactortrip4-sderivedfromthe.nitiating event-eventhoughsafetylimf.tswouldnotoeexceededifareac":=tripweredelayeduntilanoverpressure orover-tempera=ure rri"oc""red.1nthismanner,undesirable excursions arepreven=ed, rathet"..scterminated.
Also, since many process variables are monitored, considerable overlap in protection functions is a natural consequence.
4.1-1 certainprotective functions areprovidedprimarily toensuretheF~~lly,ceufngintegrity ofplantcomponent andpipingsystems.Examplesinclude-ortriponhighpressurizer waterleveltoprotectsafetyvalverelief.eacor@fanCoandreactortriponlossoffeedwater toanysteamgenerator.
(The@clear'ossofsafetyrequirement istopreventcompletelossofheatsink;i.e.,feedwater toallsteamgenerators.)
."-orequipment designpurposes, nodistinction ismadebetweenthevariouscategories ofprotection mentioned above.ThesamecriteriaanddesignoracticeareappLiedtoallchannels.
Otheralternatives areneitherdefensible norpractical, sincealloftheseprotective functions enhancenuclearsafetyandcomplement orsupplement oneanother.:hisapproachrequiresaninstrumentation systemthatmeasures, onatimely,accurate, andreLiablebasis,dominatenuclearplantprocessvariables.
instrument ranges,sensitivity, andtimeresponsemustbeselectedconsistent Wththerangeandvariation ofeachvariablemonitored.
Also,sincemanyprocessvariables aremonitored, considerable overlapinprotection functions isanaturalconsequence.
4.L-2  
4.L-2  
~lst'I~
~l st'I~
CONTROLSYS~FUNCTIONAL DESIGNPowerlevelandreactorcoolanttemperatures arecontrolled automatica3.l.y inaWestinghouse PWRPlant.Thereactoriscontrolled tofoU.owanyturbineloadperturbation.
CONTROL SYS~FUNCTIONAL DESIGN Power level and reactor coolant temperatures are controlled automatica3.l.y in a Westinghouse PWR Plant.The reactor is controlled to foU.ow any turbine load perturbation.
Thisisidealforloadfrequency control.Theautomatic ReactorControlSystem,therefore, formsanessential partoftheplantoperation.
This is ideal for load frequency control.The automatic Reactor Control System, therefore, forms an essential part of the plant operation.
Itisbasically aregulating systemwhichmaintains propersteady-state operating conditions, therebyassuringadequatemarginstotripsettingsforoperational purposesandpropereconomicperformance.
It is basically a regulating system which maintains proper steady-state operating conditions, thereby assuring adequate margins to trip settings for operational purposes and proper economic performance.
Otherautomatic controlsystemsarepressurizer pressureandlevelcontrol,feedwater control,andsteamdumpcontrol.Thesesystemsarealsoessential tomaintainnormaloperating conditions ortosuppressexcursions imposedbyoaerational transients withoutrecoursetoprotective action.AsintheProtection Systemdesign,thisrequiresaninstrumentation systemthat\measures, onanaccurate, timely,andreliablebasis,'ominate nuclearplaneprocessvariables.
Other automatic control systems are pressurizer pressure and level control, feedwater control, and steam dump control.These systems are also essential to maintain normal operating conditions or to suppress excursions imposed by oaerational transients without recourse to protective action.As in the Protection System design, this requires an instrumentation system that\measures, on an accurate, timely, and reliable basis,'ominate nuclear plane process variables.
Theqevariables are,forthemostpart;thesameasthoserequiredbytheProtection System:looptemperatures, neutronflux;oressurizer pressureandlevel,steamgenerator level,steamflowandfeedwater flow.Inaddition, thetimeresponse, instrument, span,and~~nsitivity requirements formeasurement channelsservingeachofthetwo~y~temsaresimilar.Asaresult,primarysensorandtransducing equipment thatisacceptable forusewiththeProtection SystemshouldalsobeemployedwiththeControlSystem.FailureoftheControlSystemtoactwhenneeded,orspuriousactuation whennotneeded,generates aneedforprotection.
Theqe variables are, for the most part;the same as those required by the Protection System: loop temperatures, neutron flux;oressurizer pressure and level, steam generator level, steam flow and feedwater flow.In addition, the time response, instrument, span, and~~nsitivity requirements for measurement channels serving each of the two~y~tems are similar.As a result, primary sensor and transducing equipment that is acceptable for use with the Protection System should also be employed with the Control System.Failure of the Control System to act when needed, or spurious actuation when not needed, generates a need for protection.
Thesafest,plantis4.2-L onipedtobeonethatrequirestheLeastprotection.
The safest, plant is 4.2-L o niped to be one that requires the Least protection.
Forthisreason,wellastheeconomicdesirability ofavoidingplantoutageswhichcouldgavebeenprevented bypropercontrolactions,everyeffortismadetoensurereliablecontrol.Whereverpractical, controlinterlocks and/orredundant controldevicesareprovidedtoensurethatcontroLactiontakesolacewhenneeded-butonlywhenneeded.Controller-induced excursions causedby asinglesensorfailurearelargelyeliminated inWestinghouse designpractice.  
For this reason, well as the economic desirability of avoiding plant outages which could gave been prevented by proper control actions, every effort is made to ensure reliable control.Wherever practical, control interlocks and/or redundant control devices are provided to ensure that controL action takes olace when needed-but only when needed.Controller-induced excursions causedby a single sensor failure are largely eliminated in Westinghouse design practice.  
: i.  
: i.  
~g++SFEEDPLOWL3SF1)XgIPROP+INZECIII~I-,IIIIIIIIIPROP+INTEGILEVELCONTROLSYSTEMlIIIPI'2)FWPlFWIIIPEEDWATER ICONTROLVALVEIACTUATORIII~/7t~JiIt2/3HILEVEL2/3LO-LOLEVELI2/2I1/2LOFLOWLEGENDFWF-PEEDWATER PLOWTRANSMITTER SF-STEAMPLOWTRANSMITTER P-STEAHPRESSURETRANSMITTER L-LEVELTRANSMITTER I-ISOLATION AMPLIFIER h-DIPPERENCE AMPLIFIER X-MULTIPLIER EDWATERCONTROLREACTORTRIPREACTORTRIPVALVECLOSUREANDAUX.FEEDPL"IPSTARTANDINDICATORS NOTSHOWN.STEAMGENERATOR LEVELCONTROLANDPROTECTION SYSTEHFIGURE4.2-1  
~g++S FEED PLOW L3 SF 1)Xg I PROP+INZEC I I I~I-, I I I I I I I I I PROP+INTEG I LEVEL CONTROL SYSTEM l I I I P I'2)FW Pl FW I I I PEEDWATER I CONTROL VALVE I ACTUATOR I I I~/7 t~Ji I t 2/3 HI LEVEL 2/3 LO-LO LEVEL I 2/2 I 1/2 LO FLOW LEGEND FWF-PEEDWATER PLOW TRANSMITTER SF-STEAM PLOW TRANSMITTER P-STEAH PRESSURE TRANSMITTER L-LEVEL TRANSMITTER I-ISOLATION AMPLIFIER h-DIPPERENCE AMPLIFIER X-MULTIPLIER EDWATER CONTROL REACTOR TRIP REACTOR TRIP VALVE CLOSURE AND AUX.FEED PL"IP START AND INDICATORS NOT SHOWN.STEAM GENERATOR LEVEL CONTROL AND PROTECTION SYSTEH FIGURE 4.2-1  


3CONTROLANDPROTECTION INTERRELATION AorrentWestinghouse PWRsystems,theProtection andControlSystemsare'ncurrenanddistinctandareidentified assuchTheControlSystem><<eer,isdependent onsignalsderivedfromtheProtection Systemthroughisolation devices.However,thereisnofeedbackfromtheControlSystem.otheProtection System.>eequipment designphilosophy, illustrated onFigure2-1,isthattheControlSystemsensoristheoutputoftheisolation amplifier.
3 CONTROL AND PROTECTION INTERRELATION Aorrent Westinghouse PWR systems, the Protection and Control Systems are'n curren and distinct and are identified as such The Control System><<eer, is dependent on signals derived from the Protection System through isolation devices.However, there is no feedback from the Control System.o the Protection System.>e equipment design philosophy, illustrated on Figure 2-1, is that the Control System sensor is the output of the isolation amplifier.
Bythisorinciple, nocomponents areshared-theyareeitherpartoftheProtection Systemandarelocatedanddesignedassuch,ortheyarepartoftheControlSystem.Thisisaveryimportant featureoftheWestinghouse design,andpermitsadividingline,bothfunctionaUy andphysically, tobedrawnbetweencontrolandprotection.
By this orinciple, no components are shared-they are either part of the Protection System and are located and designed as such, or they are part of the Control System.This is a very important feature of the Westinghouse design, and permits a dividing line, both functionaUy and physically, to be drawn between control and protection.
Italsoensuresthat,inadvertent orIdeliberate changestotheControlSystemhavenomoreeffectonthePro-IrectionSystemthaniftheControlSystemcontained independent sensors.Thedesignrequirement fortheanalogisolation amplifiers istoisolatethe~<<tectionSystemfromanyelectrical faultswhichmightoccurinthe<<<<rolSystem.Extensive testswereperformed todemonstrate this'apability.
It also ensures that, inadvertent or I deliberate changes to the Control System have no more effect on the Pro-I rection System than if the Control System contained independent sensors.The design requirement for the analog isolation amplifiers is to isolate the~<<tection System from any electrical faults which might occur in the<<<<rol System.Extensive tests were performed to demonstrate this'apability.
Inthesetests,shorts,grounds,anda-candd-cvoltageswereappliedtotheamplifier output.Eventhoughsomeofthesetestswerest<<ctive(i.e.,destroyed theabilityoftheamplifier toproduceameaningful outputsignal),innocasewasanyperceptible disturbance fedac"intotheinputcircuitandhencetotheprotection System.4.3-1 0
In these tests, shorts, grounds, and a-c and d-c voltages were applied to the amplifier output.Even though some of these tests were st<<ctive (i.e., destroyed the ability of the amplifier to produce a meaningful output signal), in no case was any perceptible disturbance fed ac" into the input circuit and hence to the protection System.4.3-1 0
Thepresenceorabsenceofregulating controldevicesonthedownstream sideoftheisolation amplifier hasnoeffectontheisolation requirements.
The presence or absence of regulating control devices on the downstream side of the isolation amplifier has no effect on the isolation requirements.
Thesameequipment anddesignrequirement wouldexistevenifthesesignalswerebroughtoutoftheProtection Systemmerelyforremotereadoutanddata-logping purposes.
The same equipment and design requirement would exist even if these signals were brought out of the Protection System merely for remote readout and data-logping purposes.Since channe1 isolation cannot be reliably main-tained on the control board or at the input terminals to a data-logger, an isolation device (amplifier or impedance network)in the protection channel represents the only feasible way to preserve protection channel independence.
Sincechanne1isolation cannotbereliablymain-tainedonthecontrolboardorattheinputterminals toadata-logger, anisolation device(amplifier orimpedance network)intheprotection channelrepresents theonlyfeasiblewaytopreserveprotection channelindependence.
Certain failures in the Protection System could conceivably negate a par-ticular channel of a protective function, simultaneously causing spurious control action that might, require protective action from that same function to prevent the excursion from exceeding design limits.Such possible failure is dealt with in accordance with the proposed standard,"Criteria<or Nuclear Power Plant Protection Systems", IEE No.279, Section 4.7, which requires that for such a fault, a second failure be assumed in the'Protection e In most cases in'which control is derived from protection, Westing-"se design meets this criterion by providing a two-out-of-four Protection System Loaic.For example, as shown in Figure 4.3-1,'a failure can be" s~ed in Protection Channel L which causes that channel to indicate high.defeats the low pressure reactor trip for the channel, and also may"e Pressure Control System (relief valves and spray)to rapidly reduce~assure.However, three of the pressure protection channels are left-.@ached t sure t P nd a reactor trip would automatically occur when any two of them T this additional redundancy is not necessary because such other cases, cannot cause the safety limits to be exceeded.This fact can canno illustrated by Figure 4.3-1.A loss of signal (low indication) bc assumed for Protection Channel 1.This defeats the high pressure bc assume or that channel and may also energize the pressurizer heaters, causing l~increase in pressure.If an independent failure is assumed in Channel 2, g glow nc cactor trip would occur when the pressure reached the high pressure trip~taint since only one of the three high pressure trip channels is left However, under this condition the safety valves on the pressurizer g<c~ore than adequate to ensure that the high pressure safety limit is not acceded.Section 4.4 discusses all such control and protection interactions for a mccific plant design.In that section, it is noted that numerous operational
CertainfailuresintheProtection Systemcouldconceivably negateapar-ticularchannelofaprotective
-'cfenses against these failures exist in addition to the primary or"protection a'ade" defense.Many of these additional barriers to.an undesirable excursion N 4c'c made possible by making redundant information avaQ.able to the Control System.+c possibility of common-mode failure cannot be completely ruled out;it is<<<<eivable that all identical channels behave identically, but incorrectly.
: function, simultaneously causingspuriouscontrolactionthatmight,requireprotective actionfromthatsamefunctiontopreventtheexcursion fromexceeding designlimits.Suchpossiblefailureisdealtwithinaccordance withtheproposedstandard, "Criteria
.""-his case, the question of Control System dependence on the Protection em is irrelevant.
<orNuclearPowerPlantProtection Systems",
It has been recognized that little, if any, additional deere e<<<<of protection is achieved by having separate, but identical, instru-"t channels for control and protection.
IEENo.279,Section4.7,whichrequiresthatforsuchafault,asecondfailurebeassumedinthe'Protection eInmostcasesin'whichcontrolisderivedfromprotection, Westing-"sedesignmeetsthiscriterion byproviding atwo-out-of-four Protection SystemLoaic.Forexample,asshowninFigure4.3-1,'afailurecanbe"s~edinProtection ChannelLwhichcausesthatchanneltoindicatehigh.defeatsthelowpressurereactortripforthechannel,andalsomay"ePressureControlSystem(reliefvalvesandspray)torapidlyreduce~assure.However,threeofthepressureprotection channelsareleft-.@achedtsuretPndareactortripwouldautomatically occurwhenanytwoofthem Tthisadditional redundancy isnotnecessary becausesuchothercases,cannotcausethesafetylimitstobeexceeded.
Indeed, Westinghouse considers t separation in this manner actually deprives the protection System of 4.3-3  
Thisfactcancannoillustrated byFigure4.3-1.Alossofsignal(lowindication) bcassumedforProtection Channel1.Thisdefeatsthehighpressurebcassumeorthatchannelandmayalsoenergizethepressurizer heaters,causingl~increaseinpressure.
Ifanindependent failureisassumedinChannel2,gglownccactortripwouldoccurwhenthepressurereachedthehighpressuretrip~taintsinceonlyoneofthethreehighpressuretripchannelsisleftHowever,underthiscondition thesafetyvalvesonthepressurizer g<c~orethanadequatetoensurethatthehighpressuresafetylimitisnotacceded.Section4.4discusses allsuchcontrolandprotection interactions foramccificplantdesign.Inthatsection,itisnotedthatnumerousoperational
-'cfenses againstthesefailuresexistinadditiontotheprimaryor"protection a'ade"defense.Manyoftheseadditional barriersto.anundesirable excursion N4c'cmadepossiblebymakingredundant information avaQ.able totheControlSystem.+cpossibility ofcommon-mode failurecannotbecompletely ruledout;itis<<<<eivable thatallidentical channelsbehaveidentically, butincorrectly.
.""-hiscase,thequestionofControlSystemdependence ontheProtection emisirrelevant.
Ithasbeenrecognized thatlittle,ifany,additional deeree<<<<ofprotection isachievedbyhavingseparate, butidentical, instru-"tchannelsforcontrolandprotection.
Indeed,Westinghouse considers tseparation inthismanneractuallydeprivestheprotection Systemof4.3-3  


eoftheday-Sy&ay, hour-by-hour surveillance giventoinstrument chaelsneededforroutineplantoperation.
e of the day-Sy&ay, hour-by-hour surveillance given to instrument chaels needed for routine plant operation.
Afurther,althoughoftenggnoreddisadvantage ofproliferation ofidentical
A further, although often ggnored disadvantage of proliferation of identical channels, is the attendant increase in visual displays and information processing problems of significant oroportions.(Timely, accurate and complet~Lnformation readout is required by the IEEE criteria previously referenced.)'
: channels, istheattendant increaseinvisualdisplaysandinformation processing problemsofsignificant oroportions.
frequently expressed concern is the need for assurance that the Protection System will not be inadvertently modified during the 40-year life of the plant, This is occasionally cited as an argument against control dependence on Protection System information Westinghouse completely agrees that every precaution must be taken to ensure adequate review of any future modification that could affect the Protection System.Such assurance can only be achieved by complete attention to details in Protection System design, operation and maintenance.
(Timely,accurateandcomplet~Lnformation readoutisrequiredbytheIEEEcriteriapreviously referenced.)'
This must include I identifica'tion of system components on drawings and on tha equipment', documentation of the system design and design basis, and establishment of groups to review all proposed instrument changes that could affect'plant~safety or plant operations.
frequently expressed concernistheneedforassurance thattheProtection Systemwillnotbeinadvertently modifiedduringthe40-yearlifeoftheplant,Thisisoccasionally citedasanargumentagainstcontroldependence onProtection Systeminformation Westinghouse completely agreesthateveryprecaution mustbetakentoensureadequatereviewofanyfuturemodification thatcouldaffecttheProtection System.Suchassurance canonlybeachievedbycompleteattention todetailsinProtection Systemdesign,operation andmaintenance.
It is fallacious to believe that independent control adds to this assurance.
ThismustincludeIidentifica'tion ofsystemcomponents ondrawingsandonthaequipment',
In fact, such independence could decrease the probability that a necessary correction to the Protection System will be Inadequacy of controller design requires correction to allow plant operation to proceed;inadequacy of protection is sometimes discovered only after an incident.4,3 4 Control System modifications may be required to improve plaat operation.
documentation ofthesystemdesignanddesignbasis,andestablishment ofgroupstoreviewallproposedinstrument changesthatcouldaffect'plant~safetyorplantoperations.
por encamp 1 e, a f i 1 ter may have to be added to achieve stabi lity.As a control modification, this would logically be performed in the Control Systm;i-e-7 downstream of the isolation dances separating the Control and Protection Systems.Physical separation and identification of equipment (separate racks for Control aad Protection Systems)and admini-strative precautions ensure that the logical route is, ia fact, the one used.Even advocates of complete independence between control and protection recognize the desirability and feasibility of using protection signals for non-protective functions...his introduces the possibility of thesesignals being diverted for other purposes unless a careful review and adherence to design bases is enforced.The division between control and protection is not always clear.This reflects difficulty in defining the function achieved, rather than in equipment design imnlementatioa.
Itisfallacious tobelievethatindependent controladdstothisassurance.
Definitions that place all reacto'x" trip aad safeguards actuation instrumentation in the Protection System, and all automatic regulating instrumentation in the Control System, clearly leave many important items in between.Another definition advanced'is that the Control System is"all instrumentation which is not protection," and the Protection System is"that instrumentation which must work when needed (to prevent unacceptable consequences)." This latter defiaitioa has considerable merit for general discussions and is useful in Judging whether or not a particular item is a"protection" item or not.However, if taken as a rigid it is difficult to apply to all design details, as is showa below.4.3-5 P z example alarms and/or control room indications derived from protection hannel information are essential if the operator is to be properly and continuingly infoxmed of the Protection System status and the status of plant safety.As px'eviously noted, these alarms and indications aze required by the referenced IEEE criteria as a vital pazt of the Protection System.order to maintain protection channel isolation, Westinghouse equipment design practice associates remote indication with the output of the isolation device.Other functions, such as control interlocks (e.g., rod stops)are often highly desirable, and may even be essential to plant safety if a number of malfunctions or maloperations should occur simultaneously (i.e., beyond the normal design proundrules).
Infact,suchindependence coulddecreasetheprobability thatanecessary correction totheProtection SystemwillbeInadequacy ofcontroller designrequirescorrection toallowplantoperation toproceed;inadequacy ofprotection issometimes discovered onlyafteranincident.
Westinghouse has used the term"supervisory" for that category of functions that.is neither clearly control or protection.(This is a functional I designation only, and does not imply a third category for equipment design.)Supervisory functions can be further subdivided into two types: those that are informative only (indicators, recorders, alarms, and data-logging);
4,34 ControlSystemmodifications mayberequiredtoimproveplaatoperation.
and those which automatically act to arrest deteriorating conditions before protective action is needed.(This latter type has been texmedi"override", or"protective override.".)
porencamp1e,afi1termayhavetobeaddedtoachievestability.Asacontrolmodification, thiswouldlogically beperformed intheControlSystm;i-e-7downstream oftheisolation dancesseparating theControlandProtection Systems.Physicalseparation andidentification ofequipment (separate racksforControlaadProtection Systems)andadmini-strativeprecautions ensurethatthelogicalrouteis,iafact,theoneused.Evenadvocates ofcompleteindependence betweencontrolandprotection recognize thedesirability andfeasibility ofusingprotection signalsfornon-protective functions...his introduces thepossibility ofthesesignals beingdivertedforotherpurposesunlessacarefulreviewandadherence todesignbasesisenforced.
Since the question is one of whether manual or automatic intervention is intended, the value of distinction is limited to failure mode analysis of automatic controllers.
Thedivisionbetweencontrolandprotection isnotalwaysclear.Thisreflectsdifficulty indefiningthefunctionachieved, ratherthaninequipment designimnlementatioa.
4.3 6 N%&A t'9" r.l~r' westinghouse record.zes that each"supervisory" function must be considered on its own merits to determine if it should form part of the protection or the Control System.A complete list of protection, control, and"supervisory" functions is included in the Appendix.4.3-7  
Definitions thatplaceallreacto'x" tripaadsafeguards actuation instrumentation intheProtection System,andallautomatic regulating instrumentation intheControlSystem,clearlyleavemanyimportant itemsinbetween.Anotherdefinition advanced'is thattheControlSystemis"allinstrumentation whichisnotprotection,"
~+m 8 w4':'l n 1' PROTECTION
andtheProtection Systemis"thatinstrumentation whichmustworkwhenneeded(topreventunacceptable consequences)."
~axWEL PROTECTION CHANNEL 2 PROTECTION CHANNEL 3 PROTECTION CHANNEL 4 PT i PQ~~~PC'~HI P R.T.t PC~LO P R.T.I I ISOL'.~~PC~HIP'.T.PC'OP~ISOL QPT" PQ PC'~HI P R.T.)PC LO P SOL gPT PgQ PC LO P R.T.SOL I r I L PRESSURE CONTROL SYST~I I I I I PRESSURE CONTROL SYSTEH (INCLUDES SIGNAL CONDITION-ING AND CONTROLLERS AND INTERLOCKS FOR HEATERS, SPRAYAND RELIEF VALVES)PT-PRESSURE TRANSHITTER PQ-POWER SUPPLY PC-CONTROLLER ISOL-ISOLATION AHP HI (LO)R.T.-HIGH (LOW)PRESSURE REACTOR TRIP PROTECTION SYSTEM COMPONENTS CONTROL SYSTEM CMPONENTS INDICATORS, AND RECORDERS ARE NOT SHOWN PRESSURIZER PRESSURE PROTECTION AND CONTROL SYSTEMS DESIGN FIGURE 4.3-1 th(O P'I 4 A4'g~
Thislatterdefiaitioa hasconsiderable meritforgeneraldiscussions andisusefulinJudgingwhetherornotaparticular itemisa"protection" itemornot.However,iftakenasarigiditisdifficult toapplytoalldesigndetails,asisshowabelow.4.3-5 Pzexamplealarmsand/orcontrolroomindications derivedfromprotection hannelinformation areessential iftheoperatoristobeproperlyandcontinuingly infoxmedoftheProtection Systemstatusandthestatusofplantsafety.Aspx'eviously noted,thesealarmsandindications azerequiredbythereferenced IEEEcriteriaasavitalpaztoftheProtection System.ordertomaintainprotection channelisolation, Westinghouse equipment designpracticeassociates remoteindication withtheoutputoftheisolation device.Otherfunctions, suchascontrolinterlocks (e.g.,rodstops)areoftenhighlydesirable, andmayevenbeessential toplantsafetyifanumberofmalfunctions ormaloperations shouldoccursimultaneously (i.e.,beyondthenormaldesignproundrules).
SPECIFIC CONTROL AND PROTECTION INTERACTIONS design basis for the Control and Protection System permits the use of fox both protection and control functions-Where this is done,>l equipment common to both the protection and control functions are classified as part of the Protection System.Isolation amplifiers prevent.a Control System failure from affecting the Protection System.In addition, Mhere failure of a Protection System component can cause a process excursion which requires protective action, the Pxotection System can withstand another, independent failure without loss of function.Generally, this is accomplished vith two-out-of-four trip logic.Also, wherever practical, provisions are included in the Control or Protection System to prevent a plant outage because of single failure of a sensor.The following discussion of specific control and protection interactions t is based on the design for the Robert Emmett Ginna Nuclear Station of the Rochester Gas and Electric Co.(RGE)-It is xepresentative of current Westinghouse design-practice.
Westinghouse hasusedtheterm"supervisory" forthatcategoryoffunctions that.isneitherclearlycontrolorprotection.
4.4.l NUCLEAR FLUX Four powex range nuclear flux channels are pxovided for overpower protection.
(Thisisafunctional Idesignation only,anddoesnotimplyathirdcategoryforequipment design.)Supervisory functions canbefurthersubdivided intotwotypes:thosethatareinformative only(indicators, recorders, alarms,anddata-logging);
so~<<ed outputs from all four channels are averaged for automatic control<od regulation of power.If any channel fails in such a way as to pxoduce~ow output, that channel is incapable of proper overpower protection-In p inciple, the same failure could cause rod withdrawal and overpower.
andthosewhichautomatically acttoarrestdeteriorating conditions beforeprotective actionisneeded.(Thislattertypehasbeentexmedi"override",
Two-"t<<-four overpower trip logic insures an overpower trip if needed, even"ith an independent failure in anothex channel.4'>>l ddition" the Contxol System responds only to rapid changes in indicated f1~.slow changes or drifts are overridden by the temperature control nuclear t i al.Also a rapid decrease of any nuclear f1~sig 1 block autistic xo w d withdrawal as part of the rod drop protection circuitry.
or"protective override.".)
Finally, an overpower signal from any nuclear channel blocks automatic rod withdrawal.
Sincethequestionisoneofwhethermanualorautomatic intervention isintended, thevalueofdistinction islimitedtofailuremodeanalysisofautomatic controllers.
The setpoint for this rod stop is below the xeactor txip setpoint.4.4.2 COOLANT TEMPERATURE Four temperature channels, each containing a Tavg and a 4T signal, are used for overtemperature-overpower protection.
4.36 N%&At'9"r.l~r' westinghouse record.zes thateach"supervisory" functionmustbeconsidered onitsownmeritstodetermine ifitshouldformpartoftheprotection ortheControlSystem.Acompletelistofprotection, control,and"supervisory" functions isincludedintheAppendix.
Isolated outputs from all four T signals are, also averaged for automatic.
4.3-7  
control rod regulation of avg power and temperature.
~+m8w4':'ln1' PROTECTION
In principal, a spuriously low T signal from one.sensor would partially defeat this protection function and also cause rod withdrawal and overtemperature.
~axWELPROTECTION CHANNEL2PROTECTION CHANNEL3PROTECTION CHANNEL4PTiPQ~~~PC'~HIPR.T.tPC~LOPR.T.IIISOL'.~~PC~HIP'.T.PC'OP~ISOLQPT"PQPC'~HIPR.T.)PCLOPSOLgPTPgQPCLOPR.T.SOLIrILPRESSURECONTROLSYST~IIIIIPRESSURECONTROLSYSTEH(INCLUDES SIGNALCONDITION-INGANDCONTROLLERS ANDINTERLOCKS FORHEATERS,SPRAYAND RELIEFVALVES)PT-PRESSURETRANSHITTER PQ-POWERSUPPLYPC-CONTROLLER ISOL-ISOLATION AHPHI(LO)R.T.-HIGH(LOW)PRESSUREREACTORTRIPPROTECTION SYSTEMCOMPONENTS CONTROLSYSTEMCMPONENTS INDICATORS, ANDRECORDERS ARENOTSHOWNPRESSURIZER PRESSUREPROTECTION ANDCONTROLSYSTEMSDESIGNFIGURE4.3-1 th(OP'I4A4'g~
Twomut-of-four trip logic is used to insure that an overtemperature trip occurs, if needed, even with an indepen-dent failure in another channel.In addition, channel deviation alarms in the Control System block automatic<<d motion (insertion or withdrawal) if any Tav signal devtates significant3.y from the others.Automatic rod withdrawal blocks also occur if any on~f-<<ur nuclear channels indicates an overpower condition or if any oneof-four temperature channels indicates an overtemperature or overpower condition.
SPECIFICCONTROLANDPROTECTION INTERACTIONS designbasisfortheControlandProtection Systempermitstheuseoffoxbothprotection andcontrolfunctions-Wherethisisdone,>lequipment commontoboththeprotection andcontrolfunctions areclassified aspartoftheProtection System.Isolation amplifiers prevent.aControlSystemfailurefromaffecting theProtection System.Inaddition, MherefailureofaProtection Systemcomponent cancauseaprocessexcursion whichrequiresprotective action,thePxotection Systemcanwithstand another,independent failurewithoutlossoffunction.
Finally, as shown in Section 14.3..2, of the RG&E Final Safety'Analysis Report, th<<ombination of trips on nuclear overpower, high pressurizer water level, nd high pressurizer pressure also serve to limit an excursion for any rate f reactivity insex'tion.
Generally, thisisaccomplished vithtwo-out-of-four triplogic.Also,whereverpractical, provisions areincludedintheControlorProtection Systemtopreventaplantoutagebecauseofsinglefailureofasensor.Thefollowing discussion ofspecificcontrolandprotection interactions tisbasedonthedesignfortheRobertEmmettGinnaNuclearStationoftheRochester GasandElectricCo.(RGE)-Itisxepresentative ofcurrentWestinghouse design-practice.
4.4-2 PRESSURIZER PRESSURE pressure channels are used for high and Low pressure protection and F for overpower-overtemperature protect i on.Isolated output signals f rom these channels also are used for pressure control and compensation signals for rod control.These are discussed separately below.Control of Rod Motion one of the pressure channels is used for rod control with a low pressure signal acting to withdraw rods.The discussion for coolant temperature is applicable; i.e., twowutwf-four logic for overpower-overtemperature protection as the primary protection, with backup from multiple rod stops and"backup" trip circuits.In addition, the pressure compensation signal is, Limited in the Control System such that failure of the pressure signa1 cannot cause more than about a LO'F change in T.This change can be avg accommodated at full power without a DNBR less.than L.30.t Finally, the pressurizer safety valves are adequately sized.to prevent system overpressure.
4.4.lNUCLEARFLUXFourpowexrangenuclearfluxchannelsarepxovidedforoverpower protection.
Pressure Control Low Pressure A spurious high pressure signal from one channel can cause low pressure by spurious actuation of spray and/or a relief valve.Additional redundancy is provided in the Protection System to insure underpressure protection;
so~<<edoutputsfromallfourchannelsareaveragedforautomatic control<odregulation ofpower.Ifanychannelfailsinsuchawayastopxoduce~owoutput,thatchannelisincapable ofproperoverpower protection-Inpinciple,thesamefailurecouldcauserodwithdrawal andoverpower.
<.e., two~ut~f-four low pressure reactor trip logic and one-out~f-three Logic for safety in)ection.(Safety in]ection is actuated on one-outmf-three coincident Low pressure and low leve1 signals.)4.4-3  
Two-"t<<-fouroverpower triplogicinsuresanoverpower tripifneeded,even"ithanindependent failureinanothexchannel.4'>>l ddition"theContxolSystemrespondsonlytorapidchangesinindicated f1~.slowchangesordriftsareoverridden bythetemperature controlnucleartial.Alsoarapiddecreaseofanynuclearf1~sig1blockautisticxowdwithdrawal aspartoftheroddropprotection circuitry.
Finally,anoverpower signalfromanynuclearchannelblocksautomatic rodwithdrawal.
Thesetpointforthisrodstopisbelowthexeactortxipsetpoint.
4.4.2COOLANTTEMPERATURE Fourtemperature
: channels, eachcontaining aTavganda4Tsignal,areusedforovertemperature-overpower protection.
IsolatedoutputsfromallfourTsignalsare,alsoaveragedforautomatic.
controlrodregulation ofavgpowerandtemperature.
Inprincipal, aspuriously lowTsignalfromone.sensorwouldpartially defeatthisprotection functionandalsocauserodwithdrawal andovertemperature.
Twomut-of-four triplogicisusedtoinsurethatanovertemperature tripoccurs,ifneeded,evenwithanindepen-dentfailureinanotherchannel.Inaddition, channeldeviation alarmsintheControlSystemblockautomatic
<<dmotion(insertion orwithdrawal) ifanyTavsignaldevtatessignificant3.y fromtheothers.Automatic rodwithdrawal blocksalsooccurifanyon~f-<<urnuclearchannelsindicates anoverpower condition orifanyoneof-four temperature channelsindicates anovertemperature oroverpower condition.
Finally,asshowninSection14.3..2,oftheRG&EFinalSafety'Analysis Report,th<<ombination oftripsonnuclearoverpower, highpressurizer waterlevel,ndhighpressurizer pressurealsoservetolimitanexcursion foranyratefreactivity insex'tion.
4.4-2 PRESSURIZER PRESSUREpressurechannelsareusedforhighandLowpressureprotection andFforoverpower-overtemperature protection.Isolatedoutputsignalsfromthesechannelsalsoareusedforpressurecontrolandcompensation signalsforrodcontrol.Thesearediscussed separately below.ControlofRodMotiononeofthepressurechannelsisusedforrodcontrolwithalowpressuresignalactingtowithdrawrods.Thediscussion forcoolanttemperature isapplicable; i.e.,twowutwf-four logicforoverpower-overtemperature protection astheprimaryprotection, withbackupfrommultiplerodstopsand"backup"tripcircuits.
Inaddition, thepressurecompensation signalis,LimitedintheControlSystemsuchthatfailureofthepressuresigna1cannotcausemorethanaboutaLO'FchangeinT.Thischangecanbeavgaccommodated atfullpowerwithoutaDNBRless.thanL.30.tFinally,thepressurizer safetyvalvesareadequately sized.topreventsystemoverpressure.
PressureControlLowPressureAspurioushighpressuresignalfromonechannelcancauselowpressurebyspuriousactuation ofsprayand/orareliefvalve.Additional redundancy isprovidedintheProtection Systemtoinsureunderpressure protection;
<.e.,two~ut~f-four lowpressurereactortriplogicandone-out~f-three Logicforsafetyin)ection.
(Safetyin]ection isactuatedonone-outmf-threecoincident Lowpressureandlowleve1signals.)
4.4-3  


0addition, iterloclareProvidedinthPressureCtolSystemsuch~tarelief.valveclosesifeitheroftwoindependent pressurechannelsidicateslowpressure.
0 addition, i terlocl are Provided in th Pressure C t ol System such~t a relief.valve closes if either of two independent pressure channels i dicates low pressure.Spray reduces pressure at a lower rate, and some ti e is avaiLable for ooerator action (about three minutes at mmchnna spray-ate before a low pressure trip is required.)
Sprayreducespressureatalowerrate,andsometieisavaiLable forooeratoraction(aboutthreeminutesatmmchnnaspray-atebeforealowpressuretripisrequired.)
The pressurizer heaters are incapable of overpressurizing the Reactor Coolant System.Maxinnm steam generation rate with heaters is about 7500 lbs/hr., compared with a total capacity of 576,000 Lbs/hr., for the two safety valves and a total capacity of 179,000 lbs/hr., for the two power-operated relief valves.Therefore, overpressure protection is not required for a pressure controL failure.Twomutmf-three high pressure trip Logic is used.Xn addition, either of the two relief valves can.easily maintain pressure below the high pressure trip point.The two relief valves are controlled by independent pressure channels, one of which is independent of the pressure channel used for heater contxol.Anally, the rate of pressure rise achievable with heaters is slow, and ample time and pressure alarms are available for operator action.4.4.4 PRESSURIZER LEVEL Three pressurizer level channels are used for high level reactor trip (2/3)and low level safety infection (1/3 logic level coincident with" Pressure).
Thepressurizer heatersareincapable ofoverpressurizing theReactorCoolantSystem.Maxinnmsteamgeneration ratewithheatersisabout7500lbs/hr.,comparedwithatotalcapacityof576,000Lbs/hr.,forthetwosafetyvalvesandatotalcapacityof179,000lbs/hr.,forthetwopower-operated reliefvalves.Therefore, overpressure protection isnotrequiredforapressurecontroLfailure.Twomutmf-three highpressuretripLogicisused.Xnaddition, eitherofthetworeliefvalvescan.easilymaintainpressurebelowthehighpressuretrippoint.Thetworeliefvalvesarecontrolled byindependent pressurechannels, oneofwhichisindependent ofthepressurechannelusedforheatercontxol.Anally,therateofpressureriseachievable withheatersisslow,andampletimeandpressurealarmsareavailable foroperatoraction.4.4.4PRESSURIZER LEVELThreepressurizer levelchannelsareusedforhighlevelreactortrip(2/3)andlowlevelsafetyinfection (1/3logiclevelcoincident with"Pressure).
Isolated output signals from these channeLs are used for volume control, increasing or decreasing water level.A level control 4.4-4  
IsolatedoutputsignalsfromthesechanneLsareusedforvolumecontrol,increasing ordecreasing waterlevel.Alevelcontrol4.4-4  
'E l
'El
;ailure could fill or empty the pressurizer at a sLow rate (on the order OE f half an hour or more).Irggh 18V81~reactor trip on pressurizer high level is provided to prevent rapid 4 thermaL expansions of reactor coolant fluid from fiLLing the pressurizer; the rapid change from high rates of steam relief to water relief can be damaging to the safety valves and the reLief piping and pressure relief tank.However, a Level control failure cannot actuate the safety valves because the high pressure reactor trip is set belo~the safety vaLve set pressure.With the slow rate of charging available, overshoot in pressure before the trip is effective is much less than the difference between reactor trip and safety valve set pressures.
;ailurecouldfilloremptythepressurizer atasLowrate(ontheorderOEfhalfanhourormore).Irggh18V81~reactortriponpressurizer highlevelisprovidedtopreventrapid4thermaLexpansions ofreactorcoolantfluidfromfiLLingthepressurizer; therapidchangefromhighratesofsteamrelieftowaterreliefcanbedamagingtothesafetyvalvesandthereLiefpipingandpressurerelieftank.However,aLevelcontrolfailurecannotactuatethesafetyvalvesbecausethehighpressurereactortripissetbelo~thesafetyvaLvesetpressure.
Therefore, a control failure does not require Protection System action.Tn addition, ample time and.alarms are available for operator action.Law Level For control failures which tend to empty the pressurizer, one-out-of-three Logic for safety infection actuation on Low Level insuresithat the Protection Sy<<em can withstand an independent failure in another channel.<n additon, a signaL of low level from either of two independent level control channels isolates Letdown, thus preventing the loss of coolant.ampule time and alarms exist for operator action.4.4-$
Withtheslowrateofchargingavailable, overshoot inpressurebeforethetripiseffective ismuchlessthanthedifference betweenreactortripandsafetyvalvesetpressures.
gTEQf GENERATOR WATER LEVEL PESWATER PLOW before describing control and protection interaction for these channels, it is beneficial to review the Protection System basis for this instru-mentation The system is shown schematically in Pigux'e 4.4-L..The basic function of the reactor protection circuits associated with Low steam generator water level and low feedwater flow is to preserve the steam generator heat sink for removal of long term residuaL heat.Should a complete loss of feedwater occur with no protective action, P the steam generators would boil dry and cause an overtemperatur~verpressure excursion in the reactor coolant.Reactor trips on'emperature, pressure, and pressuri.e'er water level trip the plant before there is any damage to the core or Reactor Coolant System.However, residuaL heat after trip causes thermal expansion and discharge of the xeactor coolant to containment through the pressurizer relief valves.This would bxeach one of the barriers-.the Reactor CooLant System to release of fission products.Redundant emergency feedwater pumps are provided to prevent this.Reactor trips act before the steam generators are dry to xeduce the required capacity and starting time requirements of these pumps and to minimize the thermaL transient on the Reactor Coolant System and steam generators.
Therefore, acontrolfailuredoesnotrequireProtection Systemaction.Tnaddition, ampletimeand.alarmsareavailable foroperatoraction.LawLevelForcontrolfailureswhichtendtoemptythepressurizer, one-out-of-three Logicforsafetyinfection actuation onLowLevelinsuresithat theProtection Sy<<emcanwithstand anindependent failureinanotherchannel.<nadditon,asignaLoflowlevelfromeitheroftwoindependent levelcontrolchannelsisolatesLetdown,thuspreventing thelossofcoolant.ampuletimeandalarmsexistforoperatoraction.4.4-$
Xndependent tx'ip circuits are provided fox the two steam generators for the following reasons: a)Should severe mechanicaL damage occur to the feedwatsx'in'e to one s~eam generator, it is difficult to insure the functional integrity of level and flow instrumentation for that-unit.Por instance, a 4-4-6.
gTEQfGENERATOR WATERLEVELPESWATERPLOWbeforedescribing controlandprotection interaction forthesechannels, itisbeneficial toreviewtheProtection Systembasisforthisinstru-mentation Thesystemisshownschematically inPigux'e4.4-L..Thebasicfunctionofthereactorprotection circuitsassociated withLowsteamgenerator waterlevelandlowfeedwater flowistopreservethesteamgenerator heatsinkforremovaloflongtermresiduaLheat.Shouldacompletelossoffeedwater occurwithnoprotective action,Pthesteamgenerators wouldboildryandcauseanovertemperatur~verpressure excursion inthereactorcoolant.Reactortripson'emperature,
r~c-'c.'(l\1 I pipe break between the f eedwater f low element and the steam os]or p pe generator exator would cause high flow through the flow element.The rapid xessurization of the steam generator would drastically affect the depxessu ac elation between downcomer water level and steam generator water inven-However, the independent circuits on the second steam generator~e sufficient to actuate a reactor trip if needed.~j gt~r desirable to miabaize thermal transients on a steam generator for credible loss of feedwater accidents.
: pressure, andpressuri.e'er waterleveltriptheplantbeforethereisanydamagetothecoreorReactorCoolantSystem.However,residuaLheataftertripcausesthermalexpansion anddischarge ofthexeactorcoolanttocontainment throughthepressurizer reliefvalves.Thiswouldbxeachoneofthebarriers-.theReactorCooLantSystemtoreleaseoffissionproducts.
Coatxoller malfunctions caused by a Protection System failure affect only aoe steam genexator.
Redundant emergency feedwater pumpsareprovidedtopreventthis.Reactortripsactbeforethesteamgenerators aredrytoxeducetherequiredcapacityandstartingtimerequirements ofthesepumpsandtominimizethethermaLtransient ontheReactorCoolantSystemandsteamgenerators.
A1so, they do.not impair the capability of the main feedsrater system under either manual control or automatic T control.avg Hence, these failures are far from being the worst case with respect to core decay heat removal with the steam generators.
Xndependent tx'ipcircuitsareprovidedfoxthetwosteamgenerators forthefollowing reasons:a)ShouldseveremechanicaL damageoccurtothefeedwatsx'in'e toones~eamgenerator, itisdifficult toinsurethefunctional integrity oflevelandflowinstrumentation forthat-unit.Porinstance, a4-4-6.
Frectvater Plow*Npu<<ous high signal from, the feedwater flow channel being used for control used cause a reduction in feedwater flow and prevent that channel from~ping.A reactor trip on low-low water level, independeqxt of indicated~<<er.low, insures a xeactor trip, if needed." t<<n.the three-element feedwater controller incorporates reset on~such that with expected gains, a rapid increase in the flow signal~d ca o>>y a 12-inch decrease in level before the controller xe-opened eedwat r valve.A slow increase in the feedwater signal would have no g4C+~~ect 4.4 7 CC 88K spurious low steam f low signal would have the same effect as a high ceedwater signal, discussed above.~r A spurious high water level signa1 from the protection channel used for cont ol tends to close the feedwater valve.This level channel is inde F Pendent of the level and flow channels used for reactor trip on low flow coincident with low level.a)A rapid increase in the level signal completely stops fee@rater flow and actuates a reactor trip on low feedwater flow coincident with low level.b)A slow drift in the level signal may not actuate a low feedwater signal.Since the level decrease is slow, the operator has time to respond to low level alarms.Since only one steam generator is affected, automatic protection is not mandatory and reactor trip..on two-out~f-three low-low level is acceptable.
r~c-'c.'(l\1I pipebreakbetweenthefeedwaterflowelementandthesteamos]orppegenerator exatorwouldcausehighflowthroughtheflowelement.Therapidxessurization ofthesteamgenerator woulddrastically affectthedepxessuacelationbetweendowncomer waterlevelandsteamgenerator waterinven-However,theindependent circuitsonthesecondsteamgenerator
4-4.6 STEAN LINE PRESSURE~<<three pressure channels per steam line are used for steam break Protection (twomutmf-three low pressure signals for any steam line actuates saf Bty in]ectj.on)
~esufficient toactuateareactortripifneeded.~jgt~rdesirable tomiabaizethermaltransients onasteamgenerator forcrediblelossoffeedwater accidents.
.One of these channels is used to control the Powermperated relief valve on that steam line.These valves.are typically t<<at 10K of the safety valve capacity A spurious high pressure signal C>>he channel used for control opens the re1ief valve and causes low~ure~This is a slow rate of steam release, evaluated as a credible 4.4-8 break in Section 14.2.5 of the RG&E Final Safety Analysis Report.~the analysis of steam breaks of this size, no credit is taken for the te~line pressure instrumentation-Safety injection is actuated by the oressurizer instrumentation.
Coatxoller malfunctions causedbyaProtection Systemfailureaffectonlyaoesteamgenexator.
Therefore, a control faire does not create for this protection, and two-out-of-three logic is acceptable.
A1so,theydo.notimpairthecapability ofthemainfeedsrater systemundereithermanualcontrolorautomatic Tcontrol.avgHence,thesefailuresarefarfrombeingtheworstcasewithrespecttocoredecayheatremovalwiththesteamgenerators.
Frectvater Plow*Npu<<oushighsignalfrom,thefeedwater flowchannelbeingusedforcontrolusedcauseareduction infeedwater flowandpreventthatchannelfrom~ping.Areactortriponlow-lowwaterlevel,independeqxt ofindicated
~<<er.low,insuresaxeactortrip,ifneeded."t<<n.thethree-element feedwater controller incorporates reseton~suchthatwithexpectedgains,arapidincreaseintheflowsignal~dcao>>ya12-inchdecreaseinlevelbeforethecontroller xe-opened eedwatrvalve.Aslowincreaseinthefeedwater signalwouldhavenog4C+~~ect4.47 CC88Kspuriouslowsteamflowsignalwouldhavethesameeffectasahighceedwater signal,discussed above.~rAspurioushighwaterlevelsigna1fromtheprotection channelusedforcontoltendstoclosethefeedwater valve.ThislevelchannelisindeFPendentofthelevelandflowchannelsusedforreactortriponlowflowcoincident withlowlevel.a)Arapidincreaseinthelevelsignalcompletely stopsfee@rater flowandactuatesareactortriponlowfeedwater flowcoincident withlowlevel.b)Aslowdriftinthelevelsignalmaynotactuatealowfeedwater signal.Sincetheleveldecreaseisslow,theoperatorhastimetorespondtolowlevelalarms.Sinceonlyonesteamgenerator isaffected, automatic protection isnotmandatory andreactortrip..ontwo-out~f-threelow-lowlevelisacceptable.
4-4.6STEANLINEPRESSURE~<<threepressurechannelspersteamlineareusedforsteambreakProtection (twomutmf-three lowpressuresignalsforanysteamlineactuatessafBtyin]ectj.on)
.OneofthesechannelsisusedtocontrolthePowermperated reliefvalveonthatsteamline.Thesevalves.aretypically t<<at10KofthesafetyvalvecapacityAspurioushighpressuresignalC>>hechannelusedforcontrolopensthere1iefvalveandcauseslow~ure~Thisisaslowrateofsteamrelease,evaluated asacredible4.4-8 breakinSection14.2.5oftheRG&EFinalSafetyAnalysisReport.~theanalysisofsteambreaksofthissize,nocreditistakenforthete~linepressureinstrumentation-Safetyinjection isactuatedbytheoressurizer instrumentation.
Therefore, acontrolfairedoesnotcreateforthisprotection, andtwo-out-of-three logicisacceptable.
4'g  
4'g  


~~~ATIONe~DEWALACCT~Syst'~evaluation oftherodwithdrawal accidentisbasedSystemparameters, protection system,andexpectedreactivity
~~~ATION e~DEWAL ACCT~Syst'~evaluation of the rod withdrawal accident is based System parameters, protection system, and expected reactivity
?ThedesignbasisfortheReactorProtection Systemto~tt~ts-carefarrodwithdrawal accidents istotripthereactorygececi30DNBRisreachedinthehotchannel.Whilediversity intrumentation isnotapartafthedesignbasis,thesystem~~idleddoesprovidealarms,rodstopsandcontrolfunctions to~~t>evithdrawal fromproceeding tothetrippoint.Becauseof~~teffectofoverpower onalltheprocessvariables, additional
?The design basis for the Reactor Protection System to~tt~ts-care far rod withdrawal accidents is to trip the reactor ygececi 30 DNBR is reached in the hot channel.While diversity in trumentation is not a part af the design basis, the system~~idled does provide alarms, rod stops and control functions to~~t>e vithdrawal from proceeding to the trip point.Because of~~t effect of overpower on all the process variables, additional
~!unct~<aswouldacttoterminate theexcursion, butaot'necessarily
~!unct~<as would act to terminate the excursion, but aot'necessarily
~el.30.Extending thecourseoftheaccident, aDNBRof1.0inthe.~+seeably" isarbitrarily selectedasaUmitfora.secondLevelofycecectian.
~e l.30.Extending the course of the accident, a DNBR of 1.0 in the.~+seeably" is arbitrarily selected as a Umit for a.second Level of ycecectian.(The"hot assembly" is essentia1ly the hot channel without a?Xueaaca for engineering hot channel factors.)No credit.'is taken for~!~ttening or Local,'void reactivity effects at overpower conditions.
(The"hotassembly" isessentia1ly thehotchannelwithouta?Xueaaca forengineering hotchannelfactors.)
~est pess&istic instrument error.and'set points are assumed for aLl I tea:tar wips.~iced averpawer is of serious concern because of the potential damage to De core d the Reactor Coolant System.Syst by either the high pressure reactor trip~sea M con)unction with any reactor~p at'ater lev ity for core damage+n Wta evalua uatian is zocused on this cance~'.L-L  
Nocredit.'is takenfor~!~ttening orLocal,'void reactivity effectsatoverpower conditions.
~estpess&istic instrument error.and'set pointsareassumedforaLlItea:tarwips.~icedaverpawer isofseriousconcernbecauseofthepotential damagetoDecoredtheReactorCoolantSystem.Systbyeitherthehighpressurereactortrip~seaMcon)unction withanyreactor~pat'aterlevityforcoredamage+nWtaevaluauatianiszocusedonthiscance~'.L-L  


'~sprottectionagainsttherodwithdrawal leadingtoundesirable conse-quencessisinconsiderable depth,andthereareindeedmultiplelevelsofPratefro'rection aslistedbelow.Eachoftheselevelscouldbeindependently
'~s prot tection against the rod withdrawal leading to undesirable conse-quences s is in considerable depth, and there are indeed multiple levels of Prate f ro'rection as listed below.Each of these levels could be independently
~ideredadequate, diverseprotection againstanaccident.
~idered adequate, diverse protection against an accident.Because the reactivity available by rod withdrawal is limited, only very rare cases could complete rod withdrawal cause core damage.A single trip function with redundant channels protects against this condition.
Becausethereactivity available byrodwithdrawal islimited,onlyveryrarecasescouldcompleterodwithdrawal causecoredamage.Asingletripfunctionwithredundant channelsprotectsagainstthiscondition.
No diversity or separation is required.b)~u1tiple, diverse rod stops are provided such that no failure can cause a sustained automatic rod withdrawal.
Nodiversity orseparation isrequired.
Therefore, a reactor trip could be considered as backup protecti.on.
b)~u1tiple, diverserodstopsareprovidedsuchthatnofailurecancauseasustained automatic rodwithdrawal.
c)For"fast" excursions, two reactor trip functions prevent all but limited core damage.For"slow" excursions, manual action is an adequate backup to the automatic protection system.4)For all rod withdrawal accidents, ae least two reactor trip functions exist, either of which would again prevent all but limited core damage.Fault tree diagrams are shown on Figure 5.1-1 and 5 3.-2.5'l.l.PROBABLE CONSEQUENCES OP ACCIDENT The adequacy, or depth, of protection required for an accident should be measured against the probability of the accident and the probable consequences of the unprotected accident.The probable consequences are discussed here.The od tivity available is in (alize burnup mai,ntain e 5.1-2 s A distribution, and reduce ejected rod worths).The design allowance~er d st ro d insertion at full power is 0.1X for"bite" plus 0.4X for the man-euver g i.e., rod insertion may be anywhere from O.IX to 0.5X.~izh calculated values for moderator and power coefficients at beginning f core lif e*, 0.3X reactivity insertion is required to reach a hot assembly gggR p f 1.0.Also, af ter 20X core burnup, 0.5X insertion does not cause a hot assembly DNBR less than 1.0-Therefore, a random, complete rod withdrawal from design full power conditions with no protection has about probability of causing, DNBR less than 1.0.This is illustrated by Figure 5.1.3.Although the figure and the above discussion are based on full power, they are equally applicable to accidents starting from less than full power since the additional inserted rod worth is needed to achieve full power.However, it may not be practical to guarantee these conditions because allowances for calculation or measurement uncertainties can significantly affect the results..Figures 5-1-4.and 5.1.5 shows a"worst case" complete rod withdrawal at 25X.of cox'eI life from 102X power, nondnal T plus 4 F, and nominal pressure less avg 30 psi.Reactivity insertion is assumed to be 0.6X, or 0.5X x 1.2.(This 20X uncertainty could have been applied, to the reactivity coefficients-instead of the rod worth.)M~aum hot assembly DNBR is 0.91, or slightly less than the axbitrary limit of 1.0.The same transient at 6(X of core knife is shown fox comparison.
Therefore, areactortripcouldbeconsidered asbackupprotecti.on.
MfxdnnmL hot assembly DNBR is 1.4&.*R activity coef f icients based on Figures 3 Z.1-8 and 3.2.1 10 in Supplement 4 to the RGE PSAR, dated October 23, 1968.5.1-3  
c)For"fast"excursions, tworeactortripfunctions preventallbutlimitedcoredamage.For"slow"excursions, manualactionisanadequatebackuptotheautomatic protection system.4)Forallrodwithdrawal accidents, aeleasttworeactortripfunctions exist,eitherofwhichwouldagainpreventallbutlimitedcoredamage.FaulttreediagramsareshownonFigure5.1-1and53.-2.5'l.l.PROBABLECONSEQUENCES OPACCIDENTTheadequacy, ordepth,ofprotection requiredforanaccidentshouldbemeasuredagainsttheprobability oftheaccidentandtheprobableconsequences oftheunprotected accident.
'I'5.J I C 1 lete analysis, considering statistical variations in all uncertainties, A comp~d determine a more valid value or the probability of exceeding any vould liven sa s sf sty limit If this value were suf f iciently small, a comparatively
Theprobableconsequences arediscussed here.Theodtivityavailable isin(alizeburnupmai,ntain e5.1-2 sA distribution, andreduceejectedrodworths).Thedesignallowance
~a~i<<protection system might be justified.
~erdstrodinsertion atfullpoweris0.1Xfor"bite"plus0.4Xfortheman-euvergi.e.,rodinsertion maybeanywherefromO.IXto0.5X.~izhcalculated valuesformoderator andpowercoefficients atbeginning fcorelife*,0.3Xreactivity insertion isrequiredtoreachahotassemblygggRpf1.0.Also,after20Xcoreburnup,0.5Xinsertion doesnotcauseahotassemblyDNBRlessthan1.0-Therefore, arandom,completerodwithdrawal fromdesignfullpowerconditions withnoprotection hasaboutprobability ofcausing,DNBRlessthan1.0.Thisisillustrated byFigure5.1.3.Althoughthefigureandtheabovediscussion arebasedonfullpower,theyareequallyapplicable toaccidents startingfromlessthanfullpowersincetheadditional insertedrodworthisneededtoachievefullpower.However,itmaynotbepractical toguarantee theseconditions becauseallowances forcalculation ormeasurement uncertainties cansignificantly affecttheresults..
2 PROEABII,ITY OF ACCZDENT~e design intent of the Reactor Control System is to block automatic~d withdrawal for any failure which can cause sustained rod withdrawaL.
Figures5-1-4.and5.1.5showsa"worstcase"completerodwithdrawal at25X.ofcox'eIlifefrom102Xpower,nondnalTplus4F,andnominalpressurelessavg30psi.Reactivity insertion isassumedtobe0.6X,or0.5Xx1.2.(This20Xuncertainty couldhavebeenapplied,tothereactivity coefficients-insteadoftherodworth.)M~aumhotassemblyDNBRis0.91,orslightlylessthantheaxbitrary limitof1.0.Thesametransient at6(Xofcoreknifeisshownfoxcomparison.
~is is accomplished by rod stops on rapid nuclear flux decrease, T avg channel deviation, spurious rod motion, and subsequent rod stops on high AT or high flux.If rod stops were considered as independent protection, Protection System criteria would be applied.These rod stops would then be classified fuLLy as part of the Protection System for a rod withdrawal accident.5.l.3 MANUAL INTERVENTXON
MfxdnnmLhotassemblyDNBRis1.4&.*RactivitycoefficientsbasedonFigures3Z.1-8and3.2.110inSupplement 4totheRGEPSAR,datedOctober23,1968.5.1-3  
!annual action is reliable backup to automatic protection provided that sufficient time exists for operator response.The time required depends n the alarms available, the nature of the problem, and the required action.igure 5.1-6 illustrates steadymtate core limits and several alarm points nd trip points.Alarms are intentionally quite close to the design operating conditions.
'I'5.JIC1 leteanalysis, considering statistical variations inalluncertainties, Acomp~ddetermine amorevalidvalueortheprobability ofexceeding anyvouldlivensassfstylimitIfthisvalueweresufficientlysmall,acomparatively
Other alarms such as high pressure would be reached during a transient.
~a~i<<protection systemmightbejustified.
These alarms are tabulated on Table 5.1-1.~though steam cycle heat removal may be the most Limiting steadymtate rest triction on reactor power, time is required to reach corresponding
2PROEABII,ITY OFACCZDENT~edesignintentoftheReactorControlSystemistoblockautomatic
~arms and trip paints.'(Far instance~it would take about two minutes st 110X reactor Power with steam generator saf ty vaLves blowing before a steam generator Low-low water leveL trip could be expected.)
~dwithdrawal foranyfailurewhichcancausesustained rodwithdrawaL.
For thi reason, this evaluation did not include these alarms and trips Figures 5.1-7 through 5.1-10 show the results of transient analysi far various reactivity insertion rates at beginning of core Life from~full power (102X, nominal T+4'F, noa~pressure less 30 psi avg from nominaL conditions at 80X power.A constant reactivity insertion rate with unlimited available reactivity is assumed.Hmdmea settings end instrument errors are assumed for the reactor trips, and nominaL set points for the alarms.(Note: the high 4T rod stops are taken as 3'F below their reactor trips rather than their nominal set points.)ror a reactivity insertion rate of 0.5 x.10 gk./sec,, (corresponding roughly to maxfxnun rod speed at average rod worth), a hot assembly DER of 1.0 is reached, in about.two minutes.During this time, there are alarms on high T, pressurizer pressure, and pressurizer Level, as well as rod stops and alarms on high flux and high 4T.Also, the steam safety.alves would be actuated.Mith the multiplicity of aLarms, i.t.-is easy to diagnose a ms)or overpower-avertemperature excursion.
~isisaccomplished byrodstopsonrapidnuclearfluxdecrease, Tavgchanneldeviation, spuriousrodmotion,andsubsequent rodstopsonhighATorhighflux.Ifrodstopswereconsidered asindependent protection, Protection Systemcriteriawouldbeapplied.Theserodstopswouldthenbeclassified fuLLyaspartoftheProtection Systemforarodwithdrawal accident.
Xt is reasonable
5.l.3MANUALINTERVENTXON
<<expect operator intervention (manual trip)during this thea For fast ter reactivity insertion rates, reacto<trip on high nuclear flux is a reliable protection system barrier.Therefore, since the avertemperature
!annualactionisreliablebackuptoautomatic protection providedthatsufficient timeexistsforoperatorresponse.
}11 h g 4T trip protects for all excursions, one could classify it as the principal protection barrier with"backup" from high nuclear flux in con-~un<<ian with manual action.5.1-5 DEITY OF REACTOR TRIPS e protection system design basis for the rod withdrawal accident for ore protection required that one trip function with redundant channels preven<event a minimum DNBR less than 1.30.This is accomplished with the<<ertemperature AT trip for slow reactivity excursions, and the high nuclear flux trip for fast excursions.
Thetimerequireddependsnthealarmsavailable, thenatureoftheproblem,andtherequiredaction.igure5.1-6illustrates steadymtate corelimitsandseveralalarmpointsndtrippoints.Alarmsareintentionally quiteclosetothedesignoperating conditions.
As shown by Figures 5.1-7 through 5.1-10, these two trips meet the design basis-The evaluation also shows that for all cases of sustained reactivity insertion for rates up to four times the maximka rate expected from rod withdrawal, any of the following prevent a hot assembly DNBR less than 1.0.a)High nuclear flux reactor trip b)High AT trip l.Overpower AT 2.Overtemperature AT c)High pressurizer level reactor trip plus high pressurizer pressure reactor trip.(Not valid for high reactivity insertion rates:,.from near full power.)This depth of protection cannot be expected for all accidents or for all plants.5.1-6 TABLE 5.1-1 ALARMS FOR ROD WITHDRAWAL
Otheralarmssuchashighpressurewouldbereachedduringatransient.
~arms which would be actuated for a spurious rod withdrawal accident~e eax'r M.l Power are listed below i the aPPro~te order i which they Alarm points assumed for the evaluation are listed.Initiating Fault*-Mose'failures which can cause a spurious control rod withdrawal are alarmed and, in general, automatic moeian prahibited.
Thesealarmsaretabulated onTable5.1-1.~thoughsteamcycleheatremovalmaybethemostLimitingsteadymtate resttrictiononreactorpower,timeisrequiredtoreachcorresponding
These include-a)NXS flux rapid decrease (1/4)(5X in 5 seconds)b)T channel deviation (1/4)p5 F from average)avg c)Rod.control fault-rod motion with no demand Z.Seep Counter-audible clicks from step counter alerts operator eo rad motion.3.NIS PWR RANGE OVERPOWER ROD STOP+(1/4)(105X)4.AVG TAVG-T REF DEV (T 5'F from program)avg 5.PRESSURIZER HX PRESSURE (2350 psia)6.PRESSURIZER RELXEF LXNE HX TEMP (when power-operated relief valves open)7.REACTOR'OOL HX TAVG (1/4)(5'bove nominal T at full power)avg 8.PRESSURXZER LEVEL DEVIATION (5X abave progr:mamed level ae full power)9.AUTO TURBINE RUNBACK OVERPOWER AW (1/4)(3 F less chan high 4T trip paine)AUTO TURBINE RUNBACK OVERTEMP 4M (1/4)(3 F less than high AT trip point)Ll.Steam Generator Relief and Safety Valve Actuation-audible steam release eo atmosphere 12.STEAM GENERATOR LEVEL SET POINT DEVIATION PRESSURIZER SAFETY VALVE OUTLET HX TEMP (2500 psia)CHAHM.'L ALERT-as reactor trip paints are reached for each channel Capitalized word groupings represent engxaving on annunciator panels.REACTOR TRXPS FOR ROD WITHDRAWAL Th<<allowing tx'ip paints were assumed for the evaluation:
~armsandtrippaints.'(Farinstance~
NIS POWER RANGE HIGH RANGE (2/4)(118X)2.OVERPOWER 4T (2/4)(118X of full pawer AT).OVERTEMPERATURE dT (2/4)(variable) 4~PRESSURIZER HX PRESSURE (2/3)(2400 psia)PRESSURXZER HI LEVEL (2/3)(95X of span)Alarm and Rod Stop PAULT TREE fOR ROD NITHDRANAL ACCIDENT AUIONATIC PROTECTION HEEDED INSUFFICIENT TI'lE fOR MANUAL PROTECTION NEEDED EXCESSIVE ROD NORTH INSERTED EARLY IN CORE LIPE SUSTAIllED ROD MITHDRAVAL HIGH TBQ'AT ROD STOt RICH POSER AT RDD STOt CONTINUOUS ROD llITHDRANAL REACTOR IN NANUAL CONIROL AIPIQIATIC CON THOL PAILURE (SEE PICURE 5+1 2)fICURE 5 1~1 w J4 S fltAOLI t~f ISA~~~VII~A441~~IIC C480fl4.tf&I (SRS PICURE$.1-1)PA I LURE CONTINUOUS ROD MITHDRAMAL COND IT1OH OR EVENT RPS~REACTOR PROTECTION STSTIH RCS~REACTOR CONTROI.SIST IHPROPER C1RCUIT IH RCS ROD'NITHDRAMAL SEC IHS 1HDl GATED TISIP ERATURE OD SPEED HTROLLER(RCS)
itwouldtakeabouttwominutesst110XreactorPowerwithsteamgenerator saftyvaLvesblowingbeforeasteamgenerator Low-lowwaterleveLtripcouldbeexpected.)
ROD MITHDRAMAL SEC IHS ALL T VG CHANHE (RtS)Oa THPROPER SET POINTS (RCS)AHD TURS INK LOAD SIC HAL OR tOMER HISHATCH CHAICIFL (RCS)AVG OD STOP ROD MITHDRAMAL SEC INS NIS ROD DROP ROD STOt AVIRAGE TAVG DECREASE INDICATED tRESSURE DECREASE DECREASE IN INDlCATED PLUZ OR NIS (RPS)QQNHEL (RtS)AY%E TAVG RCS RESSURE CHANNEL (RtS)RESSURE CHAHHEI.(RCS)FIGURE 5.1-2 INSERTED ROD WORTH AND REACTIVIXY REQUIRED TO REACH DNBR~1.0 IN HOT ASSEMBLY VERSUS CORE LIFE 1.5~~~-Reactivity Required To Reach Hot Assembly DNBR Of 1.0 (116.5X Power," T~~589, 2250 PSZA)From FuLL Power~~1 0 Region Where Protection Is.Required~I P 0.5 PP Max.Inserted Rod Worth~P'~(Bottom of Maneuvering Band)-': I 0 Min.~erted Rod Worth (Top of Maneuvering Band)-.0 20 40 60 80 100 X OF CORE LIFE FIGURE 5.1-3  
Forthireason,thisevaluation didnotincludethesealarmsandtripsFigures5.1-7through5.1-10showtheresultsoftransient analysifarvariousreactivity insertion ratesatbeginning ofcoreLifefrom~fullpower(102X,nominalT+4'F,noa~pressureless30psiavgfromnominaLconditions at80Xpower.Aconstantreactivity insertion ratewithunlimited available reactivity isassumed.Hmdmeasettingsendinstrument errorsareassumedforthereactortrips,andnominaLsetpointsforthealarms.(Note:thehigh4Trodstopsaretakenas3'Fbelowtheirreactortripsratherthantheirnominalsetpoints.)rorareactivity insertion rateof0.5x.10gk./sec,,
(corresponding roughlytomaxfxnunrodspeedataveragerodworth),ahotassemblyDERof1.0isreached,inabout.twominutes.Duringthistime,therearealarmsonhighT,pressurizer
: pressure, andpressurizer Level,aswellasrodstopsandalarmsonhighfluxandhigh4T.Also,thesteamsafety.alveswouldbeactuated.
Miththemultiplicity ofaLarms,i.t.-iseasytodiagnoseams)oroverpower-avertemperature excursion.
Xtisreasonable
<<expectoperatorintervention (manualtrip)duringthistheaForfastterreactivity insertion rates,reacto<triponhighnuclearfluxisareliableprotection systembarrier.Therefore, sincetheavertemperature
}11hg4Ttripprotectsforallexcursions, onecouldclassifyitastheprincipal protection barrierwith"backup"fromhighnuclearfluxincon-~un<<ianwithmanualaction.5.1-5 DEITYOFREACTORTRIPSeprotection systemdesignbasisfortherodwithdrawal accidentfororeprotection requiredthatonetripfunctionwithredundant channelspreven<eventaminimumDNBRlessthan1.30.Thisisaccomplished withthe<<ertemperature ATtripforslowreactivity excursions, andthehighnuclearfluxtripforfastexcursions.
AsshownbyFigures5.1-7through5.1-10,thesetwotripsmeetthedesignbasis-Theevaluation alsoshowsthatforallcasesofsustained reactivity insertion forratesuptofourtimesthemaximkarateexpectedfromrodwithdrawal, anyofthefollowing preventahotassemblyDNBRlessthan1.0.a)Highnuclearfluxreactortripb)HighATtripl.Overpower AT2.Overtemperature ATc)Highpressurizer levelreactortripplushighpressurizer pressurereactortrip.(Notvalidforhighreactivity insertion rates:,.fromnearfullpower.)Thisdepthofprotection cannotbeexpectedforallaccidents orforallplants.5.1-6 TABLE5.1-1ALARMSFORRODWITHDRAWAL
~armswhichwouldbeactuatedforaspuriousrodwithdrawal accident~eeax'rM.lPowerarelistedbelowitheaPPro~teorderiwhichtheyAlarmpointsassumedfortheevaluation arelisted.Initiating Fault*-Mose'failures whichcancauseaspuriouscontrolrodwithdrawal arealarmedand,ingeneral,automatic moeianprahibited.
Theseinclude-a)NXSfluxrapiddecrease(1/4)(5Xin5seconds)b)Tchanneldeviation (1/4)p5Ffromaverage)avgc)Rod.control fault-rodmotionwithnodemandZ.SeepCounter-audibleclicksfromstepcounteralertsoperatoreoradmotion.3.NISPWRRANGEOVERPOWER RODSTOP+(1/4)(105X)4.AVGTAVG-TREFDEV(T5'Ffromprogram)avg5.PRESSURIZER HXPRESSURE(2350psia)6.PRESSURIZER RELXEFLXNEHXTEMP(whenpower-operated reliefvalvesopen)7.REACTOR'OOL HXTAVG(1/4)(5'bovenominalTatfullpower)avg8.PRESSURXZER LEVELDEVIATION (5Xabaveprogr:mamed levelaefullpower)9.AUTOTURBINERUNBACKOVERPOWER AW(1/4)(3Flesschanhigh4Ttrippaine)AUTOTURBINERUNBACKOVERTEMP4M(1/4)(3FlessthanhighATtrippoint)Ll.SteamGenerator ReliefandSafetyValveActuation
-audiblesteamreleaseeoatmosphere 12.STEAMGENERATOR LEVELSETPOINTDEVIATION PRESSURIZER SAFETYVALVEOUTLETHXTEMP(2500psia)CHAHM.'LALERT-asreactortrippaintsarereachedforeachchannelCapitalized wordgroupings represent engxaving onannunciator panels.REACTORTRXPSFORRODWITHDRAWAL Th<<allowing tx'ippaintswereassumedfortheevaluation:
NISPOWERRANGEHIGHRANGE(2/4)(118X)2.OVERPOWER 4T(2/4)(118XoffullpawerAT).OVERTEMPERATURE dT(2/4)(variable) 4~PRESSURIZER HXPRESSURE(2/3)(2400psia)PRESSURXZER HILEVEL(2/3)(95Xofspan)AlarmandRodStop PAULTTREEfORRODNITHDRANAL ACCIDENTAUIONATIC PROTECTION HEEDEDINSUFFICIENT TI'lEfORMANUALPROTECTION NEEDEDEXCESSIVE RODNORTHINSERTEDEARLYINCORELIPESUSTAIllED RODMITHDRAVAL HIGHTBQ'ATRODSTOtRICHPOSERATRDDSTOtCONTINUOUS RODllITHDRANAL REACTORINNANUALCONIROLAIPIQIATIC CONTHOLPAILURE(SEEPICURE5+12)fICURE51~1 wJ4 SfltAOLIt~fISA~~~VII~A441~~IICC480fl4.tf&I(SRSPICURE$.1-1)PAILURECONTINUOUS RODMITHDRAMAL CONDIT1OHOREVENTRPS~REACTORPROTECTION STSTIHRCS~REACTORCONTROI.SISTIHPROPERC1RCUITIHRCSROD'NITHDRAMAL SECIHS1HDlGATEDTISIPERATUREODSPEEDHTROLLER(RCS)
RODMITHDRAMAL SECIHSALLTVGCHANHE(RtS)OaTHPROPERSETPOINTS(RCS)AHDTURSINKLOADSICHALORtOMERHISHATCHCHAICIFL(RCS)AVGODSTOPRODMITHDRAMAL SECINSNISRODDROPRODSTOtAVIRAGETAVGDECREASEINDICATED tRESSUREDECREASEDECREASEININDlCATED PLUZORNIS(RPS)QQNHEL(RtS)AY%ETAVGRCSRESSURECHANNEL(RtS)RESSURECHAHHEI.(RCS)FIGURE5.1-2 INSERTEDRODWORTHANDREACTIVIXY REQUIREDTOREACHDNBR~1.0INHOTASSEMBLYVERSUSCORELIFE1.5~~~-Reactivity RequiredToReachHotAssemblyDNBROf1.0(116.5XPower,"T~~589,2250PSZA)FromFuLLPower~~10RegionWhereProtection Is.Required~IP0.5PPMax.InsertedRodWorth~P'~(BottomofManeuvering Band)-':I0Min.~ertedRodWorth(TopofManeuvering Band)-.020406080100XOFCORELIFEFIGURE5.1-3  


1a1.0o.50COMPLETERODWITHDRAWAL FROMMAXIMUMFULLPOWERCa/-----MIDDLEOFCORELIFEINITIALRATE~Oa9X106k/SeC.)i~I..I[~.'.".a...p....'.",.'I..
1 a 1.0 o.5 0 COMPLETE ROD WITHDRAWAL FROM MAXIMUM FULL POWER Ca/-----MIDDLE OF CORE LIFE INITIAL RATE~Oa9 X 10 6k/SeC.)i~I..I[~.'.".a...p....'.",.'I..
0'040.6080100120140TIME,SECONDS160150~la~~140UP120~0~OWfeo1004<<:HIFLUXtRODSTOP.':;:
0'0 40.60 80 100 120 140 TIME, SECONDS 160 150~la~~140 UP 120~0~OW f eo 100 4<<: HI FLUX t ROD STOP.':;: i HI FLUX=.-.~aa~~0 20 40 60 80 100 120 140 TIME1 SECONDS 160 a~~ta 3 j dT mENTS (M.O L)620~aaa aa aa'~~I 600 tP HI POWER.HI'PORN'SHI TEMP.)HI TZMIP.""""'"IHi&"'"'-I-I""" dT ROD:dT TRIP:IAT ROD.":dT TRIP.":I: '::-:.::!!::":I=-i:I
iHIFLUX=.-.~aa~~020406080100120140TIME1SECONDS160a~~ta3jdTmENTS(M.OL)620~aaaaaaa'~~I600tPHIPOWER.HI'PORN'SHI TEMP.)HITZMIP.""""'"IHi&"'"'-I-I"""
.'i: 0......',.".'.-..'.~:.: '.....i:-..~jl laa':::a~"'g 580 560 540 IN~<<~~(~''i L I~1""~=-q--)~..'..."..'"::I.i::
dTROD:dTTRIP:IATROD.":dTTRIP.":I:'::-:.::!!::":I=-i:I
T~+:Ii 52O 20 40 60 8O 100 120 140 160 TIME, SECONDS  
.'i:0......',.".'.-..'.~:.:'.....i:-..~jllaa':::a~"'g580560540IN~<<~~(~''iLI~1""~=-q--)~..'..."..'"::I.i::
T~+:Ii52O2040608O100120140160TIME,SECONDS  


.t~C0't-...:--0'I'>>I>>~~TRIPANDSTEADY-STATE CORELIMITSANDREACTOR.-.ALABMPOINTS160>>~~If~:t->>~~i---.-ALARMPOINTS--'...RODSTOPI>>>>>>y>>.',:.:..[~>>IJ-.I>>~$~~>>-REACTORTRIP~>>>>~~.I~.>>!WATERLEVELTRIPII'..I-HIPRESSURIZER
.t~C 0't-...:--0'I'>>I>>~~TRIP AND STEADY-STATE CORE LIMITS AND REACTOR.-.ALABM POINTS 160>>~~I f~:t->>~~i---.-ALARM POINTS--'...ROD STOP I>>>>>>y>>.',:.:..[~>>I J-.I>>~$~~>>-REACTOR TRIP~>>>>~~.I~.>>!WATER LEVEL TRIPI I'..I-HI PRESSURIZER
"-~-.-"-n140~~~+o.~:>>~~p>>I-~~Ii."IIiI~I.'STM.GEN.SAFETYVALVES..lI~~'-:IIPI.-}.I~>>>>>>/>>~('Tl~~>>II~~~/>>120110'>>,!I..pl".I.:.HXFLUX.HIATp,i..:l~I~I.f.::..HIAT~PI~Tl.'I>>I.~.~I..-.3.I"I'-.":l,*>>+100~.:::I,~~~:'I~'I)HIFLUX~>>I~~~~~III~~~,LLNOM'l"II>>l'~rI'NAL'-Itt90~>>>>>>~>>I'Lis>>I>>~>>~~>>>>I~PLOWLIMITI.'~HIPRESSURIZER WATERLEVFL:Ii>~.I.i'HIAX82400PSIA~I~I8070>>~I>>~~~>>GfxAVI'.I.g.II~'II.III>>I7'~-HITEMP.4T-HIPOWERdT540560580INLETTEMPERATURE,
"-~-.-"-n 140~~~+o.~:>>~~p>>I-~~I i."I I i I~I.'STM.GEN.SAFETY VALVES..l I~~'-:I I P I.-}.I~>>>>>>/>>~('Tl~~>>I I~~~/>>120 110'>>,!I..pl".I.:.HX FLUX.HI AT p , i..:l~I~I.f.::..HI AT~PI~T l.'I>>I.~.~I..-.3.I" I'-.":l,*>>+100~.:::I ,~~~:'I~'I)HI FLUX~>>I~~~~~I I I~~~, LL NOM'l" I I>>l'~r I'NAL'-I tt 90~>>>>>>~>>I'Lis>>I>>~>>~~>>>>I~PLOW LIMIT I.'~HI PRESSURIZER WATER LEVFL: I i>~.I.i'HI AX 82400 PSIA~I~I 80 70>>~I>>~~~>>G fx AV I'.I.g.II~'I I.I I I>>I 7'~-HI TEMP.4T-HI POWER dT 540 560 580 INLET TEMPERATURE,'P 600 FIGURE 5.1-6 BEGINNING OF LIFE ROD WITHDRAWAL FROM l02X POWER MINIMUM DNBR;I 2.50 2.00.I sf I I sll'e ti~es sse Ie's~~Ill: W)I'tt I~,I es sg~~e r tet'I~I e I sl e e~f~I I I I I lift:ef II~I~I I~I~LEV I I I I s~Ie~~[,H lift fits sf''e~e's"''tel lift:n et 1 set.11 est I el Is I Isl-Its st sl" I i I I.I'Ill st I.'t pg SsuRE~elt'f<<s'st~~e'l$N~HI FLUX~~~'e I I.e II I fit""~I fl;e I Ref st f f I ft tile e s..-,il If l'I I I I I e ees.~~I I I I III'se tits (MAX ROD SPEED, MAX ROD WORTH)'-'Hl'LuX:.'-
'P600FIGURE5.1-6 BEGINNING OFLIFERODWITHDRAWAL FROMl02XPOWERMINIMUMDNBR;I2.502.00.IsfIIsll'eti~essseIe's~~Ill:W)I'ttI~,Iessg~~ertet'I~IeIslee~f~IIIIIlift:efII~I~II~I~LEVIIIIs~Ie~~[,Hliftfitssf''e~e's"''tellift:net1set.11estIelIsIIsl-Itsstsl"IiII.I'IllstI.'tpgSsuRE~elt'f<<s'st~~e'l$N~HIFLUX~~~'eII.eIIIfit""~Ifl;eIRefstffIfttilees..-,ilIfl'IIIIIeees.~~IIIIIII'setits(MAXRODSPEED,MAXRODWORTH)'-'Hl'LuX:.'-
I I~~II It~I I fet f I)e fl'l~el l.50\~I~s<<s'I~'s'I.s.e, lift'll I I I I~~I f I<<H I TEMP.AT.:-I e.~..Qtf'~II te ltf~''I eis lett et'I J~I'tl'I tees~~'I', Pt'1st"." Iflj j'l<<n-'HI POWER dT I I I I~f e'HI TBP e~~~~H':-'"''s s tt e~es't~tt~iles e e I sit',I's'tl~ss'II'etes wl f f''ts f~e: HI POWER AT f-, s'T-.I~~I I I~~,~~~I~I~'ll I~tie e I~Is~I I I~I HI POWER dT;t t I stts tsl;I I I I I!" I I I I.i'I s~'"<<tt''I'I I I test J s sr , 1':,I ee'.HI POWER hT;,~ie~stl I II'',;:.-.~HI LEVEL',&SIC(.,'I TEMP.AT!III~I I I st~III I~gt It lett el list e I Isle ss~e l.00 50 I stt Ole'~I e fl'S.G.~f" j:('OR HOT ASSEMBLY)i
II~~IIIt~IIfetfI)efl'l~ell.50\~I~s<<s'I~'s'I.s.e,lift'llIIII~~IfI<<HITEMP.AT.:-Ie.~..Qtf'~IIteltf~''Ieislettet'IJ~I'tl'Itees~~'I',Pt'1st"."Ifljj'l<<n-'HIPOWERdTIIII~fe'HITBPe~~~~H':-'"''sstte~es't~tt~ileseeIsit',I's'tl~ss'II'eteswlff''tsf~e:HIPOWERATf-,s'T-.I~~III~~,~~~I~I~'llI~tieeI~Is~III~IHIPOWERdT;ttIsttstsl;IIIII!"IIII.i'Is~'"<<tt''I'IIItestJssr,1':,Iee'.HIPOWERhT;,~ie~stlIII'',;:.-.~HILEVEL',&SIC(.,'ITEMP.AT!III~IIIst~IIII~gtItlettellisteIIsless~el.0050IsttOle'~Iefl'S.G.~f"j:('ORHOTASSEMBLY)i
..SAFETY>VALVES'-, el~I~t~~I I II tsii I I I III Ite I sl in t(f I I II et I n es II.,~'I ttl''I~I~I I~'.I f I le Ils e e I'il tfs sfts I*e'tts I~e~e~~~fit Ie s I+e te si~s es tees Is It'I (CORRESPONDS TO DNBR it'.e ,S If I''te<<I~I I I I i<<I I'':" I~', Ittl If ttf~~Itl sits e I I gtn I I~I<<I s'<<s.In~ss;Ij'I s e s l f I I I<<I I I I~~~Iltl fit 0.05 O.IO 0.25 0.5 L.O 2.0 4.0 Reactivity Insertion Rate, 10 6k/sec ALARM ROD STOP REACTOR TRIP"DESIGN" REACTOR TRIP CORE LIYiIT FIGURE 5.l-7 s
..SAFETY>VALVES'-,
~e BEGXNNING OF LIFE ROD WITHDRAWAL FROM 102X POWER TIME OF EVENT lls tr I~1 r Is s st el ills I'I soI'tss~tl ss I I I I s I le ills lese s lt I" s I I~I I I~I L I 1~~s its sis ills i i I Ilsi 1111 I, s Ii se ts st 250 Ilsi I I:st il I see ss 200 vo 11'ie sst ssi ise ts t'I st I I~,s~~~I see s st Its;ii~I HI le,'ss.'I" so I~I I I I il I ts.;Ii~~I I~~~TEMP.dT'?.i HI LEVEL~'~ss As t'I I't~e s ss ss Jl1.'l'ssl'I s el ls'1 ss s I t I se I ss.'SO I li~l I;I II'~I" I'I t I~ss I~~~I s I'l"I li: s tt?e"s~~~'se I I, I~I~s JC I~~~<'ltll sl H Os I Is I I II I@i sl 1 I I~~d s DNBR HA~1.0~~s I~II sile ss~I 1 i'i i!i~r r II's 1st~i II s ssl sr~I sl I I s I I Ills IIIIIII.'~Ill ilr,.I I'~~~ALARM ROD STOP, REACTOR.TRXP"DESIGN" REACTOR TRXP CORE LXMIT s I'~I is I'1st ll r<o s II, ,I''I 100 50 IC'lls it i st, HI PRESSURE sill~1 s'is.tf I I~'il lt s'e ls s s"I'I'I',l ts I I I I ski'S'I I;1st ceil;I,~s ts sll I I'Ie~I i'i'st I.i.I es dT it I>>I s Ii I'.ss is st...~I I".II HI POWER.I Il''t s s I'~e~I I I sist J it 1 tl sll'I I il'a I s sl (MAX ROD SPEED,;MAX ROD WORTH);, 11 ss'It st e I I 1 t'I!1st Is I s'st its t'ss i~~~HX LEVEL lg-7:<~IL I 11 e I is~e ss Iss tl St sl I 1st 4 i I Jll I I*Ills r, q tt\se s~~~~'3 DNBR MIN~1.s s'I s's~s.r s't~~~I i I~~~I~s I s li s II~I I I li" I~: I~II s'1 I,'It'I Ij e s Is~st st I'sli e,'.'\l ls I.s~eli~I 1st I t ss I~t Vg is~p'l'sa~I II I t'l I s+II s t s gl s s Il.I Is~l I I s~~dT Ill tli~~I~I;Is ,se t s: I iHX TEMP ss I~s I I s I~I I~~>>Ie I~I ss sill I I I~sl 11 I I I I III.0.'05 0.10 0.25 0.5 1.0 2.0 4.0 REACTIVITY INSERTION RATE, 10 hK/SEC FIGURE 5.1-8  
el~I~t~~IIIItsiiIIIIIIIteIslint(fIIIIetInesII.,~'Ittl''I~I~II~'.IfIleIlseeI'iltfssftsI*e'ttsI~e~e~~~fitIesI+etesi~sesteesIsIt'I(CORRESPONDS TODNBRit'.e,SIfI''te<<I~IIIIi<<II'':"I~',IttlIfttf~~ItlsitseIIgtnII~I<<Is'<<s.In~ss;Ij'IseslfIII<<IIII~~~Iltlfit0.05O.IO0.250.5L.O2.04.0Reactivity Insertion Rate,106k/secALARMRODSTOPREACTORTRIP"DESIGN"REACTORTRIPCORELIYiITFIGURE5.l-7s
, wt C BEGINNING OF LIFE ROD WITHDRAWAL FROM 80X POWER MXNIMUM DNBR s'AVG~sls~I ,I~iles Il~s~~~I~f~I HI FLUX~I.Ii~-,.~,r,<;'r:,HZ T':::" I'Ii I;II AVG I~s"(jest Qs I I I I s~I s q)AVG,I,~ei I s I I<<HI LEVEL.g..(PRESSURIZER) st i~HI POWER'~~ts I I isa'.'S.G.-:-SAFETY: 'ALVES-i.'>>-'-'IA gg'I,~~~I;s>>I'is I'"I')HI TEMP'~st.I~I,~'~~e~e sets ieii iis'Is's, te I ,~I-'-AT: I ls)~I~,~~~Ii'lte s I I I~I:~T'IM~~f$:.-';~~~si"I'P~~I I ee~I s e s~I I I L-r WER hT'X PRESSURE."NNR!!',tGMFI::"'.:l i I-I-~HI Po I>>ss II['tt'It'Ls I'i'DEVIATION I>>:f s~~s I I i~I I: I I ll I~I~I irpg e, s li (i~I~s ALARM ROD STOP REACTOR TRXP"DESIGN" REACTOR s>>>>see eels>>%TRXP'~~~~i~tl I II~~~~I'I Ills'e~I~.;Is II~e'HX FLGX~I I I~I.II<<Ii<<lit~CORRESP 1.0" I i I~I Is S~.I I I I I~i ss I~i'll il ONDS TO DNBR>LN HOT ASSEMBLY i:e~~~,i'sse I I II t s I~it e I I Ill ss's J I'el I~sli le',~ei~~~, (MAX.ROD SPEED,-.MAX.ROD WORTH)~It'tsi Iles~~~~i Iil~t~I;~I lls i'~I I~~s ,~~~~~~I s s s~I~, se ii e~~~s I~i i i~I II~I s le i.e~<<s'I e~s I 0 tls sill s s e'.III'Iii't'll'll'l el~il III lss O.OS O.1O O.ZS O.S 1.O 2.0 4.0 REACTIVITY INSERTION RATE, 10 8K/SEC FIGURE 5.1-9 W 4ol BEGINNXNG OF LIFE ROD WITHDRAWAL FROM 80/POWER o~TIME OF EVENT i~~o'tl ll-;-I-.':i'-::~G: "-HI PRESSURIZER';, LEVEL~.I~~~I I I It~-'rrr-I~i~i i~I~I~I" o I'.~I~I I o s.t l SAFEZY s-l~vALvEss I o~I~J'I I I Q1 ,~I, LEVEL~~~I ,I j"-,T',;I3
~eBEGXNNING OFLIFERODWITHDRAWAL FROM102XPOWERTIMEOFEVENTllstrI~1rIssstelillsI'IsoI'tss~tlssIIIIsIleillslesesltI"sII~III~ILI1~~sitssisillsiiIIlsi1111I,sIisetsst250IlsiII:stilIseess200vo11'iesstssiisetst'IstII~,s~~~IseesstIts;ii~IHIle,'ss.'I"soI~IIIIilIts.;Ii~~II~~~TEMP.dT'?.iHILEVEL~'~ssAst'II't~esssssJl1.'l'ssl'Isells'1sssItIseIss.'SOIli~lI;III'~I"I'ItI~ssI~~~IsI'l"Ili:stt?e"s~~~'seII,I~I~sJCI~~~<'ltllslHOsIIsIIIII@isl1II~~dsDNBRHA~1.0~~sI~IIsiless~I1i'ii!i~rrII's1st~iIIssslsr~IslIIsIIIllsIIIIIII.'~Ill ilr,.II'~~~ALARMRODSTOP,REACTOR.TRXP"DESIGN"REACTORTRXPCORELXMITsI'~IisI'1stllr<osII,,I''I10050IC'llsitist,HIPRESSUREsill~1s'is.tfII~'illts'elsss"I'I'I',ltsIIIIski'S'II;1stceil;I,~stssllII'Ie~Ii'i'stI.i.IesdTitI>>IsIiI'.ssisst...~II".IIHIPOWER.IIl''tssI'~e~IIIsistJit1tlsll'IIil'aIssl(MAXRODSPEED,;MAXRODWORTH);,11ss'ItsteII1t'I!1stIsIs'stitst'ssi~~~HXLEVELlg-7:<~ILI11eIis~essIsstlStslI1st4iIJllII*Illsr,qtt\ses~~~~'3DNBRMIN~1.ss'Is's~s.rs't~~~IiI~~~I~sIslisII~IIIli"I~:I~IIs'1I,'It'IIjesIs~ststI'slie,'.'\llsI.s~eli~I1stItssI~tVgis~p'l'sa~IIIIt'lIs+IIstsglssIl.IIs~lIIs~~dTIlltli~~I~I;Is,sets:IiHXTEMPssI~sIIsI~II~~>>IeI~IsssillIII~sl11IIIIIII.0.'050.100.250.51.02.04.0REACTIVITY INSERTION RATE,10hK/SECFIGURE5.1-8  
..'.",.'I PRESSURE'v Iso E li o.'I~~t sl'I I~'AVG;, I;:AT,:Lol
,wtCBEGINNING OFLIFERODWITHDRAWAL FROM80XPOWERMXNIMUMDNBRs'AVG~sls~I,I~ilesIl~s~~~I~f~IHIFLUX~I.Ii~-,.~,r,<;'r:,HZT':::"I'IiI;IIAVGI~s"(jestQsIIIIs~Isq)AVG,I,~eiIsII<<HILEVEL.g..(PRESSURIZER) sti~HIPOWER'~~tsIIisa'.'S.G.-:-SAFETY:'ALVES-i.'>>-'-'IAgg'I,~~~I;s>>I'isI'"I')HITEMP'~st.I~I,~'~~e~esetsieiiiis'Is's, teI,~I-'-AT:Ils)~I~,~~~Ii'ltesIII~I:~T'IM~~f$:.-';~~~si"I'P~~IIee~Ises~IIIL-rWERhT'XPRESSURE.
''ITJ~g HI PRESSURXZER,.
"NNR!!',tGMFI::"'.:l iI-I-~HIPoI>>ssII['tt'It'Ls I'i'DEVIATION I>>:fs~~sIIi~II:IIllI~I~Iirpge,sli(i~I~sALARMRODSTOPREACTORTRXP"DESIGN"REACTORs>>>>seeeels>>%TRXP'~~~~i~tlIII~~~~I'IIlls'e~I~.;IsII~e'HXFLGX~III~I.II<<Ii<<lit~CORRESP1.0"IiI~IIsS~.IIIII~issI~i'llilONDSTODNBR>LNHOTASSEMBLYi:e~~~,i'sseIIIItsI~iteIIIllss'sJI'elI~slile',~ei~~~,(MAX.RODSPEED,-.MAX.RODWORTH)~It'tsiIles~~~~iIil~t~I;~Illsi'~II~~s,~~~~~~Isss~I~,seiie~~~sI~iii~III~Islei.e~<<s'Ie~sI0tlssillsse'.III'Iii't'll'll'lel~ilIIIlssO.OSO.1OO.ZSO.S1.O2.04.0REACTIVITY INSERTION RATE,108K/SECFIGURE5.1-9 W4olBEGINNXNG OFLIFERODWITHDRAWAL FROM80/POWERo~TIMEOFEVENTi~~o'tlll-;-I-.':i'-::
t: itlt!:I',.;I Illl li!i i~~'io~I~~HI TEMP 4T~o~I 41:,~o HX POWER 4T DNBR~1.0'.o~I I I L I'.~~i o~I: I I I!4 I I~I''-~J I i I I I I I~sill~I~I I'~~I~, I ls I~~~o~~~il:~ilt'~,~I o o~~~I DNBR~1.3'it'I~'t~~'~~(MAX, ROD SPEED,, MAX 4 ROD WORTH)~il, i s~I I: I I!II s Itts~o ALARM ROD STOP REACTOR TRIP"DESEGN" REACTOR TREE~~Ls slot Ills i il~Its~I I I I I~oil Io I~o~.L.l.J::::
~G:"-HIPRESSURIZER';,
4lt I~I I~~~I t~o 4~o~jilt!too io.,';:@goal: "i~I~o j>>!i is I oJ~I I I: I't s't.Il'"..I tlt!I~~st~o~~~E'X PRESS o, is>>I~~I I II III St I'~I.i I H%H&iti,'-',: HI FLUX'ot'is J tl~o~~I I~II I I I~I I~I~I: tl~~I I~~o!It~~" i li i~o~I~'~il>>io~~~I~~~itis sl 100 T AVC 50 olo~oo~I'!to'lli IID oi":i ri.~I I'~~o~I I I~4 I~'~I I~I I I I I*I~I~o o I o~I~~~~I I I lo~~I I 4I~o~I I~~t I~~~I~'iti,~!il I~I~o-:: ".:++I~.-..'i'il~o~I~~~~o~i is 4s i~!~l I~I~I~I i~oL~I~~~!iot~~I~~I~s~!I~till I ll I IQ~I l'~'io t!4 I I I~~;Is o I~I~I I i It I~I I~I HI POWER 4T~-:.';HI TEMP 4T I o~I It~I I~JA.I I i lot gi i It/lt!.~it'il io~I o~~i o ,is.,'I o i't~tl~'~s i~~sot!I loss I~SS"~'II: I:~-."I 0.05 0.10 0.25 0.5 1.0 2.0 4.0 Reactivity Insertion Rate, 10 6k/sec FIGURE 5.1-10 LPSS Op FEEDWATER>ring power operation, loss of feedwater to the steam generators is of potential concern because it affects the ability of the steam generators to rmove decay heat after trip The protection for thi accident consists of reactor trip and an auxiliary feedwater system.This evaluation describes the Control and Protection System instrumentation provided on a typical Westinghouse PWR Plant to directly monitor or control steam genitor water level.Loss of feedwater accidents without credit for this instrumentation are evaluated.
LEVEL~.I~~~IIIIt~-'rrr-I~i~ii~I~I~I"oI'.~I~IIos.tlSAFEZYs-l~vALvEss Io~I~J'IIIQ1,~I,LEVEL~~~I,Ij"-,T',;I3
Typical Westinghouse design requirements for the auxiliary feedwater system are included.A typical 1456 MWt two-loop plant was selected for the transient analysis.A loss of feedwater accident to one steam generator is most severe on a two-loop plant.For a complete loss of feedwater, the transient per loop, is dependent on the normalized kinetic parameters; e.g., power (so the results shown here are representative for all plants currently under design.Zn all cases, diverse automatic reactor trips insure a plant trip before any core damage or system overpressure occurs.Manual actuation of the auxiliary feedwater system is considered an adequate backup to the automatic actuation.
..'.",.'IPRESSURE'vIsoElio.'I~~tsl'II~'AVG;,I;:AT,:Lol
There is sufficient time (24 minutes)and alarms to take credit for manual actuation.
''ITJ~gHIPRESSURXZER,.
<nteractions of steam generator level control and protection resulting C~rom random failure modes are presented in Section 4.2.5.Alarms actuated 5.2-1 or a complete loss of f eedwater accident are presented in Tab le 5.2-1'C-.suit trees for loss of feedwater accidents are presented in Figures C-2 l, 5.2-2,and 5.2-3.LOSS OF FEEDQATER-TRANSIENT ANALYSIS Several representative transient cases are evaluated for loss of feedwater accidents.
t:itlt!:I',.;IIlllli!ii~~'io~I~~HITEMP4T~o~I41:,~oHXPOWER4TDNBR~1.0'.o~IIILI'.~~io~I:III!4II~I''-~JIiIIIII~sill~I~II'~~I~,IlsI~~~o~~~il:~ilt'~,~Ioo~~~IDNBR~1.3'it'I~'t~~'~~(MAX,RODSPEED,,MAX4RODWORTH)~il,is~II:II!IIsItts~oALARMRODSTOPREACTORTRIP"DESEGN"REACTORTREE~~LsslotIllsiil~Its~IIIII~oilIoI~o~.L.l.J::::
Figure 5.2-4 shows the transient resulting from complete loss of the steam flow control signal.As shown by the figure, the Level Control System restores water level such that only a temporary decrease in~ster level occurs.There is no approach to unsafe conditions or to any reactor trip set point.Figures 5.2-'5 and 5.2-6 illustrate a typical complete loss of feedwater"o one steam generator'of a two-loop plant.No credit was taken for reactor trips derived from the steam generator.
4ltI~II~~~It~o4~o~jilt!tooio.,';:@goal:"i~I~oj>>!iisIoJ~III:I'ts't.Il'"..Itlt!I~~st~o~~~E'XPRESSo,is>>I~~IIIIIIIStI'~I.iIH%H&iti,'-',:
The loss of subcooled feedwater is reflected to the reactor as a small decrease in therma1 I load, causing the increase in pressure and temperature shown in the-irst minute.(The reactor was assumed to be in manual control with<<manual correction.)
HIFLUX'ot'isJtl~o~~II~IIIII~II~I~I:tl~~II~~o!It~~"ilii~o~I~'~il>>io~~~I~~~itissl100TAVC50olo~oo~I'!to'lli IIDoi":iri.~II'~~o~III~4I~'~II~IIIII*I~I~ooIo~I~~~~IIIlo~~II4I~o~II~~tI~~~I~'iti,~!ilI~I~o-::".:++I~.-..'i'il~o~I~~~~o~iis4si~!~lI~I~I~Ii~oL~I~~~!iot~~I~~I~s~!I~tillIllIIQ~Il'~'iot!4III~~;IsoI~I~IIiItI~II~IHIPOWER4T~-:.';HITEMP4TIo~IIt~II~JA.IIilotgiiIt/lt!.~it'ilio~Io~~io,is.,'Ioi't~tl~'~si~~sot!IlossI~SS"~'II:I:~-."I0.050.100.250.51.02.04.0Reactivity Insertion Rate,106k/secFIGURE5.1-10 LPSSOpFEEDWATER
One minute after the.loss of feedwater, the steam generator tubes begin to uncover, causing a rapid.pressure and temperature increase.If amchnum pressure control capacity (power operated relief valves)is available, the pressure rise is limited and a high pressure reactor trip does not result.A reactor trip on high pressurizer el occurs appro~tely two minutes after the loss of feedwater.
>ringpoweroperation, lossoffeedwater tothesteamgenerators isofpotential concernbecauseitaffectstheabilityofthesteamgenerators tormovedecayheataftertripTheprotection forthiaccidentconsistsofreactortripandanauxiliary feedwater system.Thisevaluation describes theControlandProtection Systeminstrumentation providedonatypicalWestinghouse PWRPlanttodirectlymonitororcontrolsteamgenitorwaterlevel.Lossoffeedwater accidents withoutcreditforthisinstrumentation areevaluated.
5.2-2 l r>
TypicalWestinghouse designrequirements fortheauxiliary feedwater systemareincluded.
z inventory in the second steam generator is sufficient to bring Water plant to normal no>>load condi tions.There is no overpressure ox the p an of water from the Reactoz Coolant System.loss o figures,5.2-7 and 5.2-8 illustrate a worst case complete loss of feed>>water to all steam generators with no trip from steam generatox instxu>>~tation.A conservative evaluation is done for a high-power densi.ty p an lant typical of current PWR design g.456 MWt 2>>loop).No credit is taken for charging systems or for energy absorption by metal in the Reactor Coolant System.The results are considered to be extreme values rather than realistic conditions for an actual plant.The reactor trips on high pressurizer pressure about one minute after the loss of feed.Stored heat in the core continues to heat the reactor coolant and the pressurizer M.ls in about three minutes.Steam dump values open fuU.y under Tavg control and reduce steam line l I pressure.After about ten minutes, the Reactor Coolant System begins to boy., aa"h<<h time the x'eactor coolant pumps are assumed to cease adding energy to the coolant.Boiling causes a rapid increase in the volumetric surge rate, and system pressure rises until the volumetric expansion is balanced by safety value capacity for water zelief.(No credit was taken"or the power-operated relief values in this analysis.)
Atypical1456MWttwo-loopplantwasselectedforthetransient analysis.
te&#x17d;generated in the core is assumed to fill the upper reactor vessel, e steam generators, and half of the coolant piping befoxe escaping to e px'essurizer.
Alossoffeedwater accidenttoonesteamgenerator ismostsevereonatwo-loopplant.Foracompletelossoffeedwater, thetransient perloop,isdependent onthenormalized kineticparameters; e.g.,power(sotheresultsshownherearerepresentative forallplantscurrently underdesign.Znallcases,diverseautomatic reactortripsinsureaplanttripbeforeanycoredamageorsystemoverpressure occurs.Manualactuation oftheauxiliary feedwater systemisconsidered anadequatebackuptotheautomatic actuation.
During this four minute period, most of the reactor 5.2-3 e
Thereissufficient time(24minutes)andalarmstotakecreditformanualactuation.
olant fluid'is lost as water discharge through the pressurizer
<nteractions ofsteamgenerator levelcontrolandprotection resulting C~romrandomfailuremodesarepresented inSection4.2.5.Alarmsactuated5.2-1 oracompletelossoffeedwateraccidentarepresented inTable5.2-1'C-.suittreesforlossoffeedwater accidents arepresented inFiguresC-2l,5.2-2,and 5.2-3.LOSSOFFEEDQATER
>+sty valve.As steam is discharge through the pressurizer, pre measure decreases to the set pressure for the safety valves.After an additional ten minutes of boiling, (24 minutes after the loss of feedwater), the top of the core is nearly uncovered.
-TRANSIENT ANALYSISSeveralrepresentative transient casesareevaluated forlossoffeedwater accidents.
Xt was assumed that the Auxiliary Feedwater System was manually actuated at this time (push buttons on the control board)and 200 gpm auxiliary f eedwater per steam generator began immediately.
Figure5.2-4showsthetransient resulting fromcompletelossofthesteamflowcontrolsignal.Asshownbythefigure,theLevelControlSystemrestoreswaterlevelsuchthatonlyatemporary decreasein~sterleveloccurs.Thereisnoapproachtounsafeconditions ortoanyreactortripsetpoint.Figures5.2-'5and5.2-6illustrate atypicalcompletelossoffeedwater "oonesteamgenerator
Qithin two minutes of starting auxiliary feedwater, the steam generator heat removal exceeds decay heat and reactor coolant~emperature and pressure rapidly decrease.5.2.2 TYPICAL SYSTEM 1ESIPil REQVIEEMENTS Auxiliarv Feedwater System To prevent release of reactor coolant through pressurizer safety valves i and to protect the core, a supply of high pressure feedwater must be provided for the removal of residual heat from the core by heat exchange in the steam generators when the main feedwater pumps cease to operate on blackout or because of fault conditions.
'ofatwo-loopplant.Nocreditwastakenforreactortripsderivedfromthesteamgenerator.
'yp<<al criteria for actuation of auxiliary feedwater is presented in iable 5 2-2 afety zequi.rement is to include two separate auxiliary feedwater y terna to ensure reliability of supply.One s'ystem utilixas a steam turbine driven auxfLiazy feedwater pump, ae urbine being connected such that steam can be supplied from some 5.2-4 t,  
Thelossofsubcooled feedwater isreflected tothereactorasasmalldecreaseintherma1Iload,causingtheincreaseinpressureandtemperature showninthe-irstminute.(Thereactorwasassumedtobeinmanualcontrolwith<<manualcorrection.)
~of the steam generators.
Oneminuteafterthe.lossoffeedwater, thesteamgenerator tubesbegintouncover,causingarapid.pressureandtemperature increase.
The flow rate, usually about 200 gpm nr steam generator, is, sufficient to maintain a milkman depth of water>r ste the steam generators.
Ifamchnumpressurecontrolcapacity(poweroperatedreliefvalves)isavailable, thepressureriseislimitedandahighpressurereactortripdoesnotresult.Areactortriponhighpressurizer eloccursappro~tely twominutesafterthelossoffeedwater.
ocher system utilizes two (2)reserve auxiliary f eedwater pumps, a~of about half the capacity of the steam driven.pump.How rate suf ficienc to ensure cooling of the system and to Prevent water discharge crom Reactor'oolant System xelief valves.The reserve auxiliary feed-vacex pumps normally are driven by prime movers using'source of energy other than steam from steam generators.
5.2-2 lr>
The head generated by the feedwater pumps is to be sufficient to ensure that feedwater can be pumped into the steam generacor when safety'valves are discharging.
zinventory inthesecondsteamgenerator issufficient tobringWaterplanttonormalno>>loadconditions.Thereisnooverpressure oxthepanofwaterfromtheReactozCoolantSystem.lossofigures,5.2-7 and5.2-8illustrate aworstcasecompletelossoffeed>>watertoallsteamgenerators withnotripfromsteamgeneratox instxu>>~tation.Aconservative evaluation isdoneforahigh-power densi.typanlanttypicalofcurrentPWRdesigng.456MWt2>>loop).Nocreditistakenforchargingsystemsorforenergyabsorption bymetalintheReactorCoolantSystem.Theresultsareconsidered tobeextremevaluesratherthanrealistic conditions foranactualplant.Thereactortripsonhighpressurizer pressureaboutoneminuteafterthelossoffeed.Storedheatinthecorecontinues toheatthereactorcoolantandthepressurizer M.lsinaboutthreeminutes.SteamdumpvaluesopenfuU.yunderTavgcontrolandreducesteamlinelIpressure.
Pumps axe capable of starting and delivering feedwater vithin two (2)minutes of the blackout or fault conditions requiring puup actuation.
Afterabouttenminutes,theReactorCoolantSystembeginstoboy.,aa"h<<htimethex'eactorcoolantpumpsareassumedtoceaseaddingenergytothecoolant.Boilingcausesarapidincreaseinthevolumetric surgerate,andsystempressurerisesuntilthevolumetric expansion isbalancedbysafetyvaluecapacityforwaterzelief.(Nocreditwastaken"orthepower-operated reliefvaluesinthisanalysis.)
>ie typical design basis for sizing auxiliary feedwater pumps is given by Table 5.2-3.Sources of water for auxiliary and reserve auxiliary feedwater pumps are duplicated or if convenient, triplicated.
te&#x17d;generated inthecoreisassumedtofilltheupperreactorvessel,esteamgenerators, andhalfofthecoolantpipingbefoxeescapingtoepx'essurizer.
Ordinarily, wager is'}rawn from a condensate storage tank containing water of normal purity,'<<may be drawn through emergency connections from other sources such~city water, well water, fix~+in water, service water, etc., to obt ain a supply under sufficient pressure to satisfy auxiliary feed>>"-pump suction requirements under emergency conditions.
Duringthisfourminuteperiod,mostofthereactor5.2-3 e
olantfluid'islostaswaterdischarge throughthepressurizer
>+styvalve.Assteamisdischarge throughthepressurizer, premeasuredecreases tothesetpressureforthesafetyvalves.Afteranadditional tenminutesofboiling,(24minutesafterthelossoffeedwater),
thetopofthecoreisnearlyuncovered.
XtwasassumedthattheAuxiliary Feedwater Systemwasmanuallyactuatedatthistime(pushbuttonsonthecontrolboard)and200gpmauxiliary feedwaterpersteamgenerator beganimmediately.
Qithintwominutesofstartingauxiliary feedwater, thesteamgenerator heatremovalexceedsdecayheatandreactorcoolant~emperature andpressurerapidlydecrease.
5.2.2TYPICALSYSTEM1ESIPilREQVIEEMENTS Auxiliarv Feedwater SystemTopreventreleaseofreactorcoolantthroughpressurizer safetyvalvesiandtoprotectthecore,asupplyofhighpressurefeedwater mustbeprovidedfortheremovalofresidualheatfromthecorebyheatexchangeinthesteamgenerators whenthemainfeedwater pumpsceasetooperateonblackoutorbecauseoffaultconditions.
'yp<<alcriteriaforactuation ofauxiliary feedwater ispresented iniable52-2afetyzequi.rement istoincludetwoseparateauxiliary feedwater yternatoensurereliability ofsupply.Ones'ystemutilixasasteamturbinedrivenauxfLiazy feedwater pump,aeurbinebeingconnected suchthatsteamcanbesuppliedfromsome5.2-4 t,  
~ofthesteamgenerators.
Theflowrate,usuallyabout200gpmnrsteamgenerator, is,sufficient tomaintainamilkmandepthofwater>rstethesteamgenerators.
ochersystemutilizestwo(2)reserveauxiliary feedwaterpumps,a~ofabouthalfthecapacityofthesteamdriven.pump.HowratesufficienctoensurecoolingofthesystemandtoPreventwaterdischarge cromReactor'oolant Systemxeliefvalves.Thereserveauxiliary feed-vacexpumpsnormallyaredrivenbyprimemoversusing'sourceofenergyotherthansteamfromsteamgenerators.
Theheadgenerated bythefeedwater pumpsistobesufficient toensurethatfeedwater canbepumpedintothesteamgeneracor whensafety'valvesaredischarging.
Pumpsaxecapableofstartinganddelivering feedwater vithintwo(2)minutesoftheblackoutorfaultconditions requiring puupactuation.
>ietypicaldesignbasisforsizingauxiliary feedwater pumpsisgivenbyTable5.2-3.Sourcesofwaterforauxiliary andreserveauxiliary feedwater pumpsareduplicated orifconvenient, triplicated.
Ordinarily, wageris'}rawnfromacondensate storagetankcontaining waterofnormalpurity,'<<maybedrawnthroughemergency connections fromothersourcessuch~citywater,wellwater,fix~+inwater,servicewater,etc.,toobtainasupplyundersufficient pressuretosatisfyauxiliary feed>>"-pumpsuctionrequirements underemergency conditions.
5.2-5  
5.2-5  
(
(
fromtheauxiliary pumpsisdelivered tothesteamgenerators
from the auxiliary pumps is delivered to the steam generators
~pterpipelinesseparatefromthemainfeedpipelines.Pipelinesarepapespacedtoassurethatasinglefaultdoesnotpreventfeedwater
~pter pip elines separate from the main f eed pipel ines.Pip elines are pape spaced to assure that a single fault does not prevent feedwater~~Jv spa~e whole of the auxiliary feedwater system (water supply, piping, diesel generators, etc.)must be"Class I" seismic design standard.+
~~Jvspa~ewholeoftheauxiliary feedwater system(watersupply,piping,dieselgenerators, etc.)mustbe"ClassI"seismicdesignstandard.+
pggp+I~Steam and Feedwater Pi in<iailure of any main steam or feedwater line or malfunction of a valve~tel].ed the"ein or any consequential damage must not reduce flow capability if>e auxiliary (emergency) feedwater system, render inoperable any~eered safeguard service (i.e., controls, electric cables, containment aeM4 g piping, etc.), initiate a loss-of-coolant accident, cause failure if any other steam or feedwater line, result in the containment pressure exceeding the design value or impair its impermeability and integrity.
pggp+I~SteamandFeedwater Piin<iailureofanymainsteamorfeedwater lineormalfunction ofavalve~tel].edthe"einoranyconsequential damagemustnotreduceflowcapability if>eauxiliary (emergency) feedwater system,renderinoperable any~eeredsafeguard service(i.e.,controls, electriccables,containment aeM4gpiping,etc.),initiatealoss-of-coolant
I>steam and feedwater lines together with their supports and structures
: accident, causefailureifanyothersteamorfeedwater line,resultinthecontainment pressureexceeding thedesignvalueorimpairitsimpermeability andintegrity.
~<<en each steam generator and their associated isolation valves are to-"'"Class l" seismic design standard.*
I>steamandfeedwater linestogetherwiththeirsupportsandstructures
e oe expression"Class I" used in this context is defined in sign of Nuclear Power Reactors against Earthquakes" in a document~titled"Behaviour of Structures During Earthquakes" Appendix A, by Housner, professor of Civil Engineering', California Institute of,~""oology.
~<<eneachsteamgenerator andtheirassociated isolation valvesareto-"'"Classl"seismicdesignstandard.*
Pasadena, California.
eoeexpression "ClassI"usedinthiscontextisdefinedinsignofNuclearPowerReactorsagainstEarthquakes" inadocument~titled"Behaviour ofStructures DuringEarthquakes" AppendixA,byHousner,professor ofCivilEngineering',
Published by American Society of"-+1 Engineers-Engineering Mechanics Division.(October 1959 EM4)5.2-6  
California Institute of,~""oology.
: Pasadena, California.
Published byAmericanSocietyof"-+1Engineers
-Engineering Mechanics Division.
(October1959EM4)5.2-6  


TABLE5.2-1~SACTUATEDFORACO%'LETELOSSOFFEEDWATER ACCIDENTCauseoffault(ingeneral,anycondition causingacompletelossoffeedwater causesanalarm)2.Lowfeedwater flow(partialreactortrip,twochannelspersteamgenerator)
TABLE 5.2-1~S ACTUATED FOR A CO%'LETE LOSS OF FEEDWATER ACCIDENT Cause of fault (in general, any condition causing a complete loss of feedwater causes an alarm)2.Low feedwater flow (partial reactor trip, two channels per steam generator)
Steamgenerator leveldeviation (onepersteamgenerator)
Steam generator level deviation (one per steam generator)
Lowsteamgenerator level(partialreactortrip,incoincidence with2.above,twochannelspersteamgenerator) a5.Low-lowsteamgenerator level(reactortrip,thr'eechannelspersteamgenerator) 6.Automatic controlrodmotion7.Tdeviation avg8.HighT(3or4channels) avg9.Pressurizer leveldeviation LO.Highpressurizer pressure(twochannels) 11.Pressurizer relieflinehightemperature lHighpressurizer pressurereactortripNote:Itisassumedthatthe-turbineandreactoraretrippedonhighpressurizer pressure.
Low steam generator level (partial reactor trip, in coincidence with 2.above, two channels per steam generator) a 5.Low-low steam generator level (reactor trip, thr'ee channels per steam generator) 6.Automatic control rod motion 7.T deviation avg 8.High T (3 or 4 channels)avg 9.Pressurizer level deviation LO.High pressurizer pressure (two channels)11.Pressurizer relief line high temperature l High pressurizer pressure reactor trip Note: It is assumed that the-turbine and reactor are tripped on high pressurizer pressure.Pressurizer safety valve outlet high temperature
Pressurizer safetyvalveoutlethightemperature
~4'igh pressurizer level reactor trip Low steam line pressure (not on all plants)~6~Pressurizer relief tank liquid high temperature
~4'ighpressurizer levelreactortripLowsteamlinepressure(notonallplants)~6~Pressurizer relieftankliquidhightemperature
~7'ressurizer relief tank high pressure~8'ressurizer relief tank high level 19.~High containment pressure (safety injection actuation, at about lO~of design pressure)10 Low pressurizer level (partial safety in)ection actuation)
~7'ressurizer relieftankhighpressure~8'ressurizer relieftankhighlevel19.~Highcontainment pressure(safetyinjection actuation, ataboutlO~ofdesignpressure) 10Lowpressurizer level(partialsafetyin)ection actuation)
TABLE 5.2-2 TYPICAL CRITERIA FOR AUXILIARY FEEDVATER ACTUATION Motor"Qxiven P s Low-low level in any steam generator starts both pumps.action requires the same bistables and relay logic as used for the reactor trfp.(2/3 circuitry for any steam generator)
TABLE5.2-2TYPICALCRITERIAFORAUXILIARY FEEDVATER ACTUATION Motor"Qxiven PsLow-lowlevelinanysteamgenerator startsbothpumps.actionrequiresthesamebistables andrelaylogicasusedforthereactortrfp.(2/3circuitry foranysteamgenerator)
.b)Opening of both feedwater pump circuit breakers staxts both pumps (1/1+1/1 logic).c)Safety injection sequence d)Manual.Turbine-Driven P a)Low-low level in two steam generators.(Same circuitry as I.A.above)b)Loss of voltage on both 4KV buses (1/1+1/1 logic)c)Manual.3.General Criteria a)All three pumps are to have independent starting circuits such that no single failure prevents mire than one pump from starting.b)Instxmentation and logic circuits for la and 2a must meet the single-failure cxiterion fox actuation and be capable of testing at po~er.Compatibility with reactor trip circuit testing is also required.c)Spurious actuation due to unusual failures is tolerable, but routine testing of reactor trip circuits should not cause spurious starts.
.b)Openingofbothfeedwater pumpcircuitbreakersstaxtsbothpumps(1/1+1/1logic).c)Safetyinjection sequenced)Manual.Turbine-Driven Pa)Low-lowlevelintwosteamgenerators.
400 0 HZ PRESS/ALARM:-":.'-.='::.
(Samecircuitry asI.A.above)b)Lossofvoltageonboth4KVbuses(1/1+1/1logic)c)Manual.3.GeneralCriteriaa)Allthreepumpsaretohaveindependent startingcircuitssuchthatnosinglefailurepreventsmirethanonepumpfromstarting.
b)Instxmentation andlogiccircuitsforlaand2amustmeetthesingle-failure cxiterion foxactuation andbecapableoftestingatpo~er.Compatibility withreactortripcircuittestingisalsorequired.
c)Spuriousactuation duetounusualfailuresistolerable, butroutinetestingofreactortripcircuitsshouldnotcausespuriousstarts.
4000HZPRESS/ALARM:-":.'-.='::.
-,'tL.'-':4:-:1::!!
-,'tL.'-':4:-:1::!!
t:::il::-::rW I'.='=Qptftt!ti.!r.'L"COMPLETERODWITHDRAWAL FROMMAX.HJLLPOWERBBCINNZNC URE-----MIDDLEOFOFCORELIFECORELIFE020406080TIMENSECONDS1001201401608004&NNaWi50HILEVEL406080IflP~&l~a100120140160TIMENSECONDS2.01.51.00.5'Wa.IBt~IVPfPt.-DNBRMIN.:~1.30tll')"HOTQQLNNEL:1-WOOI~NC1BBBMILY-N~020'0608010012014010TIME,SECONDS TABLE5.2>>2d)Instrumentation andlogicforlband2bshouldbeconsidered asoperational signalsforeconomic(notpublicsafety)protec-tion,(SimQ.artoreactortriponreactorcoolantpumpcircuitbreakeropening).e)AsEngineered Safeguards components, theactuation circuitry forauxiliary feedvater actuation shallmeetallappU.cable IEEEDesignCriteria.  
t:::il::-::rW I'.='=Qptftt!ti.!r.'L" COMPLETE ROD WITHDRAWAL FROM MAX.HJLL POWER BBCINNZNC URE-----MIDDLE OF OF CORE LIFE CORE LIFE 0 20 40 60 80 TIMEN SECONDS 100 120 140 160 800 4&NN aW i 5 0 HI LEVEL 40 60 80 I fl P~&l~a 100 120 140 160 TIMEN SECONDS 2.0 1.5 1.0 0.5'Wa.IB t~IVPfPt.-DNBR MIN.:~1.30 tll')" HOT QQLNNEL:1-WOO I~NC1 BBBMILY-N~0 20'0 60 80 100 120 140 1 0 TIME, SECONDS TABLE 5.2>>2 d)Instrumentation and logic for lb and 2b should be considered as operational signals for economic (not public safety)protec-tion, (SimQ.ar to reactor trip on reactor coolant pump circuit breaker opening).e)As Engineered Safeguards components, the actuation circuitry for auxiliary feedvater actuation shall meet all appU.cable IEEE Design Criteria.  


e'TABLE5.2-3CALDESIGNBASISFORSIZINGAUXILLQEFEEDWATER'PUMPS
e'TABLE 5.2-3 CAL DESIGN BASIS FOR SIZING AUXILLQE FEEDWATER'PUMPS
~~DRIVENPUMPSI~steam~riven pumpcapacityisadequatetomaintainatleastlpfeetofwaterinallsteamgenerators intheeventoflossofstationpowerfromnormalfullpoweroperation.
~~DRIVEN PUMPS I~steam~riven pump capacity is adequate to maintain at least lp feet of water in all steam generators in the event of loss of station power from normal full power operation.
Nocreditis~owedformotor-driven pumpcapacity.
No credit is~owed for motor-driven pump capacity.~OR-DRIVEN PUMPS'I Each moto~ven pump, by itself,.is'adequate to prevent water relief from the pressurizer relief valves under the following as sump tions.a)Plant trip occurs frommaachnun steadymtate power and temperature.
~OR-DRIVEN PUMPS'IEachmoto~venpump,byitself,.is'adequate topreventwaterrelieffromthepressurizer reliefvalvesunderthefollowing assumptions.a)Planttripoccursfrommaachnun steadymtate powerandtemperature.
conditions.
conditions.
b)Allsteamgenerators areattheirlowlowleve1trippointsatthetimeoftrip.c)Nocreditistakenforanyadditional sourcesoffeedwater aftertrip(stationblackoutassumed.)
b)All steam generators are at their low low leve1 trip points at the time of trip.c)No credit is taken for any additional sources of feedwater after trip (station blackout assumed.)d)At least half, but not all of the steam generators are supplied.with amcLliary f eedwater.e)Natural circulation exists in the Reactor Coolant System.0 No credit is taken for charging or letdown from the Reactor Coolant System.g)Applicable starting delays and feedwater pipe purging times are used.
d)Atleasthalf,butnotallofthesteamgenerators aresupplied.
FAULT TRtt FOR IDSS Ol'IB+STIR F(DM'.m~I'l~O CORE SECIHS To UNCOVER INSUffo S Iol gURCINC CAT.A NAHUAL A o f 0 ll 0$o TIKE (ilo NIH.)NANUAL A,F,M,S, TINE (o lo NIN.)RCS HEATS OH DECAT HEAT M Oo AUTO, A.F.M.S.ALL SoCo'S Dtf STATION (Stt FICURR Sot I RoTo ON H'lo FREE OIlltt SoCo'$Q(FTT bCS HFATS SoC TURES RECIN To UNCOVER HOTEl HI.FREES.R.T.NAT bt HECSSSART TO=FREVBIT STSTt&#xc3;OVER TRESSURE IO IO IXIOL I O I I.OIO.IIOII OOI.IIIOII MIO I.OIO.IOI OOO OOO LOM SoCo LEVEL NANUAL REACTOR AND IRIF-~M SINo NIS IP SLUM LOSS Or LEVEL RAPID lOSS OF LEVtL LOSS OF SoCo LEVEL REACIOR AT FMRo MITH IHSUFF.F.M OR AbbbtVIATIOHS RCS~REACIOR COOLANf STSTEN RT REACIOR IRIF S.I SAftff IlQECTION Fo Mo ftEDMATER AofoMoSo AUIILIART FoMo START Sooo~STEAN CENtRATOR N J4 NOIOR DRIVEN NECRANICAL FAULT AUTO.C(NIROL FAULT ELECTRICAL f AULT LOSS Of FELID (Stt FICURR Sot I)
withamcLliary feedwater.
 
e)Naturalcirculation existsintheReactorCoolantSystem.0NocreditistakenforchargingorletdownfromtheReactorCoolantSystem.g)Applicable startingdelaysandfeedwater pipepurgingtimesareused.
pan.T Tace poa ross op pcaeATca nuu SER Flcuac S.I-I AUTQtATIC CONTRO FAULT ELECTRICAL fhULT LOSS Of f.M.SUCTION 2/>Hl.LEVEL CLOSES F.M.VLV IHCOHPLETE S.le SIGQ-H$R.T.I RQQIHIHG F.Mo MHAN~f.M.VALVE CLOSE EI CONTROL fAULT I LOOP LOSS Of COOIAHF FLOV RE-REACTOR AT BILL POllER S.CEN.LEVEL CONTROLLER fAUL OR RFACIOR AT RE-DUCID FOlXR TNFROFER cxTe IN CONTROLLER I PLPIP L.O.F.M.-(ELEC.FAULT)4 EV.RUS FAILURE ONE SUS LOSS OF COH-OENSATE tUHPS OR I~lie SS OF HTR.DRAB f LBP LO.SIN.fLOM Rl fEED BOll C T OH T OH HI LEVEL INDICA-TION (R,t.S.)AILURE OF COH-EHSATE RYPASS Ab baEVIATI ONS fAILURE CONDITION R.T.-REACTOR Tait S.l.-,SAfETT IHIECTION R.t.S.-REACTOR PROTECTION STSTEH f.M.-FEEDMATER Aaf.M.S.-AUXILIARY f.M.START fIGURE 5.2-2,
FAULTTRttFORIDSSOl'IB+STIR F(DM'.m~I'l~OCORESECIHSToUNCOVERINSUffoSIolgURCINCCAT.ANAHUALAof0ll0$oTIKE(iloNIH.)NANUALA,F,M,S,TINE(oloNIN.)RCSHEATSOHDECATHEATMOoAUTO,A.F.M.S.ALLSoCo'SDtfSTATION(SttFICURRSotIRoToONH'loFREEOIllttSoCo'$Q(FTTbCSHFATSSoCTURESRECINToUNCOVERHOTElHI.FREES.R.T.NATbtHECSSSART TO=FREVBITSTSTt&#xc3;OVERTRESSUREIOIOIXIOLIOII.OIO.IIOIIOOI.IIIOIIMIOI.OIO.IOIOOOOOOLOMSoCoLEVELNANUALREACTORANDIRIF-~MSINoNISIPSLUMLOSSOrLEVELRAPIDlOSSOFLEVtLLOSSOFSoCoLEVELREACIORATFMRoMITHIHSUFF.F.MORAbbbtVIATIOHS RCS~REACIORCOOLANfSTSTENRTREACIORIRIFS.ISAftffIlQECTION FoMoftEDMATER AofoMoSoAUIILIART FoMoSTARTSooo~STEANCENtRATOR NJ4NOIORDRIVENNECRANICAL FAULTAUTO.C(NIROLFAULTELECTRICAL fAULTLOSSOfFELID(SttFICURRSotI)  
~~FAULT TREE POR LOSS OF PEEDWATER PLOW SEE FIGURE 5.2-1 STATION BLACKOUT WITH LOSS OF PEED STM.GEN.LO-LO LEVEL A.F.W.S.LOSS OP LEVEL IN STM.GEN.F.W PUMP BKR.MOTOR A.F.W S 4 KV UNDERVOLT STEAM A.F.W S.(LOSS OP REACTOR COOLANT FMW REQUIRES 2963)IATE REACTOR TRIP)COMPLETE LOSS OF 4 RV SYMBOLS ABBREVIATIONS F.W.-PEED WATER A..P.W.S.-AUXILIARY P.W.STAR]FIGURE 5.2-3 lt F F LEVEL RESPONSE TO LOSS OF STER%AN SIGNAL PROP+INTEGRAL K+-1 1S PROP+INTEGRAL K+-1 2 T S PHEOMATIC POSITIONER POSITION W 8 Qf Q NORMALIZED STEhK FLOQ 8 Qf NOHHAIZZED PEEDWATER PLOW-1 K<<1 fe T-200sec 1 K~10 T~200 sec 2 2 l~~-" FEED%TER VALVE~POLLY OPEN~~~]~~~~4~-~~~--I-I~~10 10 20 20 30~, SECONDS 30 40 40 50 50'0 60~~~~~~~~I'~~W~~~~~I.~~o FZGaaE 5.2-4 LOSS OF FEEDQATER TO ONE STEAM GENERATOR AT T~ONE SECOND TYPXCAL TWO-LOOP PLANT 2600 2200 1800~W~I t=LL:~t 1400~~800 600 400~t~~~PRESSURIZER
.LEVEL HEACTOR TRXP-'~t 200'25,,dao~~50,00 25,Oej~~4~~~~40 80 120 160 200 MME, SECONDS FIGURE 5.2-5 LOSS OF FEEDWATER TO ONE STEhH GENERATOR AT T~ONE SECOND" 640:".I:~l I~E~~~I A.~I~'I 620"..:.:-:.-.~~~-: 600~~~~~E"'3'-'-=580~~:~~500 540.L--..:4.P':: ll=.S'500 1.0.8-COEE~-POWER'-:=..~.6 i-.:)"&#x17d;TOTAL GEN.~2 0 40 80 120 160 200~, SECONDS FIGURE 5 2-6 l~
't e'e 0 0 F00 50 0 0 3.0 2e5 2.0 200 100 ga 0 0 Q2IPLETE LOSS OF PEEDWATER<<~~I~~I~~~~I e e e i!i~:..i'.I~~I~I I~I>>~e~~~'I~~500 1000 TIME SECONDS 1500 I~I r~~I, t':I~~~('I~I:::: J<<i~~I.<<n I..~::~(r'i:..('I~.I~'I'~~I~e~e~I.~e I~e I~I.e I'00 TIME SECOR)S 500 1500 STEhM PLOW'TO PRESSURIZER
~I I(i WhTER BKZEF j I e (*'STEhM RELIEF IHS BOILIHG.COHDENSATZOS
~HZ PRESS TRZP-'KCEIES BOILS~:...II....j;-.-:i:<<;';;,I I-:;:-'-'I'<<'U-
~e 0'0 00 1500~~:~I I: 4 J<<~::.i.-.~~10.:::..":: LI I I I t~~:-BOTLTHG f~WhTER R1KXEF::.-.;hei~.:.'"::.:.ll'.
I g~i'.I:.II I."I e.I~.~i I I (:-:~~,"".,: hIEZLZhRT PEH"'HsSRS i:I I.':j~e 1000 500 1500 TIME AFZER LOSS OF PEED, SECONDS PIGUBE 5 2 7 CQHFLEZE LOSS OF PEEDWATEK~+o 600)$50 0 500 1000-1500 TZHE, SECONDS 10QO la 8QQ 6QQ.'0 gQQ Q 0 500 1000 1500 2000 TIME, SECONDS AUXILIARY FEHNATER SYSTEM SCHEMATIC 2 LOOP PLANT Motor Operated Valve M Pneumatica11y L O.Locked Open Operated Valve Manual Valve (normally open)I,~MOTOR OPERAL~CHECK VALVE STOP CHECK VALVE Condensate Storage Tank Manual Valve (normally closed)~Prom Alternate Water Supply (CLASS I)CLASS IXi CLASS I L 0.LO L.O.Motor Drive Turbine f Drive Motor Drive Prom Main Peedwater System SG B-"rom Main Peedwater System FIGURE 5.2 9 4*
OSS OF COOT~i-~OW ANALYSIS LO INTRODUCTIO&#xc3;
~SD
 
==SUMMARY==
c~3~I the reactor is~the power range of operation, loss of coolant flow eaten t e potential conce-n.Without suf f icient flow, DNB and clad failure~d quickly occur.estinghouse PWR's, constant-speed pumps supply coolant flow.Plow is egulated or otherwise varied.High-inertia flywheels are mounted on each.so that f low dec=eases ovex'period o f time (typically 12 seconds to f flow)following a loss of power to the pump motor.This flow coast-ioMn allows for Protection System tMe delays and remova1 of stored heat in xbe fueL.Subsequent decay heat is removed by natural circulation.
Diverse, redundant protection circuits are provided to protect against all possible loss of flow accidents.
These protection circuits axe evaluated this report for multiloop loss of flow, single loop loss of;flow, and~othetical pumo seizure.Although design Limits might be exceeded, the onsequences are found to be tolerable in all cases even if any one protection circuit failed to per orm its function.-3.Z PROTECTION SYSTRf DESCRIPTION erous reactor trf.p circuits provide core protection for a Loss of flow~c-"ident.
These trips are: reactor'oolant f low, Reactor coolant pump bus Low voltage, Reactor coolant pump bus Low frequency, Reactor coolant pump bx'esker position, Overpower Delta-T.5.3-L


pan.TTacepoarossoppcaeATcanuuSERFlcuacS.I-IAUTQtATIC CONTROFAULTELECTRICAL fhULTLOSSOff.M.SUCTION2/>Hl.LEVELCLOSESF.M.VLVIHCOHPLETE S.leSIGQ-H$R.T.IRQQIHIHGF.MoMHAN~f.M.VALVECLOSEEICONTROLfAULTILOOPLOSSOfCOOIAHFFLOVRE-REACTORATBILLPOllERS.CEN.LEVELCONTROLLER fAULORRFACIORATRE-DUCIDFOlXRTNFROFERcxTeINCONTROLLER IPLPIPL.O.F.M.-(ELEC.FAULT)4EV.RUSFAILUREONESUSLOSSOFCOH-OENSATEtUHPSORI~lieSSOFHTR.DRABfLBPLO.SIN.fLOMRlfEEDBOllCTOHTOHHILEVELINDICA-TION(R,t.S.)AILUREOFCOH-EHSATERYPASSAbbaEVIATIONSfAILURECONDITION R.T.-REACTORTaitS.l.-,SAfETTIHIECTION R.t.S.-REACTORPROTECTION STSTEHf.M.-FEEDMATER Aaf.M.S.-AUXILIARY f.M.STARTfIGURE5.2-2,  
percept f or the overpower Delta-T trip, all trips are blocked below 10X power.Low Reactor Coolant Flow Three redundant flow channels are provided for each loop.At high power, loss of flow in any loop, as sensed by two of the three channels, actuates a reactor trip.The set point for this trip is typically at 90X of normal indicated flow.At lower power (typically 50X, 65X, and 75X for 2, 3, and 4-loop plants respectively) loss of flow in any two loops actuates trip.The same flow set point and 2/3 logic is used as for the single loop low flow trip.Reactor Coolant Pump Low Volta e In order to insure that total loss of pump power does not violate the core design limits, a reactor trip is actuated by low voltage on thy, reactor I coolant pump buses.The design requirement is to meet the single-failure criterion for complete loss'of pump power.The trip logic is generally such that loss of power on any two buses causes a reactor trip.Typical set points for this trip are in the range of 60X to 80X~of normal voltage.Reactor Coolant Punm Low Fre uenc The reactor coolant pumps are provided with flywheels to increase their rotating inertia.This provides forced circulation for some period of time after a loss of power.It is conceivable that a rapid system fre-quency decrease would slow the pumps down faster than for a loss of power.5.3-2
~~FAULTTREEPORLOSSOFPEEDWATER PLOWSEEFIGURE5.2-1STATIONBLACKOUTWITHLOSSOFPEEDSTM.GEN.LO-LOLEVELA.F.W.S.LOSSOPLEVELINSTM.GEN.F.WPUMPBKR.MOTORA.F.WS4KVUNDERVOLT STEAMA.F.WS.(LOSSOPREACTORCOOLANTFMWREQUIRES2963)IATE REACTORTRIP)COMPLETELOSSOF4RVSYMBOLSABBREVIATIONS F.W.-PEEDWATERA..P.W.S.
-AUXILIARY P.W.STAR]FIGURE5.2-3 ltFF LEVELRESPONSETOLOSSOFSTER%ANSIGNALPROP+INTEGRALK+-11SPROP+INTEGRALK+-12TSPHEOMATIC POSITIONER POSITIONW8QfQNORMALIZED STEhKFLOQ8QfNOHHAIZZED PEEDWATER PLOW-1K<<1feT-200sec1K~10T~200sec22l~~-"FEED%TERVALVE~POLLYOPEN~~~]~~~~4~-~~~--I-I~~1010202030~,SECONDS3040405050'060~~~~~~~~I'~~W~~~~~I.~~oFZGaaE5.2-4 LOSSOFFEEDQATER TOONESTEAMGENERATOR ATT~ONESECONDTYPXCALTWO-LOOPPLANT260022001800~W~It=LL:~t1400~~800600400~t~~~PRESSURIZER
.LEVELHEACTORTRXP-'~t200'25,,dao~~50,0025,Oej~~4~~~~4080120160200MME,SECONDSFIGURE5.2-5 LOSSOFFEEDWATER TOONESTEhHGENERATOR ATT~ONESECOND"640:".I:~lI~E~~~IA.~I~'I620"..:.:-:.-.~~~-:600~~~~~E"'3'-'-=580~~:~~500540.L--..:4.P'::
ll=.S'5001.0.8-COEE~-POWER'-:=..~.6i-.:)"&#x17d;TOTALGEN.~204080120160200~,SECONDSFIGURE52-6 l~
'te'e00F0050003.02e52.0200100ga00Q2IPLETELOSSOFPEEDWATER
<<~~I~~I~~~~Ieeei!i~:..i'.I~~I~II~I>>~e~~~'I~~5001000TIMESECONDS1500I~Ir~~I,t':I~~~('I~I::::J<<i~~I.<<nI..~::~(r'i:..('I~.I~'I'~~I~e~e~I.~eI~eI~I.eI'00TIMESECOR)S5001500STEhMPLOW'TOPRESSURIZER
~II(iWhTERBKZEFjIe(*'STEhMRELIEFIHSBOILIHG.COHDENSATZOS
~HZPRESSTRZP-'KCEIESBOILS~:...II....j;-.-:i:<<;';;,II-:;:-'-'I'<<'U-
~e0'0001500~~:~II:4J<<~::.i.-.~~10.:::.."::LIIIIt~~:-BOTLTHGf~WhTERR1KXEF::.-.;hei~.:.'"::.:.ll'.
Ig~i'.I:.III."Ie.I~.~iII(:-:~~,"".,:hIEZLZhRT PEH"'HsSRSi:II.':j~e10005001500TIMEAFZERLOSSOFPEED,SECONDSPIGUBE527 CQHFLEZELOSSOFPEEDWATEK
~+o600)$5005001000-1500TZHE,SECONDS10QOla8QQ6QQ.'0gQQQ0500100015002000TIME,SECONDS AUXILIARY FEHNATERSYSTEMSCHEMATIC 2LOOPPLANTMotorOperatedValveMPneumatica11y LO.LockedOpenOperatedValveManualValve(normally open)I,~MOTOROPERAL~CHECKVALVESTOPCHECKVALVECondensate StorageTankManualValve(normally closed)~PromAlternate WaterSupply(CLASSI)CLASSIXiCLASSIL0.LOL.O.MotorDriveTurbinefDriveMotorDrivePromMainPeedwater SystemSGB-"romMainPeedwater SystemFIGURE5.29 4*
OSSOFCOOT~i-~OWANALYSISLOINTRODUCTIO&#xc3;
~SDSUMMARYc~3~Ithereactoris~thepowerrangeofoperation, lossofcoolantfloweatentepotential conce-n.Withoutsufficientflow,DNBandcladfailure~dquicklyoccur.estinghouse PWR's,constant-speed pumpssupplycoolantflow.Plowisegulatedorotherwise varied.High-inertia flywheels aremountedoneach.sothatflowdec=eases ovex'periodoftime(typically 12secondstofflow)following alossofpowertothepumpmotor.Thisflowcoast-ioMnallowsforProtection SystemtMedelaysandremova1ofstoredheatinxbefueL.Subsequent decayheatisremovedbynaturalcirculation.
Diverse,redundant protection circuitsareprovidedtoprotectagainstallpossiblelossofflowaccidents.
Theseprotection circuitsaxeevaluated thisreportformultiloop lossofflow,singlelooplossof;flow,and~othetical pumoseizure.AlthoughdesignLimitsmightbeexceeded, theonsequences arefoundtobetolerable inallcasesevenifanyoneprotection circuitfailedtoperormitsfunction.
-3.ZPROTECTION SYSTRfDESCRIPTION erousreactortrf.pcircuitsprovidecoreprotection foraLossofflow~c-"ident.
Thesetripsare:reactor'oolant flow,ReactorcoolantpumpbusLowvoltage,ReactorcoolantpumpbusLowfrequency, Reactorcoolantpumpbx'eskerposition, Overpower Delta-T.5.3-L


perceptfortheoverpower Delta-Ttrip,alltripsareblockedbelow10Xpower.LowReactorCoolantFlowThreeredundant flowchannelsareprovidedforeachloop.Athighpower,lossofflowinanyloop,assensedbytwoofthethreechannels, actuatesareactortrip.Thesetpointforthistripistypically at90Xofnormalindicated flow.Atlowerpower(typically 50X,65X,and75Xfor2,3,and4-loopplantsrespectively) lossofflowinanytwoloopsactuatestrip.Thesameflowsetpointand2/3logicisusedasforthesinglelooplowflowtrip.ReactorCoolantPumpLowVoltaeInordertoinsurethattotallossofpumppowerdoesnotviolatethecoredesignlimits,areactortripisactuatedbylowvoltageonthy,reactorIcoolantpumpbuses.Thedesignrequirement istomeetthesingle-failure criterion forcompleteloss'ofpumppower.Thetriplogicisgenerally suchthatlossofpoweronanytwobusescausesareactortrip.Typicalsetpointsforthistripareintherangeof60Xto80X~ofnormalvoltage.ReactorCoolantPunmLowFreuencThereactorcoolantpumpsareprovidedwithflywheels toincreasetheirrotatinginertia.Thisprovidesforcedcirculation forsomeperiodoftimeafteralossofpower.Itisconceivable thatarapidsystemfre-quencydecreasewouldslowthepumpsdownfasterthanforalossofpower.5.3-2  
Therefore, an undhrfzequency reactor tirp is provided.The trip logic is identical to that used fox the undexvoltage reactox trip.In addition to tripping the reactor, underfxequency also trips open the reactor coolant Pump circuit breakers to maintain effective flywheel inertia.Typical setpoints for this txip are in the range of 56-58 cps.p Circuit Breaker Position A reactor trip dezived from auxiliary contacts on the reactor coolant pump circuit breaker affords additional safety mazgin for the most Likely causes of loss of flow.Trip logic is shear to that used fox the low flow'rip;i.e., opening of any breaker, as indicated by a position contact, actuates a zeactor trip at high power, and opening of any two breakers at reduced power actuates a trip.Ove ower Delta>>T Reactor Tri This trip circuit is designed to protect the core against overpower transients.
However,since Delta>>T increases as flow decreases, it also provides backup protection for loss of flow accidents.
On a two-loop plant, two Delta-T channels per loop are pxovided;one channel per loop U provided on thx'ee-and four-loop plants.For aLL plants, trip of two channels trips the reactor.During steady-state operation, the trip set-Point for these channels is in the range of llOX to 120X of the normal Delta-T indicated at full power.This setpoint is automatically reduced<<r increasing temperature (x'ate of change of T)to compensate for piping avg delays.(However, the setpoint is not increased for decreasing T.)Since avg also increases following a loss of flow accident, the Delta-T set-avg 5.3-3 4@i'4.a*A'4" po oint decreases at.the same time as Delta-T increases.
This significantly decreases the trip delay time.ggarlacks
~cept for the overpower Delta-T reactor trip, the loss of flow protection trips are blocked at low power.This interlock is in itself redundant and diverse, in that the trip signal is passed.if either 2/4 nuclear channels indicate above 10X or if 2/2 turbine load signals indicate above 10X.Single loop loss of flow trips from low flow and circuit breaker position are blocked at reduced power.(The trip is passed if 2/4 nuclear channels indicate above a preset, power.)Since these two trips share a common, nonMiverse interlock, they should not be considered as.completely diverse protection functions.
5.3.3 MULTILOOP LOSS OF FLOW I A fault tree for a multi-loop loss of flow accident is shown, on Figure 5.3-1.Only electrical faults can cause all pumps to fail simultaneously, and the undervoltage and underfrequency reactor trips provide direct protection against these faults.The low flow reactor trip circuits provide backup protection for this accident, and they do not necessarily insure a minimum DNB ratio greater than 1.30.Figure 5.3-4 illustrates the transient resulting from a complete loss of flow accident representative of high power density plants currently under design.The solid lines represent the design case, with reactor trip on undervoltage.
The dashed lines illustrate the calculated transient if this reactor trip is neglected.
5.3-4 alculations are done by standard design methods, with the usual~ese ca c tions for safety analysis;e.g., the most adverse steady-state sssump<<opera rating conditions at the time of trip.accident is relatively rapid, with a DNB ratio of 1.3 in..the hot~e acc channel reached in about two seconds.It is not appropriate, therefore, gp assum ssume any manual corrective action.Also, the minimum DNB ratio is reached at the time the hot spot heat f lux begins to decrease.There is little transient overshoot except for reactor trip time delays.The undervoltage trip ii the design protection for this accident, and it meets the requirement that, the minimum DNB ratio does not fall below 1.30.Less restrictive requirements would be imposed on a backup trip.A minimum allowable DNB ratio of 1.0 in the hot assembly, could be selected on the basis that this would insure that core damage, if it occurred at, all, would be limited to a very small fraction of the coze.(The peaking factors in the hot assembly are essentially those in the hot channel gthout al1owance for engineering subfactors.)
Alternately, a hot-spot clad melting limit could be imposed for this accident on the backup protection.
With either requirement, Protection System diversity exLsts.The low flow reactor trip point is reached at 1.8 seconds, assaying a 3Z error in the set point (trip point at 87X flow).Although the hot channel minimum DNB ratio is somewhat below 1.3, the hot assembly minimum DNB ratio is still well above 1.0.If DNB should occur at the>>t spot, the transition boiling correlation'ndicates that peak clad temperature would be in the neighborhood of 1000'F, and no clad damage is expected.(See results for single 1oop loss of flow.)5.3-5 Ne De ta-e D lta-T transient is calculated for this case.Because of piping~d instrume trument delays a trip signal would not be generated until about gecon nds after the loss of flow.The effect of rate compensation on is to reduce the trip set point.Even with this longer trip delay, ave die pea ak clad temperature is not expected to exceed 1500'F, we11 below<he melting point.Therefore, three levels of protection exist for a~nltiloop loss of flow accident..
5.3,4 SINGLE LOOP LOSS OF FLOE A Eault tree for a single loop loss of flow accident is shown on Figure 5.3-2.Vote that loss of power to one bus is the only credible way this accident can occur without an immediate trip from the pump circuit breaker.{An open circuit in the pump motor is a highly unlikely fault, and is shown r Eor the sake of completeness.)
The circuit breaker trip is therefore classed as a backup, or anticipatory, trip.I Figure 5.3-5 illustrates the transient resulting from a single-loop loss ot flow accident in a high-power density, two-loop plant.The transient h is less severe in a three or four-loop plant.The low-flow reactor trip is the design protection for this accident,<nd it meets the design requirement of minimum hot channel DNB ratio uo less than 1.30.If the accident is caused by loss of bus voltage, and no credit is taken Eor the low flow reactor trip, the hot channel DNB ratio would be less than 1.3.However, a reactor trip on high Delta-T would terminate the 5.3-6 icc ident before 18B occurs in a significant percentage of the core.pssumI sag that the hot spot goes into DNB at the time the hot spot DNB rat o+t j o is L.30, and assigning a conservative additional instrument delay of p 9 sec to the Delta-T trip, a peak hot spot clad temperature (on the inner clad surface)of appro~tely 1300'F is calculated using a transition boiling correlation.
Only the Delta-T transient for the active loop is shown on Figure 5.3-5.S For the dead loop, Delta-T increases somewhat more rapidly.On a two-loop plant, two Delta-T channels exist on each loop, so a reactor trip is expected earlier than is shown.Ia summary: For a single loop loss of flow accident, Protection System ddversdty does seder.At least tso, and generally three, dndspendent levels of protection exist.5.3.5 LOCKED ROTOR ACCIDENT The hypothetical'case of an instantaneous pump seizure.has been'evaluated
<o determine whether diversity exists.The fault tree is shown on Figure 5.3-3.If this accident occurs when the reactor is at high power, the core design limits are exceeded independent of any protective action.The design requirement for this accident is to prevent any consequential failure of<he Reactor Coolant System.Failure could be caused by high system pressure.Also, systems calculations cannot be done with confidence if gross core damage occurs.For this reason, core conditions are evaluated.
5.3-7 The transient for a hypothetica1 locked rotor accident is shown on Figure 5.3-6..Flow through the Reactor Coolant System is rapidly reduced, Leading to a reactor trip on a low-flow signal.Following the trip, heat stored in the fuel rods continues to pass into the core coolant, causing the coolant to expand.At the same time, heat transfer to the shell side p f the steam generator is reduced, f irst because the reduced f low resuLts in a decreased tube side film coefficient and then because the reactor coolant, in the tubes cools down while the shell side temperature increases (turbine steam flow is reduced to zero upon plant trip).The rapid expansion of the coolant in the reactor core, combined with the reduced heat transfer in the steam generator, causes an insurge into the pressurizer and a pressure increase throughout the Reactor Coolant System.The insurge into the pressurizer compresses the steam volume, actuates the automatic Spray System, opens the power~perated relief valves, and opens the pressurizer safety vaLves, in that sequence.The two power-'operated relief valves are designed for reLiable operation and would be expected to function properly during the accident.However, for conservatism, their pressure-reducing effect is not included in the analysis.With no protection, a peak reactor coolant pressure of approximately 3050 psia would be reached about.3.5 seconds after the pump seizes.After this time, fluid, mixing and increased heat transfer in the active steam generator tend to reduce the pressurizer surge rate, and the pressurizer safety valves reduce pressure.(During the peak, the pressurizer surge rate may slightly exceed the pressurizer safety valve capacity, but pressurizer pressure does not significantly exceed the safety valve set 5.3-8 lus aU.owance for accumulation.)
Although the normal code-allowable
><assure p Us pressure o of 2750 psia is exceeded foz this accident, the peak pressure is below t e u he ultimate strength of all members of the Reactor CooLant System by an approx a ximate factor of two.Therefore, the Reactor Coolant System would z'ega jn intact o In the core, clad melting at the.hot spot inner clad surface begins at.24 seconds.Af ter this time, system calculations are uncertain.
The reactor trip set.point for the redundant low flow instrumentation on the affected loop is reached within 0.1 seconds.Assuming DNB at 0.1 seconds, and.a conservative trip delay (2 seconds befoze the nuclear flux is reduced to 80X), the peak clad temperature is approximately 1%0'P and is reached at 4.5 seconds.Other calculated results for this case are peak system pressure of 2800 psia and less than 20K of the fuel.rods with a k calculated DNB ratio of 1.0 or less.Neglecting this trip, a high pressurizer pressure trip point would be C reached at about 1.5 seconds,'nd a high Delta<<T trip (from the active loop)would be reached at about 4.5 seconds.The peak clad temperature for these cases would be 1750 and 1950 for the high pressure and high Delta>>T trips respectively.
Since these values are well below the melting point, no gross cLad failure is expected.In summary: For the hypothetical locked rotor accident, core design Limits may be exceeded.However, three independent, diverse levels of protection exist, any of which would insure that the Reactor Coolant System boundary is not violated.5.3-9 FAULT TREE FOR MULTZLOOP LOSS OF FLOW PROBABLE GROSS CORE DAMAGE SLS HI 4T R.T.COND XTIO POSSIBLE CORE DAMAGE FAXL'ORE LOW PLOW R.T.L.O;F.-LOSS OF FLOW R.T.-REACTOR TRIP R.C.P.-REACTOR COOLANT PUMP DESIGN CORE LIMITS EXCEEDED (DNBR<1.30)REACTOR.AT HXGH~~POWER~ALL LOOP L.O.F.WXTH NO IMMEDIATE R.T OR UNDER VOLTAGE R T.BKR.OPEN R.T.LOW FREQUEHCY ON ALL BUSES SIMULTANEOUS LOSS OF POWER SIMULTANEOUS R.C.P.BKR.OPTING."IGURE 5.3-1


Therefore, anundhrfzequency reactortirpisprovided.
FAULT TREE IOR SIICLE UM)t lOSS OF FMQ tRObhhLK CROSS CORE NHhCI CONDITION Nl AT R.T.CORK DKSICN LINITS KICKKDKD UN FLON R>>T>>.L>>O>>F~MSS OF FLON R>>T>>~REACTOR IRIt R>>C>>t ii RKACFOR COOIANT FUNt CORK DNSR>>l 3 hfACIOR AT RICiR FOMER'llCLE LOOt L>>O>>NO INNKDIA (I)REACTOR'NOFFKTION SISTIIl (2)ELECTRICAL thOFKCTION STETS)I SINCLE UXlt R C FAULT lAl5$OF bUS PARR SKR OFKN R>>E, (I)SUS FAULT IO ntKN SKR.a TSKF AKD SKR IO OPENS TRIP!KACIOR (2)R>>C>>P>>bKR>>Ot INC IC>>P>>OPEN CKT>>R>>C>>t>>QIORT CKT SUS FAULT PI&et$3>>>>2
Thetriplogicisidentical tothatusedfoxtheundexvoltage reactoxtrip.Inadditiontotrippingthereactor,underfxequency alsotripsopenthereactorcoolantPumpcircuitbreakerstomaintaineffective flywheelinertia.Typicalsetpoints forthistxipareintherangeof56-58cps.pCircuitBreakerPositionAreactortripdezivedfromauxiliary contactsonthereactorcoolantpumpcircuitbreakeraffordsadditional safetymazginforthemostLikelycausesoflossofflow.Triplogicissheartothatusedfoxthelowflow'rip; i.e.,openingofanybreaker,asindicated byapositioncontact,actuatesazeactortripathighpower,andopeningofanytwobreakersatreducedpoweractuatesatrip.OveowerDelta>>TReactorTriThistripcircuitisdesignedtoprotectthecoreagainstoverpower transients.
~q I I i FAULT TREE FOR LOCKED ROTOR ACCIDENT PROBABLE GROSS CORE DAMAGE HI dT R.T.HI PRESSURE R.T.PROBABLE CORE DAMAGE LOW FLOW R.T.CORE DESIGN LIMITS EXCEEDED SYMBOLS CONDITIO REACTOR AT HIGH POWER R.C.P.MECHANI FAIISRE (LOCKED ROTOR)R.T.-REACTOR TRIP R.C.P.-REACTOR COOLANT PUMP FIGURE 5.3-3 h Pt~>a' Es KULTI~P LOSS OP PLOW, TYPIChL PL@K'I~t 80 a 70 60 50 CORE FLOW PO NUCLEhR POWER{meZRVOLTaCZ ,TRIP)HOT SPOT HKLT FLUX'UNDEKVOLThaK lzazH..,pe~I~a: t I l.6 HOT ASSMLY'--MXH.DHB RATIO=)i I()~fe~J 1.2 L00 0 100 90 SIC LOOP LOSS OP Kl&#xc3;2-UNp MT 80~0 70 OW DEAD: LOOP 50 1.8:.:.i HIM.DMS RATIO j~I~1.4 ROT ASSZ8BLY-1.0 1400 1200 NO TRIP aoo TRXP ON LOW PLOW~*I*~\120 u.p DELTh T TRXP POISE HX 4T-=-...TRZP.~NO TRIP~~~~I~100 (ACTIVE LNP-TRZP PolllT 0 1 2'3 4 5 6 7 8 9 10~jj&la'e ht TPVr tmTP C 0 C  
However,sinceDelta>>Tincreases asflowdecreases, italsoprovidesbackupprotection forlossofflowaccidents.
Onatwo-loopplant,twoDelta-Tchannelsperlooparepxovided; onechannelperloopUprovidedonthx'ee-andfour-loop plants.ForaLLplants,tripoftwochannelstripsthereactor.Duringsteady-state operation, thetripset-PointforthesechannelsisintherangeofllOXto120XofthenormalDelta-Tindicated atfullpower.Thissetpointisautomatically reduced<<rincreasing temperature (x'ateofchangeofT)tocompensate forpipingavgdelays.(However, thesetpointisnotincreased fordecreasing T.)Sinceavgalsoincreases following alossofflowaccident, theDelta-Tset-avg5.3-3 4@i'4.a*A'4" poointdecreases at.thesametimeasDelta-Tincreases.
Thissignificantly decreases thetripdelaytime.ggarlacks
~ceptfortheoverpower Delta-Treactortrip,thelossofflowprotection tripsareblockedatlowpower.Thisinterlock isinitselfredundant anddiverse,inthatthetripsignalispassed.ifeither2/4nuclearchannelsindicateabove10Xorif2/2turbineloadsignalsindicateabove10X.Singlelooplossofflowtripsfromlowflowandcircuitbreakerpositionareblockedatreducedpower.(Thetripispassedif2/4nuclearchannelsindicateaboveapreset,power.)Sincethesetwotripsshareacommon,nonMiverse interlock, theyshouldnotbeconsidered as.completely diverseprotection functions.
5.3.3MULTILOOP LOSSOFFLOWIAfaulttreeforamulti-loop lossofflowaccidentisshown,onFigure5.3-1.Onlyelectrical faultscancauseallpumpstofailsimultaneously, andtheundervoltage andunderfrequency reactortripsprovidedirectprotection againstthesefaults.Thelowflowreactortripcircuitsprovidebackupprotection forthisaccident, andtheydonotnecessarily insureaminimumDNBratiogreaterthan1.30.Figure5.3-4illustrates thetransient resulting fromacompletelossofflowaccidentrepresentative ofhighpowerdensityplantscurrently underdesign.Thesolidlinesrepresent thedesigncase,withreactortriponundervoltage.
Thedashedlinesillustrate thecalculated transient ifthisreactortripisneglected.
5.3-4 alculations aredonebystandarddesignmethods,withtheusual~esecactionsforsafetyanalysis; e.g.,themostadversesteady-state sssump<<operaratingconditions atthetimeoftrip.accidentisrelatively rapid,withaDNBratioof1.3in..thehot~eaccchannelreachedinabouttwoseconds.Itisnotappropriate, therefore, gpassumssumeanymanualcorrective action.Also,theminimumDNBratioisreachedatthetimethehotspotheatfluxbeginstodecrease.
Thereislittletransient overshoot exceptforreactortriptimedelays.Theundervoltage tripiithedesignprotection forthisaccident, anditmeetstherequirement that,theminimumDNBratiodoesnotfallbelow1.30.Lessrestrictive requirements wouldbeimposedonabackuptrip.Aminimumallowable DNBratioof1.0inthehotassembly, couldbeselectedonthebasisthatthiswouldinsurethatcoredamage,ifitoccurredat,all,wouldbelimitedtoaverysmallfractionofthecoze.(Thepeakingfactorsinthehotassemblyareessentially thoseinthehotchannelgthoutal1owance forengineering subfactors.)
Alternately, ahot-spotcladmeltinglimitcouldbeimposedforthisaccidentonthebackupprotection.
Witheitherrequirement, Protection Systemdiversity exLsts.Thelowflowreactortrippointisreachedat1.8seconds,assayinga3Zerrorinthesetpoint(trippointat87Xflow).AlthoughthehotchannelminimumDNBratioissomewhatbelow1.3,thehotassemblyminimumDNBratioisstillwellabove1.0.IfDNBshouldoccuratthe>>tspot,thetransition boilingcorrelation'ndicates thatpeakcladtemperature wouldbeintheneighborhood of1000'F,andnocladdamageisexpected.
(Seeresultsforsingle1ooplossofflow.)5.3-5 NeDeta-eDlta-Ttransient iscalculated forthiscase.Becauseofpiping~dinstrumetrumentdelaysatripsignalwouldnotbegenerated untilaboutgeconndsafterthelossofflow.Theeffectofratecompensation onistoreducethetripsetpoint.Evenwiththislongertripdelay,avediepeaakcladtemperature isnotexpectedtoexceed1500'F,we11below<hemeltingpoint.Therefore, threelevelsofprotection existfora~nltiloop lossofflowaccident..
5.3,4SINGLELOOPLOSSOFFLOEAEaulttreeforasinglelooplossofflowaccidentisshownonFigure5.3-2.Votethatlossofpowertoonebusistheonlycrediblewaythisaccidentcanoccurwithoutanimmediate tripfromthepumpcircuitbreaker.{Anopencircuitinthepumpmotorisahighlyunlikelyfault,andisshownrEorthesakeofcompleteness.)
Thecircuitbreakertripistherefore classedasabackup,oranticipatory, trip.IFigure5.3-5illustrates thetransient resulting fromasingle-loop lossotflowaccidentinahigh-power density,two-loopplant.Thetransient hislesssevereinathreeorfour-loop plant.Thelow-flowreactortripisthedesignprotection forthisaccident,
<nditmeetsthedesignrequirement ofminimumhotchannelDNBratiouolessthan1.30.Iftheaccidentiscausedbylossofbusvoltage,andnocreditistakenEorthelowflowreactortrip,thehotchannelDNBratiowouldbelessthan1.3.However,areactortriponhighDelta-Twouldterminate the5.3-6 iccidentbefore18Boccursinasignificant percentage ofthecore.pssumIsagthatthehotspotgoesintoDNBatthetimethehotspotDNBrato+tjoisL.30,andassigning aconservative additional instrument delayofp9sectotheDelta-Ttrip,apeakhotspotcladtemperature (ontheinnercladsurface)ofappro~tely 1300'Fiscalculated usingatransition boilingcorrelation.
OnlytheDelta-Ttransient fortheactiveloopisshownonFigure5.3-5.SForthedeadloop,Delta-Tincreases somewhatmorerapidly.Onatwo-loopplant,twoDelta-Tchannelsexistoneachloop,soareactortripisexpectedearlierthanisshown.Iasummary:Forasinglelooplossofflowaccident, Protection Systemddversdty doesseder.Atleasttso,andgenerally three,dndspendent levelsofprotection exist.5.3.5LOCKEDROTORACCIDENTThehypothetical'case ofaninstantaneous pumpseizure.hasbeen'evaluated
<odetermine whetherdiversity exists.ThefaulttreeisshownonFigure5.3-3.Ifthisaccidentoccurswhenthereactorisathighpower,thecoredesignlimitsareexceededindependent ofanyprotective action.Thedesignrequirement forthisaccidentistopreventanyconsequential failureof<heReactorCoolantSystem.Failurecouldbecausedbyhighsystempressure.
Also,systemscalculations cannotbedonewithconfidence ifgrosscoredamageoccurs.Forthisreason,coreconditions areevaluated.
5.3-7 Thetransient forahypothetica1 lockedrotoraccidentisshownonFigure5.3-6..FlowthroughtheReactorCoolantSystemisrapidlyreduced,Leadingtoareactortriponalow-flowsignal.Following thetrip,heatstoredinthefuelrodscontinues topassintothecorecoolant,causingthecoolanttoexpand.Atthesametime,heattransfertotheshellsidepfthesteamgenerator isreduced,firstbecausethereducedflowresuLtsinadecreased tubesidefilmcoefficient andthenbecausethereactorcoolant,inthetubescoolsdownwhiletheshellsidetemperature increases (turbinesteamflowisreducedtozerouponplanttrip).Therapidexpansion ofthecoolantinthereactorcore,combinedwiththereducedheattransferinthesteamgenerator, causesaninsurgeintothepressurizer andapressureincreasethroughout theReactorCoolantSystem.Theinsurgeintothepressurizer compresses thesteamvolume,actuatestheautomatic SpraySystem,opensthepower~perated reliefvalves,andopensthepressurizer safetyvaLves,inthatsequence.
Thetwopower-'operated reliefvalvesaredesignedforreLiableoperation andwouldbeexpectedtofunctionproperlyduringtheaccident.
However,forconservatism, theirpressure-reducingeffectisnotincludedintheanalysis.
Withnoprotection, apeakreactorcoolantpressureofapproximately 3050psiawouldbereachedabout.3.5secondsafterthepumpseizes.Afterthistime,fluid,mixingandincreased heattransferintheactivesteamgenerator tendtoreducethepressurizer surgerate,andthepressurizer safetyvalvesreducepressure.
(Duringthepeak,thepressurizer surgeratemayslightlyexceedthepressurizer safetyvalvecapacity, butpressurizer pressuredoesnotsignificantly exceedthesafetyvalveset5.3-8 lusaU.owance foraccumulation.)
Althoughthenormalcode-allowable
><assurepUspressureoof2750psiaisexceededfozthisaccident, thepeakpressureisbelowteuheultimatestrengthofallmembersoftheReactorCooLantSystembyanapproxaximatefactoroftwo.Therefore, theReactorCoolantSystemwouldz'egajnintactoInthecore,cladmeltingatthe.hotspotinnercladsurfacebeginsat.24seconds.Afterthistime,systemcalculations areuncertain.
Thereactortripset.pointfortheredundant lowflowinstrumentation ontheaffectedloopisreachedwithin0.1seconds.AssumingDNBat0.1seconds,and.aconservative tripdelay(2secondsbefozethenuclearfluxisreducedto80X),thepeakcladtemperature isapproximately 1%0'Pandisreachedat4.5seconds.Othercalculated resultsforthiscasearepeaksystempressureof2800psiaandlessthan20Kofthefuel.rodswithakcalculated DNBratioof1.0orless.Neglecting thistrip,ahighpressurizer pressuretrippointwouldbeCreachedatabout1.5seconds,'nd ahighDelta<<Ttrip(fromtheactiveloop)wouldbereachedatabout4.5seconds.Thepeakcladtemperature forthesecaseswouldbe1750and1950forthehighpressureandhighDelta>>Ttripsrespectively.
Sincethesevaluesarewellbelowthemeltingpoint,nogrosscLadfailureisexpected.
Insummary:Forthehypothetical lockedrotoraccident, coredesignLimitsmaybeexceeded.
However,threeindependent, diverselevelsofprotection exist,anyofwhichwouldinsurethattheReactorCoolantSystemboundaryisnotviolated.
5.3-9 FAULTTREEFORMULTZLOOP LOSSOFFLOWPROBABLEGROSSCOREDAMAGESLSHI4TR.T.CONDXTIOPOSSIBLECOREDAMAGEFAXL'ORELOWPLOWR.T.L.O;F.-LOSSOFFLOWR.T.-REACTORTRIPR.C.P.-REACTORCOOLANTPUMPDESIGNCORELIMITSEXCEEDED(DNBR<1.30)REACTOR.ATHXGH~~POWER~ALLLOOPL.O.F.WXTHNOIMMEDIATE R.TORUNDERVOLTAGERT.BKR.OPENR.T.LOWFREQUEHCY ONALLBUSESSIMULTANEOUS LOSSOFPOWERSIMULTANEOUS R.C.P.BKR.OPTING."IGURE5.3-1


FAULTTREEIORSIICLEUM)tlOSSOFFMQtRObhhLKCROSSCORENHhCICONDITION NlATR.T.CORKDKSICNLINITSKICKKDKDUNFLONR>>T>>.L>>O>>F~MSSOFFLONR>>T>>~REACTORIRItR>>C>>tiiRKACFORCOOIANTFUNtCORKDNSR>>l3hfACIORATRICiRFOMER'llCLE LOOtL>>O>>NOINNKDIA(I)REACTOR'NOFFKTION SISTIIl(2)ELECTRICAL thOFKCTION STETS)ISINCLEUXltRCFAULTlAl5$OFbUSPARRSKROFKNR>>E,(I)SUSFAULTIOntKNSKR.aTSKFAKDSKRIOOPENSTRIP!KACIOR(2)R>>C>>P>>bKR>>OtINCIC>>P>>OPENCKT>>R>>C>>t>>QIORTCKTSUSFAULTPI&et$3>>>>2
LOCKED ROTOR, LOSS OP HOW 2 LOOP PLANT~~F00 SO I..i~~~ACTXVZ MOP I~~~~~*60~~CORE PL(M~~~I]JJ~~~~w~40 20 3000 zsoo~~DEAD LOOP':.l I~~~~>>~l-~~I~~~'I~I~~~~0 5'o S~6'.I'.~I OJ 2600 2400~~REACTOR f COOLANT SYSTEH PRESSURIZER
~qIIi FAULTTREEFORLOCKEDROTORACCIDENTPROBABLEGROSSCOREDAMAGEHIdTR.T.HIPRESSURER.T.PROBABLECOREDAMAGELOWFLOWR.T.COREDESIGNLIMITSEXCEEDEDSYMBOLSCONDITIOREACTORATHIGHPOWERR.C.P.MECHANIFAIISRE(LOCKEDROTOR)R.T.-REACTORTRIPR.C.P.-REACTORCOOLANTPUMPFIGURE5.3-3 hPt~>a' EsKULTI~PLOSSOPPLOW,TYPIChLPL@K'I~t80a706050COREFLOWPONUCLEhRPOWER{meZRVOLTaCZ
'NO TRIP LOP FL(N TRIP~~2200'0 3000~o~~~~~~TIHE, SECONDS\~2500 J~+>>~e f I~~~I II.I'I TIHE OF REACTOR.NO TRIP-=(SEC)2000 e 4 4 F500 H 2 lOQO 500~~~~~~~~l~i I I~%t~I L~~~\)~~~I~~'l I~~<<I I~I 2 TIHE AFTER PUHP SEIZURE, SECONDS 0
,TRIP)HOTSPOTHKLTFLUX'UNDEKVOLThaK lzazH..,pe~I~a:tIl.6HOTASSMLY'--MXH.DHBRATIO=)iI()~fe~J1.2L000 10090SICLOOPLOSSOPKl&#xc3;2-UNpMT80~070OWDEAD:LOOP501.8:.:.iHIM.DMSRATIOj~I~1.4ROTASSZ8BLY-1.014001200NOTRIPaooTRXPONLOWPLOW~*I*~\120u.pDELThTTRXPPOISEHX4T-=-...TRZP.~NOTRIP~~~~I~100(ACTIVELNP-TRZPPolllT012'345678910~jj&la'ehtTPVrtmTPC0C
ROD JUNCTION ANALYSIS ji4 INTRODUCTION AND


LOCKEDROTOR,LOSSOPHOW2LOOPPLANT~~F00SOI..i~~~ACTXVZMOPI~~~~~*60~~COREPL(M~~~I]JJ~~~~w~40203000zsoo~~DEADLOOP':.lI~~~~>>~l-~~I~~~'I~I~~~~05'oS~6'.I'.~IOJ26002400~~REACTORfCOOLANTSYSTEHPRESSURIZER
==SUMMARY==
'NOTRIPLOPFL(NTRIP~~2200'03000~o~~~~~~TIHE,SECONDS\~2500J~+>>~efI~~~III.I'ITIHEOFREACTOR.NOTRIP-=(SEC)2000e44F500H2lOQO500~~~~~~~~l~iII~%t~IL~~~\)~~~I~~'lI~~<<II~I2TIHEAFTERPUHPSEIZURE,SECONDS 0
5 4~zimary protection for a rod ejection accident is a reactor trip on~e pz~igh nuc h nuclear flux.The nuclear flux instzumentation is made up of four ce>p e letely separate sensors and channels, and reactor trip is actuated if any two channels indicate high power.Analysis has been conducted to r:.'.-e*t~~~=~vl~Ie determine the consequences of a hypothetical failure of all the nuclear channels coupled with a hypothetical rod ejection accident.Analysis, made on the basis of the Ginna Nuclear Plant of Rochester Gas a Electric Co.(RGB), indicate that in the majority of rod ejection cases no protection is required (for example, ejection of a zod from its normally-expected position).
RODJUNCTIONANALYSISji4INTRODUCTION ANDSUMMARY54~zimaryprotection forarodejectionaccidentisareactortripon~epz~ighnuchnuclearflux.Thenuclearfluxinstzumentation ismadeupoffource>peletelyseparatesensorsandchannels, andreactortripisactuatedifanytwochannelsindicatehighpower.Analysishasbeenconducted tor:.'.-e*t~~~=~vl~Iedetermine theconsequences ofahypothetical failureofallthenuclearchannelscoupledwithahypothetical rodejectionaccident.
It is further shown that the Delta-T trip provides I~, an acceptable second level of defense for some cases.However, protection can not be demonstrated for some of the more severe full power cases.Protection may in fact exist, but it is not possible to positively demonstrate this with the currently available models.An analysis of the available trip has been made, and is compared with an I arbitrary clad limit of 2750'F and an arbitrary pressure Vms of 3000'psi.Two detailed cases are presented:
: Analysis, madeonthebasisoftheGinnaNuclearPlantofRochester GasaElectricCo.(RGB),indicatethatinthemajorityofrodejectioncasesnoprotection isrequired(forexample,ejectionofazodfromitsnormally-expectedposition).
a severe case from zero power end of core life, and a moderate case from full power end of core life.No reactor trip has been assumed for either case.5.4.2 CASES CONSIDERED IN DETAIL Zero Power Case The case considered represents a zod ejection accident for an end of life core.The assumed ejected zod worth and hot channel factor aze 1.0X6k and 12.5 respectively.  
ItisfurthershownthattheDelta-TtripprovidesI~,anacceptable secondlevelofdefenseforsomecases.However,protection cannotbedemonstrated forsomeofthemoreseverefullpowercases.Protection mayinfactexist,butitisnotpossibletopositively demonstrate thiswiththecurrently available models.Ananalysisoftheavailable triphasbeenmade,andiscomparedwithanIarbitrary cladlimitof2750'Fandanarbitrary pressureVmsof3000'psi.
Twodetailedcasesarepresented:
aseverecasefromzeropowerendofcorelife,andamoderatecasefromfullpowerendofcorelife.Noreactortriphasbeenassumedforeithercase.5.4.2CASESCONSIDERED INDETAILZeroPowerCaseThecaseconsidered represents azodejectionaccidentforanendoflifecore.Theassumedejectedzodworthandhotchannelfactoraze1.0X6kand12.5respectively.  


~tingpowertransient andhotspottemperatures aredetailedin~~resultF5.4-1.1steadypowerlevelisconservatively assumedtobe15Xoffull~+finasThispowerlevelislowerthanthevaluewhichonemightnormally~er.~q)ectfozarodreactivity insertion of1.0<k>>owingtothehighfeedbackueigihtingfactors-{Thelargehotchannelfactorsresultsinalargepowern<einthehotspot,wherethestatistical weightishigh).Thepromptyzstresultsinareactivity undershoot which,combinedwiththeshortageofdelayedneutrons, temporarily fozcesthepowertoavaluebelowequilibrium condition.
~ting power transient and hot spot temperatures are detailed in~~result F 5.4-1.1 steady power level is conservatively assumed to be 15X of full~+fina s This power level is lower than the value which one might normally~er.~q)ect foz a rod reactivity insertion of 1.0<k>>owing to the high feedback ueig i hting factors-{The large hot channel factors results in a large power n<e in the hot spot, where the statistical weight is high).The prompt yzst results in a reactivity undershoot which, combined with the shortage of delayed neutrons, temporarily fozces the power to a value below equilibrium condition.
Thepowerlevelisassumedtorampupto15Xat5secondsaftere]ection>>
The power level is assumed to ramp up to 15X at 5 seconds after e]ection>>although calculations indicated that it would take much longer to reach this power level.The plotted hot spot temperatures indicate that equilibrium conditions can be sustained.
althoughcalculations indicated thatitwouldtakemuchlongertoreachthispowerlevel.Theplottedhotspottemperatures indicatethatequilibrium conditions canbesustained.
Zt is therefore concluded that no protection is required for this accident.Zn general, the ejected rod worths and hot channel factors arq lower for the beginning of life zero power cases, and therefore the consequences are expected to be, somewhat less severe.Full Power End of Life Case The case presented is for a rod ejection accident occurring at the end of core life with an e5ected rod worth of 0.336k and a hot channel factor of 3'3.The power transients and hot spot temperatures are detailed in Figure 5.4-2.The equilibrium power level is 112X of full power.5.4-2 0
Ztistherefore concluded thatnoprotection isrequiredforthisaccident.
k cladding temperature of 2950'F occurs some 50 seconds after ge pe Under equilibrium conditions, some 50X by volume of the hot ,ection 0]fuel is melted.A reactor trip'n overpower Delta-T occurs at 6~~c ue limiting clad temperature to about 2400'.This case represents recon s, evere accident, but is not intended to represent a limit.~<eve>~~lar rod ejection accident, occurring at the beginning of life, auld result in an equilibrium power level of about 12SX of full power,ith an equilibrium cladding temperature of the order 3100'F to 3200'F.5.4.3 BACK<<UP TRIP PROTECTION The most limiting cases occur at or near full power.The protection System is examined to determine under what circumstances a trip signal would terminate a rod ejection accident at full power.The results of the study are illustrated in Figure 5.4-3.The graph is a plot of total excess nuclear energy addition versus time.Steady full power operation results in a locus covering the hd~ontal axis.The nuclear flux trip is represented by a straight line of gradient 0.18,, corresponding to a power'level of 118X Note that this line is an upper and its position is in fact dependent on the power versus time shape.This is a general, but not important, effect for the lines plot~ed.A rise in nuclear power produces a pressure surge.However, the effect is attenuated by the heat transfer time constant, of the fuel (of the order of 4 seconds), and the possible relieving effect of the hole in the vessel head and relieving capacity of the power-operated relief valves.The high pressure trip could not be expected for any rod ejection accident.5.4-3 The high Delta-T trip furnishes a backup trip for any severe rod e)ection zcc cident.Except in the most severe cases, it Limits the clad temperatuxe pp]ess than 2750'F.Transport delays in the coolant loop delay the trip f or several seconds.Also plotted on the graph axe two arbitrary limit lines.They are respectively a clad Limit of 2750 F*and a Coolant System pressure of 3000 psi.Both these Limits have been arbitrarily selected and are not intended to represent I~I-.r pl~S physical Limits.A power burst of some six full power seconds at time zero results in both these 1lmits being reached some two to.three seconds I later.This is not a physically reliable condition for any Westinghouse reactor.Figure 5.4-4 shows the power transients for rod ejection accidents occurring at end of core life for various ejected xod worths.fr f t I 1+These Lines are based on stead~tate and transient hot channel factors of 3.23.5.4W j ZERO POWER EHD OF LIFE ROD EJECTION, NO TRIP&~~~HjjCLjj&R POjjE&VS~T2$=~1~~~I i.: A~~4~1.0X F~12.S"::?30 20 M~--EHERGT INPUT UP TO O.S SECONDS~1.70 F.P.S fact::.FPS: Full ot spo power seconds~'-9-&vmbols 6k: Change in reactiviey T.F: Total heat flux peald.ng or at h t 10~~~i~~~i~i&(&.=~::i I:.-:i i&~~~~&--~)&'i 0 2 4 6 8 10 12 14 16 TQK, SECONDS: HOT SPOT VS.TIHE=-"-.~~~4000: FUEL AVG.-I~~~L~e:::3Z&&":&&2000 1~-~~-~~~~~~~-.-::-.1008 0 4 6 S 10 12 14 16 18 TIME, SECONDS FIGURE S.4-1  
Zngeneral,theejectedrodworthsandhotchannelfactorsarqlowerforthebeginning oflifezeropowercases,andtherefore theconsequences areexpectedtobe,somewhatlesssevere.FullPowerEndofLifeCaseThecasepresented isforarodejectionaccidentoccurring attheendofcorelifewithane5ectedrodworthof0.336kandahotchannelfactorof3'3.Thepowertransients andhotspottemperatures aredetailedinFigure5.4-2.Theequilibrium powerlevelis112Xoffullpower.5.4-2 0
kcladdingtemperature of2950'Foccurssome50secondsaftergepeUnderequilibrium conditions, some50Xbyvolumeofthehot,ection0]fuelismelted.Areactortrip'noverpower Delta-Toccursat6~~cuelimitingcladtemperature toabout2400'.Thiscaserepresents recons,evereaccident, butisnotintendedtorepresent alimit.~<eve>~~larrodejectionaccident, occurring atthebeginning oflife,auldresultinanequilibrium powerlevelofabout12SXoffullpower,ithanequilibrium claddingtemperature oftheorder3100'Fto3200'F.5.4.3BACK<<UPTRIPPROTECTION Themostlimitingcasesoccuratornearfullpower.Theprotection Systemisexaminedtodetermine underwhatcircumstances atripsignalwouldterminate arodejectionaccidentatfullpower.Theresultsofthestudyareillustrated inFigure5.4-3.Thegraphisaplotoftotalexcessnuclearenergyadditionversustime.Steadyfullpoweroperation resultsinalocuscoveringthehd~ontalaxis.Thenuclearfluxtripisrepresented byastraightlineofgradient0.18,,corresponding toapower'level of118XNotethatthislineisanupperanditspositionisinfactdependent onthepowerversustimeshape.Thisisageneral,butnotimportant, effectforthelinesplot~ed.Ariseinnuclearpowerproducesapressuresurge.However,theeffectisattenuated bytheheattransfertimeconstant, ofthefuel(oftheorderof4seconds),
andthepossiblerelieving effectoftheholeinthevesselheadandrelieving capacityofthepower-operated reliefvalves.Thehighpressuretripcouldnotbeexpectedforanyrodejectionaccident.
5.4-3 ThehighDelta-Ttripfurnishes abackuptripforanysevererode)ectionzcccident.Exceptinthemostseverecases,itLimitsthecladtemperatuxe pp]essthan2750'F.Transport delaysinthecoolantloopdelaythetripforseveralseconds.Alsoplottedonthegraphaxetwoarbitrary limitlines.Theyarerespectively acladLimitof2750F*andaCoolantSystempressureof3000psi.BoththeseLimitshavebeenarbitrarily selectedandarenotintendedtorepresent I~I-.rpl~SphysicalLimits.Apowerburstofsomesixfullpowersecondsattimezeroresultsinboththese1lmitsbeingreachedsometwoto.threesecondsIlater.Thisisnotaphysically reliablecondition foranyWestinghouse reactor.Figure5.4-4showsthepowertransients forrodejectionaccidents occurring atendofcorelifeforvariousejectedxodworths.frftI1+TheseLinesarebasedonstead~tate andtransient hotchannelfactorsof3.23.5.4W jZEROPOWEREHDOFLIFERODEJECTION, NOTRIP&~~~HjjCLjj&R POjjE&VS~T2$=~1~~~Ii.:A~~4~1.0XF~12.S"::?3020M~--EHERGTINPUTUPTOO.SSECONDS~1.70F.P.Sfact::.FPS:Fullotspopowerseconds~'-9-&vmbols6k:Changeinreactiviey T.F:Totalheatfluxpeald.ngoratht10~~~i~~~i~i&(&.=~::iI:.-:ii&~~~~&--~)&'i0246810121416TQK,SECONDS:HOTSPOTVS.TIHE=-"-.~~~4000:FUELAVG.-I~~~L~e:::3Z&&":&&20001~-~~-~~~~~~~-.-::-.1008046S1012141618TIME,SECONDSFIGURES.4-1  


PULLPOWERENDOPLIFERODEJECTION, NOTRIPI~>~~:='UCLEAR POWERVS.TIME~leak0.33Pm'3~23Tr~~'i.-:L~SbaIIISk:ChangeinReactivity P:TotalHeatFluxPeakingFactorTqatHotSpot~.~45TIME,SECONDSting).~II~~rI~4sr,~~IIII~IHOTSPOTTEMPSULTURE VS+TZME':.-.-,:-
PULL POWER END OP LIFE ROD EJECTION, NO TRIP I~>~~:='UCLEAR POWER VS.TIME~leak 0.33 P m'3~23 T r~~'i.-: L~Sba III Sk: Change in Reactivity P: Total Heat Flux Peaking Factor T q at Hot Spot~.~4 5 TIME, SECONDS ting).~I I~~rI~4s r ,~~III I~I HOT SPOT TEMPSULTURE VS+TZME':.-.-,:-'Mel=--'-'-~~~PURL AVG I:~r~~~'"I~~~W M.:~..~'~..':'LAD OUT~T':.I:I~Ii~~IP'PEAK CLAD SURFACE TEMP.''--:~2950'P AT 50 SEC.50X (HY VOLUME)OF'cCL i'.." MELTS.V.~:.-..~-=-'i::!=-'i;:, i-.--'2 4 6 S 10 12 14 16 TIME, SECONDS PIGURI'.4-2 0 P e Full Power End of Life F~3.23 T xa~+\8 7 6 4 3 pi 2 C~8p~0 2 3 4 5 6 7 8 9 l0 TIME, SECONDS~~TOM OF SkFEXY GZHZTS AND TRIP POINTS'~<ROD EJECTION'ACCIDENTS, HO TRIP-represents the locus of points at which trio would terminate the accident represeecs laces ar sefery lfrsirs FULL POWER END OP LIPS ROB EHKTION WH33RK TRIP CO 4l 5 CD~CC3 CO~~C~2~~I 1~l 0 0 10.e 0.33 TIME, SECOHDS Wte: 0.4X Qc'represents a practical Bait:ar fuIl pcwer ceses.~ROD EJECTION ACCIDEHTS'QXXH N)THXP,'IGURE 5.4~
'Mel=--'-'-~~~PURLAVGI:~r~~~'"I~~~WM.:~..~'~..':'LADOUT~T':.I:I~Ii~~IP'PEAKCLADSURFACETEMP.''--:~2950'PAT50SEC.50X(HYVOLUME)OF'cCLi'.."MELTS.V.~:.-..~-=-'i::!=-'i;:,
I 0 LOSS OF STEAM LOAD 5,5.1 XNTRODUCTION AND SUHHARY Vp'<<,', loss of steam load may be caused by closing of the turbine stop valves, which norma21y follows a turbine trip signal;by closing of the turbine control valves following a rejection of electrical load;or by steam isolation following a Reactor protection System signal.The consequences
i-.--'246S10121416TIME,SECONDSPIGURI'.4-2 0P eFullPowerEndofLifeF~3.23Txa~+\87643pi2C~8p~023456789l0TIME,SECONDS~~TOMOFSkFEXYGZHZTSANDTRIPPOINTS'~<RODEJECTION'ACCIDENTS, HOTRIP-represents thelocusofpointsatwhichtriowouldterminate theaccidentrepreseecs lacesarseferylfrsirs FULLPOWERENDOPLIPSROBEHKTIONWH33RKTRIPCO4l5CD~CC3CO~~C~2~~I1~l0010.e0.33TIME,SECOHDSWte:0.4XQc'represents apractical Bait:arfuIlpcwerceses.~RODEJECTIONACCIDEHTS
<<of a loss of steam load are a rapidly increasing Steam System pressure and Reactor Coolant System temperature and pressure due to the loss of heat sink.Protection instrumentation is provided to immediately trip the reactor following a turbine trip signal.A.steam line isolation signal is normally accompanied by a safety infection signal and also results in a reactor trip.Following a re)ection of electrical load, a Steam Dump<<~"".%'ystem acts to prevent reactor trip by automatic steam dump to the con-, denser.(Up to 100X load rejection can be handled by some'planes-)Xf the load re)ection great1y exceeds the steam dump capacity, or if the Steam Dump System should fail to operate, a reactor trip may occur on high pressure.Redundant protective instrumentation and conservative design of pressure relief devices assures the safety of the plant for a large load rejection without recourse to Automatic Rod Control, Pressurizer Pressure Control, or Steam Dump Control Systems.5.5-1 In this report, the Protection System is examined to see if diverse px'o rotection exists for a complete loss of load without direct reactor trip.Diversity is found to exist to protect the Reactor Coolant System and reactor coxe.5.5.2 LOSS OF LOAD PROTECTION AND DESIGN CRITERIA The reactor is pxotected for loss of load by: a)Steam dump to'ondenser (actuated by the Contxol System)b)c)Pressurizer pressure relief (safety valves and powez~perated reLief valves)Steam System pressure relief (safety valves and power-operated relief.valves)')
'QXXHN)THXP,'IGURE 5.4~
Direct reactor trip (on turbine trip)e)High pressurizer-pressure trip f)Overtemperatuze 4T trip g)High pressurizer level trip.Steam D to Condenser The Steam Dump System acts automatically upon sensing a loss of load greater than a preset amount.The steam dump valves are then either modulated or tripped open until the Reactor Coolant System temperatuxe reaches the new programmed load reference temperature.
I0 LOSSOFSTEAMLOAD5,5.1XNTRODUCTION ANDSUHHARYVp'<<,',lossofsteamloadmaybecausedbyclosingoftheturbinestopvalves,whichnorma21yfollowsaturbinetripsignal;byclosingoftheturbinecontrolvalvesfollowing arejection ofelectrical load;orbysteamisolation following aReactorprotection Systemsignal.Theconsequences
The reactor power is reduced by control rod, insertion during this time.Zn case of a turbine trip or reactor trip, the steam dump is actuated and con-trolled on a preset uo-load reference temperatuze.
<<ofalossofsteamloadarearapidlyincreasing SteamSystempressureandReactorCoolantSystemtemperature andpressureduetothelossofheatsink.Protection instrumentation isprovidedtoimmediately tripthereactorfollowing aturbinetripsignal.A.steamlineisolation signalisnormallyaccompanied byasafetyinfection signalandalsoresultsinareactortrip.Following are)ection ofelectrical load,aSteamDump<<~"".%'ystem actstopreventreactortripbyautomatic steamdumptothecon-,denser.(Upto100Xloadrejection canbehandledbysome'planes-)
The Steam Dump Control System is described in Section 3.2.5.5-2 0
Xftheloadre)ection great1yexceedsthesteamdumpcapacity, oriftheSteamDumpSystemshouldfailtooperate,areactortripmayoccuronhighpressure.
t Pressurizer Pressure Relief The pressurizer safety valves are sized to match the maxfmnnn volumetric surge rate associated with a complete loss of load without steam dump or a direct reactor trip.This is not dependent on pxessurizer pressure control.The pressurizer safety valves therefore completely protect the Reactor Coolant System against ovexpressure, independent of the high pressure reactor trip.The relief valves are sized to prevent actuation of the high pressure trip when the steam dump and rod drive systems work, and the required steam reLLef is within the capacity of the Steam Dump System.Steam S stem Pressure Relief The Steam System safety valves pass 100Z of ma~man calculated turbine steam flow, at the safety valve set pressure plus accumulation.
Redundant protective instrumentation andconservative designofpressurereliefdevicesassuresthesafetyoftheplantforalargeloadrejection withoutrecoursetoAutomatic RodControl,Pressurizer PressureControl,orSteamDumpControlSystems.5.5-1 Inthisreport,theProtection Systemisexaminedtoseeifdiversepx'orotection existsforacompletelossofloadwithoutdirectreactortrip.Diversity isfoundtoexisttoprotecttheReactorCoolantSystemandreactorcoxe.5.5.2LOSSOFLOADPROTECTION ANDDESIGNCRITERIAThereactorispxotected forlossofloadby:a)Steamdumpto'ondenser (actuated bytheContxolSystem)b)c)Pressurizer pressurerelief(safetyvalvesandpowez~perated reLiefvalves)SteamSystempressurerelief(safetyvalvesandpower-operated relief.valves)')
This allows the plant to accept a 100Z load re]ection without reactor txip or steam dump without ovexpressurizing the Steam System..Xn addition, relief valves set to open at a lower pressure are also provided, and axe typically sized at about lOZ of the safety valve capacity.Direct Reactor Tri The most common cause of a loss of load is a turbine-generator trip.Zn the event of such a trip, the turbine stop valves close.A turbine 5.5-3 trip sensed bye 2/3 low auto-scop oil pressure or 2/2 stop valve closure results in a reactor trip if the reactor is at high power.The purpose o f these triPs is to mizdzMe the thermal transient snd steam dumP requirements for these relatively frequent plant transients.
Directreactortrip(onturbinetrip)e)Highpressurizer-pressuretripf)Overtemperatuze 4Ttripg)Highpressurizer leveltrip.SteamDtoCondenser TheSteamDumpSystemactsautomatically uponsensingalossofloadgreaterthanapresetamount.Thesteamdumpvalvesaretheneithermodulated ortrippedopenuntiltheReactorCoolantSystemtemperatuxe reachesthenewprogrammed loadreference temperature.
Hi h Pressurizer Pressure Tri There is a reactor trip on 2/3 high pressurizer pressure, generally set to 2400 psia, or slightly above the pressurizer power operated relief valve setting and below the pressurizer safety valve opening pressure.Overt erature dT The purpose of this trip is to protect the core against any combination of reactor coolant temperature, power or pressure which could cause I DNS.Trip logic is 2/4 for 2.and 4-loop plants snd 2/3 for 3-loop plants.Hi h Pressurizer Level Tri This trip acts to prevent water discharge from the pressurizer safety valves.Logic is 2/3.5.5W 5.5.3 EVALELKON OF PROTECTION SYSTEM FOR LOSS OF LOAD A complete loss of load without steam dump and without a direct reactor trip is evaluated to find if diverse protection exists to prevent a hazard to the integrity of the plant through overpressurization or'NB.The transient was investigated for a current, high power density\lant, and no credit was taken for power reduction due to automatic'../'.".t~control rod motion or moderator temperature coefficient.
Thereactorpowerisreducedbycontrolrod,insertion duringthistime.Zncaseofaturbinetriporreactortrip,thesteamdumpisactuatedandcon-trolledonapresetuo-loadreference temperatuze.
/'Initiation of Accident Figure 5.5.1 shows a fault tree for a loss of load without steam dump, with the reactor at high power and ao direct reactor trip.One way a 1088 of load can occur is by closing of the turbine stop valves following a turbine trip signal or by hydraulic fluid pressure failure{the valves are held open by hydraulic fluid)-However, one and.possibly two trips must then fail in order to prevent an immediate reactor trip.Another possible failure mode is a turbine runback caused by, the throttle valves closing.This could be initiated by a rod drop, an overpower or overtemperature 4T signal, by an actual or spurious loss of electrical load signal, or by a failure in the turbine controller and load limit system.A spurious rod drop signal would normally decrease the turbine load by a fixed small percentage of full load.The control 5.5-5 alve could close completely only if an improper circuit exists in the controller.
TheSteamDumpControlSystemisdescribed inSection3.2.5.5-2 0
Similarly, an overpower or overtemperature 4T signal coxmally causes a step load.decrease of SX every 30 seconds;and only in the case of a simultaneous failure ox improper circuit in the controller could there be insufficient time for the operator to take notice.Ef the turbine runback is caused by an overpower or overtemperature 4T protection System failure, the failure could only be in the safe direction; that is, the error or failure would be in the direction to cause a reactor trip.A third possible path for a loss of load is through steam line isolation.
tPressurizer PressureReliefThepressurizer safetyvalvesaresizedtomatchthemaxfmnnnvolumetric surgerateassociated withacompletelossofloadwithoutsteamdumporadirectreactortrip.Thisisnotdependent onpxessurizer pressurecontrol.Thepressurizer safetyvalvestherefore completely protecttheReactorCoolantSystemagainstovexpressure, independent ofthehighpressurereactortrip.Thereliefvalvesaresizedtopreventactuation ofthehighpressuretripwhenthesteamdumpandroddrivesystemswork,andtherequiredsteamreLLefiswithinthecapacityoftheSteamDumpSystem.SteamSstemPressureReliefTheSteamSystemsafetyvalvespass100Zofma~mancalculated turbinesteamflow,atthesafetyvalvesetpressureplusaccumulation.
This may occur either through a loss of air supply to the isolation valves, or by a spurious or real isolation signa1 from the Reactor Protection System.As a result of the loss of steam flow.to the turbine by any hf the three paths outlined above, the Steam Dump System is activated.
Thisallowstheplanttoaccepta100Zloadre]ection withoutreactortxiporsteamdumpwithoutovexpressurizing theSteamSystem..Xnaddition, reliefvalvessettoopenatalowerpressurearealsoprovided, andaxetypically sizedataboutlOZofthesafetyvalvecapacity.
However, no 1 credit can be taken for this following steam line isolation, since, the dump valves are downstream of the isolation valves.For all three paths, the resulting decrease in first stage turbine impulse pressure causes automatic reactox'ower reduction by control rod insertion.
DirectReactorTriThemostcommoncauseofalossofloadisaturbine-generator trip.Zntheeventofsuchatrip,theturbinestopvalvesclose.Aturbine5.5-3 tripsensedbye2/3lowauto-scop oilpressureor2/2stopvalveclosureresultsinareactortripifthereactorisathighpower.ThepurposeofthesetriPsistomizdzMethethermaltransient sndsteamdumPrequirements fortheserelatively frequentplanttransients.
Even if the reactor is in manual control, the moderator coefficient of reactivity is generally negative and would cause a power decrease as temperatures increase.5.5-6 0 I i)~~  
HihPressurizer PressureTriThereisareactortripon2/3highpressurizer
'C The fault tree shown on Figure 5.5.1 indicates that, in most cases, a fault could cause a complete loss of load with no steam dump or reactor it"~>>I'power decrease only if one ox more simultaneous failures of the Control or Protection System also xesuLted.However, the following analysis is based on a complete loss of steam load without steam dump, reactor contxol, or direct reactor trip.Anal sis and Discussion Figure 5.5.3 shows the results of a transient analysis for a complete loss of load without steam dump.The results'show that'he safety~~I I'I I I>>valves capacity of the Steam System is..sufficient to LixQt the pressure l''rise to less than LUO psia, even without a reactor trip.The Reactor Coolant System T.transient is shown for a high pressurizer pressure avg or high pressurizer level reactor trip, as well as for no txip.I Actuation of the Steam System safety valves restores the reactor heat\s~and causes a decxease in the rate of rise of the reactor coolant average tempexature.
: pressure, generally setto2400psia,orslightlyabovethepressurizer poweroperatedreliefvalvesettingandbelowthepressurizer safetyvalveopeningpressure.
Without a reactor trip, T would eventually come avg into equilibrium when the required heat dissipation at the suety valve ,~set pressure is reached.The Reactor CooLant System pressure transient is also depicted.in Figure 5.5.3.The effect of the pressurizer power operated relief valves is felt slightly above their set pressure of 2350 psia.Since the required 5.5-7 4 e relief for a&61 loss of load without steam dump far exceeds the relief valve capacity, the pressure continues to rise to the safety valve set pressure of 2500 psia.The opening of the pressurizer safety valves, and the restoration of the secondary sink by steam relief, limits the Reactor Coolant System pressure rise.The surge rate decreases as the rate of rise of T decreases, and eventually the pressure decreases to avg the relief valve opening pressure.The transient is also shown for the high pressurizer pressure and leve1 reactor trips.The power operated relief valves delay the reaching of the high pressure reactor trip setpoint by about 2 seconds.The lower graph in Figure 5.5.3 shows the aduinnxm (hot channel)DNB transient.
OverteraturedTThepurposeofthistripistoprotectthecoreagainstanycombination ofreactorcoolanttemperature, powerorpressurewhichcouldcauseIDNS.Triplogicis2/4for2.and4-loopplantssnd2/3for3-loopplants.HihPressurizer LevelTriThistripactstopreventwaterdischarge fromthepressurizer safetyvalves.Logicis2/3.5.5W 5.5.3EVALELKON OFPROTECTION SYSTEMFORLOSSOFLOADAcompletelossofloadwithoutsteamdumpandwithoutadirectreactortripisevaluated tofindifdiverseprotection existstopreventahazardtotheintegrity oftheplantthroughoverpressurization or'NB.Thetransient wasinvestigated foracurrent,highpowerdensity\lant,andnocreditwastakenforpowerreduction duetoautomatic
For the first few seconds, the DNB ratio rises due to the increasing system pressure, while piping delays cause the core inlet temperature to remain constant.Two trips, the high pressure and overtemperature hT reactor trips, prevent the core design limf.ts from being exceeded.Rate compensation on T, which.is included in avg'he overtemperature dT trip, would actually cause the trip setpoint-to be reached much sooner than is depicted in the figure.The high pressurizer water level reactor trip is inadequate to prevent the core from exceeding the design limits.However, the minimum DNB ratio in the hot assembly for a high level trip is above 1.0 and would assure that core damage, if it occured at all, would be limited to a small fraction of the core.A conservative setpoint was assumed for the high level trip.5.5-8 0
'../'.".t~controlrodmotionormoderator temperature coefficient.
A fault tree for the accident, leading to core damage, is shown in Pigure 5.5.2.5.
/'Initiation ofAccidentFigure5.5.1showsafaulttreeforalossofloadwithoutsteamdump,withthereactorathighpowerandaodirectreactortrip.Onewaya1088ofloadcanoccurisbyclosingoftheturbinestopvalvesfollowing aturbinetripsignalorbyhydraulic fluidpressurefailure{thevalvesareheldopenbyhydraulic fluid)-However,oneand.possiblytwotripsmustthenfailinordertopreventanimmediate reactortrip.Anotherpossiblefailuremodeisaturbinerunbackcausedby,thethrottlevalvesclosing.Thiscouldbeinitiated byaroddrop,anoverpower orovertemperature 4Tsignal,byanactualorspuriouslossofelectrical loadsignal,orbyafailureintheturbinecontroller andloadlimitsystem.Aspuriousroddropsignalwouldnormallydecreasetheturbineloadbyafixedsmallpercentage offullload.Thecontrol5.5-5 alvecouldclosecompletely onlyifanimpropercircuitexistsinthecontroller.
Similarly, anoverpower orovertemperature 4Tsignalcoxmallycausesastepload.decrease ofSXevery30seconds;andonlyinthecaseofasimultaneous failureoximpropercircuitinthecontroller couldtherebeinsufficient timefortheoperatortotakenotice.Eftheturbinerunbackiscausedbyanoverpower orovertemperature 4Tprotection Systemfailure,thefailurecouldonlybeinthesafedirection; thatis,theerrororfailurewouldbeinthedirection tocauseareactortrip.Athirdpossiblepathforalossofloadisthroughsteamlineisolation.
Thismayoccureitherthroughalossofairsupplytotheisolation valves,orbyaspuriousorrealisolation signa1fromtheReactorProtection System.Asaresultofthelossofsteamflow.totheturbinebyanyhfthethreepathsoutlinedabove,theSteamDumpSystemisactivated.
However,no1creditcanbetakenforthisfollowing steamlineisolation, since,thedumpvalvesaredownstream oftheisolation valves.Forallthreepaths,theresulting decreaseinfirststageturbineimpulsepressurecausesautomatic reactox'ower reduction bycontrolrodinsertion.
Evenifthereactorisinmanualcontrol,themoderator coefficient ofreactivity isgenerally negativeandwouldcauseapowerdecreaseastemperatures increase.
5.5-6 0Ii)~~  
'CThefaulttreeshownonFigure5.5.1indicates that,inmostcases,afaultcouldcauseacompletelossofloadwithnosteamdumporreactorit"~>>I'powerdecreaseonlyifoneoxmoresimultaneous failuresoftheControlorProtection SystemalsoxesuLted.
However,thefollowing analysisisbasedonacompletelossofsteamloadwithoutsteamdump,reactorcontxol,ordirectreactortrip.AnalsisandDiscussion Figure5.5.3showstheresultsofatransient analysisforacompletelossofloadwithoutsteamdump.Theresults'showthat'hesafety~~II'III>>valvescapacityoftheSteamSystemis..sufficient toLixQtthepressurel''risetolessthanLUOpsia,evenwithoutareactortrip.TheReactorCoolantSystemT.transient isshownforahighpressurizer pressureavgorhighpressurizer levelreactortrip,aswellasfornotxip.IActuation oftheSteamSystemsafetyvalvesrestoresthereactorheat\s~andcausesadecxeaseintherateofriseofthereactorcoolantaveragetempexature.
Withoutareactortrip,Twouldeventually comeavgintoequilibrium whentherequiredheatdissipation atthesuetyvalve,~setpressureisreached.TheReactorCooLantSystempressuretransient isalsodepicted.
inFigure5.5.3.Theeffectofthepressurizer poweroperatedreliefvalvesisfeltslightlyabovetheirsetpressureof2350psia.Sincetherequired5.5-7 4e relieffora&61lossofloadwithoutsteamdumpfarexceedsthereliefvalvecapacity, thepressurecontinues torisetothesafetyvalvesetpressureof2500psia.Theopeningofthepressurizer safetyvalves,andtherestoration ofthesecondary sinkbysteamrelief,limitstheReactorCoolantSystempressurerise.Thesurgeratedecreases astherateofriseofTdecreases, andeventually thepressuredecreases toavgthereliefvalveopeningpressure.
Thetransient isalsoshownforthehighpressurizer pressureandleve1reactortrips.Thepoweroperatedreliefvalvesdelaythereachingofthehighpressurereactortripsetpointbyabout2seconds.ThelowergraphinFigure5.5.3showstheaduinnxm(hotchannel)DNBtransient.
Forthefirstfewseconds,theDNBratiorisesduetotheincreasing systempressure, whilepipingdelayscausethecoreinlettemperature toremainconstant.
Twotrips,thehighpressureandovertemperature hTreactortrips,preventthecoredesignlimf.tsfrombeingexceeded.
Ratecompensation onT,which.isincludedinavg'heovertemperature dTtrip,wouldactuallycausethetripsetpoint-tobereachedmuchsoonerthanisdepictedinthefigure.Thehighpressurizer waterlevelreactortripisinadequate topreventthecorefromexceeding thedesignlimits.However,theminimumDNBratiointhehotassemblyforahighleveltripisabove1.0andwouldassurethatcoredamage,ifitoccuredatall,wouldbelimitedtoasmallfractionofthecore.Aconservative setpointwasassumedforthehighleveltrip.5.5-8 0
Afaulttreefortheaccident, leadingtocoredamage,isshowninPigure5.5.2.5.


==5.4CONCLUSION==
==5.4 CONCLUSION==
S Thisaccidentisnotconsidered 1Qcelysinceinmostoftheincidents whichcouldcauseit,oneormoresimultaneous failuresofcontrolorprotection instrumentation mustalsooccur.Inaddition, atanytime.otherthanearlyin.coreLife,thelargenegativemoderator coefficient wouldcausetheaccidenttobeselflimitingandgivemuchbetterresultsthandepictedinthisanalysis.
S This accident is not considered 1Qcely since in most of the incidents which could cause it, one or more simultaneous failures of control or protection instrumentation must also occur.In addition, at any time.other than early in.core Life, the large negative moderator coefficient would cause the accident to be self limiting and give much better results than depicted in this analysis.However, if the accident were to occur, diversity does exist in that three different levels of protection are avail,able.
However,iftheaccidentweretooccur,diversity doesexistinthatthreedifferent levelsofprotection areavail,able.
5.5-9  
5.5-9  
,Ih SJSNfs<<ls<<s<<<<<<<<<<<<u~<<"<<<<<<<<.<<<<<<NSJSSR<<j~R<<g@N<<'JJ@
,I h SJSNfs<<ls<<s<<<<<<<<<<<<u~<<"<<<<<<<<.<<<<<<NSJSSR<<j~R<<g@N<<'JJ@
"g<<<<j,,<<,lt,fIQJRS5.52OjRTsORSD<<sNORODJIFIONCFORNMANUALCONIIJOL<<<<4fTKAMLIbEISOIATION, NOTURRINECO&#xc3;IROLVALVESCLO.E,NOTURSINESTOPvvx.v""AIRSUPPLIAUTO.S,D,AUTO.S.D,LOADLIMITACIUALORSIUFIQJSLOSSOjEJECT~LOADSCOPVALVER<<T<<TURBINECONIROLIA3
" g<<<<j ,,<<,lt, fIQJRS 5.5 2 Oj R Ts OR S D<<s NO ROD JIFION CFOR N MANUAL CONIIJOL<<<<4 fTKAM LIbE ISOIATION, NO TURRINE CO&#xc3;IROL VALVES CLO.E, NO TURSINE STOP vvx.v"" AIR SUPPLI AUTO.S,D, AUTO.S.D, LOAD LIMIT ACIUAL OR SIUFIQJS LOSS Oj EJECT~LOAD SCOP VALVE R<<T<<TURBINE CONIROLIA3.SR EXCESSIVE RUNS'X IJJSS OF IIQiCENCV FIUID NJRIQJF ICOIA TION f IGNAI'<<ITN QJT REAClOR TRIP IMISOPER CRT AND hlJTOGIOP R.T<<CONDITIOJI FA I JJJRI REACIOR I%REC-TION SISIIJ'.IAJGIC FAULTs SBJRIQJS F<<OD DROP EIGJIAL REAL OR SIURIQJG OVIR POLJER OR OVER OR LOSS DP AUIOSIOP PIJJID NUCL<<INST<<SISTIIl ROD POSITION INDICATION i FAIIJJRE ANT SJRBINE TRIP SIGNAL R.T.RKACIOR TRIP K.C,-ST&QJJJP , S)1, SAINT INJECFICN I~SCFEJ Anf Slsaa IIos Isolalloa~ISJ<<al Is also~@castor tcIP sISJnal.Theccfcea>
.SREXCESSIVE RUNS'XIJJSSOFIIQiCENCV FIUIDNJRIQJFICOIATIONfIGNAI'<<ITNQJTREAClORTRIPIMISOPERCRTANDhlJTOGIOP R.T<<CONDITIOJI FAIJJJRIREACIORI%REC-TIONSISIIJ'.IAJGICFAULTsSBJRIQJSF<<ODDROPEIGJIALREALORSIURIQJGOVIRPOLJEROROVERORLOSSDPAUIOSIOPPIJJIDNUCL<<INST<<SISTIIlRODPOSITIONINDICATION iFAIIJJREANTSJRBINETRIPSIGNALR.T.RKACIORTRIPK.C,-ST&QJJJP,S)1,SAINTINJECFICN I~SCFEJAnfSlsaaIIosIsolalloa
ooIF loSto clccoll falllls shool4 Lc coas14ctc4
~ISJ<<alIsalso~@castortcIPsISJnal.Theccfcea>
~NIGH TAV NIGH AT FIGURE 5.5-1 FAULT TREE IOR INN 0 j llRD ACCII<<ENI  
ooIFloStoclccollfallllsshool4Lccoas14ctc4
, 5'~a~'1 1 FAULT TREE FOR CORE DAMAGE LOSS OF STEAM LOAD CONDITION Probable Gross Core Damage AND High Pressurize Level R.T.Core Design Limits Exceeded R.T.-REACTOR TRIP S.D.-STEAM DUMP S.I.-SAFETY INJECTION Overtemperature AT R.T.i High Prdssure RiT Loss of Load, No SeD~or POUer Decrease Early in Core Life Loss of Load, No Direct R.T.or S.D., No Rod Insertion (See Figure 5.5-1)FIGURE 5.5-2 1200 1000 800 600 2600 2500 2400 2300 zzoo 6zo 600 580 560 1 8 1.6 1.4 5 1.2 1.0.8 0 LOSS OP LOAD ACCIDENT~~I l-~1-STEAM SYSTEM PRESSURE'-)~.':~te~~~I I~I~~~~I~/~l".~I." REACTOR COOLANT SYSTEM PRESSURE I:-:~I t~~I~~~~~~i~'O TRIP."'HIGH PRESSURE" REACTOR TRIP J'.'''l"''IGH LEVEL REACTOR TRIP~).'I l.'.!.(I I t'~I l'-i=(REACTOR COOLANT T VG I'~~).-.NO~~I~'t.TRIP (HIGH LEVEL-'EACTOR TRIP f..~~~~~I~)~.HIGH PRESSURE.-'REACTOR TRIP~~I HIGH PRESSURE".:-.EEACTOR TRIP~I~~~g I.L.-~~I I'VERHK'ERATURE
~NIGHTAVNIGHATFIGURE5.5-1FAULTTREEIORINN0jllRDACCII<<ENI  
.AT REACTOR TRIP i'IGH LEVEL'EA,CTOR TRIP-'~~~L.'UNB RATIO.NO L~4~~)20 30 40 50 10 SECONDS FIGURE 5.5-3 0 I, 5,6 ROD WITHDRAWAB DURING STARTUP Normal startup procedure is by control rod withdrawal under manual control.~function of the rod contxol system or operator error can cause a reactivity excuxsion with a resultant rapid increase in power.Rod withdrawal accidents ia the power range are evaluated in Section 5.1.For these accidents, the power increase is approximately linear for a linear increase in reactivity.
,5'~a~'11 FAULTTREEFORCOREDAMAGELOSSOFSTEAMLOADCONDITION ProbableGrossCoreDamageANDHighPressurize LevelR.T.CoreDesignLimitsExceededR.T.-REACTORTRIPS.D.-STEAMDUMPS.I.-SAFETYINJECTION Overtemperature ATR.T.iHighPrdssureRiTLossofLoad,NoSeD~orPOUerDecreaseEarlyinCoreLifeLossofLoad,NoDirectR.T.orS.D.,NoRodInsertion (SeeFigure5.5-1)FIGURE5.5-2 120010008006002600250024002300zzoo6zo600580560181.61.451.21.0.80LOSSOPLOADACCIDENT~~Il-~1-STEAMSYSTEMPRESSURE'-)~.':~te~~~II~I~~~~I~/~l".~I."REACTORCOOLANTSYSTEMPRESSUREI:-:~It~~I~~~~~~i~'OTRIP."'HIGHPRESSURE"REACTORTRIPJ'.'''l"''IGH LEVELREACTORTRIP~).'Il.'.!.(IIt'~Il'-i=(REACTORCOOLANTTVGI'~~).-.NO~~I~'t.TRIP(HIGHLEVEL-'EACTORTRIPf..~~~~~I~)~.HIGHPRESSURE.
For accidents starting from very, low power (staxtup x'ange), the neutron flux may increase by many decades before there is significant Doppler feedback..
-'REACTORTRIP~~IHIGHPRESSURE".:-.EEACTORTRIP~I~~~gI.L.-~~II'VERHK'ERATURE
The nuclear power response to a continuous reactivity insertion from the startup range is characterised by a very fast rise terminated by the reac-tivity feedback effect of the negative fuel temperature coefficient (Doppler effect).This self limitiag effect is of prime importance during a startup I accident since it.limits the power to a tolerable level prior to external protective action.After the initial power burst, the nuclear power is momentarily xeduced aad then if the accident is not terminated, the nucl'ear power increases again but at a much slower rate.Protection against startup accidents is provided by diverse types of neutron-monitoring instrumentatioa:
.ATREACTORTRIPi'IGHLEVEL'EA,CTORTRIP-'~~~L.'UNBRATIO.NOL~4~~)2030405010SECONDSFIGURE5.5-3 0I, 5,6RODWITHDRAWAB DURINGSTARTUPNormalstartupprocedure isbycontrolrodwithdrawal undermanualcontrol.~function oftherodcontxolsystemoroperatorerrorcancauseareactivity excuxsion witharesultant rapidincreaseinpower.Rodwithdrawal accidents iathepowerrangeareevaluated inSection5.1.Fortheseaccidents, thepowerincreaseisapproximately linearforalinearincreaseinreactivity.
source range, intermediate range, and power range channels.Ma)or differences in the ion chamber and cixcuit design exist between the intermediate and power range channels.The source xaage uses a neutron sensor of a different principle:
Foraccidents startingfromvery,lowpower(staxtupx'ange),theneutronfluxmayincreasebymanydecadesbeforethereissignificant Dopplerfeedback..
proportional counter rather than ionization chamber.5-6-L  
Thenuclearpowerresponsetoacontinuous reactivity insertion fromthestartuprangeischaracterised byaveryfastriseterminated bythereac-tivityfeedbackeffectofthenegativefueltemperature coefficient (Dopplereffect).Thisselflimitiageffectisofprimeimportance duringastartupIaccidentsinceit.limitsthepowertoatolerable levelpriortoexternalprotective action.Aftertheinitialpowerburst,thenuclearpowerismomentarily xeducedaadtheniftheaccidentisnotterminated, thenucl'earpowerincreases againbutatamuchslowerrate.Protection againststartupaccidents isprovidedbydiversetypesofneutron-monitoring instrumentatioa:
~'4 4 Should continuous control rod withdrawal be initiated and assuming the source and intermediate range alarms and indications are ignored, the transient will be terminated by any of the following automatic protective actions.a)Source range flux level trip-actuated when either of two independent.
sourcerange,intermediate range,andpowerrangechannels.
source range channels indicates a flux level above a preselected,~g~<<manually ad]ustable value..This trip function may be manually bypassed when either intermediate range flux channel indicates a flux level above the source range cutoff power level.It is automatically rein-stated when both intermediate range channels indicate a flux level belo~the source range cutoff power level.~<<b)Intermediate range rod stop-actuated when either of two independent
Ma)ordifferences intheionchamberandcixcuitdesignexistbetweentheintermediate andpowerrangechannels.
<<intermediate range channels indicates a flux level above a preselected, manually ad)ustable value.This rod stop may be manually bypassed when two out of the four power range channels indicate a power level above approximately ten per cent power.It is automatically reinstated when three of the four power range channels are below this value.c)Intermediate range flux level trip-actuated when either of two independent intermediate range channels indicates a flux level above a preselected, manually ad]ustable value.This trip function is manually bypassed when two of the four power range channels are reading above approximately ten per cent power and is automatically reinstated when three of the four channels indicate a power level below this value.d)Power range flux level trip (low setting)-actuated when two out of the four power range channels indicate a power level above approxima y tel 25 per cent.This trip function may be manually bypassed when two of the 5.6>>2 II'0 four power range channels indicate a power level above approximately ten per cent power and is automatically xeinstated when three of the four channels indicate a power level below this value.e)Power range flux level trip (high setting)-actuated when two out of the four power range channels indicate a'power level above a preset setpoint.This trip function is always active.Since all protective actions in the above list are based on level set points, I rather than rate set points, protection is not dependent upon having a rapid rate of power increase.The standard startup accident analysis reported in Safety Analysis Reports takes credit fox only the power range protection.
Thesourcexaageusesaneutronsensorofadifferent principle:
Howevex, the intermediate range hfgh flux reactor trip is always in service below lOX power, and would also serve to terminate the accident.Further,.any accident starting from a subcritical condition would be terminated by the high source range'I xeactor trip.Therefore, Protection System deversity exists for startup accidents.
proportional counterratherthanionization chamber.5-6-L  
Figures 5.6-1 and 5.6-2 show the calculated transient response of nuclear flux and fuel temperatuxes for a startup accident with a high rate of xeactivity insex tion.5.6-3 0  
~'44Shouldcontinuous controlrodwithdrawal beinitiated andassumingthesourceandintermediate rangealarmsandindications areignored,thetransient willbeterminated byanyofthefollowing automatic protective actions.a)Sourcerangefluxleveltrip-actuatedwheneitheroftwoindependent.
~I 10 10'~I I I~~Uncontrolled Rod Qithdrawal Prom a Subcritical Condition Praction of Nuclear Power a~+1 x 10 6k/F W 5 o a<lxlp 6k/P f Reactivity Insertion Rate~8 x 10 6k/sec k~1.0 0-1~t~I 10 8 W 0 g M 10 pl il li ko C o Oe 10 g~~~I~~I~10 8 0 W o o o 10-3 5 o Cl~u 10 10 0 10 20 25 10 30 Time, Seconds FlGVRE 5.6-1 4~<<((I-"~(4<<<<.(.<<<<4V,~~I(are J>~w<<(i'(<<<<M>>1000 900 Puel Clad Uncontrolled Rod MithdraMal Prom a Subcritical Condition Temperature 4 ag<<+1 x 10 5 6k/'P o=-1 x 10 6k/'P Reactivitg Insertion Rate f<<8 x 10 Lk/sec k<<l.0 70 65 800 700 Core Mater 14 o (4 l0 c e'0 oj 60 55 600 50 500 45 6 10 1.L 18 22 26 30'Time, Seconds FIGURE 5.6-2 5 7 CONTROL ROD DROP De-energixing a drive mechanism causes a full>>length control rod to fall into the core.(Part-length rods fail"as-is" when de-energized.)
sourcerangechannelsindicates afluxlevelaboveapreselected,
This causes an immediate decrease in coxe power, most noticeable in the region of the dropped rod.Xf the average coze power is returned to its original valve, most of the core would be at a higher power density because of the local depxession in the region of the dropped rod.During the initial design fox the current generation of Westinghouse PWR's, the increase in hot channel factors for a dropped zod was not known.Zt was therefore assumed that DNB might xesult if the core were allowed to return to full power following a zod drop.Protective circuits were design-ed accordingly and classified as part of the Protection System.The design requirement for this protective function was to insure that, follmrtng a dynamic rod drop, the xeactor would not zeturn to a power leve3high enough I to cause a DNB ratio less than 1.30., Mechanisms which would tend to restore r initial core power are.noxmal automatic control and plant cooldown with a negative moderator coefficient.
~g~<<manuallyad]ustable value..Thistripfunctionmaybemanuallybypassedwheneitherintermediate rangefluxchannelindicates afluxlevelabovethesourcerangecutoffpowerlevel.Itisautomatically rein-statedwhenbothintermediate rangechannelsindicateafluxlevelbelo~thesourcerangecutoffpowerlevel.~<<b)Intermediate rangerodstop-actuatedwheneitheroftwoindependent
However, recent physics analysis for malpositioned control rods has shown that, in every case for an insezted rod, full power operation would not cause a DNB ratio less than 1.30.Because the local power decrease causes a general power increase throughout the rest of the core, the increase in hot channel factors is Usted to approximately 15'x less, depending on core size.With x'espect to DNB, this is equivalent to 15X overpower.
<<intermediate rangechannelsindicates afluxlevelaboveapreselected, manuallyad)ustable value.Thisrodstopmaybemanuallybypassedwhentwooutofthefourpowerrangechannelsindicateapowerlevelaboveapproximately tenpercentpower.Itisautomatically reinstated whenthreeofthefourpowerrangechannelsarebelowthisvalue.c)Intermediate rangefluxleveltrip-actuatedwheneitheroftwoindependent intermediate rangechannelsindicates afluxlevelaboveapreselected, manuallyad]ustable value.Thistripfunctionismanuallybypassedwhentwoofthefourpowerrangechannelsarereadingaboveapproximately tenpercentpowerandisautomatically reinstated whenthreeofthefourchannelsindicateapowerlevelbelowthisvalue.d)Powerrangefluxleveltrip(lowsetting)-actuatedwhentwooutofthefourpowerrangechannelsindicateapowerlevelaboveapproxima ytel25percent.Thistripfunctionmaybemanuallybypassedwhentwoofthe5.6>>2 II'0 fourpowerrangechannelsindicateapowerlevelaboveapproximately tenpercentpowerandisautomatically xeinstated whenthreeofthefourchannelsindicateapowerlevelbelowthisvalue.e)Powerrangefluxleveltrip(highsetting)-actuatedwhentwooutofthefourpowerrangechannelsindicatea'powerlevelaboveapresetsetpoint.
Core DNB'esign 5.7-1  
Thistripfunctionisalwaysactive.Sinceallprotective actionsintheabovelistarebasedonlevelsetpoints,Iratherthanratesetpoints,protection isnotdependent uponhavingarapidrateofpowerincrease.
~~~E margins of this magnitude must exist at full power to allow for operational transients and instrumentation errors.In additon, for plants presently near completion, it has been found that inserted rod hot channel.factors do not even exceed the design hot channel factors.Since the consequences of a dynamic rod drop are tolerable, the following ff discussion of rod drop protection is somewhat academic.Rod drop protection diversity has been provided, both in the means of detection and in the means of actuating protection.
ThestandardstartupaccidentanalysisreportedinSafetyAnalysisReportstakescreditfoxonlythepowerrangeprotection.
Howevex,theintermediate rangehfghfluxreactortripisalwaysinservicebelowlOXpower,andwouldalsoservetoterminate theaccident.
Further,.
anyaccidentstartingfromasubcritical condition wouldbeterminated bythehighsourcerange'Ixeactortrip.Therefore, Protection Systemdeversity existsforstartupaccidents.
Figures5.6-1and5.6-2showthecalculated transient responseofnuclearfluxandfueltemperatuxes forastartupaccidentwithahighrateofxeactivity insextion.5.6-3 0  
~I1010'~III~~Uncontrolled RodQithdrawal PromaSubcritical Condition PractionofNuclearPowera~+1x106k/FW5oa<lxlp6k/PfReactivity Insertion Rate~8x106k/seck~1.00-1~t~I108W0gM10plillikoCoOe10g~~~I~~I~1080Wooo10-35oCl~u101001020251030Time,SecondsFlGVRE5.6-1 4~<<((I-"~(4<<<<.(.<<<<4V,~~I(areJ>~w<<(i'(<<<<M>>1000900PuelCladUncontrolled RodMithdraMal PromaSubcritical Condition Temperature 4ag<<+1x1056k/'Po=-1x106k/'PReactivitg Insertion Ratef<<8x10Lk/seck<<l.07065800700CoreMater14o(4l0ce'0oj605560050500456101.L18222630'Time,SecondsFIGURE5.6-2 57CONTROLRODDROPDe-energixing adrivemechanism causesafull>>length controlrodtofallintothecore.(Part-length rodsfail"as-is"whende-energized.)
Thiscausesanimmediate decreaseincoxepower,mostnoticeable intheregionofthedroppedrod.Xftheaveragecozepowerisreturnedtoitsoriginalvalve,mostofthecorewouldbeatahigherpowerdensitybecauseofthelocaldepxession intheregionofthedroppedrod.Duringtheinitialdesignfoxthecurrentgeneration ofWestinghouse PWR's,theincreaseinhotchannelfactorsforadroppedzodwasnotknown.Ztwastherefore assumedthatDNBmightxesultifthecorewereallowedtoreturntofullpowerfollowing azoddrop.Protective circuitsweredesign-edaccordingly andclassified aspartoftheProtection System.Thedesignrequirement forthisprotective functionwastoinsurethat,follmrtng adynamicroddrop,thexeactorwouldnotzeturntoapowerleve3highenoughItocauseaDNBratiolessthan1.30.,Mechanisms whichwouldtendtorestorerinitialcorepowerare.noxmal automatic controlandplantcooldownwithanegativemoderator coefficient.
However,recentphysicsanalysisformalpositioned controlrodshasshownthat,ineverycaseforaninseztedrod,fullpoweroperation wouldnotcauseaDNBratiolessthan1.30.Becausethelocalpowerdecreasecausesageneralpowerincreasethroughout therestofthecore,theincreaseinhotchannelfactorsisUstedtoapproximately 15'xless,depending oncoresize.Withx'especttoDNB,thisisequivalent to15Xoverpower.
CoreDNB'esign 5.7-1  
~~~Emarginsofthismagnitude mustexistatfullpowertoallowforoperational transients andinstrumentation errors.Inadditon,forplantspresently nearcompletion, ithasbeenfoundthatinsertedrodhotchannel.factorsdonotevenexceedthedesignhotchannelfactors.Sincetheconsequences ofadynamicroddroparetolerable, thefollowing ffdiscussion ofroddropprotection issomewhatacademic.
Roddropprotection diversity hasbeenprovided, bothinthemeansofdetection andinthemeansofactuating protection.
Redundancy.
Redundancy.
wasmorereadilyobtainedbydiverseinstrumentation thanbyindependent, butidentical, channels.
was more readily obtained by diverse instrumentation than by independent, but identical, channels.A rod drop signal is generated by either of the following:
Aroddropsignalisgenerated byeitherofthefollowing:
a)A=rapid decrease in indicated nuclear flux from any one of the four power range nuclear instrument channels b)Rod bottom indication from any one of the rod position indicators when the associated rod bank is not on the bottom.One-out-of-four logic for the nuclear channels is used'because it was not known whether more than one channel would respond to the dropped rod.Therefore, redundancy is not claimed.Protective action is directed toward inhibiting those mechanisms which would otherwise cause the reactor to return to its initial power level, i..e., automatic rod withdrawal and load demand with a negative moderator temperature coefficient.
a)A=rapiddecreaseinindicated nuclearfluxfromanyoneofthefourpowerrangenuclearinstrument channelsb)Rodbottomindication fromanyoneoftherodpositionindicators whentheassociated rodbankisnotonthebottom.One-out-of-four logicforthenuclearchannelsisused'because itwasnotknownwhethermorethanonechannelwouldrespondtothedroppedrod.Therefore, redundancy isnotclaimed.Protective actionisdirectedtowardinhibiting thosemechanisms whichwouldotherwise causethereactortoreturntoitsinitialpowerlevel,i..e.,automatic rodwithdrawal andloaddemandwithanegativemoderator temperature coefficient.
Again, since the magnitude of the hot channel factor increase was not known, it was assumed that both mechanisms would have to be inhibited.
Again,sincethemagnitude ofthehotchannelfactorincreasewasnotknown,itwasassumedthatbothmechanisms wouldhavetobeinhibited.
5.7-2 Redundant rod stop contacts are provided to block normal automatic control rod withdrawal.
5.7-2 Redundant rodstopcontactsareprovidedtoblocknormalautomatic controlrodwithdrawal.
Manual rod withdrawal is not blocked since it is necessary to withdraw the dropped rod.Turbine load reduction is accomplished through redundant channels.Most plants are supplied with electro-hydrauLLc (E-H)control systems for the turbine.The turbine runback is activated by the following~
Manualrodwithdrawal isnotblockedsinceitisnecessary towithdrawthedroppedrod.Turbineloadreduction isaccomplished throughredundant channels.
either of which reduces or restricts turbine control valve position and steam load.a)Reduction of the load refezence setpoint of the turbine,E-H., controller by a preset amount.This is accomplished by zeducing the set point at constant rate (200X/min.)
Mostplantsaresuppliedwithelectro-hydrauLLc (E-H)controlsystemsfortheturbine.Theturbinerunbackisactivated bythefollowing~
for a preset time with a.time delay relay.b)Reduction of the turbine load.limit to a preset value.The load limit (a clamp on the voltage signal controlling the turbine control valve position)is reduced until turbine thermal load as I)sensed by either of two turbine impulse pressure'channels is below a preset value.Following plant startup tests to verify that the DNB ratio is greater than 1.30 at full power with a dropped rod, it is intended to adjust the turbine runback for operational requirements.
eitherofwhichreducesorrestricts turbinecontrolvalvepositionandsteamload.a)Reduction oftheloadrefezence setpointoftheturbine,E-H.,
That is, the automatic load reduction would be large enough such that, with reasonable operator action, an orderly manual plant shutdown can be accomplished, rather than a reactor trip on low pressurizer pressure.Fi.gures 5.7-1 and 5.7-2 show the transient response of nuclear plant variables to a rod drop with turbine runback.5.7-3  
controller byapresetamount.Thisisaccomplished byzeducingthesetpointatconstantrate(200X/min.)
forapresettimewitha.timedelayrelay.b)Reduction oftheturbineload.limittoapresetvalue.Theloadlimit(aclamponthevoltagesignalcontrolling theturbinecontrolvalveposition) isreduceduntilturbinethermalloadasI)sensedbyeitheroftwoturbineimpulsepressure'channels isbelowapresetvalue.Following plantstartupteststoverifythattheDNBratioisgreaterthan1.30atfullpowerwithadroppedrod,itisintendedtoadjusttheturbinerunbackforoperational requirements.
Thatis,theautomatic loadreduction wouldbelargeenoughsuchthat,withreasonable operatoraction,anorderlymanualplantshutdowncanbeaccomplished, ratherthanareactortriponlowpressurizer pressure.
Fi.gures5.7-1and5.7-2showthetransient responseofnuclearplantvariables toaroddropwithturbinerunback.5.7-3  


lllr1.U.9.8.7~t~~-I.I~~I.',.f=~CI~:I~-I.~~~t4~~~~~~:H'ResponsetoaDroppedRCCAof.North-2.3x,106kWithaPowerCutbackof25PercentofNominal~-3.5x10bk/7'-'~>>1.65x106k/Z'.~~II~~i:I~..l.,~~~~~t~t1.000CKheQE8.9.8'~~7~t>~tl~tttI~~~I'~':I-"'I~l~'t{~~~I~~ttI~I~~II24002300~pk~~~~~~~~~It~~-I~tt~~~'{::.-~II~~I~It~~~t22002100~~~"-I~I4080120160200 04~  
l l l r 1.U.9.8.7~t~~-I.I~~I.',.f=~C I~:I~-I.~~~t 4~~~~~~:H'Response to a Dropped RCCA of.North-2.3 x,10 6k With a Power Cutback of 25 Percent of Nominal~-3.5 x 10 bk/7'-'~>>1.65 x 10 6k/Z'.~~I I~~i: I~..l.,~~~~~t~t 1.0 0 0C K he Q E 8.9.8'~~7~t>~t l~t tt I~~~I'~':I-"'I~l~'t{~~~I~~tt I~I~~I I 2400 2300~pk~~~~~~~~~I t~~-I~t t~~~'{::.-~I I~~I~I t~~~t 2200 2100~~~"-I~I 40 80 120 160 200 0 4~  
~'III~~I~~0~~~~~~~~~~~0t~0'I.tt0~~~II0~I0~~--}t~*L0~>>0t'If0580578576IL00~IQ0Q~~~I0~r~0~~0<<I~000~0~I~~It~LL~00L0000~>>~>I~I0~~0I~~~lI~~-I'='~I~0:..00J~565IQ0~0I~ResponsetoaDroppedRCCAofWoph-203x106kwithaPowerCutbackof25PercentofNominal~~5604~~,004a0~t0't~'fQMC4o555550U~M~IJ0=I~I~~~I~~~~~~OH1.0~~0~~M00g,9~>>~~0I~~0,8L~~00'~0~~~~~~I~~.74080120160200TDK,SECONDS  
~'I I I~~I~~0~~~~~~~~~~~0t~0'I.t t0~~~I I 0~I 0~~--}t~*L0~>>0t'If 0 580 578 576 I L00~IQ 0 Q~~~I 0~r~0~~0<<I~00 0~0~I~~I t~LL~00 L 00 00~>>~>I~I 0~~0 I~~~l I~~-I'='~I~0:..00 J~565 I Q 0~0 I~Response to a Dropped RCCA of Woph-203 x 10 6k with a Power Cutback of 25 Percent of Nominal~~560 4~~, 0 0 4a 0~t 0't~'fQ M C4 o 555 550 U~M~I J0=I~I~~~I~~~~~~O H 1.0~~0~~M 00 g ,9~>>~~0 I~~0 ,8 L~~00'~0~~~~~~I~~.7 40 80 120 160 200 TDK, SECONDS  


5~8ENGINEERED SAFEGUARDS ACTUATION Actuation ofauxiliary feedwater isdiscussed inSection5.2.Engineered safeguards forcontainment pressureprotection arediscussed inSection5.9.Actuation ofEmergency CoreCoolingforlossofcoolantprotection isdiscussed inthissection.Forlossofcoolantprotection, asafetyin]ection signalisgenerated byeitheroftwodiversesetsofautomatic signals:a)Coincident lowpzessureandwaterleve1inthepressurizer; b)Highcontainment pzessure.
5~8 ENGINEERED SAFEGUARDS ACTUATION Actuation of auxiliary feedwater is discussed in Section 5.2.Engineered safeguards for containment pressure protection are discussed in Section 5.9.Actuation of Emergency Core Cooling for loss of coolant protection is discussed in this section.For loss of coolant protection, a safety in]ection signal is generated by either of two diverse sets of automatic signals: a)Coincident low pzessure and water leve1 in the pressurizer; b)High containment pzessure.Both sets of signals are redundant and meet all protection System design criteria.The signals derived from the pressurixer indicate that reactor coolant is being lost well before the core is uncovered.
Bothsetsofsignalsareredundant andmeetallprotection Systemdesigncriteria.
Reactor coolant blowdown also increases containment pressure.Set points'for high can-tainment pressure are typically about 10X of contaiaamt design pressure.This set point is reached well before the core uncovers.Figure 5.8-1 shows the results of a calculation for a representative plant for the complete range of break sixes.Zt shows that either the pressurixer or the containment signal initiate safety in)ection l-l/2 minutes or more before the core would be otherwise uncovered.(For large breaks>passive accumulator system supplies water and delays the time.at which active core cooling is required.)
Thesignalsderivedfromthepressurixer indicatethatreactorcoolantisbeinglostwellbeforethecoreisuncovered.
This analysis included the effects of containment heat sinks and fan coolers in delaying the time at which the containment high pressure signal is reached.5.8>>1 SAFETY INJECTION ACTUATION SIG:NL VS BREAK AREA 1000 4 o~I+I'~'T~~~i I}.o~l<<~,~~I I I I l~~I~~<<~~}le r o, on e*o I r I~~~~~<<~t~~>>v~t tt~I~"tt rl tt<<~~~I}'-: Range of Protection of I:.: Passive Accumulator System-(;I~I ae I 4 V 100~~o oo 1}:<<I I~I~~I P tl~~I'~I'<<~~>>:ii}'."~I It~~I~I I~''~~}I~~~~~I~~~v 0~~r,~!Ia.~o~~~tt~\~v}'"--t t I~~~~\~~t<<to~o~to~~~I'I~~o~~~~~<<~~~~I<<.)~o I I O I hC 10 o~~t~<<'o o~I~~I~Itz~~<<'I''''I~'I.....~Time to Reach Lou Pres-I:-surizer Pressure and Level Signal 7>>~~~~\~~~~~~>>~~~~I~I~~~~<<o~<<e~o<<v pt t I:TI~I~~*~I~I~I~~~~I~~I" I~}~~~~~~~i-.', I~PI~'~I"I<<I~I I~)}=.1-I:i lne ce Uncavel Case Ndd Plane LNe Sadecv ln eccdcn)j~o~~~\f<<~~~~~I~~I t I~lel~~~'I~~jjjr"~~i Time to Reach Pigh Containment Pressure Signal'<<l l~~~v I<<j~0.01'ii l\~4 0.1~6" 10" DAUEa:.BREAK SIZE (Fi)FIGUPE 5.8-1  
Reactorcoolantblowdownalsoincreases containment pressure.
~V 5 9 CONTAINMENT PRESSURE PROTECTION Typical westinghouse dry concaiament plants are equipped with faa cooler unics aad spray systems.These are provided to reduce the contaiamenc pressure eo to esseatially atmospheric following a loss of coolant accident or a steam line break accident inside the containmeac.
Setpoints'for highcan-tainmentpressurearetypically about10Xofcontaiaamt designpressure.
The containment is designed to withstand the eoeal blowdown of the Reactor Coolant Syscem or a steam generator wieh no dependence on ehe aceive safe-guards.The active safeguards are, however, aueomatically actuated following che accident.The pr9nary containment safeguards are the fan cooler units and their cooling water supply which aze actuated by the safety injection signal which is generated by: a)Coincident low pressurizer pzessure and waeer level in the pressurizer b)Ri.gh containment pressure (approximately lOX of design pressure).
Thissetpointisreachedwellbeforethecoreuncovers.
The backup contaiameac safeguard, ch'e coneaiamene Spray 9ystem, is accuaeed by a high containmenc pzessure signal when the concainmenc pressure reaches appxoximacely 50X of che design value.Automatic spray actuation uses six concainmenc pressuze channels, in 2/3 2/3 logic.The Spxay System can also be actuated manually.Only 2 ouc of 4 fan cooliag units for two or three loop plants and 3 ouc of S cooling units for four loop plaacs are necessary eo limit the containmene pressuxe below design even considering ehac the Emergency Core Cooling Syseem is.unable co suppxess boiling in ehe core, and ehe core decay heac energy continues co be added to ehe containmenc in the form of steam.5.9-1  
Figure5.8-1showstheresultsofacalculation forarepresentative plantforthecompleterangeofbreaksixes.Ztshowsthateitherthepressurixer orthecontainment signalinitiatesafetyin)ection l-l/2minutesormorebeforethecorewouldbeotherwise uncovered.
(Forlargebreaks>passiveaccumulator systemsupplieswateranddelaysthetime.atwhichactivecorecoolingisrequired.)
Thisanalysisincludedtheeffectsofcontainment heatsinksandfancoolersindelayingthetimeatwhichthecontainment highpressuresignalisreached.5.8>>1 SAFETYINJECTION ACTUATION SIG:NLVSBREAKAREA10004o~I+I'~'T~~~iI}.o~l<<~,~~IIIIl~~I~~<<~~}lero,one*oIrI~~~~~<<~t~~>>v~ttt~I~"ttrltt<<~~~I}'-:RangeofProtection ofI:.:PassiveAccumulator System-(;I~IaeI4V100~~ooo1}:<<II~I~~IPtl~~I'~I'<<~~>>:ii}'."~IIt~~I~II~''~~}I~~~~~I~~~v0~~r,~!Ia.~o~~~tt~\~v}'"--ttI~~~~\~~t<<to~o~to~~~I'I~~o~~~~~<<~~~~I<<.)~oIIOIhC10o~~t~<<'oo~I~~I~Itz~~<<'I''''I~'I.....~TimetoReachLouPres-I:-surizerPressureandLevelSignal7>>~~~~\~~~~~~>>~~~~I~I~~~~<<o~<<e~o<<vpttI:TI~I~~*~I~I~I~~~~I~~I"I~}~~~~~~~i-.',I~PI~'~I"I<<I~II~)}=.1-I:ilneceUncavelCaseNddPlaneLNeSadecvlneccdcn)j~o~~~\f<<~~~~~I~~ItI~lel~~~'I~~jjjr"~~iTimetoReachPighContainment PressureSignal'<<ll~~~vI<<j~0.01'iil\~40.1~6"10"DAUEa:.BREAKSIZE(Fi)FIGUPE5.8-1  
~V 59CONTAINMENT PRESSUREPROTECTION Typicalwestinghouse dryconcaiament plantsareequippedwithfaacoolerunicsaadspraysystems.Theseareprovidedtoreducethecontaiamenc pressureeotoesseatially atmospheric following alossofcoolantaccidentorasteamlinebreakaccidentinsidethecontainmeac.
Thecontainment isdesignedtowithstand theeoealblowdownoftheReactorCoolantSyscemorasteamgenerator wiehnodependence oneheaceivesafe-guards.Theactivesafeguards are,however,aueomatically actuatedfollowing cheaccident.
Thepr9narycontainment safeguards arethefancoolerunitsandtheircoolingwatersupplywhichazeactuatedbythesafetyinjection signalwhichisgenerated by:a)Coincident lowpressurizer pzessureandwaeerlevelinthepressurizer b)Ri.ghcontainment pressure(approximately lOXofdesignpressure).
Thebackupcontaiameac safeguard, ch'econeaiamene Spray9ystem,isaccuaeedbyahighcontainmenc pzessuresignalwhentheconcainmenc pressurereachesappxoximacely 50Xofchedesignvalue.Automatic sprayactuation usessixconcainmenc pressuzechannels, in2/32/3logic.TheSpxaySystemcanalsobeactuatedmanually.
Only2oucof4fancooliagunitsfortwoorthreeloopplantsand3oucofScoolingunitsforfourloopplaacsarenecessary eolimitthecontainmene pressuxebelowdesignevenconsidering ehactheEmergency CoreCoolingSyseemis.unablecosuppxessboilinginehecore,andehecoredecayheacenergycontinues cobeaddedtoehecontainmenc intheformofsteam.5.9-1  


Theoperation ofonlyoneofthespraypumpsisrequiredinorderfortheSpraySystemtosupplement theheatremovalcapabiU.ty ofthefancoolingunitstoprovideamarginforeffectsfrommetalmater orotherchemicalreactions thatcouldoccurasaconsequence offailureofEmergency CoreCoolingSystems.Sinceeitherfansorspraysareadequate, anddiversesignalsareusedtoactuatethefans,.the Protection Systemisdiverseforactuation ofcon-tainmentpressureprotection.
The operation of only one of the spray pumps is required in order for the Spray System to supplement the heat removal capabiU.ty of the fan cooling units to provide a margin for effects from metalmater or other chemical reactions that could occur as a consequence of failure of Emergency Core Cooling Systems.Since either fans or sprays are adequate, and diverse signals are used to actuate the fans,.the Protection System is diverse for actuation of con-tainment pressure protection.
5.9-2 5.3.0EXCESSIVE LOAD~rgb~a+&vf"f'>Excessive loadisonemeanswhichcouldcauseexcessive corepowergeneration.
5.9-2 5.3.0 EXCESSIVE LOAD~rgb~a+&vf" f'>Excessive load is one means which could cause excessive core power generation.
Asdistinctfromtheovezpower~vertemperature accidentdiscussed inSection5.3.(RodWithdrawal atPower),reactorcoolanttemperature,
As distinct from the ovezpower~vertemperature accident discussed in Section 5.3.(Rod Withdrawal at Power), reactor coolant temperature, pressuze, and pressurizer water level would not increase.Reactor power follows turbine load, both by contxol design intent and the inherently negative moderator coefficient.
: pressuze, andpressurizer waterlevelwouldnotincrease.
An increase in load above design is therefoxe of potential concern.Diverse overpower protection is provided by Reactor Protection System., These aze the ovezpower delta-T and the nuclear overpower reactor txips-Since the accident is initiated from the secondary plant, the reactor I coolant loop temperatures respond before the core coolant temperature.
Reactorpowerfollowsturbineload,bothbycontxoldesignintentandtheinherently negativemoderator coefficient.
!I Piping lags applicable to the rod withdrawal accident are therefore not applicable to an excessive load accident, and either the delta-T or-the nuclear overpower trip protects the core for any rate or magnitude load increase.5.10-1 p P
Anincreaseinloadabovedesignistherefoxe ofpotential concern.Diverseoverpower protection isprovidedbyReactorProtection System.,Theseazetheovezpower delta-Tandthenuclearoverpower reactortxips-Sincetheaccidentisinitiated fromthesecondary plant,thereactorIcoolantlooptemperatures respondbeforethecorecoolanttemperature.
'C 5.11 EXCESSXVE FEEDWATER FLOW An excessive feedwater flow accident is primarily of concern to the turbine (high water level Xn the steam generator leads to excessive moisture carryover and potentia1 turbine damage).'ith respect to nuclear protection, however, excessive feedwater flow (or feedwater temperature decrease)is seen as an excessive thermal load, and the discussion in Section 5.10 is applicable.  
!IPipinglagsapplicable totherodwithdrawal accidentaretherefore notapplicable toanexcessive loadaccident, andeitherthedelta-Tor-thenuclearoverpower tripprotectsthecoreforanyrateormagnitude loadincrease.
5.10-1 pP
'C5.11EXCESSXVE FEEDWATER FLOWAnexcessive feedwater flowaccidentisprimarily ofconcerntotheturbine(highwaterlevelXnthesteamgenerator leadstoexcessive moisturecarryover andpotentia1 turbinedamage).'ith respecttonuclearprotection, however,excessive feedwater flow(orfeedwater temperature decrease) isseenasanexcessive thermalload,andthediscussion inSection5.10isapplicable.  


512STATIONBLACKOUTAstationblackout, orlossofaU.a-cpowertothestationauxiliaries, resultsfromlossofincomingstationa~powercoincident withaplanttrip.Numerousreactortripsignalswouldbegenerated, suchasturbinetrip,lowcoolantflow,lowgpedwater flow,etc.Thisisnotimportant however,sincethelossofa-cpowerdeenezgizes thezodcontrolpower'upply,andthecontrolrodsfallintothecore,evenifnoreactortripsignalisgenerated.
5 12 STATION BLACKOUT A station blackout, or loss of aU.a-c power to the station auxiliaries, results from loss of incoming station a~power coincident with a plant trip.Numerous reactor trip signals would be generated, such as turbine trip, low coolant flow, low gpedwater flow, etc.This is not important however, since the loss of a-c power deenezgizes the zod control power'upply, and the control rods fall into the core, even if no reactor trip signal is generated.
Naturalcirculation ofreactorcoolanttransfers reactordecayheatfromthecozetothesteamgenerators.
Natural circulation of reactor coolant transfers reactor decay heat from the coze to the steam generators.
Sincesteamgenerator steampressureisautomatically controlled bythepower-operated steamlinereliefvalves(withbackupfromthesteamlinesafetyvalves,ifnecessazy),
Since steam generator steam pressure is automatically controlled by the power-operated steam line relief valves (with backup from the steam line safety valves, if necessazy), the only requirement for maintaining hot shutdown conditions is to Apply feedwater to the steam generatozs.
theonlyrequirement formaintaining hotshutdownconditions istoApplyfeedwater tothesteamgeneratozs.
The auxiLiary feedwater system is discussed in Section 5.2, Loss of Feedwater.
TheauxiLiary feedwater systemisdiscussed inSection5.2,LossofFeedwater.
As noted in that section, the loss of a~power starts all a~iazy pumps-A diverse automatic actuation signal-steam generator low water level-is also provided.Further, the energy sources for the auxiliary feedwater pumps are.themselves diverse (steam-driven pumps and motor-driven pumps energized from the diesel-generator), such that faQ.uze to actuate an energy source does not prevent auxiliary feedwater.
Asnotedinthatsection,thelossofa~powerstartsalla~iazypumps-Adiverseautomatic actuation signal-steamgenerator lowwaterlevel-isalsoprovided.
Further,theenergysourcesfortheauxiliary feedwater pumpsare.themselves diverse(steam-driven pumpsandmotor-driven pumpsenergized fromthediesel-generator),
suchthatfaQ.uzetoactuateanenergysourcedoesnotpreventauxiliary feedwater.
5.12-1  
5.12-1  


APPENDIXCONTROLANDPROTECTION FUNCTIONS reactorcon'tro1andprotection functions performedfromeachprocess~eterinthepresentWestinghouse designareMmlatedbelow.Pro-e~tionfunctions arelistedfirst,andcontrolfunctions listedlast.u~nyfunctions
APPENDIX CONTROL AND PROTECTION FUNCTIONS reactor con'tro 1 and protection functions perf ormed f rom each process~eter in the present Westinghouse design are Mmlated below.Pro-e~tion functions are listed first, and control functions listed last.u~ny functions'.g-, indication, alarms and interlocks, are not clearly either control or protection.
'.g-,indication, alarmsandinterlocks, arenotclearlyeithercontrolorprotection.
~These are classified as"supervisory" unc talons~In the left margin, all functions are listed as P, S or C, showing pro-tection, supervisory or control;-i%JCLEAR INSTRUMENTATION 1,.3.Power Range 1.2 Intermediate Range 1.3 Source Range'W~REACTOR COOLANT SYSTEM PARAMETERS Z.l Reactor Coolanr, Temperature (4T, T)avg 2-2 Pressurizer Pressure 2.3 Pressurizer Water Level 2.4 Reactor Coolant Flow 3~STEAM GENERATOR PARA%.'TERS 3.l Steam Generator Water Level 3.2 Feedwater Flow 3.3 Steam Plow 3 4 Steam Line Pressure 3 S Steam Header Pressure V PARAMETERS Turbine First Stage Steam Pressure Oo m Turbine Auto Stop Oil Pressure Turbine Stop Valve Position~ASTROL ROD POSITION 5.1 Bank Position).Z Individual Rod Position~.CONTAINMENT PRESSURE gZCZRICAL PARAMZERS 7'.1 Reactor Coolant Pump Bus 7.2 Reactor Coolant Pump Breaker Position 7.3 F edwater Pump Power A-2  
~Theseareclassified as"supervisory" unctalons~Intheleftmargin,allfunctions arelistedasP,SorC,showingpro-tection,supervisory orcontrol;-
i%JCLEARINSTRUMENTATION 1,.3.PowerRange1.2Intermediate Range1.3SourceRange'W~REACTORCOOLANTSYSTEMPARAMETERS Z.lReactorCoolanr,Temperature (4T,T)avg2-2Pressurizer Pressure2.3Pressurizer WaterLevel2.4ReactorCoolantFlow3~STEAMGENERATOR PARA%.'TERS 3.lSteamGenerator WaterLevel3.2Feedwater Flow3.3SteamPlow34SteamLinePressure3SSteamHeaderPressure VPARAMETERS TurbineFirstStageSteamPressureOomTurbineAutoStopOilPressureTurbineStopValvePosition~ASTROLRODPOSITION5.1BankPosition).ZIndividual RodPosition~.CONTAINMENT PRESSUREgZCZRICAL PARAMZERS 7'.1ReactorCoolantPumpBus7.2ReactorCoolantPumpBreakerPosition7.3FedwaterPumpPowerA-2  


gJCLEARZNSTRUMENTATION SYSTBtpowerRange-(linearindication inpowerrangeofoperation).
gJCLEAR ZNSTRUMENTATION SYSTBt power Range-(linear indication in power range of operation).
P1.Overpower reactortrip(highrange)-rapiddetection offastoverpower excursions duringpoweroperation.
P 1.Overpower reactor trip (high range)-rapid detection of fast overpower excursions during power operation.
P2.Overpower reactortrip(lowrange)-protection duringlowpowerplantoperation.
P 2.Overpower reactor trip (low range)-protection during low power plant operation.
p3.Top-to-bottom fluxtiltbiasof4Treactortripsetpoints-reduceDNBprotection limitstooffseteffectsofhotchannelfactors.(BothhighdTreactortrips),see2.1,1&3P4.Reactortrippermissives a.Permitsinglelooplossofflowtripathighpower.b.Permitreactortriponturbinetripathighpower.c.Permit"at-power" tripsduringpoweroperation.
p 3.Top-to-bottom flux tilt bias of 4T reactor trip set points-reduce DNB protection limits to offset effects of hot channel factors.(Both high dT reactor trips), see 2.1, 1&3 P 4.Reactor trip permissives a.Permit single loop loss of flow trip at high power.b.Permit reactor trip on turbine trip at high power.c.Permit"at-power" trips during power operation.
d.Defeat,manualblockoflowrangeand&termediate rangeoverpower tripsatlowpower.e.Lockoutsourcerangehighvoltagesupplyduringpoweroperation.
d.Defeat, manual block of low range and&termediate range overpower trips at low power.e.Lock out source range high voltage supply during power operation.
S5.Roddropdetection
S 5.Rod drop detection-rod stop and turbine runback to maintain DNB margins.6-Overpower rod stop.-stop a power excursion caused by rod withdrawal.
-rodstopandturbinerunbacktomaintainDNBmargins.6-Overpower rodstop.-stopapowerexcursion causedbyrodwithdrawal.
7.Overpower alarm (for equipment purposes, this function is combined with the overpower rod stop).8.Control room indication and recording (including top-to bottom difference).
7.Overpower alarm(forequipment
Channel deviation alarm-detect channel failure, detect flux tilts.10.Top-to<<bottom flux tilt bias of dT rod stop and turbine runback set points (see 2-1, 264).A 3
: purposes, thisfunctioniscombinedwiththeoverpower rodstop).8.Controlroomindication andrecording (including top-tobottomdifference).
Channeldeviation alarm-detectchannelfailure,detectfluxtilts.10.Top-to<<bottom fluxtiltbiasofdTrodstopandturbinerunbacksetpoints(see2-1,264).A3


Automatic controlrodmotion-providestablereactorcontrolandrapidresponse.
Automatic control rod motion-provide stable reactor control and rapid response.gntermediate Ran e-(Logarithmic scale for power range and upper startup range)p'.High level reactor trip-prevent power increase into power range unless power range channels are indicating.
gntermediate Rane-(Logarithmic scaleforpowerrangeandupperstartuprange)p'.Highlevelreactortrip-preventpowerincreaseintopowerrangeunlesspowerrangechannelsareindicating.
p 2.Defeat manual block of source range high level trip-low intermediate range indication rearms source range trip.S 3.High leve1 rod stop-prevents excessive withdrawal of control rods during low power operation.
p2.Defeatmanualblockofsourcerangehighleveltrip-lowintermediate rangeindication rearmssourcerangetrip.S3.Highleve1rodstop-preventsexcessive withdrawal ofcontrolrodsduringlowpoweroperation.
S 4.Control room indicating and recording.
S4.Controlroomindicating andrecording.
S 5.Startup rate indication.
S5.Startuprateindication.
P.l.High leveL reactor trip-prevent startup accident from source range;prevent power increase into intermediate range unless intermediate range channels are indicating.
P.l.HighleveLreactortrip-preventstartupaccidentfromsourcerange;preventpowerincreaseintointermediate rangeunlessintermediate rangechannelsareindicating.
S 2.High count rate alarms-warn of approach to cripicality.
S2.Highcountratealarms-warnofapproachtocripicality.
S'.Control room indication and audible count.range.S 4..Startup rate indication.
S'.Controlroomindication andaudiblecount.range.S4..Startup rateindication.
A-4  
A-4  
~Nc.sgP't"K5  
~N c.s gP't"K5  
<<<CTORCOOLANTSYSTEMPARAMETER orCoolantTemeraeure(4T-T)avgOvereemperature high4Treactortrip-preventcoreDNB(setpointcalculated fromT,pressure, andnuclearavg'luxaxialtilt).2.Overtemperacure high4Trodstopandturbinecueback-maintainoperating margineoDNB(setpointisafixedmarginbelowreactortripsetpoint).3.Overpower high4Treactorezip>>preventhighpowerdensity(seepointcalculaeed fromnuclearfluxtile)i4.Overpower high4Trodscopandturbinerunback-maintainoperating powerdensity(seepointisafixedmarginbelowreactortripsetpoint).S5.Channeldeviation alarms-deeectchannelfailures, detectabnormalprocesscandieions.
<<<CTOR COOLANT SYSTEM PARAMETER or Coolant Tem eraeure (4T-T)avg Overeemperature high 4T reactor trip-prevent core DNB (set point calculated from T , pressure, and nuclear avg'lux axial tilt).2.Overtemperacure high 4T rod stop and turbine cueback-maintain operating margin eo DNB (set point is a fixed margin below reactor trip set point).3.Overpower high 4T reactor ezip>>prevent high power density (see point calculaeed from nuclear flux tile)i 4.Overpower high 4T rod scop and turbine runback-maintain operating power density (see point is a fixed margin below reactor trip set point).S 5.Channel deviation alarms-deeect channel failures, detect abnormal process candieions.
S6.Controlroomindication andrecording.
S 6.Control room indication and recording.
S7.Controlrodinsertion limitalarm-maintainreactiviey shutdownmargin;maintainlowejectedrodworth;maintain,uniformcoreburnup.fr.8.LowTalarm(interlocked withhighscesmflowforsteamavglineisolation)
S 7.Control rod insertion limit alarm-maintain reactiviey shutdown margin;maintain low ejected rod worth;maintain , uniform core burnup.f r.8.Low T alarm (interlocked with high scesm flow for steam avg line isolation)
-steambreakprotection.
-steam break protection.
Inadditiontotheabovefunctions for4TandT,Tisalsoavg'vgused09.HighTalarm.avg10.Tchanneldeviation rodscop(ofautomatic motion)-avgpreventspuriousrodwithdrawal orinsertion.
In addition to the above functions for 4T and T, T is also avg'vg used 0 9.High T alarm.avg 10.T channel deviation rod scop (of automatic motion)-avg prevent spurious rod withdrawal or insertion.
11.Tdeviation alarm-deviacion framprogrammed setpoinc.
11.T deviation alarm-deviacion fram programmed setpoinc.avg  
avg  


Automatic controlrodmotion-controlcorepowex'omain>>tainprogrammed tempex'ature.
Automatic control rod motion-control core powex'o main>>tain programmed tempex'ature.
13~Steamdumpcontrol(condenser steamdump)-removeexcessenergyfromreactorcoolant.14.Feedwater valvecontrol-controladditiontosubcooled watertosteamgenerators following aplanttrip.15.Pressurizer levelprogramming
13~Steam dump control (condenser steam dump)-remove excess energy from reactor coolant.14.Feedwater valve control-control addition to subcooled water to steam generators following a plant trip.15.Pressurizer level programming
-determine levelsetpointtominimizechargingandletdownchangesduringloadchanges.2.2Pressurizer Pressurep1.Highpressurereactortrip-maintainpressureinATprotection range;provideoverpressure backuptosafetyvalves.P2.Lowpressurereactortrip-maintainpressurein4Tprotection range.P3.Lowpressuresafeguax'ds actuation
-determine level setpoint to minimize charging and letdown changes during load changes.2.2 Pressurizer Pressure p 1.High pressure reactor trip-maintain pressure in AT protection range;provide overpressure backup to safety valves.P 2.Low pressure reactor trip-maintain pressure in 4T protection range.P 3.Low pressure safeguax'ds actuation-actuate loss of coolant protection.
-actuatelossofcoolantprotection.
P 4.High pressuxe defeat of safeguards actuation manual block-I.automatically renave manual block as operating pressure is approached.
P4.Highpressuxedefeatofsafeguards actuation manualblock-I.automatically renavemanualblockasoperating pressureisapproached.
P 5-Compensate overtemperature AT reactor trip setpoint-core DNB pzotection.
P5-Compensate overtemperature ATreactortripsetpoint-coreDNBpzotection.
6.Compensate qvertemperature T rod stop and.turbine runback setpoint-maintain operating margin to DNB.Control room indication and recording.
6.Compensate qvertemperature Trodstopand.turbinerunbacksetpoint-maintainoperating margintoDNB.Controlroomindication andrecording.
8 High-low pressure alarms.Low pressure relief valve interlock-close relief valves on 10.low pressure to avoid accidental loss of coolant./Pxessure control (on-off heaters, vaziable heatexs, spray, and x'elief valve actuation)
8High-lowpressurealarms.Lowpressurereliefvalveinterlock
-maintain normal operating pressure.A-6 F
-closereliefvalveson10.lowpressuretoavoidaccidental lossofcoolant./Pxessurecontrol(on-offheaters,vaziableheatexs,spray,andx'eliefvalveactuation)
11.Compensation signal for automatic control rod motion-improve reactor control response.2.3 Pressurizer Water Level-(This variable measures reactor coolant fluid inventory and mean temperature).
-maintainnormaloperating pressure.
P 1.High level reactor trip-prevent water discharge (an relief piping damage)through safety valves following rapid insurge.P 2.Low level safegnards actuation-indication of loss of reactor coolant.S 3.Control room indication and recording.
A-6 F
S 4.High-low level alarms.S 5.Low level heater cutoff-prevent energizing heaters when uncovered (equipment protection).
11.Compensation signalforautomatic controlrodmotion-improvereactorcontrolresponse.
S 6.Low level letdown isolation-prevent loss of coolant by excessive letdown.C 8.High-low level deviation alarm-deviation from level set-point.Charging pump speed control-maintain progranmN.d water level.C 9.High level deviation heater a'ctuation
2.3Pressurizer WaterLevel-(Thisvariablemeasuresreactorcoolantfluidinventory andmeantemperature).
-heat subcooled water insurge.2.4 Reactor Coolant F P 1.Low flow reactor trip-prevent core DNB.S 2.Control room indication-A-7 P
P1.Highlevelreactortrip-preventwaterdischarge (anreliefpipingdamage)throughsafetyvalvesfollowing rapidinsurge.P2.Lowlevelsafegnards actuation
3 ST~GENERATOR PRtAK'.TERS Steam Generator Water Level-(This variable is a measure of water inventory in steam generators).
-indication oflossofreactorcoolant.S3.Controlroomindication andrecording.
p l.Low-low water level reactor trip and auxiliary feedwater pump start-protect steam generators; preserve normal heat sink for removal of early decay heat.p 2.Low level reactor trip (coincident with low feedwater flow)-provide rapid protection against a complete loss of f eedwater flow.S 3.High level feedwater control valve override-close feed-water valve to prevent excessive moisture carryover and turbine damage.S 4.High-low level.alarms.S 5.Control room indication and recording.
S4.High-lowlevelalarms.S5.Lowlevelheatercutoff-preventenergizing heaterswhenuncovered (equipment protection).
S 6.Level deviation alarm-deviation from programmed level.C 7.Feedwater valve control-maintain desired steam generator level.l 3.2 Feedwater Flow P 1.Low feedwater flow reactor trip (coincident with low steam generator water level)-provide rapid protection against complete loss of feedwater flow.S 2.Control room indication and recording.
S6.Lowlevelletdownisolation
C 3.Feedwater valve control>>provide stable control of steam generator level.3.3~Se~F1 ow P.1.Set point for low feedwater flow reactor trip (see 3.2.1 above).P 2.High steam flow steam line isolation-steam break protection.  
-preventlossofcoolantbyexcessive letdown.C8.High-lowleveldeviation alarm-deviation fromlevelset-point.Chargingpumpspeedcontrol-maintainprogranmN.d waterlevel.C9.Highleveldeviation heatera'ctuation
't V 4 S 3~C 4 Control room indication and recording.
-heatsubcooled waterinsurge.2.4ReactorCoolantFP1.Lowflowreactortrip-preventcoreDNB.S2.Controlroomindication-A-7 P
Feedwater valve control-provide rapid res'ponse gf cgntzot for steam generator level.3.4 Steam Line Pressure>~, W/!-P 1.Low pressure (or tuic differential pressure)safe~d actuation-steam break protection P,C 2.Compensation of steam flow channels-provide accurate signal of steam flow.S 3~S 4.C.5.Low steam pressure alarm.Control room indication and recording.
3ST~GENERATOR PRtAK'.TERS SteamGenerator WaterLevel-(Thisvariableisameasureofwaterinventory insteamgenerators).
Control of steam line relief valves-minimize actuation g f safety valves.3.5 Steam Header Pressure C 1.Contzol steam dump to condenser.
pl.Low-lowwaterlevelreactortripandauxiliary feedwater pumpstart-protectsteamgenerators; preservenormalheatsinkforremovalofearlydecayheat.p2.Lowlevelreactortrip(coincident withlowfeedwater flow)-providerapidprotection againstacompletelossoffeedwaterflow.S3.Highlevelfeedwater controlvalveoverride-closefeed-watervalvetopreventexcessive moisturecarryover andturbinedamage.S4.High-lowlevel.alarms.S5.Controlroomindication andrecording.
S 2.Control zoom indication
S6.Leveldeviation alarm-deviation fromprogrammed level.C7.Feedwater valvecontrol-maintaindesiredsteamgenerator level.l3.2Feedwater FlowP1.Lowfeedwater flowreactortrip(coincident withlowsteamgenerator waterlevel)-providerapidprotection againstcompletelossoffeedwater flow.S2.Controlroomindication andrecording.
,F TUgBXNE PARAMETERS Turbine First Sta e Steam Pressure-(This variable is proportional to turbine steam load).p l.Reactor trip permissives
C3.Feedwater valvecontrol>>providestablecontrolofsteamgenerator level.3.3~Se~F1owP.1.Setpointforlowfeedwater flowreactortrip(see3.2.1above).P2.Highsteamflowsteamlineisolation
-pexmits"at-power" reactor trips above minimum turbine load.p 2.Steam line isolation-determines set point for high steam flow for steam break protection.
-steambreakprotection.  
S 3.Control room indication.
'tV4 S3~C4Controlroomindication andrecording.
S 4.Low power block of automatic control rod withdrawal-prevents unstable reactor control.S 5.Steam dump interlock-prevents operation of steam dump to condenser unless a rapid loss of load has occurred.C 6.T program-determines set point for T in control avg avg rod and steam bypass control systems.C 7.Steam generator level program-determine set point for level in feedwater control system.4.2 Turbine Auto-Sto Oil Pressure-(Presence or absence of oil pressure indicates'trip or non-trip condition of turbine).1.Reactor trip-prevent temperature-pressure excursion in reactor coolant from loss of steam load.C 2.Steam bypass control-selects mode of contxol.3.Feedwater control-selects mode of control, steam generator water level or T avg 4~3 Turbine Sto Valve Position-used as backup to autostop oil pressure fox reactor trip signal.
Feedwater valvecontrol-providerapidres'ponse gfcgntzotforsteamgenerator level.3.4SteamLinePressure>~,W/!-P1.Lowpressure(ortuicdifferential pressure) safe~dactuation
CO~OL ROD POSITION Bank Position-(SteP counters)Bank insertion limit alarm (set point determined from and 4T)-maintain reactivity shutdown margins;avg maintain acceptable core power distribution.
-steambreakprotection P,C2.Compensation ofsteamflowchannels-provideaccuratesignalofsteamflow.S3~S4.C.5.Lowsteampressurealarm.Controlroomindication andrecording.
S 2, Bank withdrawal limf.t alarm-warn operator that control rods are nearing the end of their useful travel.S 3, Control zoom indication and recording 5.Z Individual Rod Position (LVDT)S l.Rod position'deviation alarm-warn of possible rod malpositioning.
Controlofsteamlinereliefvalves-minimizeactuation gfsafetyvalves.3.5SteamHeaderPressureC1.Contzolsteamdumptocondenser.
S Z.Rod bottom rod drop detection-rod stop and turbine runback to maintain DNB margins.S 3.Control zoom indication and recording=
S2.Controlzoomindication
CPNTAZgKNT PRESSURE p l.High containment pressure safeguards actuation and reactor trip-protection against small steam breaks, backup protection for loss of coolant accidents and large steam breaks.-P 2.High containment pressure steam line isolation p 3.High containment pressure spray actuation.
,F TUgBXNEPARAMETERS TurbineFirstStaeSteamPressure-(Thisvariableisproportional toturbinesteamload).pl.Reactortrippermissives
S 4.Control room indication.
-pexmits"at-power" reactortripsaboveminimumturbineload.p2.Steamlineisolation
A>>12 ELECTRICAL SYSTEM VARIABLES Resistor Coolant Pump Bus P l.Underyoltage reactor trip-protection against multi-loop loss of flow.p 2i Underfrequency reactor trip and RCP breaker opening-prevent rapid system frequency opening-prevent rapid system.fre-quency decrease from braking RCP.7.2 Reactor Coolant Pump Breaker Position (contacts)
-determines setpointforhighsteamflowforsteambreakprotection.
P 1.Reactor trip on breaker opening-backup.to low flow protection for loss of flow.7.3 Feedwater Power P l.Auxiliary feedwater system actuation (feedwater pump breaker position and/or bus voltage)-backup feedwater protection for loss of feedwater.
S3.Controlroomindication.
A-l3 ATTACHMENT 8 TO AEP:NRC'1184H2 RESPONSE TO ITEM 8 DEFENSE-IN-DEPTH EVALUATION PERFORMED FOR THE REACTOR PROTECTION AND CONTROL PROCESS INSTRUMENTATION REPLACEMENT PROJECT}}
S4.Lowpowerblockofautomatic controlrodwithdrawal-preventsunstablereactorcontrol.S5.Steamdumpinterlock
-preventsoperation ofsteamdumptocondenser unlessarapidlossofloadhasoccurred.
C6.Tprogram-determines setpointforTincontrolavgavgrodandsteambypasscontrolsystems.C7.Steamgenerator levelprogram-determine setpointforlevelinfeedwater controlsystem.4.2TurbineAuto-StoOilPressure-(Presence orabsenceofoilpressureindicates'trip ornon-tripcondition ofturbine).
1.Reactortrip-preventtemperature-pressure excursion inreactorcoolantfromlossofsteamload.C2.Steambypasscontrol-selectsmodeofcontxol.3.Feedwater control-selectsmodeofcontrol,steamgenerator waterlevelorTavg4~3TurbineStoValvePosition-usedasbackuptoautostopoilpressurefoxreactortripsignal.
CO~OLRODPOSITIONBankPosition-(StePcounters)
Bankinsertion limitalarm(setpointdetermined fromand4T)-maintainreactivity shutdownmargins;avgmaintainacceptable corepowerdistribution.
S2,Bankwithdrawal limf.talarm-warnoperatorthatcontrolrodsarenearingtheendoftheirusefultravel.S3,Controlzoomindication andrecording 5.ZIndividual RodPosition(LVDT)Sl.Rodposition'deviation alarm-warnofpossiblerodmalpositioning.
SZ.Rodbottomroddropdetection
-rodstopandturbinerunbacktomaintainDNBmargins.S3.Controlzoomindication andrecording=
CPNTAZgKNT PRESSUREpl.Highcontainment pressuresafeguards actuation andreactortrip-protection againstsmallsteambreaks,backupprotection forlossofcoolantaccidents andlargesteambreaks.-P2.Highcontainment pressuresteamlineisolation p3.Highcontainment pressuresprayactuation.
S4.Controlroomindication.
A>>12 ELECTRICAL SYSTEMVARIABLES ResistorCoolantPumpBusPl.Underyoltage reactortrip-protection againstmulti-loop lossofflow.p2iUnderfrequency reactortripandRCPbreakeropening-preventrapidsystemfrequency opening-preventrapidsystem.fre-quencydecreasefrombrakingRCP.7.2ReactorCoolantPumpBreakerPosition(contacts)
P1.Reactortriponbreakeropening-backup.to lowflowprotection forlossofflow.7.3Feedwater PowerPl.Auxiliary feedwater systemactuation (feedwater pumpbreakerpositionand/orbusvoltage)-backupfeedwater protection forlossoffeedwater.
A-l3 ATTACHMENT 8TOAEP:NRC'1184H2 RESPONSETOITEM8DEFENSE-IN-DEPTH EVALUATION PERFORMED FORTHEREACTORPROTECTION ANDCONTROLPROCESSINSTRUMENTATION REPLACEMENT PROJECT}}

Revision as of 07:09, 6 July 2018

RPS Diversity in Westinghouse Pwrs.
ML17332A851
Person / Time
Site: Cook American Electric Power icon.png
Issue date: 04/30/1969
From: BURNETT T W, DORRYCOTT J W, RISHER D H
WESTINGHOUSE ELECTRIC COMPANY, DIV OF CBS CORP.
To:
Shared Package
ML17332A849 List:
References
WCAP-7306, NUDOCS 9507180151
Download: ML17332A851 (276)


Text

{{#Wiki_filter:wnu-7306 NUCLEAR ENERGY SYSTEMS CLASS 3 REACTOR PROTECTION SYSTEM DIVERSITY ZN WESTINGHOUSE PRESSURIZED WATER REACTORS April 1969 Author: T.Q.T.Burnett Contributors: J.W.Dorrycott A.C.Hall D.H.Risher APPROVED: S.ore, Manager Core Engineering Westinghouse Electric Corporation Nuclear Energy Systems Division P.O.Box 355 Pittsburgh, Pennsylvania 15230 9507180151 950707 PDR ADQCK 05000315 9 PDR<3RZ Restintthouse Electric Corp./ FOREWORD Over the past four years, considerable attention has been focused on design cx'iteria and methods of implementation for nuclear power plant protection systems.Of paxticular difficulty has been che"establishment of suitable criteria to deal with the problems of single and multiple failures, channel independence, Control and Proteccion System independence, and the'eviation of Protection System inputs..A key factor in this difficulty has b'een the conflict between the goal to minimize the number of redundant measurements fox'ny single process variable, with regaxd to the overall nuclear plane requirements, and the goal to establish a auucbnum degree of separation between the Protection System and the Control System.Obtaining an accurate and reliable measuxement of a particular process variable is one of the most difficult aspects of an instrumentacdon system.There are significant problems associated with the physical mounting of the measurement devices including optimum location, supporting structuxes, access to che equipment for maintenance, and protection against adverse environmental factors.In the case of nuclear power plants, there is also the problem of transmitting the signals fxom the containment to the control room equipment. All of these factors provide arguments for minimizing the number of separate measuremencs. Most of the functions performed by the plant Control System require the same process information as the Protection System.In these cases, Westinghouse provides Control System inputs from Protection System channels.The"Proposed IEEE Criteria for Nuclear Power Plant Protection Systems," IEEE No.279, permits this design approach, sub)ect to certain restrictions. However, this proposed resolution was not unanimously accepted by members of other United States standards and regulatory agencies, in particular, USASX Sectional Committee N3 (N42), and the AEC-ACRS.Westinghouse held meetings with members of the AEC to clarify the Westinghouse design approach and to identify the additional design criteria applied by Westinghouse, which go beyond the proposed IEEE criteria.These additional criteria require separation and identification of control and protection equipment and the use of isolation devices to transmit signals from the Protection System to the Control System.It is the position of Westinghouse that these additional criteria offer a resolution to the'tated design conflict.Westinghouse has demonstrated by actual implementation of these criteria that a high degree of separation, including proper identification, can be achieved between Protection System equipment and Control System equipment. More recently, the question of the failure mode changed from that of a single random failure to common-mode failure-a failure mode which would adversely affect all, redundant channels of a particular protective function in the Protection System.It is generally recognized that separation of control and protection does not provide defense against the common-mode failures. The nuclear power plant Control and Protection System design employed by Westinghouse was evaluated in detail with respect to the commonmode failure and presented in a series of meetings to members of the AEC.This report documents the information transmitted in these meetings and provides a technical basis for the development of criteria for design of Protection Systems with adequate consideration for common-mode failures.The conclusion of Westinghouse based>upon actual experience, previous work, and reinforced by the results presented herein, is that design criteria for nuclear power plant protection systems should permit magnum effective use of process measurements both for control and protection functions including the use of Protection System measurements in the Control.System.Such criteria significantly enhance the designer's capability to provide a system with adequate capability to deal with the majority of common~ode failures t as well as to provide redundancy for critical control functions. J.M.Gallagher,'Jr. Consulting Engineer-Control Technology Vestinghouse design philosophy for Reactor Protection and Control Systems is to make maxiunaa use, for both protection and control functions, of a wide range of measurements. The Protection and Control Systems are separate and identifiable. The design approach permits not only redundancy of control, providing its own desirable increment to overall plant safety, but also provides a Protection System which continuously monitors numerous system variables by different means;i.e., protection system diversity. The extent of Protection System diversity has been evaluated for a wide variety of postulated accidents. In most cases, two or more=diverse pro-tective functions. would terminate an accident before intolerable consequences could occur.

teetiee 1 1.1 1.2 2 3 3.1 3.1.1 3.1.2 3.1.3 3.1.4 3.1.5 3.2 3.2.3., 3.2.2 3.3 TABLE OF CONTENTS Title ABSTRACT INTRODUCTION COMMONMODE FAILURES AND.DIVERSITY PROTECTION SYSTEM EVALUATION QjMMARY FUNCTIONAL DESCRIPTION, REACTOR CONTROL AND PROTECTION SYSTEM REACTOR PROTECTION SYSTEM GENERAL REACTOR TRIPS Manual Trip High Nuclear Power (Power Range)High Nuclear Power (Intermediate Range)High Nuclear Power (Source Range)Overtemperature 4T Trip Overpower 4T Trip'Low Pressure Trip High Pressure Trip High Pressurizer Water Level Trip Low Reactor Coolant Flow Safety In)ection System Actuation Trip (SIS)Turbine Trip Low Feedwater Flow Reactor Trip Low Steam Generator Water Level Trip PERMISSIVE CIRCUITS List of Permissive Circuits ROD STOPS Rod Stop List INDICATION Control Board Indicators and Recorder Central Board Annunciator Panel Control Board Status Panel STEAM DUMP CONTROL SYSTEM CONDENSER STEAM DUMP SYSTEM System Design Control System Load Refection Control Turbine Trip Control Pressure Control ATMOSPHERIC STEAM RELIEF SYSTEM REACTOR CONTROL The Temperature Chanel The Power Mismatch Channel The Pressure Channel The Rod Speed Program~Pa e iv 1>>1 l-l 1-5 2 1 3.1-1 3.1-1 3.1>>1 3.1-1 3.1-1 3.1-1 3.1-2 3.1-2 3.1-3 3.1-3 3.1-4 3.1W 3.1-5 3.1>>5 3.1-6 3.1-7 3.1-7 3.1-7 3.1-8 3.1-8 3.1-9 3.1-9 3.1-10 3.1-10 3.'1-10 3.1-11 3.2-1 3.2-1 3.2-1 3e2~3 3e2~3 3.2-4 3.2-5 3.2-6 3.3-1 3.3-1 3.3-1 3'~2 3~3 2 Seetiet 3,4'.5 3.5.1 3.5.2 3.5.3 4 4.1 4.2 4.3 4.4 4.4.1 4.4.2 4.4.3 4.4.4 4.4.5 4.4.6 5 5.l.5.1.1 5.1.2 5.1.3 5.1.4 5.2 5.2.1~5.2.2.;:!.5.3 5.3-1 5-3.2 TABLE OP CONTENTS (Cont'd)Title STEAM GENERATOR LEVEL CONTROL STEAM BREAK PROTECTION SYSTEM SAFETY INJECTION SYSTEM ACTUATION FEEDWATER LINE XSOLATION STEAM LINE ISOLATION PROTECTION AND CONTROL SYSTEMS DESXGN PRINCIPLES PROTECTION SYSTEM FUNCTIONAL DESIGN CONTROL SYSTEM PJNCTIONAL DESXGN CONTROL AND PROTECTION INTERRELATION SPECIFIC CONTROL AND PROTECTION INTERACTIONS NUCLEAR FLUX COOLANT TEMPERATURE PRESSURIZER PRESSURE Control of Rod Motion Pressure Control Low Pressure High Pressure PRESSURIZER LEVEL High Level Low Level STEAM GENERATOR WATER LEVEL FEEDWATER PLO..Feedwater Flow Steam Flow Level STEAM LINE PRESSURE ACCIDENT EVALUATXON ROD WITHDRAWAL ACCIDENT I PROBABLE CONSEOUENCES OF ACCIDENT PROBABILITY OF ACCIDENT MANUAL INTERVENTION DIVERSXTY OF REACTOR TRIPS LOSS OF FEEDWATER LOSS OF FEEDWATER-TRANSIENT ANALYSIS TYPXCAL SYSTEM DESIGN REOUIR1M2KS Auxiliary Feedwater System Main Steam and Feedwater Piping LOSS OF COOLANT PLOW ANALYSIS ZNTRODUCTION AND

SUMMARY

PROTECTION SYSTEM DESCRIPTXON Low Reactor Coolant Plow Reactor Coolant Pump Low Voltage Reactor Coolant Pump Low Frequency Pump Circuit Breaker Position Overpower Delta-T Reactor Trip Interlocks ~Pa e 3.4-1 3.5-1 3.5-1 3-5-1 3.5-1 4.1<<1 4.1-1 4.2-1 4.3-1 4.4-1 4.4-1 4e 4-2 4.4-3 4.4-3 4.M3 4.4-3 4.4-4 4.4-4 4.4-5 4.4-5 4.4>>6 4.4>>7 4.4-8 4.4-8 4.4-8 5.3.-1 5.1-1 5.1-2 5.1-4 5.1-4 5.1-6 5.2-1 5.2-2 5.2-4 5.2-4 5.2-6 5.3-1 5.3-1 5.3-1 5.3-2 5.3-2 5.3-2 5.3-3 5.3-3 5.3-4 1 4 C Sectice 5.3.3 5.3.4 5.3.5 5.4 5.4.1 5.4.2 5.4.3 5.5 5.5.1 5.5.2 5.5.3 5.5.4 5.6 5.7 5.8 5.9 5.10: 5.11 5.12 TABLE OF CONTENTS (Cont'd)Title MULTILOOP LOSS OF FLOW SINGLE LOOP LOSS OF FLOW LOCKED ROTOR ACCIDENT ROD EJECTION ANALYSIS INTRODUCTION AND

SUMMARY

CASES CONSIDERED IN DETAIL Zero Power Case Full Power End of Life Coze BACK-UP TRIP PROTECTION LOSS OF STEAM LOAD INTRODUCTION AND

SUMMARY

LOSS OF LOAD PROTECTION AND DESIGN CRITERIA Steam Dump to Condenser Pressurizer Pressure Relief Steam System Pressure Relief Direct Reactor Trip High Pressurizer Pressure Trip Overtemperature 4T High Pressurizer Level Trip EVALUATION OF'PROTECTION SYSTEM FOR LOSS OF LOAD Initiation of Accident Analysis and Discussion CONCLUSIONS ROD WITHDRAWAL DURING STARTUP CONTROL ROD DROP ENGINEERED SAFEGUARDS ACTUATION CONTAINMENT PRESSURE PROTECTION EXCESSIVE MAD EXCESSZVE FEEDWATER PLOW STATION BLACKOUT CONTROL AND PROTECTION FUNCTIONS~Pa e 5.3-4 5.3-6 5.3-7 5.4-1 5.4-1 5.4-1 5.4 1 5.4-2 5.4-3 5.5-1 5.5-1 5.5-2 5.5-2 5.5-3 5.5-3 5.5-3 5,5~4 5.5W 5.5-4 5.5-5 5.5-5 5.5-7 5.5-9 5.6 1 5.7-1 5.8-1 5.9-1 5.10-1 5.11-1 5.12-1

LIST OF FIGURES~Fg ure No.2-1 Illustration of Control and Protection Design 3.1-1 3.1-2 3.2-1 3.3-2 3.3-1 Overtemperature dT Channel Overpower dT Channel Steam Cycle Valve Arrangement Condenser Steam Dump Control Scheme Reactor Control System 4.2-1 4.3-1 5.1-1 5.1-2 5.1-3 5.1-4 5.1-5 5.1-6 5.1-7 5.1-8 5.1-9 5.1-10 5 2-1 5 2 2.~5.2-3 5.2-4 5.2-5 5.2-6 5.2-7 5.2-8 5.2-9 5.3-I.5-3-2 5+3 3 5.3-4 5.3-5 5.3-6 Steam Generator Level Contxol and Protection System Pressurizer Pressure Protection and Contxol Systems Design I Fault Tree fox Rod Withdrawal Accident Fault Tree for Rod Withdrawal Accident Inserted Rod Wox'th and Reactivity Required to Reach DNBR~1.0 in Hot Assembly Versus Core Life Complete Rod Withdrawal from Maximum Full Power Complete Rod Withdrawal from Maximum Full Power Steady State Core Limits and Reactor Trip and Alarm Points Beginning of Life, Rod Withdrawal from 102X Power, Minimum DNBR Beginning of Life, Rod Withdrawal from 102X Power, Time of Event Beginning of Life, Rod Withdrawal from 80X Power, Resulting Minimum DNBR Beginning of Life, Rod Withdrawal from 80X Power, Time of Event Fault Tree for Loss of Feedwater Flow Fault Tree for Loss of Feedwater Flow Fault Tree for Loss of Feedwater Flow Level Response to Loss of Steam Flow Signal Loss of Feedwater Flow to One Steam Generator at T~One Second, Typical Two-Loop Plant Loss of Feedwater Flow to One Steam Generator at T~One Second, Typical Two-Loop Plant Complete Loss of Feedwater Complete Loss of Feedwater Auxiliary Feedwater System Schematic, Two-Loop Plant Fault Tree for Multi-Loop Loss of Flow Fault Tree for Single Loop Loss of Flow Fault Tree for Locked Rotor Accident Multi-Loop Loss of Flow, Typical Plant Single Loop Loss of Flow, Two Loop Plant Locked Rotor Loss of Flow, Two Loop Plant ~e+l y I A'I'I'lh P l 0 V 0 LIST OF FIGURES (Cont'd)Fi ure No-5.4-1 5.4-2 5.4-3 5.4-4 5.5-1 5.5>>2 5.5-3 5.6-1 5.6-2 5.7-1.5.7 2 5.8-1 Zero Power End of Life Rod Ejection, No Trip Full Power End of Life Rod Ejection, No Trip Illustration of Safety Limits and Trip Points for Rod Ejection Accidents, No Trip Illustration of Transient Trajectories for Rod Ejection Accidents, With No Trip Fault Tree for Loss of Load Accident Fault Tree for Core Damage, Loss of Steam Load Loss of Load Accident Uncontrolled Rod Withdrawal from Subcritical, Fraction of Nuclear Power Uncontrolled Rod Withdrawal from Subcritical Condition, Temperature Response to a Dropped Control Rod Response to a Dropped Control Rod Safety Injection Actuation Signal vs Break Area ~e mme~e'~'%q el t*4 9~*t 1.INTRODUCTION p o ophy for Reactor Protection and Co ol tomaema xaum use for both protection and control functions of a wide range of measurements. This results in a broad spectrum of redundant protection and control functions. The design approach used permits all equipment components to be identified as protection or control and located accordingly, with electrical isolation and physical separation between them.The design approach thus permits not only reduncancy of contx'ol, providing a significant and desirable increment to overall plant safety, but also provides a Protection System which continuously monitors numerous system vax'iables by different means;i.e., Protection System diversity. Although the Protection System design basis requires only that random single failures not negate the Protection System, a considerable depth of protection I is achieved by the Westinghouse design approach.Systems designers and re-viewers have xecently emphaaLzed the importance of achieving a suitable balance of design obfectives in regard to functional and equipment diversity. "'nteraction of control and protection functions, testing, and surveillance to~thieve a Protection System design that has adequate capability to cope with both random and systematic failure modes.(Systematic failures are also known as common-mode, or nonrandom failures.)

1.1 COMMONWODE

FAILURES AND DIVERSITY Common-mode, or systematic failures, are those that partially or completely prevent identical, instrument channels from performing their function-p'~.4*/I dundancy is no t an answer to this tyPe o f f ailure, since all channels are assume~ed to be affected.Further, these failures cannot be evaluated by pro ao~bability analysis or reliability data;indeed, they are characterized by oversights or deficiencies which presumably would be corrected when first detected.The general categories of common~ode failures are: a)Functional deficiency -The variable being monitored does not provide the information intended during the course of an accident.This deficiency could be caused by the accident's following a different course/than calcu1ated by the designers, or by a change in the plant characteristics which changes the relation between the pxocess and the variable being monitored. b)Maintenance error-This failure includes consistent miscalibration of all channels of a type, and also circuit modification ox repqir which inadvertently renders the channels functionally inoperative.'esign deficiency -Pailuxe of the equipment as installed to meet functional requirements. This could arise thxough unrecognized dependence on a single, common element., such as ventilation; by an unexpected charpcteristic (such as saturation or slow response)in all controllers of a type;or by the instrumentation being disabled as a result of the accident-d)~<<mal catastrophe -With proper isolation and separation between redundant channels, this is confined to ma)or disasters such as flood,<<rthquake, fire, etc.Where separation is not complete, less drastic~vents can have the same result.For example, a falling ob)ect could conceivably sever all cables in a small area.1-2 t+J~~N Considerable effort is being made in Reactor Protection Systems design prevent these common-mode failures, as illustrated by the examples below.However remote, the possibility of a commonmode failure must nevertheless be considered. The likelihood of maintenance errors can be minimized by proper administrative procedures, identif ication of Protection System components, and complete documentation of the as-supplied Protection System, including the design basis.Design deficiencies can be largely.eliminated by equipment qualification testing and by caxeful review of all potential common elements.Redundancy is an accepted defense against x'andom failures which affect only one component or channel at a time.Similarly,"cliversity is a defense against common~de failures which could affect multiple channels.Such protective diversity can be achieved in either of two ways: equipment diversity, by providing different types of instrumentat'ion'to monitor the same variable, or functional diversity, by monitoring different plant variables. Functional diversity entails some degree of equipment diversity, P~rily with respect to sensors and setpoints. More importantly, however, functional diversity is not dependent on the calculated respense of any one"ariable during an accident.As a convex'se of this, functional diversity is more complex to demonstrate since the response of several variables must be analyzed for each type of accident evaluated. The Westinghouse Pxotection System is therefore evaluated in this report with respect to functional divexsity. To demonstrate diversity where protective action is needed, it is necessary to show combinations of two or more of the 1-3 e 4 f o 1 lowing barriers" for each accident.Some of these are addressed to the need for protective action, rather than to the Instrumentation System itself.This is considered a reasonable approach to judging the adequacy of a Protection System.a)Tolerable consequences for expected conditions -Although case" analysis might fail to prove that protection is not vast majority of cases may have acceptable consequences. worst needed, the Whether or not this is a suitable barrier depends on the probability of adverse conditions (such as excessive inserted rod worth)and the design and operating precautions taken to prevent them.b)Low probability of accident-Probability of the initiating fault might be considered, but only in conjunction with the probable consequences. That is, a loss-of-coolant accident does not require less protection t than a loss of flow accident simply because it is less likely to occur.c)Control interlocks -Rod stops or other devices which arrest or modify spurious control action short of reactor trip can be part of the Protection System.Protection System design standards, equipment testing, and Technical Specification limits would therefore be applied.nual action-Manual action can be considered a reliable backup to automatic protection, depending on the accident rate, the complex ty the problem and corrective action, and the alarms and indication provided.1-4

Automatic reactor trip-Each accident may have a"principle" reactor trip associated with it..)BackuP reactor trip-A second reactor trip function of is an additional barrier.In all but a few cases in the Westinghouse design, a specific reactor trip is not categorically either"principle" or"backup": it serves as the principle protection against some accidents, and as backup protection against others.1.Z PROTECTION SYSTEM-EVALUATION An accident-by>>accident evaluation has been performed in order to evaluate the"depth" or degree of diversity provided by current Westinghouse design.As expected, diversity could not be demonstrated for all accidents. The xesults in genex'al, however, indicate a considerable degree of protection System divexsity. The evaluation, reported in-.Section 5 of this report, analyzed each postulated ~ccident without credit for protective action to the point at which one of the three following events occurs: Inherent plant charactex'istics terminated the accident;b)The consequences are clearly intolex'able', or c)=<<<ting analytical methods are no longer valid (for example, system alculations cannot be perfoxmed with any degx'ee of confidence if severe core damage occurs).1-5 tyne of evaluation, the amount of analytical rigor must be reduced Ka this type o as con t on s become increasingly remote and safety lhaits are exceeded is because present technology cannot rigorously support assumptions as system behavior for these remote cases.In large part, this fact explains the reason why such conservative safety limits are selected for design purposes.1-6 I SL~5ARY In the Westing ou tin house Reactor Control and Pro tection Systems the Control System is seoara's seoarate and distinct from the Protection Syst P"orection System is independent of the Contro]he Protect on S"ste-"L is highly dependent upon signals derived from the Protectio S through isolation amplifiers; This interre].ationship is illust d in inure-1.he design of the Control and Protection Syst~d th interactions between them are discussed in detail i Sectio'd 4 of this report.The design philosophy is to make maxianun usage, for both control and protection purposes, of all measurements of plant variables. For each variable monitored, the best type of equipment available is selected as the vehicle of measurement. Clearly, the requirements for measurements for control or protection purposes so nearly overlap that the optimum equipment for one purpose is also the optimum for the other,.It's recognized by those responsible for Protection System design and review that little if any additional safety is achieved by utilizing independent, but identical, measurements for control and protection. In fa<<, it is Westinghouse's position that additional identical channels are seriously disadvantageous jn that more penetrations, maintenance, and control room readouts are required.por example, operator surveiU.ance of protection channels'is necessarily diluted when plant operation is dependent on other indications.

pressurized water reactor plant, it is almost axiomatic that-.n a Large Pre s rturbation which encroaches on safety limits significantly affects~v pertur a For example, a reactivity excursion-such as accidental rod vt.th raw drawal-causes not only an increase in neutron flux and core power,~so an increase in coolant temperatures and in pressurizer pressure but and level.Reliable control is obviously'he best approach to plant safety.The prime, purpose of a control system is to limit excursions before protective action is necessary. Since the control devices must be capable of Limiting excursions, they are also capable of causing an excursion-perhaps in the, opposite direction-if spuriously actuated.Failure of the Control System, either by not acting when needed, or acting when not needed, decreases the leve1 of safety.Redundancy-of control, where applicable, is therefore highly desirable. Pressurizer pressure control is a prime example of efficient use of redundant measurements for safe operation via a reliable Control System.Two oower-operated pneumatic relief valves are provided to limit pressure excursions within the normal operating range.Although not essential to-safety, these valves increase safety margins for system overpressure ~overpressure protection is provided by the high pressure reactor trip~safety valves).Should either valve be actuated spuriously, however, p~tection against the reduction in pressure might also be required.2~2 'Ph contro3.channels, derived form the four pressure protection ."-our pressure con t no sing3.e ins-hanne3.s, are use-el'ei when needed, nor can any single i Qt~t fail duce pressure to the point at which protection would be needed ressure channels are used to contro1 each valve.One pressure channel Mo pressure serves as an interlock, blocking the air supply to the valve on a low pressure a3.arm.Since the pneumatic valve requires air to open, thi's low pressure alarm closes the valve (if open)and holds it closed.In the absence of a low pressure alarm on the first channel, a high pressure alarm on the second channel opens the valve.."-rom the protection System viewpoint, the corollary to maxbaum usage of all measurements is that protection against any given accident is not necessarily confined to measurement of just one variable.Thus the reactivity excursion noted previously, the reactor trip on high pressurizer wager leve3, also provides a degree of protection, even though the basic purpose of this trip is to protect the pressurizer relief piping from water relief surge, through the safety valves.Since completely different. types of measurement are used<<r neutron flux and pressurizer water level, diversity does exist in the Protection System.Lhe extent of such diversity is evaluated in Section 5 for a wide variety ot accidents. In most cases, two or more diverse reactor trips terminate~accident before catastrophic consequences can occur.However, the second trip reached (the"backup")generally does not prevent the design satey limit from being exceeded.In this context, the design saiety 2-3 h h as a DNg ratio of 1.30, is itself a highly conservative such~,.exceeding this limit does not imply intolerable consequences. ~one case evaluated-the hypothetical rod ejection accident-protection system em diversity could not be adequately demonstrated for the worst case.~eyer a rod ej ection is considered to be an extremely unlikely accident one caused by complete and instantaneous mechanical failure of a control rod pressure housing.Further, the probable consequences, as distinct from the worst case, are tolerable since most control rods are fully withdrawn from the core.Even those rods that remain inserted are seldom inserted to their insertion limits.."-or another type of accident-complete loss of feedwater-diversity of reactor trips does exist.Ho~ever, automatic actuation of the auxiliary feedwater system is not diverse for all of'he ways in which feedwater flow could be lost.For those cases, it is shown that manual actuation consti-rutes a reliable back-up to automatic actuation. 2-4 'P 7"I H t I 0 ILLUSTRATION OF CONT."d)L'lND PROTECTION DESIGN CONTROL SYSTEM l (Signal con~itionins, controllers,~I interlocks, and defeat switches)t.otection {test signa.ague)(test r adout)~est CONTROL PROTECTION Channel'Sensor I\I Cabling and Penetrations ~I!P ewer Suoply!Isolation I;ihmplifier I Bistable l I (From other protection channels)".harm el Channel 2 3 f" 1 I In8icatio Channel 4 C C CJ o 4k IJ CO C IH g~g O Cl~+I cd 0 C cC CJ PROTECTION LOGIC a&CKS TRAIN TO REACTOR TRIP BREAKERS FIGURE 2-l ~,'I 1"k 0 P CTIONAL DESCRIPTION REACTOR CONTROL AND PROTECTION SYSTEH~~CTIONAL REACTOR PROTECTION SYSTEH 3.1 3.1.1 GENERAL'r'1 and Protection Szstm functi~di , , based on the Robert Emmett Ginna Nuclear Station of the Rochester Gas and Electric Co.(RGBE).It is representative of Westinghouse design practice.All reactor trips meet the following criteria: a)A single fai1ure shall not negate a reactor trip b)All channels are capable of calibration and maintenance at power.3.1.2 REACTOR TRIPS 4 A resume of reactor trips, means of actuation and coincident circuit requirements is given in Table 3.1-1.i~fllnual Trig Depressing either of two manual push buttons on the main control board actuates a reactor trip.Hi h Nuclear Power (Power Ran e)Dual trip settings=are provided: 3.1 1 " ca.l\"1~ )Low (approximately 25X)b)High (approximately 110X).The low setting can be manually blocked when power increases above P-10*(approximately 10X power)and is automatically reinstated when power decreases below P-10.These circuits trip the reactor when two of the four external ion chamber average flux signals are above the trip setpoint.Hi h Nuclear Power (Intermediate Ran e)This circuit trips the reactor when either of the two intermediate channels indicate above the trip setpoint, Et may be manual1y blocked when power is above P-10 and is automatically reset when power decreases-below P-10.Expected trip setpoint is 25X.HL h Nuclear Power (Source Ran e)This circuit trips the reactor when either of the two intermediate P range channels indicate above the trip setpoint.It may be manua11y blocked when two intermediate range channels reads a value above P-6 and is automatically reinstated when both intermediate range channels decrease below P-6.Trip setting is between P-6 and the maximum source range power level.*P-()designates a permissive circuit to block or activate a trip function.These circuits are defined in Section 3.1.3. 4~I' ~Fj t yvertemoe temperature 4T Trio of this trip is to protect the core purpose o po , p ssure, temperature,'cion Two out~f four oop~For each channel per eactor c lative measure of reactor power and is compared with a continu ously calculated setpoint of the form: 4T~K+K xPressure-K x T>>f(4I)setpoint L 2 J avg~en the reactor coolant loop 4T exceeds the calculated setpoint, the r atfected channel is tripped.Zn the above equation, 4Z is the difference'between the top and bottom power-range ion chamber signals..This compensation signal automat-ically reduces the trip setpoint if adverse axial core power I distribution exists.Dynamic compensation of the T signal is avg also provided to compensate for instrument and piping delays between the reactor core and the'loop temperature sensors..A schematic representation of this circuit is shown on Figure 3.1-1.An illustration of the setpoint is shown on Figure 5.1-6.Overoower 4T Tri The purpose of this trip is to protect against excessive power (fuel<<d power density).Two-out-of-four trip logic is used;there are two channels per reactor coolant loop.3.1-3 i for each channel is calculated as: Ne setpoint tor e~K-K-T-K (T-T)-f(II)4 5 dt avg 6 avg avg~'quation>f (41)is the same function as used in the overtemperature equat o-serpo nt e tpoint equation.The term K5 compensates for the piping and instrument delay.The term K6 compensates for the change in density and heat t~ac ty o ity of water with temperature (T's the nominal T at full power).avg avg 6~th K and K are limited such that the rate and/or magnitude of T can avg only decrease the 4T trip setpoint from its normal value at full power.ected steady-state trip setpoint is llOX of the indicated hT at full poMer;i.e., llOX power.A schematic representation of this cricuit is shown on Figure 3.1-2.~Pressure Tri.he purpose of'this trip is to protect against excessive boiling in the core and to limit the pressure range in which coze DNB protection is required for the overtempezature aT zeactor trip.This circuit trips the:eactor on coincidence of twmf-four channels.It is automatically blocked below P-7.The expected setpoint is 1715 psig.-"-'-h Pressure Tri=he purpose of this trip is to protect against overpressure and to limit the es<<<<range in which core DNB protection is required of the overtemperature Wected setpoint is 2385 psig.-a<<circuit trips the reactor on coincidence of two~f-three channels.3.1-4 ~h Pressurizer Water Level Tri tzip provides a backup to the high pressure trip and also prevents the pzessuz zessuzizer safety and relief valves from relieving water for credible accident conditions. Expected setpoint is 92X of span.This circuit trips the reactor on coincidence of two-of-three channels.Xt is automatically blocked.below P-7.Low Reactor Coolant Flow This circuit is provided to protect the core from DUB following a loss of coolant flow accident.The means of sensing a loss of coolant flow accident aze as follows: a)Measured low flow tn the reactor coolant piping b)Reactor coolant pump circuit breaker open c)Undervoltage on reactor coolant pump bus d)Underfrequency on reactor coolant pump bus The low flow trip signal is actuated by the coincidence of two-of-three signals per loop.Above P-7, reactor trip occurs for a loss of flow in both loops;above P-S, reactor trip occurs for a loss of few in either loop.Expected setpoint is 90K of indicated full flow.The reactor trip signal derived from reactor coolant pump breaker position is actuated by a single auxiliary contact'or each reactor coolant pump breaker.Trip logic is similar to the low flow trip;above P-7 reactor trip occurs for a"breaker open" signal from any two breakers;above P8.a signal fzom any one breaker actuates a reactor trip. ~wg a~~V~~tor trip provides additonal reactor protection against~undervoltage reactor powers 4 coaplete loss o o~t pump buses as~d b oa Lcw voltage on o ected setpoint is 70Z of~crvoltage se a~t a r t j rapid decrease in electrical frequency can decelerate th~princip e, a~tor coolant pumps faster than a complete loss of power.An underfrequency condition on both reactor coolant buses, as sensed by either of two under>>frequency relays on'ach bus, trips the reactor and opens both reactor coolant pump circuit breakers.Expected setpoint is approximately 58 cps.a Safety Xn ection S stem Actuation Tri (SIS)"pon actuation of the Safety Infection System, the reactor fs tripped to decrease the severity of the accident condition. The means of actuating the Safety In)ection System and thus tripping the reactor are as follows: l a)Low pressurizer pressure (1715 psig)in coincidence with low pressurizer water.level (5Z span).Any one of the three circuits La actuates the SIS.This function may be manually bypassed below 2000 psig.~Pressure (500 psig)in any steam line.A coincidence of two~f-three signals for any steam line actuates this function.This function can be manually bypassed when reactor coolant pr~ssure is below 2000 psig.c)"igh containment pressure (6 psig).A coincidence of two-of-three signals actuates the SIS.d)Manual Actuatj on f~~ Trio~trip sensed by loss of autostop oi 1 pressure or by turbine stop g turbine tr ps losure actuates a reactor trip during high power operation. Trip<s~o~r-three for the autostop oil pressure switches and two~f-two pic is sor the stop valve position switches.This trip is in coincidence with~r~sszve ci~ssiye circuit P-7 (blocked below 10X power)and permissive circuit P-9~blocked below 50X power unless condenser steam dump is blocked).Low."-eedvater Plow Reactor Tri For either steam generator, low feedwater flow (compared to steam flow)in coincidence with low steam generator vater level actuates a reactor trip.'Ms protects the reactor against a sudden loss of heat sink.This condition is sensed for either steam generator if e'ither of: two steam flow~feedvater flov channels indicate a difference greater than a setpoint and either of tvo steam generator narrow-range level channels indicate less 6 than a setpoint.Expected setpoints are 0.7 x.10 lbs/hr and 30X of span respectively. Low Steam Generator Water Level Tri~e purpose of this trip is to protect the reactor from a'1oss of heat sink-<<the case of a sustained steam/feedwater flow mismatch which is too ll<<actuate the low feedwater flow trip.~h~s~~-s trip is actuated on coincidence of two-of-three lov-lov level signals~n steam generator. Expected setpoint, is 15X of narrow range level span-3.1-7 /t 6.,.t;>)0 C 3>MQSSIVE CIRCUITS 3.'.3 p ously to permissive circuits Reference has been ma o k certain activities as well-~~its are use to ac'vfties.t of Permissive Circuits nunbnc Funccfnn Rod withdrawal stop on overpower (Automatic and manual)~Xn uc One~f-four high nuclear power (power range)*;one-of-two high nuclear power (intermediate range*l;one-of-four overtemperature AW;or one-of-four overpower AT*.Automatic rod with-drawal stop at low power.Automatic rod with-drawal stop on rod drop Selection of steam dump controller mode Permit manual block of source range high nuclear power trip One-of-one turbine first stage steam pressure I Oneof-four rapid decrease of nuclear power or rod bottom indication h Turbine trip signal One~f-two high intermediate range nuclear power allows manual block, twomf-two low intermediate range nuclear power automatically reinstates trip.~bypass on individual channels.."~y e~ally blocked if peanissive circuit P-10 is cleared. ~' ~ssive Circuits (Cont'd)t of Pe ss luabaa puaaaiaa~Xa ua permissive power (block various trips at low power)Block single primary loop loss of flow trip Block reactor trip on turbine trip Threemf-four low nuclear power and onemf-two low turbine impulse stage pressure Threeof-four low nuclear power Three~f-four low nuclear power and condenser steam dump avaQ-able (not locked out by high condenser pressure or by loss of both circulating water pumps)10 3.1.>>ROD STOPS Permit manual block of intermediate range power level trip and rod stop and low power range trip Two-of-four high nuclear power allows manual block, thre~f-four low nuclear power automatically reinstates the trips A complete list of rod stops is noted below.Rd Stop List Fuaaataa a)Rod drop b)Nuclear Overpower Actuation Si nal One~f-four rapid power range nuclear power decrease or any rod bottom signal Oneof-four high power range nuclear power or Rod Motion to be Blocked Automatic withdrawal (redundant, contacts)Automatic and manual withdrawal one-of-two high intermediate range nuclear power 3.1-9 t~g 4-top~st (Cont d)UjjCj:Xjjn c)iU.gh 4T Actuation Si nal One-of-four overpower 4T or one-of-four Rod Motion to be Blocked Automatic and manual withdrawal overtemperature 4T (Manual bypass on indi-vidual 4T channels)(Actuation of this rod stop initiates a continuous turbine load reduction until the actuation signal is'emoved) .d)Low power e)T avg deviation One-ofmne low turbine impulse stage pressure One-of-four T devia-avg tion from average T avg Automatic withdrawal H Automatic withdrawal and insertion 3.1.5 LQXCATION F Control Board Xndicators and Recorder-All transmitted analog signals which actuate reactor trips, rod stops, oz permissive circuits are either indicated or recorded for every.channel-Also.variable trip setpoints (overpower 4T and overtemperature 4T)are icated or recorded for every channel.Central Board Annunciator Panel~y of the following conditions actuate an alarm: Reactor trip (first out annunciator) b).aztial reactortrip (any channel)~wi oz~i<<deviation of any control variable (pressure, T, pressurizer level avg'li nuclear power, and steam generator level)for any channel.3.1-10 ~>>~t'lvl%1~y W C~ns'r, zy~\~ ';t"o>.3oard Status Pm&status of each reactor trip'c" on the trip status panel'-'.channel is continuously displayed I status o f each permissive circuit is continuously displayed on th pe~sive stat panel~~'reactor trip channel;bypass is.continuously indicated on the hypos status pmn-'I 17~a 3.1-11 s P k .,y ll+~~l IE~Tgtp I.fluuual 2.High nuclear flux CplHClUEHCY. ClRCULTRY b lHTERIXKKS 1/2, no interlocks 2/4, no interlocks for high setting P-10 for low setting l.'ON 1 k l)1 S High and low setttngs;manual block and automatic reset of low setting 3.', lligh nuclear flux (inter>>mediate range)High nuclear flux (source range)1/2q P-10 I 2/4;no interlocks 2/4, no interlocks 2/4>blocked by P-7 2/3>no interlocks 2/3, blocked by P-7 5, Overtemperature LiT 6.Overpower hT 7.Low'ressure 8.9.High pressure High pressurizer water level 10a.Low Flop 10b.Pump breaker trip 10c.Undervoltage 10d.Underfrequency SIS actuation 12.Turbine trip 13, Low feedwater flow 14.Low-low S.G.water level 2/3 per loop~p 7~P>>S 1/1 per loop]P 7)P+S 1/2 t'1/2~P-7 1/2+1/2 P-7 1/3,.(low pressurizer pressure and low pressurizer level);2/3 Low pressure in any steam line;or 2/3 high containment pressure 2/3 autostop oil or 2/2 stop valves>P;7]P-9 1/2+1/2 per loop, (flow mismatch in coincidence with low leyel)2/3$per loop h 0 Tayg n>AYO K4 T38 8 AT setpoint 1 Comparator C3.C3 C 4 2/4 ogic hot T c Comparator Rod Stop 0~POWER AT CHANNEL (ONE CHANNEL OF FOUR SROHH)FIGURE 3.1-2 l.l CONTROL SYSTEH t am dumP are available: condensex'umP and atmosPheric <cle valve arrangement is shown on Figure 3-2-1-yq steam cy C0gDENSER S~QUMP SYSTEM Svs ea Desi steam lines are installed to dump steam from the steam generators directly co the condenser, bypassing the turbine.Connections with the steam mains axe downstream of the stea'm main isolation valves.ralves and LLnes are sized to pass 35X of turbine auuctunan calculated steam flow at full load steam pressure.Condenser steam dump performs three functions: Following a sudden loss of load of up to 210 MRe{about 45X of=aximum calculated turbine load), condenser dump acts as an artificial load removing excess power and stored energy while the reactor power is decreased to match the xeduced turbine\In this manner, the condenser steam dump acts to prevent a reactor trip.Condenser steam dump, together with feedwater addition, removes stored energy in the Reactor Coolant System following a plant trip, bringing the plant ro equilibrium no load condition without 3.2-1 r o f the s team generator saf ety valves.It also maintains~tuation o 1 t at hot shutdown by removing residual heat.gg pJ.ant at ser steam dump is used for plant cooldown to cold shutdown.condenser ste~~er steam dump is used to improve operational flexibility. For a plant trip may occur following a large load reduction if~le, ap an~4.user steam dump is not available. ~condenser steam dump system uses modulating, Unear-characteristics,~~crated valves (air to open).Their stroke time is approximately 5 aecaads.Xn addition, they can be tripped from the fully closed to tate fu11 open position within 3 seconds after receiving an input eLectric trip signal.While this trip signal exists, the valves are bahf~the fully open position.When the trip signal does not exist, che valve position is determined by a variable input electrical signal-For condenser protection, condenser steam dump is blocked by high~enser pressure.Other interlocks'described below)are used~~e same manner to avoid spurious operation. ~pur'<<ous actuation of steam dump may cause a plant trip In addition,'-the ralves stay open, an uncontrolled cooldown results.For these the steam dump control system is required to meet the criterion signal failure shall cause spurious actuation-3~2~2

Control System al block diagram for the Condenser Steam Dump Control~e funct on Svstem is shown on Figure 3.2-2.Load Re ection Control."-or partial loss of turbine load, steam dump is controlled by the error signal between T and T f, where T is the average of four avg ref'vg reactor coolant average.temperatures and.T" is the progz~ed, se~ref, point for T as a function of turbine load.(These signals are the avg same as those used in the Reactor Control System.)Following a turbine load decrease, T is imm'ediately reset to a lower value, causing an ref error signal.If the error signal exceeds the deadband for the load.re)ection controller, the dump valves are modulated open.If the error signal exceeds the HI setpoint, a trip.signal is generated which rapidly opens four of the eight valves to their fully~~en position.At'he occurrence of a HZ-HI trip signal, all eight valves trip open.The distinction between modulating and tripping valves open is made because of the difference in required time for both of these actions.If valves are already modulated open corresponding to the error signal<<the time a trip open signal is generated, no additional trip action takes place.Sin~e the steam dump system requires a finite time to, act, an increase is to be expected.Lead/lag compensation for T increases avg avg 3~2 3 g f T on the error, thereby compensating f or the legs~gcect of l response and valve positioning. s reactor power by control rod insertion. reduces reac tpoint steam dump is redu appx'oaches avg valves are f ully seated M en ough to be handledoontroL system alone.~~d contra trol system also acting on the T-T f errox'ignal ~avg ref Ln order to prevent actuation of steam dump on small load perturbations, ,r a block is provided which prevents valve response to either the trip~modulate signal unless a turbine load reduction has occurred.AIl elcaents of this channel, including the turbine impulse chamber pressure tap, are independent of the steam dump control system described above.4 rate/lag unit in this channel generates an output proportional to~rare of decrease in turbine load;This output, when indicating a Load rejection gxeater than lOX step or 5X/mLnute ramp, removes the Once unblocked, this block is manually xeset.Minual-contxol of~team dump also removes this block.7uxb inc Tri Control~~e of the laxge heat capacity of the Reactox Coolant System and~~high T at full load the steam generator safety valves would avg~'~owing a turbine trip if there were no other means of removing ed heat.'ondenser steam dump and subcooled feedwater flow 3.2-4

plant to thermal no-load equilibrium without~~ed to bring-lease to atmosphere. e ea I e trip, monitored by loss of turbine autostop oil t e o he load re]ection steam dump controller is defeated and plant tr p trip controller becomes active.In the T control mode, avg r signal is T-T d'nd steam dump is proportional ~error s gn avg no-Load'he same error signal is used for on-off control of~fe~>>ter control valve, as described in 3.4, Steam Generator~L Control.As T.is reduced to its no>>load setpoint, steam'vg reduced and feedwater is shut off.As in the case of p load re)ection, if the error signal exceeds the HX setpoint, a trip asgaaL w generated which trips open four of the eight valves to their iull~pen position.At the occurrence of a HI-Hl trip signal, all~ght valves trip open.GeneraUy, the valves are not closed completely l~use of decay heat.No-load conditions are established within mo minutes.pressure Control'or><<g term removal of residual heat at hot shutdown, o~during plant it>rtup or cooldown, the plant operator can manually switch to steam der pressure control.In this control mode, condenser steam dump o maintain a preset pressure in the steam header.A manual~tion is provided so that the operator can ad)ust the setpoint~<<ssure or manually position the valves.3.2-5 ~pbbs j, S>H~ZC S~RELIEF SYSTEH steam relief valves are mounted on the steam mains upstream uoayher'c steam ves.At the set pre 4g~>o steam (about 1050 psig), f low calcu'c have provisgon f e s less than Z0 Provided to reduce d to permit a plant oold s'cedia dump is not available. These functions are explained below.a)If a plant trip is caused by loss of condenser vacuum, condenser dump m bIocked.The'steam generator safety valves are available to remove stored energy from the Reactor Coolant System.Atmos-@heroic steam relief reduces the steam pressure below the safety valve set pressure within two minutes after the trip.This prevents'ontinuous chattering of the safety valves as residual beat m removed from the reactor.Plant coo]down is accomplished by steam dump.If condens<<dump not available, the atmospheric relief is adequate to cool d~to the temperature and pressure at which the residual heat removal system can be used.3.2-6

C)Zn the event of a plant trip caused by an overpower/overtemperature condition or by a faU.ure in the feedwater system, the atmospheric steam dump provides additidhal relief capacity, reducing the pro-babDity of safety valve actuation. Separate controllers are provided for the atmospheric dump valves on the two steam generators, permitting independent pressure regu-lation if the steam generators are isolated.3e 2~7 T cold AVG T~at 1 V2 Swl K3 P K2 AT setpoi t E Comparator 2 2]4 Logic 3 C 4 hot cold'/Comparator Rod Stop 0$EBTEMPEBATURE AT CHANNEL (ONE CHANNEL OF POUR SHOWN)P1GVRE 3.1-1 F~.~~'I rl EnM lEHEl/ATOR Nntrr.)VAl VN ISAtIM YAllg l J IOOla'nON VALVE BYPASS.VALVE HAIN FEEDWATEE kLN.IQ'AI.VL I IA)I AT I lNli Olla:K TO TURBINE CON1'AINMENT AUXILIARY FEEUHATER+P go I i CONDENSER STEAM DUMP VALVES<<TEAM IEHERATOR B MAIN FEEWATER TO CONDENSER AUXILIARY FEEOHATER Figure 3.2-1 STEAM CYCLE VALVE ARRAMEMENT I i ~en/LAG COMPENSATION STEAM DUMP)ER PRESSURE CONTROLLER r RATE+RESET AUTO"MAN STATION PROP.ANALOG SWITCH OPERA-TING ON TURBIHE TRIP SIGHAL STEAM DUMP SELECTOR SWITCH MODULATE COHDEHSER DUMP VALVES LEAD/LAG COMPENSATION ((<>>s).I Jf<Sgl+fg$)L TRZ I COmZROLIhR Hi-TURB ZHE TRIP INTER-LOCK LOGIC TURBINE-TRIP SIGNAL TRIP OPEH GROUP A VALVES OR TRIP OPEN GROUP A 8c B VAL~STEAM DUMP VALVES.TRIP OPEH ONLY IF UHBLOCK SIGNAL IS PRESENT (SEE BELOW)Hj E LOSS OF LOAD INTERLOCK r:J+A--ROPRIATE POSITION OH SKZCTOR SWITCH ZHTKGDCK Figure 3.2-2 CONDENSER STEAM EUMP CONTROL SC1HHE UHB LOCK STEAM DUMP VALVES SIGHAL TURBINE TRIP SIGNAL BYPASSES LOSS OF LOAD INTERLOCK AHD UHBLOCKS STEAM DUMP VALVES 1 f'V (Y+gpQ+g+q+gl Y f" Al+J 1l 3 3 REACTOR CONTROL The basic Reactor Control System consists of three channels, which are re temperature (T), powez'ismatch (QT-Q)and reactor coolant avg'x'essure (P)~The output'of these three channels is used to drive the control rods via the rod program.A schematic representation of the control system is given in Figure 3.3>>1.The functions of each of these channels are as foU.ows: a)To maintain the programmed T as accurately as possible avg b)To be responsive to load perturbations without causing undue movement and reactor trips c)To take corrective action in the case of large load changes if the pressure exceeds the limits of the noxma1 pressure control.The T erature Channel The temperature channel functions to maintain the programmed temperature -(T)as accurately as possible.The main requirements of this channel avg are that it should be accuxate, stable and repeatable. This is the dominant contx'ol channel in steady-state conditions.'he Power Mismatch Channel The power mismatch channels provide control stability and fast response t>>oad pertuxbations. The output is proportional to the mismatch between turbine power and nucleax power.A high-pass filter in this channel ensures that steady-state calibration errors in the input power signals"as no effect on steady-state control.3.3-1 .at I ,'g l~jl ~other requirement of this channel is that its steady-state output should be zero even though a Axed offset in power signals may exist.The Pressure Channel This channel is provided to prevent large pressure changes foU.owing a large change in power.It retards the rate at which the controller changes T to its new programmed set point.(If T were to be changed avg avg too rapidly, pressurizer pressure contxol might not be able to maintain pressure within the normal operating range.)The pressure control channel has an adjustable deadband, so that only large pressure changes have an effect on rod motion.This channel is not required for initial plant.operation. The Rod S eed Pro am The rod speed program is made up of four parts: ari adjustable deadband, a minimum speed, a proportional speed, and a maxLmum speed.The auucLannn speed is dictated by the mechanism design.A11 the other settings are ad)ustable.

Expected set points are+1.5 F for the deadband, and+5 F for amximum rod speed demand.The outputs from the three channe1s mentioned above feed into the summing amplifier associated with the rod program.3a3~2 Ijgg~gi 4t'~s~A)t l(~

  • I l.(I~')F~As)u AVO l Turbine Im ulse Pressure~gS+1 Speed 4n+E T S t6S+1 0 ariable Gain+Pressurizer Pressure E tyS+1~88+1 Pressure Set oint REACTOR CONTROL SYSTEH Figure 3.3-'1 ~I~I 4 j~ CINERATOR LEVEL CONTROL M operation, the position of the main f eedwater control valve is ope 11ed by the three-element controller (feedwater flow, steam flow, At low loads a bypass control valve is used.>+tpoint o f the 1 evel contro 1 1 er is a f unct ion of load, programned ise with load between OX and-2OX load.A deviation alarm provides~ti~uous monitoring of the level channel used for contxol versus the programmed level.~>narrow-range level channels are indicated. The wide-range level channel is recorded..he steam flow and feedwater flow signals aze supplied by either of two transmitters as selected by a contxol board mounted selector switch.The steam and feedwater flow signals used for control are recorded on a two pen recorder.":ollowing a turbine trip, automatic control of the feedwater valve is switched from the three mode level controller to on off T control.avg<1<<edwater control valves under automatic control are fully opened to admit auucbnum feedwater, then fully closed as no-load T avg approached to avoid excessive cooldown of the Reactor Coolant System.~<<1 contzol of feedwater control valve position is available at the ontrol board.This mode o f control overrides automatic contzol on either level or T avg 3.4-1 tO~+~~'"'=*4%-4'ft'%41V~~k/+t p i t' order to prevent excessive'moisture cazxyover caused by high steam~erator water lev~.a sig al of high water level ove~des a3.Other tzol and closes the feedwater control valve.The signal is obtained from coincidence of two-of-three level channeLs above a preset value.This override is automatically removed from the main control valves as the water level drops below Che set value.Manual reset is required for the bypass control valve.The signals affecting feedwater valve control, in increasing the order of priority, are listed below: a)Three-element level control or on-off T control (dependent on avg whethez or not'turbine is tripped)b)Manual control c)High level override (closes feedwater valves)d)Safety Injection System actuation (closes feedwater valves).A wide-range level channeL, calibrated for no-load conditions, fa provided co allow manual control at hot shutdown and is also useful at cold shutdown This channel includes a recorder.3.4-2 ~PROTECTION SYSTEM~~q BR IN JECTION SYSTEM ACTUATION QEEIY f actuating the Safety Injection System have been noted in o act Those particularly concerned with steam line break pro-~~4 3~~~a are low steam 1 ine pressure and hi gh containment pressure.~An are o low steam~steam line pressure signal is generated by the coincidence of~f three channels below approximately 500 psig for either steam line.~~high containment pressure signal is generated by the coincidence of~f-three channels above approximately ten per cent of containment ~ign pressure.3.5.2 FEEDWATER LINE ISOLATION Any safety infection signal isolates the main feedwater lines by closing all four main control valves, tripping the main feedwater pumps, and closing the pump discharge valves.3.5-3 STEAM LINE ISOLATION a)High steam flow in coincidence with any safety in)ection signa1 closes the isolation valve in that steam Une.One-out-of-two steam flow signals above a HI-HI~p p (approximately 120X of fuLl load steam flow)One-out-of-two steam flow signals above a HI trip point (approx-imately 20X of full load steam flow)in coincidence with two-out-of-four low T signals (below approximately 540'7)avg 3.5-1 ll IJ, J,=" 4~1'~~"J bi~e coincidence of tv~f-three high contaf.nment pressure signaLs Rctustion~ 3.5-2 A'~8) .OV<VD CONTROL SYSTEMS DESIGN PRINCIPLES PUNCTIONAL DESIGN p hi los oohy f or f unctional design Protection System is to derive p os on~re wirectly from the process variables of interest whenever possible.~oner, safety limit protection is assured independent of the ting acc'dent..~ertemperature high delta-T trip protects the core against Departure nucleate Boiling (DNB)for all combinations of pressure, temperature,~r.and axial power distribution. Thus, this single trip prevents DNB!'r.-cd<<ithdrawal accidents, boron dilution, xenon oscillations, and cxcessire load variations. Protection against other limits, such as excess ve power, density and system overpressure, is also provided by close~itorinz of the variable of direct interest.;c ce="ain cases, however, these general protection functions are not rapid enough, or complete enough, to assure protection against a specific accident, such as loss of coo~~nt flow.In these cases, specific trip functions are orovidec, such as reactor coolant pump bus undervoltage and reactor coolant~or ce""ain more cre"'ble transients, such as turbine trip, a reactor trip 4-s derived from the.nitiating event-even though safety limf.ts would not oe exceeded if a reac":=trip were delayed until an overpressure or over-tempera=ure rri" oc""red.1n this manner, undesirable excursions are preven=ed, rathe t"..sc terminated. 4.1-1 certain protective functions are provided primarily to ensure the F~~lly, ce ufng integrity of plant component and piping systems.Examples include-or trip on high pressurizer water level to protect safety valve relief.eac or@fan Co and reactor trip on loss of feedwater to any steam generator.(The@clear'oss of safety requirement is to prevent complete loss of heat sink;i.e., feedwater to all steam generators.) ."-or equipment design purposes, no distinction is made between the various categories of protection mentioned above.The same criteria and design oractice are appLied to all channels.Other alternatives are neither defensible nor practical, since all of these protective functions enhance nuclear safety and complement or supplement one another.:his approach requires an instrumentation system that measures, on a timely, accurate, and reLiable basis, dominate nuclear plant process variables. instrument ranges, sensitivity, and time response must be selected consistent Wth the range and variation of each variable monitored. Also, since many process variables are monitored, considerable overlap in protection functions is a natural consequence. 4.L-2 ~l st'I~ CONTROL SYS~FUNCTIONAL DESIGN Power level and reactor coolant temperatures are controlled automatica3.l.y in a Westinghouse PWR Plant.The reactor is controlled to foU.ow any turbine load perturbation. This is ideal for load frequency control.The automatic Reactor Control System, therefore, forms an essential part of the plant operation. It is basically a regulating system which maintains proper steady-state operating conditions, thereby assuring adequate margins to trip settings for operational purposes and proper economic performance. Other automatic control systems are pressurizer pressure and level control, feedwater control, and steam dump control.These systems are also essential to maintain normal operating conditions or to suppress excursions imposed by oaerational transients without recourse to protective action.As in the Protection System design, this requires an instrumentation system that\measures, on an accurate, timely, and reliable basis,'ominate nuclear plane process variables. Theqe variables are, for the most part;the same as those required by the Protection System: loop temperatures, neutron flux;oressurizer pressure and level, steam generator level, steam flow and feedwater flow.In addition, the time response, instrument, span, and~~nsitivity requirements for measurement channels serving each of the two~y~tems are similar.As a result, primary sensor and transducing equipment that is acceptable for use with the Protection System should also be employed with the Control System.Failure of the Control System to act when needed, or spurious actuation when not needed, generates a need for protection. The safest, plant is 4.2-L o niped to be one that requires the Least protection. For this reason, well as the economic desirability of avoiding plant outages which could gave been prevented by proper control actions, every effort is made to ensure reliable control.Wherever practical, control interlocks and/or redundant control devices are provided to ensure that controL action takes olace when needed-but only when needed.Controller-induced excursions causedby a single sensor failure are largely eliminated in Westinghouse design practice.
    i.
    ~g++S FEED PLOW L3 SF 1)Xg I PROP+INZEC I I I~I-, I I I I I I I I I PROP+INTEG I LEVEL CONTROL SYSTEM l I I I P I'2)FW Pl FW I I I PEEDWATER I CONTROL VALVE I ACTUATOR I I I~/7 t~Ji I t 2/3 HI LEVEL 2/3 LO-LO LEVEL I 2/2 I 1/2 LO FLOW LEGEND FWF-PEEDWATER PLOW TRANSMITTER SF-STEAM PLOW TRANSMITTER P-STEAH PRESSURE TRANSMITTER L-LEVEL TRANSMITTER I-ISOLATION AMPLIFIER h-DIPPERENCE AMPLIFIER X-MULTIPLIER EDWATER CONTROL REACTOR TRIP REACTOR TRIP VALVE CLOSURE AND AUX.FEED PL"IP START AND INDICATORS NOT SHOWN.STEAM GENERATOR LEVEL CONTROL AND PROTECTION SYSTEH FIGURE 4.2-1 3 CONTROL AND PROTECTION INTERRELATION Aorrent Westinghouse PWR systems, the Protection and Control Systems are'n curren and distinct and are identified as such The Control System><<eer, is dependent on signals derived from the Protection System through isolation devices.However, there is no feedback from the Control System.o the Protection System.>e equipment design philosophy, illustrated on Figure 2-1, is that the Control System sensor is the output of the isolation amplifier. By this orinciple, no components are shared-they are either part of the Protection System and are located and designed as such, or they are part of the Control System.This is a very important feature of the Westinghouse design, and permits a dividing line, both functionaUy and physically, to be drawn between control and protection. It also ensures that, inadvertent or I deliberate changes to the Control System have no more effect on the Pro-I rection System than if the Control System contained independent sensors.The design requirement for the analog isolation amplifiers is to isolate the~<<tection System from any electrical faults which might occur in the<<<<rol System.Extensive tests were performed to demonstrate this'apability. In these tests, shorts, grounds, and a-c and d-c voltages were applied to the amplifier output.Even though some of these tests were st<<ctive (i.e., destroyed the ability of the amplifier to produce a meaningful output signal), in no case was any perceptible disturbance fed ac" into the input circuit and hence to the protection System.4.3-1 0 The presence or absence of regulating control devices on the downstream side of the isolation amplifier has no effect on the isolation requirements. The same equipment and design requirement would exist even if these signals were brought out of the Protection System merely for remote readout and data-logping purposes.Since channe1 isolation cannot be reliably main-tained on the control board or at the input terminals to a data-logger, an isolation device (amplifier or impedance network)in the protection channel represents the only feasible way to preserve protection channel independence. Certain failures in the Protection System could conceivably negate a par-ticular channel of a protective function, simultaneously causing spurious control action that might, require protective action from that same function to prevent the excursion from exceeding design limits.Such possible failure is dealt with in accordance with the proposed standard,"Criteria<or Nuclear Power Plant Protection Systems", IEE No.279, Section 4.7, which requires that for such a fault, a second failure be assumed in the'Protection e In most cases in'which control is derived from protection, Westing-"se design meets this criterion by providing a two-out-of-four Protection System Loaic.For example, as shown in Figure 4.3-1,'a failure can be" s~ed in Protection Channel L which causes that channel to indicate high.defeats the low pressure reactor trip for the channel, and also may"e Pressure Control System (relief valves and spray)to rapidly reduce~assure.However, three of the pressure protection channels are left-.@ached t sure t P nd a reactor trip would automatically occur when any two of them T this additional redundancy is not necessary because such other cases, cannot cause the safety limits to be exceeded.This fact can canno illustrated by Figure 4.3-1.A loss of signal (low indication) bc assumed for Protection Channel 1.This defeats the high pressure bc assume or that channel and may also energize the pressurizer heaters, causing l~increase in pressure.If an independent failure is assumed in Channel 2, g glow nc cactor trip would occur when the pressure reached the high pressure trip~taint since only one of the three high pressure trip channels is left However, under this condition the safety valves on the pressurizer g<c~ore than adequate to ensure that the high pressure safety limit is not acceded.Section 4.4 discusses all such control and protection interactions for a mccific plant design.In that section, it is noted that numerous operational -'cfenses against these failures exist in addition to the primary or"protection a'ade" defense.Many of these additional barriers to.an undesirable excursion N 4c'c made possible by making redundant information avaQ.able to the Control System.+c possibility of common-mode failure cannot be completely ruled out;it is<<<<eivable that all identical channels behave identically, but incorrectly. .""-his case, the question of Control System dependence on the Protection em is irrelevant. It has been recognized that little, if any, additional deere e<<<<of protection is achieved by having separate, but identical, instru-"t channels for control and protection. Indeed, Westinghouse considers t separation in this manner actually deprives the protection System of 4.3-3 e of the day-Sy&ay, hour-by-hour surveillance given to instrument chaels needed for routine plant operation. A further, although often ggnored disadvantage of proliferation of identical channels, is the attendant increase in visual displays and information processing problems of significant oroportions.(Timely, accurate and complet~Lnformation readout is required by the IEEE criteria previously referenced.)' frequently expressed concern is the need for assurance that the Protection System will not be inadvertently modified during the 40-year life of the plant, This is occasionally cited as an argument against control dependence on Protection System information Westinghouse completely agrees that every precaution must be taken to ensure adequate review of any future modification that could affect the Protection System.Such assurance can only be achieved by complete attention to details in Protection System design, operation and maintenance. This must include I identifica'tion of system components on drawings and on tha equipment', documentation of the system design and design basis, and establishment of groups to review all proposed instrument changes that could affect'plant~safety or plant operations. It is fallacious to believe that independent control adds to this assurance. In fact, such independence could decrease the probability that a necessary correction to the Protection System will be Inadequacy of controller design requires correction to allow plant operation to proceed;inadequacy of protection is sometimes discovered only after an incident.4,3 4 Control System modifications may be required to improve plaat operation. por encamp 1 e, a f i 1 ter may have to be added to achieve stabi lity.As a control modification, this would logically be performed in the Control Systm;i-e-7 downstream of the isolation dances separating the Control and Protection Systems.Physical separation and identification of equipment (separate racks for Control aad Protection Systems)and admini-strative precautions ensure that the logical route is, ia fact, the one used.Even advocates of complete independence between control and protection recognize the desirability and feasibility of using protection signals for non-protective functions...his introduces the possibility of thesesignals being diverted for other purposes unless a careful review and adherence to design bases is enforced.The division between control and protection is not always clear.This reflects difficulty in defining the function achieved, rather than in equipment design imnlementatioa. Definitions that place all reacto'x" trip aad safeguards actuation instrumentation in the Protection System, and all automatic regulating instrumentation in the Control System, clearly leave many important items in between.Another definition advanced'is that the Control System is"all instrumentation which is not protection," and the Protection System is"that instrumentation which must work when needed (to prevent unacceptable consequences)." This latter defiaitioa has considerable merit for general discussions and is useful in Judging whether or not a particular item is a"protection" item or not.However, if taken as a rigid it is difficult to apply to all design details, as is showa below.4.3-5 P z example alarms and/or control room indications derived from protection hannel information are essential if the operator is to be properly and continuingly infoxmed of the Protection System status and the status of plant safety.As px'eviously noted, these alarms and indications aze required by the referenced IEEE criteria as a vital pazt of the Protection System.order to maintain protection channel isolation, Westinghouse equipment design practice associates remote indication with the output of the isolation device.Other functions, such as control interlocks (e.g., rod stops)are often highly desirable, and may even be essential to plant safety if a number of malfunctions or maloperations should occur simultaneously (i.e., beyond the normal design proundrules). Westinghouse has used the term"supervisory" for that category of functions that.is neither clearly control or protection.(This is a functional I designation only, and does not imply a third category for equipment design.)Supervisory functions can be further subdivided into two types: those that are informative only (indicators, recorders, alarms, and data-logging); and those which automatically act to arrest deteriorating conditions before protective action is needed.(This latter type has been texmedi"override", or"protective override.".) Since the question is one of whether manual or automatic intervention is intended, the value of distinction is limited to failure mode analysis of automatic controllers. 4.3 6 N%&A t'9" r.l~r' westinghouse record.zes that each"supervisory" function must be considered on its own merits to determine if it should form part of the protection or the Control System.A complete list of protection, control, and"supervisory" functions is included in the Appendix.4.3-7 ~+m 8 w4':'l n 1' PROTECTION ~axWEL PROTECTION CHANNEL 2 PROTECTION CHANNEL 3 PROTECTION CHANNEL 4 PT i PQ~~~PC'~HI P R.T.t PC~LO P R.T.I I ISOL'.~~PC~HIP'.T.PC'OP~ISOL QPT" PQ PC'~HI P R.T.)PC LO P SOL gPT PgQ PC LO P R.T.SOL I r I L PRESSURE CONTROL SYST~I I I I I PRESSURE CONTROL SYSTEH (INCLUDES SIGNAL CONDITION-ING AND CONTROLLERS AND INTERLOCKS FOR HEATERS, SPRAYAND RELIEF VALVES)PT-PRESSURE TRANSHITTER PQ-POWER SUPPLY PC-CONTROLLER ISOL-ISOLATION AHP HI (LO)R.T.-HIGH (LOW)PRESSURE REACTOR TRIP PROTECTION SYSTEM COMPONENTS CONTROL SYSTEM CMPONENTS INDICATORS, AND RECORDERS ARE NOT SHOWN PRESSURIZER PRESSURE PROTECTION AND CONTROL SYSTEMS DESIGN FIGURE 4.3-1 th(O P'I 4 A4'g~ SPECIFIC CONTROL AND PROTECTION INTERACTIONS design basis for the Control and Protection System permits the use of fox both protection and control functions-Where this is done,>l equipment common to both the protection and control functions are classified as part of the Protection System.Isolation amplifiers prevent.a Control System failure from affecting the Protection System.In addition, Mhere failure of a Protection System component can cause a process excursion which requires protective action, the Pxotection System can withstand another, independent failure without loss of function.Generally, this is accomplished vith two-out-of-four trip logic.Also, wherever practical, provisions are included in the Control or Protection System to prevent a plant outage because of single failure of a sensor.The following discussion of specific control and protection interactions t is based on the design for the Robert Emmett Ginna Nuclear Station of the Rochester Gas and Electric Co.(RGE)-It is xepresentative of current Westinghouse design-practice. 4.4.l NUCLEAR FLUX Four powex range nuclear flux channels are pxovided for overpower protection. so~<<ed outputs from all four channels are averaged for automatic control<od regulation of power.If any channel fails in such a way as to pxoduce~ow output, that channel is incapable of proper overpower protection-In p inciple, the same failure could cause rod withdrawal and overpower. Two-"t<<-four overpower trip logic insures an overpower trip if needed, even"ith an independent failure in anothex channel.4'>>l ddition" the Contxol System responds only to rapid changes in indicated f1~.slow changes or drifts are overridden by the temperature control nuclear t i al.Also a rapid decrease of any nuclear f1~sig 1 block autistic xo w d withdrawal as part of the rod drop protection circuitry. Finally, an overpower signal from any nuclear channel blocks automatic rod withdrawal. The setpoint for this rod stop is below the xeactor txip setpoint.4.4.2 COOLANT TEMPERATURE Four temperature channels, each containing a Tavg and a 4T signal, are used for overtemperature-overpower protection. Isolated outputs from all four T signals are, also averaged for automatic. control rod regulation of avg power and temperature. In principal, a spuriously low T signal from one.sensor would partially defeat this protection function and also cause rod withdrawal and overtemperature. Twomut-of-four trip logic is used to insure that an overtemperature trip occurs, if needed, even with an indepen-dent failure in another channel.In addition, channel deviation alarms in the Control System block automatic<<d motion (insertion or withdrawal) if any Tav signal devtates significant3.y from the others.Automatic rod withdrawal blocks also occur if any on~f-<<ur nuclear channels indicates an overpower condition or if any oneof-four temperature channels indicates an overtemperature or overpower condition. Finally, as shown in Section 14.3..2, of the RG&E Final Safety'Analysis Report, th<<ombination of trips on nuclear overpower, high pressurizer water level, nd high pressurizer pressure also serve to limit an excursion for any rate f reactivity insex'tion. 4.4-2 PRESSURIZER PRESSURE pressure channels are used for high and Low pressure protection and F for overpower-overtemperature protect i on.Isolated output signals f rom these channels also are used for pressure control and compensation signals for rod control.These are discussed separately below.Control of Rod Motion one of the pressure channels is used for rod control with a low pressure signal acting to withdraw rods.The discussion for coolant temperature is applicable; i.e., twowutwf-four logic for overpower-overtemperature protection as the primary protection, with backup from multiple rod stops and"backup" trip circuits.In addition, the pressure compensation signal is, Limited in the Control System such that failure of the pressure signa1 cannot cause more than about a LO'F change in T.This change can be avg accommodated at full power without a DNBR less.than L.30.t Finally, the pressurizer safety valves are adequately sized.to prevent system overpressure. Pressure Control Low Pressure A spurious high pressure signal from one channel can cause low pressure by spurious actuation of spray and/or a relief valve.Additional redundancy is provided in the Protection System to insure underpressure protection; <.e., two~ut~f-four low pressure reactor trip logic and one-out~f-three Logic for safety in)ection.(Safety in]ection is actuated on one-outmf-three coincident Low pressure and low leve1 signals.)4.4-3 0 addition, i terlocl are Provided in th Pressure C t ol System such~t a relief.valve closes if either of two independent pressure channels i dicates low pressure.Spray reduces pressure at a lower rate, and some ti e is avaiLable for ooerator action (about three minutes at mmchnna spray-ate before a low pressure trip is required.) The pressurizer heaters are incapable of overpressurizing the Reactor Coolant System.Maxinnm steam generation rate with heaters is about 7500 lbs/hr., compared with a total capacity of 576,000 Lbs/hr., for the two safety valves and a total capacity of 179,000 lbs/hr., for the two power-operated relief valves.Therefore, overpressure protection is not required for a pressure controL failure.Twomutmf-three high pressure trip Logic is used.Xn addition, either of the two relief valves can.easily maintain pressure below the high pressure trip point.The two relief valves are controlled by independent pressure channels, one of which is independent of the pressure channel used for heater contxol.Anally, the rate of pressure rise achievable with heaters is slow, and ample time and pressure alarms are available for operator action.4.4.4 PRESSURIZER LEVEL Three pressurizer level channels are used for high level reactor trip (2/3)and low level safety infection (1/3 logic level coincident with" Pressure). Isolated output signals from these channeLs are used for volume control, increasing or decreasing water level.A level control 4.4-4 'E l
    ailure could fill or empty the pressurizer at a sLow rate (on the order OE f half an hour or more).Irggh 18V81~reactor trip on pressurizer high level is provided to prevent rapid 4 thermaL expansions of reactor coolant fluid from fiLLing the pressurizer; the rapid change from high rates of steam relief to water relief can be damaging to the safety valves and the reLief piping and pressure relief tank.However, a Level control failure cannot actuate the safety valves because the high pressure reactor trip is set belo~the safety vaLve set pressure.With the slow rate of charging available, overshoot in pressure before the trip is effective is much less than the difference between reactor trip and safety valve set pressures.
    Therefore, a control failure does not require Protection System action.Tn addition, ample time and.alarms are available for operator action.Law Level For control failures which tend to empty the pressurizer, one-out-of-three Logic for safety infection actuation on Low Level insuresithat the Protection Sy<<em can withstand an independent failure in another channel.<n additon, a signaL of low level from either of two independent level control channels isolates Letdown, thus preventing the loss of coolant.ampule time and alarms exist for operator action.4.4-$ gTEQf GENERATOR WATER LEVEL PESWATER PLOW before describing control and protection interaction for these channels, it is beneficial to review the Protection System basis for this instru-mentation The system is shown schematically in Pigux'e 4.4-L..The basic function of the reactor protection circuits associated with Low steam generator water level and low feedwater flow is to preserve the steam generator heat sink for removal of long term residuaL heat.Should a complete loss of feedwater occur with no protective action, P the steam generators would boil dry and cause an overtemperatur~verpressure excursion in the reactor coolant.Reactor trips on'emperature, pressure, and pressuri.e'er water level trip the plant before there is any damage to the core or Reactor Coolant System.However, residuaL heat after trip causes thermal expansion and discharge of the xeactor coolant to containment through the pressurizer relief valves.This would bxeach one of the barriers-.the Reactor CooLant System to release of fission products.Redundant emergency feedwater pumps are provided to prevent this.Reactor trips act before the steam generators are dry to xeduce the required capacity and starting time requirements of these pumps and to minimize the thermaL transient on the Reactor Coolant System and steam generators. Xndependent tx'ip circuits are provided fox the two steam generators for the following reasons: a)Should severe mechanicaL damage occur to the feedwatsx'in'e to one s~eam generator, it is difficult to insure the functional integrity of level and flow instrumentation for that-unit.Por instance, a 4-4-6. r~c-'c.'(l\1 I pipe break between the f eedwater f low element and the steam os]or p pe generator exator would cause high flow through the flow element.The rapid xessurization of the steam generator would drastically affect the depxessu ac elation between downcomer water level and steam generator water inven-However, the independent circuits on the second steam generator~e sufficient to actuate a reactor trip if needed.~j gt~r desirable to miabaize thermal transients on a steam generator for credible loss of feedwater accidents. Coatxoller malfunctions caused by a Protection System failure affect only aoe steam genexator. A1so, they do.not impair the capability of the main feedsrater system under either manual control or automatic T control.avg Hence, these failures are far from being the worst case with respect to core decay heat removal with the steam generators. Frectvater Plow*Npu<<ous high signal from, the feedwater flow channel being used for control used cause a reduction in feedwater flow and prevent that channel from~ping.A reactor trip on low-low water level, independeqxt of indicated~<<er.low, insures a xeactor trip, if needed." t<<n.the three-element feedwater controller incorporates reset on~such that with expected gains, a rapid increase in the flow signal~d ca o>>y a 12-inch decrease in level before the controller xe-opened eedwat r valve.A slow increase in the feedwater signal would have no g4C+~~ect 4.4 7 CC 88K spurious low steam f low signal would have the same effect as a high ceedwater signal, discussed above.~r A spurious high water level signa1 from the protection channel used for cont ol tends to close the feedwater valve.This level channel is inde F Pendent of the level and flow channels used for reactor trip on low flow coincident with low level.a)A rapid increase in the level signal completely stops fee@rater flow and actuates a reactor trip on low feedwater flow coincident with low level.b)A slow drift in the level signal may not actuate a low feedwater signal.Since the level decrease is slow, the operator has time to respond to low level alarms.Since only one steam generator is affected, automatic protection is not mandatory and reactor trip..on two-out~f-three low-low level is acceptable. 4-4.6 STEAN LINE PRESSURE~<<three pressure channels per steam line are used for steam break Protection (twomutmf-three low pressure signals for any steam line actuates saf Bty in]ectj.on) .One of these channels is used to control the Powermperated relief valve on that steam line.These valves.are typically t<<at 10K of the safety valve capacity A spurious high pressure signal C>>he channel used for control opens the re1ief valve and causes low~ure~This is a slow rate of steam release, evaluated as a credible 4.4-8 break in Section 14.2.5 of the RG&E Final Safety Analysis Report.~the analysis of steam breaks of this size, no credit is taken for the te~line pressure instrumentation-Safety injection is actuated by the oressurizer instrumentation. Therefore, a control faire does not create for this protection, and two-out-of-three logic is acceptable. 4'g ~~~ATION e~DEWAL ACCT~Syst'~evaluation of the rod withdrawal accident is based System parameters, protection system, and expected reactivity ?The design basis for the Reactor Protection System to~tt~ts-care far rod withdrawal accidents is to trip the reactor ygececi 30 DNBR is reached in the hot channel.While diversity in trumentation is not a part af the design basis, the system~~idled does provide alarms, rod stops and control functions to~~t>e vithdrawal from proceeding to the trip point.Because of~~t effect of overpower on all the process variables, additional ~!unct~<as would act to terminate the excursion, but aot'necessarily ~e l.30.Extending the course of the accident, a DNBR of 1.0 in the.~+seeably" is arbitrarily selected as a Umit for a.second Level of ycecectian.(The"hot assembly" is essentia1ly the hot channel without a?Xueaaca for engineering hot channel factors.)No credit.'is taken for~!~ttening or Local,'void reactivity effects at overpower conditions. ~est pess&istic instrument error.and'set points are assumed for aLl I tea:tar wips.~iced averpawer is of serious concern because of the potential damage to De core d the Reactor Coolant System.Syst by either the high pressure reactor trip~sea M con)unction with any reactor~p at'ater lev ity for core damage+n Wta evalua uatian is zocused on this cance~'.L-L '~s prot tection against the rod withdrawal leading to undesirable conse-quences s is in considerable depth, and there are indeed multiple levels of Prate f ro'rection as listed below.Each of these levels could be independently ~idered adequate, diverse protection against an accident.Because the reactivity available by rod withdrawal is limited, only very rare cases could complete rod withdrawal cause core damage.A single trip function with redundant channels protects against this condition. No diversity or separation is required.b)~u1tiple, diverse rod stops are provided such that no failure can cause a sustained automatic rod withdrawal. Therefore, a reactor trip could be considered as backup protecti.on. c)For"fast" excursions, two reactor trip functions prevent all but limited core damage.For"slow" excursions, manual action is an adequate backup to the automatic protection system.4)For all rod withdrawal accidents, ae least two reactor trip functions exist, either of which would again prevent all but limited core damage.Fault tree diagrams are shown on Figure 5.1-1 and 5 3.-2.5'l.l.PROBABLE CONSEQUENCES OP ACCIDENT The adequacy, or depth, of protection required for an accident should be measured against the probability of the accident and the probable consequences of the unprotected accident.The probable consequences are discussed here.The od tivity available is in (alize burnup mai,ntain e 5.1-2 s A distribution, and reduce ejected rod worths).The design allowance~er d st ro d insertion at full power is 0.1X for"bite" plus 0.4X for the man-euver g i.e., rod insertion may be anywhere from O.IX to 0.5X.~izh calculated values for moderator and power coefficients at beginning f core lif e*, 0.3X reactivity insertion is required to reach a hot assembly gggR p f 1.0.Also, af ter 20X core burnup, 0.5X insertion does not cause a hot assembly DNBR less than 1.0-Therefore, a random, complete rod withdrawal from design full power conditions with no protection has about probability of causing, DNBR less than 1.0.This is illustrated by Figure 5.1.3.Although the figure and the above discussion are based on full power, they are equally applicable to accidents starting from less than full power since the additional inserted rod worth is needed to achieve full power.However, it may not be practical to guarantee these conditions because allowances for calculation or measurement uncertainties can significantly affect the results..Figures 5-1-4.and 5.1.5 shows a"worst case" complete rod withdrawal at 25X.of cox'eI life from 102X power, nondnal T plus 4 F, and nominal pressure less avg 30 psi.Reactivity insertion is assumed to be 0.6X, or 0.5X x 1.2.(This 20X uncertainty could have been applied, to the reactivity coefficients-instead of the rod worth.)M~aum hot assembly DNBR is 0.91, or slightly less than the axbitrary limit of 1.0.The same transient at 6(X of core knife is shown fox comparison. MfxdnnmL hot assembly DNBR is 1.4&.*R activity coef f icients based on Figures 3 Z.1-8 and 3.2.1 10 in Supplement 4 to the RGE PSAR, dated October 23, 1968.5.1-3 'I'5.J I C 1 lete analysis, considering statistical variations in all uncertainties, A comp~d determine a more valid value or the probability of exceeding any vould liven sa s sf sty limit If this value were suf f iciently small, a comparatively ~a~i<<protection system might be justified. 2 PROEABII,ITY OF ACCZDENT~e design intent of the Reactor Control System is to block automatic~d withdrawal for any failure which can cause sustained rod withdrawaL. ~is is accomplished by rod stops on rapid nuclear flux decrease, T avg channel deviation, spurious rod motion, and subsequent rod stops on high AT or high flux.If rod stops were considered as independent protection, Protection System criteria would be applied.These rod stops would then be classified fuLLy as part of the Protection System for a rod withdrawal accident.5.l.3 MANUAL INTERVENTXON !annual action is reliable backup to automatic protection provided that sufficient time exists for operator response.The time required depends n the alarms available, the nature of the problem, and the required action.igure 5.1-6 illustrates steadymtate core limits and several alarm points nd trip points.Alarms are intentionally quite close to the design operating conditions. Other alarms such as high pressure would be reached during a transient. These alarms are tabulated on Table 5.1-1.~though steam cycle heat removal may be the most Limiting steadymtate rest triction on reactor power, time is required to reach corresponding ~arms and trip paints.'(Far instance~it would take about two minutes st 110X reactor Power with steam generator saf ty vaLves blowing before a steam generator Low-low water leveL trip could be expected.) For thi reason, this evaluation did not include these alarms and trips Figures 5.1-7 through 5.1-10 show the results of transient analysi far various reactivity insertion rates at beginning of core Life from~full power (102X, nominal T+4'F, noa~pressure less 30 psi avg from nominaL conditions at 80X power.A constant reactivity insertion rate with unlimited available reactivity is assumed.Hmdmea settings end instrument errors are assumed for the reactor trips, and nominaL set points for the alarms.(Note: the high 4T rod stops are taken as 3'F below their reactor trips rather than their nominal set points.)ror a reactivity insertion rate of 0.5 x.10 gk./sec,, (corresponding roughly to maxfxnun rod speed at average rod worth), a hot assembly DER of 1.0 is reached, in about.two minutes.During this time, there are alarms on high T, pressurizer pressure, and pressurizer Level, as well as rod stops and alarms on high flux and high 4T.Also, the steam safety.alves would be actuated.Mith the multiplicity of aLarms, i.t.-is easy to diagnose a ms)or overpower-avertemperature excursion. Xt is reasonable <<expect operator intervention (manual trip)during this thea For fast ter reactivity insertion rates, reacto<trip on high nuclear flux is a reliable protection system barrier.Therefore, since the avertemperature }11 h g 4T trip protects for all excursions, one could classify it as the principal protection barrier with"backup" from high nuclear flux in con-~un<<ian with manual action.5.1-5 DEITY OF REACTOR TRIPS e protection system design basis for the rod withdrawal accident for ore protection required that one trip function with redundant channels preven<event a minimum DNBR less than 1.30.This is accomplished with the<<ertemperature AT trip for slow reactivity excursions, and the high nuclear flux trip for fast excursions. As shown by Figures 5.1-7 through 5.1-10, these two trips meet the design basis-The evaluation also shows that for all cases of sustained reactivity insertion for rates up to four times the maximka rate expected from rod withdrawal, any of the following prevent a hot assembly DNBR less than 1.0.a)High nuclear flux reactor trip b)High AT trip l.Overpower AT 2.Overtemperature AT c)High pressurizer level reactor trip plus high pressurizer pressure reactor trip.(Not valid for high reactivity insertion rates:,.from near full power.)This depth of protection cannot be expected for all accidents or for all plants.5.1-6 TABLE 5.1-1 ALARMS FOR ROD WITHDRAWAL ~arms which would be actuated for a spurious rod withdrawal accident~e eax'r M.l Power are listed below i the aPPro~te order i which they Alarm points assumed for the evaluation are listed.Initiating Fault*-Mose'failures which can cause a spurious control rod withdrawal are alarmed and, in general, automatic moeian prahibited. These include-a)NXS flux rapid decrease (1/4)(5X in 5 seconds)b)T channel deviation (1/4)p5 F from average)avg c)Rod.control fault-rod motion with no demand Z.Seep Counter-audible clicks from step counter alerts operator eo rad motion.3.NIS PWR RANGE OVERPOWER ROD STOP+(1/4)(105X)4.AVG TAVG-T REF DEV (T 5'F from program)avg 5.PRESSURIZER HX PRESSURE (2350 psia)6.PRESSURIZER RELXEF LXNE HX TEMP (when power-operated relief valves open)7.REACTOR'OOL HX TAVG (1/4)(5'bove nominal T at full power)avg 8.PRESSURXZER LEVEL DEVIATION (5X abave progr:mamed level ae full power)9.AUTO TURBINE RUNBACK OVERPOWER AW (1/4)(3 F less chan high 4T trip paine)AUTO TURBINE RUNBACK OVERTEMP 4M (1/4)(3 F less than high AT trip point)Ll.Steam Generator Relief and Safety Valve Actuation-audible steam release eo atmosphere 12.STEAM GENERATOR LEVEL SET POINT DEVIATION PRESSURIZER SAFETY VALVE OUTLET HX TEMP (2500 psia)CHAHM.'L ALERT-as reactor trip paints are reached for each channel Capitalized word groupings represent engxaving on annunciator panels.REACTOR TRXPS FOR ROD WITHDRAWAL Th<<allowing tx'ip paints were assumed for the evaluation: NIS POWER RANGE HIGH RANGE (2/4)(118X)2.OVERPOWER 4T (2/4)(118X of full pawer AT).OVERTEMPERATURE dT (2/4)(variable) 4~PRESSURIZER HX PRESSURE (2/3)(2400 psia)PRESSURXZER HI LEVEL (2/3)(95X of span)Alarm and Rod Stop PAULT TREE fOR ROD NITHDRANAL ACCIDENT AUIONATIC PROTECTION HEEDED INSUFFICIENT TI'lE fOR MANUAL PROTECTION NEEDED EXCESSIVE ROD NORTH INSERTED EARLY IN CORE LIPE SUSTAIllED ROD MITHDRAVAL HIGH TBQ'AT ROD STOt RICH POSER AT RDD STOt CONTINUOUS ROD llITHDRANAL REACTOR IN NANUAL CONIROL AIPIQIATIC CON THOL PAILURE (SEE PICURE 5+1 2)fICURE 5 1~1 w J4 S fltAOLI t~f ISA~~~VII~A441~~IIC C480fl4.tf&I (SRS PICURE$.1-1)PA I LURE CONTINUOUS ROD MITHDRAMAL COND IT1OH OR EVENT RPS~REACTOR PROTECTION STSTIH RCS~REACTOR CONTROI.SIST IHPROPER C1RCUIT IH RCS ROD'NITHDRAMAL SEC IHS 1HDl GATED TISIP ERATURE OD SPEED HTROLLER(RCS) ROD MITHDRAMAL SEC IHS ALL T VG CHANHE (RtS)Oa THPROPER SET POINTS (RCS)AHD TURS INK LOAD SIC HAL OR tOMER HISHATCH CHAICIFL (RCS)AVG OD STOP ROD MITHDRAMAL SEC INS NIS ROD DROP ROD STOt AVIRAGE TAVG DECREASE INDICATED tRESSURE DECREASE DECREASE IN INDlCATED PLUZ OR NIS (RPS)QQNHEL (RtS)AY%E TAVG RCS RESSURE CHANNEL (RtS)RESSURE CHAHHEI.(RCS)FIGURE 5.1-2 INSERTED ROD WORTH AND REACTIVIXY REQUIRED TO REACH DNBR~1.0 IN HOT ASSEMBLY VERSUS CORE LIFE 1.5~~~-Reactivity Required To Reach Hot Assembly DNBR Of 1.0 (116.5X Power," T~~589, 2250 PSZA)From FuLL Power~~1 0 Region Where Protection Is.Required~I P 0.5 PP Max.Inserted Rod Worth~P'~(Bottom of Maneuvering Band)-': I 0 Min.~erted Rod Worth (Top of Maneuvering Band)-.0 20 40 60 80 100 X OF CORE LIFE FIGURE 5.1-3 1 a 1.0 o.5 0 COMPLETE ROD WITHDRAWAL FROM MAXIMUM FULL POWER Ca/-----MIDDLE OF CORE LIFE INITIAL RATE~Oa9 X 10 6k/SeC.)i~I..I[~.'.".a...p....'.",.'I.. 0'0 40.60 80 100 120 140 TIME, SECONDS 160 150~la~~140 UP 120~0~OW f eo 100 4<<: HI FLUX t ROD STOP.':;: i HI FLUX=.-.~aa~~0 20 40 60 80 100 120 140 TIME1 SECONDS 160 a~~ta 3 j dT mENTS (M.O L)620~aaa aa aa'~~I 600 tP HI POWER.HI'PORN'SHI TEMP.)HI TZMIP.""""'"IHi&"'"'-I-I""" dT ROD:dT TRIP:IAT ROD.":dT TRIP.":I: '::-:.::!!::":I=-i:I .'i: 0......',.".'.-..'.~:.: '.....i:-..~jl laa':::a~"'g 580 560 540 IN~<<~~(~i L I~1""~=-q--)~..'..."..'"::I.i:: T~+:Ii 52O 20 40 60 8O 100 120 140 160 TIME, SECONDS .t~C 0't-...:--0'I'>>I>>~~TRIP AND STEADY-STATE CORE LIMITS AND REACTOR.-.ALABM POINTS 160>>~~I f~:t->>~~i---.-ALARM POINTS--'...ROD STOP I>>>>>>y>>.',:.:..[~>>I J-.I>>~$~~>>-REACTOR TRIP~>>>>~~.I~.>>!WATER LEVEL TRIPI I'..I-HI PRESSURIZER "-~-.-"-n 140~~~+o.~:>>~~p>>I-~~I i."I I i I~I.'STM.GEN.SAFETY VALVES..l I~~'-:I I P I.-}.I~>>>>>>/>>~('Tl~~>>I I~~~/>>120 110'>>,!I..pl".I.:.HX FLUX.HI AT p , i..:l~I~I.f.::..HI AT~PI~T l.'I>>I.~.~I..-.3.I" I'-.":l,*>>+100~.:::I ,~~~:'I~'I)HI FLUX~>>I~~~~~I I I~~~, LL NOM'l" I I>>l'~r I'NAL'-I tt 90~>>>>>>~>>I'Lis>>I>>~>>~~>>>>I~PLOW LIMIT I.'~HI PRESSURIZER WATER LEVFL: I i>~.I.i'HI AX 82400 PSIA~I~I 80 70>>~I>>~~~>>G fx AV I'.I.g.II~'I I.I I I>>I 7'~-HI TEMP.4T-HI POWER dT 540 560 580 INLET TEMPERATURE,'P 600 FIGURE 5.1-6 BEGINNING OF LIFE ROD WITHDRAWAL FROM l02X POWER MINIMUM DNBR;I 2.50 2.00.I sf I I sll'e ti~es sse Ie's~~Ill: W)I'tt I~,I es sg~~e r tet'I~I e I sl e e~f~I I I I I lift:ef II~I~I I~I~LEV I I I I s~Ie~~[,H lift fits sfe~e's"tel lift:n et 1 set.11 est I el Is I Isl-Its st sl" I i I I.I'Ill st I.'t pg SsuRE~elt'f<<s'st~~e'l$N~HI FLUX~~~'e I I.e II I fit""~I fl;e I Ref st f f I ft tile e s..-,il If l'I I I I I e ees.~~I I I I III'se tits (MAX ROD SPEED, MAX ROD WORTH)'-'Hl'LuX:.'- I I~~II It~I I fet f I)e fl'l~el l.50\~I~s<<s'I~'s'I.s.e, lift'll I I I I~~I f I<<H I TEMP.AT.:-I e.~..Qtf'~II te ltf~I eis lett et'I J~I'tl'I tees~~'I', Pt'1st"." Iflj j'l<<n-'HI POWER dT I I I I~f e'HI TBP e~~~~H':-'"s s tt e~es't~tt~iles e e I sit',I's'tl~ss'II'etes wl f fts f~e: HI POWER AT f-, s'T-.I~~I I I~~,~~~I~I~'ll I~tie e I~Is~I I I~I HI POWER dT;t t I stts tsl;I I I I I!" I I I I.i'I s~'"<<ttI'I I I test J s sr , 1':,I ee'.HI POWER hT;,~ie~stl I II,;:.-.~HI LEVEL',&SIC(.,'I TEMP.AT!III~I I I st~III I~gt It lett el list e I Isle ss~e l.00 50 I stt Ole'~I e fl'S.G.~f" j:('OR HOT ASSEMBLY)i ..SAFETY>VALVES'-, el~I~t~~I I II tsii I I I III Ite I sl in t(f I I II et I n es II.,~'I ttlI~I~I I~'.I f I le Ils e e I'il tfs sfts I*e'tts I~e~e~~~fit Ie s I+e te si~s es tees Is It'I (CORRESPONDS TO DNBR it'.e ,S If Ite<<I~I I I I i<<I I:" I~', Ittl If ttf~~Itl sits e I I gtn I I~I<<I s'<<s.In~ss;Ij'I s e s l f I I I<<I I I I~~~Iltl fit 0.05 O.IO 0.25 0.5 L.O 2.0 4.0 Reactivity Insertion Rate, 10 6k/sec ALARM ROD STOP REACTOR TRIP"DESIGN" REACTOR TRIP CORE LIYiIT FIGURE 5.l-7 s ~e BEGXNNING OF LIFE ROD WITHDRAWAL FROM 102X POWER TIME OF EVENT lls tr I~1 r Is s st el ills I'I soI'tss~tl ss I I I I s I le ills lese s lt I" s I I~I I I~I L I 1~~s its sis ills i i I Ilsi 1111 I, s Ii se ts st 250 Ilsi I I:st il I see ss 200 vo 11'ie sst ssi ise ts t'I st I I~,s~~~I see s st Its;ii~I HI le,'ss.'I" so I~I I I I il I ts.;Ii~~I I~~~TEMP.dT'?.i HI LEVEL~'~ss As t'I I't~e s ss ss Jl1.'l'ssl'I s el ls'1 ss s I t I se I ss.'SO I li~l I;I II'~I" I'I t I~ss I~~~I s I'l"I li: s tt?e"s~~~'se I I, I~I~s JC I~~~<'ltll sl H Os I Is I I II I@i sl 1 I I~~d s DNBR HA~1.0~~s I~II sile ss~I 1 i'i i!i~r r II's 1st~i II s ssl sr~I sl I I s I I Ills IIIIIII.'~Ill ilr,.I I'~~~ALARM ROD STOP, REACTOR.TRXP"DESIGN" REACTOR TRXP CORE LXMIT s I'~I is I'1st ll r<o s II, ,II 100 50 IC'lls it i st, HI PRESSURE sill~1 s'is.tf I I~'il lt s'e ls s s"I'I'I',l ts I I I I ski'S'I I;1st ceil;I,~s ts sll I I'Ie~I i'i'st I.i.I es dT it I>>I s Ii I'.ss is st...~I I".II HI POWER.I Ilt s s I'~e~I I I sist J it 1 tl sll'I I il'a I s sl (MAX ROD SPEED,;MAX ROD WORTH);, 11 ss'It st e I I 1 t'I!1st Is I s'st its t'ss i~~~HX LEVEL lg-7:<~IL I 11 e I is~e ss Iss tl St sl I 1st 4 i I Jll I I*Ills r, q tt\se s~~~~'3 DNBR MIN~1.s s'I s's~s.r s't~~~I i I~~~I~s I s li s II~I I I li" I~: I~II s'1 I,'It'I Ij e s Is~st st I'sli e,'.'\l ls I.s~eli~I 1st I t ss I~t Vg is~p'l'sa~I II I t'l I s+II s t s gl s s Il.I Is~l I I s~~dT Ill tli~~I~I;Is ,se t s: I iHX TEMP ss I~s I I s I~I I~~>>Ie I~I ss sill I I I~sl 11 I I I I III.0.'05 0.10 0.25 0.5 1.0 2.0 4.0 REACTIVITY INSERTION RATE, 10 hK/SEC FIGURE 5.1-8 , wt C BEGINNING OF LIFE ROD WITHDRAWAL FROM 80X POWER MXNIMUM DNBR s'AVG~sls~I ,I~iles Il~s~~~I~f~I HI FLUX~I.Ii~-,.~,r,<;'r:,HZ T':::" I'Ii I;II AVG I~s"(jest Qs I I I I s~I s q)AVG,I,~ei I s I I<<HI LEVEL.g..(PRESSURIZER) st i~HI POWER'~~ts I I isa'.'S.G.-:-SAFETY: 'ALVES-i.'>>-'-'IA gg'I,~~~I;s>>I'is I'"I')HI TEMP'~st.I~I,~'~~e~e sets ieii iis'Is's, te I ,~I-'-AT: I ls)~I~,~~~Ii'lte s I I I~I:~T'IM~~f$:.-';~~~si"I'P~~I I ee~I s e s~I I I L-r WER hT'X PRESSURE."NNR!!',tGMFI::"'.:l i I-I-~HI Po I>>ss II['tt'It'Ls I'i'DEVIATION I>>:f s~~s I I i~I I: I I ll I~I~I irpg e, s li (i~I~s ALARM ROD STOP REACTOR TRXP"DESIGN" REACTOR s>>>>see eels>>%TRXP'~~~~i~tl I II~~~~I'I Ills'e~I~.;Is II~e'HX FLGX~I I I~I.II<<Ii<<lit~CORRESP 1.0" I i I~I Is S~.I I I I I~i ss I~i'll il ONDS TO DNBR>LN HOT ASSEMBLY i:e~~~,i'sse I I II t s I~it e I I Ill ss's J I'el I~sli le',~ei~~~, (MAX.ROD SPEED,-.MAX.ROD WORTH)~It'tsi Iles~~~~i Iil~t~I;~I lls i'~I I~~s ,~~~~~~I s s s~I~, se ii e~~~s I~i i i~I II~I s le i.e~<<s'I e~s I 0 tls sill s s e'.III'Iii't'll'll'l el~il III lss O.OS O.1O O.ZS O.S 1.O 2.0 4.0 REACTIVITY INSERTION RATE, 10 8K/SEC FIGURE 5.1-9 W 4ol BEGINNXNG OF LIFE ROD WITHDRAWAL FROM 80/POWER o~TIME OF EVENT i~~o'tl ll-;-I-.':i'-::~G: "-HI PRESSURIZER';, LEVEL~.I~~~I I I It~-'rrr-I~i~i i~I~I~I" o I'.~I~I I o s.t l SAFEZY s-l~vALvEss I o~I~J'I I I Q1 ,~I, LEVEL~~~I ,I j"-,T',;I3 ..'.",.'I PRESSURE'v Iso E li o.'I~~t sl'I I~'AVG;, I;:AT,:Lol ITJ~g HI PRESSURXZER,. t: itlt!:I',.;I Illl li!i i~~'io~I~~HI TEMP 4T~o~I 41:,~o HX POWER 4T DNBR~1.0'.o~I I I L I'.~~i o~I: I I I!4 I I~I-~J I i I I I I I~sill~I~I I'~~I~, I ls I~~~o~~~il:~ilt'~,~I o o~~~I DNBR~1.3'it'I~'t~~'~~(MAX, ROD SPEED,, MAX 4 ROD WORTH)~il, i s~I I: I I!II s Itts~o ALARM ROD STOP REACTOR TRIP"DESEGN" REACTOR TREE~~Ls slot Ills i il~Its~I I I I I~oil Io I~o~.L.l.J:::: 4lt I~I I~~~I t~o 4~o~jilt!too io.,';:@goal: "i~I~o j>>!i is I oJ~I I I: I't s't.Il'"..I tlt!I~~st~o~~~E'X PRESS o, is>>I~~I I II III St I'~I.i I H%H&iti,'-',: HI FLUX'ot'is J tl~o~~I I~II I I I~I I~I~I: tl~~I I~~o!It~~" i li i~o~I~'~il>>io~~~I~~~itis sl 100 T AVC 50 olo~oo~I'!to'lli IID oi":i ri.~I I'~~o~I I I~4 I~'~I I~I I I I I*I~I~o o I o~I~~~~I I I lo~~I I 4I~o~I I~~t I~~~I~'iti,~!il I~I~o-:: ".:++I~.-..'i'il~o~I~~~~o~i is 4s i~!~l I~I~I~I i~oL~I~~~!iot~~I~~I~s~!I~till I ll I IQ~I l'~'io t!4 I I I~~;Is o I~I~I I i It I~I I~I HI POWER 4T~-:.';HI TEMP 4T I o~I It~I I~JA.I I i lot gi i It/lt!.~it'il io~I o~~i o ,is.,'I o i't~tl~'~s i~~sot!I loss I~SS"~'II: I:~-."I 0.05 0.10 0.25 0.5 1.0 2.0 4.0 Reactivity Insertion Rate, 10 6k/sec FIGURE 5.1-10 LPSS Op FEEDWATER>ring power operation, loss of feedwater to the steam generators is of potential concern because it affects the ability of the steam generators to rmove decay heat after trip The protection for thi accident consists of reactor trip and an auxiliary feedwater system.This evaluation describes the Control and Protection System instrumentation provided on a typical Westinghouse PWR Plant to directly monitor or control steam genitor water level.Loss of feedwater accidents without credit for this instrumentation are evaluated. Typical Westinghouse design requirements for the auxiliary feedwater system are included.A typical 1456 MWt two-loop plant was selected for the transient analysis.A loss of feedwater accident to one steam generator is most severe on a two-loop plant.For a complete loss of feedwater, the transient per loop, is dependent on the normalized kinetic parameters; e.g., power (so the results shown here are representative for all plants currently under design.Zn all cases, diverse automatic reactor trips insure a plant trip before any core damage or system overpressure occurs.Manual actuation of the auxiliary feedwater system is considered an adequate backup to the automatic actuation. There is sufficient time (24 minutes)and alarms to take credit for manual actuation. <nteractions of steam generator level control and protection resulting C~rom random failure modes are presented in Section 4.2.5.Alarms actuated 5.2-1 or a complete loss of f eedwater accident are presented in Tab le 5.2-1'C-.suit trees for loss of feedwater accidents are presented in Figures C-2 l, 5.2-2,and 5.2-3.LOSS OF FEEDQATER-TRANSIENT ANALYSIS Several representative transient cases are evaluated for loss of feedwater accidents. Figure 5.2-4 shows the transient resulting from complete loss of the steam flow control signal.As shown by the figure, the Level Control System restores water level such that only a temporary decrease in~ster level occurs.There is no approach to unsafe conditions or to any reactor trip set point.Figures 5.2-'5 and 5.2-6 illustrate a typical complete loss of feedwater"o one steam generator'of a two-loop plant.No credit was taken for reactor trips derived from the steam generator. The loss of subcooled feedwater is reflected to the reactor as a small decrease in therma1 I load, causing the increase in pressure and temperature shown in the-irst minute.(The reactor was assumed to be in manual control with<<manual correction.) One minute after the.loss of feedwater, the steam generator tubes begin to uncover, causing a rapid.pressure and temperature increase.If amchnum pressure control capacity (power operated relief valves)is available, the pressure rise is limited and a high pressure reactor trip does not result.A reactor trip on high pressurizer el occurs appro~tely two minutes after the loss of feedwater. 5.2-2 l r> z inventory in the second steam generator is sufficient to bring Water plant to normal no>>load condi tions.There is no overpressure ox the p an of water from the Reactoz Coolant System.loss o figures,5.2-7 and 5.2-8 illustrate a worst case complete loss of feed>>water to all steam generators with no trip from steam generatox instxu>>~tation.A conservative evaluation is done for a high-power densi.ty p an lant typical of current PWR design g.456 MWt 2>>loop).No credit is taken for charging systems or for energy absorption by metal in the Reactor Coolant System.The results are considered to be extreme values rather than realistic conditions for an actual plant.The reactor trips on high pressurizer pressure about one minute after the loss of feed.Stored heat in the core continues to heat the reactor coolant and the pressurizer M.ls in about three minutes.Steam dump values open fuU.y under Tavg control and reduce steam line l I pressure.After about ten minutes, the Reactor Coolant System begins to boy., aa"h<<h time the x'eactor coolant pumps are assumed to cease adding energy to the coolant.Boiling causes a rapid increase in the volumetric surge rate, and system pressure rises until the volumetric expansion is balanced by safety value capacity for water zelief.(No credit was taken"or the power-operated relief values in this analysis.) teŽgenerated in the core is assumed to fill the upper reactor vessel, e steam generators, and half of the coolant piping befoxe escaping to e px'essurizer. During this four minute period, most of the reactor 5.2-3 e olant fluid'is lost as water discharge through the pressurizer >+sty valve.As steam is discharge through the pressurizer, pre measure decreases to the set pressure for the safety valves.After an additional ten minutes of boiling, (24 minutes after the loss of feedwater), the top of the core is nearly uncovered. Xt was assumed that the Auxiliary Feedwater System was manually actuated at this time (push buttons on the control board)and 200 gpm auxiliary f eedwater per steam generator began immediately. Qithin two minutes of starting auxiliary feedwater, the steam generator heat removal exceeds decay heat and reactor coolant~emperature and pressure rapidly decrease.5.2.2 TYPICAL SYSTEM 1ESIPil REQVIEEMENTS Auxiliarv Feedwater System To prevent release of reactor coolant through pressurizer safety valves i and to protect the core, a supply of high pressure feedwater must be provided for the removal of residual heat from the core by heat exchange in the steam generators when the main feedwater pumps cease to operate on blackout or because of fault conditions. 'yp<<al criteria for actuation of auxiliary feedwater is presented in iable 5 2-2 afety zequi.rement is to include two separate auxiliary feedwater y terna to ensure reliability of supply.One s'ystem utilixas a steam turbine driven auxfLiazy feedwater pump, ae urbine being connected such that steam can be supplied from some 5.2-4 t, ~of the steam generators. The flow rate, usually about 200 gpm nr steam generator, is, sufficient to maintain a milkman depth of water>r ste the steam generators. ocher system utilizes two (2)reserve auxiliary f eedwater pumps, a~of about half the capacity of the steam driven.pump.How rate suf ficienc to ensure cooling of the system and to Prevent water discharge crom Reactor'oolant System xelief valves.The reserve auxiliary feed-vacex pumps normally are driven by prime movers using'source of energy other than steam from steam generators. The head generated by the feedwater pumps is to be sufficient to ensure that feedwater can be pumped into the steam generacor when safety'valves are discharging. Pumps axe capable of starting and delivering feedwater vithin two (2)minutes of the blackout or fault conditions requiring puup actuation. >ie typical design basis for sizing auxiliary feedwater pumps is given by Table 5.2-3.Sources of water for auxiliary and reserve auxiliary feedwater pumps are duplicated or if convenient, triplicated. Ordinarily, wager is'}rawn from a condensate storage tank containing water of normal purity,'<<may be drawn through emergency connections from other sources such~city water, well water, fix~+in water, service water, etc., to obt ain a supply under sufficient pressure to satisfy auxiliary feed>>"-pump suction requirements under emergency conditions. 5.2-5 ( from the auxiliary pumps is delivered to the steam generators ~pter pip elines separate from the main f eed pipel ines.Pip elines are pape spaced to assure that a single fault does not prevent feedwater~~Jv spa~e whole of the auxiliary feedwater system (water supply, piping, diesel generators, etc.)must be"Class I" seismic design standard.+ pggp+I~Steam and Feedwater Pi in<iailure of any main steam or feedwater line or malfunction of a valve~tel].ed the"ein or any consequential damage must not reduce flow capability if>e auxiliary (emergency) feedwater system, render inoperable any~eered safeguard service (i.e., controls, electric cables, containment aeM4 g piping, etc.), initiate a loss-of-coolant accident, cause failure if any other steam or feedwater line, result in the containment pressure exceeding the design value or impair its impermeability and integrity. I>steam and feedwater lines together with their supports and structures ~<<en each steam generator and their associated isolation valves are to-"'"Class l" seismic design standard.* e oe expression"Class I" used in this context is defined in sign of Nuclear Power Reactors against Earthquakes" in a document~titled"Behaviour of Structures During Earthquakes" Appendix A, by Housner, professor of Civil Engineering', California Institute of,~""oology. Pasadena, California. Published by American Society of"-+1 Engineers-Engineering Mechanics Division.(October 1959 EM4)5.2-6 TABLE 5.2-1~S ACTUATED FOR A CO%'LETE LOSS OF FEEDWATER ACCIDENT Cause of fault (in general, any condition causing a complete loss of feedwater causes an alarm)2.Low feedwater flow (partial reactor trip, two channels per steam generator) Steam generator level deviation (one per steam generator) Low steam generator level (partial reactor trip, in coincidence with 2.above, two channels per steam generator) a 5.Low-low steam generator level (reactor trip, thr'ee channels per steam generator) 6.Automatic control rod motion 7.T deviation avg 8.High T (3 or 4 channels)avg 9.Pressurizer level deviation LO.High pressurizer pressure (two channels)11.Pressurizer relief line high temperature l High pressurizer pressure reactor trip Note: It is assumed that the-turbine and reactor are tripped on high pressurizer pressure.Pressurizer safety valve outlet high temperature ~4'igh pressurizer level reactor trip Low steam line pressure (not on all plants)~6~Pressurizer relief tank liquid high temperature ~7'ressurizer relief tank high pressure~8'ressurizer relief tank high level 19.~High containment pressure (safety injection actuation, at about lO~of design pressure)10 Low pressurizer level (partial safety in)ection actuation) TABLE 5.2-2 TYPICAL CRITERIA FOR AUXILIARY FEEDVATER ACTUATION Motor"Qxiven P s Low-low level in any steam generator starts both pumps.action requires the same bistables and relay logic as used for the reactor trfp.(2/3 circuitry for any steam generator) .b)Opening of both feedwater pump circuit breakers staxts both pumps (1/1+1/1 logic).c)Safety injection sequence d)Manual.Turbine-Driven P a)Low-low level in two steam generators.(Same circuitry as I.A.above)b)Loss of voltage on both 4KV buses (1/1+1/1 logic)c)Manual.3.General Criteria a)All three pumps are to have independent starting circuits such that no single failure prevents mire than one pump from starting.b)Instxmentation and logic circuits for la and 2a must meet the single-failure cxiterion fox actuation and be capable of testing at po~er.Compatibility with reactor trip circuit testing is also required.c)Spurious actuation due to unusual failures is tolerable, but routine testing of reactor trip circuits should not cause spurious starts. 400 0 HZ PRESS/ALARM:-":.'-.='::. -,'tL.'-':4:-:1::!! t:::il::-::rW I'.='=Qptftt!ti.!r.'L" COMPLETE ROD WITHDRAWAL FROM MAX.HJLL POWER BBCINNZNC URE-----MIDDLE OF OF CORE LIFE CORE LIFE 0 20 40 60 80 TIMEN SECONDS 100 120 140 160 800 4&NN aW i 5 0 HI LEVEL 40 60 80 I fl P~&l~a 100 120 140 160 TIMEN SECONDS 2.0 1.5 1.0 0.5'Wa.IB t~IVPfPt.-DNBR MIN.:~1.30 tll')" HOT QQLNNEL:1-WOO I~NC1 BBBMILY-N~0 20'0 60 80 100 120 140 1 0 TIME, SECONDS TABLE 5.2>>2 d)Instrumentation and logic for lb and 2b should be considered as operational signals for economic (not public safety)protec-tion, (SimQ.ar to reactor trip on reactor coolant pump circuit breaker opening).e)As Engineered Safeguards components, the actuation circuitry for auxiliary feedvater actuation shall meet all appU.cable IEEE Design Criteria. e'TABLE 5.2-3 CAL DESIGN BASIS FOR SIZING AUXILLQE FEEDWATER'PUMPS ~~DRIVEN PUMPS I~steam~riven pump capacity is adequate to maintain at least lp feet of water in all steam generators in the event of loss of station power from normal full power operation. No credit is~owed for motor-driven pump capacity.~OR-DRIVEN PUMPS'I Each moto~ven pump, by itself,.is'adequate to prevent water relief from the pressurizer relief valves under the following as sump tions.a)Plant trip occurs frommaachnun steadymtate power and temperature. conditions. b)All steam generators are at their low low leve1 trip points at the time of trip.c)No credit is taken for any additional sources of feedwater after trip (station blackout assumed.)d)At least half, but not all of the steam generators are supplied.with amcLliary f eedwater.e)Natural circulation exists in the Reactor Coolant System.0 No credit is taken for charging or letdown from the Reactor Coolant System.g)Applicable starting delays and feedwater pipe purging times are used. FAULT TRtt FOR IDSS Ol'IB+STIR F(DM'.m~I'l~O CORE SECIHS To UNCOVER INSUffo S Iol gURCINC CAT.A NAHUAL A o f 0 ll 0$o TIKE (ilo NIH.)NANUAL A,F,M,S, TINE (o lo NIN.)RCS HEATS OH DECAT HEAT M Oo AUTO, A.F.M.S.ALL SoCo'S Dtf STATION (Stt FICURR Sot I RoTo ON H'lo FREE OIlltt SoCo'$Q(FTT bCS HFATS SoC TURES RECIN To UNCOVER HOTEl HI.FREES.R.T.NAT bt HECSSSART TO=FREVBIT STSTtÃOVER TRESSURE IO IO IXIOL I O I I.OIO.IIOII OOI.IIIOII MIO I.OIO.IOI OOO OOO LOM SoCo LEVEL NANUAL REACTOR AND IRIF-~M SINo NIS IP SLUM LOSS Or LEVEL RAPID lOSS OF LEVtL LOSS OF SoCo LEVEL REACIOR AT FMRo MITH IHSUFF.F.M OR AbbbtVIATIOHS RCS~REACIOR COOLANf STSTEN RT REACIOR IRIF S.I SAftff IlQECTION Fo Mo ftEDMATER AofoMoSo AUIILIART FoMo START Sooo~STEAN CENtRATOR N J4 NOIOR DRIVEN NECRANICAL FAULT AUTO.C(NIROL FAULT ELECTRICAL f AULT LOSS Of FELID (Stt FICURR Sot I) pan.T Tace poa ross op pcaeATca nuu SER Flcuac S.I-I AUTQtATIC CONTRO FAULT ELECTRICAL fhULT LOSS Of f.M.SUCTION 2/>Hl.LEVEL CLOSES F.M.VLV IHCOHPLETE S.le SIGQ-H$R.T.I RQQIHIHG F.Mo MHAN~f.M.VALVE CLOSE EI CONTROL fAULT I LOOP LOSS Of COOIAHF FLOV RE-REACTOR AT BILL POllER S.CEN.LEVEL CONTROLLER fAUL OR RFACIOR AT RE-DUCID FOlXR TNFROFER cxTe IN CONTROLLER I PLPIP L.O.F.M.-(ELEC.FAULT)4 EV.RUS FAILURE ONE SUS LOSS OF COH-OENSATE tUHPS OR I~lie SS OF HTR.DRAB f LBP LO.SIN.fLOM Rl fEED BOll C T OH T OH HI LEVEL INDICA-TION (R,t.S.)AILURE OF COH-EHSATE RYPASS Ab baEVIATI ONS fAILURE CONDITION R.T.-REACTOR Tait S.l.-,SAfETT IHIECTION R.t.S.-REACTOR PROTECTION STSTEH f.M.-FEEDMATER Aaf.M.S.-AUXILIARY f.M.START fIGURE 5.2-2, ~~FAULT TREE POR LOSS OF PEEDWATER PLOW SEE FIGURE 5.2-1 STATION BLACKOUT WITH LOSS OF PEED STM.GEN.LO-LO LEVEL A.F.W.S.LOSS OP LEVEL IN STM.GEN.F.W PUMP BKR.MOTOR A.F.W S 4 KV UNDERVOLT STEAM A.F.W S.(LOSS OP REACTOR COOLANT FMW REQUIRES 2963)IATE REACTOR TRIP)COMPLETE LOSS OF 4 RV SYMBOLS ABBREVIATIONS F.W.-PEED WATER A..P.W.S.-AUXILIARY P.W.STAR]FIGURE 5.2-3 lt F F LEVEL RESPONSE TO LOSS OF STER%AN SIGNAL PROP+INTEGRAL K+-1 1S PROP+INTEGRAL K+-1 2 T S PHEOMATIC POSITIONER POSITION W 8 Qf Q NORMALIZED STEhK FLOQ 8 Qf NOHHAIZZED PEEDWATER PLOW-1 K<<1 fe T-200sec 1 K~10 T~200 sec 2 2 l~~-" FEED%TER VALVE~POLLY OPEN~~~]~~~~4~-~~~--I-I~~10 10 20 20 30~, SECONDS 30 40 40 50 50'0 60~~~~~~~~I'~~W~~~~~I.~~o FZGaaE 5.2-4 LOSS OF FEEDQATER TO ONE STEAM GENERATOR AT T~ONE SECOND TYPXCAL TWO-LOOP PLANT 2600 2200 1800~W~I t=LL:~t 1400~~800 600 400~t~~~PRESSURIZER .LEVEL HEACTOR TRXP-'~t 200'25,,dao~~50,00 25,Oej~~4~~~~40 80 120 160 200 MME, SECONDS FIGURE 5.2-5 LOSS OF FEEDWATER TO ONE STEhH GENERATOR AT T~ONE SECOND" 640:".I:~l I~E~~~I A.~I~'I 620"..:.:-:.-.~~~-: 600~~~~~E"'3'-'-=580~~:~~500 540.L--..:4.P':: ll=.S'500 1.0.8-COEE~-POWER'-:=..~.6 i-.:)"ŽTOTAL GEN.~2 0 40 80 120 160 200~, SECONDS FIGURE 5 2-6 l~ 't e'e 0 0 F00 50 0 0 3.0 2e5 2.0 200 100 ga 0 0 Q2IPLETE LOSS OF PEEDWATER<<~~I~~I~~~~I e e e i!i~:..i'.I~~I~I I~I>>~e~~~'I~~500 1000 TIME SECONDS 1500 I~I r~~I, t':I~~~('I~I:::: J<<i~~I.<<n I..~::~(r'i:..('I~.I~'I'~~I~e~e~I.~e I~e I~I.e I'00 TIME SECOR)S 500 1500 STEhM PLOW'TO PRESSURIZER ~I I(i WhTER BKZEF j I e (*'STEhM RELIEF IHS BOILIHG.COHDENSATZOS ~HZ PRESS TRZP-'KCEIES BOILS~:...II....j;-.-:i:<<;';;,I I-:;:-'-'I'<<'U- ~e 0'0 00 1500~~:~I I: 4 J<<~::.i.-.~~10.:::..":: LI I I I t~~:-BOTLTHG f~WhTER R1KXEF::.-.;hei~.:.'"::.:.ll'. I g~i'.I:.II I."I e.I~.~i I I (:-:~~,"".,: hIEZLZhRT PEH"'HsSRS i:I I.':j~e 1000 500 1500 TIME AFZER LOSS OF PEED, SECONDS PIGUBE 5 2 7 CQHFLEZE LOSS OF PEEDWATEK~+o 600)$50 0 500 1000-1500 TZHE, SECONDS 10QO la 8QQ 6QQ.'0 gQQ Q 0 500 1000 1500 2000 TIME, SECONDS AUXILIARY FEHNATER SYSTEM SCHEMATIC 2 LOOP PLANT Motor Operated Valve M Pneumatica11y L O.Locked Open Operated Valve Manual Valve (normally open)I,~MOTOR OPERAL~CHECK VALVE STOP CHECK VALVE Condensate Storage Tank Manual Valve (normally closed)~Prom Alternate Water Supply (CLASS I)CLASS IXi CLASS I L 0.LO L.O.Motor Drive Turbine f Drive Motor Drive Prom Main Peedwater System SG B-"rom Main Peedwater System FIGURE 5.2 9 4* OSS OF COOT~i-~OW ANALYSIS LO INTRODUCTIOÃ ~SD

    SUMMARY

    c~3~I the reactor is~the power range of operation, loss of coolant flow eaten t e potential conce-n.Without suf f icient flow, DNB and clad failure~d quickly occur.estinghouse PWR's, constant-speed pumps supply coolant flow.Plow is egulated or otherwise varied.High-inertia flywheels are mounted on each.so that f low dec=eases ovex'period o f time (typically 12 seconds to f flow)following a loss of power to the pump motor.This flow coast-ioMn allows for Protection System tMe delays and remova1 of stored heat in xbe fueL.Subsequent decay heat is removed by natural circulation. Diverse, redundant protection circuits are provided to protect against all possible loss of flow accidents. These protection circuits axe evaluated this report for multiloop loss of flow, single loop loss of;flow, and~othetical pumo seizure.Although design Limits might be exceeded, the onsequences are found to be tolerable in all cases even if any one protection circuit failed to per orm its function.-3.Z PROTECTION SYSTRf DESCRIPTION erous reactor trf.p circuits provide core protection for a Loss of flow~c-"ident. These trips are: reactor'oolant f low, Reactor coolant pump bus Low voltage, Reactor coolant pump bus Low frequency, Reactor coolant pump bx'esker position, Overpower Delta-T.5.3-L

    percept f or the overpower Delta-T trip, all trips are blocked below 10X power.Low Reactor Coolant Flow Three redundant flow channels are provided for each loop.At high power, loss of flow in any loop, as sensed by two of the three channels, actuates a reactor trip.The set point for this trip is typically at 90X of normal indicated flow.At lower power (typically 50X, 65X, and 75X for 2, 3, and 4-loop plants respectively) loss of flow in any two loops actuates trip.The same flow set point and 2/3 logic is used as for the single loop low flow trip.Reactor Coolant Pump Low Volta e In order to insure that total loss of pump power does not violate the core design limits, a reactor trip is actuated by low voltage on thy, reactor I coolant pump buses.The design requirement is to meet the single-failure criterion for complete loss'of pump power.The trip logic is generally such that loss of power on any two buses causes a reactor trip.Typical set points for this trip are in the range of 60X to 80X~of normal voltage.Reactor Coolant Punm Low Fre uenc The reactor coolant pumps are provided with flywheels to increase their rotating inertia.This provides forced circulation for some period of time after a loss of power.It is conceivable that a rapid system fre-quency decrease would slow the pumps down faster than for a loss of power.5.3-2

    Therefore, an undhrfzequency reactor tirp is provided.The trip logic is identical to that used fox the undexvoltage reactox trip.In addition to tripping the reactor, underfxequency also trips open the reactor coolant Pump circuit breakers to maintain effective flywheel inertia.Typical setpoints for this txip are in the range of 56-58 cps.p Circuit Breaker Position A reactor trip dezived from auxiliary contacts on the reactor coolant pump circuit breaker affords additional safety mazgin for the most Likely causes of loss of flow.Trip logic is shear to that used fox the low flow'rip;i.e., opening of any breaker, as indicated by a position contact, actuates a zeactor trip at high power, and opening of any two breakers at reduced power actuates a trip.Ove ower Delta>>T Reactor Tri This trip circuit is designed to protect the core against overpower transients. However,since Delta>>T increases as flow decreases, it also provides backup protection for loss of flow accidents. On a two-loop plant, two Delta-T channels per loop are pxovided;one channel per loop U provided on thx'ee-and four-loop plants.For aLL plants, trip of two channels trips the reactor.During steady-state operation, the trip set-Point for these channels is in the range of llOX to 120X of the normal Delta-T indicated at full power.This setpoint is automatically reduced<<r increasing temperature (x'ate of change of T)to compensate for piping avg delays.(However, the setpoint is not increased for decreasing T.)Since avg also increases following a loss of flow accident, the Delta-T set-avg 5.3-3 4@i'4.a*A'4" po oint decreases at.the same time as Delta-T increases. This significantly decreases the trip delay time.ggarlacks ~cept for the overpower Delta-T reactor trip, the loss of flow protection trips are blocked at low power.This interlock is in itself redundant and diverse, in that the trip signal is passed.if either 2/4 nuclear channels indicate above 10X or if 2/2 turbine load signals indicate above 10X.Single loop loss of flow trips from low flow and circuit breaker position are blocked at reduced power.(The trip is passed if 2/4 nuclear channels indicate above a preset, power.)Since these two trips share a common, nonMiverse interlock, they should not be considered as.completely diverse protection functions. 5.3.3 MULTILOOP LOSS OF FLOW I A fault tree for a multi-loop loss of flow accident is shown, on Figure 5.3-1.Only electrical faults can cause all pumps to fail simultaneously, and the undervoltage and underfrequency reactor trips provide direct protection against these faults.The low flow reactor trip circuits provide backup protection for this accident, and they do not necessarily insure a minimum DNB ratio greater than 1.30.Figure 5.3-4 illustrates the transient resulting from a complete loss of flow accident representative of high power density plants currently under design.The solid lines represent the design case, with reactor trip on undervoltage. The dashed lines illustrate the calculated transient if this reactor trip is neglected. 5.3-4 alculations are done by standard design methods, with the usual~ese ca c tions for safety analysis;e.g., the most adverse steady-state sssump<<opera rating conditions at the time of trip.accident is relatively rapid, with a DNB ratio of 1.3 in..the hot~e acc channel reached in about two seconds.It is not appropriate, therefore, gp assum ssume any manual corrective action.Also, the minimum DNB ratio is reached at the time the hot spot heat f lux begins to decrease.There is little transient overshoot except for reactor trip time delays.The undervoltage trip ii the design protection for this accident, and it meets the requirement that, the minimum DNB ratio does not fall below 1.30.Less restrictive requirements would be imposed on a backup trip.A minimum allowable DNB ratio of 1.0 in the hot assembly, could be selected on the basis that this would insure that core damage, if it occurred at, all, would be limited to a very small fraction of the coze.(The peaking factors in the hot assembly are essentially those in the hot channel gthout al1owance for engineering subfactors.) Alternately, a hot-spot clad melting limit could be imposed for this accident on the backup protection. With either requirement, Protection System diversity exLsts.The low flow reactor trip point is reached at 1.8 seconds, assaying a 3Z error in the set point (trip point at 87X flow).Although the hot channel minimum DNB ratio is somewhat below 1.3, the hot assembly minimum DNB ratio is still well above 1.0.If DNB should occur at the>>t spot, the transition boiling correlation'ndicates that peak clad temperature would be in the neighborhood of 1000'F, and no clad damage is expected.(See results for single 1oop loss of flow.)5.3-5 Ne De ta-e D lta-T transient is calculated for this case.Because of piping~d instrume trument delays a trip signal would not be generated until about gecon nds after the loss of flow.The effect of rate compensation on is to reduce the trip set point.Even with this longer trip delay, ave die pea ak clad temperature is not expected to exceed 1500'F, we11 below<he melting point.Therefore, three levels of protection exist for a~nltiloop loss of flow accident.. 5.3,4 SINGLE LOOP LOSS OF FLOE A Eault tree for a single loop loss of flow accident is shown on Figure 5.3-2.Vote that loss of power to one bus is the only credible way this accident can occur without an immediate trip from the pump circuit breaker.{An open circuit in the pump motor is a highly unlikely fault, and is shown r Eor the sake of completeness.) The circuit breaker trip is therefore classed as a backup, or anticipatory, trip.I Figure 5.3-5 illustrates the transient resulting from a single-loop loss ot flow accident in a high-power density, two-loop plant.The transient h is less severe in a three or four-loop plant.The low-flow reactor trip is the design protection for this accident,<nd it meets the design requirement of minimum hot channel DNB ratio uo less than 1.30.If the accident is caused by loss of bus voltage, and no credit is taken Eor the low flow reactor trip, the hot channel DNB ratio would be less than 1.3.However, a reactor trip on high Delta-T would terminate the 5.3-6 icc ident before 18B occurs in a significant percentage of the core.pssumI sag that the hot spot goes into DNB at the time the hot spot DNB rat o+t j o is L.30, and assigning a conservative additional instrument delay of p 9 sec to the Delta-T trip, a peak hot spot clad temperature (on the inner clad surface)of appro~tely 1300'F is calculated using a transition boiling correlation. Only the Delta-T transient for the active loop is shown on Figure 5.3-5.S For the dead loop, Delta-T increases somewhat more rapidly.On a two-loop plant, two Delta-T channels exist on each loop, so a reactor trip is expected earlier than is shown.Ia summary: For a single loop loss of flow accident, Protection System ddversdty does seder.At least tso, and generally three, dndspendent levels of protection exist.5.3.5 LOCKED ROTOR ACCIDENT The hypothetical'case of an instantaneous pump seizure.has been'evaluated <o determine whether diversity exists.The fault tree is shown on Figure 5.3-3.If this accident occurs when the reactor is at high power, the core design limits are exceeded independent of any protective action.The design requirement for this accident is to prevent any consequential failure of<he Reactor Coolant System.Failure could be caused by high system pressure.Also, systems calculations cannot be done with confidence if gross core damage occurs.For this reason, core conditions are evaluated. 5.3-7 The transient for a hypothetica1 locked rotor accident is shown on Figure 5.3-6..Flow through the Reactor Coolant System is rapidly reduced, Leading to a reactor trip on a low-flow signal.Following the trip, heat stored in the fuel rods continues to pass into the core coolant, causing the coolant to expand.At the same time, heat transfer to the shell side p f the steam generator is reduced, f irst because the reduced f low resuLts in a decreased tube side film coefficient and then because the reactor coolant, in the tubes cools down while the shell side temperature increases (turbine steam flow is reduced to zero upon plant trip).The rapid expansion of the coolant in the reactor core, combined with the reduced heat transfer in the steam generator, causes an insurge into the pressurizer and a pressure increase throughout the Reactor Coolant System.The insurge into the pressurizer compresses the steam volume, actuates the automatic Spray System, opens the power~perated relief valves, and opens the pressurizer safety vaLves, in that sequence.The two power-'operated relief valves are designed for reLiable operation and would be expected to function properly during the accident.However, for conservatism, their pressure-reducing effect is not included in the analysis.With no protection, a peak reactor coolant pressure of approximately 3050 psia would be reached about.3.5 seconds after the pump seizes.After this time, fluid, mixing and increased heat transfer in the active steam generator tend to reduce the pressurizer surge rate, and the pressurizer safety valves reduce pressure.(During the peak, the pressurizer surge rate may slightly exceed the pressurizer safety valve capacity, but pressurizer pressure does not significantly exceed the safety valve set 5.3-8 lus aU.owance for accumulation.) Although the normal code-allowable ><assure p Us pressure o of 2750 psia is exceeded foz this accident, the peak pressure is below t e u he ultimate strength of all members of the Reactor CooLant System by an approx a ximate factor of two.Therefore, the Reactor Coolant System would z'ega jn intact o In the core, clad melting at the.hot spot inner clad surface begins at.24 seconds.Af ter this time, system calculations are uncertain. The reactor trip set.point for the redundant low flow instrumentation on the affected loop is reached within 0.1 seconds.Assuming DNB at 0.1 seconds, and.a conservative trip delay (2 seconds befoze the nuclear flux is reduced to 80X), the peak clad temperature is approximately 1%0'P and is reached at 4.5 seconds.Other calculated results for this case are peak system pressure of 2800 psia and less than 20K of the fuel.rods with a k calculated DNB ratio of 1.0 or less.Neglecting this trip, a high pressurizer pressure trip point would be C reached at about 1.5 seconds,'nd a high Delta<<T trip (from the active loop)would be reached at about 4.5 seconds.The peak clad temperature for these cases would be 1750 and 1950 for the high pressure and high Delta>>T trips respectively. Since these values are well below the melting point, no gross cLad failure is expected.In summary: For the hypothetical locked rotor accident, core design Limits may be exceeded.However, three independent, diverse levels of protection exist, any of which would insure that the Reactor Coolant System boundary is not violated.5.3-9 FAULT TREE FOR MULTZLOOP LOSS OF FLOW PROBABLE GROSS CORE DAMAGE SLS HI 4T R.T.COND XTIO POSSIBLE CORE DAMAGE FAXL'ORE LOW PLOW R.T.L.O;F.-LOSS OF FLOW R.T.-REACTOR TRIP R.C.P.-REACTOR COOLANT PUMP DESIGN CORE LIMITS EXCEEDED (DNBR<1.30)REACTOR.AT HXGH~~POWER~ALL LOOP L.O.F.WXTH NO IMMEDIATE R.T OR UNDER VOLTAGE R T.BKR.OPEN R.T.LOW FREQUEHCY ON ALL BUSES SIMULTANEOUS LOSS OF POWER SIMULTANEOUS R.C.P.BKR.OPTING."IGURE 5.3-1

    FAULT TREE IOR SIICLE UM)t lOSS OF FMQ tRObhhLK CROSS CORE NHhCI CONDITION Nl AT R.T.CORK DKSICN LINITS KICKKDKD UN FLON R>>T>>.L>>O>>F~MSS OF FLON R>>T>>~REACTOR IRIt R>>C>>t ii RKACFOR COOIANT FUNt CORK DNSR>>l 3 hfACIOR AT RICiR FOMER'llCLE LOOt L>>O>>NO INNKDIA (I)REACTOR'NOFFKTION SISTIIl (2)ELECTRICAL thOFKCTION STETS)I SINCLE UXlt R C FAULT lAl5$OF bUS PARR SKR OFKN R>>E, (I)SUS FAULT IO ntKN SKR.a TSKF AKD SKR IO OPENS TRIP!KACIOR (2)R>>C>>P>>bKR>>Ot INC IC>>P>>OPEN CKT>>R>>C>>t>>QIORT CKT SUS FAULT PI&et$3>>>>2 ~q I I i FAULT TREE FOR LOCKED ROTOR ACCIDENT PROBABLE GROSS CORE DAMAGE HI dT R.T.HI PRESSURE R.T.PROBABLE CORE DAMAGE LOW FLOW R.T.CORE DESIGN LIMITS EXCEEDED SYMBOLS CONDITIO REACTOR AT HIGH POWER R.C.P.MECHANI FAIISRE (LOCKED ROTOR)R.T.-REACTOR TRIP R.C.P.-REACTOR COOLANT PUMP FIGURE 5.3-3 h Pt~>a' Es KULTI~P LOSS OP PLOW, TYPIChL PL@K'I~t 80 a 70 60 50 CORE FLOW PO NUCLEhR POWER{meZRVOLTaCZ ,TRIP)HOT SPOT HKLT FLUX'UNDEKVOLThaK lzazH..,pe~I~a: t I l.6 HOT ASSMLY'--MXH.DHB RATIO=)i I()~fe~J 1.2 L00 0 100 90 SIC LOOP LOSS OP KlÃ2-UNp MT 80~0 70 OW DEAD: LOOP 50 1.8:.:.i HIM.DMS RATIO j~I~1.4 ROT ASSZ8BLY-1.0 1400 1200 NO TRIP aoo TRXP ON LOW PLOW~*I*~\120 u.p DELTh T TRXP POISE HX 4T-=-...TRZP.~NO TRIP~~~~I~100 (ACTIVE LNP-TRZP PolllT 0 1 2'3 4 5 6 7 8 9 10~jj&la'e ht TPVr tmTP C 0 C

    LOCKED ROTOR, LOSS OP HOW 2 LOOP PLANT~~F00 SO I..i~~~ACTXVZ MOP I~~~~~*60~~CORE PL(M~~~I]JJ~~~~w~40 20 3000 zsoo~~DEAD LOOP':.l I~~~~>>~l-~~I~~~'I~I~~~~0 5'o S~6'.I'.~I OJ 2600 2400~~REACTOR f COOLANT SYSTEH PRESSURIZER 'NO TRIP LOP FL(N TRIP~~2200'0 3000~o~~~~~~TIHE, SECONDS\~2500 J~+>>~e f I~~~I II.I'I TIHE OF REACTOR.NO TRIP-=(SEC)2000 e 4 4 F500 H 2 lOQO 500~~~~~~~~l~i I I~%t~I L~~~\)~~~I~~'l I~~<p e letely separate sensors and channels, and reactor trip is actuated if any two channels indicate high power.Analysis has been conducted to r:.'.-e*t~~~=~vl~Ie determine the consequences of a hypothetical failure of all the nuclear channels coupled with a hypothetical rod ejection accident.Analysis, made on the basis of the Ginna Nuclear Plant of Rochester Gas a Electric Co.(RGB), indicate that in the majority of rod ejection cases no protection is required (for example, ejection of a zod from its normally-expected position). It is further shown that the Delta-T trip provides I~, an acceptable second level of defense for some cases.However, protection can not be demonstrated for some of the more severe full power cases.Protection may in fact exist, but it is not possible to positively demonstrate this with the currently available models.An analysis of the available trip has been made, and is compared with an I arbitrary clad limit of 2750'F and an arbitrary pressure Vms of 3000'psi.Two detailed cases are presented: a severe case from zero power end of core life, and a moderate case from full power end of core life.No reactor trip has been assumed for either case.5.4.2 CASES CONSIDERED IN DETAIL Zero Power Case The case considered represents a zod ejection accident for an end of life core.The assumed ejected zod worth and hot channel factor aze 1.0X6k and 12.5 respectively.

    ~ting power transient and hot spot temperatures are detailed in~~result F 5.4-1.1 steady power level is conservatively assumed to be 15X of full~+fina s This power level is lower than the value which one might normally~er.~q)ect foz a rod reactivity insertion of 1.0<k>>owing to the high feedback ueig i hting factors-{The large hot channel factors results in a large power n<e in the hot spot, where the statistical weight is high).The prompt yzst results in a reactivity undershoot which, combined with the shortage of delayed neutrons, temporarily fozces the power to a value below equilibrium condition. The power level is assumed to ramp up to 15X at 5 seconds after e]ection>>although calculations indicated that it would take much longer to reach this power level.The plotted hot spot temperatures indicate that equilibrium conditions can be sustained. Zt is therefore concluded that no protection is required for this accident.Zn general, the ejected rod worths and hot channel factors arq lower for the beginning of life zero power cases, and therefore the consequences are expected to be, somewhat less severe.Full Power End of Life Case The case presented is for a rod ejection accident occurring at the end of core life with an e5ected rod worth of 0.336k and a hot channel factor of 3'3.The power transients and hot spot temperatures are detailed in Figure 5.4-2.The equilibrium power level is 112X of full power.5.4-2 0 k cladding temperature of 2950'F occurs some 50 seconds after ge pe Under equilibrium conditions, some 50X by volume of the hot ,ection 0]fuel is melted.A reactor trip'n overpower Delta-T occurs at 6~~c ue limiting clad temperature to about 2400'.This case represents recon s, evere accident, but is not intended to represent a limit.~<eve>~~lar rod ejection accident, occurring at the beginning of life, auld result in an equilibrium power level of about 12SX of full power,ith an equilibrium cladding temperature of the order 3100'F to 3200'F.5.4.3 BACK<<UP TRIP PROTECTION The most limiting cases occur at or near full power.The protection System is examined to determine under what circumstances a trip signal would terminate a rod ejection accident at full power.The results of the study are illustrated in Figure 5.4-3.The graph is a plot of total excess nuclear energy addition versus time.Steady full power operation results in a locus covering the hd~ontal axis.The nuclear flux trip is represented by a straight line of gradient 0.18,, corresponding to a power'level of 118X Note that this line is an upper and its position is in fact dependent on the power versus time shape.This is a general, but not important, effect for the lines plot~ed.A rise in nuclear power produces a pressure surge.However, the effect is attenuated by the heat transfer time constant, of the fuel (of the order of 4 seconds), and the possible relieving effect of the hole in the vessel head and relieving capacity of the power-operated relief valves.The high pressure trip could not be expected for any rod ejection accident.5.4-3 The high Delta-T trip furnishes a backup trip for any severe rod e)ection zcc cident.Except in the most severe cases, it Limits the clad temperatuxe pp]ess than 2750'F.Transport delays in the coolant loop delay the trip f or several seconds.Also plotted on the graph axe two arbitrary limit lines.They are respectively a clad Limit of 2750 F*and a Coolant System pressure of 3000 psi.Both these Limits have been arbitrarily selected and are not intended to represent I~I-.r pl~S physical Limits.A power burst of some six full power seconds at time zero results in both these 1lmits being reached some two to.three seconds I later.This is not a physically reliable condition for any Westinghouse reactor.Figure 5.4-4 shows the power transients for rod ejection accidents occurring at end of core life for various ejected xod worths.fr f t I 1+These Lines are based on stead~tate and transient hot channel factors of 3.23.5.4W j ZERO POWER EHD OF LIFE ROD EJECTION, NO TRIP&~~~HjjCLjj&R POjjE&VS~T2$=~1~~~I i.: A~~4~1.0X F~12.S"::?30 20 M~--EHERGT INPUT UP TO O.S SECONDS~1.70 F.P.S fact::.FPS: Full ot spo power seconds~'-9-&vmbols 6k: Change in reactiviey T.F: Total heat flux peald.ng or at h t 10~~~i~~~i~i&(&.=~::i I:.-:i i&~~~~&--~)&'i 0 2 4 6 8 10 12 14 16 TQK, SECONDS: HOT SPOT VS.TIHE=-"-.~~~4000: FUEL AVG.-I~~~L~e:::3Z&&":&&2000 1~-~~-~~~~~~~-.-::-.1008 0 4 6 S 10 12 14 16 18 TIME, SECONDS FIGURE S.4-1

    PULL POWER END OP LIFE ROD EJECTION, NO TRIP I~>~~:='UCLEAR POWER VS.TIME~leak 0.33 P m'3~23 T r~~'i.-: L~Sba III Sk: Change in Reactivity P: Total Heat Flux Peaking Factor T q at Hot Spot~.~4 5 TIME, SECONDS ting).~I I~~rI~4s r ,~~III I~I HOT SPOT TEMPSULTURE VS+TZME':.-.-,:-'Mel=--'-'-~~~PURL AVG I:~r~~~'"I~~~W M.:~..~'~..':'LAD OUT~T':.I:I~Ii~~IP'PEAK CLAD SURFACE TEMP.--:~2950'P AT 50 SEC.50X (HY VOLUME)OF'cCL i'.." MELTS.V.~:.-..~-=-'i::!=-'i;:, i-.--'2 4 6 S 10 12 14 16 TIME, SECONDS PIGURI'.4-2 0 P e Full Power End of Life F~3.23 T xa~+\8 7 6 4 3 pi 2 C~8p~0 2 3 4 5 6 7 8 9 l0 TIME, SECONDS~~TOM OF SkFEXY GZHZTS AND TRIP POINTS'~<ROD EJECTION'ACCIDENTS, HO TRIP-represents the locus of points at which trio would terminate the accident represeecs laces ar sefery lfrsirs FULL POWER END OP LIPS ROB EHKTION WH33RK TRIP CO 4l 5 CD~CC3 CO~~C~2~~I 1~l 0 0 10.e 0.33 TIME, SECOHDS Wte: 0.4X Qc'represents a practical Bait:ar fuIl pcwer ceses.~ROD EJECTION ACCIDEHTS'QXXH N)THXP,'IGURE 5.4~ I 0 LOSS OF STEAM LOAD 5,5.1 XNTRODUCTION AND SUHHARY Vp'<<,', loss of steam load may be caused by closing of the turbine stop valves, which norma21y follows a turbine trip signal;by closing of the turbine control valves following a rejection of electrical load;or by steam isolation following a Reactor protection System signal.The consequences <<of a loss of steam load are a rapidly increasing Steam System pressure and Reactor Coolant System temperature and pressure due to the loss of heat sink.Protection instrumentation is provided to immediately trip the reactor following a turbine trip signal.A.steam line isolation signal is normally accompanied by a safety infection signal and also results in a reactor trip.Following a re)ection of electrical load, a Steam Dump<<~"".%'ystem acts to prevent reactor trip by automatic steam dump to the con-, denser.(Up to 100X load rejection can be handled by some'planes-)Xf the load re)ection great1y exceeds the steam dump capacity, or if the Steam Dump System should fail to operate, a reactor trip may occur on high pressure.Redundant protective instrumentation and conservative design of pressure relief devices assures the safety of the plant for a large load rejection without recourse to Automatic Rod Control, Pressurizer Pressure Control, or Steam Dump Control Systems.5.5-1 In this report, the Protection System is examined to see if diverse px'o rotection exists for a complete loss of load without direct reactor trip.Diversity is found to exist to protect the Reactor Coolant System and reactor coxe.5.5.2 LOSS OF LOAD PROTECTION AND DESIGN CRITERIA The reactor is pxotected for loss of load by: a)Steam dump to'ondenser (actuated by the Contxol System)b)c)Pressurizer pressure relief (safety valves and powez~perated reLief valves)Steam System pressure relief (safety valves and power-operated relief.valves)') Direct reactor trip (on turbine trip)e)High pressurizer-pressure trip f)Overtemperatuze 4T trip g)High pressurizer level trip.Steam D to Condenser The Steam Dump System acts automatically upon sensing a loss of load greater than a preset amount.The steam dump valves are then either modulated or tripped open until the Reactor Coolant System temperatuxe reaches the new programmed load reference temperature. The reactor power is reduced by control rod, insertion during this time.Zn case of a turbine trip or reactor trip, the steam dump is actuated and con-trolled on a preset uo-load reference temperatuze. The Steam Dump Control System is described in Section 3.2.5.5-2 0 t Pressurizer Pressure Relief The pressurizer safety valves are sized to match the maxfmnnn volumetric surge rate associated with a complete loss of load without steam dump or a direct reactor trip.This is not dependent on pxessurizer pressure control.The pressurizer safety valves therefore completely protect the Reactor Coolant System against ovexpressure, independent of the high pressure reactor trip.The relief valves are sized to prevent actuation of the high pressure trip when the steam dump and rod drive systems work, and the required steam reLLef is within the capacity of the Steam Dump System.Steam S stem Pressure Relief The Steam System safety valves pass 100Z of ma~man calculated turbine steam flow, at the safety valve set pressure plus accumulation. This allows the plant to accept a 100Z load re]ection without reactor txip or steam dump without ovexpressurizing the Steam System..Xn addition, relief valves set to open at a lower pressure are also provided, and axe typically sized at about lOZ of the safety valve capacity.Direct Reactor Tri The most common cause of a loss of load is a turbine-generator trip.Zn the event of such a trip, the turbine stop valves close.A turbine 5.5-3 trip sensed bye 2/3 low auto-scop oil pressure or 2/2 stop valve closure results in a reactor trip if the reactor is at high power.The purpose o f these triPs is to mizdzMe the thermal transient snd steam dumP requirements for these relatively frequent plant transients. Hi h Pressurizer Pressure Tri There is a reactor trip on 2/3 high pressurizer pressure, generally set to 2400 psia, or slightly above the pressurizer power operated relief valve setting and below the pressurizer safety valve opening pressure.Overt erature dT The purpose of this trip is to protect the core against any combination of reactor coolant temperature, power or pressure which could cause I DNS.Trip logic is 2/4 for 2.and 4-loop plants snd 2/3 for 3-loop plants.Hi h Pressurizer Level Tri This trip acts to prevent water discharge from the pressurizer safety valves.Logic is 2/3.5.5W 5.5.3 EVALELKON OF PROTECTION SYSTEM FOR LOSS OF LOAD A complete loss of load without steam dump and without a direct reactor trip is evaluated to find if diverse protection exists to prevent a hazard to the integrity of the plant through overpressurization or'NB.The transient was investigated for a current, high power density\lant, and no credit was taken for power reduction due to automatic'../'.".t~control rod motion or moderator temperature coefficient. /'Initiation of Accident Figure 5.5.1 shows a fault tree for a loss of load without steam dump, with the reactor at high power and ao direct reactor trip.One way a 1088 of load can occur is by closing of the turbine stop valves following a turbine trip signal or by hydraulic fluid pressure failure{the valves are held open by hydraulic fluid)-However, one and.possibly two trips must then fail in order to prevent an immediate reactor trip.Another possible failure mode is a turbine runback caused by, the throttle valves closing.This could be initiated by a rod drop, an overpower or overtemperature 4T signal, by an actual or spurious loss of electrical load signal, or by a failure in the turbine controller and load limit system.A spurious rod drop signal would normally decrease the turbine load by a fixed small percentage of full load.The control 5.5-5 alve could close completely only if an improper circuit exists in the controller. Similarly, an overpower or overtemperature 4T signal coxmally causes a step load.decrease of SX every 30 seconds;and only in the case of a simultaneous failure ox improper circuit in the controller could there be insufficient time for the operator to take notice.Ef the turbine runback is caused by an overpower or overtemperature 4T protection System failure, the failure could only be in the safe direction; that is, the error or failure would be in the direction to cause a reactor trip.A third possible path for a loss of load is through steam line isolation. This may occur either through a loss of air supply to the isolation valves, or by a spurious or real isolation signa1 from the Reactor Protection System.As a result of the loss of steam flow.to the turbine by any hf the three paths outlined above, the Steam Dump System is activated. However, no 1 credit can be taken for this following steam line isolation, since, the dump valves are downstream of the isolation valves.For all three paths, the resulting decrease in first stage turbine impulse pressure causes automatic reactox'ower reduction by control rod insertion. Even if the reactor is in manual control, the moderator coefficient of reactivity is generally negative and would cause a power decrease as temperatures increase.5.5-6 0 I i)~~ 'C The fault tree shown on Figure 5.5.1 indicates that, in most cases, a fault could cause a complete loss of load with no steam dump or reactor it"~>>I'power decrease only if one ox more simultaneous failures of the Control or Protection System also xesuLted.However, the following analysis is based on a complete loss of steam load without steam dump, reactor contxol, or direct reactor trip.Anal sis and Discussion Figure 5.5.3 shows the results of a transient analysis for a complete loss of load without steam dump.The results'show that'he safety~~I I'I I I>>valves capacity of the Steam System is..sufficient to LixQt the pressure lrise to less than LUO psia, even without a reactor trip.The Reactor Coolant System T.transient is shown for a high pressurizer pressure avg or high pressurizer level reactor trip, as well as for no txip.I Actuation of the Steam System safety valves restores the reactor heat\s~and causes a decxease in the rate of rise of the reactor coolant average tempexature. Without a reactor trip, T would eventually come avg into equilibrium when the required heat dissipation at the suety valve ,~set pressure is reached.The Reactor CooLant System pressure transient is also depicted.in Figure 5.5.3.The effect of the pressurizer power operated relief valves is felt slightly above their set pressure of 2350 psia.Since the required 5.5-7 4 e relief for a&61 loss of load without steam dump far exceeds the relief valve capacity, the pressure continues to rise to the safety valve set pressure of 2500 psia.The opening of the pressurizer safety valves, and the restoration of the secondary sink by steam relief, limits the Reactor Coolant System pressure rise.The surge rate decreases as the rate of rise of T decreases, and eventually the pressure decreases to avg the relief valve opening pressure.The transient is also shown for the high pressurizer pressure and leve1 reactor trips.The power operated relief valves delay the reaching of the high pressure reactor trip setpoint by about 2 seconds.The lower graph in Figure 5.5.3 shows the aduinnxm (hot channel)DNB transient. For the first few seconds, the DNB ratio rises due to the increasing system pressure, while piping delays cause the core inlet temperature to remain constant.Two trips, the high pressure and overtemperature hT reactor trips, prevent the core design limf.ts from being exceeded.Rate compensation on T, which.is included in avg'he overtemperature dT trip, would actually cause the trip setpoint-to be reached much sooner than is depicted in the figure.The high pressurizer water level reactor trip is inadequate to prevent the core from exceeding the design limits.However, the minimum DNB ratio in the hot assembly for a high level trip is above 1.0 and would assure that core damage, if it occured at all, would be limited to a small fraction of the core.A conservative setpoint was assumed for the high level trip.5.5-8 0 A fault tree for the accident, leading to core damage, is shown in Pigure 5.5.2.5.

    5.4 CONCLUSION

    S This accident is not considered 1Qcely since in most of the incidents which could cause it, one or more simultaneous failures of control or protection instrumentation must also occur.In addition, at any time.other than early in.core Life, the large negative moderator coefficient would cause the accident to be self limiting and give much better results than depicted in this analysis.However, if the accident were to occur, diversity does exist in that three different levels of protection are avail,able. 5.5-9 ,I h SJSNfs<<ls<<s<<<<<<<<<<<<u~<<"<<<<<<<<.<<<<<<NSJSSR<<j~R<<g@N<<'JJ@ " g<<<<j ,,<<,lt, fIQJRS 5.5 2 Oj R Ts OR S D<<s NO ROD JIFION CFOR N MANUAL CONIIJOL<<<<4 fTKAM LIbE ISOIATION, NO TURRINE COÃIROL VALVES CLO.E, NO TURSINE STOP vvx.v"" AIR SUPPLI AUTO.S,D, AUTO.S.D, LOAD LIMIT ACIUAL OR SIUFIQJS LOSS Oj EJECT~LOAD SCOP VALVE R<<T<<TURBINE CONIROLIA3.SR EXCESSIVE RUNS'X IJJSS OF IIQiCENCV FIUID NJRIQJF ICOIA TION f IGNAI'<<ITN QJT REAClOR TRIP IMISOPER CRT AND hlJTOGIOP R.T<<CONDITIOJI FA I JJJRI REACIOR I%REC-TION SISIIJ'.IAJGIC FAULTs SBJRIQJS F<<OD DROP EIGJIAL REAL OR SIURIQJG OVIR POLJER OR OVER OR LOSS DP AUIOSIOP PIJJID NUCL<<INST<<SISTIIl ROD POSITION INDICATION i FAIIJJRE ANT SJRBINE TRIP SIGNAL R.T.RKACIOR TRIP K.C,-ST&QJJJP , S)1, SAINT INJECFICN I~SCFEJ Anf Slsaa IIos Isolalloa~ISJ<<al Is also~@castor tcIP sISJnal.Theccfcea> ooIF loSto clccoll falllls shool4 Lc coas14ctc4 ~NIGH TAV NIGH AT FIGURE 5.5-1 FAULT TREE IOR INN 0 j llRD ACCII<<ENI , 5'~a~'1 1 FAULT TREE FOR CORE DAMAGE LOSS OF STEAM LOAD CONDITION Probable Gross Core Damage AND High Pressurize Level R.T.Core Design Limits Exceeded R.T.-REACTOR TRIP S.D.-STEAM DUMP S.I.-SAFETY INJECTION Overtemperature AT R.T.i High Prdssure RiT Loss of Load, No SeD~or POUer Decrease Early in Core Life Loss of Load, No Direct R.T.or S.D., No Rod Insertion (See Figure 5.5-1)FIGURE 5.5-2 1200 1000 800 600 2600 2500 2400 2300 zzoo 6zo 600 580 560 1 8 1.6 1.4 5 1.2 1.0.8 0 LOSS OP LOAD ACCIDENT~~I l-~1-STEAM SYSTEM PRESSURE'-)~.':~te~~~I I~I~~~~I~/~l".~I." REACTOR COOLANT SYSTEM PRESSURE I:-:~I t~~I~~~~~~i~'O TRIP."'HIGH PRESSURE" REACTOR TRIP J'.'l"IGH LEVEL REACTOR TRIP~).'I l.'.!.(I I t'~I l'-i=(REACTOR COOLANT T VG I'~~).-.NO~~I~'t.TRIP (HIGH LEVEL-'EACTOR TRIP f..~~~~~I~)~.HIGH PRESSURE.-'REACTOR TRIP~~I HIGH PRESSURE".:-.EEACTOR TRIP~I~~~g I.L.-~~I I'VERHK'ERATURE .AT REACTOR TRIP i'IGH LEVEL'EA,CTOR TRIP-'~~~L.'UNB RATIO.NO L~4~~)20 30 40 50 10 SECONDS FIGURE 5.5-3 0 I, 5,6 ROD WITHDRAWAB DURING STARTUP Normal startup procedure is by control rod withdrawal under manual control.~function of the rod contxol system or operator error can cause a reactivity excuxsion with a resultant rapid increase in power.Rod withdrawal accidents ia the power range are evaluated in Section 5.1.For these accidents, the power increase is approximately linear for a linear increase in reactivity. For accidents starting from very, low power (staxtup x'ange), the neutron flux may increase by many decades before there is significant Doppler feedback.. The nuclear power response to a continuous reactivity insertion from the startup range is characterised by a very fast rise terminated by the reac-tivity feedback effect of the negative fuel temperature coefficient (Doppler effect).This self limitiag effect is of prime importance during a startup I accident since it.limits the power to a tolerable level prior to external protective action.After the initial power burst, the nuclear power is momentarily xeduced aad then if the accident is not terminated, the nucl'ear power increases again but at a much slower rate.Protection against startup accidents is provided by diverse types of neutron-monitoring instrumentatioa: source range, intermediate range, and power range channels.Ma)or differences in the ion chamber and cixcuit design exist between the intermediate and power range channels.The source xaage uses a neutron sensor of a different principle: proportional counter rather than ionization chamber.5-6-L ~'4 4 Should continuous control rod withdrawal be initiated and assuming the source and intermediate range alarms and indications are ignored, the transient will be terminated by any of the following automatic protective actions.a)Source range flux level trip-actuated when either of two independent. source range channels indicates a flux level above a preselected,~g~<<manually ad]ustable value..This trip function may be manually bypassed when either intermediate range flux channel indicates a flux level above the source range cutoff power level.It is automatically rein-stated when both intermediate range channels indicate a flux level belo~the source range cutoff power level.~<<b)Intermediate range rod stop-actuated when either of two independent <<intermediate range channels indicates a flux level above a preselected, manually ad)ustable value.This rod stop may be manually bypassed when two out of the four power range channels indicate a power level above approximately ten per cent power.It is automatically reinstated when three of the four power range channels are below this value.c)Intermediate range flux level trip-actuated when either of two independent intermediate range channels indicates a flux level above a preselected, manually ad]ustable value.This trip function is manually bypassed when two of the four power range channels are reading above approximately ten per cent power and is automatically reinstated when three of the four channels indicate a power level below this value.d)Power range flux level trip (low setting)-actuated when two out of the four power range channels indicate a power level above approxima y tel 25 per cent.This trip function may be manually bypassed when two of the 5.6>>2 II'0 four power range channels indicate a power level above approximately ten per cent power and is automatically xeinstated when three of the four channels indicate a power level below this value.e)Power range flux level trip (high setting)-actuated when two out of the four power range channels indicate a'power level above a preset setpoint.This trip function is always active.Since all protective actions in the above list are based on level set points, I rather than rate set points, protection is not dependent upon having a rapid rate of power increase.The standard startup accident analysis reported in Safety Analysis Reports takes credit fox only the power range protection. Howevex, the intermediate range hfgh flux reactor trip is always in service below lOX power, and would also serve to terminate the accident.Further,.any accident starting from a subcritical condition would be terminated by the high source range'I xeactor trip.Therefore, Protection System deversity exists for startup accidents. Figures 5.6-1 and 5.6-2 show the calculated transient response of nuclear flux and fuel temperatuxes for a startup accident with a high rate of xeactivity insex tion.5.6-3 0 ~I 10 10'~I I I~~Uncontrolled Rod Qithdrawal Prom a Subcritical Condition Praction of Nuclear Power a~+1 x 10 6k/F W 5 o a<lxlp 6k/P f Reactivity Insertion Rate~8 x 10 6k/sec k~1.0 0-1~t~I 10 8 W 0 g M 10 pl il li ko C o Oe 10 g~~~I~~I~10 8 0 W o o o 10-3 5 o Cl~u 10 10 0 10 20 25 10 30 Time, Seconds FlGVRE 5.6-1 4~<<((I-"~(4<<<<.(.<<<<4V,~~I(are J>~w<<(i'(<<<<M>>1000 900 Puel Clad Uncontrolled Rod MithdraMal Prom a Subcritical Condition Temperature 4 ag<<+1 x 10 5 6k/'P o=-1 x 10 6k/'P Reactivitg Insertion Rate f<<8 x 10 Lk/sec k<<l.0 70 65 800 700 Core Mater 14 o (4 l0 c e'0 oj 60 55 600 50 500 45 6 10 1.L 18 22 26 30'Time, Seconds FIGURE 5.6-2 5 7 CONTROL ROD DROP De-energixing a drive mechanism causes a full>>length control rod to fall into the core.(Part-length rods fail"as-is" when de-energized.) This causes an immediate decrease in coxe power, most noticeable in the region of the dropped rod.Xf the average coze power is returned to its original valve, most of the core would be at a higher power density because of the local depxession in the region of the dropped rod.During the initial design fox the current generation of Westinghouse PWR's, the increase in hot channel factors for a dropped zod was not known.Zt was therefore assumed that DNB might xesult if the core were allowed to return to full power following a zod drop.Protective circuits were design-ed accordingly and classified as part of the Protection System.The design requirement for this protective function was to insure that, follmrtng a dynamic rod drop, the xeactor would not zeturn to a power leve3high enough I to cause a DNB ratio less than 1.30., Mechanisms which would tend to restore r initial core power are.noxmal automatic control and plant cooldown with a negative moderator coefficient. However, recent physics analysis for malpositioned control rods has shown that, in every case for an insezted rod, full power operation would not cause a DNB ratio less than 1.30.Because the local power decrease causes a general power increase throughout the rest of the core, the increase in hot channel factors is Usted to approximately 15'x less, depending on core size.With x'espect to DNB, this is equivalent to 15X overpower. Core DNB'esign 5.7-1 ~~~E margins of this magnitude must exist at full power to allow for operational transients and instrumentation errors.In additon, for plants presently near completion, it has been found that inserted rod hot channel.factors do not even exceed the design hot channel factors.Since the consequences of a dynamic rod drop are tolerable, the following ff discussion of rod drop protection is somewhat academic.Rod drop protection diversity has been provided, both in the means of detection and in the means of actuating protection. Redundancy. was more readily obtained by diverse instrumentation than by independent, but identical, channels.A rod drop signal is generated by either of the following: a)A=rapid decrease in indicated nuclear flux from any one of the four power range nuclear instrument channels b)Rod bottom indication from any one of the rod position indicators when the associated rod bank is not on the bottom.One-out-of-four logic for the nuclear channels is used'because it was not known whether more than one channel would respond to the dropped rod.Therefore, redundancy is not claimed.Protective action is directed toward inhibiting those mechanisms which would otherwise cause the reactor to return to its initial power level, i..e., automatic rod withdrawal and load demand with a negative moderator temperature coefficient. Again, since the magnitude of the hot channel factor increase was not known, it was assumed that both mechanisms would have to be inhibited. 5.7-2 Redundant rod stop contacts are provided to block normal automatic control rod withdrawal. Manual rod withdrawal is not blocked since it is necessary to withdraw the dropped rod.Turbine load reduction is accomplished through redundant channels.Most plants are supplied with electro-hydrauLLc (E-H)control systems for the turbine.The turbine runback is activated by the following~ either of which reduces or restricts turbine control valve position and steam load.a)Reduction of the load refezence setpoint of the turbine,E-H., controller by a preset amount.This is accomplished by zeducing the set point at constant rate (200X/min.) for a preset time with a.time delay relay.b)Reduction of the turbine load.limit to a preset value.The load limit (a clamp on the voltage signal controlling the turbine control valve position)is reduced until turbine thermal load as I)sensed by either of two turbine impulse pressure'channels is below a preset value.Following plant startup tests to verify that the DNB ratio is greater than 1.30 at full power with a dropped rod, it is intended to adjust the turbine runback for operational requirements. That is, the automatic load reduction would be large enough such that, with reasonable operator action, an orderly manual plant shutdown can be accomplished, rather than a reactor trip on low pressurizer pressure.Fi.gures 5.7-1 and 5.7-2 show the transient response of nuclear plant variables to a rod drop with turbine runback.5.7-3

    l l l r 1.U.9.8.7~t~~-I.I~~I.',.f=~C I~:I~-I.~~~t 4~~~~~~:H'Response to a Dropped RCCA of.North-2.3 x,10 6k With a Power Cutback of 25 Percent of Nominal~-3.5 x 10 bk/7'-'~>>1.65 x 10 6k/Z'.~~I I~~i: I~..l.,~~~~~t~t 1.0 0 0C K he Q E 8.9.8'~~7~t>~t l~t tt I~~~I'~':I-"'I~l~'t{~~~I~~tt I~I~~I I 2400 2300~pk~~~~~~~~~I t~~-I~t t~~~'{::.-~I I~~I~I t~~~t 2200 2100~~~"-I~I 40 80 120 160 200 0 4~ ~'I I I~~I~~0~~~~~~~~~~~0t~0'I.t t0~~~I I 0~I 0~~--}t~*L0~>>0t'If 0 580 578 576 I L00~IQ 0 Q~~~I 0~r~0~~0<<I~00 0~0~I~~I t~LL~00 L 00 00~>>~>I~I 0~~0 I~~~l I~~-I'='~I~0:..00 J~565 I Q 0~0 I~Response to a Dropped RCCA of Woph-203 x 10 6k with a Power Cutback of 25 Percent of Nominal~~560 4~~, 0 0 4a 0~t 0't~'fQ M C4 o 555 550 U~M~I J0=I~I~~~I~~~~~~O H 1.0~~0~~M 00 g ,9~>>~~0 I~~0 ,8 L~~00'~0~~~~~~I~~.7 40 80 120 160 200 TDK, SECONDS

    5~8 ENGINEERED SAFEGUARDS ACTUATION Actuation of auxiliary feedwater is discussed in Section 5.2.Engineered safeguards for containment pressure protection are discussed in Section 5.9.Actuation of Emergency Core Cooling for loss of coolant protection is discussed in this section.For loss of coolant protection, a safety in]ection signal is generated by either of two diverse sets of automatic signals: a)Coincident low pzessure and water leve1 in the pressurizer; b)High containment pzessure.Both sets of signals are redundant and meet all protection System design criteria.The signals derived from the pressurixer indicate that reactor coolant is being lost well before the core is uncovered. Reactor coolant blowdown also increases containment pressure.Set points'for high can-tainment pressure are typically about 10X of contaiaamt design pressure.This set point is reached well before the core uncovers.Figure 5.8-1 shows the results of a calculation for a representative plant for the complete range of break sixes.Zt shows that either the pressurixer or the containment signal initiate safety in)ection l-l/2 minutes or more before the core would be otherwise uncovered.(For large breaks>passive accumulator system supplies water and delays the time.at which active core cooling is required.) This analysis included the effects of containment heat sinks and fan coolers in delaying the time at which the containment high pressure signal is reached.5.8>>1 SAFETY INJECTION ACTUATION SIG:NL VS BREAK AREA 1000 4 o~I+I'~'T~~~i I}.o~l<<~,~~I I I I l~~I~~<<~~}le r o, on e*o I r I~~~~~<<~t~~>>v~t tt~I~"tt rl tt<<~~~I}'-: Range of Protection of I:.: Passive Accumulator System-(;I~I ae I 4 V 100~~o oo 1}:<<I I~I~~I P tl~~I'~I'<<~~>>:ii}'."~I It~~I~I I~~~}I~~~~~I~~~v 0~~r,~!Ia.~o~~~tt~\~v}'"--t t I~~~~\~~t<<to~o~to~~~I'I~~o~~~~~<<~~~~I<<.)~o I I O I hC 10 o~~t~<<'o o~I~~I~Itz~~<<'I''I~'I.....~Time to Reach Lou Pres-I:-surizer Pressure and Level Signal 7>>~~~~\~~~~~~>>~~~~I~I~~~~<<o~<<e~o<<v pt t I:TI~I~~*~I~I~I~~~~I~~I" I~}~~~~~~~i-.', I~PI~'~I"I<<I~I I~)}=.1-I:i lne ce Uncavel Case Ndd Plane LNe Sadecv ln eccdcn)j~o~~~\f<<~~~~~I~~I t I~lel~~~'I~~jjjr"~~i Time to Reach Pigh Containment Pressure Signal'<<l l~~~v I<<j~0.01'ii l\~4 0.1~6" 10" DAUEa:.BREAK SIZE (Fi)FIGUPE 5.8-1 ~V 5 9 CONTAINMENT PRESSURE PROTECTION Typical westinghouse dry concaiament plants are equipped with faa cooler unics aad spray systems.These are provided to reduce the contaiamenc pressure eo to esseatially atmospheric following a loss of coolant accident or a steam line break accident inside the containmeac. The containment is designed to withstand the eoeal blowdown of the Reactor Coolant Syscem or a steam generator wieh no dependence on ehe aceive safe-guards.The active safeguards are, however, aueomatically actuated following che accident.The pr9nary containment safeguards are the fan cooler units and their cooling water supply which aze actuated by the safety injection signal which is generated by: a)Coincident low pressurizer pzessure and waeer level in the pressurizer b)Ri.gh containment pressure (approximately lOX of design pressure). The backup contaiameac safeguard, ch'e coneaiamene Spray 9ystem, is accuaeed by a high containmenc pzessure signal when the concainmenc pressure reaches appxoximacely 50X of che design value.Automatic spray actuation uses six concainmenc pressuze channels, in 2/3 2/3 logic.The Spxay System can also be actuated manually.Only 2 ouc of 4 fan cooliag units for two or three loop plants and 3 ouc of S cooling units for four loop plaacs are necessary eo limit the containmene pressuxe below design even considering ehac the Emergency Core Cooling Syseem is.unable co suppxess boiling in ehe core, and ehe core decay heac energy continues co be added to ehe containmenc in the form of steam.5.9-1

    The operation of only one of the spray pumps is required in order for the Spray System to supplement the heat removal capabiU.ty of the fan cooling units to provide a margin for effects from metalmater or other chemical reactions that could occur as a consequence of failure of Emergency Core Cooling Systems.Since either fans or sprays are adequate, and diverse signals are used to actuate the fans,.the Protection System is diverse for actuation of con-tainment pressure protection. 5.9-2 5.3.0 EXCESSIVE LOAD~rgb~a+&vf" f'>Excessive load is one means which could cause excessive core power generation. As distinct from the ovezpower~vertemperature accident discussed in Section 5.3.(Rod Withdrawal at Power), reactor coolant temperature, pressuze, and pressurizer water level would not increase.Reactor power follows turbine load, both by contxol design intent and the inherently negative moderator coefficient. An increase in load above design is therefoxe of potential concern.Diverse overpower protection is provided by Reactor Protection System., These aze the ovezpower delta-T and the nuclear overpower reactor txips-Since the accident is initiated from the secondary plant, the reactor I coolant loop temperatures respond before the core coolant temperature. !I Piping lags applicable to the rod withdrawal accident are therefore not applicable to an excessive load accident, and either the delta-T or-the nuclear overpower trip protects the core for any rate or magnitude load increase.5.10-1 p P 'C 5.11 EXCESSXVE FEEDWATER FLOW An excessive feedwater flow accident is primarily of concern to the turbine (high water level Xn the steam generator leads to excessive moisture carryover and potentia1 turbine damage).'ith respect to nuclear protection, however, excessive feedwater flow (or feedwater temperature decrease)is seen as an excessive thermal load, and the discussion in Section 5.10 is applicable.

    5 12 STATION BLACKOUT A station blackout, or loss of aU.a-c power to the station auxiliaries, results from loss of incoming station a~power coincident with a plant trip.Numerous reactor trip signals would be generated, such as turbine trip, low coolant flow, low gpedwater flow, etc.This is not important however, since the loss of a-c power deenezgizes the zod control power'upply, and the control rods fall into the core, even if no reactor trip signal is generated. Natural circulation of reactor coolant transfers reactor decay heat from the coze to the steam generators. Since steam generator steam pressure is automatically controlled by the power-operated steam line relief valves (with backup from the steam line safety valves, if necessazy), the only requirement for maintaining hot shutdown conditions is to Apply feedwater to the steam generatozs. The auxiLiary feedwater system is discussed in Section 5.2, Loss of Feedwater. As noted in that section, the loss of a~power starts all a~iazy pumps-A diverse automatic actuation signal-steam generator low water level-is also provided.Further, the energy sources for the auxiliary feedwater pumps are.themselves diverse (steam-driven pumps and motor-driven pumps energized from the diesel-generator), such that faQ.uze to actuate an energy source does not prevent auxiliary feedwater. 5.12-1

    APPENDIX CONTROL AND PROTECTION FUNCTIONS reactor con'tro 1 and protection functions perf ormed f rom each process~eter in the present Westinghouse design are Mmlated below.Pro-e~tion functions are listed first, and control functions listed last.u~ny functions'.g-, indication, alarms and interlocks, are not clearly either control or protection. ~These are classified as"supervisory" unc talons~In the left margin, all functions are listed as P, S or C, showing pro-tection, supervisory or control;-i%JCLEAR INSTRUMENTATION 1,.3.Power Range 1.2 Intermediate Range 1.3 Source Range'W~REACTOR COOLANT SYSTEM PARAMETERS Z.l Reactor Coolanr, Temperature (4T, T)avg 2-2 Pressurizer Pressure 2.3 Pressurizer Water Level 2.4 Reactor Coolant Flow 3~STEAM GENERATOR PARA%.'TERS 3.l Steam Generator Water Level 3.2 Feedwater Flow 3.3 Steam Plow 3 4 Steam Line Pressure 3 S Steam Header Pressure V PARAMETERS Turbine First Stage Steam Pressure Oo m Turbine Auto Stop Oil Pressure Turbine Stop Valve Position~ASTROL ROD POSITION 5.1 Bank Position).Z Individual Rod Position~.CONTAINMENT PRESSURE gZCZRICAL PARAMZERS 7'.1 Reactor Coolant Pump Bus 7.2 Reactor Coolant Pump Breaker Position 7.3 F edwater Pump Power A-2

    gJCLEAR ZNSTRUMENTATION SYSTBt power Range-(linear indication in power range of operation). P 1.Overpower reactor trip (high range)-rapid detection of fast overpower excursions during power operation. P 2.Overpower reactor trip (low range)-protection during low power plant operation. p 3.Top-to-bottom flux tilt bias of 4T reactor trip set points-reduce DNB protection limits to offset effects of hot channel factors.(Both high dT reactor trips), see 2.1, 1&3 P 4.Reactor trip permissives a.Permit single loop loss of flow trip at high power.b.Permit reactor trip on turbine trip at high power.c.Permit"at-power" trips during power operation. d.Defeat, manual block of low range and&termediate range overpower trips at low power.e.Lock out source range high voltage supply during power operation. S 5.Rod drop detection-rod stop and turbine runback to maintain DNB margins.6-Overpower rod stop.-stop a power excursion caused by rod withdrawal. 7.Overpower alarm (for equipment purposes, this function is combined with the overpower rod stop).8.Control room indication and recording (including top-to bottom difference). Channel deviation alarm-detect channel failure, detect flux tilts.10.Top-to<<bottom flux tilt bias of dT rod stop and turbine runback set points (see 2-1, 264).A 3

    Automatic control rod motion-provide stable reactor control and rapid response.gntermediate Ran e-(Logarithmic scale for power range and upper startup range)p'.High level reactor trip-prevent power increase into power range unless power range channels are indicating. p 2.Defeat manual block of source range high level trip-low intermediate range indication rearms source range trip.S 3.High leve1 rod stop-prevents excessive withdrawal of control rods during low power operation. S 4.Control room indicating and recording. S 5.Startup rate indication. P.l.High leveL reactor trip-prevent startup accident from source range;prevent power increase into intermediate range unless intermediate range channels are indicating. S 2.High count rate alarms-warn of approach to cripicality. S'.Control room indication and audible count.range.S 4..Startup rate indication. A-4 ~N c.s gP't"K5 <<<CTOR COOLANT SYSTEM PARAMETER or Coolant Tem eraeure (4T-T)avg Overeemperature high 4T reactor trip-prevent core DNB (set point calculated from T , pressure, and nuclear avg'lux axial tilt).2.Overtemperacure high 4T rod stop and turbine cueback-maintain operating margin eo DNB (set point is a fixed margin below reactor trip set point).3.Overpower high 4T reactor ezip>>prevent high power density (see point calculaeed from nuclear flux tile)i 4.Overpower high 4T rod scop and turbine runback-maintain operating power density (see point is a fixed margin below reactor trip set point).S 5.Channel deviation alarms-deeect channel failures, detect abnormal process candieions. S 6.Control room indication and recording. S 7.Control rod insertion limit alarm-maintain reactiviey shutdown margin;maintain low ejected rod worth;maintain , uniform core burnup.f r.8.Low T alarm (interlocked with high scesm flow for steam avg line isolation) -steam break protection. In addition to the above functions for 4T and T, T is also avg'vg used 0 9.High T alarm.avg 10.T channel deviation rod scop (of automatic motion)-avg prevent spurious rod withdrawal or insertion. 11.T deviation alarm-deviacion fram programmed setpoinc.avg

    Automatic control rod motion-control core powex'o main>>tain programmed tempex'ature. 13~Steam dump control (condenser steam dump)-remove excess energy from reactor coolant.14.Feedwater valve control-control addition to subcooled water to steam generators following a plant trip.15.Pressurizer level programming -determine level setpoint to minimize charging and letdown changes during load changes.2.2 Pressurizer Pressure p 1.High pressure reactor trip-maintain pressure in AT protection range;provide overpressure backup to safety valves.P 2.Low pressure reactor trip-maintain pressure in 4T protection range.P 3.Low pressure safeguax'ds actuation-actuate loss of coolant protection. P 4.High pressuxe defeat of safeguards actuation manual block-I.automatically renave manual block as operating pressure is approached. P 5-Compensate overtemperature AT reactor trip setpoint-core DNB pzotection. 6.Compensate qvertemperature T rod stop and.turbine runback setpoint-maintain operating margin to DNB.Control room indication and recording. 8 High-low pressure alarms.Low pressure relief valve interlock-close relief valves on 10.low pressure to avoid accidental loss of coolant./Pxessure control (on-off heaters, vaziable heatexs, spray, and x'elief valve actuation) -maintain normal operating pressure.A-6 F 11.Compensation signal for automatic control rod motion-improve reactor control response.2.3 Pressurizer Water Level-(This variable measures reactor coolant fluid inventory and mean temperature). P 1.High level reactor trip-prevent water discharge (an relief piping damage)through safety valves following rapid insurge.P 2.Low level safegnards actuation-indication of loss of reactor coolant.S 3.Control room indication and recording. S 4.High-low level alarms.S 5.Low level heater cutoff-prevent energizing heaters when uncovered (equipment protection). S 6.Low level letdown isolation-prevent loss of coolant by excessive letdown.C 8.High-low level deviation alarm-deviation from level set-point.Charging pump speed control-maintain progranmN.d water level.C 9.High level deviation heater a'ctuation -heat subcooled water insurge.2.4 Reactor Coolant F P 1.Low flow reactor trip-prevent core DNB.S 2.Control room indication-A-7 P 3 ST~GENERATOR PRtAK'.TERS Steam Generator Water Level-(This variable is a measure of water inventory in steam generators). p l.Low-low water level reactor trip and auxiliary feedwater pump start-protect steam generators; preserve normal heat sink for removal of early decay heat.p 2.Low level reactor trip (coincident with low feedwater flow)-provide rapid protection against a complete loss of f eedwater flow.S 3.High level feedwater control valve override-close feed-water valve to prevent excessive moisture carryover and turbine damage.S 4.High-low level.alarms.S 5.Control room indication and recording. S 6.Level deviation alarm-deviation from programmed level.C 7.Feedwater valve control-maintain desired steam generator level.l 3.2 Feedwater Flow P 1.Low feedwater flow reactor trip (coincident with low steam generator water level)-provide rapid protection against complete loss of feedwater flow.S 2.Control room indication and recording. C 3.Feedwater valve control>>provide stable control of steam generator level.3.3~Se~F1 ow P.1.Set point for low feedwater flow reactor trip (see 3.2.1 above).P 2.High steam flow steam line isolation-steam break protection. 't V 4 S 3~C 4 Control room indication and recording. Feedwater valve control-provide rapid res'ponse gf cgntzot for steam generator level.3.4 Steam Line Pressure>~, W/!-P 1.Low pressure (or tuic differential pressure)safe~d actuation-steam break protection P,C 2.Compensation of steam flow channels-provide accurate signal of steam flow.S 3~S 4.C.5.Low steam pressure alarm.Control room indication and recording. Control of steam line relief valves-minimize actuation g f safety valves.3.5 Steam Header Pressure C 1.Contzol steam dump to condenser. S 2.Control zoom indication ,F TUgBXNE PARAMETERS Turbine First Sta e Steam Pressure-(This variable is proportional to turbine steam load).p l.Reactor trip permissives -pexmits"at-power" reactor trips above minimum turbine load.p 2.Steam line isolation-determines set point for high steam flow for steam break protection. S 3.Control room indication. S 4.Low power block of automatic control rod withdrawal-prevents unstable reactor control.S 5.Steam dump interlock-prevents operation of steam dump to condenser unless a rapid loss of load has occurred.C 6.T program-determines set point for T in control avg avg rod and steam bypass control systems.C 7.Steam generator level program-determine set point for level in feedwater control system.4.2 Turbine Auto-Sto Oil Pressure-(Presence or absence of oil pressure indicates'trip or non-trip condition of turbine).1.Reactor trip-prevent temperature-pressure excursion in reactor coolant from loss of steam load.C 2.Steam bypass control-selects mode of contxol.3.Feedwater control-selects mode of control, steam generator water level or T avg 4~3 Turbine Sto Valve Position-used as backup to autostop oil pressure fox reactor trip signal. CO~OL ROD POSITION Bank Position-(SteP counters)Bank insertion limit alarm (set point determined from and 4T)-maintain reactivity shutdown margins;avg maintain acceptable core power distribution. S 2, Bank withdrawal limf.t alarm-warn operator that control rods are nearing the end of their useful travel.S 3, Control zoom indication and recording 5.Z Individual Rod Position (LVDT)S l.Rod position'deviation alarm-warn of possible rod malpositioning. S Z.Rod bottom rod drop detection-rod stop and turbine runback to maintain DNB margins.S 3.Control zoom indication and recording= CPNTAZgKNT PRESSURE p l.High containment pressure safeguards actuation and reactor trip-protection against small steam breaks, backup protection for loss of coolant accidents and large steam breaks.-P 2.High containment pressure steam line isolation p 3.High containment pressure spray actuation. S 4.Control room indication. A>>12 ELECTRICAL SYSTEM VARIABLES Resistor Coolant Pump Bus P l.Underyoltage reactor trip-protection against multi-loop loss of flow.p 2i Underfrequency reactor trip and RCP breaker opening-prevent rapid system frequency opening-prevent rapid system.fre-quency decrease from braking RCP.7.2 Reactor Coolant Pump Breaker Position (contacts) P 1.Reactor trip on breaker opening-backup.to low flow protection for loss of flow.7.3 Feedwater Power P l.Auxiliary feedwater system actuation (feedwater pump breaker position and/or bus voltage)-backup feedwater protection for loss of feedwater. A-l3 ATTACHMENT 8 TO AEP:NRC'1184H2 RESPONSE TO ITEM 8 DEFENSE-IN-DEPTH EVALUATION PERFORMED FOR THE REACTOR PROTECTION AND CONTROL PROCESS INSTRUMENTATION REPLACEMENT PROJECT}}