Showing posts with label Defense in Depth. Show all posts
Showing posts with label Defense in Depth. Show all posts

Saturday, October 18, 2008

A Primer on Nuclear Safety: 2.6 Defense in Depth

A Primer on Nuclear Safety:
2.6 Defense in Depth
Molten Salt Reactors, Moir-Teller Defenses


Introduction
The term Molten Salt Reactor if generic. All reactors that use liquid salts as both coolant and fuel carrier are Molten Salt Reactors. Reactors that use Liquid Fluoride salts, and operate on a thorium rather than a uranium fuel cycle are Liquid Fluoride Thorium Reactors. Most discussions about Molten Salt Reactor safety are primarily directed to LFTR safety, but many of the safety features of the the LFTR will also be present in other MSRs.

Many of the safety features of the LWR are not required for the MSR. For example the massive steel pressure vessel can be dispensed with since MSRs operate under atmospheric pressure. There is always a risk of steam explosion with the LWR but of course no risk with the MSR. If the pressure vessel is removed from our reactor design, we loose one of the physical barriers present in the LWR defense in depth system. A way should be found to compensate for that loss.

The rigid, hidebound, intellectually stunted, stubbornly prejudiced, and inflexible bureaucracy of the NRC simply sees the absence of pressure vessels as a safety issue. The NRC leadership is too narrow-minded to look at the the possibility that the MSR and the PBR require a different intellectual approach to reactor safety.

A second feature of MSRs, one that it does not share with the PBR is the potential to remove radioactive isotopes from the carrier salts. These would include fission products, transuranium elements, and tritium that is produced by neutron radiation of lithium in the carrier salt. This opens a route to an alternative containment system, one which removes, processes, seperates and concentrates and then diverts to useful purposes. This approach, incidentally, eliminates the problem of nuclear waste, represents both a safety feature, and a potential means of producing valuable byproducts during the nuclear process.

Thus the ability to process fuel while the reactors is operating constitutes a type of defense that will not entirely preventing the release of radioactive materials during a worst case MSR accident, certainly would partially mitigate that release.

In order to understand the containment issue we have to understand what problems lead to the necessity of defenses in depth. In the case of light water reactors it is the vulnerability of the water based coolant systems to disruption. We have seen from the ESBWR design that it is possible to build in powerful protections against coolant failure. For LWRs coolant failure is a hazard because it leads to core meltdown. Since the core of the MSR is already molten, from the viewpoint of the NRC the MSR violates profoundly important safety rules. We have seen that much of the LWR's defense in depth system is devoted to to prevention of core melt down, a molten core would represent a partial failure of the reactor defense system for those who view the ESBWR type Light Water Reactor as the non plus ultra of nuclear safety.

Not only has the core of the MSR melted down by design, but it lacks the containment defense of a pressure vessel. There is no guarantee that the MSR will never leak. I for one am a pessimist about reactor leaks. Anything fluid is want to leak, and will leak sooner or later. Advocates of sodium cooled fast breeders should always remember that. Even with continuous fuel processing the core fluid of a MSR is very hot and radioactive. It is just plain nasty wicked stuff. Thus MSR defenses in depth must assume core excursions of molten reactor fuel and fission products.

Not only that, but a standard safety feature of the MSR is the ability to dump core fluids into tanks, in the event of a failure of the cooling system after shutdown. This are far from the only controlled fuel core excursion with the MSR design. MSR fuel is forced out of the core as it heats, because liquid salt expands with greater heat. Core salt is channeled out of the core in order to transfer heat from the the reactor to the generating system or in order to provide shutdown or emergency core cooling. Core salts are also withdrawn from the core in order to process them. Each controlled core excursion represents a breach of containment, and therefore a a serious safety issue.

It must be obvious then that defense in depth for a MSR must operate in a quite different fashion than for a LWR or a PBR.

Reactor defenses are the most reliable if they depend on the automatic operation of laws of nature, rather than human intervention. Thus if a reactor defenses depend on an ironclad natural law than cannot be violated, there is no need for redundancy or further defenses. We do not tie iron bars down to keep them from floating away. Defense in depth in necessitated with undesirable events a unlikely but not impossible. Defense in depth thus is about defense against the unlikely. The purpose of defense in depth is to make the unlikely even more unlikely, if not impossible. More defense in depths in depth are not needed if undesirable consequences cease to be matters of practical concern, or when they stop being theoretically impossible.

MSR Defense in Depth: The Moir-Teller View

The levels of MSR defenses in this view are:

- the negative coefficient of reactivity - increased temperature slows down and eventually stops the nuclear reaction

- the low fuel burn up margin and fast burnup rate - failure to add new fuel slows and then stops the chain reaction process

- the continuous removal of radioactive gasses

- The addition primary core containment structure, piping, drain tanks and other fuel holding and processing structures

- the reactor system chamber

- An outer containment vessel

- An underground location requiring escaping radioactive materials to counteract the forces of gravity before any obove surface excursion.

Other potential barriers exist. In two fluid MSRs, the blanket containment structure constitutes another safety barrier. Core salts breaching core containment must mix with blankert salts and then breach the blanket.

All out of core controlled excursion structures can be protected by secondary barriers. Thus pips supplied with sleeves designed to drain any escaping salts directly into a holding tank if the primary pipe ruptures. Holding tanks can be double walled. Fuel processing equipment can be encased in an air tight structure. Thus the primary barriers can in every case be doubled.

The fluoride salt mixture also constitutes a significant barrier. Some radioactive material are chemically bonded to the salt. Other materials, including nobel gases and metals are disolved in the salt liquid but can escape during a salt excursion. Thus the processing of fuel should always involve the removal of radioactive gases as part of the first line of MSR defenses. High priority should also be given to the removal of nobel metals, whose presence inside the reactor is likely to cause problems. Thus to the extent possible, radioactive materials likely to escape from the fuel mixture during an uncontrolled out of reactor excursion, out to be removed before the excursion occurs. Thus under the best circumstances if an out of primary and secondary containment breach occurs, fuel either drains into catch tanks, or it freezes. In either case the further excursions of radioisotopes is contained. Of course, there will be a messy clean up problem with frozen fuel.

Core containment breaches with conventional reactors carries with them concerns about the release of radioactive gases. In the case of the MSR, that concern, while not disappearing, diminishes. Offsetting the decrease of radioactive gas release on occasions of uncontrolled core excursion is the increased likelihood of core excursions.

Since the MSR does not have a containment vessel, from the viewpoint of the NRC is has as serious safety defect. But is it in fact defective from the view point of human safety? First, only a limited a mouth of radioactive gas is going to escape all containment as the direct result of a core breach. Much of the escaping gas is biologically inactive, and will not bond chemically with living tissue. The Three Mile Island accident demonstrated that the escape of nobel gases from a nuclear accident poses little danger to the public. The other potentially troubling gas to escape would be tritium. 

Tritium should, like nobel gases be captured during reactor operations If left in the reactor core it will eventually diffuse out of MSR anyway, thus tritium containment is almost entirely dependent on its ongoing capture.  However, although tritium is biologically active, it is quickly diluted by the atmosphere. Research in the area surrounding the Savannah River Reactors, that saw repeated and massive tritium releases during their operation, has not indicated the rise of tritium exposure health complaints. CANDU reactors also produce and release relatively large amounts of tritium. There is no evidence of tritium related health complaints in connection with CANDU reactor operation. Indeed,
The mass of tritium (from CANDU reactors) added to the lake each year by Ontario Hydro’s PNGS and DNGSreactors is about 8% of the inventory of tritium currently in (Lake Erie)
Tritium from CANDU reactors appears to be uniformly diluted in the Great Lakes.  Although the data to has not established the presence of tritium related health problems, and Lord knows that Greenpeace would look for evidence, quite obviously more research is needed.  It should also be kept in mine that no effort to capture tritium is made in CANDU reactors, while tritium capture is expected to be routine in MSRs like the LFTR.   No credible evidence thus exists that a tritium release in  MSR accident would pose a threat to public health.  The most likely outcome of a tritium release in a MSR accident is that the tritium would quickly be diluted to background levels in the atmosphere.    

Finally it should be noted that we are not talking about an enormous amount of Tritium here. Five large Savannah River reactors produced tritium for the United States Government during the cold war.  There combined tritium output from 1954 to 1998 was something like 25 kgs.  A tritium release from a MSR accident would be many orders of magnitude smaller.   Population research concerning adverse public health consequences of Savannah River tritium manufacture has so far been negative.

It would appear then that the release of radioactive gases from a MSR core breach poses no significant public health hazard, and is an acceptable risk.

Frozen fluoride salts from resulting from containment failures ought to be cleaned up quickly, and salts that flow to emergency dump tanks ought to be recovered, processed and returned to reactor use.  

Normally a MSR would seldom be shut down.  In the event of a planned prolonged shutdown the core would be drained, core salts processed, and then stored in heated temperature controlled tanks until the reactor is ready to resume operations.  In the event of emergency 
shutdown the cooling of core salts should be maintained through the regular cooling system, or in its absence through backup cooling systems.  At least one passive cooling system would be required for core salts.  

A complete MSR shutdown is accomplished by a core dump into holding tanks.  The core holding tanks, which may also serve as leak drain tanks would require a passive cooling system. 

The drain and holding tanks system would thus form a level of reactor containment.    
In the Moir-Teller safety system, the reactor system with its holding/drain tank system, would be housed in an underground structure.  The inner housing structure would serve as a containment barrier.  A further containment barrier would be provided by an outer containment bubble that surrounds the outer containment structure.  
In addition the outer containment barrier could be made air tight. There are both advantages and disadvantages of doing this, and an air tight barrier would not prevent the escape of tritium into the soil if the reactor were located underground. This might not be undesirable if as a consequence the tritium is fixed in place for a few hundred years. An air tight chamber would contain other radioactive gases.


A final containment barrier, in the Moir-Teller program would be the laws of gravity.  Gravity would prevent the flow of solid fission products to the surface.  


The only possible way fission products could escape the forces of gravity would be through fission product decay heating of reactor salts in the reactor core or holding tanks. Sufficient heat from radioactive decay of fission products would cause MSR core salts to boil. It is not clear if the hot salt vapors could escape containment or if all containment were breached, if vaporized salts would remain in air long enough to escape the confines of the immediate reactor site. Core salt vapors would not escape an air tight outer containment barrier. The function of a passive core and holding tank emergency cooling would be to prevent core salt boiling.

Would a underground MSR be vulnerable from terrorist attacks. Granted typical reactor security, the answer is no. First vehicular security barriers would prevent truck bombs from approaching the above surface location of the reactor. Secondly, attacking aircraft would have no visible target. Even if terrorists controlling a large aircraft crashed it directly above the reactor, the impact crater would not penetrate deeply enough to effect the reactor. Finally, human access to the reactor could be through easily defended corridors, with a bank vault type entry into the reactor's protective chambers. Other, very sophisticated security measure would be available to defeat attempted terrorist attacks. In short the Moir-Teller underground siting approach coupled with modern and appropriate security measures would make an underground sited MSR a very heard target for terrorist attacks. Terrorist attacks through truck bombs and aircraft attacks would stand on chance
of inflicting significant damage on an underground reactor, while security measures would defeat any threat from terrorist attempting to penetrate the physical structure of the reactor on foot.

My conclusion then is that the Moir-Teller scheme of defense in depth for MSRs would create a reactor that would probabilisticly safe for practical purposes. Even in the face of core breach, an underground MSR would not present an even slight danger to public safety. It would appear that the Moir-Teller system actually contains redundancies which are not required from the viewpoint of public safety, and further research my actually lead to dispensing with them. The Moir-Teller system coupled with modern security systems, would present a very hard and indeed invisible target, that would defeat terrorist threats. Thus implementation of the Moir-Teller MSR safety system would be practically safe and would never become so unsafe as to become a danger to public well being.

Wednesday, October 15, 2008

A Primer on Nuclear Safety: 2.4 Defense in Depth

A Primer on Nuclear Safety:
2.4 Defense in Depth
A Brief Note on ESBWR Safety

How Safe is the ESBWR? Given a probabalistic approach to nuclear safety, we first note that the ESBWR designers GE has estimated that a likelihood of core meltdown every 29 million years. But a core meltdown is far from a release of a large amount of radiation from the reactor into the environment. Thus we must look at the likelihood of a failure of not only the presser vessel, but of the core catcher, a system designed to trap and contain molten material from the core and to prevent its movement out side the reactor containment system. The core catcher is a passive safety system that uses the force of gravity,to move molten core materials into a series of dead end underground passages. Finally, our large amount of radioactive material must escape the massive outer containment dome of the reactor. Let us assume that each of these containment structures works as intended. We know, for example, that the pressure vessel will contain a core meltdown, because the core of the Three Mile Island reactor was contained by its pressure vessel. Thus it is very unlikely that the pressure vessel of a ESBWR would fail if its core did melt down. Let us consider that the likelihood of that the average time to pressure vessel breach by a molten core is average time to core meltdown multiplied by a factor of 10. That would give us a figure of 290,000,000 years to pressure vessel breach.

Now the failure of the core catcher is far more unlikely than the breach of the pressure vessel because the core catcher relies on natural forces to capture and hold the molten core. Let us assume for the sake of argument that the likelihood of a core catcher failure is the average time to pressure vessel failure multiplied by a factor of 10. That would give us a period of time of about 2,900,000,000 years before core catcher failure.

Once the core catcher fails there are still the massive outer containment walls of the reactor to prevent a large scale release of radioactive materials. Again we will assume that this structure will increase the likelihood of containment by a factor of 10. This would give us a catastrophic release of radioisotopes into the environment once every 29 billion years. That figure happens to be over twice the age of the Universe, and several times the expected lifespan of the earth.

Given a probabalistic world, many natural catastrophic events are far more likely than containment failure including the eruption of the Yellowstone super-volcano and event which could kill millions of people, and which is likely to occur sometime within the next 160,000 years.

Of course if more ESBWRs are built, our probability of catastrophic containment failure will increase. With a set of 1000 ESBWRs, we end up a gain with the figure of once every 29,000,000 million years between containment failures. To put this figure into some perspective collisions between the Earth and astroids of at least 5 km in diameter occur once every 10 million years. The impact of such an astroid with the earth would cause enormous damage to human society. Such events are three times as likely to occur as the catastrophic failure of containment in a ESBWR in a thousand reactor system. The worst possible consequences of reactor core containment failure would be very small compared to the consequences of a once every 10 million year astroid impact event.

It is my contention then that the dangers posed to the population of the world by a massive 1000 reactor system of ESBWRs is insignificant when compared with far more likely natural disasters.  However, as safe as the ESBWR is, it is not the ultimately safe reactor.  I will turn next to an exploration of how to make reactors even safer than the ESBWR is.

Tuesday, October 14, 2008

A Primer on Nuclear Safety: 2.3 Defense in Depth

A Primer on Nuclear Safety:
2.3 Defense in Depth
Light Water Reactors - Water and other safety features


The most important aspect of safety in Light Water Reactors is the cooling system. The coioling system also serves te purpose of moderating the nuclear reaction in Light water reactors. As we have noted, a loss of coolant in Light Water Reactors will stop the chain reaction, but will lead to core overheating because of the continued core heating caused by the radioactive decay of fission products. For that reason it is vital to maintain the presence of cooling water in the reactor core. There is one major variation in the LWR cooling system. Pressurized Water Reactors use secondary coolant systems. The secondary coolant system, in the PWR is responsible for stem generation. Water at high temperature and under heavy pressure leaves the reactor core and flows through pips to a steam generator. In the steam generator the water from the reactor passes through a heat exchange where is passes heat to the secondary coolant water. The primary coolant water then pumped back into the reactor, where it begins the cycle again. The secondary coolant water, once it has entered the heat exchange begins to rapidly boil. The steam is then routed to steam turbines where power is produced. Upon exiting the turbine the steam is cooled and condensed, and returned to the secondary coolant system.

The Boiling Water Reactor only has a primary coolant system. Water, under somewhat lower pressure in a BWR turns to steam in a BWR. the steam then flows to the turbines, the spent steam is cooled and condensed, and the cooled water is returned to the reactor where the cycle begins again. The coolant system of the BWR is simpler, and simplicity often enhances safety. Hence the BWR is potentially very safe, but at a price of somewhat lower efficiency.

Coolant systems usually rely on pumps to move water around, and like any other mechanical objct pumps do break down. They have to be periodically serviced, and in addition have been known to fai lin the course of reactor operations. There is a work around for pump servicing and pump failure, and that is back up coolant systems, that can be either automatically brought into operation in the event of pump failure, or when the pump of the primary coolant system is being serviced. One of the major contributing factors to the Three Mile Island Accident was the failure of the secondary coolant system, due to the tripping of a water pump. The backup pumps had been accidentally locked off line, so the essentially the primary coolant system lost its ability to dump heat from the reactor core. The reactor shut down, and other systems to maintain core safety automatically came into play. At that point the accident would have been over, had not an operator not shut down the emergency coolant system.

Thus the Three Mile Island accident illustrates the successful function of the defense in depth philosophy. Because even though secondary coolant system failed, and its backup was off line, and the the emergency coolant system was turned off, and the reactor core suffered partial meltdown, defense against a major release of radioactive material held. The cost of the coolant system failures was however, major damage to the reactor core.

Since the Three Mile Island accident illustrated the vulnerability of LWRs to coolant system failure, much attention has been paid both by reactor manufacturers and the Nuclear Regulatory commission of the United States to the improvement of the safety and reliability of Light Water Reactor coolant systems. One major approach for improvement has been the replacement of pumps with thermal syphons. Thermal syphoning is not exactly high tecnology. The principle was sucessfully used to circulate engine coolant in the Model T Ford! A thermal syphon takes advantage of the natural tendency of heated liquid to rise in a liquid column, while cooled fluid falls. In a closed system where the liquid is both heated - for example in the engine of a Model T Ford - and cooled - in the radiator of the Model T Ford - the coolant may achieve natural circulation without mechanical pumps. Remarkably, the same thermal syphon principle which works with antique cars, also works for the latest models of very large reactors. One notable example of this is the Evolutionary Simplified Boiling Water Reactor (ESBWR), which has is the Latest Word in Generation III + reactor safety. Because the ESBWR dispenses with cool water pumps, it also eliminates the very possibility of pump related accidents. A second feature which the ESBWR has in common with other Generation III+ reactors is the use of gravity feed emergency water systems. These systems place large tanks of emergency cooling water above the reactor core. In the event of a loss of coolant accident, water from the emergency coolant tank will automatically flood the reactor core. The ESBWR emergency coolant system does not rely on pumps. Rather gravity feeds the energency coolant water into the reactor core.

The sophisticated features of the ESBWR greatly enhances its safety compared to other Light Water Reactors. The ESBWR is calculated to be in danger of core melt down once every 29 million years. One would expect that with the extreme unlikelihood of core meltdown with the ESBWR, and the success of core containment by the reactor pressure vessel in the Three Mile Island that no provision for the containment of a molten reactor core would be made in the case of pressure vessel failure. Such is the safety of the ESBWR design that provision is made for the almost infinitely slight probability of that a molten core would escape its pressure vessel. In that case a core drainage and capture system has been been included in the ESBWR reactor design.

In a probabilistic world it is impossible to completely dismiss the possibility that a ESBWR Will ultimately fail in a catastrophic accident that will cost human lives, but the sun will also fail costing the life of everyone left on earth, and in a somewhat similar time frame. Thus the advanced safety features of the ESBWR coolant system, coupled with standard reactor defenses in depth against radiation releases, and a very advanced molten core capturing system, render concerns about ESBWR safety irrational.

Sunday, October 12, 2008

A Primer on Nuclear Safety: 2.1 Defense in Depth


A Primer on Nuclear Safety:
2.1.1 Defense in Depth
Light Water Reactors - Physical Barriers

The Defense in Depth philosophy is applied to the release of radioactive materials from inside the core of light water reactors. Helen Caldicott, the ceaseless critic of nuclear power notes
Nuclear power creates massive quantities of radioactive isotopes, which are classified as nuclear waste. Among these materials are strontium 90, . . cesium 137 . . . plutonium, . . . lutonium has a radioactive life of half a million years. It enters the body through the lung, where it is known to cause cancer. It mimics iron in the body. Hence it migrates to the bone, where it can induce bone cancer or leukemia, or to the liver, causing liver cancer; and it crosses the placenta into the embryo, where, like the drug thalidomide, it can cause gross birth deformities. Finally, it has a predilection for the testicles, thus inducing genetic mutations in humans and other animals that are passed from generation to generation for the rest of time. Meanwhile, the plutonium itself lives on to enter testicle after testicle, lung after lung, liver after liver for the rest of time as well. Children are 10 to 20 times more susceptible to the carcinogenic effects of radiation than are adults.
That it is possible for such radioactive materials to escape in massive amounts from some reactors is certain given the Chernobyl accident. Even though massive amounts of radioactive materials that escaped during the Chernobyl incident did not lead to the sort of human disaster Dr. Caldicott imagined large scale releases of bioactive readio active materials from reactors is highly undesirable.   

During the 1950's and 60's nuclear chemists at Oak Ridge National Laboratory did extensive theoretical, field and Laboratory research on routs to radioisotope release from reactors.   This research was of major importance to nuclear safety because by identifying routs for radioisotope escape, the researchers alerted reactor designers to those escape routes and the possible means of mitigating events that could potentially lead to radioisotope escape.  

Nuclear safety researchers were by no means satisfied with their acomplishments. In 1967 my father, C.J. Barton, Sr. wrote
In order to promote confidence in such large reduction factors, continued research into the efficiency of removal for al l the various forms of the released fission products will be required.


During the 1960's researchers at ORNL. Battelle Northwest, and Phillips-Idaho conducted sophisticated containment and reactor accident research with facilities that were designed to simulate nuclear accidents. Again the findings of this research were fundamental to reactor safety design. As I have pointed out elsewhere in this blog, the continuation of nuclear safety research at AEC facilities became during the late 1960'sane early 1970's became a major matter of political controversy.


Even though the politically inspired attack on nuclear safety research was never completely rectified by the American political establishment, enough progress had been made to allow for great improvements in Light Water Reactor safety.

Physical Barriers increase Light Water Reactor safety

Defense in Depth against the release of radioisotopes required a series of physical barriers that inhibited the movement of radioisotopes from the nuclear fuel pellets, into the environment. In order to illustrate the defense in depth of civilian light water reactors, a brief comparison to the Soviet RBMK reactor is in order. The failure of the safety features of one of the RBMK at Chernobyl lead to the release of large amounts of radioisotopes from the reactor core. The RBMK reactor like Western Light Water Reactors featured ceramic uranium fuel elements made of uranium dioxide baked at high heat. In Western reactors the fuel pellets are clad with Zirconium a sturdy metal that resists the reactors heat and radiation.
The Uranium Oxide fuel is itself the first barrier in the defense in depth, and it is a one of the strongest barriers in the whole defense. Fission products are basically locked in to the rock like fuel pellet. As George Parker and my father were to observe that the release of fission products from Light Water Reactor fuel was cause by a variety of mechanisms that were all triggered by overheating. Thus the first barrier could be breached by reactor over heating.

The Zirconium cladding adds protection against fission product escape. Zirconium has a high melting temperature, although not as high as uranium oxide. Like uranium oxide, zirconium and zirconium alloys are dependent on reactor cooling to prevent to maintain integrity as a barrier to fission product escape. A further consequence of the failure of Zirconium cladding would be that it would subject uranium oxide fuel to mechanisms that promote fission product loss.

A Zirconium tubes in which the fuel pellets rest in the reactor core constitute a third barrier to fission product release, however in practice if reactor core heat is sufficiently high to cause the failure of Zirconium cladding, it will also cause the failure of zirconium tubes. The outer structure of the reactor provides a further barrier to fission product release. In LWRs the pressure vessel is a major barrier to solid fission product release, although radioactive gases can work their way around the barrier in major reactor accidents. The RBMK does not have a pressure vessel, which is perhaps the most significant reason for the massive release of radioisotopes in the Chernobyl accident. The Chernobyl RBMK appears to have included an outer structure designed to maintain the RBMK core in a helium environment in order to prevent graphite burning. This containment structure failed during the Chernobyl incident, and the resulting graphite fire contributed greatly to the fission product release during the Chernobyl incident.

The next barrier to fission product release is the reactor outer radiation shield. Although this shield is seldom mentioned in discussions of defenses in depth, it does provide a barrier to the release of solid and molten fission particles whose movement is limited by the forces of gravity. Thus in the event of a core melt down which penetrated the pressure vessel, the radiation shield would offer considerable containment of the molten fission particles. Because of its massive nature, the radiation barrier would also mitigate a steam explosion powerful enough to rupture the wall of the pressure vessel. The sideways and downward pressure of the steam explosion would be baffled by the massive radiation shield while gravity would contribute to containing the movement of non-gaseous fission products within the outer containment structure. The Chernobyl reactor was surrounded by a radiation containment structure which failed because the of a powerful steam explosion. The cause of the blast was a combination of design flaws that caused a dramatic rise power levels in the reactor when an operator attempted to shut the reactor down.

The destruction of the radiation shield of the Chernobyl reactor removed the last level of containment for that reactor, while another level of containment, represented by the outer containment dome, would have still survived a Chernobyl like explosion. The failure of the Chernobyl radiation shield and the subsequent graphite fire lead the the massive release of radioisotopes from the burning Chernobyl reactor. Thus the critical features that lead to the radioisotope release from the Chernobyl radiation release were not present and two outer barriers to the release of solid radioactive materials, the massive 8" thick steel pressure vessel, and the even more massive outer dome of the reactor were not features of the Chernobyl reactor design. Other unique features of the RBMK reactor design including the use of a graphite moderator, and numerous design flaws that created safety problems contributed to the accident.

Anti-nuclear critics of nuclear safety often point to the Chernobyl accident as evidence of the fundamental safety flaws of all reactors, without noting the significant differences in safety features between RBMK reactors and LWRs. In fact during the Three Mile Island accident the outer safety barriers, the pressure vessel, the radiation shield, and the containment dome all remained in tact. There were no verified cases of radiation related health problems as a result of the Three Mile Island accident, and subsequent research failed to identify any increase in the number of cancer cases that could be associated with the accident. Thus the defense in depth deployed at the Three Mile Island Reactor was successful.

A Note on Radioactive Gases

The radioactive material released as a consequence of the Three Mile Accident were primarily nobel gases. The nobel gases and other radioactive gases are fission bi-products that are present in the uranium oxide fuel pellets, Normally they would remained trapped in the uranium oxide pellets, but if the reactor core heats enough to melt down, the zirconium cladding will rupture or melt, and the melting of the uranium oxide pellets will release the nobel gases. The gases escape from the reactor core through the cooling system. The gases are quickly dispersed by the atmosphere. While nuclear critics rase the issue of radioactive gases as an issue in justifying their opposition to nuclear power, nuclear critics often display a strange inconsistency. Radon, a radioactive gas is also released by coal burning coal fired power plants. In addition natural gas contains radon. More radioactive gas is released into the environment by the use of fossil than by nuclear power plants, yet nuclear critics rarely raise their voices in concern about radioactive gasses released by the use of fossil fuels. In fact, many supposedly pro-environmental, anti-nuclear organizations, accept funds from foundations with ties to fossil fuel produces, sometimes with stipulations that the funds will be used to promote fossil fuel use. Needless to say, these organizations never raise talk about the association of radon gas with fossil fuel use.

I will in a later post discuss a methods of preventing or at least limiting the release of radioactive gases associated with the development of the LFTR.

Friday, October 10, 2008

A Primer on Nuclear Safety: 2.0 Defense in Depth

A Primer on Nuclear Safety:
2.0 Defense in Depth


In 1964, Ralph Nader had no reason to question that nuclear power was a clean, safe, cost-efficient technology. Then he attended a conference at the Oak Ridge National Laboratory. Over lunch, Nader began asking nuclear engineers some penetrating questions. "They couldn't answer them, or the answers weren't satisfactory," Nader recalls. "'What could happen if a system goes wrong?' I asked. They avoided any such descriptions or said, 'we've got defense in depth' -- and other jargon."
- David Bollier (Citizen Action and Other Big Ideas)

The concept of defense in depth is fundamental to nuclear safety. The defense in dapth approach applies not only to reactor design but also to safety management. Definse in Depth assumes that human judgement is flawed, designs are imperfect, constructors can fail to follow plans, and that things can go wrong in numerous ways. Thus a defense in depth approach assumes that things can go wrong in with reactor, and there must be bacj up systems if things go wrong. But things can go wrong with the back up system, and they must also have back up plans.

Defense in depth assumes that the potential causes of nuclear accidents are in many instances controllable. One object of nuclear safety research would be the identification of potential causes of accidents, and the design systems to control those causes. The most fundamental causes of nuclear accidents are hidden in reactor design. Western reactor scientist knew imediately the cause of the Chernobyl accident. It was a fundamental design flaw in the RBMK reactor design. The existence of the problem, was what is called a large positive void coefficient, which lead to positive reactor feedback to increased heat.

What does this mean? It means that the cooling water in the RBMK reactor acts as a preak on the chain reaction. If the cooling water is removed from the reactor, the chain reaction will start to run away. Further more water can be removed from the reactor by heat. If the cooling water inside the reactor gets hot enough, it starts to boil. As the cooloing water boils, the steam forces water outside the reactor, thus removing the nuclear break, increasing reactor heat, which inturn boils more water, etc. So the basic design of the RBMK is flawed and dangerous. Alvin Weinberg, who was an expert on reactor safety noted that when reactors that were similar to the RBMK were designed in the United States during World War II, American scientists were aware of their safety flaw.

Therefore it must be understood that nuclear safety must begin with the recognition that not all reactor designs are equally safe. Some reactor designs are much safer than others, and some reactor designs are inherently safer and perhaps can be even made inherently safe. Other reactors have potentially unsafe design features tht can be worked around.

Thus reactor safety is the primary level of nuclear safety, and the defenses against accidents in a reactor may feature both redundancy and a many leveled safety defense system. The current generation of Light Water Reactors have high levels of safety built in to their designs. Nuclear safety engineers have calculated that the General Electric Evolutionary Simple Boiling Water Reactir is so safe, that it would experience a core meltdown once every 29 million years. In contrast the Yellowstone Super volcano, which is capable of killing milllons of people with an erruption, erupts every 600,000 to 800,000 years. It has been 640,000 years since the last erruption of the Yellowstone super volcano. The likelihood of a major reactor accident and its consequnces, ought to be placed in the context of far more likely natural disasters.

Stepts that can be taken to prevent reactor accidents include:

A. good design based on an up to date understanding of reactor safety,
B. An exhaustive follow through of all safety related reactor features in the procurement of manufactureing materials and replace ment oarts, The actual manufacture and maintence of the reactor, and reactor operations
C. systematic faults detected in procurement, manufacture and operationals, with a prompt and complete follow up.
D. Redundant or fall back systems in the event of the failure of a reactor system.
E. Automatic system response that rely ion the laws of nature, rarher thn opeartor intervention.
F. Reactor siting consistent with reactor safety issues. Experimental reactors placed in remote locations.
G. Reactor staff should be both well trained and highly motivated to follow all safety guidelines.
unit placed in safe state by well-trained staff using
approved procedures

The second level of nuclear safety is accident mitigation. These would include those elements of reactor design that would tend to diminish the effects of a nuclear accident on the public. Mitigation would include both internal reactor design features, and design features of the reactor facility that would tend to mitigate the effects of a major nuclear accident. Mitigation defenses can be in depth. Hence in the event of a core meltdown in a light water reactor, the reactor pressure vessal would pose a significant defense against the escape of solid fission products. The reactor containment dome would form another layer of defense against fission product release, while the isolation of the reactor would lead to the dissipation of radioactive gases, and the precipitation of solid radioactive particles escaping the reactor containment facility prior to contacts with human communities.

Accident mitigation would include, the automatic shutdown of a reactor after a partial system failure, the automatic initiation of back up cooling and/or emergency cooling in the event of a primary cooling syetem failure. The design of reactor monitoring panels and system alerts to give clear and concise information about what is happening, without creating an overwelming flow of information. Staff training in accident management. Well defined accident response procedures to be included in staff training. The management of initial recovery after accident related shut down, Well defined accident cleanup and recovery procedures.

A third level of defense would be the management of public consequences after a nuclear accident. These wouldinclude the notification of the NRC, as well as Federal, State and Local officials. Steps which might be taken to manage the consequences of a serious accident include evacuations, bans on the use of potentually contaminated food and.or water. Provisions for safe sheltering of at risk populations, andthe distribution of KI pills, as well as other pre-planed interventions by the federal, state and local governments.

Normal accounts of nuclear safety defense in depth stop at this point. There are however other levels of nuclear safety, A forth level would be a well informed public. Nuclear safety is a genuine matter for public concern. The public should demand the safest nuclear technology possible, and both support nuclear safety research and for monitoring of observance of safety rules and procedures by demanding that reactor operators comply with them, and that the NRC vigerously enforce them.

One of the great flaws of the anti-nuclear movement has been to disempower the public on nuclear safety issues. Figures like Ralph Nader, failed to avail themselves of opportunities to learn more about nuclear safety. Had Ralph Nader really wanted to understand the safety concerns that Alvin Weinberg discussed with Claire Nader and with Ralph himself, had Ralph Nader tried to understand what the ORNL nuclear safety engineer was telling him about defense in depth, the history of the first nuclear era might have ended differently. Had there have been a public outcry for nuclear safety in the 1970's rather than an anti-nuclear movement, the owners of the Three Mile Island reactor, would not havebeen allowed to get away with the safety errors they committed. Had there been a public outcry for safety research, staff safety training, and safe design of reactor control panels, there would have been no Three Mile Island accident. By convincing the public of the ill intentions of safety advocates within the nuclear community, and by convincing the public that nuclear safety was impossible, and therefore it had no stake in the development of nuclear safety improvements, the anti nuclear movement, disempowered the public on nuclear safety issues. It is up to the public to take its power back from the anti-nuclear movement, and assert its right to demand the highest levels of nuclear safety possible. Such a public demand would be a fourth level of nuclear safety defense.

The fifth level of of nuclear safety defense is nuclear safety research, and safe reactor design coupled with the actual replacement with reactors designed to current safety standards by reactors designed with even higher levels of safety. Nuclear safety is something that happens in time. Nuclear safety has a history. It has evolved during its history, and can be expected to continue to do so. It is perhaps unfortunate that the Light Water Reactior emerged early on as the predominant power reactor type. Light Water Reactors have inherent safety flaws. Those flaws can be largely worked around, by engineering reactor modifications, but those modifications are expensive. To much of the history of nuclear safety has been the history of increasingly expensive safety developments for the light water reactor.

Reactor scientist have known since the 1940's that it is possible to eliminate the very possibility of the most serious of reactor accident, the core melt down. Reactors designs developed over 50 years ago posses inherent safety feature that far surpass those of light water reactors. Furthermore one of those two advanced reactor designs, the Liquid Flouride Thorium Reactor,relies on an abundant nuclear fuel, Thorium, which it uses so efficiently that it will provide sustainable nuclear power for millions of years to come. Because of its efficient use of the Thorium fuel cycle, the LFTR also virtually eleminates the long term nuclear waste. Developing and implementing the LFTR reactor designs would not be inordinately expensive, or require an extensive period of time. The development cost for either reactor design would cost less than the cost of two light water reactors, or less than the cost of the imported oil the United States consumes in one week. The manufacturing cost for the LFTR would also be lower that the current cost of building Light Water Reactors. Thus at a relatively small cost the United States could acquire a fifth level of nuclear defense, one which would make the most serious reactor accident impossible, and solve other problems related to the use of nuclear energy in the generation of electrical power.

Followers

Blog Archive

Some neat videos

Nuclear Advocacy Webring
Ring Owner: Nuclear is Our Future Site: Nuclear is Our Future
Free Site Ring from Bravenet Free Site Ring from Bravenet Free Site Ring from Bravenet Free Site Ring from Bravenet Free Site Ring from Bravenet
Get Your Free Web Ring
by Bravenet.com
Dr. Joe Bonometti speaking on thorium/LFTR technology at Georgia Tech David LeBlanc on LFTR/MSR technology Robert Hargraves on AIM High