Fukushima Japan Earthquake: nuclear plants Fukushima part 2

Click For Summary
A magnitude-5.3 earthquake struck Fukushima, Japan, prompting concerns due to its proximity to the damaged nuclear power plant from the 2011 disaster. The U.S. Geological Survey reported the quake occurred at a depth of about 13 miles, but no tsunami warning was issued. Discussions in the forum highlighted ongoing issues with tank leaks at the plant, with TEPCO discovering loosened bolts and corrosion, complicating monitoring efforts. There are plans for fuel removal from Unit 4, but similar structures will be needed for Units 1 and 3 to ensure safe decontamination. The forum also addressed the need for improved groundwater management and the establishment of a specialist team to tackle contamination risks.
  • #901
mheslep said:
The tsunami hit 41 minutes after the quake. How could a cold shut down have been acquired under those circumstances?
As it was discussed in the old days, after the emergency trip they followed the standard procedures and kept a constant cooling speed which was slower than the maximal. They had even had to switch off the IC partially to keep the allowed maximal temperature change speed.
Would they know about the tsunami approaching, they could be able to switch to maximal cooling instead.
I don't know if they could be able to reach the 'cold shutdown' state, but it could mean a great deal of heat removed when it matters most - the early stage when the power output is still high.

But at that time nobody knew about the tsunami, and even if they had knewn about it, such violation of rules would require permissions (what means delay).

Ps.: posts around https://www.physicsforums.com/threads/japan-earthquake-nuclear-plants.480200/page-411#post-3322059
 
Engineering news on Phys.org
  • #902
Rive said:
I don't know if they could be able to reach the 'cold shutdown' state, but it could mean a great deal of heat removed when it matters most - the early stage when the power output is still high.
Yes, though with decay heat still at ~ 6MW at the time of cooling failure, I don't think anything is accomplished besides buying a couple more hours before that inevitable explosion.

Another alternative: I've never seen the possibility raised of restarting the reactor post quake and running cooling directly off a tap from the generator mains, i.e. self-powered, so I suppose there is some obvious reason why it should not be done that I'm missing. Clearly restarting the reactor after a strong quake carries some risk, but after cooling power failure the outcome was inevitable.
 
  • #903

mheslep said:
The tsunami hit 41 minutes after the quake. How could a cold shut down have been acquired under those circumstances?

try it on your simulator ?
They're more maneuverable than people think.
I've seen my plant back online and at full power fifty minutes after a scram .
New folks find that incredible.

...................

Your bootstrap is plausible except that their switchgear rooms were flooded with saltwater.

My vintage Westinghouse plant is in theory capable of rolling turbine on natural circulation and bootstrapping itself up
but it's not within bounds of permissible operation.
I assume BWR is similar.
try it on your simulator ?

old jim
 
Last edited:
  • Like
Likes turi and mheslep
  • #904
Red_Blue said:
It's interesting to compare the response in Fukushima 2 that suffered from the same earthquake and tsunami, but maintained effective reactor cooling during the same time period as Fukushima 1 had core melts and hydrogen explosions. The designs and plant systems were hardly different. The significant difference appeared to be that F-2 operators never lost control of their reactors, while F-1 operators never really regained it after the tsunami. It also appears that the most critical factor in losing control was not the loss of control systems, but the loss of incoming information about plant status and subsequent breakdown in effective decission making.

IIRC in Daini, they did not lose all external power. That is a huge difference.
 
  • #905
@Red_Blue

This fellow rather specializes on Fukushima
https://www.researchgate.net/profile/Akira_Tokuhiro

i'd peruse his papers, maybe try to contact him ?
 
Last edited by a moderator:
  • #907
Rive said:
But at that time nobody knew about the tsunami, and even if they had knewn about it, such violation of rules would require permissions (what means delay).
I think the correct phrasing is that nobody knew the incoming tsunami would be high enough to inundate the entire seaside of the site, until a few minutes before it was too late.

Cabinet Investigation Committee Interim Report @ section IV1.(2)a(iii) said:
Situation and response from the time the earthquake hit until the arrival of the tsunami
(from approximately 14:46 to 15:35 on March 11, 2011)
Action taken by the NPS ERC
- -
The shift teams, the NPS ERC and the TEPCO ERC thought that they could put the
reactors into a state of cold shutdown before the loss of all AC power sources due to the
tsunami so long as they implement the prescribed procedures.

Obviously, at that point they didn't know they were going to have a SBO, just suspected it.
This is later clarified as:

Cabinet Investigation Committee Interim Report @ section IV2.(1)(i) said:
Site Superintendent Yoshida first learned from the news on television that a three-meter
high tsunami would hit the Fukushima Dai-ichi NPS then he learned that the estimated
height had been changed to six meters. Site Superintendent Yoshida felt an apprehension
that the Residual Heat Removal System (RHR) might lose its cooling function if the
emergency seawater pump facilities would be damaged by the backrush of the tsunami.
At that moment, however, Site Superintendent Yoshida did not yet expect that more
than one units were to lose all AC power sources at once and station blackout would
continue for a long time. He thought that even if the emergency seawater pump facility
were damaged, the IC of Unit 1 and the RCICs of Units 2 and 3 could be used to cool
down the reactors or they could recover cooling capability by restoring the pump facility
while constructing power interchange facility between the units.

The timeline I've seen looks like this:
14:46 earthquake
14:49 first automatic tsunami forecast for F-1 region: 3 m
15:14 new forecast from JMA: 6m
15:27 5 meter runup from the first arriving tsunami (5.5m protection level)
15:31 new forecast: 10m
15:36 15m biggest tsunami arrives

So in other words, up until 15:31 it looked like they would be able to handle it. That left 5 minutes to do something about it, which would have been barely enough to consider a plan, let alone communicate or implement it.

In F-2 Superintendent Masuda ordered some staff from his ERC to go to the balcony of the 3rd floor of the seismic isolation building and look out to the sea and report back when they spotted the incoming tsunami. But in F-2 they also cooled the reactors at the limit rate by shutting down RCIC periodically.

It should be noted that the 55 C cooling limit was imposed in the emergency operation procedures, not a limit just for normal operations that could have been overruled easily.
 
  • #908
BWR senior reactor operator here.

For cool down rate, 100degF per hour or 55C per hour is an ASME design limit for BWR vessels. BWRs are analyzed for a single emergency blowdown event, and require the vessel ASME code analysis to be updated after such an event. Momentarily exceeding the cool down rate typically isn't an issue. But the emergency operating procedures heavily protect this cool down limit. The only times that you are allowed to intentionally exceed the limit is if you lose adequate core cooling or if a primary or secondary containment parameter is going to exceed maximum safe limits, or if release rates are approaching general emergency levels. In almost all cases, the requirement is to perform an emergency blowdown using the automatic depressurization system, meaning you fully depressurize to under 50 psig.

During the period of time between the earthquake and tsunami, the pressure control actions require you to STABILIZE pressure, that means to hold pressure as stable as possible. With only the IC in operation, this means you'll be maintaining a large pressure band, but well within the 100 degF per hour limit. If they chose to transition from STABILIZATION or COOLDOWN, the requirement is still to maintain that 100 degF per hour cooldown limit.

If the IC was in operation, they would have had hours of decay heat removal, plus they had IC gravity driven makeup tanks that could have extended that to close to a day I believe, and with fire pumps or portable pumps to refill the makeup tanks you could establish a relatively long term decay heat removal. But the issue I understand is the drywell inboard isolation went closed when DC power was lost. The valves auto closed on loss of control signal as designed. This made the IC non recoverable. If the drywell isolation valves didn't close, the operators could have opened and shut the outboard isolation valves manually (I believe the MO-3) to control cooldown rate. Unless the core was uncovered, the EOPs do not allow placing the IC in service and leaving it in service to violate the cooldown limit. If the core is uncovered, and alternate level control does not maintain level above the minimum steam cooling reactor water level (MSCRWL) (1500 degF temp limit), then the steam cooling contingency will mandate placing the ICs in service even if the cooldown limit will be violated, and allows level to drop to the minimum zero injection reactor water level (MZIRWL) (1800 degF temp limit). After that, or if any injection source becomes available, you need to open the automatic depressurization system valves to blowdown.

As for HPCI operation, I'll need to talk to someone at Dresden. I think HPCI should have been available, but if it isolated due to the loss of dc power it would be unavailable for black start. Given when they realized the IC wasn't functioning, and that the torus rooms and basement were pretty badly flooded, they may not have been able to access these areas to black start it. Without DC power, both automatic and remote startup methods would have been unavailable. HPCI auto starts on level 2 or high drywell.

Someone mentioned the daini site, my understanding was that they were in station blackout, and the reason they were able to survive was because they still had DC power, and because all units RCIC systems were in operation until they got ultimate heat sink capability back to cool the suppression pools.

RCIC and HPCI are pretty significant decay heat removal systems. HPCI can depressurize a BWR in 12 hours, and RCIC can remove a good chunk of decay heat (not all of it), but for low or moderate decay heat levels it can depressurize the core as well. Typically a BWR will run HPCI in pressure control mode (Recirculation) and RCIC in injection mode when the streamlines are shut to prevent relief valves from lifting. My plant doesn't have HPCI, but we have used RCIC when streamlines were shut and RCIC in combination with streamline drains was enough to get our decay heat out.

Someone mentioned black starting a BWR. I don't think any BWRs are analyzed for black start at this time. Typically BWR emergency generators are dedicated to class 1E ESF busses only. Not all BWRs have control Rod drive hydraulic pumps on their diesels either, which is required for Rod motion. BWRs are designed to perform an isolated startup and heat up, but it is hard to control and many plants have gotten rid of that section of procedures and require a heat up with main steam and condenser in service.

I'll post more as I get time.
 
Last edited:
  • #909
Red_Blue said:
They were using SCBA gear with 20 minute tanks and full body suits to enter other parts of the reactor buildings due to radiological conditions already after midnight of March 12th. That equipment must have been present onsite and not brought in, as such external supplies started to only arrive on the morning of 12th.

I would expect the PCV airlock to be manually operable as an option, suggesting otherwise doesn't make much sense. There were several missions during the accident to high radiation fields inside the reactor buildings to manually open valves. I don't see how the PCV would have been any different, especially considering that the dose rate there was under 10 mSv/h by CAMS before core uncovery and damage. I was also under the assumption that some of the missions actually went inside containment during the middle phases of the accident, but I would have to check to confirm that. At least the crews went to the torus rooms and several ground and 2nd floor rooms of the RBs.

The mark I is inerted. I believe the containment personnel air locks have shield walls that need to be moved. It depends on the design. I do not believe one could have easily or safely gotten into the drywell to open the inboards though. IIRC they are pretty high up and need some climbing.
 
  • #910
mheslep said:
The tsunami hit 41 minutes after the quake. How could a cold shut down have been acquired under those circumstances?
There's no allowable way in the emergency operating procedures to get there in this scenario.
 
  • #911
Red_Blue said:
There's no need to bring in straw men in the form of fictional action heroes. We already know the plant operators did many unconventional, hazardous and even unprecedented things when they had adapted to the realisation that they were managing a very severe accident with life threatening consequences. Unfortunately that adaptation took about a day and night, even though the factors forcing that adaptation (almost total loss of remote control and monitoring) were present immediately after the tsunami.If you are willing to stifle discussions about the proper response to a beyond design basis accident, then you are really suggesting that you can always design for every accident scenario, which has proven time and time again unfeasible. It's interesting to compare the response in Fukushima 2 that suffered from the same earthquake and tsunami, but maintained effective reactor cooling during the same time period as Fukushima 1 had core melts and hydrogen explosions. The designs and plant systems were hardly different. The significant difference appeared to be that F-2 operators never lost control of their reactors, while F-1 operators never really regained it after the tsunami. It also appears that the most critical factor in losing control was not the loss of control systems, but the loss of incoming information about plant status and subsequent breakdown in effective decission making.

Loss of dc power significantly complicated the unit 1/2 events at daiichi. I personally believe if they didn't lose their dc power the event would have looked more like daiichi. The loss of dc caused an inappropriate focus on unit 2, and contributed to the failure of the IC at unit 1.
 
  • #912
I'm still amazed that so many "emergency cooling" measures don't actually remove heat from the unit, they merely move it around. HPCI, RCIC, they all move hot water/steam from the RPV to various other pools and tanks, and this water eventually goes back into RPV. To me, this looks somewhat stupid.

Only the "old" IC actually does cool the whole damn thing.
 
  • #913
nikkkom said:
I'm still amazed that so many "emergency cooling" measures don't actually remove heat from the unit, they merely move it around. HPCI, RCIC, they all move hot water/steam from the RPV to various other pools and tanks, and this water eventually goes back into RPV. To me, this looks somewhat stupid.

Only the "old" IC actually does cool the whole damn thing.

The RHR heat exchangers are your ultimate heat sink. For a DBA LOCA they are required to be placed in service manually within 10-30 minutes. For LOOP events, you need one heat exchanger in service to prevent exceeding suppression pool design temperature.

My Mark III will get close to 160 degF in a LOOP with one RHR HX in service per our power uprate analysis.

The goal is to always minimize the amount of heat you have to reject to containment. If the condenser is unavailable you have no choice, but even in this scenario the expectation is that you cool down using RCIC taking a suction from the condensate storage tanks to minimize pool heat up. The CST is required to maintain sufficient water to support a RCIC cooldown.

Keeping the pool cooled is a big deal. The operating license has strict limits on pool temp and will mandate a rapid cooldown if you're getting too hot. The EOPs have a heat capacity temperature limit graph, which if exceeded requires immediate cooldown or emergency blowdown to ensure you don't exceed the containment temperature limit during a subsequent line break or emergency blowdown. It's also one of the only places in the EOPs that emphasize containment protection over core cooling, as it mandates exceeding the cooldown rate intentionally to protect the HCTL.
 
  • #914
Hiddencamper said:
The RHR heat exchangers are your ultimate heat sink. For a DBA LOCA they are required to be placed in service manually within 10-30 minutes. For LOOP events, you need one heat exchanger in service to prevent exceeding suppression pool design temperature.

This is the part which I find stupid. What's the point in the design which transfers heat from RPV to suppression pool, so now you need to cool the suppression pool? This introduces more failure points, and false sense of security. "RCIC can keep the reactor from overheating", one might think. Wrong. "RCIC can keep the reactor from overheating *if* and *until* suppression pool overheats". Now you need RCIC to not fail *and* RHRs to not fail.
 
  • #915
nikkkom said:
This is the part which I find stupid. What's the point in the design which transfers heat from RPV to suppression pool, so now you need to cool the suppression pool? This introduces more failure points, and false sense of security. "RCIC can keep the reactor from overheating", one might think. Wrong. "RCIC can keep the reactor from overheating *if* and *until* suppression pool overheats". Now you need RCIC to not fail *and* RHRs to not fail.

The original design was just the IC.

The IC has no injection capability though, which for long term events is important. So GE swapped it out for RCIC plus the steam condensing mode of the RHR heat exchangers. The RHR HX are designed to handle reactor steam, and used a level and pressure controller to control cooldown rate. Steam from the RCIC steam line would go to the HX, be condensed on the tubes, then would be fed back to the RCIC pump suction. This provided long term heat sink. I know some plants had issues with this, but I have yet to find the details (astronuc if you can find out why please let me know, I speculate tube damage after Humboldt Bay stayed critical on RCIC/RHRHX for over a day). But most plants ultimately deactivated steam condensing mode. HPCI plants can use it for pressure control. HPCS plants have to lift SRVs which sucks. A lot.

Remember that compared to a PWR, where the turbine driven aux feed loses inventory to the atmosphere and will eventually run out, BWRs never lose inventory. If the containment is being vented, you can remove all decay heat that way and never lose RCIC. There are trade offs between various designs. But due to Recirculation seal leakage during loop events, the IC alone will eventually not be sufficient as water level slowly drops. Loop design leakage is close to 50 gpm, or 1 inch every 4 minutes. Given there's 200 inches of inventory, the IC is not going to protect the core for these events. (These are average/typical levels). (50 gpm is a design limit, typical leakage is much much lower)
 
Last edited:
  • #916
Hiddencamper said:
The original design was just the IC.

The IC has no injection capability though, which for long term events is important.

This is another thing which baffles me: the unexplicable desire to keep RPV pressurized. *Of course* you will have difficulty ensuring that RPV water level is high enough if it is pressurized. One, pressurized tanks want to leak. Two, pressurized tanks are difficult to pump water into. Conversely, pumping water into a RPV which is at 1 atm is piece of cake.

What's up with this... er... peculiar desire to keep RPV pressurized (and hot) during accidents? Shouldn't the opposite be done?
 
  • #917
nikkkom said:
What's up with this... er... peculiar desire to keep RPV pressurized (and hot) during accidents? Shouldn't the opposite be done?
There was a document linked somewhere back (years ago) about simulated results of handling a complete SBO on GE MK-I containment. As I recall that went exactly on the same way as you. The sooner the PCV depressurized is the better.

However, this contradicts the actual way of thinking about containing an accident with multiple barriers, even if with this the accident might end in a steam bomb slowly pumping up.
 
  • #918
Rive said:
There was a document linked somewhere back (years ago) about simulated results of handling a complete SBO on GE MK-I containment. As I recall that went exactly on the same way as you. The sooner the PCV depressurized is the better.

However, this contradicts the actual way of thinking about containing an accident with multiple barriers, even if with this the accident might end in a steam bomb slowly pumping up.

Cooldown is obviously the best way to protect the vessel long term, however an emergency blowdown or cooldown in excess of the ASME code limit has the potential for putting severe stress on the RPV and potentially causing a LOCA. Additionally, pressure changes will affect your water level instruments and make it very hard to control level. For this reason the EOPs direct stabizing pressure and level. Pressure should be stabilized within the 100 degF per hour cooldown limit and held as constant as possible, then level should be stabilized between the high and low water level trips. Once you have everything stabilized you commence a controlled cooldown. You're looking to minimize the challenges to level and pressure control, while also minimizing thermal stress or damage to the RPV. The stresses imposed on the RPV are huge during a blowdown, and the EOPs recognize this by not allowing you to exceed the cooldown limit unless the fuel or containment are challenged, where the risk to the public is larger by keeping the vessel hot than it is to blowdown and potentially have a LOCA.

As for level and pressure: when an srv opens up, you get a 25-35 inch spike in level, due to the swell effect, which continues to grow. The whole time you are losing inventory, with false high water level readings. This can cause your injection sources to trip off on high level. Then when the srv is closed, the shrink can cause another low level scram or ECCS injection signal. It's difficult to control. Additionally if you start rapidly cooling down, you need substantial inventory makeup to deal with inventory loss through steam relief and the water shrink during the cooldown. Something like IC provides no inventory. RCIC does, however it's nominal flow rate is 450-600 gpm, and it does not have sufficient makeup capability for the first 10-15 minutes, and until you let decay heat die a little RCIC doesn't have enough flow to support a rapid cooldown. You would have to rely on ECCS, which stresses your vessel nozzles and can damage fuel (either through foreign material in the suppression pool, or for plants with in-shroud ECCS water impingement on fuel bundles). So there's all these factors that have to be weighed. What we have done, is when we had to cooldown, we let decay heat die for an hour or two, use that time to take care of the secondary, then start cooling down. When you aren't fighting substantial decay heat, it's much easier to control. Also, at lower pressures, a single relief valve is going to pass less steam flow due to lower driving head, so you end up keeping relief valves open longer to achieve any meaningful depressurization which results in larger pool heat ups and larger makeup requirements. Above 500 psig, a single relief valve can almost always handle all decay heat. But below that, you'll need to cycle multiple relief valves which is outside of the containment and relief valve sparger loading analysis. It's assumed in the containment safety analysis that the only time you'll have multiple relief valves opening up for design basis events is during the initial load reject, after that only a single relief valve will be used which minimizes acoustic/water/structural loading on the suppression pool.

If condenser/Feedwater is available you can easily and rapidly cooldown. And in fact BWR procedures will demand a pretty quick cooldown to 500 psig to minimize thermal stress on the Feedwater nozzles, even if a hot restart is coming. But when you are isolated, the faster you move pressure, the harder it is to control the rest of the plant. Staying hot means you keep your steam driven injection sources, have more controllability, minimize stress on the vessel, and avoid spurious trips on your injection systems.

As for SBO, since it's only a 4 or 8 hour event per the design basis, you don't want to depressurize, as this adds heat to containment that can't be removed and also thermally challenges RCIC. Eventually, for long term coping, you either need to restore RHR HX, or wait until the last minute to blow down then reflood with fire pumps and seawater. Typically the suppression pool heat capacity is going to drive you to blowdown, not level, as RCIC/HPCI/HPCS operation is assumed for the coping duration.
 
  • Like
Likes Rive and jim hardy
  • #919
Thank You Hiddencamper for sharing your expertise.

Rive said:
There was a document linked somewhere back (years ago) about simulated results of handling a complete SBO on GE MK-I containment. As I recall that went exactly on the same way as you. The sooner the PCV depressurized is the better.
I'll see if i can find that document i know i have a copy on disk but the link would be betterEDIT found one of them

NUREG/CR-5869 is 214 pages
http://web.ornl.gov/info/reports/1992/3445603689514.pdf

it expands on an earlier one that's far shorter and of course less detailed. will try to track it down, it's easier for us non-BWR folks to absorb

i think this is the one i remember ( it's been five years already ?)
http://www.iaea.org/inis/collection/NCLCollectionStore/_Public/24/072/24072657.pdf
old jim
 
Last edited by a moderator:
  • #920
Hiddencamper said:
... per the design basis...
Thank you very much for the long explanation.

Regarding the relevance of that document: as I recall it was really about the old GE MK-I containment, designed with a very different, far less demanding design basis. Interesting to see this as kind of historical context of reactor evolution. Actually, as I take it your detailed explanation and reasoning is kind of a result of the experience and simulations on that old design, and the next step (ESBWR?) is already knocking on the door - with the IC brought back in large.
 
  • #921
Hiddencamper said:
There's no allowable way in the emergency operating procedures to get there in this scenario.
Operation per the EOP is relevant to looking backward and possibly laying blame on operators at this point. That's not of interest to me. I'm interested in what's possible, period, given this BWR, to stop or mitigate the follow-on accident with respect to cooling before loss of power. Given the decay power, it does not superficially appear to me that any amount of cooling for an hour was going to stop the core from eventually becoming uncovered.
 
  • #922
mheslep said:
it does not superficially appear to me that any amount of cooling for an hour was going to stop the core from eventually becoming uncovered.
Only if you get pressure down to point some pump , perhaps a portable engine driven one, can inject makeup.
 
  • #923
Hiddencamper said:
...

Remember that compared to a PWR, where the turbine driven aux feed loses inventory to the atmosphere and will eventually run out, BWRs never lose inventory. If the containment is being vented, you can remove all decay heat that way and never lose RCIC. There are trade offs between various designs. But due to Recirculation seal leakage during loop events, the IC alone will eventually not be sufficient as water level slowly drops. Loop design leakage is close to 50 gpm, or 1 inch every 4 minutes. Given there's 200 inches of inventory, the IC is not going to protect the core for these events. ...

HC, can you expand on that if you have a moment? How is 6MW of decay heat on the first day after scram transferred by venting, given a LOC?
 
  • #924
jim hardy said:
Only if you get pressure down to point some pump , perhaps a portable engine driven one, can inject makeup.
"Some pump"? How does this apply in the Fukushima context? The backup diesel pump power drowned. Did your nuke have secret aux pumps and portable diesels stored separately from the main diesel backup?
 
  • #925
Rive said:
Thank you very much for the long explanation.

Regarding the relevance of that document: as I recall it was really about the old GE MK-I containment, designed with a very different, far less demanding design basis. Interesting to see this as kind of historical context of reactor evolution. Actually, as I take it your detailed explanation and reasoning is kind of a result of the experience and simulations on that old design, and the next step (ESBWR?) is already knocking on the door - with the IC brought back in large.

The IC is probably the only real passive cooling solution for light water reactors. The AP1000 essentially uses an IC, which dumps heat to the containment and relies on containment cooling to get that heat to the UHS. The ESBWR uses 4 ICs for the reactor, and I believe 2 for the containment, for design basis load rejects and accidents. With any 3 ICs in service, you should never have to lift relief valves after the initial load reject/MSIV closure. Combined with the non-safety Reactor Water Cleanup system in Shutdown-Cooling mode, the plant will automatically cool to cold shutdown if the operator takes no manual actions following the reactor scram.

What's nice about ICs is that you can fill them up using just about anything. Obviously demineralized water is preferred, but go ahead and dump lake water in if you have to, it's only operating at boiling point, so it's not going to be wrecked like an RPV will be.

As for BWR Mark I/II/III containment, the Mark I was originally qualified looking at just the line rupture. But they later found issues with long term accidents, issues with the "Swell zone" for the suppression pool (the blowdown from a LOCA or ADS actuation would cause a huge swell in pool level and large loads on the suppression chamber). This required substantial re-analysis and upgrades to the design basis requirements for the containment. Even the Mark III, designed with most of this in mind already, found new issues in the 1/4 scale LOCA test facility, several of which had backfit applications to Mark I/II containments.
 
  • #926
mheslep said:
Operation per the EOP is relevant to looking backward and possibly laying blame on operators at this point. That's not of interest to me. I'm interested in what's possible, period, given this BWR, to stop or mitigate the follow-on accident with respect to cooling before loss of power. Given the decay power, it does not superficially appear to me that any amount of cooling for an hour was going to stop the core from eventually becoming uncovered.

Even if you violated all EOPs and performed a full emergency blowdown and cooled to 200 degF in the first hour, there was sufficient decay heat to damage the unit 1 core. You would have bought some time, maybe enough to recognize something was wrong, but the only real "solution" I personally could have seen was if HPCI was capable of being started and placed in service, you may have bought enough time to get some type of effective response, similar to the Daini site.
 
  • #927
mheslep said:
HC, can you expand on that if you have a moment? How is 6MW of decay heat on the first day after scram transferred by venting, given a LOC?

What we've learned is that RCIC can really run continuously up to at least 248 degF, which is well above atmospheric boiling point.

The decay heat is going to raise reactor pressure. To maintain pressure, heat from the reactor is transferred to the suppression pool using SRVs and RCIC turbine steam discharge. The pool heats up, and gets pumped back into the reactor. With no RHR HX in service, the pool eventually saturates, and the steam added to the suppression pool will raise containment pressure if it is sealed. If you commence venting at this point (assuming no fuel failure and atmospheric release rates would be in acceptable limits) then rather than raising containment/drywell pressure, you would simply be venting decay heat out the vent. You would lose pool inventory at this time, but you could operate RCIC until the suppression pool was almost entirely drained. You could make up to the suppression pool with almost any injection pump (fire pumps) to continue RCIC operation.

Old EOPs didn't allow this as once the suppression pool HCL was reached you were required to blowdown. New EOPs recognize that you may be relying solely on steam powered cooling systems, and allow you to perform a partial blowdown to continue to use steam driven cooling systems to avoid a transition to Severe accident management procedures.
 
  • #928
mheslep said:
"Some pump"? How does this apply in the Fukushima context? The backup diesel pump power drowned. Did your nuke have secret aux pumps and portable diesels stored separately from the main diesel backup?

US plants did have diesel driven pumps after 9/11. Japan did not, and even said they should have considered implementing portions of the US's b5b program for extensive damage mitigation after Fukushima occurred.
 
  • #929
mheslep said:
"Some pump"? How does this apply in the Fukushima context? The backup diesel pump power drowned. Did your nuke have secret aux pumps and portable diesels stored separately from the main diesel backup?

Actually we did.
Fittings to connect a portable diesel driven high pressure pump for seal injection
A feedwater line from the adjacent fossil plants
an emergency AC tie to five more similar diesels in adjacent fossil plant

not credited in accident analyses , but comforting

ties to adjacent fossil plant were eventually removed as plant upgrades progressed

old jim
 
Last edited:
  • #930
jim hardy said:
NUREG/CR-5869 is 214 pages
http://web.ornl.gov/info/reports/1992/3445603689514.pdf

it expands on an earlier one that's far shorter and of course less detailed. will try to track it down, it's easier for us non-BWR folks to absorb

i think this is the one i remember ( it's been five years already ?)
http://www.iaea.org/inis/collection/NCLCollectionStore/_Public/24/072/24072657.pdf
These are quite interesting studies. The Japanese Fukushima reports also mention two papers on hydrogen explosions outside of primary containment, which they consider obscure (one modelling Olkiluoto NPP in Finland and the other Browns Ferry NPP). It appears a lot of theoretical work on severe accident mitigation was simply overlooked or at least not integrated to EOPs. Some of that was even Japanese experiences, such as using plant fire department fire engines for core injection, provisions which had been prepared after earthquake damage to other plants, but formal procedures apparently had not been updated to Fukushima EOP.

A completely another question is that even if there had been much more extensive formal severe accident mitigation guidance available, would they have really implemented it? One of the main human factors issues identified by the Japanese reports, especially the Cabinet ones, is the comparison of how F-2 managed the crisis by always being one step ahead of things. They always had a Plan A in action, while preparing for Plan B to be implemented immediately should there be indication of Plan A failure. And when they were switching Plan A, they tested the viability of implementation of the entire new plan several times before actually carrying the switch over.

In contrast in F-1 this was never achieved when it became obvious that RHR and other sea water reliant systems were going to be out of operation for days. After that, there was over reliance on Plan A continuing to work despite lack of monitoring data and Plan B formulation only started when information came in putting Plan A viability in doubt, sometimes only after several misunderstandings and delays in information flow.

If we accept for Unit 1 that IC in the heavily degraded condition with the internal isolation valves partially closed would not have delayed core uncovery sufficiently for work to fully restore it, even if all PCV external valves had been opened for both trains, and that there was insufficient 125VDC power to start HPCI, then it appears the logical course of action would have been to implement the fire cistern->fire engine->FP system->core spray and car batteries to the MRC for SRV remote manual depressurisation plan ASAP. The question if enough time was available for this would have to look at how long implementing the individual parts of this work took at later stages of the crisis, but with the same resources available.

It appears the biggest problems and longest delays in the accident response all came after the hydrogen explosions and when radiological conditions had degraded both inside key buildings and outside in close vicinity. Another system that took very long time to get to work was SC venting arrangements, which at the end still was only partially successful for Units 1 and 3, being unsuccessful for Unit 2 despite almost a day of trying. In F-2 it was undestood early that any work inside the RBs, including manual valve actuations should be done proactively with anticipated not forced need. They also lined up venting paths, without the need to ever use them. The same was also understood in F-1, but apparently only after observing how things had already gone sour in Unit 1.

Venting however should not have been needed for Unit 1 until many hours or couple days, had core cooling being restored before severe damage, considering how long the other units went with RCIC.
 
Last edited by a moderator:

Similar threads

  • · Replies 5 ·
Replies
5
Views
4K
  • · Replies 14K ·
473
Replies
14K
Views
4M
  • · Replies 12 ·
Replies
12
Views
49K
  • · Replies 5 ·
Replies
5
Views
6K
  • · Replies 6 ·
Replies
6
Views
16K
  • · Replies 5 ·
Replies
5
Views
3K
  • · Replies 3 ·
Replies
3
Views
4K
  • · Replies 16 ·
Replies
16
Views
4K
  • · Replies 763 ·
26
Replies
763
Views
275K
  • · Replies 1 ·
Replies
1
Views
3K