Instrumentation and control (I&C) systems play a crucial role in the operation of nuclear power plants(NPP) and other safety critical processes. An important change is the replacement of the old analogue I&Csystems with new digitalised ones. The programmable digital logic controllers enable more complicatedcontrol tasks than the old analogue systems and thus the validation of the control logic designs against safetyrequirements has become more important. In order to diminish the subjective component of the evaluationthere is a need to develop new formal verification methods. A promising approach is a method called modelchecking, which enables the complete verification of requirements when a finite state machine model of thesystem is available. The use of model checking to verify two nuclear power plant related systems isdescribed: an arc protection system and a reactor emergency cooling system. For the verification, it was alsonecessary to model the operation environment of the device and the larger system it is part of. Theenvironment models could be kept relatively simple, but it is important that the essential behaviour of theenvironment is covered. The reactor emergency cooling system is in use in an operating nuclear power plantand the arc protection system model included a typical realistic operation environment. The results showedthat it was possible to reliably verify the presence of desired behaviour as well as the absence of anundesired behaviour of the system. The possibility for complete verification makes model checking differentfrom simulation-based testing where only a number of selected scenarios can be simulated and one can neverbe sure that all the possible behaviour is covered. The challenges for future research are to develop morededicated methods for the verification of safety critical automation and safety critical embedded software.
[1]
Ilkka Niemelä,et al.
Model-Based Analysis of an Arc Protection and an Emergency Cooling System - MODSAFE 2007 Working Report
,
2008
.
[2]
Edmund M. Clarke,et al.
Model Checking
,
1999,
Handbook of Automated Reasoning.
[3]
Joseph Sifakis,et al.
Specification and verification of concurrent systems in CESAR
,
1982,
Symposium on Programming.
[4]
Marco Pistore,et al.
NuSMV 2: An OpenSource Tool for Symbolic Model Checking
,
2002,
CAV.
[5]
Philippe Schnoebelen,et al.
Systems and Software Verification
,
2001,
Springer Berlin Heidelberg.
[6]
Ilkka Niemelä,et al.
Model-Based Analysis of an Arc Protection and an Emergency Cooling System
,
2008
.
[7]
Edmund M. Clarke,et al.
Design and Synthesis of Synchronization Skeletons Using Branching-Time Temporal Logic
,
1981,
Logic of Programs.
[8]
Jan-Erik Holmberg,et al.
Model-Based Analysis of an Arc Protection and an Emergency Cooling System MODSAFE 2007 Work Report
,
2008
.
[9]
Edmund M. Clarke,et al.
Design and Synthesis of Synchronization Skeletons Using Branching Time Temporal Logic
,
2008,
25 Years of Model Checking.
[10]
Randal E. Bryant,et al.
Symbolic Boolean manipulation with ordered binary-decision diagrams
,
1992,
CSUR.
[11]
Ilkka Niemelä,et al.
NPP Safety Automation Systems Analysis: State of the Art
,
2008
.
[12]
Edmund M. Clarke,et al.
Symbolic Model Checking: 10^20 States and Beyond
,
1990,
Inf. Comput..