Mitigation of Severe Accident Consequences Using Inherent Safety Principles

Sodium-cooled fast reactors are designed to have a high level of safety. Events of high probability of occurrence are typically handled without consequence through reliable engineering systems and good design practices. For accidents of lower probability, the initiating events are characterized by larger and more numerous challenges to the reactor system, such as failure of one or more major engineered systems and can also include a failure to scram the reactor in response. As the initiating conditions become more severe, they have the potential for creating serious consequences of potential safety significance, including fuel melting, fuel pin disruption and recriticality. If the progression of such accidents is not mitigated by design features of the reactor, energetic events and dispersal of radioactive materials may result. For severe accidents, there are several approaches that can be used to mitigate the consequences of such severe accident initiators, which typically include fuel pin failures and core disruption. One approach is to increase the reliability of the reactor protection system so that the probability of an ATWS event is reduced to less than 1 x 10-6 per reactor year, where larger accident consequences are allowed, meeting the U.S. NRC goal of relegating such accident consequences as core disruption to these extremely low probabilities. The main difficulty with this approach is to convincingly test and guarantee such increased reliability. Another approach is to increase the redundancy of the reactor scram system, which can also reduce the probability of an ATWS event to a frequency of less than 1 x 10-6 per reactor year or lower. The issues with this approach are more related to reactor core design, with the need for a greater number of control rod positions in the reactor core and the associated increase in complexity of the reactor protection system. A third approach is to use the inherent reactivity feedback that occurs in a fast reactor to automatically respond to the change in reactor conditions and to result in a benign response to these events. This approach has the advantage of being relatively simple to implement, and does not face the issue of reliability since only fundamental physical phenomena are used in a passive manner, not active engineered systems. However, the challenge is to present a convincing case that such passive means can be implemented and used. The purpose of this paper is to describe this third approach in detail, the technical basis and experimental validation for the approach, and the resulting reactor performance that can be achieved for ATWS events.