<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Safety-critical Certification of FPGA-based Platform against Requirements of U.S. Nuclear Regulatory Commission (NRC): Industrial Case Study</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vladimir Sklyar</string-name>
          <email>vvsklyar@ukr.net</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aerospace University “KhAI”</institution>
          ,
          <addr-line>Kharkiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <fpage>21</fpage>
      <lpage>24</lpage>
      <abstract>
        <p>Instrumentation and Control systems play important role in operation and maintenance of Nuclear Power Plants. A challenge in such systems implementation is certification and licensing against national safety regulatory requirements. A considered case describes certification of Instrumentation and Control platform of Ukrainian company Radiy against the United States nuclear safety requirements. General framework is described. Research activities of the project are presented.</p>
      </abstract>
      <kwd-group>
        <kwd>certification</kwd>
        <kwd>licensing</kwd>
        <kwd>FPGA</kwd>
        <kwd>NPP I&amp;C system</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>Nuclear energy is still one from the essential sources in energy agenda of many
countries. In Ukraine, for example, up to 50% of energy is generated at Nuclear
Power Plants (NPP). Instrumentation and Control (I&amp;C) systems play important role in
NPP safety and security assurance as well as in effective control of energy
production. Safe and cost-effective operations of NPPs require the modernization of I&amp;C
systems to cope with obsolescence and age-related degradation. A computation core
of the most parts of I&amp;C systems are generic programmable platform also named as</p>
      <sec id="sec-1-1">
        <title>Programmable Logic Controllers (PLCs) [1].</title>
        <p>Research and Production Corporation (RPC) Radiy (Kirovograd, Ukraine) has a
long history of working with operating NPPs and installing new I&amp;C systems during
turn-key projects. RPC Radiy provides a wide variety of I&amp;C solutions ranging from
full-scope turn-key modernization projects to reverse engineering and printed circuit
board-level. Also like-for-like replacements and equipment to solve ageing and
obsolescence problems are implemented for both safety and non-safety applications. RPC
Radiy uses Field Programmable Gate Array (FPGA) technology in its digital platform
to implement customized solutions for NPPs I&amp;C systems. RPC Radiy’s proven
technological expertise has been demonstrated in over 100 systems installed to date.</p>
        <p>
          - 130
RPC Radiy’s I&amp;C systems have been installed in safety related systems of all
operating NPP sites in Ukraine and Bulgaria [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>
          FPGA-based safety I&amp;C platform RadICS is the main product of RPC Radiy. The
RadICS Platform is designed to be functionally and physically similar to currently
installed I&amp;C systems. Such platform capabilities include input processing,
customizable control logic, and output processing. The RadICS Platform continuously
monitors system status through signals that are received from field sensors. It performs
logic computations to create control commands. It also converts control commands to
output signals that are applied to field actuators. The RadICS Platform has a modular
and scalable design that can be configured to meet the needs of safety I&amp;C
applications in NPPs [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ].
        </p>
        <p>A big part of efforts to provide I&amp;C systems for utility is licensing efforts. I&amp;C
systems have to comply with state-of-the-art standards. A licensing permission
process lies in consideration of appropriate documentation related with I&amp;C system
design. A challenge is each country has its own set of regulation requirements. So I&amp;C
vendors face to make a new licensing case with penetration to any new market. For
I&amp;C vendors there are the most challenging licensing barriers at the United States
(U.S.) nuclear market. From the one hand the U.S. operate more than one hundred
reactors what is the biggest nuclear fleet in the world. From the other hand the U.S.
Nuclear Regulatory Commission (NRC) implements one form the strongest
regulatory framework in the word, and it is a reason why the biggest part of the nuclear
community respects the U.S. NRC licensing permission.</p>
        <p>In 2015 RPC Radiy started a project to certify RadICS platform against the U.S.
NRC requirements. This paper contains description of the project framework and
states some obtained results.</p>
        <p>An essential part of the mentioned certification process is a deep
UniversityIndustry Cooperation (UIC) conducted between RPC Radiy and National Aerospace
University (Kharkiv, Ukraine). Academicians are involved in all parts of RadICS
platform certification what is one from the main factor of successful project running.
Conclusion of this paper contains a list of researches directed to support of industrial
certification activities.</p>
        <p>Available references in the investigated area are mainly technical reports available
from the U.S. NRC documentation system ADAMS
(www.nrc.gov/readingrm/adams.html).</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>2 FPGA-based I&amp;C Safety Platform RadICS</title>
      <p>The RadICS Platform is a state-of-the-art digital product specifically designed for
safety-related control and protection systems of NPPs. A modular and distributed
FPGA-based architecture is one from the RadICS Platform features. There is a set of
general purpose building blocks (modules) that can be configured and used to
implement application specific functions of I&amp;C systems (see Fig. 1).</p>
      <p>The basic architecture of the RadICS Platform consists of instrument chassis
containing a logic module, as well as up to 14 other Input/Output (I/O) and fiber optic
communication modules. Logic module gathers input data from input modules,
execute application specific logic, and update the value driving the output modules.
Logic module is also responsible for gathering diagnostic and general health information
from all I/O modules. The I/O modules provide interfaces with field devices (e.g.,
sensors, transmitters, and actuators). The functionality of each module is defined by
the logic implemented in the FPGA that are part of the above modules. The backplane
of the RadICS Platform provides interfaces to power supplies, process I/Os,
communication links, and indicators. The internal backplane provides interfaces to the
various modules installed within each chassis by means of a dedicated, isolated,
point-topoint low voltage differential signaling (LVDS) interface.</p>
      <p>Field
Transmitters</p>
      <p>Field
Actuators</p>
      <p>Input
Terminals
Discrete and
Analog Input</p>
      <p>Signals
Processing
Modules</p>
      <p>MCU
(FPGA)</p>
      <p>Control Logic</p>
      <p>Module
MCU
(FPGA)
Internal Data Bus</p>
      <p>Output
Terminals
Discrete and
Analog Output</p>
      <p>Signals
Processing
Modules</p>
      <p>MCU
(FPGA)</p>
      <p>For application development, RPC Radiy provides a tool called Radiy Product
Configuration Toolset (RPCT). This tool can be used to configure logic for various
applications using the Application Functional Block Library (AFBL).</p>
      <p>In addition, the RadICS Platform includes extensive on-line self-surveillance and
diagnostics at various levels, including control of FPGA power, watchdog timer,
cyclical redundancy check (CRC) calculations, and monitoring of the performance of</p>
      <sec id="sec-2-1">
        <title>FPGA support circuits, I/O modules, communications units, and power supplies.</title>
        <p>Safety Life Cycle (LC) of the RadICS Platform is presented on Fig. 2. The RadICS
Platform LC implements specific stages of FPGA design development and
verification. Specific technique of fault insertion testing has been performed for both
hardware and software parts. This LC complies with requirements traceability concept
which requested the following:
 Every requirement has a child (either a lower level requirement or a solution);
 Every lower level requirement or solution has a higher level requirement (and
opposite, an orphan represents unjustified functionality);
 Every requirement has been tested.</p>
        <p>- 132</p>
        <p>Technical
Specification</p>
        <p>Architecture</p>
        <p>Design</p>
        <p>Detailed
Design
Units
Modules</p>
        <p>Hardware</p>
        <p>Design</p>
        <p>FMEA
Report</p>
        <p>Validation</p>
        <p>TP&amp;S
Integration</p>
        <p>TP&amp;S
Fault Insertion</p>
        <p>TP&amp;S
Functional</p>
        <p>TP&amp;S
FMEA – Failure Mode and Effect Analysis
TP&amp;S – Test Plan and Specification
TR – Test Report</p>
        <p>Code</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3 General Approach to Certify I&amp;C Safety Platform in the U.S.</title>
      <p>Firstly RPC Radiy established RadICS in 2012, as a wholly owned Limited
Liability Company (LLC). The Company RadICS business focus is the design and delivery
of I&amp;C systems for NPPs using the RadICS Platform equipment. Company RadICS,
based together with RPC Radiy in Kirovograd, Ukraine, is responsible for all
RadICS-based application project activities except the manufacturing of the RadICS
Platform equipment. Such approach allows to focus certification efforts only on target
processes for safety assurance.</p>
      <p>After that the basic U.S. licensing strategy is to demonstrate that the generic
RadICS Platform and the associated quality and software life cycle processes comply
with U.S. nuclear safety requirements. As it is mentioned above, the RadICS Platform
has been already licensed in Ukraine and Bulgaria. Difference of the U.S. regulatory
requirements was analyzed. Licensing activities workflow was built on the base of
results of such analysis, as it is shown it Table 1.</p>
      <p>Actions to demonstrate compliance with the U.S. licensing requirements are
presented at Fig. 3. An umbrella document for licensing activities is the Topical Report.</p>
      <sec id="sec-3-1">
        <title>Some details of the RadICS Topical Report are discussed in the next part.</title>
        <p>It should be noticed, the U.S. NRC requires conducting technical meetings for
discussion of the provided documents. Since the U.S. NRC has a specific philosophy of
I&amp;C systems consideration, additional research have been performed to fulfill this gap
(see the Conclusions).</p>
        <p>Validation</p>
        <p>TR
Integration</p>
        <p>TR</p>
        <p>Fault
Insertion TR
Functional</p>
        <p>TR
Logic Level
Simulation
&amp; Timing
Simulation</p>
        <p>TR
Static</p>
        <p>Timing
Analysis TR
Static Code
Analysis</p>
        <p>Report
- 133</p>
      </sec>
      <sec id="sec-3-2">
        <title>Difference in requirements</title>
      </sec>
      <sec id="sec-3-3">
        <title>The U.S. NRC requires to</title>
        <p>implement a specific Quality</p>
      </sec>
      <sec id="sec-3-4">
        <title>Management Program (QMS) in accordance with regulations 10 CFR Part 50 Appendix B</title>
      </sec>
      <sec id="sec-3-5">
        <title>The U.S. NRC requires to</title>
        <p>implement a specific process
for Commercial Grade
Dedication for as named
commercial components. RadICS</p>
      </sec>
      <sec id="sec-3-6">
        <title>Platform components at the</title>
      </sec>
      <sec id="sec-3-7">
        <title>RPC Radiy site are commercial since they are produced under not nuclear ISO 9001 QMS</title>
      </sec>
      <sec id="sec-3-8">
        <title>The U.S. NRC requires to submit the Topical Report which has to represent the main platform features</title>
      </sec>
      <sec id="sec-3-9">
        <title>The U.S. NRC requires to</title>
        <p>submit a set of documents
which support the Topical</p>
      </sec>
      <sec id="sec-3-10">
        <title>Report argument</title>
      </sec>
      <sec id="sec-3-11">
        <title>The U.S. NRC requires to provide a representative (QTS)</title>
      </sec>
      <sec id="sec-3-12">
        <title>The U.S. NRC requires to perform a set of qualification tests for the QTS</title>
      </sec>
      <sec id="sec-3-13">
        <title>Actions to meet requirements</title>
      </sec>
      <sec id="sec-3-14">
        <title>Establish RadICS QMS in compliance with the</title>
      </sec>
      <sec id="sec-3-15">
        <title>U.S. NRC requirement. It should be noted U.S.</title>
      </sec>
      <sec id="sec-3-16">
        <title>NRC requirements to QMS are different from</title>
        <p>widely used ISO 9001 QMS, so many efforts are
spent to adopt specific requirements in accordance
with regulations 10 CFR Part 50 Appendix B
“Quality Assurances Requirements for Nuclear</p>
      </sec>
      <sec id="sec-3-17">
        <title>Power Plants and Fuel Reprocessing Plants” and</title>
      </sec>
      <sec id="sec-3-18">
        <title>ASME NQA-1-2008, “Quality Assurance Program</title>
      </sec>
      <sec id="sec-3-19">
        <title>Requirements for Nuclear Facilities”. The RadICS</title>
      </sec>
      <sec id="sec-3-20">
        <title>QMS governs the system design, integration, and</title>
        <p>delivery of I&amp;C systems for NPPs using the</p>
      </sec>
      <sec id="sec-3-21">
        <title>RadICS Platform equipment</title>
      </sec>
      <sec id="sec-3-22">
        <title>Dedicate the generic RadICS Platform, which was</title>
        <p>not originally developed under a 10 CFR Part 50</p>
      </sec>
      <sec id="sec-3-23">
        <title>Appendix B QMS, in accordance with the basic</title>
        <p>requirements for Commercial Grade Dedication.</p>
      </sec>
      <sec id="sec-3-24">
        <title>RadICS is employing the commercial dedication</title>
        <p>processes described in Electric Power Research</p>
      </sec>
      <sec id="sec-3-25">
        <title>Institute (EPRI) Technical Report (TR)-107330</title>
        <p>“Generic Requirements Specification for
Qualifying a Commercially Available PLC for
Safety</p>
      </sec>
      <sec id="sec-3-26">
        <title>Related Applications in Nuclear Power Plants” and</title>
      </sec>
      <sec id="sec-3-27">
        <title>EPRI TR-106439 “Guideline on Evaluation and</title>
      </sec>
      <sec id="sec-3-28">
        <title>Acceptance of Commercial Grade Digital Equip</title>
        <p>ment for Nuclear Safety Applications”</p>
      </sec>
      <sec id="sec-3-29">
        <title>Develop the RadICS Topical Report. The purpose</title>
        <p>of the RadICS Topical Report is to demonstrate
that the RadICS Platform and the associated
quality and programmable logic life cycle process
comply with NRC requirements</p>
      </sec>
      <sec id="sec-3-30">
        <title>Submit to the U.S. NRC the RadICS Topical Re</title>
        <p>port with sets of relevant documents. These
documents have to be submitted in three phases. The
main part of such documents have been already
developed before</p>
      </sec>
      <sec id="sec-3-31">
        <title>Design, produce and dedicate from RPC Radiy the</title>
      </sec>
      <sec id="sec-3-32">
        <title>Qualification Test Specimen (QTS) with the with</title>
        <p>the Data Acquisition System (DAS)</p>
      </sec>
      <sec id="sec-3-33">
        <title>Perform QTS Equipment Qualification Testing in one from the U.S. testing laboratory recognized by NRC</title>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4 Content of the Topical Report</title>
      <p>The RadICS Topical Report is the summary licensing document for the RadICS
Platform digital safety I&amp;C platform. It presents design, performance, and
qualification information for the RadICS digital safety I&amp;C platform developed by RPC
Radiy. The RadICS Platform is a generic digital safety I&amp;C platform dedicated to the
implementation of Class 1E (the highest safety class) safety I&amp;C functions in the U.S.</p>
      <sec id="sec-4-1">
        <title>NPPs.</title>
        <p>The RadICS Topical Report has been divided into 12 chapters and 3 appendices
(see Fig. 4). The most important issues of this Topical Report are the following:
 An overview of RadICS development and operational use in international NPPs
where it is currently deployed in a variety of digital safety I&amp;C applications. This
information is provided to illustrate the safety I&amp;C developments that led to the
RadICS Platform;
 An overview of the quality program and the quality process employed to dedicate
the generic RadICS Platform hardware and associated programmable logic and
develop systems for delivery to U.S. customers;
 An overview of the commercial grade dedication program used to dedicate the
generic RadICS Platform hardware and associated platform programmable logic;
 A description of the RadICS Platform operation and how it can be applied in NPP
safety-related applications. It also provides descriptions of the hardware and
associated generic programmable logic that comprise the RadICS Platform. In addition,
details are provided on how digital communications and testability are
implemented in the RadICS Platform;
 A description of the hardware development process with associated planning
documents and component testing process;
 A description of the RadICS Platform generic programmable logic development
life cycle, planning documents, and the verification and validation process. The
RadICS programmable logic life cycle processes were examined in more detail as
part of the functional safety certification;
 An overview of the generic equipment qualification program for the RadICS
Platform. The RadICS qualification “envelope” is designed to meet or exceed the
environmental qualification requirements for NPPs in the U.S.;
 An overview of the RadICS approach to platform diversity;
 A summary of a RadICS Platform vulnerability analysis and the secure
development and operational environment controls provided by RPC Radiy;
 A conformance summary of the RadICS design and development processes for the
key regulatory guidance documents;
 The plant-specific system design guidance for use of the RadICS Platform,
including recommended practices and any restrictions;
 A compliance matrix for the U.S. NRC regulatory document DI&amp;C-ISG-04
“Highly Integrated Control Rooms – Digital Communication Systems” with the
requirement listed as well as RadICS Platform compliance to each criterion defined;
 A list of the RadICS Platform design documents associated with the Electronic
Designs for the RadICS Modules and identifies an initial set of documents planned
for submittal to NRC to support the review of the RadICS Topical Report.</p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5 Conclusions</title>
      <p>
        As well as I&amp;C platform is a high tech product, certification and licensing of such
product requires innovative approach followed with research activities. A good basis
for such researches provides UIC conducted between RPC Radiy and National
Aerospace University. The following research directions have been chosen as priorities to
support safety-critical certification:
 Research in FPGA and design tools safety features to support safe use of FPGA
chip as a logic control core;
 Research in combination of different testing methodology with different coverage
criteria to support effective verification and validation of I&amp;C platform through life
cycle;
 Research in efficient power consumption of I&amp;C platform with optimization of
used algorithms [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ];
 Research in security of I&amp;C platform to protect safety critical application from
malware injection;
 Research in Safety and Security Case [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ] methodology as a tool to support integral
safety evaluation.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sklyar</surname>
            <given-names>V.V.</given-names>
          </string-name>
          (
          <article-title>Edits)</article-title>
          .
          <source>FPGA-based NPP Instrumentation and Control Systems: Development</source>
          and Safety Assessment / Bakhmach E.S.,
          <string-name>
            <surname>Herasimenko</surname>
            <given-names>A.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Golovyr</surname>
            <given-names>V.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.S.</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Rozen</given-names>
            <surname>Yu</surname>
          </string-name>
          .V.,
          <string-name>
            <surname>Siora</surname>
            <given-names>A.A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sklyar</surname>
            <given-names>V.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tokarev</surname>
            <given-names>V.I.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Vinogradskaya</surname>
            <given-names>S.V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yastrebenetsky</surname>
            <given-names>M.A.</given-names>
          </string-name>
          <string-name>
            <surname>Research</surname>
          </string-name>
          and Production Corporation “Radiy”, National Aerospace University named after N.E. Zhukovsky “KhAI”,
          <source>State Scientific Technical Centre on Nuclear and Radiation Safety</source>
          ,
          <year>2008</year>
          . 188 p.
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>Nuclear</given-names>
            <surname>Power</surname>
          </string-name>
          <article-title>Plant Instrumentation and Control Systems for Safety</article-title>
          and Security / Yastrebenetsky M.,
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.</given-names>
          </string-name>
          (Edits). - IGI
          <string-name>
            <surname>Global</surname>
          </string-name>
          .
          <article-title>-</article-title>
          <year>2014</year>
          . - 470 p.
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Multi-Version FPGA-Based Nuclear Power Plant I&amp;C Systems</surname>
          </string-name>
          <article-title>: Evolution of Safety Ensuring by Vyacheslav Kharchenko, Olexandr Siora and Volodymyr Sklyar in the book "Nuclear Power - Control, Reliability and Human Factors" edited by Pavel Tsvetkov</article-title>
          ,
          <string-name>
            <surname>Texas</surname>
            <given-names>A</given-names>
          </string-name>
          &amp;M University, USA ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Kharchenko</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gorbenko</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sklyar</surname>
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Phillips</surname>
            <given-names>C</given-names>
          </string-name>
          .
          <source>Green Computing and Communications in Critical Application Domains: Challenges and Solutions // Proceedings of the 9th Digital Technologies International Conference “DT</source>
          <year>2013</year>
          ”.
          <article-title>-</article-title>
          <string-name>
            <surname>Žilina</surname>
          </string-name>
          , Slovakia, May
          <volume>29</volume>
          -31,
          <year>2013</year>
          . - P.
          <fpage>241</fpage>
          -
          <lpage>247</lpage>
          ,
          <string-name>
            <surname>on</surname>
            <given-names>CD</given-names>
          </string-name>
          <source>-ROM, ISBN 978-80-554- 0682-4.</source>
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>T.</given-names>
            <surname>Kelly</surname>
          </string-name>
          , Arguing Safety:
          <article-title>A Systematic Approach to Managing Safety Cases</article-title>
          ,
          <source>PhD thesis</source>
          , Univ. of York,
          <year>1998</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>