8/10/71SAFETYGUIDE6INDEPENDENCEBETWEENREDUNDANTSTANDBY(ONSITE)POWERSOURCESANDBETWEENTHEIRDISTRIBUTIONSYSTEMSA.IntroductionGeneralDesignCriterion17requiresthatonsiteelectricalpowersystemshavesufficientindependencetoperformtheirsafetyfunctionsassumingasinglefailure.Thissafetyguidedescribesanacceptabledegreeofindependencebetweenredundantstandby(onsite)powersourcesandbetweentheirdistributionsystems.Thisguidedoesnotaddressthesuitabilityofnearbyhydroelectric,nuclear,orfossilunitsasstandbypowersourcesatmultiple-unitsites.Thismatterwillbeevaluatedonanindividualcasebasis.B.DefinitionsPreferredPowerSystem:Theoffsiteexternalcommercialpowersystem.StandbyPowerSystem:Thoseonsitepowersourcesandtheirdistributionequipmentprovidedtoenergizedevicesessentialtosafetyandcapableofoperationindependentlyofthepreferredpowersystem.StandbyPowerSource:Anelectricalgeneratingunitandallnecessaryauxiliaries,usuallyadieselgeneratorset,whichispartofthestandbypowersystem.LoadGroup:Anarrangementofbuses,transformers,switchingequipment,loads,etc.,fedfromthesamepowersource.C.DiscussionThereisevidencebasedonoperatingexperienceandanalyticalconsiderationsthattheparalleloperationofstandbypowersourcesrendersthemvulnerabletocommonmodefailures.Currentdesignsarethereforebasedontheconceptofindependent,redundantloadgroups.Inthesedesigns,thestandbypowersourceforoneloadgroupisneverautomaticallyinterconnectedunderaccidentconditionswiththestandbypowersourceofaredundantcounterpart.Therecanalsobecompromisesofindependenceresultingfromautomaticbusties(botha-candd-c)whichconnecttheloadsofoneloadgrouptothepowersourceofanotherintheeventthepowersourceofthefirstloadgrouphasfailed.Theslightlyimproveddefenseagainstrandomfailuresachievedbythesebustiesismorethanoffsetbytheadditionalvulnerabilitytocommonmodefailureswhichtheycreate.Aspecialcaseoftheforegoingisthebusthatisautomaticallytransferredtooneortheotheroftworedundantstandbypowersources;thisiscommonlyreferredtoasaswingbus.Thisarrangementalsocompromisestheindependenceofredundantpowersourcesandtheirloadgroupswhileaddinglittletothedefenseagainstrandomsinglefailures.Theinclusionofaswingbusinanotherwisewelldesignedsystemoftenresultsfromanincompatibilitybetweenthenumberofstandbypowersources(whethera-cord-c)andthenumberofredundantloadgroups.Forexample,anengineeredsafetyfeaturesystemdesignwhichdependsontheoperationofatleasttwoofthreeelectricallydrivenpumpsandwhichderivespowerfromeitheroftworedundantstandbypowersourcesmustprovidefortheswingingofoneofthethreepumpmotorsinordertomeetthesinglefailurecriterion.Acompatibledesign,suchasonebasedonthree'powersources,wouldnotutilizetheswingfeature.Thenecessityforaswingbuscanalsoresultfromanincompatibilitybetweenthea-candd-cpowersourcesthemselves.Anexamplewouldbeathreedieselgenerator,threebussystemutilizingd-ccontrolcircuits.Ifonlytwo5.1d-csourcesareprovided,theswitchingofdieselgeneratorcontrolcircuitsbetweenthed-csourcesbecomesnecessaryinordertoprovidethenecessaryredundancy.Again,acompatibledesignsuchasonebasedonthreed-csources,oneforeachgenerator,wouldnotutilizeaswingbus.Adieselgeneratorthatswingsbetweentheloadgroupsofdifferentunitsatamultipleunitsiteisnotanexampleoftheforegoingsincesuchloadgroupsarenotredundanttoeachother.D.RegulatoryPosition1.Theelectricallypoweredsafetyloads(a-candd-c)shouldbeseparatedintoredundantloadgroupssuchthatlossofanyonegroupwillnotpreventtheminimumsafetyfunctionsfrombeingperformed.2.Eacha-cloadgroupshouldhaveaconnectiontothepreferred(offsite)powersourceandtoastandby(onsite)powersource(usuallyasingledieselgenerator).Thestandbypowersourceshouldhavenoautomaticconnectiontoanyotherredundantloadgroup.Atmultiplenuclearunitsites,thestandbypowersourceforoneloadgroupmayhaveanautomaticconnectiontoaloadgroupofadifferentunit.Apreferredpowersourcebus,however,mayserveredundantloadgroups.8.Eachd-cloadgroupshouldbeenergizedbyabatteryandbatterycharger.Thebattery-chargercombinationshouldhavenoautomaticconnectiontoanyotherredundantd-cloadgroup.4.Whenoperatingfromthestandbysources,redundantloadgroupsandtheredundantstandbysourcesshouldbeindependentofeachotheratleasttothefollowingextent:a.Thestandbysourceofoneloadgroupshouldnotbeautomaticallyparalleledwiththestandbysourceofanotherloadgroupunderaccidentconditions;b.Noprovisionsshouldexistforautomaticallyconnectingoneloadgrouptoanotherloadgroup;c.Noprovisionsshouldexistforautomaticallytransferringloadsbetweenredundantpowersources;d.Ifmeansexistformanuallyconnectingredundantloadgroupstugether,atleastoneinterlockshouldbeprovidedtopreventanoperatorerrorthatwouldparalleltheirstandbypowersources.5.Asinglegeneratordrivenbyasingleprimemoverisacceptableasthestandbypowersourceforeacha-cloadgroupofthesizeandcharacteristicstypicalofrecentapplications.Ifotherarrangementssuchasmultipledieselgeneratorsoperatedinparallelormultipleprimemoversdrivingasinglegeneratorareproposed,theapplicantshoulddemonstratethattheproposedarrangementhasanequivalentreliability.Commonmodefailuresaswellasrandomsinglefailuresshouldbeconsideredintheanalysis.6.2