Drawing No. EH–702 // Nuclear
An interactive, simplified model of a 300 MW(e) boiling water small modular reactor. Move the control rods, adjust feedwater, and trigger events to see how reactivity feedback, steam generation, the turbine, and the passive safety systems interact in real time. Click any component in the diagram for a description.
Where the plant is operating right now, plotted against the regions where boiling-water flow oscillations become a concern. The marker moves live as you operate the reactor.
Operating point
The shaded regions are not fixed. They are recomputed each moment from reactor pressure and feedwater temperature, so you can watch the safe area shrink when conditions get less favourable — try dragging feedwater temperature down to 20 °C at full power.
Optional reading — open any section below.
A boiling water reactor makes steam directly in the reactor vessel. Water flows upward through the core, where fission heat boils part of it. The resulting steam–water mixture rises through the chimney, passes through separators and dryers at the top of the vessel, and leaves as dry steam through the main steam line.
The steam drives a turbine coupled to a generator, exhausts into a condenser where cooling water condenses it back to liquid, and the condensate is pumped back to the vessel as feedwater. It is a single closed loop — unlike a pressurised water reactor, there is no separate steam generator.
This plant uses natural circulation: there are no recirculation pumps. Coolant is driven around the loop purely by the density difference between the light steam–water mixture rising inside the shroud and the denser water descending in the outer downcomer annulus. That means core flow is not an independent control — it is a consequence of power, which matters a great deal for stability.
Criticality. Reactivity (ρ) measures how far the chain reaction is from exactly self-sustaining. At ρ = 0 the reactor is critical and power is steady. Withdrawing control rods adds reactivity; inserting them removes it. In this model the core reaches criticality near 38% rod withdrawal, and full power is reached at about 85%. Control rods are deliberately not fully withdrawn at rated power: the remaining travel is margin for burn-up, xenon, and power manoeuvring. Withdrawing all the way would give roughly 114% power, above the high-flux trip setpoint.
Why power does not jump. Only about 0.65% of fission neutrons are delayed, emitted seconds to minutes after fission by decaying fission products. That small fraction — the delayed neutron fraction β — is what makes a reactor controllable. As long as ρ stays below β, the reactor period is set by those slow precursors, so power ramps over seconds rather than microseconds. The simulator uses the prompt-jump approximation of point kinetics, which reproduces this behaviour: a small instant step in power followed by a slow exponential ramp.
Why the rods move slowly. Rod motion is rate-limited here to 3.5% per second. Insert reactivity faster than the feedback mechanisms can respond and power overshoots badly. Reaching the full-power rod pattern takes about 25 seconds, but the plant still needs roughly 70 seconds to settle at full power. That remaining time is set by reactor physics, not rod speed: the delayed neutron precursors, the void distribution, and the fuel temperature all have to come to equilibrium. Withdrawing rods faster does not meaningfully shorten it.
Feedback holds it there. Two negative feedbacks stabilise the reactor without operator action. Void feedback: more power means more steam voids in the core, fewer neutrons are moderated, and reactivity falls. Doppler feedback: hotter fuel absorbs more neutrons through resonance broadening, which acts almost instantly. Together they mean the reactor finds its own equilibrium power for a given rod position.
Feedwater is a reactivity control, not just a level control. This surprises people, and it is worth understanding. Core flow in a boiling water reactor is several times the steam flow: water returning saturated from the separators mixes in the downcomer with relatively cold feedwater, and that mixture enters the core. The resulting core inlet subcooling is roughly
ΔTsub ≈ (Wfw / Wcore) × (Tsat − Tfw)
which is about 15 K at rated conditions here. Subcooled water must be heated to saturation before it can boil, so more subcooling pushes the boiling boundary higher up the core and leaves fewer voids. Fewer voids means better moderation, positive reactivity, and rising power.
Notice that the expression contains flow and temperature. Raising feedwater flow makes the core inlet colder just as surely as lowering feedwater temperature does. In this model roughly 1 K of extra subcooling buys about 1% more power, so the full feedwater flow range moves power from about 87% to 116%, and losing feedwater heating entirely can push the reactor past its high-flux trip.
But flow and temperature are not equivalent levers. Feedwater flow must equal steam flow in steady state, otherwise vessel level runs away and the reactor trips on high or low level. Its reactivity effect is therefore inherently a transient one, which is why a feedwater pump trip causes a sharp power reduction. Feedwater temperature can be held indefinitely, so a loss of feedwater heating is a sustained reactivity insertion — and a design-basis transient at real plants for exactly that reason. Switch the level controller to manual and try both.
On a scram, rods insert in a few seconds. Neutron power drops promptly to roughly 15%, then decays over tens of seconds as the delayed precursors die away. What remains is decay heat from radioactive fission products — a few percent of rated power immediately after shutdown, falling slowly over hours and days. It cannot be switched off, which is why the passive cooling system exists.
What the map shows. The horizontal axis is core flow, the vertical axis is reactor power, both as a percentage of rated. Any operating condition is a single point on this plane. Boiling water reactors can exhibit density-wave oscillations: a disturbance in core inlet flow creates a travelling wave of steam voids, which changes the pressure drop, which feeds back on the flow. Add neutronic coupling through void reactivity and the oscillation can reinforce itself.
Decay ratio is the standard measure. It is the ratio of successive peaks in the oscillation after a disturbance. Below 1, each peak is smaller than the last and the oscillation dies out. Above 1, it grows. Plants are operated with margin — typically a decay ratio well under 1 — and the region where that margin is lost is drawn on the map as an exclusion region.
Why it sits in the upper left. Trouble comes from high power combined with low flow. High power means vigorous boiling and a strongly void-dominated core; low flow means a long transit time for those voids, so the feedback lags. Together they make the loop gain large and the phase lag unfavourable.
Why this reactor has its own map. With no recirculation pumps, an operator cannot move horizontally on this plot. Flow follows power along the dashed natural circulation line. The startup guidance that follows from this is simple: raise power gradually and let natural circulation establish, keep the vessel pressurised so steam voids stay small and dense, and avoid very cold feedwater at high power. Each of those is a lever in this simulator, and each visibly moves the decay ratio.
A note on realism. The decay ratio here comes from an illustrative correlation chosen to reproduce the right trends and sensitivities, not from a thermal-hydraulic stability solver. Real stability analysis uses frequency-domain or time-domain codes validated against plant data.
Defence in depth is the organising principle of nuclear safety. Rather than relying on any single barrier or system being perfect, it layers independent provisions so that failure of one is caught by the next: conservative design and inherent feedback first, then control systems, then protection systems, then accident mitigation, and finally emergency response.
Reactor shutdown is the clearest illustration. A boiling water reactor does not have one way to shut down — it has several, built on diverse principles so that a common cause cannot disable all of them at once.
1. Inherent feedback (no system at all). Before any equipment acts, the physics resists. Void and Doppler feedback both oppose a power rise, which is why the reactor in this simulator finds its own equilibrium instead of running away. This is the innermost layer and it cannot fail, because there is nothing to fail.
2. Hydraulic scram — the primary system. Each control rod drive has an accumulator charged with high-pressure water. On a trip signal, scram valves open and that stored energy drives the rods into the core from below in a few seconds. It is fast, and it is fail-safe by design: the accumulators are already charged, so the rods insert on loss of electrical power rather than being held out by it. This is the mechanism the simulator models when you press SCRAM — note the short delay before the rods start moving, which is the signal and valve response time.
3. Electric motor run-in — a diverse backup. The same rods can also be driven in by their electric drive motors, independently of the hydraulic system. This is slower, taking minutes rather than seconds, but it uses different equipment, different energy, and different failure modes. In modern plants this is often automated as alternate rod insertion, deliberately kept separate from the main protection system so that a fault in that system's logic cannot block it.
4. Standby liquid control — diverse in principle, not just in hardware. The systems above all depend on moving control rods. If rods cannot be inserted at all — the classic "anticipated transient without scram" — a completely different physical mechanism is needed. The standby liquid control system pumps a concentrated solution of borated water into the vessel. Boron is a strong neutron absorber, so it shuts the reactor down chemically rather than mechanically. It is slow, taking tens of minutes, and it contaminates the coolant, so it is genuinely a last resort. But it shares no failure mode with the rod systems, which is the entire point.
Why this matters for the rod withdrawal accident. Try the accident scenario in this simulator: a control rod group becomes decoupled and falls clear of the core, inserting positive reactivity in about a second. Power spikes past the high-flux trip setpoint and the reactor scrams — but the dropped group cannot be driven back in, because it is no longer connected to its drive. Shutdown still succeeds here, because the remaining rods carry enough negative worth on their own. That margin is not luck; plants are required to demonstrate that the core can be held subcritical with the single highest-worth rod fully withdrawn. Defence in depth means the answer to "what if this one fails" has already been worked out before it does.
Decay heat is why shutdown is not the end. Stopping fission removes about 93% of the heat. The remaining few percent comes from decaying fission products and cannot be switched off by any shutdown system, which is why the passive cooling loop in this plant exists as its own independent layer.
Description.
Found something wrong with this calculator? Let us know and we'll take a look.