ShelterFactor Radiological Resilience

ShelterFactor knowledge base

Power, Control & Remote Activation

A resilient shelter system should remain controllable when the grid, internet connection or cloud service is unavailable β€” while still allowing secure remote activation when communications are available.

Design objective

The control architecture should be local-first, remote-capable and fail-safe. Remote operation is useful when a radiological incident occurs while occupants are away from home: the protected space can be placed into its defined operating mode before return, where that is appropriate for the scenario. Remote control must not become a dependency for basic operation.

Local-first architecture

  • Local controller: ventilation, valves, pressure control and alarm logic operate without an internet connection.
  • Local controls: occupants can start, stop and select defined modes at the protected space.
  • Manual override: critical functions remain operable if automation fails.
  • Defined default state: behaviour after reboot, communications loss and power restoration is specified rather than left to consumer-device defaults.

Remote activation

A secure remote interface can provide authenticated activation, mode selection and status viewing. A useful remote command is not merely β€œfan on”: the system should return evidence that the requested protective state has actually been achieved.

Status confirmation

  • ventilation running / fault state;
  • measured pressure differential;
  • selected operating mode;
  • mains, battery or other power source;
  • battery state of charge and estimated remaining autonomy;
  • filter or airflow alarms where instrumented;
  • communications health and last successful status update.

Grid-failure operation

Critical shelter loads can be supplied from a home battery, dedicated battery system, UPS or another suitable emergency-power source. The design should isolate the loads that actually preserve protection rather than attempting to keep every household circuit energised.

Typical critical loads

  • filtered ventilation and any actuated dampers or valves;
  • local controller and pressure sensing;
  • selected radiological and environmental monitoring;
  • communications equipment required for status and official information;
  • essential lighting and other explicitly defined shelter loads.

Backup autonomy

A first-order energy balance can be written as:

Tbackup = Eusable battery / (Pvent + Pcontrol + Pmonitoring + Pcomms + Pother critical)

This is only a starting point. Engineering calculations should account for inverter and conversion losses, minimum state of charge, battery degradation, temperature, standby consumption, startup currents, load variation and any energy reserved for other essential functions.

Load shedding

During an outage, non-essential household loads can be disconnected or deprioritised so stored energy is preserved for the protected environment. The transfer from grid to backup supply should be tested with the actual ventilation and control equipment, including restart behaviour.

Failure modes to test

  1. Loss of mains power while the system is operating.
  2. Loss of mains power while the shelter is inactive.
  3. Loss of internet with local network still available.
  4. Loss of all external communications.
  5. Controller or sensor reboot.
  6. Battery inverter transfer and return to mains.
  7. Remote command issued but target pressure not achieved.
  8. Low battery state of charge during an extended event.

Cybersecurity and availability

Remote access increases convenience but also creates an additional attack surface. The remote-control path should use strong authentication, encrypted communications and least-privilege access. Safety-relevant local operation should not depend exclusively on a third-party cloud platform.

Relationship to ShelterFactor metrics

Backup power and control do not directly increase shielding. Their function is to preserve the systems that support PFair and the habitability of the protected environment over time. They therefore contribute principally to Tautonomy and to confidence that the intended protective state is actually maintained.

Assessment output

A ShelterFactor assessment can document the critical-load schedule, backup architecture, remote/local control concept, expected battery autonomy, transfer behaviour, alarm philosophy and commissioning tests. The result should be a defined and testable operating concept rather than a collection of unrelated smart-home devices.