Cargando…

System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection

Subject of the present work is the application of the methods STPA (System Theoretic Process Analysis) and CAST (Causal Analysis based on STAMP) to analyze the protection systems of the superconducting magnet circuit of the LHC at CERN, Geneva. The named methods are derived from the at MIT develo...

Descripción completa

Detalles Bibliográficos
Autor principal: Hugle, Dennis
Lenguaje:eng
Publicado: 2017
Materias:
Acceso en línea:http://cds.cern.ch/record/2297093
_version_ 1780956839728381952
author Hugle, Dennis
author_facet Hugle, Dennis
author_sort Hugle, Dennis
collection CERN
description Subject of the present work is the application of the methods STPA (System Theoretic Process Analysis) and CAST (Causal Analysis based on STAMP) to analyze the protection systems of the superconducting magnet circuit of the LHC at CERN, Geneva. The named methods are derived from the at MIT developed STAMP (System Theoretic Accident Model and Processes) accident model. The CAST method was applied to the analysis of the 2008 Incident during the Hardware Commissioning. An incorrect interconnection between two magnets damaged the accelerator severely. The analysis defines the control structure of the Commissioning and investigates every subsystem and the interaction between the components. The results were social and technical requirements. Among others, it shows the necessity for safety culture at CERN and a revision of the magnet interconnection process. The present analysis found the same root causes for the incident than a task force did in 2009. Further, the CAST analysis found more, socio-technical root causes and defined requirements to eradicate them. The second study concerns the focusing magnets enclosing the CMS and ATLAS experiments (inner triplets), which will be renewed as part of the High Luminosity Upgrade. The STPA analysis investigates the protection mechanisms of these magnets and defines a control structure. The components within this structure communicate with control actions. It is investigated, how these control actions can turn unsafe and what can cause these unsafe control actions. The results include requirements for operational safety, reliability, availability and maintainability. Especially the analysis shows, that an additional supervision unit for surveilling accidental CLIQ Unit triggering is needed. The analysis showed the safety of the protection layout of the inner triplets and added requirements for more dependability.
id cern-2297093
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2017
record_format invenio
spelling cern-22970932019-09-30T06:29:59Zhttp://cds.cern.ch/record/2297093engHugle, DennisSystem Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit ProtectionAccelerators and Storage RingsSubject of the present work is the application of the methods STPA (System Theoretic Process Analysis) and CAST (Causal Analysis based on STAMP) to analyze the protection systems of the superconducting magnet circuit of the LHC at CERN, Geneva. The named methods are derived from the at MIT developed STAMP (System Theoretic Accident Model and Processes) accident model. The CAST method was applied to the analysis of the 2008 Incident during the Hardware Commissioning. An incorrect interconnection between two magnets damaged the accelerator severely. The analysis defines the control structure of the Commissioning and investigates every subsystem and the interaction between the components. The results were social and technical requirements. Among others, it shows the necessity for safety culture at CERN and a revision of the magnet interconnection process. The present analysis found the same root causes for the incident than a task force did in 2009. Further, the CAST analysis found more, socio-technical root causes and defined requirements to eradicate them. The second study concerns the focusing magnets enclosing the CMS and ATLAS experiments (inner triplets), which will be renewed as part of the High Luminosity Upgrade. The STPA analysis investigates the protection mechanisms of these magnets and defines a control structure. The components within this structure communicate with control actions. It is investigated, how these control actions can turn unsafe and what can cause these unsafe control actions. The results include requirements for operational safety, reliability, availability and maintainability. Especially the analysis shows, that an additional supervision unit for surveilling accidental CLIQ Unit triggering is needed. The analysis showed the safety of the protection layout of the inner triplets and added requirements for more dependability.CERN-THESIS-2017-260oai:cds.cern.ch:22970932017-12-12T13:53:31Z
spellingShingle Accelerators and Storage Rings
Hugle, Dennis
System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection
title System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection
title_full System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection
title_fullStr System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection
title_full_unstemmed System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection
title_short System Theoretic Dependability Analysis of the LHC Superconducting Magnet Circuit Protection
title_sort system theoretic dependability analysis of the lhc superconducting magnet circuit protection
topic Accelerators and Storage Rings
url http://cds.cern.ch/record/2297093
work_keys_str_mv AT hugledennis systemtheoreticdependabilityanalysisofthelhcsuperconductingmagnetcircuitprotection