Cargando…

Dependability analysis of a safety critical system: the LHC beam dumping system at CERN

This thesis presents the dependability study of the Beam Dumping System of the Large Hadron Collider (LHC), the high energy particle accelerator to be commissioned at CERN in summer 2007. There are two identical, independent LHC Beam Dumping Systems (LBDS), one per LHC beam, each consisting of a ser...

Descripción completa

Detalles Bibliográficos
Autor principal: Filippini, R
Lenguaje:eng
Publicado: Pisa U. 2006
Materias:
Acceso en línea:http://cds.cern.ch/record/995680
_version_ 1780911490800287744
author Filippini, R
author_facet Filippini, R
author_sort Filippini, R
collection CERN
description This thesis presents the dependability study of the Beam Dumping System of the Large Hadron Collider (LHC), the high energy particle accelerator to be commissioned at CERN in summer 2007. There are two identical, independent LHC Beam Dumping Systems (LBDS), one per LHC beam, each consisting of a series of magnets that extract the particle beam from the LHC ring into the extraction line leading to the absorbing block. The consequences of a failure within the LBDS can be very severe. This risk is reduced by applying redundancy to the design of the most critical components and on-line surveillance that, in case of a detected failure, issues a safe operation abort, called false beam dump. The system has been studied applying Failure Modes Effects and Criticality Analysis (FMECA) and reliability prediction. The system failure processes have been represented with a state transition diagram, governed by a Markov regenerative stochastic process, and analysed for different operational scenarios for one year of operation. The analysis of the system results in a safety level ranked SIL4 in the IEC 61508 standard and 4 (± 2) expected false beam dumps generated per LBDS. These results will be validated through a three months reliability run. Several sensitivity analyses have been made providing additional evidence on the importance of the fault tolerant design features and the achieved trade-off between safety and availability. The Beam Dumping System is part of the LHC machine Protection System for which a safety level SIL3 is required. A simplified model of the LHC Machine Protection System (MPS), including the LBDS and other critical protection systems, has been analysed. Depending on the hazards (e.g. the fast beam losses being the most critical event in the LHC) and their coverage, the safety of the MPS has been calculated between SIL2 and SIL4 with about 40 (± 6) expected false dumps per year, which is the 10% of the machine fills. In the context of the MPS the LBDS is one of the safest systems and contributes to unavailability with an acceptable fraction of false dumps.
id cern-995680
institution Organización Europea para la Investigación Nuclear
language eng
publishDate 2006
publisher Pisa U.
record_format invenio
spelling cern-9956802019-09-30T06:29:59Zhttp://cds.cern.ch/record/995680engFilippini, RDependability analysis of a safety critical system: the LHC beam dumping system at CERNAccelerators and Storage RingsThis thesis presents the dependability study of the Beam Dumping System of the Large Hadron Collider (LHC), the high energy particle accelerator to be commissioned at CERN in summer 2007. There are two identical, independent LHC Beam Dumping Systems (LBDS), one per LHC beam, each consisting of a series of magnets that extract the particle beam from the LHC ring into the extraction line leading to the absorbing block. The consequences of a failure within the LBDS can be very severe. This risk is reduced by applying redundancy to the design of the most critical components and on-line surveillance that, in case of a detected failure, issues a safe operation abort, called false beam dump. The system has been studied applying Failure Modes Effects and Criticality Analysis (FMECA) and reliability prediction. The system failure processes have been represented with a state transition diagram, governed by a Markov regenerative stochastic process, and analysed for different operational scenarios for one year of operation. The analysis of the system results in a safety level ranked SIL4 in the IEC 61508 standard and 4 (± 2) expected false beam dumps generated per LBDS. These results will be validated through a three months reliability run. Several sensitivity analyses have been made providing additional evidence on the importance of the fault tolerant design features and the achieved trade-off between safety and availability. The Beam Dumping System is part of the LHC machine Protection System for which a safety level SIL3 is required. A simplified model of the LHC Machine Protection System (MPS), including the LBDS and other critical protection systems, has been analysed. Depending on the hazards (e.g. the fast beam losses being the most critical event in the LHC) and their coverage, the safety of the MPS has been calculated between SIL2 and SIL4 with about 40 (± 6) expected false dumps per year, which is the 10% of the machine fills. In the context of the MPS the LBDS is one of the safest systems and contributes to unavailability with an acceptable fraction of false dumps.Pisa U.CERN-THESIS-2006-054oai:cds.cern.ch:9956802006
spellingShingle Accelerators and Storage Rings
Filippini, R
Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
title Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
title_full Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
title_fullStr Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
title_full_unstemmed Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
title_short Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
title_sort dependability analysis of a safety critical system: the lhc beam dumping system at cern
topic Accelerators and Storage Rings
url http://cds.cern.ch/record/995680
work_keys_str_mv AT filippinir dependabilityanalysisofasafetycriticalsystemthelhcbeamdumpingsystematcern