Cargando…
Dependability analysis of a safety critical system: the LHC beam dumping system at CERN
This thesis presents the dependability study of the Beam Dumping System of the Large Hadron Collider (LHC), the high energy particle accelerator to be commissioned at CERN in summer 2007. There are two identical, independent LHC Beam Dumping Systems (LBDS), one per LHC beam, each consisting of a ser...
Autor principal: | |
---|---|
Lenguaje: | eng |
Publicado: |
Pisa U.
2006
|
Materias: | |
Acceso en línea: | http://cds.cern.ch/record/995680 |
_version_ | 1780911490800287744 |
---|---|
author | Filippini, R |
author_facet | Filippini, R |
author_sort | Filippini, R |
collection | CERN |
description | This thesis presents the dependability study of the Beam Dumping System of the Large Hadron Collider (LHC), the high energy particle accelerator to be commissioned at CERN in summer 2007. There are two identical, independent LHC Beam Dumping Systems (LBDS), one per LHC beam, each consisting of a series of magnets that extract the particle beam from the LHC ring into the extraction line leading to the absorbing block. The consequences of a failure within the LBDS can be very severe. This risk is reduced by applying redundancy to the design of the most critical components and on-line surveillance that, in case of a detected failure, issues a safe operation abort, called false beam dump. The system has been studied applying Failure Modes Effects and Criticality Analysis (FMECA) and reliability prediction. The system failure processes have been represented with a state transition diagram, governed by a Markov regenerative stochastic process, and analysed for different operational scenarios for one year of operation. The analysis of the system results in a safety level ranked SIL4 in the IEC 61508 standard and 4 (± 2) expected false beam dumps generated per LBDS. These results will be validated through a three months reliability run. Several sensitivity analyses have been made providing additional evidence on the importance of the fault tolerant design features and the achieved trade-off between safety and availability. The Beam Dumping System is part of the LHC machine Protection System for which a safety level SIL3 is required. A simplified model of the LHC Machine Protection System (MPS), including the LBDS and other critical protection systems, has been analysed. Depending on the hazards (e.g. the fast beam losses being the most critical event in the LHC) and their coverage, the safety of the MPS has been calculated between SIL2 and SIL4 with about 40 (± 6) expected false dumps per year, which is the 10% of the machine fills. In the context of the MPS the LBDS is one of the safest systems and contributes to unavailability with an acceptable fraction of false dumps. |
id | cern-995680 |
institution | Organización Europea para la Investigación Nuclear |
language | eng |
publishDate | 2006 |
publisher | Pisa U. |
record_format | invenio |
spelling | cern-9956802019-09-30T06:29:59Zhttp://cds.cern.ch/record/995680engFilippini, RDependability analysis of a safety critical system: the LHC beam dumping system at CERNAccelerators and Storage RingsThis thesis presents the dependability study of the Beam Dumping System of the Large Hadron Collider (LHC), the high energy particle accelerator to be commissioned at CERN in summer 2007. There are two identical, independent LHC Beam Dumping Systems (LBDS), one per LHC beam, each consisting of a series of magnets that extract the particle beam from the LHC ring into the extraction line leading to the absorbing block. The consequences of a failure within the LBDS can be very severe. This risk is reduced by applying redundancy to the design of the most critical components and on-line surveillance that, in case of a detected failure, issues a safe operation abort, called false beam dump. The system has been studied applying Failure Modes Effects and Criticality Analysis (FMECA) and reliability prediction. The system failure processes have been represented with a state transition diagram, governed by a Markov regenerative stochastic process, and analysed for different operational scenarios for one year of operation. The analysis of the system results in a safety level ranked SIL4 in the IEC 61508 standard and 4 (± 2) expected false beam dumps generated per LBDS. These results will be validated through a three months reliability run. Several sensitivity analyses have been made providing additional evidence on the importance of the fault tolerant design features and the achieved trade-off between safety and availability. The Beam Dumping System is part of the LHC machine Protection System for which a safety level SIL3 is required. A simplified model of the LHC Machine Protection System (MPS), including the LBDS and other critical protection systems, has been analysed. Depending on the hazards (e.g. the fast beam losses being the most critical event in the LHC) and their coverage, the safety of the MPS has been calculated between SIL2 and SIL4 with about 40 (± 6) expected false dumps per year, which is the 10% of the machine fills. In the context of the MPS the LBDS is one of the safest systems and contributes to unavailability with an acceptable fraction of false dumps.Pisa U.CERN-THESIS-2006-054oai:cds.cern.ch:9956802006 |
spellingShingle | Accelerators and Storage Rings Filippini, R Dependability analysis of a safety critical system: the LHC beam dumping system at CERN |
title | Dependability analysis of a safety critical system: the LHC beam dumping system at CERN |
title_full | Dependability analysis of a safety critical system: the LHC beam dumping system at CERN |
title_fullStr | Dependability analysis of a safety critical system: the LHC beam dumping system at CERN |
title_full_unstemmed | Dependability analysis of a safety critical system: the LHC beam dumping system at CERN |
title_short | Dependability analysis of a safety critical system: the LHC beam dumping system at CERN |
title_sort | dependability analysis of a safety critical system: the lhc beam dumping system at cern |
topic | Accelerators and Storage Rings |
url | http://cds.cern.ch/record/995680 |
work_keys_str_mv | AT filippinir dependabilityanalysisofasafetycriticalsystemthelhcbeamdumpingsystematcern |