990 likes | 1.22k Vues
Risk Reduction Levels…. September 2016. benjamin.todd@cern.ch. 0. To Take Away Today. This presentation supposed to be Safety Integrity Levels… a big leap…. Start the discussion by considering Risk Reduction via Risk Analysis. risk analysis is a core part of every engineer’s toolbox
E N D
Risk Reduction Levels… September 2016 benjamin.todd@cern.ch 0
To Take Away Today This presentation supposed to be Safety Integrity Levels… a big leap… Start the discussion by considering Risk Reduction via Risk Analysis • risk analysis is a core part of every engineer’s toolbox • – zero risk does not exist • the context is vital • –need to consider system, machine and organisationallevel impact • If you remember only two things from today…
Contents 1. Risk Analysis Safety – Protection – Plant Powering Protection Interlock Implementation 2. An Example Beam Interlock System Failure Modes Effects and Criticality Analysis
Protection Functions MagnetEnergy Emergency Discharge Powering Protection: 100x energy of TEVATRON 0.000005% of beam lost into a magnet = quench 0.005% beam lost into magnet = damage BeamEnergy Beam Dump Beam Protection: Failure in protection – complete loss of LHC is possible 10-20x energy per magnet of TEVATRON magnet quenched = hours downtime many magnets quenched= days downtime magnet damaged = $1 million, months downtime many magnets damaged = many millions, many months downtime
Protection Functions 100x energy of TEVATRON 0.000005% of beam lost into a magnet = quench 0.005% beam lost into magnet = damage BeamEnergy Beam Dump Beam Protection: Failure in protection – complete loss of LHC is possible Concrete Shielding Beam is ‘painted’ diameter 35cm 8m long absorber Graphite = 800°C
Protection Functions 100x energy of TEVATRON 0.000005% of beam lost into a magnet = quench 0.005% beam lost into magnet = damage BeamEnergy Beam Dump Beam Protection: Failure in protection – complete loss of LHC is possible To protect against fastest failure modes ≈ 400 µs over 27km
Comparison of LHC with others powering is split into sub-sectors: energy in each circuit manageable, allows for a staged commissioning [13]
SPS Experiment at 450 GeV Controlled SPS experiment to qualify simulations At 450GeV … 8x1012 protons causes damage 6 cm 4x1012 6x1012 2x1012 8x1012 beam size σx/y = 1.1mm/0.6mm Plate 2mm thick 0.1% LHC Full Beam Energy! Beam in LHC is 10x smaller!! [14]
Safety – Protection – Plant • Vacuum Example: • maintain correct pressure Plant Systems: Fulfill operational requirements Vacuum Pressure Vacuum Pump Speed Control [11]
Safety – Protection – Plant • Vacuum Example: • maintain correct pressure • bad pressure = close valves Vacuum Pressure Vacuum Valve Actuator Plant Protection: Ensure plant stays within limits Plant Systems: Fulfill operational requirements Vacuum Pressure Vacuum Pump Speed Control [11]
Safety – Protection – Plant Vacuum Pressure Vacuum Valve Actuator Plant Systems: Ensure plant stays within limits Fulfill operational requirements • Sensors, Actuators and Process maybecombined • No rules regarding combination • Must meet functionalrequirement Vacuum Pump Speed Control [11]
Safety – Protection – Plant Access doors Beam absorbers Personnel Safety System: People in perimeter – stop machine personnel safe but machine at risk • cannot be merged with plants • Must meet legal requirement [11]
Safety – Protection – Plant Machine Protection System: Prevent damage to machine Prevent undue stress to components • No rules regarding implementation • Must meet functionalrequirement [11]
Safety – Protection – Plant Machine Protection System: Prevent damage to machine Prevent undue stress to components • No rules regarding implementation • Must meet functionalrequirement powering protection closely coupled to powering plant [11]
Safety – Protection – Plant Personnel Safety System: Machine Protection System: danger willexist – prevent – extract energy danger exists – protect – extract energy Plant Systems: [11]
So… Each of these systems has a job to do… If they malfunction, we are in a tough situation Everything that can malfunction, will eventually malfunction… Prepare for and accept malfunction as “normal”. Build the systems using a risk-based approach e.g. Safety Systems – IEC61508 inspired
Protection System Lifecycle systems involved in protection are unique certain technologies used have never been tried on this scale before high cost of failure development and analysis of machine protection as if it were a safety system Design System Protection System Lifecycle AssessExisting worked example Dipole Magnet Protection – 9GJ
Protection System Lifecycle Magnet Cryogenics Power Converter Equipment Under Control
154 in series Magnet Cryogenics Power Converter Equipment Under Control
prevent protect Quench Damage 154 in series Magnet Cryogenics Power Converter Equipment Under Control
Hazard Chain: from Quench to Damage… • Resistive zone appears in a magnet • I2R losses begin • Zone heats up (heat propagates to neighbouring magnets) • Damage to magnets 154 in series
Hazard Chain: from Quench to Damage… • Resistive zone appears in a magnet • I2R losses begin • Zone heats up (heat propagates to neighbouring magnets) • Damage to magnets 154 in series What Protection Functions and Protection Systems are in place?
Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy = purple = 3 • Link Related Circuits = green = 1 when quench occurs…
Power Abort Detection • Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy = purple = 3 • Link Related Circuits = green = 1 when quench occurs…
Quench Heater • Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy = purple = 3 • Link Related Circuits = green = 1 when quench occurs…
Energy Extraction Loop Extraction Switch Resistor • Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy = purple = 3 • Link Related Circuits = green = 1 when quench occurs…
Powering Loop • Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy = purple = 3 • Link Related Circuits = green = 1 when quench occurs…
Escape Diode • Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy= purple = 3 • Link Related Circuits = green = 1 when quench occurs…
Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy= purple = 3 • Link Related Circuits = green = 1 when quench occurs…
classify probability and consequence using risk matrix Colour boundaries, probabilities, consequences intentionally vague = talking points risk, if function didn’t exist, according to system experts… • Turn off Power Converter = purple = 3 • Propagate Quench = orange = 2 • Extract Energy = purple = 3 • Link Related Circuits = green =1
classify probability and consequence using risk matrix Colour boundaries, probabilities, consequences intentionally vague = talking points risk, if function didn’t exist, according to system experts… • Turn off Power Converter =purple = 3 • Propagate Quench =orange = 2 • Extract Energy =purple = 3 • Link Related Circuits = green =1
Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
determine risk reduction level using matrix • Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
determine risk reduction level using matrix = dependability requirements • Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
determine risk reduction level using matrix = dependability requirements • Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
How do we qualify a system meets a level? How about programmable logic? • Turn off Power Converter = purple= 3 • Propagate Quench = orange= 2 • Extract Energy = purple= 3 • Link Related Circuits = green= 1
So… Each of these systems has a job to do… If they malfunction, we are in a tough situation = “risky”? Everything that can malfunction, will eventually malfunction… Prepare for and accept malfunction as “normal”. Realise functions using a high-reliability approach, determine failure rates and modes