Computing Library › Component Control
Component Control

Fault Ride-Through and Safe Shutdown

When something goes wrong the plant must either ride through the disturbance or shut down safely in a controlled, predictable sequence.

Two responses to a fault

Not every fault warrants stopping. Minor, recoverable disturbances, a brief loss of coupling on a heating source or a transient sensor glitch, are ridden through: the affected loop trims or momentarily backs off and operation continues. Serious faults, a magnet quench, loss of cooling, or loss of vertical control, require a controlled shutdown before damage occurs.

Riding through

Kronos motion — control room

Ride-through relies on margin and graceful degradation. A heating system that loses one source continues on the others; a control loop near a limit backs off rather than tripping. Feedforward and reserved actuator margin give the system room to absorb a disturbance without losing the plasma, so a small upset does not cost an entire pulse.

Safe shutdown

When shutdown is required, the plant follows a planned termination: heating and fueling are reduced, the plasma current is ramped down in a controlled way to avoid a disruption, magnets are handled per their protection scheme, and utilities are parked safely. The state machine drives this sequence so the plant reaches a known safe state predictably rather than through ad-hoc reactions.

Avoiding disruptions

In a tokamak a sudden uncontrolled termination, a disruption, imposes large forces and heat loads, so a graceful shutdown is far preferable. Disruption prediction and mitigation systems watch for the precursors and, if a disruption is unavoidable, act to soften it. In the Kronos breeder design study, controlled termination and disruption avoidance protect the modeled spherical tokamak; the machine is a simulation and design case, and these behaviours are described in general engineering terms.

The measure of a control system is how calmly it handles the moment something breaks.