Hardware-in-the-Loop Commissioning
Before either machine energizes, L1 is validated against the digital twin in hardware-in-the-loop tests that exercise every loop and failsafe deterministically.
Proving the control plane before first plasma
Both machines are, today, design and simulation studies; construction of the breeder begins Q2 2027, with first-of-a-kind first tritium around 2030. Long before energization, the control plane must be proven. Kronos validates L1 with hardware-in-the-loop (HIL) testing: the real FPGA controllers, drivers, and interlocks run against the digital twin standing in for the plasma and plant.
What HIL exercises
- Every fast loop against twin-generated state: shape, stability, plug density, DEC.
- Protection paths: quench precursor to dump, disruption mitigation trigger, thermal limits.
- Timing: measured WCET and jitter compared against the analytic budgets.
- Fault injection: dropped diagnostics, stage faults, stalled controllers, missing setpoints.
Fault injection is central: HIL deliberately drops channels, faults DEC stages, stalls controllers, and withholds MPC targets to confirm that watchdogs fire, redundancy votes, ride-through holds, and the machine defaults safe. A failsafe is only trustworthy once it has been made to act in test.
Closing the analytic loop
HIL confirms that the certified bounds are real. Measured latency and jitter must agree with the WCET and jitter budgets; where they diverge, the design is corrected before hardware energizes. This is how the paper guarantees of the deterministic layer become validated guarantees.
From twin to machine
Because the same digital twin used in HIL later runs as the operating L3 shadow, commissioning and operation share a model lineage: the control plane is tested against the same physics it will later be advised by. HIL is the bridge from simulation study to a machine whose control plane is trusted from first energization onward.