Safety-Critical Cyber-Physical Design
Cybersecurity and functional safety are co-designed so that no cyber event - however severe - can prevent the machine from reaching a safe state.
Safety must survive a full compromise
The central safety claim is deliberately strong: even if an attacker fully owns the control network, the machine must still be able to reach a safe state. That is only possible if the shutdown path does not depend on the compromised systems. Kronos separates the safety function from the control function and gives safety an independent, simpler, and more assured path to act.
Independence in depth
- The safety-instrumented system is on its own isolated network - see SIS isolation.
- Safety logic is simple and analyzable, not an ML model, so its behavior is provable.
- Actuation for safe shutdown (de-energizing heating, dumping plasma, opening fast gas paths) is triggerable without the control plane's cooperation.
- Fail-closed everywhere: a lost or subverted control node causes the supervisor to move toward, not away from, safe state - see secure boot.
The two machines' safe states
For the breeder (Hyperion), a safe state includes controlled termination of the 9.66 MA discharge and securing tritium/vacuum boundaries. For the burner (Aegis / MetroVolt), it includes de-energizing the high-field plug/throat magnets and stopping D-3He fueling. In both, the safety path can command these independently of the L1/L2 control autonomy.
Where cyber meets the honest gates
Candor: the burner's design carries physics gates unrelated to cyber - the plug coil is overstressed roughly 3 to 3.9x at the design bore, its operating regime sits 166-830x beyond any built device, its He-3 fuel demand is ~400x domestic supply per commercial unit, and its availability of 0.86-0.995 is far below hyperscale Tier III's 0.99982. Safety-critical cyber design does not remedy those physics facts; it ensures that whatever machine is eventually built can be driven to a safe state under adversarial conditions.
Design status: the safety/control separation and fail-closed logic are validated in the twin and hardware-in-the-loop rigs. The independent SIS hardware is part of the FOAK build; no live reactor yet exercises it.