Machine Protection Systems
The machine protection system is the last line of defense, acting to protect hardware even when it means abandoning the plasma.
Purpose and priority
The machine protection system (MPS) exists to keep the device from damaging itself. Its priority is above all performance goals: if protecting the plasma and protecting the machine conflict, the machine wins. This inversion of priority relative to normal control is deliberate, because hardware is expensive and slow to repair while a lost discharge can simply be repeated.
What it protects against
- Overheating of plasma-facing components
- Coil currents or forces beyond structural limits
- Excessive voltage across the central solenoid
- Vacuum, cooling, or power-supply faults
- Runaway electron beams striking the wall
Independence from control
A key principle is that protection functions are as independent as practical from the performance control system. They use separate sensors, separate logic, and often simpler, hard-wired interlocks so that a bug in the control software cannot disable protection. This mirrors safety practice in other high-energy systems, where protection and control are kept apart.
Actions
When a protection limit is threatened, the MPS can command a fast, safe shutdown, or in extreme cases a mitigated shutdown that trades a controlled disruption for avoiding worse damage. Because these actions are drastic, protection thresholds are set with margin and validated so false trips are rare but real threats are always caught.
In the Kronos program
The Hyperion breeder's protection system guards its high-field magnets, which reach 16.84 tesla at the coil, and its plasma-facing surfaces. The burner generators protect their mirror plug coils at 26.49 tesla. In both cases protection is layered beneath performance control and above the physical interlocks, and its logic is verified independently of the control code.