A multi-dimensional COTS device intelligent computing system reliability design method
By setting up a fault detection and recovery module in the intelligent computing system and using a long-delay system-level watchdog for a two-level reliability design, the problem of insufficient reliability of COTS devices in space environments was solved, achieving high system reliability and resource savings.
Patent Information
- Application Number
- CN202411802174.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Existing COTS devices are prone to failure when used in space environments, resulting in insufficient reliability of intelligent computing systems. Backup designs also lead to design redundancy, occupying space and computing resources.
A two-level reliability design approach is adopted, including setting up fault detection and recovery modules in the intelligent computing module and the external interface module, and using a long-delay system-level watchdog for fault detection and recovery. The system reliability is improved through a latch arbitration circuit and a multi-channel long-delay pulse generator.
It greatly improves the reliability of the system, reduces the space and computing resources occupied, realizes the system recovery mechanism in the event of a failure, and solves the problem of insufficient reliability of COTS devices in space environments.
Smart Images

Figure CN119718746B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of spatial fault tolerance technology, and in particular to a reliability design method for a multi-dimensional COTS device intelligent computing system. Background Art
[0002] In model applications, using COTS (Commercial Off-The-Shelf) components to implement intelligent computing system hardware and software platforms can significantly reduce costs and shorten development cycles. However, low-cost commercial components are more prone to failure when used in space environments, necessitating reliability design to ensure their reliability in space applications. Existing reliability design methods mostly rely on backup designs, which can easily lead to design redundancy and consume significant space space space space space space resources.
[0003] Therefore, a multi-dimensional COTS device intelligent computing system reliability design method is urgently needed. Summary of the Invention
[0004] This invention provides a multi-dimensional COTS device intelligent computing system reliability design method, which can solve the problem of insufficient reliability of intelligent computing systems using COTS devices. The technical solution is as follows:
[0005] An embodiment of the present invention provides a reliability design method for a multi-dimensional COTS device intelligent computing system. The intelligent computing system includes at least one intelligent computing module and N peripheral external interface modules. The reliability design method includes: providing a corresponding fault detection and recovery module within the intelligent computing module and each external interface module, respectively, and providing a long-delay system-level watchdog connected to the intelligent computing module and the external interface module respectively; the long-delay system-level watchdog includes a latch arbitration circuit and a multi-channel long-delay pulse generator, one input end of the latch arbitration circuit is connected to the clearing interface of the intelligent computing module and the N external interface modules respectively, and the other input end is connected to the output end of the multi-channel long-delay pulse generator; the output ends of some of the long-delay pulse generators are connected to the reset interface of one or more of the intelligent computing modules, and the output ends of the remaining long-delay pulse generators are connected to the reset interface of the corresponding one or more external interface modules;
[0006] Utilizing N+n fault detection and recovery modules to perform first layer fault detection and recovery on the intelligent computing module and each external interface module, respectively; n is the number of the intelligent computing modules;
[0007] The latch arbitration circuit receives clear signals sent by the intelligent computing module and N external interface modules, and clears the timing of each long-delay pulse generator after latching and arbitration. If the timing exceeds a first set delay, the long-delay pulse generator outputs a first reset signal;
[0008] The first reset signal of the long-delay pulse generator is used to reset and restart the corresponding intelligent computing module or the external interface module, and to release the latching and arbitration of the corresponding clear signal in the latch arbitration circuit to perform second-layer fault detection and recovery; wherein the number of paths of the long-delay pulse generator is less than or equal to N+n.
[0009] An embodiment of the present invention provides a reliability design device for a multi-dimensional COTS device intelligent computing system. The intelligent computing system includes at least one intelligent computing module and N peripheral external interface modules. The reliability design device includes: a fault detection and recovery module disposed within the intelligent computing module and each external interface module, respectively; and a long-delay system-level watchdog connected to the intelligent computing module and the external interface module, respectively.
[0010] The long-delay system-level watchdog includes a latch arbitration circuit and a multi-channel long-delay pulse generator. One input end of the latch arbitration circuit is connected to the clearing interface of the intelligent computing module and N external interface modules respectively, and the other input end is connected to the output end of the multi-channel long-delay pulse generator. The latch arbitration circuit is used to receive the clear signal sent by the intelligent computing module and the N external interface modules, and clear the timing of each long-delay pulse generator after latching and arbitration. If the timing exceeds a first set delay, the long-delay pulse generator outputs a first reset signal;
[0011] The output ends of some of the long-delay pulse generators are connected to the reset interfaces of one or more of the intelligent computing modules, and the output ends of the remaining long-delay pulse generators are connected to the reset interfaces of one or more corresponding external interface modules, so as to use the first reset signal of the long-delay pulse generator to reset and restart the corresponding intelligent computing module or the external interface module, and release the latching and arbitration of the corresponding clear signal in the latch arbitration circuit; wherein the number of the long-delay pulse generators is less than or equal to N+n, where n is the number of the intelligent computing modules.
[0012] An embodiment of the present invention provides a reliability design method for a multi-dimensional COTS device intelligent computing system. This method includes a fault detection and recovery module within the intelligent computing module and each external interface module, forming the first layer of reliability design. A long-latency system-level watchdog is provided as the second layer of system-level reliability design. This two-level reliability design significantly improves system reliability, implements a system recovery mechanism in the event of a fault, and ensures overall system reliability. This effectively addresses the issue of insufficient reliability in intelligent computing systems when low-cost commercial components are used in space environments. The use of a long-latency system-level watchdog for fault detection and recovery significantly reduces space and computing resource usage compared to backup designs. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0014] Figure 1 This is a schematic diagram of a reliability design device for a multi-dimensional COTS device intelligent computing system provided by one embodiment of the present invention;
[0015] Figure 2 This is a schematic diagram of the composition of a long-delay pulse generator provided by one embodiment of the present invention. DETAILED DESCRIPTION
[0016] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0017] Please refer to Figure 1An embodiment of the present invention provides a reliability design method for a multi-dimensional COTS device intelligent computing system. The intelligent computing system includes at least one intelligent computing module and N peripheral external interface modules. The reliability design method includes: providing a corresponding fault detection and recovery module within the intelligent computing module and each external interface module, and providing a long-delay system-level watchdog connected to the intelligent computing module and the external interface module respectively; the long-delay system-level watchdog includes a latch arbitration circuit and a multi-channel long-delay pulse generator, one input end of the latch arbitration circuit is connected to the clearing interface of the intelligent computing module and the N external interface modules respectively, and the other input end is connected to the output end of the multi-channel long-delay pulse generator; the output ends of some of the long-delay pulse generators are connected to the reset interfaces of one or more intelligent computing modules, and the output ends of the remaining long-delay pulse generators are connected to the reset interfaces of the corresponding one or more external interface modules;
[0018] Use N+n fault detection and recovery modules to perform first-layer fault detection and recovery on the intelligent computing module and each external interface module, respectively; n is the number of intelligent computing modules;
[0019] A latch arbitration circuit is used to receive clear signals sent by the intelligent computing module and N external interface modules, and the timing of each long-delay pulse generator is cleared after latching and arbitration. If the timing exceeds a first set delay, the long-delay pulse generator outputs a first reset signal;
[0020] The first reset signal of the long-delay pulse generator is used to reset and restart the corresponding intelligent computing module or external interface module, and to release the latching and arbitration of the corresponding clear signal in the latch arbitration circuit to perform second-layer fault detection and recovery; wherein the number of long-delay pulse generators is less than or equal to N+n.
[0021] In this embodiment of the present invention, a fault detection and recovery module is provided within the intelligent computing module and each external interface module, representing the first layer of reliability design. A long-latency system-level watchdog is provided as the second layer of system-level reliability design. This two-tier reliability design significantly improves system reliability, implements a system recovery mechanism in the event of a fault, and ensures overall system reliability. This effectively addresses the issue of insufficient reliability in intelligent computing systems when low-cost commercial components are used in space environments. The use of a long-latency system-level watchdog for fault detection and recovery significantly reduces space and computing resource usage compared to backup designs.
[0022] Please refer to Figure 1An embodiment of the present invention provides a reliability design device for a multi-dimensional COTS device intelligent computing system. The intelligent computing system includes at least one intelligent computing module and N peripheral external interface modules. The reliability design device includes: a fault detection and recovery module disposed within the intelligent computing module and each external interface module, and a long-delay system-level watchdog connected to the intelligent computing module and the external interface module, respectively;
[0023] The long-delay system-level watchdog includes a latch arbitration circuit and a multi-channel long-delay pulse generator. One input end of the latch arbitration circuit is connected to the clearing interface of the intelligent computing module and N external interface modules respectively, and the other input end is connected to the output end of the multi-channel long-delay pulse generator. The latch arbitration circuit is used to receive the clear signal sent by the intelligent computing module and the N external interface modules, and clear the timing of each long-delay pulse generator after latching and arbitration. If the timing exceeds the first set delay, the long-delay pulse generator outputs a first reset signal.
[0024] The output ends of some of the long-delay pulse generators are connected to the reset interfaces of one or more intelligent computing modules, and the output ends of the remaining long-delay pulse generators are connected to the reset interfaces of one or more corresponding external interface modules, so as to use the first reset signal of the long-delay pulse generator to reset and restart the corresponding intelligent computing module or external interface module, and release the latch and arbitration of the corresponding clear signal in the latch arbitration circuit; wherein, the number M of long-delay pulse generators is less than or equal to N+n, and n is the number of intelligent computing modules.
[0025] like Figure 1 In the example shown, the intelligent computing system has only one intelligent computing module, but it is understandable that there may also be multiple intelligent computing modules.
[0026] For example, assume that in an intelligent computing system, the number of intelligent computing modules n is 1 and the number of external interface modules N is 2. The long-delay system-level watchdog includes a latching arbitration circuit and two long-delay pulse generators. The latching arbitration circuit inputs three clear signals. The intelligent computing module adapts to the first long-delay pulse generator, and the two external interface modules share the same long-delay pulse generator. After latching and arbitration, the timing of each long-delay pulse generator is cleared. If the first long-delay pulse generator does not clear within a first set delay, it outputs a first reset signal after timeout, restarting the intelligent computing module and achieving fault recovery. The first reset signal of the first long-delay pulse generator is also fed back to the latching arbitration circuit. At this time, the latching arbitration circuit only releases the latch and arbitration of the clear signal of the intelligent computing module. If the second long-delay pulse generator is not cleared within the first set delay, it will output the first reset signal after timeout, and restart the two external interface modules to achieve fault recovery. The first reset signal of the second long-delay pulse generator will also be fed back to the latch arbitration circuit. At this time, the latch arbitration circuit only releases the latch and arbitration of the two clear signals of the two external interface modules.
[0027] It is understandable that three long-delay pulse generators may also be provided, with the first corresponding to the intelligent computing module and the remaining two corresponding to two external interface modules respectively.
[0028] In some embodiments, the fault detection and recovery module inside the intelligent computing module is a configurable watchdog, which is connected to the processor system in the intelligent computing module. The configurable watchdog configuration software program periodically sends heartbeat packets to the processor system to receive the clearing signal returned by the processor system. When the configurable watchdog does not receive the clearing signal within the second set delay, it sends a second reset signal to the processor system to restart the processor system.
[0029] In an embodiment of the present invention, the first set delay of the long delay pulse generator is greater than the second set delay of the intelligent computing module.
[0030] It can be understood that the first-level reliability design inside the intelligent computing module is a short-delay design, and the long-delay system-level watchdog of the second-level reliability design takes into account the functional characteristics of the entire intelligent computing system and the long startup time. Therefore, the first set delay of the long-delay pulse generator is greater than the second set delay of the intelligent computing module.
[0031] In this embodiment, a hardware-configured watchdog (WDT) is implemented within the intelligent computing module. The time from powering on the intelligent computing module to booting the Linux processor system is approximately 60 seconds. The configurable watchdog driver can only be loaded after the Linux operating system boots. Software can be used to configure the watchdog's second set delay to 3 seconds. Software is also used to clear the watchdog, with a clearing cycle of 500 seconds, thereby achieving first-level fault detection and recovery for the intelligent computing module. Since the fault detection and recovery module within the intelligent computing module is a software-configurable hardware watchdog, watchdog activation requires the intelligent computing module hardware to self-check and boot, and boot the operating system before it can begin operating. The time from powering on the intelligent computing module to watchdog activation is approximately one minute or longer. Only then is the long-delay system-level watchdog, designed for second-level reliability, required for fault detection and recovery. Therefore, the first set delay of the long-delay system-level watchdog is at least a minute. In this embodiment, the first set delay is set to 100 seconds.
[0032] In some embodiments, the fault detection and recovery module inside the external interface module uses a chip as a short-delay pulse generator, and the short-delay pulse generator is connected to the external interface circuit in the external interface module. If the clear signal sent by the external interface circuit is not received within a third set delay, a third reset signal is sent to the external interface circuit to restart the external interface circuit; wherein the third set delay is less than the first set delay of the long-delay pulse generator.
[0033] In some implementations, the chip is a monitoring chip MAX706, and the third set delay is configured using software.
[0034] In this embodiment, a hardware chip is used within the external interface module to implement a short-delay pulse generator for fault detection and recovery. The fault detection and recovery module within the external interface module can be implemented using a dedicated monitoring chip, the MAX706, which has a built-in timer function. Only the third set delay time is configured using software. In this embodiment, the third set delay time is 1.6 seconds.
[0035] In some implementations, the chip is an FPGA chip, and a clearable counter with a third set delay is programmed using VHDL language.
[0036] In this embodiment, the fault detection and recovery module within the external interface module can also utilize an FPGA chip with a 10 MHz external crystal oscillator. A resettable 1.6-second counter is implemented in VHDL, which serves as a short-delay pulse generator with a 1.6-second period. If the timer is not cleared within 1.6 seconds, a reset pulse is output, which restarts the external interface module and recovers from the fault.
[0037] In some embodiments, the latch arbitration circuit performs logical arbitration on the clear signal corresponding to each long-delay pulse generator. If the clear signal corresponding to the long-delay pulse generator is issued by one or more external interface modules, the latest clear signal from these one or more external interface modules is latched and a "logical AND" arbitration is performed. If the clear signal corresponding to the long-delay pulse generator is issued by one or more intelligent computing modules, the latest clear signal from these multiple intelligent computing modules is latched and a "logical OR" arbitration is performed.
[0038] In this embodiment, because the intelligent computing module has a higher priority and a failure in one intelligent computing module may affect other intelligent computing modules, if the clear signal corresponding to the path delay pulse generator is issued by one or more intelligent computing modules, a logical OR is used for arbitration. If only one module fails, all modules must be restarted. However, the fault detection and recovery module within the external interface module already has a layer of protection and a relatively lower priority. Furthermore, there is a certain probability that a clear signal may erroneously trigger a system-level timer clear. Therefore, a logical AND is used for arbitration. If no clear signal is issued by any of the corresponding external interface modules within the first set delay, the corresponding external interface modules are restarted. This prevents the clear signal from a single or several functional modules from erroneously triggering a system-level timer clear.
[0039] Therefore, the multi-signal latching and arbitration of this embodiment is used to latch and judge the clear signals of the (N+n) functional modules, which is necessary to ensure that the system-level timing can be effectively cleared when the (N+n) functional modules are all normal, and to avoid the situation where the clear signals of a single or several functional modules mistakenly trigger the clearing of the system-level timing.
[0040] In some embodiments, each long-delay pulse generator is composed of a controllable pulse generator, a monostable trigger, a resistor-capacitor network and a shaping network. The controllable pulse generator, the monostable trigger and the shaping network are connected in series in sequence. The output end of the shaping network is connected to the intelligent computing module or external interface module corresponding to the long-delay pulse generator. The controllable pulse generator is connected to the output end of the latch arbitration circuit to generate a pulse for clearing the timing of the monostable trigger under the drive of the clear signal output by the latch arbitration circuit. The resistor-capacitor network is connected to the monostable trigger to set a first set delay for the monostable trigger. When the controllable pulse generator does not generate a pulse within the first set delay, the monostable trigger generates a timeout reset signal, which passes through the shaping network and serves as a reset signal to restart the corresponding intelligent computing module or external interface module.
[0041] The design of each long delay pulse generator is as follows Figure 2As shown, its design simultaneously meets the requirements of long-delay pulse output and single-particle radiation resistance. Since digital circuit chips are prone to single-particle events in space radiation environments, that is, abnormal flip-flops caused by radiation, in this embodiment, the long-delay pulse generator is implemented using simple discrete components, avoiding the use of large-scale digital circuits (such as FPGAs). Its components are divided into three parts: a controllable pulse generator, a delay circuit based on a monostable trigger, and a shaping circuit. The controllable pulse generator continuously generates pulses with a pulse period of 2 seconds (2 seconds < 100 seconds), so that the monostable trigger is not triggered. If the controllable pulse generator does not generate a pulse within 100 seconds, the monostable trigger generates a timeout reset signal after a first set delay of 100 seconds according to the resistor-capacitor network. This signal is shaped and used as a reset signal to restart the corresponding functional module. Therefore, the long-delay pulse generator uses simple discrete components to achieve a minute-level dog bite signal, which not only ensures the long-delay function but also ensures its own reliability in space radiation environments.
[0042] In summary, the embodiment of the present invention adopts a two-layer reliability design. The bottom layer (N+n) nodes use their hardware and software resources to implement their own fault detection and recovery based on their hardware functions and characteristics, thereby ensuring their own reliability. The top layer considers the functional characteristics of the entire intelligent computing system, especially the long startup time of the intelligent processing module, and can use simple devices as much as possible to implement fault detection and recovery of the entire system to ensure system reliability.
[0043] It should be noted that the method embodiment and the device embodiment in the embodiments of the present invention are based on the same inventive concept, and their specific implementation process is detailed in the device embodiment.
[0044] It should be noted that, in this document, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0045] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk, etc. Various media that can store program codes.
[0046] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A multi-dimensional COTS device intelligent computing system reliability design method, characterized by: An intelligent computing system includes at least one intelligent computing module and N peripheral external interface modules. The reliability design method includes: providing a corresponding fault detection and recovery module within the intelligent computing module and each external interface module, and providing a long-delay system-level watchdog connected to the intelligent computing module and the external interface module respectively; the long-delay system-level watchdog includes a latch arbitration circuit and a multi-channel long-delay pulse generator, one input end of the latch arbitration circuit is connected to the clearing interface of the intelligent computing module and the N external interface modules respectively, and the other input end is connected to the output end of the multi-channel long-delay pulse generator; the output ends of some of the long-delay pulse generators are connected to the reset interface of one or more of the intelligent computing modules, and the output ends of the remaining long-delay pulse generators are connected to the reset interface of the corresponding one or more external interface modules; Utilizing N+n fault detection and recovery modules to perform first layer fault detection and recovery on the intelligent computing module and each external interface module, respectively; n is the number of the intelligent computing modules; The latch arbitration circuit receives clear signals sent by the intelligent computing module and N external interface modules, and clears the timing of each long-delay pulse generator after latching and arbitration. If the timing exceeds a first set delay, the long-delay pulse generator outputs a first reset signal; The first reset signal of the long-delay pulse generator is used to reset and restart the corresponding intelligent computing module or the external interface module, and to release the latching and arbitration of the corresponding clear signal in the latch arbitration circuit to perform second-layer fault detection and recovery; wherein the number of paths of the long-delay pulse generator is less than or equal to N+n.
2. A multi-dimensional COTS device intelligent computing system reliability design device, characterized by: The intelligent computing system includes at least one intelligent computing module and N peripheral external interface modules, wherein the reliability design device includes: a fault detection and recovery module respectively disposed in the intelligent computing module and each external interface module, and a long-delay system-level watchdog respectively connected to the intelligent computing module and the external interface module; The long-delay system-level watchdog includes a latch arbitration circuit and a multi-channel long-delay pulse generator. One input end of the latch arbitration circuit is connected to the clearing interface of the intelligent computing module and N external interface modules respectively, and the other input end is connected to the output end of the multi-channel long-delay pulse generator. The latch arbitration circuit is used to receive the clear signal sent by the intelligent computing module and the N external interface modules, and clear the timing of each long-delay pulse generator after latching and arbitration. If the timing exceeds a first set delay, the long-delay pulse generator outputs a first reset signal; The output ends of some of the long-delay pulse generators are connected to the reset interfaces of one or more of the intelligent computing modules, and the output ends of the remaining long-delay pulse generators are connected to the reset interfaces of one or more corresponding external interface modules, so as to use the first reset signal of the long-delay pulse generator to reset and restart the corresponding intelligent computing module or the external interface module, and release the latching and arbitration of the corresponding clear signal in the latch arbitration circuit; wherein the number of the long-delay pulse generators is less than or equal to N+n, where n is the number of the intelligent computing modules.
3. The device according to claim 2, characterized in that The fault detection and recovery module inside the intelligent computing module is a configurable watchdog, which is connected to the processor system in the intelligent computing module. The configurable watchdog configuration software program regularly sends heartbeat packets to the processor system to receive a clearing signal returned by the processor system. When the configurable watchdog does not receive the clearing signal within a second set delay, it sends a second reset signal to the processor system to restart the processor system.
4. The device according to claim 3, characterized in that The first set delay of the long delay pulse generator is greater than the second set delay of the configurable watchdog.
5. The device according to claim 2, characterized in that The fault detection and recovery module inside the external interface module uses a chip as a short-delay pulse generator. The short-delay pulse generator is connected to the external interface circuit in the external interface module. If the clear signal sent by the external interface circuit is not received within a third set delay, the third reset signal is sent to the external interface circuit to restart the external interface circuit; wherein the third set delay is less than the first set delay of the long-delay pulse generator.
6. The device according to claim 5, characterized in that The chip is a monitoring chip MAX706, and the third set delay is configured using software.
7. The device according to claim 5, characterized in that The chip is an FPGA chip, and a clearable counter for the third set delay is programmed using VHDL language.
8. The device according to claim 2, characterized in that The latch arbitration circuit performs logical arbitration on the clear signal corresponding to each long-delay pulse generator. If the clear signal corresponding to the long-delay pulse generator is issued by one or more external interface modules, the latest clear signal of the one or more external interface modules is latched and logically arbitrated.
9. The device according to claim 8, characterized in that If the clear signal corresponding to the path length delay pulse generator is issued by one or more intelligent computing modules, the latest clear signals of the multiple intelligent computing modules are latched and subjected to logic OR arbitration.
10. The device according to claim 2, characterized in that Each of the long-delay pulse generators is composed of a controllable pulse generator, a monostable trigger, a resistor-capacitor network, and a shaping network. The controllable pulse generator, the monostable trigger, and the shaping network are connected in series in sequence. The output end of the shaping network is connected to the intelligent computing module or the external interface module corresponding to the long-delay pulse generator. The input end of the controllable pulse generator is connected to the output end of the latch arbitration circuit to generate a pulse for clearing the timing of the monostable trigger under the drive of the clear signal output by the latch arbitration circuit. The resistor-capacitor network is connected to the monostable trigger and is used to set a first set delay for the monostable trigger. When the controllable pulse generator does not generate a pulse within the first set delay, the monostable trigger generates a timeout reset signal. After passing through the shaping network, the signal serves as a reset signal to restart the corresponding intelligent computing module or the external interface module.
Citation Information
Patent Citations
Heterogeneous satellite-borne fault-tolerant computer based on COTS (Commercial Off The Shelf) device
CN102053882A
Intelligent watchdog system based on complex programmable logic device
CN109753373A