Satellite on-orbit cold start monitoring system and device and storage medium

By recording and monitoring satellite cold start parameters through MRAM and Nor Flash memory modules, the problem of satellite cold start data loss in orbit is solved, efficient cold start monitoring and fault recovery are achieved, and the stability of satellite operation and troubleshooting capabilities are improved.

CN120653312APending Publication Date: 2025-09-16SHANGHAI SPACEFLIGHT INST OF TT&C & TELECOMM +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510556210.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

The cold start phenomenon of satellites in orbit leads to data loss, and the number and duration of cold starts cannot be effectively monitored, which affects satellite status analysis and troubleshooting and increases operational risks.

Method used

MRAM and Nor Flash memory modules are used, and cold start parameters are recorded and monitored through non-volatile memory modules, parallel storage control modules and cold start monitoring modules. The parameters are then transmitted to the ground measurement and control system through the satellite-to-ground link, and word-level three-out-of-two repair data is combined to ensure data integrity.

Benefits of technology

It realizes the rapid writing and persistent storage of on-orbit cold start parameters, improves the accuracy of satellite operation status analysis and troubleshooting efficiency, shortens fault recovery time, and reduces the impact of program errors caused by single-particle upsets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120653312A_ABST
    Figure CN120653312A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of aerospace engineering, in particular to a satellite on-orbit cold start monitoring system, which comprises a nonvolatile memory module, an MRAM (Magnetic Random Access Memory) memory, a Nor Flash memory, a Nor Flash memory module, a Nor Flash memory module and a Nor Flash memory module, according to the parallel storage control module, an MRAM manager manages the storage address and state of a cold start log through a storage interface index table, and a Flash manager writes cold start duration data into a Nor Flash storage area; the cold start monitoring module is used for loading an operating system target code to a memory from a Nor Flash storage area in a two-out-of-three mode, repairing data according to word level two-out-of-three when verification fails, and triggering the time synchronization module and a main node clock to correct time when a cold start mark is set; and the communication module is used for analyzing the ground remote control instruction, packaging the cold start parameter into a telemetering frame, and injecting the telemetering frame into a ground measurement and control system. The method can ensure that data are not lost after the satellite is powered off, effectively monitors the cold start frequency and duration parameters, and supports a ground measurement and control system to monitor and analyze the satellite in-orbit state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of aerospace engineering technology, and in particular to a satellite on-orbit cold start monitoring system, equipment and storage medium. Background Art

[0002] During satellite operation and launch, there is a risk of in-orbit cold starts. This refers to a sudden power-on startup of a satellite due to abnormal operation during operation. During launch, solar panels may provide power to the satellite after being exposed to sunlight, which can easily cause an in-orbit cold start.

[0003] Typically, after a satellite loses power, the data in its memory cannot be saved. Due to the lack of an effective data storage and recording mechanism, satellites are unable to monitor the number and duration of cold starts in orbit. Parameters such as the number and duration of cold starts are crucial for accurately assessing the satellite's on-orbit operational status. The lack of these cold start parameters makes it difficult for ground personnel to conduct a comprehensive and in-depth analysis of the satellite's on-orbit status, making it impossible to promptly identify potential problems with the satellite. This, in turn, affects the assessment and troubleshooting of the satellite's overall operational performance, introducing numerous uncertainties and potential risks to the satellite's stable operation and scientific applications. Summary of the Invention

[0004] The purpose of the present invention is to solve the shortcomings of the prior art and provide a satellite on-orbit cold start monitoring system, comprising: A non-volatile memory module includes an MRAM memory and a Nor Flash memory. The MRAM memory is divided into several physical partitions for storing operating system software and statically compiled application software, and a metadata header including a checksum, software length, and version identifier is stored at the software start address. When loading a program in the physical partition, a physical partition check mechanism determines whether to load the program based on the metadata header. The Nor Flash memory is divided into a primary partition and a redundant partition for storing a dynamically compiled software set. Several satellite parameter storage areas are divided in the remaining space of the Nor Flash memory for recording cold start parameters including the number and duration of cold starts. A parallel storage control module includes an MRAM manager and a Nor Flash manager, wherein the MRAM manager manages the storage address and status of the cold start log through a storage interface index table, and the Flash manager divides the NorFlash storage area into blocks and writes cold start duration data sequentially; The cold start monitoring module is configured to read the same operating system target code data from three different Nor Flash storage areas at the same time when the satellite is powered on, and compare the operating system target code data read from the three different Nor Flash storage areas in pairs. If two of the data are the same, the correct operating system target code data is selected and loaded into the system memory. During the loading process, the cold start monitoring module monitors the integrity of data transmission to ensure that the data is written into the memory accurately. The operating system target code data loaded into the memory is subjected to a cyclic redundancy check (CRC) calculation to generate an operating system check code. The check code verification check is performed based on the operating system check code. If the operating system check code verification fails, the data is repaired by taking two out of three at the word level, and the time synchronization module is triggered to calibrate the time with the master node clock when the cold start flag is set. The communication module is used to parse ground remote control commands, encapsulate cold start parameters into CCSDS standard telemetry frames, and transmit them to the ground measurement and control system through the satellite-to-ground link.

[0005] Preferably, the physical partition verification mechanism verifies whether the program is loaded according to the metadata header, including: When the operating system loads the program of the physical partition, the physical partition verification mechanism reads the program according to the length information of the software start address in the physical partition; The physical partition verification mechanism performs the verification code verification check, software length check and version identification check based on the verification code, the software length and the version identification. If all the checks are passed, the physical partition verification mechanism determines that the program can be loaded. If any one of the verification code verification check, the software length check and the version identification check fails, loading of the program that failed the verification is prohibited and an alarm flag is triggered. The alarm flag and the physical address of the failed partition are encapsulated into an alarm telemetry data packet, which is sent to the ground measurement and control system, and the program is repaired or switched to the backup physical partition through ground commands.

[0006] Preferably, the check code verification check, the software length check and the version identification check include: The checksum verification check is to calculate the program data to obtain a real-time checksum value, and compare the real-time checksum value with the original checksum stored in the metadata header. If the real-time checksum is consistent with the original checksum, the program data has not been corrupted or tampered with during storage. If the real-time checksum is inconsistent with the original checksum, the verification fails. The software length check is to compare the software length stored in the metadata header with the actual length of the read software data. If the two do not match, an error including missing software data, storage error, or tampering occurs, and the check fails. If they match, no error including missing software data, storage error, or tampering occurs. If the actual length of the read software data is greater than the software length recorded in the metadata header, additional illegal data exists. If the actual length of the read software data is less than the software length recorded in the metadata header, the software data is partially lost. The version identification check compares the version identification in the metadata header with the expected version identification. If the versions do not match, the software will be incompatible with other parts of the system, thereby affecting the normal operation of the system.

[0007] Preferably, the primary partition and redundant partition for storing the dynamically compiled software set include: After the Nor Flash memory receives a new dynamically compiled software set including management software, integrated electronic software, attitude and orbit control software, and cold start monitoring software, that is, a software update instruction, it calculates a CRC software check value for the new version software set, and compares the CRC software check value with the expected check value injected from the ground. If the CRC software check value is consistent, the new version software set is written into the primary partition and the redundant partition. If the check fails, the old version is retained and marked as the version software to be repaired.

[0008] Preferably, the MRAM manager and the Flash manager include: The MRAM manager supports multi-channel access. When recording cold start related information, the MRAM manager creates an interface index table according to the interface index table structure including the log sequence, start address, data length, and status flag; The Flash manager divides the Nor Flash storage area into blocks to obtain the Nor Flash storage area. When cold start duration data is written into the Nor Flash storage area, the Flash manager first checks the block status table, filters out blocks marked as being in an idle state, and writes the cold start duration data into the selected idle blocks in chronological order. When subsequently writing new cold start duration data, the Flash manager skips the blocks marked as being in an occupied state. Preferably, the word-level 2-out-of-3 data repairing method includes: If the CRC check fails, the cold start monitoring module checks the operating system target code data word by word to confirm the location of the error word and reads three copies of the data corresponding to the location of the error word from the physical partition of the non-volatile memory; The three copies of the data are compared pairwise, and the contents of each word unit are compared word by word. A majority vote mechanism is performed on each word. If the contents of at least two word units are the same, the same content is used as the repair word. If all three words are different, the word is marked as an error word, and the word of the physical partition is selected as the repair word according to the preset priority. Combine all repair words in sequence to generate the repaired operating system target code and load it into the memory file system.

[0009] Preferably, the time synchronization module includes: The time synchronization module continuously detects the status of the cold start flag. When the cold start flag is set to 1, it sends a PTP protocol synchronization request to the synchronization master node. The synchronization master node sends a response message according to the PTP protocol synchronization request. The time synchronization module calculates the clock offset Offset and the transmission delay Delay according to the received response message and the time record of sending the PTP protocol synchronization request, generates a compensation value according to the clock offset Offset and the transmission delay Delay, uses a linear regression algorithm to predict the clock drift trend, dynamically adjusts the local clock frequency, and broadcasts the calibrated clock signal to the attitude and orbit control, power management, and communication subsystems through the CAN bus. After receiving the clock signal, each subsystem updates the local timer and feeds back a confirmation signal to the time synchronization module; Receive high-precision clock signals from the master node, calibrate local clocks, and broadcast them to each subsystem; The time synchronization module records the start timestamp of the cold start duration when the cold start flag is set to 1, and records the end timestamp after the system completes cold start related operations including clock synchronization.

[0010] Preferably, the communication module further comprises: Receive remote control commands from the ground measurement and control system and parse the source file path and destination address in the commands; Invoke a system copy command to copy the cold start parameters from a specified path of the non-volatile memory module to an onboard cache area; According to the CCSDS (Consultative Committee for Space Data Systems) standard, the cold start parameters are encapsulated into a transmission frame, wherein the transmission frame includes a frame header field, a data field, and a data field, wherein the frame header field includes a synchronization flag, a frame length, and a parameter version number, the data field includes the number of cold starts, the total cold start duration, and the last cold start timestamp, and the frame trailer field includes a CRC-32 checksum, an overlay frame header and data fields, and a frame end marker; The transmission frames are sent to the ground measurement and control system via the satellite-to-ground link, and the link transmission protocol adopts telemetry channel coding that complies with the CCSDS standard.

[0011] Based on the same concept, the present invention also provides a computer device, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes a module of the satellite in-orbit cold start monitoring system as described in any one of the embodiments.

[0012] Based on the same concept, the present invention also provides a storage medium storing computer-readable instructions. When the computer-readable instructions are executed by one or more processors, the one or more processors execute the modules of the satellite in-orbit cold start monitoring system as described in the embodiment.

[0013] Compared with the prior art, the present invention has the following beneficial effects: The present invention uses a high-performance non-volatile memory module to store the number and duration of satellite on-orbit cold start parameters, enabling rapid writing and persistent storage of on-orbit parameters. This effectively solves the problem of on-orbit parameter loss in the event of a power outage after a satellite on-orbit cold start. By storing operating system software and statically compiled application software in physical partitions, and storing dynamically compiled software collections in the primary and redundant partitions of the file system, the operating system and application programs are isolated and protected. The present invention uses a cold start monitoring module and a parallel storage control module to redundantly monitor and save high-precision cold start times and duration parameters after a satellite is cold started. After the satellite is operating normally, the data is sent to a ground measurement and control system via telemetry, shortening the fault recovery time. In addition, data is repaired by performing two-out-of-three word-level repairs to resolve program errors caused by single-event upsets. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Various other advantages and benefits will become apparent to those skilled in the art by reading the following detailed description of the preferred embodiment.The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the invention.

[0015] Figure 1 Schematic diagram of an off-chip non-volatile memory according to an embodiment of the present invention; Figure 2 A schematic diagram of time synchronization and parallel storage according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a cold start monitoring module according to an embodiment of the present invention; Figure 4 This is a flow chart of the communication module of the present invention sending bets to the ground measurement and control system. DETAILED DESCRIPTION

[0016] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Obviously, the embodiments described are part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of this application.

[0017] Those skilled in the art will understand that, unless otherwise specified, the singular forms "a," "an," and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0018] First embodiment See also Figure 1 、 Figure 2 and Figure 3 As shown, this embodiment provides a satellite on-orbit cold start monitoring system, specifically including: A non-volatile memory module includes an MRAM memory and a Nor Flash memory. The MRAM memory is divided into several physical partitions for storing operating system software and statically compiled application software, and a metadata header including a check code, software length and version identifier is stored at the software start address. When loading a program in a physical partition, the physical partition check mechanism determines whether to load the program based on the metadata header. The Nor Flash memory is divided into a primary partition and a redundant partition for storing a dynamically compiled software set, and several satellite parameter storage areas are divided in the remaining space of the Nor Flash memory to record cold start parameters including the number and duration of cold starts. Specifically, in this embodiment, the Fudan Microelectronics JFM29LV641RH Nor Flash is used to design a spatial layout of the non-volatile memory module, including four physical partitions and two file system partitions. The physical partitions are physical partition A, physical partition B, physical partition C and physical partition D. With the support of the operating system device driver, a Nor is established on the non-volatile memory. Flash memory, several satellite parameter storage areas M0, M1, M2..., M7, used to store the number and duration parameters of satellite in-orbit cold start, and the files of the memory file system are synchronized to the non-volatile memory physical partition D, the Nor Flash memory partition main partition and the file system partition redundant partition.

[0019] Preferably, the physical partition verification mechanism verifies whether the program is loaded based on the metadata header, including: When the operating system loads a program in a physical partition, the physical partition verification mechanism reads the program based on the length information of the software start address in the physical partition; The physical partition verification mechanism performs check code verification check, software length check and version identification check based on the check code, software length and version identification. If all the checks pass, the physical partition verification mechanism determines that the program can be loaded. If any of the check code verification check, software length check and version identification check fails, the loading of the program that failed the verification is prohibited and an alarm flag is triggered. The alarm flag and the physical address of the failed partition are encapsulated into an alarm telemetry data packet and sent to the ground measurement and control system. The program is repaired or switched to the backup physical partition through ground commands.

[0020] Preferably, the check code verification check, software length check and version identification check include: The checksum verification check calculates the real-time checksum value of the program data and compares it with the original checksum stored in the metadata header. If the real-time checksum is consistent with the original checksum, the program data has not been corrupted or tampered with during storage. If the real-time checksum is inconsistent with the original checksum, the verification fails. The software length check compares the software length stored in the metadata header with the actual length of the software data read. If the two do not match, an error, including missing software data, storage error, or tampering, has occurred, and the check has failed. If they match, no error, including missing software data, storage error, or tampering, has occurred. If the actual length of the software data read is greater than the software length recorded in the metadata header, there is additional illegal data. If the actual length of the software data read is less than the software length recorded in the metadata header, the software data is partially lost. The version identification check compares the version identification in the metadata header with the expected version identification. If the versions do not match, the software will be incompatible with other parts of the system, thus affecting the normal operation of the system.

[0021] Preferably, the primary partition and redundant partition for storing the dynamically compiled software set include: After the Nor Flash memory receives a new dynamically compiled software set including management software, integrated electronic software, attitude and orbit control software, and cold start monitoring software, that is, a software update instruction, it calculates the CRC software checksum value for the new version of the software set and compares the CRC software checksum value with the expected checksum value injected from the ground. If the CRC software checksum values ​​are consistent, the new version of the software set is written into the primary partition and the redundant partition. If the check fails, the old version is retained and marked as the version of the software to be repaired.

[0022] See also Figure 2 As shown, the parallel storage control module includes an MRAM manager and a Nor Flash manager. The MRAM manager manages the storage address and status of the cold start log through the storage interface index table. The Flash manager divides the Nor Flash storage area into blocks and writes the cold start duration data sequentially. Specifically, in this embodiment, LSMR64M08VS4E1 MRAM and JRTAX2000-LG624YB FPGA are used. MRAM+Nor Flash parallel storage is controlled based on FPGA hardware. MRAM realizes data interaction between multiple memories through the MRAM manager, and Nor Flash stores each data in the corresponding Flash through the Flash manager.

[0023] Preferably, the MRAM manager and the Flash manager include: The MRAM manager supports multi-channel access. When recording cold start related information, the MRAM manager builds an interface index table based on the interface index table structure including the log sequence, starting address, data length, and status flag. Specifically, in this embodiment, when the operating system sets the cold start flag to 1, the MRAM memory's storage space is obtained to store the sequence number information of the cold start log. The log number, i.e., the number of satellite cold starts, is used to store the log number and log data in the MRAM storage space. The Flash manager divides the Nor Flash storage area into blocks to obtain the Nor Flash storage area. When cold start duration data is written to the Nor Flash storage area, the Flash manager first checks the block status table, filters out the blocks marked as idle, and writes the cold start duration data into the selected idle blocks in chronological order. When writing new cold start duration data subsequently, the Flash manager skips the blocks marked as occupied. Specifically, in this embodiment, after the operating system sets the cold start flag to 1, the storage space of the Nor Flash memory is obtained to store the cold start duration information, that is, the time of the satellite cold start, and the cold start duration data is saved in the Nor Flash storage space.

[0024] See also Figure 3As shown, the cold start monitoring module is configured to read the same operating system target code data from three different Nor Flash storage areas at the same time when the satellite stand-alone is powered on, and compare the operating system target code data read from the three different Nor Flash storage areas in pairs. If two of the data are the same, the correct operating system target code data is selected and loaded into the system memory. During the loading process, the cold start monitoring module monitors the integrity of data transmission to ensure that the data is written into the memory accurately. The operating system target code data loaded into the memory is subjected to a cyclic redundancy check (CRC) calculation to generate an operating system check code. The check code verification check is performed based on the operating system check code. If the operating system check code verification fails, the data is repaired at the word level by taking two out of three, and the time synchronization module is triggered to calibrate the master node clock when the cold start flag is set. Specifically, in this embodiment, after the stand-alone is powered on, the cold start monitoring software loads the operating system target code from the non-volatile memory Flash physical area into the memory in a "three-out-two" manner, starts the operating system, and mounts the Flash file system after the operating system is started. The operating system starts by calling the system command A command is issued to establish a memory file system. After the memory file system is successfully established, the operating system determines the system cold start flag, clears the data in the three-out-of-two area, sets the hot and cold start flag to the cold start flag, and loads the cold start monitoring module at the same time. The loading process is as follows: first, the CRC value of the first data is checked. If it is correct, the first copy is read and written to the memory file system. If the CRC of the first data is incorrect, the second data is checked. If it is correct, the second copy is read and written to the memory file system. If the CRC of the second data is incorrect, the third data is checked. If it is correct, the third copy is read and written to the memory file system. If the third data check is also incorrect, the three copies of data are read and written to the memory file system word by word. The cold start parameter log file is set to be stored in MRAM, the number of cold starts and the duration variables are set. When the cold start flag is set to 1, the cold start duration count can be started. The startup time of each system is recorded in turn according to the time synchronization module, and the number of cold starts is increased by 1.

[0025] Preferably, repairing data by taking two out of three at word level includes: If the CRC check fails, the cold start monitoring module checks the operating system target code data word by word to confirm the location of the error word and reads three copies of the data corresponding to the location of the error word from the physical partition of the non-volatile memory; The three copies of the data are compared pairwise, and the contents of each word unit are compared word by word. A majority vote mechanism is performed on each word. If the contents of at least two word units are the same, the same content is used as the repair word. If all three words are different, the word is marked as an error word, and the word of the physical partition is selected as the repair word according to the preset priority. Combine all repair words in sequence to generate the repaired operating system target code and load it into the memory file system.

[0026] Preferably, the time synchronization module includes: The time synchronization module continuously detects the status of the cold start flag. When the cold start flag is set to 1, it sends a PTP protocol synchronization request to the synchronization master node. The synchronization master node sends a response message according to the PTP protocol synchronization request. The time synchronization module calculates the clock offset Offset and the transmission delay Delay according to the received response message and the time record of sending the PTP protocol synchronization request, generates a compensation value according to the clock offset Offset and the transmission delay Delay, uses a linear regression algorithm to predict the clock drift trend, dynamically adjusts the local clock frequency, and broadcasts the calibrated clock signal to the attitude and orbit control, power management, and communication subsystems through the CAN bus. After receiving the clock signal, each subsystem updates the local timer and feeds back a confirmation signal to the time synchronization module. Specifically, in this embodiment; Receive high-precision clock signals from the master node, calibrate local clocks, and broadcast them to each subsystem; The time synchronization module records the start timestamp of the cold start duration when the cold start flag is set to 1, and records the end timestamp after the system completes the cold start-related operations including clock synchronization. Specifically, in this embodiment, when the operating system sets the cold start flag to 1, the storage space of the Nor Flash memory is obtained to store the cold start duration information, that is, the time of the satellite cold start, and the cold start duration data is saved to the Nor Flash storage space.

[0027] The communication module is used to parse ground remote control commands, encapsulate cold start parameters into CCSDS standard telemetry frames, and transmit them to the ground measurement and control system through the satellite-to-ground link.

[0028] See also Figure 4 As shown, the communication module further includes: Receive remote control commands from the ground measurement and control system and parse the source file path and destination address in the commands; Call the system copy command to copy the cold start parameters from the specified path of the non-volatile memory module to the onboard cache area; According to the CCSDS (Consultative Committee for Space Data Systems) standard, the cold start parameters are encapsulated into a transmission frame. The transmission frame includes a frame header field, a data field, and a data field. The frame header field includes a synchronization flag, a frame length, and a parameter version number. The data field includes the number of cold starts, the total cold start duration, and the timestamp of the last cold start. The frame trailer field includes a CRC-32 checksum, an overlay frame header and data fields, and a frame end marker. The transmission frames are sent to the ground measurement and control system via the satellite-to-ground link, and the link transmission protocol adopts telemetry channel coding that complies with the CCSDS standard.

[0029] Second embodiment In some embodiments of the present application, a computer device is also provided, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes the module of the satellite in-orbit cold start monitoring system in the first embodiment of the present invention.

[0030] In some embodiments of the present application, a storage medium storing computer-readable instructions is also provided. When the computer-readable instructions are executed by one or more processors, the one or more processors execute a module of a satellite in-orbit cold start monitoring system in one embodiment of the present invention.

[0031] It can be understood that for the aforementioned satellite in-orbit cold start monitoring system, if it is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer server, or a network device, etc.) to execute all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.

[0032] Computer-readable storage media may include a data signal propagated in baseband or as part of a carrier wave, which carries readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0033] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiment. All technical solutions based on the concept of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A satellite on-orbit cold start monitoring system, characterized in that: include: A non-volatile memory module includes an MRAM memory and a Nor Flash memory. The MRAM memory is divided into several physical partitions for storing operating system software and statically compiled application software, and a metadata header including a checksum, software length, and version identifier is stored at the software start address. When loading a program in the physical partition, a physical partition check mechanism determines whether to load the program based on the metadata header. The Nor Flash memory is divided into a primary partition and a redundant partition for storing a dynamically compiled software set. Several satellite parameter storage areas are divided in the remaining space of the Nor Flash memory for recording cold start parameters including the number and duration of cold starts. A parallel storage control module includes an MRAM manager and a Nor Flash manager, wherein the MRAM manager manages the storage address and status of the cold start log through a storage interface index table, and the Flash manager divides the Nor Flash storage area into blocks and writes cold start duration data sequentially; The cold start monitoring module is configured to read the same operating system target code data from three different Nor Flash storage areas at the same time when the satellite is powered on, and compare the operating system target code data read from the three different Nor Flash storage areas in pairs. If two of the data are the same, the correct operating system target code data is selected and loaded into the system memory. During the loading process, the cold start monitoring module monitors the integrity of data transmission to ensure that the data is written into the memory accurately. The operating system target code data loaded into the memory is subjected to a cyclic redundancy check (CRC) calculation to generate an operating system check code. The check code verification check is performed based on the operating system check code. If the operating system check code verification fails, the data is repaired by taking two out of three at the word level, and the time synchronization module is triggered to calibrate the time with the master node clock when the cold start flag is set. The communication module is used to parse ground remote control commands, encapsulate cold start parameters into CCSDS standard telemetry frames, and transmit them to the ground measurement and control system through the satellite-to-ground link.

2. The satellite on-orbit cold start monitoring system according to claim 1, characterized in that: The physical partition verification mechanism verifies whether the program is loaded based on the metadata header, including: When the operating system loads the program of the physical partition, the physical partition verification mechanism reads the program according to the length information of the software start address in the physical partition; The physical partition verification mechanism performs the verification code verification check, software length check and version identification check based on the verification code, the software length and the version identification. If all the checks are passed, the physical partition verification mechanism determines that the program can be loaded. If any one of the verification code verification check, the software length check and the version identification check fails, loading of the program that failed the verification is prohibited and an alarm flag is triggered. The alarm flag and the physical address of the failed partition are encapsulated into an alarm telemetry data packet, which is sent to the ground measurement and control system, and the program is repaired or switched to the backup physical partition through ground commands.

3. The satellite on-orbit cold start monitoring system according to claim 2, characterized in that: The verification code verification check, the software length check, and the version identification check include: The checksum verification check is to calculate the program data to obtain a real-time checksum value, and compare the real-time checksum value with the original checksum stored in the metadata header. If the real-time checksum is consistent with the original checksum, the program data has not been corrupted or tampered with during storage. If the real-time checksum is inconsistent with the original checksum, the verification fails. The software length check is to compare the software length stored in the metadata header with the actual length of the read software data. If the two do not match, an error including missing software data, storage error, or tampering occurs, and the check fails. If they match, no error including missing software data, storage error, or tampering occurs. If the actual length of the read software data is greater than the software length recorded in the metadata header, additional illegal data exists. If the actual length of the read software data is less than the software length recorded in the metadata header, the software data is partially lost. The version identification check compares the version identification in the metadata header with the expected version identification. If the versions do not match, the software will be incompatible with other parts of the system, thereby affecting the normal operation of the system.

4. The satellite on-orbit cold start monitoring system according to claim 3, characterized in that: Primary and redundant partitions for storing dynamically compiled software collections, including: After the Nor Flash memory receives a new dynamically compiled software set including management software, integrated electronic software, attitude and orbit control software, and cold start monitoring software, that is, a software update instruction, it calculates a CRC software check value for the new version software set, and compares the CRC software check value with the expected check value injected from the ground. If the CRC software check value is consistent, the new version software set is written into the primary partition and the redundant partition. If the check fails, the old version is retained and marked as the version software to be repaired.

5. The satellite on-orbit cold start monitoring system according to claim 4, characterized in that: The MRAM manager and the Flash manager include: The MRAM manager supports multi-channel access. When recording cold start related information, the MRAM manager creates an interface index table according to the interface index table structure including the log sequence, start address, data length, and status flag; The Flash manager divides the Nor Flash storage area into blocks to obtain the Nor Flash storage area. When cold start duration data is written into the Nor Flash storage area, the Flash manager first checks the block status table, filters out blocks marked as idle, and writes the cold start duration data into the selected idle blocks in chronological order. When subsequently writing new cold start duration data, the Flash manager skips the blocks marked as occupied.

6. The satellite on-orbit cold start monitoring system according to claim 5, characterized in that: The word-level 2-out-of-3 data repair method includes: If the CRC check fails, the cold start monitoring module checks the operating system target code data word by word to confirm the location of the error word and reads three copies of the data corresponding to the location of the error word from the physical partition of the non-volatile memory; The three copies of the data are compared pairwise, and the contents of each word unit are compared word by word. A majority vote mechanism is performed on each word. If the contents of at least two word units are the same, the same content is used as the repair word. If all three words are different, the word is marked as an error word, and the word of the physical partition is selected as the repair word according to the preset priority. Combine all repair words in sequence to generate the repaired operating system target code and load it into the memory file system.

7. The satellite on-orbit cold start monitoring system according to claim 6, characterized in that: The time synchronization module includes: The time synchronization module continuously detects the status of the cold start flag. When the cold start flag is set to 1, it sends a PTP protocol synchronization request to the synchronization master node. The synchronization master node sends a response message according to the PTP protocol synchronization request. The time synchronization module calculates the clock offset Offset and the transmission delay Delay according to the received response message and the time record of sending the PTP protocol synchronization request, generates a compensation value according to the clock offset Offset and the transmission delay Delay, uses a linear regression algorithm to predict the clock drift trend, dynamically adjusts the local clock frequency, and broadcasts the calibrated clock signal to the attitude and orbit control, power management, and communication subsystems through the CAN bus. After receiving the clock signal, each subsystem updates the local timer and feeds back a confirmation signal to the time synchronization module; Receive high-precision clock signals from the master node, calibrate local clocks, and broadcast them to each subsystem; The time synchronization module records the start timestamp of the cold start duration when the cold start flag is set to 1, and records the end timestamp after the system completes cold start related operations including clock synchronization.

8. The satellite on-orbit cold start monitoring system according to claim 7, characterized in that: The communication module includes: Receive remote control commands from the ground measurement and control system and parse the source file path and destination address in the commands; Invoking a system copy command to copy the cold start parameters from a specified path of the non-volatile memory module to an onboard cache area; According to the CCSDS standard, the cold start parameters are encapsulated into a transmission frame, wherein the transmission frame includes a frame header field, a data field, and a data field, wherein the frame header field includes a synchronization flag, a frame length, and a parameter version number, the data field includes the number of cold starts, the total cold start duration, and the last cold start timestamp, and the frame tail field includes a CRC-32 checksum, an overlay frame header and data fields, and a frame end marker; The transmission frames are sent to the ground measurement and control system via the satellite-to-ground link, and the link transmission protocol adopts telemetry channel coding that complies with the CCSDS standard.

9. A computer device, characterized in that: The system comprises a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes a module of the satellite on-orbit cold start monitoring system according to any one of claims 1 to 8.

10. A storage medium storing computer-readable instructions, characterized in that: When the computer-readable instructions are executed by one or more processors, the one or more processors execute the modules of the satellite on-orbit cold start monitoring system according to any one of claims 1 to 8.

Citation Information

Cited By

  • A self-healing method and system for on-orbit anomalies of satellite-borne processor software

    CN122431942A