Maintainable spacecraft control unit architecture
By using a combination of high-performance CPU processors, antifuse PROM memory, and large-capacity FLASH/SRAM memory in the spacecraft control unit, the reliability and maintainability issues of the high-orbit spacecraft control unit were solved, enabling stable operation and maintenance of on-orbit software and improving the long-term on-orbit operation capability of the spacecraft.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI INST OF SPACE PROPULSION
- Filing Date
- 2026-01-05
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies are insufficient to meet the high reliability and maintainability requirements of control units for high-orbit spacecraft, especially the difficulty in maintaining on-orbit software, which affects the long-term stable operation and safety of spacecraft.
It employs a high-performance CPU processor, an externally expandable one-time programmable anti-fuse PROM memory for the boot program, an externally expanded capacity FLASH memory for the application software, and performs a 3-out-of-2 comparison and error correction in the SRAM memory to ensure the reliability and maintainability of the software.
It achieves high reliability and maintainability of spacecraft control units, ensures the stability and reliability of software operation in orbit, supports on-orbit software maintenance, and extends the life and safety of spacecraft.
Smart Images

Figure CN122111325A_ABST
Abstract
Description
Technical Field
[0001] This invention pertains to control unit architectures applied to spacecraft, specifically, to maintainable control unit architectures for spacecraft. More particularly, it relates to a highly reliable and maintainable control unit architecture for spacecraft. Background Technology
[0002] Currently, as the cost and value of individual spacecraft, especially high-orbit spacecraft, increase, users are placing higher demands on the lifespan, long-term on-orbit reliability, and maintainability of spacecraft. To meet these demands, it is essential to first ensure that the core control unit of the spacecraft can operate stably and reliably for a long period of time. At the same time, on-orbit software maintenance is applied to the long-term operation and maintenance of the spacecraft to ensure that the spacecraft can work continuously, stably, and safely during its on-orbit operation. This is technical support that involves the entire life cycle of the spacecraft and has a direct impact on the success or failure of the spacecraft mission.
[0003] Patent document CN117170719A discloses a high-speed, high-reliability software on-orbit update method and a data management computer system. The main steps of the method include: on-orbit update data frames are uploaded via a high-speed uploading channel; the data management computer processor receives the uploading data through a high-speed interface and temporarily stores it in a large-capacity data storage device external to the processor; after parsing the data frame, the data management computer determines the update data based on the instruction sequence number: if it is update data for the data management software, the update data is written to the CPU software program erasable memory; if it is update data for other configuration items, it is distributed from the corresponding channel.
[0004] To meet the higher demands of long-term on-orbit spacecraft for high reliability and maintainability of control units, it is necessary to provide a maintainable control unit architecture for spacecraft. Summary of the Invention
[0005] In view of the shortcomings of the prior art, the purpose of this invention is to provide a maintainable control unit architecture for spacecraft.
[0006] According to the present invention, a maintainable spacecraft control unit architecture includes: a hardware architecture; In the hardware architecture, a high-performance CPU processor is selected, and one or more of the following devices are added externally: A one-time programmable antifuse PROM type memory is used to store the boot program; A large-capacity FLASH memory is used to store application software; A large-capacity SRAM memory is used for software operation.
[0007] Preferably, the boot program relies on an antifuse PROM type memory that can be programmed once and is not affected by single particles in the space environment.
[0008] Preferably, the application software is burned into the FLASH memory in three copies. After each power-on, the bootloader reads the three copies of software data from the FLASH memory and compares them byte by byte. The comparison is performed in a two-out-of-three manner. The result returned by the comparison is used as the application software. If the three copies are inconsistent, the first copy of software data is used.
[0009] Preferably, after each power-on, a two-out-of-three comparison is performed on the application software in the FLSAH type memory, and the comparison result is written into the SRAM type memory.
[0010] Preferably, the high-performance CPU processor drives the application software to have error detection and correction functions when running in SRAM-type memory, so as to correct one-bit errors in the data and detect two-bit errors in the data during the software operation.
[0011] Preferably, after the application software starts running, it periodically reads and compares the three application software source files stored in the FLSAH type memory. If an inconsistency is detected, the erroneous file is automatically corrected, so that the application software in the FLSAH type memory can recover itself when errors occur due to the influence of the space environment.
[0012] Preferably, a high-performance CPU processor is selected, and an external large-capacity FLASH memory is used to store application software. At the same time, three additional spaces are reserved in the large-capacity FLASH memory to store on-orbit maintenance programs. When on-orbit maintenance software is required, the software source file is received via the communication bus and temporarily stored in the SRAM memory. After receiving the file, the on-orbit software cached in the SRAM memory is written into the three additional spaces in the FLASH memory via ground command control. Upon the next power-on startup, the application software can be read from the FLASH memory and written into the SRAM memory for execution.
[0013] Preferably, it also includes: a software runtime architecture; In the software operating architecture, the bootloader is burned into the antifuse PROM type memory, the application program is burned into the large-capacity FLSAH type memory, and three copies are burned. At the same time, three additional copies of the large-capacity FLSAH type memory are reserved for storing the on-orbit maintenance program.
[0014] Preferably, after the control unit is powered on, the high-performance CPU processor first reads the boot software in the PROM type memory. The function of the boot software is to control the CPU to perform a two-out-of-three comparison of the three application software files in the FLSAH type memory, write the comparison result into the SRAM type memory, and start running the application software in the SRAM type memory. During the operation of the application software, the two-out-of-three comparison of the data in the FLSAH type memory is performed periodically. If an inconsistency is detected, the erroneous file is automatically corrected.
[0015] Preferably, when software maintenance is required on-orbit, the software source file is received via the communication bus and temporarily stored in an SRAM-type memory. After receiving the file, the software cached in the SRAM-type memory is written into three additional spaces reserved in the FLASH-type memory via ground command control. The application software that is injected into the FLASH-type memory can be read from the FLASH-type memory and written into the SRAM-type memory for execution upon the next power-on.
[0016] Compared with the prior art, the present invention has the following beneficial effects: 1. In this invention, an external large-capacity FLASH memory is used to store application software, and the application software is burned into the FLASH memory in three copies. Each time the power is turned on, two out of three copies are compared, which effectively ensures the reliability of application software saving and startup. 2. During the operation of the application software, the present invention periodically performs a two-out-of-three comparison of the data in the FLSAH type memory. If an inconsistency is detected, the erroneous file is automatically corrected, further ensuring the reliability of the application software for long-term storage. 3. The present invention includes an external large-capacity SRAM memory for software operation, effectively ensuring the reliability of application software operation. When on-orbit maintenance of application software is required, the source file to be uploaded is first cached in the SRAM memory, and then written into the three additional spaces reserved in the FLASH memory. The uploaded version of the software can then be run upon the next power-on startup. Attached Figure Description
[0017] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 This is a schematic diagram of the hardware architecture of the control unit. Detailed Implementation
[0018] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the protection scope of the present invention.
[0019] To achieve highly reliable operation of control unit hardware and software on long-term orbital spacecraft, this invention provides a highly reliable and maintainable spacecraft control unit architecture that meets the requirements of long-term orbital spacecraft for high reliability and maintainability of control units. This invention selects a high-performance CPU processor and externally expands it with a one-time programmable antifuse PROM type memory to store the boot program, ensuring highly reliable storage and operation of the boot program.
[0020] This invention provides a highly reliable and maintainable control unit architecture for spacecraft. It consists of a hardware architecture and a software operation architecture.
[0021] like Figure 1 As shown, the hardware architecture includes: a high-performance CPU processor, an external anti-fuse PROM type memory for storing the boot program (which can be programmed once), a large-capacity FLASH type memory for storing application software, and a large-capacity SRAM type memory for software operation.
[0022] Among them, a high-performance CPU processor is selected, and an external anti-fuse PROM type memory that can be programmed once is used to store the boot program. This can effectively ensure that the boot program is not affected by single particles in the space environment, and achieve high reliability in the storage and operation of the boot program.
[0023] A high-performance CPU processor is selected, and an external large-capacity FLASH memory is used to store the application software. Three copies of the application software are burned into the FLASH memory. Each time power is applied, the bootloader reads the three copies of software data from the FLASH memory and compares them byte-by-byte. The comparison is performed using a two-out-of-three method. The result returned by the comparison is used as the application software. If all three copies do not match, the first copy of software data is used. This method effectively ensures the reliability of application software saving and startup.
[0024] A high-performance CPU processor is selected, and a large-capacity SRAM memory is externally installed for software operation. Upon each power-on, a two-out-of-three comparison is performed on the application software stored in the FLSAH memory, and the comparison result is written to the SRAM memory. The high-performance CPU processor driving the application software to run in the SRAM memory has EDAC (Error Detection and Correction) functionality. This function can correct one-bit errors and detect two-bit errors during software operation, effectively ensuring the reliability of the application software. After the application software starts running, it periodically reads and compares the three application software source files stored in the FLSAH memory. If inconsistencies are detected, the erroneous file is automatically corrected. This allows the application software in the FLSAH memory to recover itself from errors caused by space environment factors, further ensuring the long-term reliability of the application software.
[0025] A high-performance CPU processor was selected, and an external large-capacity FLASH memory was added to store application software. Additionally, three extra spaces were reserved within the large-capacity FLASH memory for storing on-orbit maintenance programs. When on-orbit software maintenance is required, the software source file is received via the communication bus and temporarily stored in SRAM memory. After reception, ground commands control the writing of the cached software from SRAM memory into the three extra spaces in the FLASH memory. Upon the next power-on, the application software is read from the FLASH memory and written into the SRAM memory for execution. This fulfills the requirement for on-orbit software maintenance by the control unit.
[0026] The software architecture includes: a bootloader is programmed into a high-reliability antifuse PROM, and the application program is programmed into a large-capacity FLSAH memory, with three copies programmed. Three additional copies of the FLSAH memory are reserved for storing on-orbit maintenance programs. After the control unit powers on, the high-performance CPU first reads the bootloader from the PROM. The bootloader controls the CPU to perform a two-out-of-three comparison of the three application software copies in the FLSAH memory, writes the result to SRAM, and begins running the application software in SRAM. During application software operation, a two-out-of-three comparison is periodically performed on the data in the FLSAH memory; if an inconsistency is detected, the error is automatically corrected.
[0027] When on-orbit software maintenance is required, the software source file is received via the communication bus and temporarily stored in an SRAM-type memory. After receiving the file, the software cached in the SRAM-type memory is written into three additional spaces in the FLASH-type memory via ground command. The application software that is injected into the FLASH-type memory can be read and written into the SRAM-type memory for execution upon the next power-on.
[0028] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.
Claims
1. A maintainable spacecraft control unit architecture, characterized in that, Includes: hardware architecture; In the hardware architecture, a high-performance CPU processor is selected, and one or more of the following devices are added externally: A one-time programmable antifuse PROM type memory is used to store the boot program; A large-capacity FLASH memory is used to store application software; A large-capacity SRAM memory is used for software operation.
2. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, The bootloader relies on an antifuse PROM-type memory that can be programmed once and is unaffected by single particles in the space environment.
3. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, The application software is written to three copies in the FLASH memory. After each power-on, the bootloader reads the three copies of software data from the FLASH memory and compares them byte by byte. The comparison is performed in a two-out-of-three manner. The result returned by the comparison is used as the application software. If the three copies do not match, the first copy of software data is used.
4. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, Each time power is applied, the application software in the FLSAH type memory is compared in a 3-out-of-2 manner, and the comparison result is written into the SRAM type memory.
5. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, High-performance CPU processors drive application software to run in SRAM-type memory and have error detection and correction functions, which can correct one-bit errors and detect two-bit errors during software operation.
6. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, After the application software starts running, it periodically reads and compares the three application software source files stored in the FLSAH type memory. If an inconsistency is detected, the erroneous file is automatically corrected, so that the application software in the FLSAH type memory can recover itself when errors occur due to the influence of the space environment.
7. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, A high-performance CPU processor is selected, and an external large-capacity FLASH memory is used to store application software. At the same time, three additional spaces are reserved in the large-capacity FLASH memory to store on-orbit maintenance programs. When on-orbit maintenance software is required, the software source file is received via the communication bus and temporarily stored in the SRAM memory. After receiving the file, the on-orbit software cached in the SRAM memory is written into the three additional spaces in the FLASH memory via ground command. The application software that is written into the space can be read from the FLASH memory and written into the SRAM memory for execution upon the next power-on.
8. The maintainable spacecraft control unit architecture according to claim 1, characterized in that, Also includes: Software runtime architecture; In the software operating architecture, the bootloader is burned into the antifuse PROM type memory, the application program is burned into the large-capacity FLSAH type memory, and three copies are burned. At the same time, three additional copies of the large-capacity FLSAH type memory are reserved for storing the on-orbit maintenance program.
9. The maintainable spacecraft control unit architecture according to claim 8, characterized in that, After the control unit is powered on, the high-performance CPU processor first reads the boot software in the PROM type memory. The function of the boot software is to control the CPU to perform a two-out-of-three comparison of the three application software in the FLSAH type memory, write the comparison result into the SRAM type memory, and start running the application software in the SRAM type memory. During application software operation, the data in the FLSAH type memory is periodically compared by taking two out of three. If an inconsistency is detected, the erroneous file is automatically corrected.
10. The maintainable spacecraft control unit architecture according to claim 9, characterized in that, When on-orbit software maintenance is required, the software source file is received via the communication bus and temporarily stored in an SRAM-type memory. After receiving the file, the software cached in the SRAM-type memory is written into three additional spaces in the FLASH-type memory via ground command. The application software that is injected into the FLASH-type memory can be read and written into the SRAM-type memory for execution upon the next power-on.
Citation Information
Patent Citations
High-speed and high-reliability software on-orbit updating method and data management computer system
CN117170719A