A software-controlled FPGA-based memory data fault-tolerant system and method
By adopting a software-controlled FPGA-based memory data fault-tolerant system in satellite-based computers, fault-tolerant processing of all memory data is achieved, the limitations of traditional EDAC circuits are solved, and data reliability and system stability are improved.
Patent Information
- Application Number
- CN202210790851.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-05
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-07-05
AI Technical Summary
The prior art is difficult to effectively achieve fault tolerance of memory data in satellite-borne computers, especially in space environments. Traditional EDAC circuits can only correct 1-bit data and cannot meet the needs of more complex faults.
The FPGA-based memory data fault tolerance system is adopted to implement fault tolerance processing of all memory application data through the fault tolerance logic module and configuration data modification module on the FPGA, including data hot standby and error correction.
It realizes fault-tolerant processing of all memory data, solves the limitation that traditional EDAC circuits can only correct 1-bit data, improves data reliability and system stability, and is suitable for space environments.
Smart Images

Figure CN115237646B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of onboard computer memory data fault tolerance, and in particular to a software-controlled FPGA-based memory data fault tolerance system and method. Background Art
[0002] In the computer field, data reliability is crucial to the performance of the entire system, especially the core data of the system or important application data. The reliability of the data directly affects the operation of the entire system. The onboard computer is the brain of the artificial satellite or spacecraft. Whether it can operate stably is related to the success or failure of the space mission. During the entire mission cycle, the onboard computer is always affected by harsh environments such as impact, vibration, space particle radiation, and electromagnetic interference. Therefore, how to ensure the accuracy of the data is crucial.
[0003] At present, the commonly used data fault tolerance methods are as follows:
[0004] 1) Memory Sparing: When performing memory sparing, the memory used for sparing is not used under normal circumstances, which means that the system cannot see this part of the memory capacity. There is one DIMM in each memory channel that is not used and is reserved for sparing memory. The chipset is set with a threshold for the number of memory check errors, that is, the number of errors that occur per unit time. When the number of failures in the working memory reaches this "fault tolerance threshold", the system starts a double write operation, one to the main memory and one to the sparing memory. When the system detects that the data in the two memories is consistent, the sparing memory replaces the main memory and the faulty memory is disabled. This completes the task of sparing memory taking over the work of the faulty memory, effectively avoiding data loss or system downtime due to memory failure. The capacity of the sparing memory should be greater than or equal to the capacity of the largest memory bar in the channel to meet the maximum capacity requirements of memory data migration.
[0005] To achieve memory hot standby, the processor needs to support multi-channel memory access function, but this kind of processor consumes huge power and cannot be used in space environment.
[0006] 2) Memory mirroring: Memory mirroring is to make two copies of memory data, one in the main memory and the other in the mirror memory. When the system is working, data will be written to both memories at the same time, so that there are two complete backups of memory data. Because of the cross-channel mirroring method, each channel has a complete copy of memory data.
[0007] There is a "fault tolerance threshold" set in the system chipset. If any memory reaches the "fault tolerance threshold", the channel where it is located will be marked, and the other channel will work alone. However, the memory bandwidth of the dual channel is still maintained.
[0008] To achieve memory mirroring, the processor also needs to support multi-channel memory access function, but this kind of processor consumes huge power and cannot be used in space environment.
[0009] 3) Memory Error Correction (EDAC): As human beings explore space more deeply, the impact of the space environment on the electronic equipment and devices of spacecraft has gradually emerged. Space radiation effects, especially single particle effects, have a potential great harm to the completion of space missions. Onboard computers are the core components of satellites. In the space radiation environment, the damage or impact of single particle upsets on the program control functions of onboard computers must be fully considered. To address this problem, error correction and detection (EDAC) design is currently commonly used to perform error correction and error detection processing on the RAM storage unit of the onboard computer to eliminate SEU failures.
[0010] The EDAC function can be implemented by both hardware and software. The implementation method is that the CPU sends data to the EDAC encoding module, and the EDAC encoding module generates a check code based on the data, and writes the original data and the check code into the data RAM and the check RAM respectively; during the read operation, the CPU takes out the data from the data RAM and the check RAM, and sends it to the EDAC error correction module, and the EDAC error correction module sends the correct data to the CPU. When using software means to implement it, it is necessary to calculate the stored data and redundant information when reading and writing the RAM storage unit, which takes up a lot of CPU time.
[0011] Therefore, for onboard computers, due to the limitations of CPU device selection, the CPU performance is limited, making CPU resources very valuable, so hardware means are currently commonly used to implement the EDAC function. The existing EDAC memory error correction function used in space environments requires the support of hardware circuits and can only correct 1-bit errors in RAM units caused by SEUs. If the errors are not cleared regularly, they will accumulate, causing the computer to produce 2-bit or even more bit errors in the results of the processing. In this case, the EDAC function cannot be used for data error correction, resulting in system error operations or even mission failures. Summary of the invention
[0012] The present invention provides a software-controlled FPGA-based memory data fault-tolerant system and method, the purpose of which is to perform fault-tolerant processing on all application data in the memory and solve the limitation that the traditional EDAC circuit can only correct 1-bit data.
[0013] To achieve the above object, the technical solution of the present invention is:
[0014] The present invention provides a software-controlled FPGA-based memory data fault-tolerant system, comprising a controller-side DIMM interface, an FPGA and a device-side DIMM interface, wherein the controller-side DIMM interface connects a CPU and the FPGA, and the device-side DIMM interface connects the FPGA and a RAM; a configuration data modification module and a fault-tolerant logic module are arranged on the FPGA, and the configuration data modification module is used to dynamically configure a specific fault-tolerant logic in the FPGA according to an instruction of the CPU.
[0015] The fault-tolerant logic module includes a PHY_dev interface, a command parsing module, a check coding module, a redundancy control module, a data / address conversion module, a fault detection module, a data check module, a data selection module and a PHY_host interface.
[0016] The PHY_dev interface includes a CPU command path and a CPU data strobe path, and the PHY_host interface includes a RAM command path and a RAM data strobe path.
[0017] Furthermore, the configuration data modification module includes a DFX module, a clock module and an IO initialization module.
[0018] Furthermore, the CPU command path is a unidirectional write channel, and the CPU command path includes an input cache, an input delay unit, and an input serial-to-parallel conversion unit.
[0019] Furthermore, the CPU data strobe path includes DQ data subpath I and DQS data subpath I; the DQ data subpath I is a bidirectional data transmission path, and the DQ data subpath I includes input and output buffers, input and output delay units, input serial-to-parallel conversion units, and output double data rate units. The DQS data subpath I is a unidirectional read channel, and the DQS data subpath I includes output buffers, output delay units, and output double data rate units.
[0020] Furthermore, the RAM command path is a unidirectional write channel, and the RAM command path includes an output serial-to-parallel conversion unit, an output delay unit, and an output buffer.
[0021] Furthermore, the RAM data selection path includes a DQS data subpath II and a DQ data subpath II, and both the DQS data subpath II and the DQ data subpath II are bidirectional data transmission paths. Both the DQS data subpath II and the DQ data subpath II include an output serial-to-parallel conversion unit, an input double rate acquisition unit, an input-output delay unit, and an input-output buffer.
[0022] A method for writing data in a memory data fault-tolerant system based on FPGA controlled by software comprises the following steps:
[0023] S1.CPU configures FPGA to data hot standby mode;
[0024] S2.CPU initializes DDRX memory;
[0025] S3.CPU writes data to FPGA through PHY_dev interface;
[0026] S4. Data cache;
[0027] S5. The data / address conversion module converts the 64-bit data / address written by the CPU into 32-bit data / address. The converted data is the lower 32-bit data, and the lower 32-bit data is regarded as the main data.
[0028] S6. The redundant control module copies the lower 32 bits of data to obtain the upper 32 bits of data, and regards the upper 32 bits of data as hot standby data;
[0029] S7. The check code module adds check code codes to the master data and the hot standby data respectively;
[0030] S8. The redundant control module combines the main data and the hot standby data into a set of data, and the data / address conversion module converts the combined data into 64-bit data / address;
[0031] S9. Store the data converted in the previous step into the memory through the PHY_host interface.
[0032] A method for reading data of a memory data fault-tolerant system based on FPGA controlled by software comprises the following steps:
[0033] S1.CPU configures FPGA to data hot standby mode;
[0034] S2.CPU initializes DDRX memory;
[0035] S3.CPU issues a read instruction, and FPGA reads data from a certain memory address of DDRX memory through PHY_host interface;
[0036] S4. The data / address conversion module converts the read 64-bit data / address into 32-bit data / address, and the redundant control module decodes the main data and hot standby data;
[0037] S5. The data verification module detects whether the master data and the hot standby data are consistent. If they are consistent, S7 is executed, otherwise S6 is executed;
[0038] S6. The fault detection module checks the number of faults in the master data. If it is a single fault, memory error correction is performed first, and then S7 is executed; if it is multiple faults, the data selection module is used to change the hot standby data to the master data, and memory error correction is performed on the changed master data, and finally S7 is executed;
[0039] S7. The data / address conversion module converts the main data into 64-bit data / address and transmits it to the CPU through the PHY_dev interface.
[0040] The beneficial effects achieved by the present invention are:
[0041] The overall solution of the present invention is transparent to the CPU memory controller. After adopting this method, the CPU side can achieve fault tolerance without any processing when reading memory data. Commercial devices are used to realize the redundant fault tolerance function of space data, and the limitation that the traditional EDAC circuit can only correct 1-bit data is solved. This method can perform fault tolerance processing on all application data in all memories, and the speed is fast. The cost is low, and for aerospace applications, no special radiation-resistant devices are required to meet the data fault tolerance requirements in the space environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a block diagram of the overall technical solution of the present invention.
[0043] Figure 2 It is a block diagram of the PHY_dev interface technical solution of the present invention.
[0044] Figure 3 It is a block diagram of the PHY_host interface technical solution of the present invention.
[0045] Figure 4 It is a flow chart of a data writing method of a memory data fault-tolerant system of the present invention.
[0046] Figure 5 It is a flow chart of a data reading method of a memory data fault-tolerant system of the present invention. DETAILED DESCRIPTION
[0047] To facilitate those skilled in the art to understand the present invention, specific implementations of the present invention are described below with reference to the accompanying drawings.
[0048] like Figure 1 As shown, the present invention provides a software-controlled FPGA-based memory data fault-tolerant system. The core of the system is FPGA, which becomes a communication bridge between CPU and RAM. The combination of CPU+FPGA+RAM is used to realize fault-tolerant processing of all application data. Among them, the CPU can be a commercial processor; the RAM is a standard commercial DIMM package DDRx, and DIMMDDR is used to store 64-bit valid data.
[0049] The principle of this system is: use fault-tolerant logic to convert the 64-bit data / address on the CPU side into 32-bit data / address, perform redundant hot standby in the same memory, and the control logic monitors data failures in real time. When a data error occurs, the hot standby data is used for real-time recovery and the correct path is selected. Since the effective data bit width after conversion is reduced from 64 bits to 32 bits, the rate of the following PHY_host interface is reduced to half the rate of the following PHY_dev interface, and the occupied address is twice the original. The memory is a standard memory for the CPU, and the redundant logic controlled by the FPGA is invisible to the CPU. The power-on initialization timing control, pre-charge, refresh, read and write commands of the memory are all controlled by the host.
[0050] The memory data fault-tolerant system comprises a controller-side DIMM interface, an FPGA and a device-side DIMM interface. The controller-side DIMM interface connects the CPU and the FPGA, and the device-side DIMM interface connects the FPGA and the RAM.
[0051] The FPGA is provided with a configuration data modification module and a fault-tolerant logic module, the configuration data modification module includes a DFX module, a clock module and an IO initialization module, and the configuration data modification module is used to dynamically configure the specific fault-tolerant logic in the FPGA according to the instruction of the CPU. The present invention utilizes the DFX (Dynamic Function eXchange) technology of the FPGA, through which a partial bit file can be downloaded to dynamically modify the logic block, while the remaining logic will continue to run uninterruptedly, so the CPU can dynamically configure the specific fault-tolerant logic in the FPGA according to the application situation.
[0052] The fault-tolerant logic module includes a PHY_dev interface, a command parsing module, a checksum coding module, a redundancy control module, a data / address conversion module, a fault detection module, a data check module, a data selection module and a PHY_host interface. The PHY_dev interface is used for the FPGA to receive instructions and data from the CPU, and the PHY_host interface is used for the FPGA to read and write data in the DDR; the command parsing module is used to parse the instructions issued by the CPU and control the operation of each module in the FPGA according to the instructions.
[0053] For DDR data collection, the PHY interface is implemented using the underlying IO primitive method, which effectively reduces the delay of high-speed interface data processing in the FPGA and solves the bottleneck of using FPGA to implement memory hot backup. At the same time, a method for automatically adjusting the clock and data skew is implemented based on the IODELAY unit, which solves the problem of difficulty in implementing write leveling / read calibration.
[0054] According to the ratio of the data frequency of the DIMM interface and the FPGA operating frequency, the IODD or input-output serial-to-parallel converter (IOsedes) primitive can be selected to perform data serial-to-parallel and parallel-to-serial conversion. In order to achieve the best performance, the present invention adopts a write-side path frequency ratio of 2:1 and a read-side path frequency ratio of 1:1.
[0055] like Figure 2 As shown, the PHY_dev interface includes a CPU command (CMD) path and a CPU data strobe (DQDQS) path. The CPU command path is a unidirectional write channel. The CPU command path includes an input buffer connected to the controller-side DIMM interface through a pin, an input delay unit connected to the input buffer, and an input serial-to-parallel conversion unit connected to the input delay unit. The input serial-to-parallel conversion unit is connected to the command parsing module. The command data CMD initiated by the CPU first passes through the input buffer (IBUF) after entering the FPGA; then passes through the input delay unit (IDELAY) to enter ISEDES, completes the acquisition of double rate and upper and lower edge data (one FPGA cycle acquires 4Byte data), and finally enters the logic command parsing module.
[0056] The CPU data selection path includes DQ data sub-pathway I and DQS data sub-pathway I. The DQ data sub-pathway I is a bidirectional data transmission path. When it is sent from the CPU to the logic, it is a write path. The ISERDES primitive is also used to complete the conversion of double-rate and DDR dual-edge data. The read path is the data output to the CPU. At this time, the logic operating frequency is consistent with the interface frequency, and ODDR can be used to complete the conversion of dual-edge data.
[0057] The DQ data sub-path I includes an input-output cache connected to the controller-end DIMM interface through a pin, an input-output delay unit connected to the input-output cache, an input serial-to-parallel conversion unit connected to the input-output delay unit, and an output double data rate unit connected to the input-output delay unit. The input serial-to-parallel conversion unit and the output double data rate unit are both connected to the check coding module and the redundancy control module.
[0058] The DQS data sub-pathway I is a unidirectional read channel. Although the DQS data selection signal is also bidirectional in nature, the data is not further transmitted after being sent from the controller to the FPGA logic, and is treated as unidirectional data. When outputting, the ODDR primitive is used like DQ, and the IOBUFDS primitive is used at the PAD interface to generate a differential signal. The PHY interface implemented by this method only requires three controller interface frequency cycles for delay, which greatly reduces the inherent delay caused by using FPGA to implement memory control. The DQS data sub-pathway I includes an output buffer connected to the controller-side DIMM interface through a pin, an output delay unit connected to the output buffer, and an output double data rate unit connected to the output delay unit. The output double data rate unit is connected to the check coding module and the redundant control module. The check coding module and the redundant control module can control the direction of data transmission and control which path the data passes through.
[0059] like Figure 3 As shown, the PHY_host interface includes a RAM command (CMD) path and a RAM data select (DQDQS) path. The PHY_host interface is the reverse process of the PHY_dev interface, but the implementation is more complicated because the characteristics of DDR must be considered. Before entering normal data operations, the FPGA controls the read-write balance initialization training operation.
[0060] The RAM command path is a unidirectional write channel, and the RAM command path includes an output serial-to-parallel conversion unit connected to the command parsing module, an output delay unit connected to the output serial-to-parallel conversion unit, and an output cache connected to the output delay unit, and the output cache is connected to the device-end DIMM interface through a pin.
[0061] The RAM data selection path includes DQS data sub-pathway II and DQ data sub-pathway II. Different from the CPU data selection path, the DQS data sub-pathway II and the DQ data sub-pathway II are both bidirectional data transmission paths. This is because when in the write path, the FPGA generates a data selection signal synchronized with the data DQ and writes it into the memory; and when in the read path, in order to ensure the synchronization of DQ and DQS, both are fed back to the controller after passing through the internal logic, so the DQS data sub-pathway II is bidirectional.
[0062] The DQS data sub-pathway II and the DQ data sub-pathway II both include an output serial-to-parallel conversion unit, an input double rate acquisition unit, an input-output delay unit, and an input-output buffer. The output serial-to-parallel conversion unit and the input double rate acquisition unit are both connected to the check coding module and the redundancy control module. The output serial-to-parallel conversion unit and the input double rate acquisition unit are both connected to the input-output delay unit. The input-output delay unit is connected to the input-output buffer, and the input-output buffer is connected to the device-side DIMM interface through a pin. The command parsing module can control the data transmission direction and control which path the data passes through.
[0063] like Figure 4 As shown, a method for writing data in a memory data fault-tolerant system based on FPGA controlled by software includes the following steps:
[0064] S1.CPU configures FPGA to data hot standby mode;
[0065] S2.CPU initializes DDRX memory;
[0066] S3.CPU writes data to FPGA through PHY_dev interface;
[0067] S4. Data cache;
[0068] S5. The data / address conversion module converts the 64-bit data / address written by the CPU into 32-bit data / address. The converted data is the lower 32-bit data, and the lower 32-bit data is regarded as the main data.
[0069] S6. The redundant control module copies the lower 32 bits of data to obtain the upper 32 bits of data, and regards the upper 32 bits of data as hot standby data;
[0070] S7. The check code module adds check code codes to the master data and the hot standby data respectively;
[0071] S8. The redundant control module combines the main data and the hot standby data into a set of data, and the data / address conversion module converts the combined data into 64-bit data / address;
[0072] S9. Store the data converted in the previous step into the memory through the PHY_host interface.
[0073] like Figure 5 As shown, a method for reading data in a software-controlled FPGA-based memory data fault-tolerant system includes the following steps:
[0074] S1.CPU configures FPGA to data hot standby mode;
[0075] S2.CPU initializes DDRX memory;
[0076] S3. The CPU issues a read instruction, and the FPGA reads data from a certain memory address of the DDRX memory through the PHY_host interface;
[0077] S4. The data / address conversion module converts the read 64-bit data / address into 32-bit data / address, and the redundant control module decodes the main data and hot standby data;
[0078] S5. The data verification module detects whether the master data and the hot standby data are consistent. If they are consistent, S7 is executed, otherwise S6 is executed;
[0079] S6. The fault detection module checks the number of faults in the master data. If it is a single fault, memory error correction is performed first, and then S7 is executed; if it is multiple faults, the data selection module is used to change the hot standby data to the master data, and memory error correction is performed on the changed master data, and finally S7 is executed;
[0080] S7. The data / address conversion module converts the main data into 64-bit data / address and transmits it to the CPU through the PHY_dev interface.
[0081] The DDRx command parsing process is omitted in both reading and writing data. The 64-bit data of the CPU is converted into two sets of data, the upper 32 bits and the lower 32 bits, by the conversion module, and the checksum is added to each set. The lower 32 bits written to the memory are regarded as the main data, and the upper 32 bits of the memory storing the same data are regarded as the hot standby data. The two sets of data are completely consistent, back up each other, and are stored in the same address.
[0082] When FPGA reads data from the same memory address, it reads out two sets of data at the same time, decodes the two sets of data and judges the fault. If both sets are correct, the main data is selected and converted into 64-bit data and sent to the CPU through the PHY_dev interface; if the main data fails, FPGA automatically converts the backup data into 64-bit data and sends it to the CPU through the PHY_dev interface. This completes seamless data docking and well ensures the correctness and integrity of memory data.
[0083] In addition, due to the dynamic partial reconfiguration characteristics of the FPGA, the logic function of the FPGA can be modified when the hot backup function is not used.
[0084] The above-described embodiments of the present invention do not constitute a limitation on the protection scope of the present invention. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention shall be included in the protection scope of the claims of the present invention.
Claims
1. A software-controlled FPGA-based memory data fault-tolerant system, Features: It includes a controller-side DIMM interface, an FPGA and a device-side DIMM interface, wherein the controller-side DIMM interface connects the CPU and the FPGA, and the device-side DIMM interface connects the FPGA and the RAM; a configuration data modification module and a fault-tolerant logic module are provided on the FPGA, and the configuration data modification module is used to dynamically configure the specific fault-tolerant logic in the FPGA according to the instruction of the CPU; The fault-tolerant logic module includes a PHY_dev interface, a command parsing module, a checksum coding module, a redundancy control module, a data / address conversion module, a fault detection module, a data check module, a data selection module and a PHY_host interface; The PHY_dev interface includes a CPU command path and a CPU data strobe path, and the PHY_host interface includes a RAM command path and a RAM data strobe path; The CPU data strobe path includes a DQ data subpathway I and a DQS data subpathway I; the DQ data subpathway I is a bidirectional data transmission path, and the DQ data subpathway I includes an input and output buffer, an input and output delay unit, an input serial-to-parallel conversion unit, and an output double data rate unit; the DQS data subpathway I is a unidirectional read channel, and the DQS data subpathway I includes an output buffer, an output delay unit, and an output double data rate unit; The RAM data selection path includes DQS data sub-pathway II and DQ data sub-pathway II, and both DQS data sub-pathway II and DQ data sub-pathway II are bidirectional data transmission paths; both DQS data sub-pathway II and DQ data sub-pathway II include an output serial-to-parallel conversion unit, an input double-rate acquisition unit, an input-output delay unit and an input-output buffer.
2. A software-controlled FPGA-based memory data fault-tolerant system according to claim 1, Features: The configuration data modification module includes a DFX module, a clock module and an IO initialization module.
3. The software-controlled FPGA-based memory data fault-tolerant system according to claim 1, Features: The CPU command path is a unidirectional write channel, and the CPU command path includes an input buffer, an input delay unit and an input serial-to-parallel conversion unit.
4. The software-controlled FPGA-based memory data fault-tolerant system according to claim 1, Features: The RAM command path is a unidirectional write channel, and the RAM command path includes an output serial-to-parallel conversion unit, an output delay unit and an output buffer.
5. A method for writing data to a memory data fault-tolerant system based on FPGA controlled by software, based on the memory data fault-tolerant system according to any one of claims 1 to 4 above, It is characterized in that The following steps are involved: S1.CPU configures FPGA to data hot standby mode; S2.CPU initializes DDRX memory; S3.CPU writes data to FPGA through PHY_dev interface; S4. Data cache; S5. The data / address conversion module converts the 64-bit data / address written by the CPU into 32-bit data / address. The converted data is the lower 32-bit data, and the lower 32-bit data is regarded as the main data. S6. The redundant control module copies the lower 32 bits of data to obtain the upper 32 bits of data, and regards the upper 32 bits of data as hot standby data; S7. The check code module adds check code codes to the master data and the hot standby data respectively; S8. The redundant control module combines the main data and the hot standby data into a set of data, and the data / address conversion module converts the combined data into 64-bit data / address; S9. Store the data converted in the previous step into the memory through the PHY_host interface.
6. A method for reading data from a software-controlled FPGA-based memory data fault-tolerant system, based on the memory data fault-tolerant system according to any one of claims 1 to 4. It is characterized in that The following steps are involved: S1.CPU configures FPGA to data hot standby mode; S2.CPU initializes DDRX memory; S3. The CPU issues a read instruction, and the FPGA reads data from a certain memory address of the DDRX memory through the PHY_host interface; S4. The data / address conversion module converts the read 64-bit data / address into 32-bit data / address, and the redundant control module decodes the main data and hot standby data; S5. The data verification module detects whether the master data and the hot standby data are consistent. If they are consistent, S7 is executed, otherwise S6 is executed; S6. The fault detection module checks the number of faults in the master data. If it is a single fault, memory error correction is performed first, and then S7 is executed; if it is multiple faults, the data selection module is used to change the hot standby data to the master data, and memory error correction is performed on the changed master data, and finally S7 is executed; S7. The data / address conversion module converts the main data into 64-bit data / address and transmits it to the CPU through the PHY_dev interface.
Citation Information
Patent Citations
Double-CPU (Central Processing Unit)redundancy fault-tolerant system based on high-voltage frequency converter and realizing method thereof
CN101877528A
High-reliability spaceborne computer architecture and control method thereof
CN114546722A