A method and system for reconfiguring a satellite-borne computer
By prioritizing the onboard computer and switching the main control during failure, the problem of discontinuity of spacecraft work caused by onboard computer failure is solved, and the safety and reliability of the spacecraft are improved.
Patent Information
- Application Number
- CN202211633467.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-19
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2042-12-19
AI Technical Summary
In the event of a failure, existing satellite-based computers can cause the spacecraft system to work discontinuously through dual-machine cold backup, affecting the spacecraft's on-orbit safety and reliability.
The satellite-based computer reconstruction method is used to prioritize all the satellite-based computers on the aircraft through the controller. When the satellite-based computer with the highest priority fails, the main control satellite-based computer is determined from the remaining satellite-based computers in order of priority for control.
Maximize the impact of space-based computer failures on the aircraft, ensure the continuity of spacecraft's work, and improve on-orbit safety and reliability.
Smart Images

Figure CN116088369B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of aircraft control technology, and in particular to a satellite-borne computer reconstruction method and system. Background Art
[0002] As the core of satellites and other spacecraft, the control subsystem's onboard computer (SSC) has the highest safety and reliability requirements of any onboard system. To improve the safety and reliability of SSCs, a widely adopted approach is to introduce redundancy technology. This improves the system's fault diagnosis and fault tolerance, minimizing the impact of faults on normal operation.
[0003] The control subsystem's onboard computer typically uses a dual-computer cold backup configuration for redundancy, with a single computer powered during operation. The onboard computer consists of two independent CPU boards, input and output circuits, and corresponding fault-tolerant circuits. It is primarily responsible for collecting information from the satellite's various attitude sensors, performing real-time data processing and calculations, outputting various control signals, and managing and controlling the normal operation of each onboard mission module.
[0004] At present, when dealing with spacecraft in-orbit flight failures, onboard control computers mainly use dual-machine cold backup to improve the life and reliability of spacecraft. In addition, when the software runs abnormally, the system needs to be powered on again, which is not conducive to the continuity of spacecraft system operation. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a method and system for reconfiguring a satellite-borne computer in view of the deficiencies in the prior art.
[0006] The technical solution of a satellite-borne computer reconstruction method of the present invention is as follows:
[0007] The controller prioritizes all onboard computers configured on the spacecraft;
[0008] When the onboard computer with the highest priority fails, the controller determines the master onboard computer from the remaining onboard computers in order of priority and controls the aircraft through the master onboard computer.
[0009] The beneficial effects of the onboard computer reconstruction method of the present invention are as follows:
[0010] It can eliminate the impact of onboard computer failures on the spacecraft to the greatest extent, facilitate the continuity of the spacecraft's operation, and improve the spacecraft's on-orbit safety and reliability.
[0011] The technical solution of a satellite-borne computer reconstruction system of the present invention is as follows:
[0012] It includes a controller and a plurality of onboard computers for being set on an aircraft;
[0013] The controller is used to: prioritize all onboard computers provided on the aircraft;
[0014] The controller is further configured to: when the onboard computer with the highest priority fails, determine a master onboard computer from the remaining onboard computers in order of priority, and control the aircraft via the master onboard computer.
[0015] The beneficial effects of the onboard computer reconstruction system of the present invention are as follows:
[0016] It can eliminate the impact of onboard computer failures on the spacecraft to the greatest extent, facilitate the continuity of the spacecraft's operation, and improve the spacecraft's on-orbit safety and reliability. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 1 is a flow chart of a method for reconfiguring a satellite-borne computer according to an embodiment of the present invention;
[0018] Figure 2 This is a block diagram of the onboard computer system;
[0019] Figure 3 This is a block diagram of the redundant configuration of the onboard computer;
[0020] Figure 4 This is the hardware block diagram of the onboard computer board;
[0021] Figure 5 This is the hardware block diagram of the information acquisition board;
[0022] Figure 6 This is the hardware block diagram of the drive control board;
[0023] Figure 7 This is a diagram of the data flow trigger timing. DETAILED DESCRIPTION
[0024] like Figure 1 As shown, a method for reconfiguring a satellite computer according to an embodiment of the present invention includes the following steps:
[0025] S1. The controller prioritizes all onboard computers installed on the spacecraft.
[0026] Among them, the number of all onboard computers is 2, 3, or 4, etc., and more onboard computers can be set according to actual conditions. Taking 3 as an example for explanation, the three onboard computers are respectively recorded as onboard computer A, onboard computer B, and onboard computer C. The priority of onboard computer A is higher than the priority of onboard computer B, and the priority of onboard computer B is higher than the priority of onboard computer C. Each onboard computer includes a central control unit, an information acquisition unit, and a drive control unit. The central control unit of onboard computer A is recorded as central control unit A, the information acquisition unit of onboard computer A is recorded as information acquisition unit A, and the drive control unit of onboard computer A is recorded as drive control unit A. The central control unit of onboard computer B is recorded as central control unit B, the information acquisition unit of onboard computer B is recorded as information acquisition unit B, and the drive control unit of onboard computer B is recorded as drive control unit B. The central control unit of onboard computer C is recorded as central control unit C, the information acquisition unit of onboard computer C is recorded as information acquisition unit C, and the drive control unit of onboard computer C is recorded as drive control unit C.
[0027] S2. When the onboard computer with the highest priority fails, the controller determines the master onboard computer from the remaining onboard computers in order of priority and controls the spacecraft through the master onboard computer. Specifically:
[0028] When the onboard computer with the highest priority, namely onboard computer A, fails, onboard computer B is determined as the main onboard computer to control the spacecraft in order of priority. When onboard computers A and B fail, onboard computer C is determined as the main onboard computer to control the spacecraft. This can minimize the impact of onboard computer failures on the spacecraft, facilitate the continuity of the spacecraft's operation, and improve the on-orbit safety and reliability of the spacecraft.
[0029] Optionally, in the above technical solution, the following is further included:
[0030] S02. After all onboard computers enter the task synchronization state, the controller synchronizes the time of all onboard computers at the start of each control cycle. When the number of time synchronization failures of the onboard computer with the highest priority exceeds a preset threshold, it is determined that the onboard computer with the highest priority has failed. Specifically:
[0031] After onboard computer A, onboard computer B, and onboard computer C are powered on, the user determines whether onboard computer A, onboard computer B, and onboard computer C enter the development state or the task synchronization state. If they enter the development state, the ground support software is used to debug and solidify the program; if they enter the task synchronization state, S02 is executed.
[0032] In S02, when the time synchronization of the highest priority onboard computer fails, time synchronization will be re-initiated. When the number of time synchronization failures of the highest priority onboard computer exceeds a preset threshold, it is determined that the highest priority onboard computer has failed. The preset threshold is 2 times, 3 times, or 4 times, etc., and can also be adjusted according to actual conditions.
[0033] Optionally, in the above technical solution, the following is further included:
[0034] S3. When all onboard computers are functioning properly, the controller controls the spacecraft through the onboard computer with the highest priority.
[0035] Optionally, in the above technical solution, before the controller controls the aircraft through the onboard computer with the highest priority, the process further includes:
[0036] S030. Each onboard computer sends the collected peripheral input information to each other onboard computer. Specifically:
[0037] The information acquisition unit A of the onboard computer A sends the collected peripheral input information to the central control unit B of the onboard computer B, and to the central control unit C of the onboard computer C. The information acquisition unit B of the onboard computer B sends the collected peripheral input information to the central control unit A of the onboard computer A, and to the central control unit C of the onboard computer C. The information acquisition unit C of the onboard computer C sends the collected peripheral input information to the central control unit A of the onboard computer A, and to the central control unit B of the onboard computer B. Moreover, the information acquisition unit A of the onboard computer A sends the collected peripheral input information to the central control unit A of the onboard computer A, and the information acquisition unit B of the onboard computer B The collected peripheral input information is sent to the central control unit B of the onboard computer B, and the information acquisition unit C of the onboard computer C sends the collected peripheral input information to the central control unit C of the onboard computer C. At this time, the central control unit A has the peripheral input information collected by the information acquisition unit A, the peripheral input information collected by the information acquisition unit B, and the peripheral input information collected by the information acquisition unit C, the central control unit B has the peripheral input information collected by the information acquisition unit A, the peripheral input information collected by the information acquisition unit B, and the peripheral input information collected by the information acquisition unit C, and the central control unit C has the peripheral input information collected by the information acquisition unit A, the peripheral input information collected by the information acquisition unit B, and the peripheral input information collected by the information acquisition unit C.
[0038] S031. Each onboard computer votes based on all peripheral input information to determine valid peripheral input information;
[0039] Central control unit A of onboard computer A votes on all peripheral input information, namely, peripheral input information collected by information collection unit A, peripheral input information collected by information collection unit B, and peripheral input information collected by information collection unit C, to obtain one valid peripheral input information to be determined. Central control unit B of onboard computer B and central control unit C of onboard computer C perform the same vote on all peripheral input information to obtain a total of three valid peripheral input information to be determined. Valid peripheral input information is then determined from the three valid peripheral input information to be determined.
[0040] S032. Any onboard computer obtains a calculation result corresponding to the onboard computer based on valid peripheral input information and the flight modal control law of the aircraft, until a calculation result corresponding to each onboard computer is obtained;
[0041] The central control unit A of the onboard computer A obtains the calculation result corresponding to the onboard computer A based on the valid peripheral input information and the flight modal control law of the aircraft; the central control unit B of the onboard computer B obtains the calculation result corresponding to the onboard computer B based on the valid peripheral input information and the flight modal control law of the aircraft; the central control unit C of the onboard computer C obtains the calculation result corresponding to the onboard computer C based on the valid peripheral input information and the flight modal control law of the aircraft.
[0042] S033. Each onboard computer sends its own calculation results to each other onboard computer. Specifically:
[0043] The central control unit A of onboard computer A sends the calculation results corresponding to onboard computer A to the central control unit B of onboard computer B, and to the central control unit C of onboard computer C. The central control unit B of onboard computer B sends the calculation results corresponding to onboard computer B to the central control unit A of onboard computer A, and to the central control unit C of onboard computer C. The central control unit C of onboard computer C sends the calculation results corresponding to onboard computer C to the central control unit A of onboard computer A, and to the central control unit B of onboard computer B.
[0044] S034. Any onboard computer votes based on all calculation results to obtain a valid calculation result corresponding to the onboard computer, until a valid calculation result corresponding to each onboard computer is obtained. Specifically:
[0045] The central control unit A of the onboard computer A votes on the calculation results corresponding to the onboard computer A, the calculation results corresponding to the onboard computer B, and the calculation results corresponding to the onboard computer C to obtain the valid calculation results corresponding to the onboard computer A. The central control unit B of the onboard computer B votes on the calculation results corresponding to the onboard computer A, the calculation results corresponding to the onboard computer B, and the calculation results corresponding to the onboard computer C to obtain the valid calculation results corresponding to the onboard computer B. The central control unit C of the onboard computer C votes on the calculation results corresponding to the onboard computer A, the calculation results corresponding to the onboard computer B, and the calculation results corresponding to the onboard computer C to obtain the valid calculation results corresponding to the onboard computer C.
[0046] S035. The process of the highest priority onboard computer controlling the spacecraft includes:
[0047] S036. The onboard computer with the highest priority determines the final valid calculation result from all valid calculation results and controls the spacecraft according to the final valid calculation result. Specifically:
[0048] The driving control unit A of the onboard computer A controls the aircraft according to the final effective calculation results.
[0049] In another embodiment, the satellite onboard computer adopts a three-redundant homogeneous hot backup architecture, and each redundancy (or channel) is an independent PCIE architecture onboard computer, which consists of a central control unit, a synchronization unit, an information acquisition unit, a cross-transmission unit, a drive control unit, and a power supply unit.
[0050] First, the three channels of the onboard computer are synchronized by a trigger signal. The sensor data and actuator data are collected through the information acquisition unit. Data is exchanged between channels through the cross-transmission unit. The voting input of each channel is obtained through software voting. Then, the central control unit solves the control law for each vote to obtain its own output. When outputting data, each channel exchanges data through the cross-transmission unit, performs fault detection and fault isolation operations, and votes on its own output. Finally, the outputs of the three channels are transmitted to the drive control unit at the same time. After arbitration, the drive control unit obtains a unique output, which is sent to the actuator as the final result.
[0051] The central control unit adopts the MPC8377 as the core and forms a CPU+FPGA chip structure with XC7K325. The module integrates DI / DO, AD / DA, CAN, RS422, RS485, Ethernet and SRIO drive circuits, as well as external expansion modules such as FLASH, NVRAM and SRAM.
[0052] The synchronization unit uses the Trigger signal to synchronize channels and completes related data interaction and action data transmission through the cross transmission unit.
[0053] The trigger signal is generated by the FPGA of the central control unit and enables all actions of the system. The trigger action is divided into rising edge trigger and falling edge trigger.
[0054] The three channels synchronize the system through trigger signals. Triggers are generated simultaneously by the three onboard computer channels and independently sent to each master controller, acting as the system's internal trigger source. Trigger signal priority follows the default A>B>C priority. If the onboard computer fails, the trigger validity is adjusted based on the priority.
[0055] The trigger signal selects the trigger usage and system triggering mode according to the control algorithm, sensor and actuator data characteristics.
[0056] The information acquisition unit is triggered by the Trigger signal and periodically collects the measurement data of the sensor and actuator. The measurement data is transmitted to the central control unit through the cross transmission unit.
[0057] The cross-transmission unit uses the SRIO interface to provide a high-speed point-to-point communication channel for the onboard computer, completing statistical data communication, command communication, redundant decision-making, action information backup and other related data between channels.
[0058] The three channels are monitored comparatively through cross-data transmission between them. The cross-transmission data includes ground remote control commands, satellite attitude data, information collection data, channel detection information, and output control quantity.
[0059] The drive control unit receives the output control quantities of the three channels and obtains a unique control signal output after arbitration, which is sent to the actuator as the final result.
[0060] The power supply unit provides the system with power and necessary power protection and monitoring functions, and can generate abnormal power interruptions for the subsequent equipment to achieve self-protection.
[0061] The three channels of the onboard computer are numbered A, B, and C and configured with a default priority of A>B>C. In the absence of abnormalities, A serves as the main control unit to perform three-redundancy judgment operations. If a single machine fails, it is reconstructed into a master-slave control mode according to the priority order of A>B>C. If two machines fail, the system is downgraded to a single-machine mode.
[0062] After a fault occurs, the system will autonomously detect and isolate the fault to ensure that system functions are not affected and complete system reconstruction and recovery.
[0063] An embodiment of the present invention provides a method for reconfiguring a satellite-borne computer system, the method comprising the following steps:
[0064] (1) The three channels of the onboard computer are numbered A, B, and C and prioritized according to the order A>B>C. After the onboard computer system is powered on, the computer enters either the development state or the system state based on system input. If the computer is in the development state, the program is debugged and fixed using ground support software. If the computer is in the system state, the computer enters the task synchronization state after the startup process is completed.
[0065] (2) The system enters the task synchronization state and performs three-machine synchronization at the beginning of each control cycle. After the three-machine synchronization is completed, a task scheduling is executed. If the three-machine synchronization fails, the continuous out-of-step count of the channel is increased by 1. When the continuous out-of-step count reaches the set threshold, the channel is judged as a fault and jumps to step 8. If the three-machine synchronization is successful, the continuous out-of-step count is cleared.
[0066] (3) In the task synchronization state, the synchronization unit enables all system actions. At the beginning of each control cycle, the three central control units complete system synchronization, the information acquisition unit executes the first trigger, and performs the peripheral input information acquisition task. The input signal is exchanged by the cross transmission unit.
[0067] (4) The second Trigger performs the input data comparison monitoring task, and the central control unit obtains the channel's voting input through voting.
[0068] (5) The third trigger executes the control law task. The central control unit uses the voting input information of the channel to call the corresponding flight mode control law and output the calculation results.
[0069] (6) The fourth trigger performs comparison monitoring and output tasks. The output data of the control law task is exchanged by the cross transmission unit, and the central control unit votes to obtain the channel voting output, which is then transmitted to the drive control unit at the same time.
[0070] (7) The fifth trigger performs the fault monitoring task. The output result of the central control unit is arbitrated by the arbitration module of the drive control unit to obtain a unique output, which is sent to the back-end actuator to complete the control of the satellite.
[0071] (8) In the absence of abnormal conditions, onboard computer A acts as the master control unit to perform triple redundancy judgment; if onboard computer A fails, the master control is inherited by the next-level priority computer B and reconstructed into the master-slave control mode; if onboard computer B or C fails, the master control unit does not change, and the system is downgraded and reconstructed into the master-slave control mode; if a dual-machine failure occurs in the onboard computer, the system is downgraded and reconstructed into a single-machine mode.
[0072] (9) When an abnormal situation occurs, in order to prevent the entire system from being degraded due to transient faults, the central control unit to be restored after normal startup begins to apply to the main control unit for restoration of key information. After receiving the restoration application, the main control unit sends the key restoration data to the central control unit to be restored through the cross-link unit; after receiving the important restoration data, the central control unit to be restored sends a handshake signal to the main control unit and stops receiving the important restoration data; the central control unit to be restored re-plans its own operating status; after receiving the handshake signal, the main control unit stops sending the required important restoration data.
[0073] (10) The central control unit that has completed recovery joins the normal working queue and applies for control rights from the master control unit through ground remote control commands. The master control unit determines the detection status of the slave control unit that applies for control rights. If it is in a healthy state, the control rights are transferred to the master control unit.
[0074] In another embodiment, the onboard computer adopts a triple-redundant hot standby architecture, including onboard computer boards A, B, and C, an information acquisition board, a drive control output board, a main power supply board, and a backplane. The onboard computer system block diagram is shown in FIG. Figure 2 shown.
[0075] The triple redundancy configuration of the onboard computer is shown in the figure below: Figure 3 As shown, it includes central control units A, B, and C, an information acquisition unit, and a drive control unit. The central control unit (CCU) uses a CPU + FPGA chip structure, and the central control units of the three channels adopt a homogeneous design.
[0076] The hardware block diagram of the onboard computer board is as follows: Figure 4 As shown in the figure, using channel A of the onboard computer system as an example, the central control unit (A) CPU first initializes the RapidIO system, configures the DMA interface and the Message interface, and sets the first storage space in the FPGA memory space to store three copies of the data from input interfaces A1 and A2; A1 and A2 are non-similarity sensor interface data.
[0077] The data from input interface A1 is received by the DMA interrupt, and the corresponding semaphore is released after reception to synchronize data processing tasks. The first copy is sent by the information acquisition unit, which polls the front-end sensor to obtain measurement data and sends it to the central control unit (A) FPGA. The central control unit (A) CPU reads it through the DMA interface. The second copy is sent by the central control unit B via cross transmission and is read by the central control unit (A) CPU via the DMA interface. The third copy is sent by the central control unit C via cross transmission and is read by the central control unit (A) CPU via the DMA interface. After the central control unit (A) CPU obtains the three copies of input interface A1 data, it performs a two-out-of-three vote to obtain the voting input A1 of the central processing unit (A) CPU.
[0078] The data from input interface A2 is received by the DMA interrupt. After reception, the corresponding semaphore is released to synchronize data processing tasks. The first copy is sent by the information acquisition unit, which polls the front-end sensor to obtain measurement data and sends it to the central control unit (A) FPGA. The central control unit (A) CPU reads it through the DMA interface. The second copy is sent by the central control unit B via cross transmission and is read by the central control unit (A) CPU via the DMA interface. The third copy is sent by the central control unit C via cross transmission and is read by the central control unit (A) CPU via the DMA interface. The central control unit (A) CPU receives three copies of input interface A2 data and then performs a two-out-of-three vote to obtain the voting input A2 for the central processing unit (A) CPU.
[0079] The hardware block diagram of the information acquisition board is as follows: Figure 5 Input interfaces A1 and A2 are connected to the non-similarity sensor. As long as the information collected by any one of the interfaces is correct, the input of the central processing unit (A) CPU is valid.
[0080] The second storage space of the FPGA memory space is set to store three copies of data of the output interfaces A1 and A2; wherein A1 and A2 are data transmitted to the drive control unit.
[0081] The data from output interface A1 is processed by DMA interrupts. Taking central processing unit A as an example, the first copy is the result calculated by central control unit (A) and sent to the central control unit (A) FPGA. The second copy is sent by central control unit B via cross transmission and read by central control unit (A) CPU via the DMA interface. The third copy is sent by control unit C via cross transmission and read by central control unit (A) CPU via the DMA interface. After the central control unit (A) CPU obtains the three copies of output interface A1 data, it performs a two-out-of-three vote to obtain the voting output A1 of the central processing unit (A) CPU.
[0082] The data from output interface A2 is processed by DMA interrupts. Taking central processing unit A as an example, the first copy is the result calculated by the central control unit (A) and sent to the central control unit (A) FPGA. The second copy is sent by central control unit B via cross transmission and read by the central control unit (A) CPU via the DMA interface. The third copy is sent by control unit C via cross transmission and read by the central control unit (A) CPU via the DMA interface. After the central control unit (A) CPU obtains the three copies of output interface A2 data, it performs a two-out-of-three vote to obtain the voting output A2 of the central processing unit (A) CPU.
[0083] The hardware block diagram of the drive control board is as follows: Figure 6 Output interfaces A1 and A2 are connected to the drive control unit. As long as any one of the output interfaces is working properly, the input of the drive control unit is valid.
[0084] If a two-out-of-three vote determines that the data of one channel is inconsistent with the other two channels, the transient error count of the channel is increased by one. If the transient error count reaches the set threshold, the channel is set to fault, the data output interface autonomously performs isolation self-test, and notifies other central control units through the Message interface. The system is downgraded and reconstructed to active-standby redundancy; if central control unit A fails, the main control unit is inherited by central control unit B; if central control unit B or C fails, the main control unit does not change; if dual channels fail, the system is downgraded to stand-alone mode.
[0085] In order to prevent the entire system from functional degradation due to transient faults, the central control unit to be restored after normal startup begins to apply to the central control unit of the main control unit for recovery of key information. The key information includes satellite time, working mode, orbital parameters, power-on flag and fault flag, etc. After the main control unit receives the recovery application, it sends the key recovery data to the central control unit to be restored through the cross-link unit; after receiving the important recovery data, the central control unit to be restored sends a handshake signal to the main control unit and stops receiving important recovery data; the central control unit to be restored re-plans its own operating status; after receiving the handshake signal, the main control unit stops sending the required important recovery data.
[0086] The FPGA memory space sets the third storage space for storing key recovery data of each central control unit, and the central control unit main control unit CPU periodically refreshes the data to ensure that the data received by the central control unit to be restored is the latest.
[0087] The onboard computer data stream trigger timing diagram is as follows Figure 7As shown, the trigger signal is generated by the FPGA of the master central control unit with a trigger interval of 25ms. It enables the system's information collection, data calculation, and drive control actions. Trigger actions are divided into rising edge triggering and falling edge triggering. The rising edge triggering action includes data being sent from the information acquisition unit to the central control unit's FPGA, the data being read from the FPGA's local cache by the central control unit's CPU, and then sent to the drive control unit by the central control unit FPGA. The falling edge triggering action includes data being received by the central control unit FPGA and stored in the local cache, and the calculation results being output to the FPGA by the central control unit CPU.
[0088] The trigger signal is generated by the FPGA with the highest priority in the central control unit. If the current central control unit fails, it will be inherited by the central control unit with the next priority level.
[0089] The onboard computer uses a dedicated multi-tasking operating system and is divided into six tasks according to design requirements, including: information acquisition task, input data comparison and monitoring task, control law task, comparison monitoring and output task, fault monitoring task, and periodic synchronization task.
[0090] The periodic synchronization task executes task scheduling once every 125ms; the first 25ms executes the peripheral input information acquisition task, the second 25ms executes the input data comparison and monitoring task, the third 25ms executes the control law task, the fourth 25ms executes the comparison monitoring and output task, and the fifth 25ms executes the fault monitoring task.
[0091] The advantages of the method of the present invention compared with the prior art are:
[0092] (1) A hot standby architecture with triple-redundant homogeneous CPU+FPGA chip structure is adopted. When a single machine fails, the triple-redundant control mode is seamlessly switched to the primary-backup control mode. After the failure is eliminated, the triple-redundant control mode can be restored, so that the system is in a high redundancy as much as possible.
[0093] (2) SRIO is used to realize internal interconnection between each redundant onboard computer processor, solving the problem of poor real-time performance and slow communication speed between traditional onboard computers.
[0094] (3) Software voting is designed in the data processing links of the information acquisition unit, central control unit, and drive control unit to improve the data monitoring and fault handling capabilities of the onboard computer and meet the on-orbit safety and reliability requirements of the onboard computer.
[0095] In the above embodiments, although the steps are numbered S1, S2, etc., these are only specific embodiments given in this application. Those skilled in the art can adjust the execution order of S1, S2, etc. according to actual conditions, which is also within the scope of protection of the present invention. It can be understood that in some embodiments, some or all of the above embodiments may be included.
[0096] An onboard computer reconstruction system according to an embodiment of the present invention includes a controller and a plurality of onboard computers for being arranged on an aircraft;
[0097] The controller is used to: prioritize all onboard computers configured on the spacecraft;
[0098] The controller is also used to: when the onboard computer with the highest priority fails, determine the master onboard computer from the remaining onboard computers in order of priority, and control the aircraft through the master onboard computer.
[0099] Optionally, in the above technical solution, the controller is further configured to:
[0100] When all onboard computers enter the task synchronization state, time synchronization is performed on all onboard computers at the start of each control cycle. When the number of time synchronization failures of the onboard computer with the highest priority exceeds the preset threshold, it is determined that the onboard computer with the highest priority has failed.
[0101] Optionally, in the above technical solution, the controller is further configured to:
[0102] When all onboard computers are functioning properly, the spacecraft is controlled by the onboard computer with the highest priority.
[0103] Optionally, in the above technical solution, each onboard computer sends the collected peripheral input information to each other onboard computer respectively;
[0104] Each onboard computer votes based on all peripheral input information to determine the valid peripheral input information;
[0105] Any onboard computer obtains the calculation result corresponding to the onboard computer according to the valid peripheral input information and the flight mode control law of the aircraft, until the calculation result corresponding to each onboard computer is obtained;
[0106] Each onboard computer sends its own calculation results to each other onboard computer;
[0107] Any onboard computer votes based on all the calculation results to obtain the valid calculation result corresponding to the onboard computer, until the valid calculation result corresponding to each onboard computer is obtained;
[0108] The process of the onboard computer with the highest priority controlling the spacecraft includes:
[0109] The onboard computer with the highest priority determines the final valid calculation result from all valid calculation results and controls the spacecraft according to the final valid calculation result.
[0110] Optionally, in the above technical solution, the number of all onboard computers is 3.
[0111] The above parameters and steps for each unit module to implement corresponding functions in a satellite-borne computer reconstruction system of the present invention can refer to the parameters and steps in the embodiment of a satellite-borne computer reconstruction method above, and will not be repeated here.
[0112] Those skilled in the art will appreciate that the present invention may be implemented as a system, method or computer program product.
[0113] Therefore, the present disclosure may be embodied in the following forms: entirely in hardware, entirely in software (including firmware, resident software, microcode, etc.), or in a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, the present disclosure may be embodied in the form of a computer program product embodied in one or more computer-readable media, wherein the computer-readable media contains computer-readable program code.
[0114] Any combination of one or more computer-readable media can be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device.
[0115] Although the embodiments of the present invention have been shown and described above, it will be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. A person skilled in the art may change, modify, replace and modify the above embodiments within the scope of the present invention.
Claims
1. A method for reconfiguring a satellite-borne computer, characterized in that: include: The controller prioritizes all onboard computers configured on the spacecraft; When the onboard computer with the highest priority fails, the controller determines a master onboard computer from the remaining onboard computers in order of priority, and controls the aircraft through the master onboard computer; When all onboard computers are not faulty, the controller controls the aircraft through the onboard computer with the highest priority; Before the controller controls the aircraft through the onboard computer with the highest priority, the controller further includes: Each onboard computer sends the collected peripheral input information to each other onboard computer; Each onboard computer votes based on all peripheral input information to determine the valid peripheral input information; Any onboard computer obtains a calculation result corresponding to the onboard computer according to the valid peripheral input information and the flight mode control law of the aircraft, until a calculation result corresponding to each onboard computer is obtained; Each onboard computer sends its own calculation results to each other onboard computer; Any onboard computer votes based on all the calculation results to obtain the valid calculation result corresponding to the onboard computer, until the valid calculation result corresponding to each onboard computer is obtained; The process of the onboard computer with the highest priority controlling the aircraft includes: The onboard computer with the highest priority determines a final valid calculation result from all valid calculation results, and controls the aircraft according to the final valid calculation result; The trigger signal is used for inter-channel synchronization. The trigger signal trigger interval is 25ms and is generated by the FPGA of the master central control unit. The periodic synchronization task executes task scheduling once every 125ms; the first 25ms executes the peripheral input information acquisition task, the second 25ms executes the input data comparison and monitoring task, the third 25ms executes the control law task, the fourth 25ms executes the comparison monitoring and output task, and the fifth 25ms executes the fault monitoring task.
2. The onboard computer reconstruction method according to claim 1, characterized in that: Also includes: When all onboard computers enter the task synchronization state, the controller synchronizes the time of all onboard computers at the start of each control cycle. When the number of time synchronization failures of the onboard computer with the highest priority exceeds a preset threshold, it is determined that the onboard computer with the highest priority has failed.
3. A method for reconfiguring a satellite computer according to any one of claims 1 to 2, characterized in that: The total number of onboard computers is 3.
4. A satellite-borne computer reconstruction system, characterized in that: It includes a controller and a plurality of onboard computers for being set on an aircraft; The controller is used to: prioritize all onboard computers provided on the aircraft; The controller is further configured to: when the onboard computer with the highest priority fails, determine a master onboard computer from the remaining onboard computers in order of priority, and control the aircraft through the master onboard computer; The controller is also used for: When all onboard computers are not faulty, controlling the aircraft through the onboard computer with the highest priority; Each onboard computer sends the collected peripheral input information to each other onboard computer; Each onboard computer votes based on all peripheral input information to determine the valid peripheral input information; Any onboard computer obtains a calculation result corresponding to the onboard computer according to the valid peripheral input information and the flight mode control law of the aircraft, until a calculation result corresponding to each onboard computer is obtained; Each onboard computer sends its own calculation results to each other onboard computer; Any onboard computer votes based on all the calculation results to obtain the valid calculation result corresponding to the onboard computer, until the valid calculation result corresponding to each onboard computer is obtained; The process of the onboard computer with the highest priority controlling the aircraft includes: The onboard computer with the highest priority determines a final valid calculation result from all valid calculation results, and controls the aircraft according to the final valid calculation result; The trigger signal is used for inter-channel synchronization. The trigger signal trigger interval is 25ms and is generated by the FPGA of the master central control unit. The periodic synchronization task executes task scheduling once every 125ms; the first 25ms executes the peripheral input information acquisition task, the second 25ms executes the input data comparison and monitoring task, the third 25ms executes the control law task, the fourth 25ms executes the comparison monitoring and output task, and the fifth 25ms executes the fault monitoring task.
5. The onboard computer reconstruction system according to claim 4, characterized in that: The controller is also used for: After all onboard computers enter the task synchronization state, time synchronization is performed on all onboard computers at the start of each control cycle. When the number of time synchronization failures of the onboard computer with the highest priority exceeds a preset threshold, it is determined that the onboard computer with the highest priority has failed.
6. The onboard computer reconstruction system according to any one of claims 4 to 5, characterized in that: The total number of onboard computers is 3.
Citation Information
Patent Citations
Degradable triple-modular redundancy computer system based on software synchronization
CN102724083A
Satellite-borne triple modular redundancy system based on clock synchronization technology
CN103389914A
Reconstruction degradation method of triple-redundancy computer system
CN107247644A
Multi-computer synchronous operation and time alignment method suitable for Mars detection
CN111431651A