A method, device, medium and equipment for a satellite to execute a single event effect resistant task
By monitoring the status of the satellite software in real time and automatically falling back to the previous version of the software program, the problem of low software exception handling efficiency caused by high-energy particles in orbit is solved, and the safety and stability of satellite operation are improved.
Patent Information
- Application Number
- CN202411822096.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-12-11
AI Technical Summary
When satellites are affected by high-energy particles when operating in orbit, they lead to single-particle effects, resulting in software anomalies. The existing technology is inefficient in processing through ground telemetry and manual intervention.
Monitor the operating status of satellite software programs in real time, obtain version record data through abnormal detection, and automatically fall back to the previous version of the software program for task execution.
It improves the efficiency of satellite abnormal handling in orbit, ensures the security and stability of the software, and reduces the timeliness of communication delays and manual intervention.
Smart Images

Figure CN119271503B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the technical field of spacecraft space environment effect applications, and particularly to a method, device, medium, and equipment for a satellite to execute a single event effect resistance task. Background Art
[0002] With the development of space technology, satellites play an increasingly crucial role in multiple fields such as communication, navigation, remote sensing, and scientific exploration. However, when a satellite is in orbit, it is affected by a complex and harsh space environment. For example, it is affected by high-energy particles in cosmic rays. When the electronic devices and software systems of a satellite are affected by high-energy particles, single event effects (SEEs) may be triggered, resulting in bit flips in the satellite's internal memory and data corruption, which in turn affects the normal operation of the key software used by the satellite (such as attitude control and signal processing software), and seriously affects the execution of satellite tasks. For example, when the attitude control system of a satellite responsible for attitude measurement and control of the satellite malfunctions, the attitude of the satellite may deviate, thereby affecting the pointing accuracy and stability of the satellite. Another example is that when the signal processing software responsible for signal modulation and demodulation, encoding and decoding, etc. malfunctions, it may cause communication interruption or data errors in the satellite, thereby affecting the execution of satellite tasks.
[0003] Normally, in order to avoid the impact of the harsh space environment on the execution of satellite tasks, the ground control center can monitor the operating state of the satellite in real time based on telemetry data, so as to take measures in a timely manner when it is determined that the operating state of the satellite is abnormal, and remotely update and repair the software system in the satellite. However, due to the communication delay and timeliness problems of the ground telemetry and manual intervention methods, the efficiency of dealing with the emergency anomalies of the satellite is relatively low.
[0004] Therefore, how to improve the processing efficiency of anomalies that occur when a satellite is in orbit is an urgent problem to be solved. Summary of the Invention
[0005] This specification provides a method, device, medium, and equipment for a satellite to execute a single event effect resistance task to partially solve the above problems existing in the prior art.
[0006] This specification adopts the following technical solutions:
[0007] This specification provides a method for a satellite to execute a single event effect resistance task, including:
[0008] Obtain monitoring parameters of the target software program, where the monitoring parameters are used to reflect the running status of the target software program and the current status of the hardware resources on which the target software program depends;
[0009] Based on the monitoring parameters, perform anomaly detection on the target software program to obtain an anomaly detection result of the target software program, where the anomaly detection result is used to characterize whether there is an anomaly in the target software program;
[0010] If it is determined according to the anomaly detection result that there is an anomaly in the target software program, then obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium;
[0011] Based on the version record data, determine the historical software program of the previous version adjacent to the target software program in terms of update time as the fallback software program;
[0012] Install and run the fallback software program to execute tasks through the fallback software program.
[0013] Optionally, storing the version record data corresponding to the target software program specifically includes:
[0014] Receive a data packet file sent by the ground end;
[0015] Perform decryption processing on the data packet file to extract the software program to be installed, as well as the version data and verification parameters of the software program to be installed from the data packet file, where the verification parameters are used to reflect whether there is an anomaly in the data packet file during the transmission process;
[0016] Based on the verification parameters, verify the software program to be installed to obtain a verification result, and in the case of determining that there is no anomaly in the software program to be installed according to the verification result, install the software program to be installed and store the update time and version data of the software program to be installed into the version record data corresponding to the software program to be installed.
[0017] Optionally, the verification parameters include: a digital signature value, a first key, and digest algorithm parameters. The digital signature value is obtained by the ground end encrypting the digest value corresponding to the software program to be installed using a preset second key, and the digest algorithm parameters are used to characterize the algorithm used to determine the digest value corresponding to the software program to be installed and the format of the digest value;
[0018] Based on the verification parameters, verify the software program to be installed to obtain a verification result, specifically including:
[0019] Extract a digest value from the software program to be installed according to the digest algorithm parameters to determine a reference digest value corresponding to the software program to be installed; and,
[0020] Decrypt the digital signature value according to the first key to obtain a decrypted digest value corresponding to the software program to be installed;
[0021] Verify the software program to be installed according to the reference digest value and the decrypted digest value to obtain a verification result. Among them, if the reference digest value is consistent with the decrypted digest value, it can be obtained that the software program to be installed has no abnormal verification result. If the reference digest value is inconsistent with the decrypted digest value, it can be obtained that the software program to be installed has an abnormal verification result.
[0022] Optionally, if it is determined according to the anomaly detection result that the target software program is abnormal, obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium, specifically including:
[0023] If it is determined according to the anomaly detection result that the target software program is abnormal, determine an anomaly impact range parameter according to the monitored parameter with an anomaly, and store the anomaly impact range parameter in a preset anomaly log file. The anomaly impact range parameter is used to characterize at least one other software program affected by the monitored parameter with an anomaly; and
[0024] Obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium.
[0025] Optionally, install and run the fallback software program to execute tasks through the fallback software program, specifically including:
[0026] Install and run the fallback software program, and determine a test task request that matches the fallback software program from the preset test task requests as the target test task request;
[0027] Perform a functional test on the fallback software program according to the target test task request to obtain a functional test result of the fallback software program. The functional test result is used to reflect whether the fallback software program is abnormal;
[0028] If it is determined according to the functional test result that the fallback software program is not abnormal, execute tasks through the fallback software program.
[0029] Optionally, the method further includes:
[0030] Generate an exception report file according to the exception detection result and the fallback software program, and send the exception report file to the ground end. The exception report file includes at least one of the following: the time when the exception occurred, the type of the exception, the fallback result, and the version data of the fallback software program.
[0031] Optionally, the method further includes:
[0032] At specified time intervals, obtain the verification parameters corresponding to each historical software program from a specified storage medium as alternative verification parameters;
[0033] For each historical software program, verify the historical software program according to the alternative verification parameters corresponding to the historical software program to obtain the verification result of the historical software program, and save the verification result of the historical software program.
[0034] This specification provides a satellite single event effect resistant task execution device, including:
[0035] A first acquisition module, configured to acquire monitoring parameters of a target software program, where the monitoring parameters are used to reflect the running state of the target software program and the current state of the hardware resources on which the target software program depends;
[0036] A detection module, configured to perform exception detection on the target software program according to the monitoring parameters to obtain an exception detection result of the target software program, where the exception detection result is used to characterize whether the target software program has an exception;
[0037] A second acquisition module, configured to, if it is determined according to the exception detection result that the target software program has an exception, acquire the version record data corresponding to the target software program pre-stored from a preset specified storage medium;
[0038] A determination module, configured to determine, according to the version record data, a historical software program of the previous version adjacent to the target software program in terms of update time as a fallback software program;
[0039] An execution module, configured to install and run the fallback software program to execute tasks through the fallback software program.
[0040] This specification provides a computer-readable storage medium storing a computer program, where when the computer program is executed by a processor, the above-mentioned satellite single event effect resistant task execution method is implemented.
[0041] This specification provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the above-mentioned method for executing the satellite single-event effect resistance task is implemented.
[0042] The above at least one technical solution adopted in this specification can achieve the following beneficial effects:
[0043] In the method for executing the satellite single-event effect resistance task provided in this specification, first, monitoring parameters of a target software program are obtained. Here, the monitoring parameters are used to reflect the running state of the target software program and the current state of the hardware resources on which the target software program depends. According to the monitoring parameters, anomaly detection is performed on the target software program to obtain an anomaly detection result of the target software program. The anomaly detection result is used to characterize whether there is an anomaly in the target software program. If it is determined according to the anomaly detection result that there is an anomaly in the target software program, then version record data corresponding to the target software program stored in advance is obtained from a preset specified storage medium. According to the version record data, a historical software program of the previous version adjacent to the target software program in terms of update time is determined as a fallback software program, and the fallback software program is installed and run to execute the task through the fallback software program.
[0044] It can be seen from the above method that the running state of the target software program installed on the satellite can be monitored in real time, and abnormal behaviors such as data anomalies, program crashes, and performance degradation can be automatically detected. Once software anomalies are detected, the control device can autonomously fallback to the previous normal software version to improve the processing efficiency of anomalies that occur when the satellite is operating in orbit. Description of the Drawings
[0045] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The schematic embodiments of this specification and their descriptions are used to explain this specification and do not constitute an improper limitation to this specification. In the drawings:
[0046] Figure 1 is a schematic flowchart of a method for executing a satellite single-event effect resistance task provided in this specification;
[0047] Figure 2 is a schematic diagram of a device for executing a satellite single-event effect resistance task provided in this specification;
[0048] Figure 3 corresponds to Figure 1 is a schematic diagram of an electronic device provided in this specification. Detailed Embodiments
[0049] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without creative efforts belong to the scope protected by this specification.
[0050] Currently, when a satellite is in orbit, due to the interaction between high-energy particles of cosmic rays in the space environment and semiconductor materials, charge accumulation may occur, leading to situations such as memory bit flips and data corruption, and further causing abnormalities in the software programs installed on the satellite itself or during the application of the software programs.
[0051] The following will detail the technical solutions provided by each embodiment of this specification in conjunction with the drawings.
[0052] Figure 1 The following is a schematic flowchart of a method for a satellite to execute an anti-single event effect task provided in this specification, including the following steps:
[0053] S101: Obtain the monitoring parameters of the target software program, where the monitoring parameters are used to reflect the running state of the target software program and the current state of the hardware resources on which the target software program depends.
[0054] In this specification, the satellite system can monitor the running state of each software program installed on the satellite in real time, so that when an abnormal software program is detected, the abnormality can be processed in time, thereby improving the safety of the satellite.
[0055] Specifically, for each software program installed on the satellite, the satellite system can use this software program as the target software program, and then obtain the monitoring parameters of the target software program. When it is determined that the target software program is abnormal based on the monitoring parameters of the target software program, the abnormality is processed in time, so that the satellite after the abnormality is processed can continue to execute tasks.
[0056] Among them, the above software programs can be determined according to actual needs. For example: software programs for satellite attitude control, software programs for satellite signal processing, software programs for image processing, etc.
[0057] The above monitoring parameters are used to reflect the running state of the target software program and the current state of the hardware resources on which the target software program depends. For example: the running time of the process corresponding to the target software program, the number of times the process corresponding to the target software program is launched per unit time (such as: the number of times the process corresponding to the target software program is launched within every 5s, etc.), the memory occupancy rate of the target software program, the CPU occupancy rate, etc.
[0058] In this specification, the execution entity for implementing the method for executing the satellite single-event effect resistance task may refer to a designated device such as a flight computer or an embedded device installed in the satellite, or may also refer to devices such as a desktop computer or a server. For the sake of convenience of description, hereinafter, only taking the control device as the execution entity as an example, the method for executing the satellite single-event effect resistance task provided in this specification will be described.
[0059] S102: Perform anomaly detection on the target software program according to the monitoring parameters to obtain the anomaly detection result of the target software program, where the anomaly detection result is used to characterize whether there is an anomaly in the target software program.
[0060] In this specification, the control device can determine an anomaly detection strategy matching each obtained monitoring parameter as the anomaly detection strategy corresponding to this monitoring parameter, and can perform anomaly detection on this monitoring parameter through the anomaly detection strategy corresponding to this monitoring parameter to obtain the anomaly detection result of this monitoring parameter. Furthermore, the anomaly detection result of the target software program can be determined according to the anomaly detection results of each monitoring parameter.
[0061] Among them, the above anomaly detection result is used to characterize whether there is an anomaly in the target software program.
[0062] The above anomaly detection strategy can be set in advance for different monitoring parameters. For example: if the monitoring parameter is the running time of the process corresponding to the target software program, then the anomaly detection strategy for this monitoring parameter can be determined as comparing the running time of the process corresponding to the target software program with a set running time threshold to determine whether there is an anomaly in this monitoring parameter.
[0063] For another example: if the monitoring parameter is the number of times the process corresponding to the target software program is launched per unit time, then the anomaly detection strategy for this monitoring parameter can be determined as judging whether the number of times the process corresponding to the target software program is launched per unit time exceeds a preset launch number threshold. If so, it can be determined that there is an anomaly in this monitoring parameter.
[0064] The method for determining the anomaly detection result of the target software program based on the anomaly detection results of each monitoring parameter described above may be that if, based on the anomaly detection results of each monitoring parameter, it is determined that at least one of the monitoring parameters of the target software program has an anomaly, then it can be determined that the target software program has an anomaly.
[0065] S103: If, based on the anomaly detection result, it is determined that the target software program has an anomaly, then obtain the version record data corresponding to the target software program pre-stored in a preset specified storage medium.
[0066] Furthermore, when the control device determines that the target software program has an anomaly based on the above-mentioned anomaly detection result, it can obtain the version record data corresponding to the target software program pre-stored in a preset specified storage medium.
[0067] Among them, the above-mentioned specified storage medium may refer to a memory that can resist the damage of high-energy particles in the space environment to electronic devices. For example: a memory with radiation resistance prepared from high-purity silicon materials.
[0068] For another example: a memory prepared by deep submicron technology with a smaller device size and a lower probability of single event effect.
[0069] For another example: a memory with redundant design and high fault tolerance.
[0070] The above-mentioned version record data may be the version data, update time, etc. of different versions of the software program historically installed on the satellite.
[0071] It should be noted that the above-mentioned version record data may be recorded and saved to the specified storage medium by the control device each time it receives a new software program for installation. For the convenience of understanding, the following details the entire process of the software program installed on the satellite.
[0072] Specifically, when the ground terminal needs to upload a software program to the satellite, it can use the software program to be installed on the satellite as the software program to be installed and assign a unique version number to the software program to be installed. For example: algorithm software: CAL_V1.0, CAL_V1.1, CAL_V1.2, etc.
[0073] Furthermore, the ground terminal can use a preset digest algorithm to extract the digest value of the software program to be installed, so as to determine the digest value corresponding to the software program to be installed. For example, the above-mentioned digest algorithm can be the national commercial cryptographic algorithm (SM3 Cryptographic Hash Algorithm, SM3). At this time, the ground terminal can use SM3 to perform hash calculation on the software program to be installed to obtain the digest value corresponding to the software program to be installed.
[0074] Furthermore, the ground terminal can use a preset first key to encrypt the digest value corresponding to the software program to be installed, generate a digital signature value of the software program to be installed, and package the software program to be installed (the executable file or binary code of the software program to be installed), the version data of the software program to be installed, the digital signature value of the software program to be installed, a preset second key, and the digest algorithm parameters into a data packet file, and send the data packet file to the control device.
[0075] Among them, in order to improve the security of the data packet file during transmission, the ground terminal can also encrypt the data packet using a specified encryption algorithm (such as: symmetric encryption algorithm) before sending the data packet file to the control device, obtain the encrypted data packet file, and share the encryption key used in the encryption process with the control device in advance through a secure key distribution mechanism, and then the encrypted data packet file can be sent to the control device.
[0076] In addition, in order to avoid data in the data packet file being damaged during transmission, the ground terminal can also add an error check code (such as: 32-bit Cyclic Redundancy Check (CRC32)) to the data packet file, so that the control device can perform integrity verification on the received data packet file according to the error check code after receiving the data packet file.
[0077] In this specification, after receiving the data packet file sent by the ground terminal, the control device can perform a preliminary integrity verification on the received data packet file according to the error check code in the data packet file.
[0078] Furthermore, the control device can decrypt the received data packet file according to the received encryption key to extract the software program to be installed, as well as the version data and verification parameters of the software program to be installed. Here, the verification parameters are used to reflect whether there are abnormalities in the data packet file during transmission. The verification parameters can include: digital signature value, first key, digest algorithm parameters. Here, the digest algorithm parameters are used to characterize the algorithm used to determine the digest value corresponding to the software program to be installed and the format of the digest value.
[0079] Among them, if the control device determines that the data packet file has an integrity exception based on the error check code in the data packet file, or an error occurs when decrypting the received data packet file according to the received encryption key, a warning message can be sent to the ground end.
[0080] Of course, if the control device, after receiving the encryption key and obtaining the version data and verification parameters of the software program to be installed, can verify the software program to be installed according to the verification parameters, obtain a verification result, and when it is determined that the software program to be installed is normal according to the verification result, install the software program to be installed and store the update time and version data of the software program to be installed in the version record data corresponding to the software program to be installed (the version record data corresponding to the software program to be installed here can include the version data of historical software programs of the same type as the software program to be installed but with different versions).
[0081] Specifically, the control device can determine the digest algorithm used by the ground end when calculating the digest value corresponding to the software program to be installed and the format of the digest value corresponding to the software program to be installed according to the digest algorithm parameters, and then can recalculate the digest value corresponding to the software program to be installed extracted from the received data packet file as a reference digest value according to the determined digest algorithm and the determined format of the digest value. Also, decrypt the digital signature value in the data packet file according to the first key in the data packet file to obtain the decrypted digest value corresponding to the software program to be installed.
[0082] Furthermore, the control device can verify the software program to be installed according to the calculated reference digest value and decrypted digest value to obtain a verification result.
[0083] Among them, if the calculated reference digest value is the same as the decrypted digest value, a verification result that the software program to be installed is normal can be obtained. At this time, the control device can install the software program to be installed and store the update time and version data of the software program to be installed in the version record data corresponding to the software program to be installed.
[0084] If the calculated reference digest value is different from the decrypted digest value, a verification result that the software program to be installed has an abnormality can be obtained. At this time, the control device can send an alarm message to the ground end and re-obtain the data packet file from the ground end.
[0085] It should be noted that since the specified storage medium with radiation resistance constructed by the above special technology is often small, in actual application scenarios, the software program to be installed can be stored in the specified storage medium. Preferably, the software program to be installed can also be installed in other storage media, while the version record data and verification parameters of the software program to be installed can be saved in the specified storage medium.
[0086] In addition, in this specification, the control device can perform permission verification on each software program installation operation. Only after determining that the software program installation operation meets the preset authorization conditions can the software program installation operation be executed.
[0087] It is worth noting that in order to improve the security of data transmission between the ground terminal and the satellite, the Automatic Repeat-reQuest (ARQ) mechanism can be adopted when the ground terminal and the satellite perform data transmission, so that when an abnormality is detected during the data transmission process, the data can be resent until the data is correctly received and an acknowledgment signal returned by the receiving party is received.
[0088] S104: Determine the historical software program of the previous version adjacent to the target software program in terms of update time according to the version record data as the fallback software program.
[0089] S105: Install and run the fallback software program to execute tasks through the fallback software program.
[0090] In this specification, after the control device obtains the version record data corresponding to the target software program, it can determine the historical software program of the previous version adjacent to the target software program in terms of update time according to the obtained version record data as the fallback software program. Furthermore, it can obtain the verification parameters of the fallback software program from the specified storage medium and verify the fallback software program through the above method. After determining that the fallback software program has no abnormality, install and run the fallback software program to execute tasks through the fallback software program, and save the executed fallback operation and the version data of the currently running fallback software program to the preset version management log.
[0091] Specifically, the control device can install and run the fallback software program, and determine the test task request that matches the fallback software program from the preset test task requests as the target test task request. Furthermore, it can perform a functional test on the fallback software program according to the target test task request to obtain the functional test result of the fallback software program, where the functional test result is used to reflect whether there is an abnormality in the fallback software program.
[0092] Further, if the control device determines that there is no abnormality in the fallback software program based on the functional test result, it performs tasks through the fallback software program, and during the process of performing tasks through the fallback software program, it continues to monitor the running state of the fallback software program, so as to record the abnormality and send an alarm message to the ground end when the abnormality of the fallback software program is detected again.
[0093] In addition, while performing tasks through the fallback software program, the control device can also generate an exception report file based on the exception detection result of the target software program and the fallback software program, and send the exception report file to the ground end. Here, the exception report file includes at least one of the exception occurrence time, exception type, fallback result, and version data of the fallback software program.
[0094] It should be noted that the control device can also obtain the verification parameters corresponding to each historical software program from the specified storage medium at regular time intervals as alternative verification parameters. Furthermore, for each historical software program, based on the alternative verification parameters corresponding to the historical software program, the historical software program can be verified to obtain the verification result of the historical software program, and the verification result of the historical software program can be saved, so that when performing a fallback operation, it can be determined whether the historical software program is abnormal according to the verification result of the historical software program, and when it is determined that the historical software program is not abnormal, the historical software program can be installed and run as the fallback software program.
[0095] It is worth noting that in the actual application scenario, when an abnormality occurs in a monitoring parameter of the target software program, in addition to affecting the operation of the target software program itself, it may also affect the operation of other software programs. For example: when an abnormality occurs in the monitoring parameter of the control software program installed on the satellite for controlling the sensor to collect image data, it may cause an abnormality in the software program installed on the satellite for image processing.
[0096] Based on this, when the control device determines that the target software program is abnormal according to the exception detection result, it can determine the exception influence range parameter according to the monitoring parameter with the abnormality, and store the exception influence range parameter in a preset exception log file. Here, the exception influence range parameter is used to characterize at least one other software program affected by the monitoring parameter with the abnormality.
[0097] Further, when the control device installs and runs the rollback software program to execute tasks through the rollback software program, it can also determine at least one other software program affected by the monitoring parameter with an anomaly based on the above-mentioned anomaly influence range parameter as a supplementary anomaly software program, and perform anomaly detection on the supplementary anomaly software program, so as to perform a rollback operation for the supplementary anomaly software program in a timely manner when it is determined that the supplementary anomaly software program has an anomaly.
[0098] As can be seen from the above method, the control device can automatically detect abnormal behaviors such as data anomalies, program crashes, and performance degradation by real-time monitoring the running states of software installed on the satellite, such as attitude control and signal processing. Once a software anomaly is detected, the control device can autonomously roll back to the previous normal software version and perform signature verification during the rollback process to ensure the integrity and credibility of the version.
[0099] The above is one or more embodiments of the method for executing the satellite single-event effect resistance task in this specification. Based on the same idea, this specification also provides a corresponding device for executing the satellite single-event effect resistance task, as Figure 2 shown.
[0100] Figure 2 It is a schematic diagram of a device for executing the satellite single-event effect resistance task provided in this specification, including:
[0101] A first acquisition module 201, configured to acquire monitoring parameters of a target software program, where the monitoring parameters are used to reflect the running state of the target software program and the current state of the hardware resources on which the target software program depends;
[0102] A detection module 202, configured to perform anomaly detection on the target software program according to the monitoring parameters to obtain an anomaly detection result of the target software program, where the anomaly detection result is used to characterize whether the target software program has an anomaly;
[0103] A second acquisition module 203, configured to, if it is determined according to the anomaly detection result that the target software program has an anomaly, acquire version record data corresponding to the target software program pre-stored from a preset specified storage medium;
[0104] A determination module 204, configured to determine a historical software program of the previous version adjacent to the target software program in terms of update time as a rollback software program according to the version record data;
[0105] An execution module 205, configured to install and run the rollback software program to execute tasks through the rollback software program.
[0106] Optionally, the device further includes: a storage module 206;
[0107] The storage module 206 is specifically configured to receive a data packet file sent by the ground end; decrypt the data packet file to extract the software program to be installed, as well as the version data and verification parameters of the software program to be installed, where the verification parameters are used to reflect whether there is an abnormality in the transmission process of the data packet file; verify the software program to be installed according to the verification parameters to obtain a verification result, and when it is determined according to the verification result that the software program to be installed is normal, install the software program to be installed, and store the update time and version data of the software program to be installed into the version record data corresponding to the software program to be installed.
[0108] Optionally, the verification parameters include: a digital signature value, a first key, and digest algorithm parameters. The digital signature value is obtained by encrypting the digest value corresponding to the software program to be installed by the ground end using a preset second key. The digest algorithm parameters are used to characterize the algorithm used to determine the digest value corresponding to the software program to be installed and the format of the digest value.
[0109] The storage module 206 is specifically configured to extract a digest value from the software program to be installed according to the digest algorithm parameters to determine a reference digest value corresponding to the software program to be installed; and decrypt the digital signature value according to the first key to obtain a decrypted digest value corresponding to the software program to be installed; verify the software program to be installed according to the reference digest value and the decrypted digest value to obtain a verification result. Among them, if the reference digest value is consistent with the decrypted digest value, a verification result that the software program to be installed is normal can be obtained. If the reference digest value is inconsistent with the decrypted digest value, a verification result that the software program to be installed is abnormal can be obtained.
[0110] Optionally, the second acquisition module 203 is specifically configured to, if it is determined according to the anomaly detection result that the target software program is abnormal, determine an anomaly impact range parameter according to the monitoring parameter with an anomaly, and store the anomaly impact range parameter into a preset anomaly log file. The anomaly impact range parameter is used to characterize at least one other software program affected by the monitoring parameter with an anomaly; and obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium.
[0111] Optionally, the execution module 205 is specifically configured to install and run the rollback software program, and determine, from each preset test task request, a test task request that matches the rollback software program as the target test task request; perform a function test on the rollback software program according to the target test task request to obtain a function test result of the rollback software program, where the function test result is used to reflect whether there is an abnormality in the rollback software program; if it is determined according to the function test result that the rollback software program has no abnormality, perform task execution through the rollback software program.
[0112] Optionally, the execution module 205 is specifically configured to generate an exception report file according to the exception detection result and the rollback software program, and send the exception report file to the ground end, where the exception report file includes at least one of: the exception occurrence time, the exception type, the rollback result, and the version data of the rollback software program.
[0113] Optionally, the execution module 205 is specifically configured to, at each specified time interval, obtain verification parameters corresponding to each historical software program from a specified storage medium as alternative verification parameters; for each historical software program, verify the historical software program according to the alternative verification parameters corresponding to the historical software program to obtain a verification result of the historical software program, and save the verification result of the historical software program.
[0114] This specification also provides a computer-readable storage medium storing a computer program that can be used to execute the above Figure 1 provided method for executing a satellite single-event effect resistance task.
[0115] This specification also provides Figure 3 a schematic structural diagram of an electronic device corresponding to Figure 1 as shown. As Figure 3 described, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may of course also include other hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the above Figure 1 described method for executing a satellite single-event effect resistance task. Of course, in addition to the software implementation method, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, and may also be hardware or a logic device.
[0116] For an improvement in a technology, it can be clearly distinguished whether it is a hardware improvement (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or a software improvement (improvement in method flows). However, with the development of technology, many improvements in method flows today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented with a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. The designer can program by himself to "integrate" a digital system on a piece of PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be clear that only by slightly logically programming the method flow with the above-mentioned several hardware description languages and programming it into the integrated circuit can the hardware circuit implementing the logical method flow be easily obtained.
[0117] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.
[0118] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0119] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0120] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0121] This specification is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0122] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means that implement the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0123] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and / or blocks Figure 1 or means for implementing the functions specified in one or more of the blocks.
[0124] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0125] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0126] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0127] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0128] It should be understood by those skilled in the art that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0129] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0130] The various embodiments in this specification are described in a progressive manner. For the same or similar parts among the various embodiments, reference can be made to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.
[0131] The above description is only for the embodiments of this specification and is not intended to limit this specification. For those skilled in the art, various modifications and changes can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. A method for executing a satellite single event effect resistant task, characterized in that, Including: Obtain monitoring parameters of the target software program, where the monitoring parameters are used to reflect the running state of the target software program and the current state of the hardware resources on which the target software program depends; Based on the monitoring parameters, perform anomaly detection on the target software program to obtain an anomaly detection result of the target software program, where the anomaly detection result is used to characterize whether there is an anomaly in the target software program; If it is determined according to the anomaly detection result that there is an anomaly in the target software program, obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium; The specified storage medium is a memory with radiation resistance; Based on the version record data, determine the historical software program of the previous version adjacent to the target software program in terms of update time as the fallback software program; Install and run the fallback software program, and determine a test task request that matches the fallback software program from the preset test task requests as the target test task request; Based on the target test task request, perform a function test on the fallback software program to obtain a function test result of the fallback software program, where the function test result is used to reflect whether there is an anomaly in the fallback software program; If it is determined according to the function test result that there is no anomaly in the fallback software program, perform task execution through the fallback software program.
2. The method according to claim 1, characterized in that, Storing the version record data corresponding to the target software program specifically includes: Receiving a data packet file sent by the ground end; Perform decryption processing on the data packet file to extract the software program to be installed, as well as the version data and verification parameters of the software program to be installed from the data packet file, where the verification parameters are used to reflect whether there is an anomaly in the data packet file during the transmission process; Based on the verification parameters, verify the software program to be installed to obtain a verification result, and in the case where it is determined according to the verification result that there is no anomaly in the software program to be installed, install the software program to be installed and store the update time and version data of the software program to be installed into the version record data corresponding to the software program to be installed.
3. The method according to claim 2, wherein The verification parameters include: a digital signature value, a first key, and digest algorithm parameters. The digital signature value is obtained by the ground end encrypting the digest value corresponding to the software program to be installed using a preset second key, and the digest algorithm parameters are used to characterize the algorithm used to determine the digest value corresponding to the software program to be installed and the format of the digest value; Based on the verification parameters, verifying the software program to be installed to obtain a verification result specifically includes: Extracting a digest value from the software program to be installed according to the digest algorithm parameters to determine a reference digest value corresponding to the software program to be installed; and Decrypting the digital signature value according to the first key to obtain a decrypted digest value corresponding to the software program to be installed; Verify the software program to be installed based on the reference digest value and the decrypted digest value to obtain a verification result. Specifically, if the reference digest value is consistent with the decrypted digest value, it can be obtained that the software program to be installed has no anomaly verification result. If the reference digest value is inconsistent with the decrypted digest value, it can be obtained that the software program to be installed has an anomaly verification result.
4. The method according to claim 1, wherein If it is determined that the target software program has an anomaly according to the anomaly detection result, obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium. Specifically, it includes: If it is determined that the target software program has an anomaly according to the anomaly detection result, determine the anomaly impact range parameter according to the monitored parameter with an anomaly, and store the anomaly impact range parameter in a preset anomaly log file. The anomaly impact range parameter is used to represent at least one other software program affected by the monitored parameter with an anomaly; and Obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium.
5. The method according to claim 1, characterized in that The method further includes: Generate an anomaly report file according to the anomaly detection result and the fallback software program, and send the anomaly report file to the ground end. The anomaly report file includes at least one of the anomaly occurrence time, anomaly type, fallback result, and version data of the fallback software program.
6. The method according to claim 1, characterized in that, The method further includes: At each specified time interval, obtain the verification parameter corresponding to each historical software program from the specified storage medium as an alternative verification parameter; For each historical software program, verify the historical software program according to the alternative verification parameter corresponding to the historical software program to obtain the verification result of the historical software program, and save the verification result of the historical software program.
7. A satellite single event effect resistant task execution device, characterized in that, It includes: A first acquisition module, configured to acquire the monitored parameter of the target software program, where the monitored parameter is used to reflect the running state of the target software program and the current state of the hardware resources relied on by the target software program; A detection module, configured to perform anomaly detection on the target software program according to the monitored parameter to obtain the anomaly detection result of the target software program, where the anomaly detection result is used to represent whether the target software program has an anomaly; A second acquisition module, configured to, if it is determined that the target software program has an anomaly according to the anomaly detection result, obtain the version record data corresponding to the target software program pre-stored from a preset specified storage medium; The specified storage medium is a memory with radiation resistance; A determination module, configured to determine, according to the version record data, the historical software program of the previous version adjacent to the target software program in terms of update time as the fallback software program; An execution module, configured to install and run the fallback software program, and determine, from preset test task requests, a test task request matching the fallback software program as the target test task request; According to the target test task request, perform a functional test on the fallback software program to obtain the functional test result of the fallback software program, and the functional test result is used to reflect whether there is an abnormality in the fallback software program; If it is determined according to the functional test result that there is no abnormality in the fallback software program, then perform the task through the fallback software program.
8. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and when the computer program is executed by a processor, the method described in any one of claims 1 to 6 above is implemented.
9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, the method described in any one of claims 1 to 6 above is implemented.
Citation Information
Patent Citations
Software exception rollback method and device, equipment and storage medium
CN117573163A