Satellite-borne computer and starting method of satellite-borne computer

By adopting the design of processing chips, FPGAs and redundant solid-state storage devices in the satellite-based computer, the problems of high cost and single-particle flip are solved, and a high-performance, low-cost and reliable satellite-based computer system is achieved.

CN120010937APending Publication Date: 2025-05-16ZHEJIANG LAB
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510103177.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Traditional satellite-based computers cannot meet the requirements of commercial aerospace due to their high cost, long development cycle and low performance. At the same time, satellite-based computers based on COTS devices are prone to being unable to start or operate normally due to single-particle flips under the single-particle effect of space.

Method used

A satellite-based computer is designed, using a processing chip, an FPGA, a first solid-state storage device and at least one second solid-state storage device. The state of the processing chip is detected by the FPGA. When the first solid-state storage device fails to start the system program, the system program stored in the second solid-state storage device is refreshed to the first solid-state storage device to ensure that the computer can start normally.

Benefits of technology

While reducing the hardware cost of on-site computers, this solution effectively avoids the impact of single-particle flip on computer startup and operation, ensuring the smooth execution of on-site tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010937A_ABST
    Figure CN120010937A_ABST
Patent Text Reader

Abstract

The invention discloses a spaceborne computer and a starting method of the spaceborne computer. The spaceborne computer comprises a processing chip, an FPGA (Field Programmable Gate Array), a first solid-state storage device and at least one second solid-state storage device; the first solid-state storage device and the at least one second solid-state storage device are used for storing a system program for guiding a computer to start; the processing chip is used for starting a system program from the first solid-state storage device; and the FPGA is used for detecting the state of the processing chip, and refreshing the system program stored in the second solid-state storage device to the first solid-state storage device when detecting that the first solid-state storage device fails to start the system program. According to the scheme, the hardware cost of the spaceborne computer is reduced, and meanwhile, the influence of single event upset on starting and running of the spaceborne computer is effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present specification relates to the field of computer technology, and in particular to a satellite-borne computer and a method for starting the satellite-borne computer. Background Art

[0002] In recent years, with the vigorous development and deepening of the application of various commercial satellites and satellite technologies, new requirements have been put forward for the processing power and cost of onboard computing payloads. Traditional onboard computers based on radiation-resistant space-grade chips can no longer effectively meet the requirements of commercial aerospace due to their high cost, long development cycle, and low performance. In recent years, onboard computers based on Commercial Off-The-Shelf (COTS) devices have been increasingly widely used on low-orbit commercial satellites due to their advantages such as high performance, low cost, and short development cycle.

[0003] However, due to the existence of single-particle effects in space and the poor radiation resistance of some COTS devices themselves, onboard computers often fail to start normally when performing on-orbit missions due to single-particle flips in COTS devices, or malfunction after startup, which seriously affects the normal operation of the onboard computers and cannot guarantee the smooth execution of onboard missions. Summary of the invention

[0004] This specification provides a satellite-borne computer and a method for starting the satellite-borne computer to partially solve the above-mentioned problems existing in the prior art.

[0005] This manual adopts the following technical solutions:

[0006] This specification provides a satellite-borne computer, the satellite-borne computer comprising: a processing chip, an FPGA, a first solid-state storage device and at least one second solid-state storage device;

[0007] The first solid-state storage device and the at least one second solid-state storage device are used to store a system program for booting a computer;

[0008] The processing chip is used to start the system program from the first solid-state storage device to start the onboard computer based on the started system program;

[0009] The FPGA is used to detect the state of the processing chip, and when it is detected that the first solid-state storage device fails to start the system program, refresh the system program stored in the second solid-state storage device to the first solid-state storage device, so that the processing chip starts the refreshed system program from the first solid-state storage device.

[0010] Optionally, the first solid-state storage device includes: a first FLASH memory and a first SSD; the at least one second solid-state storage device includes: at least one second FLASH memory and at least one second SSD;

[0011] The first SSD and the at least one second SSD are connected to the processing chip, the first FLASH memory and the at least one second FLASH memory are connected to the FPGA, and the FPGA is connected to the processing chip.

[0012] Optionally, the system program includes: an operating system of the onboard computer and a boot program of the operating system;

[0013] The first FLASH memory and the at least one second FLASH memory are used to store the boot program;

[0014] The first SSD and the at least one second SSD are used to store the operating system;

[0015] The processing chip is used to start the boot program from the first FLASH memory, and start the operating system from the first SSD based on the boot program;

[0016] The FPGA is used to, when it is detected that the first FLASH memory fails to start the boot program, refresh the boot program stored in the second FLASH memory to the first FLASH memory, so that the processing chip starts the refreshed boot program from the first solid-state storage device; and when it is detected that the first SSD fails to start the operating system, refresh the operating system stored in the second SSD to the first SSD, so that the processing chip starts the refreshed operating system from the first SSD.

[0017] Optionally, the onboard computer further comprises: a synchronous dynamic random access memory SDRAM;

[0018] The SDRAM is used to store application programs;

[0019] The processing chip is used to run the application program stored in the SDRAM in the operating environment provided by the operating system, so as to execute tasks through the started application program.

[0020] Optionally, the processing chip is specifically configured to send a first signal to the FPGA if the boot program is successfully started from the first FLASH memory, and otherwise not send the first signal to the FPGA;

[0021] The FPGA is configured to, if the first signal is not received, send a startup instruction to the first power supply, so as to power on the at least one second FLASH memory through the first power supply; and

[0022] After receiving the first signal, a shutdown instruction is sent to the first power supply to power off the at least one second FLASH memory.

[0023] Optionally, the processing chip is specifically configured to send a second signal to the FPGA if the operating system is successfully loaded from the first SDD, and otherwise not send the second signal to the FPGA;

[0024] The FPGA is configured to, if the second signal is not received, send a startup instruction to the second power supply to power on the at least one second SSD through the second power supply; and

[0025] After receiving the second signal, a shutdown instruction is sent to the second power supply to power off the at least one second SSD.

[0026] Optionally, the processing chip is further configured to, when the system program is successfully loaded, send a third signal to the FPGA at a preset time interval;

[0027] The FPGA is used to send a reset signal to the processing chip if the third signal is not received within a preset timing period, so that the processing chip is reset and restarted based on the reset signal.

[0028] Optionally, the failure of the first solid-state storage device to start the system program is caused by a single event upset in the first solid-state storage device.

[0029] This specification provides a method for starting a satellite computer, which is applied to the above-mentioned satellite computer, and the method includes:

[0030] The processing chip starts the system program from the first solid-state storage device;

[0031] The onboard computer is started based on the startup system program; wherein, if the FPGA detects that the first solid-state storage device fails to start the boot program, after the FPGA refreshes the system program stored in the second solid-state storage device to the first solid-state storage device, the refreshed system program is started from the first solid-state storage device.

[0032] This specification provides a startup device for a satellite-borne computer, including:

[0033] A startup module, used for processing the chip to start the system program from the first solid-state storage device;

[0034] An execution module is used to start the onboard computer based on the started system program; wherein, if it is detected through the FPGA that the first solid-state storage device fails to start the boot program, then after the FPGA refreshes the system program stored in the second solid-state storage device to the first solid-state storage device, the refreshed system program is started from the first solid-state storage device.

[0035] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects:

[0036] The onboard computer provided in this specification includes: the onboard computer includes: a processing chip, an FPGA, a first solid-state storage device and at least one second solid-state storage device; the first solid-state storage device and at least one second solid-state storage device are used to store a system program for booting the computer; the processing chip is used to start the system program from the first solid-state storage device; the FPGA is used to detect the state of the processing chip, and when it is detected that the first solid-state storage device fails to start the system program, the system program stored in the second solid-state storage device is refreshed to the first solid-state storage device. This solution effectively avoids the impact of single-particle upsets on the startup and operation of the onboard computer while reducing the hardware cost of the onboard computer.

[0037] It can be seen from the above method that the onboard computer in this scheme can utilize the hardware characteristics of FPGA that is not prone to single-particle upsets and the redundant design of solid-state storage devices, so that when the FPGA detects that the processing chip fails to start the system program in the first solid-state storage device, it can restart the system program through other solid-state storage devices. While reducing the hardware cost of the onboard computer through COTS devices, it effectively avoids the situation where the computer cannot start or run normally due to single-particle upsets in some devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The illustrative embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation on this specification. In the drawings:

[0039] Figure 1 A schematic diagram of a satellite-borne computer provided in this specification;

[0040] Figure 2 A schematic diagram of the boot switching hardware architecture of a FLASH memory provided in this specification;

[0041] Figure 3A schematic diagram of a NOR FLASH startup switching logic flow provided in this specification;

[0042] Figure 4 A schematic diagram of the SSD boot switching hardware architecture provided in this manual;

[0043] Figure 5 A schematic diagram of an SSD startup switching logic flow provided in this specification;

[0044] Figure 6 This is a schematic diagram of a processing chip system crash perception and reset restart control logic provided in this specification;

[0045] Figure 7 A schematic diagram of a method for starting a satellite computer provided in this specification;

[0046] Figure 8 This is a schematic diagram of a startup device for a satellite-borne computer provided in this manual. DETAILED DESCRIPTION

[0047] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.

[0048] The technical solutions provided by the embodiments of this specification are described in detail below in conjunction with the accompanying drawings.

[0049] Figure 1 This is a schematic diagram of a satellite-borne computer provided in this specification, and the satellite-borne computer includes: a processing chip, an FPGA, a first solid-state storage device, and at least one second solid-state storage device.

[0050] The first solid-state storage device and at least one second solid-state storage device may store a system program for booting the computer, and the processing chip may boot the system program from the first solid-state storage device, thereby booting the onboard computer based on the booted system program;

[0051] The FPGA can detect the status of the processing chip. When it is detected that the first solid-state storage device fails to start the system program, the system program stored in the second solid-state storage device can be refreshed to the first solid-state storage device so that the processing chip starts the refreshed system program from the first solid-state storage device.

[0052] Specifically, the above-mentioned first solid-state storage device may include: a first FLASH memory and a first SSD; at least one second solid-state storage device may include: at least one second FLASH memory and at least one second SSD; the above-mentioned system program may include: the operating system of the onboard computer and the boot program of the operating system.

[0053] like Figure 1 As shown, the first SSD (SSD1) and the second SSD (SSD2) are connected to the processing chip, the first FLASH memory (FLASH1) and at least one second FLASH memory (FLASH2) are connected to the FPGA, and the FPGA is connected to the processing chip.

[0054] Among them, the FPGA is interconnected with the satellite integrated power platform through the outgoing CAN interface to control the power supply of each redundant device. The processing chip and the FPGA communicate directly through the general purpose input / output (GPIO) and the serial peripheral interface (SPI). The FPGA and the FLASH memory communicate through SPI.

[0055] The above-mentioned FLASH memory may be a NOR FLASH, and the first FLASH memory and the second FLASH memory are in a cold standby relationship, that is, when the first FLASH memory is working normally, the second FLASH memory is in a power-off state, and when the first FLASH memory is abnormal, the second FLASH memory is powered on and works. Similarly, the first SSD and the second SSD are also in a cold standby relationship, that is, when the first SSD is working normally, the second SSD is in a power-off state, and when the first SSD is abnormal, the second SSD is powered on and works.

[0056] The first FLASH memory and the second FLASH memory are used to store the boot program of the processing chip, and the SSD is used to store the operating system and user data. The boot program may include a Bootloader or a Boot Program, which is used to complete the initialization process after startup and guide the processing chip to load the operating system.

[0057] During the booting process of the onboard computer, the processing chip may start the boot program from the first FLASH memory, and then load and start the operating system from the first SSD under the guidance of the boot program.

[0058] In this specification, a synchronous dynamic random access memory (SDRAM) may also be provided in the onboard computer system, wherein the SDRAM may be a double data rate synchronous dynamic random access memory (DDR SDRAM), and the processing chip is connected to the DDR SDRAM via a DDR high-speed interface and used as a cache for running programs and data.

[0059] The processing chip may load an operating system into the SDRAM and start an application in the SDRAM to run the application in an operating environment provided by the operating system and perform tasks through the application.

[0060] In practical applications, the above tasks may include image recognition, data processing, remote control and telemetry, energy management, thermal management, docking and separation control, etc., which are not specifically limited in this specification. The application programs in SDRAM may include the application programs required to perform the above tasks.

[0061] Furthermore, the FPGA may be a FLASH-type FPG that has been verified in orbit for a long time, and is used to monitor the system status and realize the core function of resisting single-particle upset.

[0062] During the startup process of the onboard computer, when the FPGA detects that the first FLASH memory fails to run the boot program, the boot program may be run through at least one second FLASH memory.

[0063] Among them, when it is detected that a single particle flip occurs due to space radiation, resulting in the failure of the first FLASH memory to run the boot program, at least one second FLASH memory can be powered on, and the boot program in at least one second FLASH memory can be refreshed to the first FLASH memory, and then the processing chip can start the refreshed boot program from the first FLASH memory.

[0064] Specifically, when the processing chip successfully starts the boot program from the first FLASH memory, the first signal is sent to the FPGA; otherwise, the first signal is not sent to the FPGA.

[0065] If the FPGA does not receive the first signal, the FPGA may send a startup instruction to the first power supply to power on at least one second FLASH memory through the first power supply.

[0066] When the processing chip successfully starts the boot program from the first FLASH memory, it can send a first signal to the FPGA. After receiving the first signal, the FPGA can send a shutdown instruction to the first power supply to power off at least one second FLASH memory. For ease of understanding, this specification provides a schematic diagram of the startup switching hardware design of the FLASH memory, such as Figure 2 shown.

[0067] Figure 2 This is a schematic diagram of the boot switching hardware architecture of a FLASH memory provided in this specification.

[0068] Among them, the processing chip is powered by a secondary power supply 3 provided by the integrated power platform, the FPGA is powered by a secondary power supply 2 provided by the integrated power platform, and each FLASH memory is powered by a secondary power supply 1 (first power supply) provided by the integrated power platform.

[0069] Furthermore, this specification also provides a NOR FLASH startup switching logic flow diagram, such as Figure 3 shown.

[0070] Figure 3 This is a schematic diagram of a NOR FLASH startup switching logic flow provided in this specification.

[0071] Among them, when the system is powered on, NOR FLASH1 is powered on by default, the mos_on signal output by FPGA is high level by default, and NOR FLASH2 is powered off; the processing chip first boots the program from NOR FLASH1.

[0072] If the processing chip successfully starts from NOR FLASH1, the processing chip will send a boot_done signal (first signal) to the FPGA. At this time, the FPGA senses that the processing chip has successfully started from NOR FLASH1, so the FPGA does not perform power switching, and the processing chip continues to start the operating system from the specified SSD.

[0073] If the FPGA does not receive the boot_done signal sent by the processing chip, the FPGA senses that the processing chip cannot be successfully started from NOR FLASH1. In this case, the FPGA first sets mos_on to a low level, powers on NOR FLASH2 through secondary power supply 1, and then refreshes the boot program in NOR FLASH2 to NOR FLASH1 to repair it.

[0074] After the repair is completed, the FPGA can power off and restart the computer, and the switching logic inside the FPGA is restored to the initial state. At this time, NOR FLASH1 is powered on, and the processing chip boots the program from NOR FLASH1 by default; NOR FLASH2 is powered off and does not work.

[0075] It should be noted that telemetry information such as the boot_done signal can be sent to the integrated power supply through the CAN bus and then transmitted to the ground receiving station; program control instructions such as switching are sent from the ground receiving station to the integrated power supply platform and then sent to the FPGA for execution through the CAN interface. The power on and off of the whole machine is directly controlled by the satellite platform.

[0076] Of course, in actual applications, if the first FLASH memory fails to start the boot program, the FPGA can also directly power on the second FLASH memory. At this time, the processing chip can start the boot program from the second FLASH memory. At the same time, the boot program in the second FLASH memory is refreshed to the first FLASH memory, and the first FLASH memory can be powered off after the first FLASH memory is repaired.

[0077] After the processing chip successfully starts the boot program from the FLASH memory, it needs to start the operating system based on the boot program. When the FPGA detects that the first FLASH memory fails to run the boot program due to a single particle upset caused by space radiation, at least one second FLASH memory can be powered on, and the boot program in at least one second FLASH memory can be refreshed to the first FLASH memory, and then the processing chip can start the refreshed boot program from the first FLASH memory.

[0078] Specifically, when the processing chip successfully loads the operating system from the first SDD, the second signal may be sent to the FPGA; otherwise, the second signal may not be sent to the FPGA.

[0079] If the FPGA does not receive the second signal, a startup instruction is sent to the second power supply to power on the at least one second SSD through the second power supply.

[0080] After the processing chip successfully starts the boot program from the first SSD, it can send a second signal to the FPGA. After receiving the second signal, the FPGA can send a shutdown instruction to the second power supply to power off at least one second SSD.

[0081] For ease of understanding, this specification provides a schematic diagram of the SSD boot switching hardware design, such as Figure 4 shown.

[0082] Figure 4This is a schematic diagram of the SSD boot switching hardware architecture provided in this manual.

[0083] Among them, the processing chip is powered by a secondary power supply 3 provided by the integrated power platform, the FPGA is powered by a secondary power supply 2 provided by the integrated power platform, and each FLASH memory is powered by a secondary power supply 4 (second power supply) provided by the integrated power platform.

[0084] Furthermore, this specification also provides a schematic diagram of an SSD startup switching logic flow, such as Figure 5 shown.

[0085] Figure 5 The following is a schematic diagram of an SSD startup switching logic flow provided in this specification.

[0086] Among them, when the system is powered on, SSD1 is powered on by default and SSD2 is powered off. After the processing chip starts the boot program, the boot program reads the operating system startup configuration signal os_boot_select output by the FPGA. The signal is high by default and is set to start the operating system from SSD1.

[0087] If the processing chip successfully starts the operating system from SSD1, the processing chip will send an os_boot_done signal (second signal) to the FPGA. At this time, the FPGA senses that the processing chip has been successfully started from SSD1, and the FPGA does not perform any action.

[0088] If the FPGA does not receive the os_boot_done signal sent by the processing chip, the FPGA senses that the processing chip cannot successfully start the operating system from SSD1. In this case, the FPGA can first power on SSD2 through the second power supply and set os_boot_select to a low level; then send a reset signal to the processing chip.

[0089] When the processing chip receives the reset signal, it starts a hot reset. First, it boots the program. The boot program reads the operating system startup configuration signal os_boot_select output by the FPGA. At this time, the signal is low and the operating system is set to start from SSD2. Since SSD2 has been in a power-off state before, it is assumed that the operating system binary file inside SSD2 has no single-particle upset and can be started normally.

[0090] After the processing chip successfully starts the operating system from SSD2, the processing chip receives instructions to refresh the minimum operating system file in SSD2 to SSD1 through a high-speed hardware link to repair it. The minimum operating system file is controlled within 10GB and can be refreshed within 6 minutes.

[0091] After the refresh is completed, the computer is powered off and restarted, and the switching control logic inside the FPGA is restored to the initial state. At this time, SSD1 is powered on, os_boot_select defaults to a high level, and the boot program boots the operating system from SSD1; SSD2 is powered off and does not work.

[0092] Among them, telemetry information such as os_boot_done signal can be sent to the integrated power supply through the CAN bus and then transmitted to the ground receiving station; program control instructions such as switching and reset are sent from the ground receiving station to the integrated power supply platform and then sent to the FPGA for execution through the CAN interface. The power on and off of the whole machine can be directly controlled by the satellite platform.

[0093] Of course, in actual applications, if the first SSD fails to start the boot program, the FPGA can also directly power on the second SSD. At this time, the processing chip can start the boot program from the second SSD. At the same time, the boot program in the second SSD is refreshed to the first FLASH memory, and the first SSD is powered off after the repair of the first SSD is completed.

[0094] Furthermore, considering the problem of single-particle upset in the onboard computer causing system crash after the operating system is normally started, the FPGA will monitor the system operation status in real time. When an abnormal system operation is detected, the FPGA will hot-reset the processing chip.

[0095] Wherein, the processing chip can send a third signal to the FPGA at a preset time interval when the operating system is successfully loaded. If the FPGA does not receive the third signal within the preset timing period, a reset signal is sent to the processing chip, so that the processing chip is reset and restarted based on the reset signal. For ease of understanding, this specification provides a schematic diagram of the processing chip system crash perception and reset and restart control logic, such as Figure 6 shown.

[0096] Figure 6 This is a schematic diagram of a processing chip system crash perception and reset restart control logic provided in this specification;

[0097] Among them, after the processing chip enters the system, it first sends a system initialization success signal os_boot_done to the FPGA; then it sends a system normal signal os_ok (the third signal) to the FPGA every 5 seconds.

[0098] When the FPGA receives the os_boot_done signal, the watchdog starts timing with a timing period of 10 seconds. If the os_ok signal is not received within 10 seconds, the system is determined to be frozen, and the FPGA sends a reset signal to the processing chip. When the next os_boot_done signal is received, the FPGA resets the watchdog and continues timing to determine whether the system is frozen. If the os_ok signal is received within 10 seconds, the system is determined to be normal, and the FPGA resets the watchdog and continues timing to determine whether the system is frozen.

[0099] It should be pointed out that in this specification, the failure of the first solid-state storage device to start the system program (including the failure of the first FLASH to start the operation boot program and the failure of the first SSD to start the operating system) may be caused by a single particle flip in the first solid-state storage device (including the first FLASH and the first SSD). Of course, it may also be caused by other internal or external non-permanent reasons.

[0100] Furthermore, this specification also provides a task execution method applied to the above-mentioned onboard computer, such as Figure 7 shown.

[0101] Figure 7 The flowchart of a method for starting a satellite computer provided in this specification includes the following steps:

[0102] S701: The processing chip starts a system program from a first solid-state storage device;

[0103] S702: Start the onboard computer based on the started system program; wherein, if the FPGA detects that the first solid-state storage device fails to start the system program, after the FPGA refreshes the system program stored in the second solid-state storage device to the first solid-state storage device, the refreshed system program is started from the first solid-state storage device.

[0104] The processing chip can run the application program stored in the SDRAM in the operating environment provided by the operating system to execute tasks through the application program.

[0105] From the above content, it can be seen that the entire computer system of this solution uses COTS devices, which greatly reduces the cost of the computer system, improves computing performance and shortens the equipment development cycle.

[0106] An FPGA that has been verified in orbit for a long time is used as the control core. Only by simply sensing and controlling the operating status of the processing chip and switching the startup storage medium can the complexity of the startup control logic and verification algorithm be reduced, ensuring that the system can provide single-particle flip resistance in a low-orbit environment under relatively simple software and hardware design conditions, thereby ensuring the reliable operation of the system.

[0107] The above are one or more implementations of the onboard computer startup method of this specification. Based on the same idea, this specification also provides a corresponding onboard computer startup device, such as Figure 8 shown.

[0108] Figure 8 A schematic diagram of a startup device of a satellite computer provided in this manual includes:

[0109] The startup module 801 is used for the processing chip to start the system program from the first solid-state storage device;

[0110] The loading module 802 is used to start the onboard computer based on the started system program; wherein, if it is detected through the FPGA that the first solid-state storage device fails to start the system program, then after the FPGA refreshes the system program stored in the second solid-state storage device to the first solid-state storage device, the refreshed system program is started from the first solid-state storage device.

[0111] For the improvement of a technology, it can be clearly distinguished whether it is a hardware improvement (for example, improvement of the circuit structure of diodes, transistors, switches, etc.) or a software improvement (improvement of the method flow). However, with the development of technology, many improvements of the method flow today can be regarded as direct improvements of the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that the improvement of a method flow cannot be implemented with a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming themselves, without having to ask chip manufacturers to design and make dedicated integrated circuit chips. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0112] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.

[0113] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0114] For the convenience of description, the above device is described by dividing it into various units according to its functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0115] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0116] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0117] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0118] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0119] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0120] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0121] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0122] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0123] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0124] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0125] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0126] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.

Claims

1. A satellite-borne computer, characterized in that: The onboard computer includes: a processing chip, an FPGA, a first solid-state storage device and at least one second solid-state storage device; The first solid-state storage device and the at least one second solid-state storage device are used to store a system program for booting a computer; The processing chip is used to start the system program from the first solid-state storage device to start the onboard computer based on the started system program; The FPGA is used to detect the state of the processing chip, and when it is detected that the first solid-state storage device fails to start the system program, refresh the system program stored in the second solid-state storage device to the first solid-state storage device, so that the processing chip starts the refreshed system program from the first solid-state storage device.

2. The onboard computer according to claim 1, wherein: The first solid-state storage device includes: a first FLASH memory and a first SSD; the at least one second solid-state storage device includes: at least one second FLASH memory and at least one second SSD; The first SSD and the at least one second SSD are connected to the processing chip, the first FLASH memory and the at least one second FLASH memory are connected to the FPGA, and the FPGA is connected to the processing chip.

3. The onboard computer according to claim 2, characterized in that: The system program includes: an operating system of the onboard computer and a boot program of the operating system; The first FLASH memory and the at least one second FLASH memory are used to store the boot program; The first SSD and the at least one second SSD are used to store the operating system; The processing chip is used to start the boot program from the first FLASH memory, and start the operating system from the first SSD based on the boot program; The FPGA is used to, when it is detected that the first FLASH memory fails to start the boot program, refresh the boot program stored in the second FLASH memory to the first FLASH memory, so that the processing chip starts the refreshed boot program from the first solid-state storage device; and when it is detected that the first SSD fails to start the operating system, refresh the operating system stored in the second SSD to the first SSD, so that the processing chip starts the refreshed operating system from the first SSD.

4. The onboard computer according to claim 3, characterized in that: The onboard computer also includes: a synchronous dynamic random access memory SDRAM; The SDRAM is used to store application programs; The processing chip is used to run the application program stored in the SDRAM in the operating environment provided by the operating system, so as to execute tasks through the started application program.

5. The onboard computer according to claim 3, characterized in that: The processing chip is specifically configured to send a first signal to the FPGA if the boot program is successfully started from the first FLASH memory, and otherwise not send the first signal to the FPGA; The FPGA is configured to, if the first signal is not received, send a startup instruction to the first power supply to power on the at least one second FLASH memory through the first power supply; as well as After receiving the first signal, a shutdown instruction is sent to the first power supply to power off the at least one second FLASH memory.

6. The onboard computer according to claim 3, characterized in that: The processing chip is specifically configured to send a second signal to the FPGA if the operating system is successfully loaded from the first SDD, and otherwise not send the second signal to the FPGA; The FPGA is configured to, if the second signal is not received, send a startup instruction to the second power supply to power on the at least one second SSD through the second power supply; as well as After receiving the second signal, a shutdown instruction is sent to the second power supply to power off the at least one second SSD.

7. The onboard computer according to claim 1, wherein: The processing chip is further configured to, when the system program is successfully executed, send a third signal to the FPGA at a preset time interval; The FPGA is used to send a reset signal to the processing chip if the third signal is not received within a preset timing period, so that the processing chip is reset and restarted based on the reset signal.

8. The onboard computer according to claim 1, wherein: The failure of the first solid-state storage device to start the system program is caused by a single event upset occurring in the first solid-state storage device.

9. A method for starting a satellite computer, characterized in that: The method is applied to the onboard computer according to any one of claims 1 to 8, and the method comprises: The processing chip starts the system program from the first solid-state storage device; The onboard computer is started based on the startup system program; wherein, if it is detected through the FPGA that the first solid-state storage device fails to start the system program, after the FPGA refreshes the system program stored in the second solid-state storage device to the first solid-state storage device, the refreshed system program is started from the first solid-state storage device.

10. A starting device for a satellite-borne computer, characterized in that: include: A startup module, used for processing the chip to start the system program from the first solid-state storage device; An execution module is used to start the onboard computer based on the started system program; wherein, if it is detected through the FPGA that the first solid-state storage device fails to start the system program, then after the FPGA refreshes the system program stored in the second solid-state storage device to the first solid-state storage device, the refreshed system program is started from the first solid-state storage device.

Citation Information

Cited By

  • Satellite computing device control method, satellite computing device and system

    CN120315781A