Satellite-borne equipment single event upset resisting system based on FPGA (Field Programmable Gate Array) and implementation method
By using anti-single-particle flip system with anti-fuse FPGA chips and three FLASH chips in satellite-based equipment, the program abnormality caused by single-particle flip in the radiated environment is solved, and the stability and cost-effectiveness of the system are improved.
Patent Information
- Application Number
- CN202510684787.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-06-24
AI Technical Summary
FPGA chips in satellite-borne equipment are susceptible to single-particle flip effect in the radiation environment, resulting in abnormal program operation and damage to hardware circuits. The existing radiation-resistant measures have problems such as high costs, scarce resources and equipment suspension.
A satellite-based device anti-single-particle flip system based on FPGA is adopted, including an anti-fuse FPGA chip, an SRAM type FPGA chip and a three-piece FLASH chip. As a refresh control chip, the anti-fuse FPGA chip is dynamically refreshed through the SRAM type FPGA chip through the SELECTMAP interface, and three FLASH chips are used for program backup and three-choice voting to ensure data accuracy and system stability.
It greatly improves the anti-single-particle flip capability of FPGA in space environment, reduces the risk of program abnormalities, ensures the stability and cost-effectiveness of the system, and provides multiple backup and verification mechanisms of program data, enhancing the reliability of the system.
Smart Images

Figure CN120196484A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of hardware devices, and particularly to a single event upset resistant system and implementation method for on-board devices based on FPGA. Background Art
[0002] With the development of space technology, a large number of integrated circuit chips are adopted in space satellites to improve the performance indexes of various aspects of the devices. On-board devices are in the radiation environment for a long time and are vulnerable to charged particle radiation, resulting in an increasing risk of anomalies in integrated circuit chips due to the single event upset effect. This problem not only causes errors in software operation, but also seriously damages the hardware circuit and causes the failure of on-board devices. At present, SRAM-based FPGAs are increasingly used in the development of on-board devices due to their advantages such as rich interfaces, strong reconfigurability, small volume, and high integration. FPGAs contain a large number of logic resources. If the FPGA and its configuration chips are in the radiation environment for a long time, the probability of being penetrated by cosmic high-energy particles will increase greatly. The binary data content of the FPGA units affected by single particle radiation will change from 0 to 1 or from 1 to 0, resulting in the inversion of the data content in its semiconductor storage device. This phenomenon is called single event upset, which will cause anomalies in the operation of the FPGA program, calculate incorrect results, and affect the normal operation of on-board devices.
[0003] Common solutions to single event upset resistance of FPGAs include methods such as re-powering, resetting the FPGA, reading back program data for reconfiguration, and adding radiation-resistant chips. However, these methods have many disadvantages, such as causing abnormal pauses of on-board devices and loss of intermediate states of the devices. Moreover, the cost of space-grade radiation-resistant chips is expensive and the available resources are few. Summary of the Invention
[0004] Based on this, it is necessary to provide a single event upset resistant system and implementation method for on-board devices based on FPGA that can enhance the single event upset resistance ability of FPGAs in the space environment and has the advantages of strong stability and low cost in view of the above technical problems.
[0005] A single event upset resistant system for on-board devices based on FPGA, the system includes an anti-fuse FPGA chip, an SRAM-based FPGA chip, and three FLASH chips; The anti-fuse FPGA chip is used as the carrier for solidifying the refresh control program of the refresh control chip to realize the program refresh of the SRAM FPGA chip; The SRAM-based FPGA chip is used to complete signal processing; The three FLASH chips are used to solidify three identical SRAM FPGA programs; After the anti-fuse FPGA chip is powered on normally, it reads the backup programs from three FLASH chips respectively at the same time, and compares the three backup programs. When at least two kinds of data are found to be consistent, voting begins, and the same data is written into the SRAM-based FPGA chip to complete the configuration of the FPGA chip. At the same time, the FPGA chip is refreshed regularly.
[0006] In one embodiment, the anti-fuse FPGA chip, as a refresh control chip, dynamically refreshes the SRAM-based FPGA chip through the SELECTMAP interface. The refresh control chip uses the master mode of SELECTMAP, and the SRAM-based FPGA chip uses the slave mode; the data bit width of the SELECTMAP interface can reach up to 32 bits at most, and it supports the transmission and loading of files in.bit,.rbt,.bin,.mcs,.hex formats.
[0007] In one embodiment, the anti-fuse FPGA chip is connected to the SRAM-based FPGA chip, and three FLASH chips are connected to the anti-fuse FPGA chip.
[0008] In one embodiment, the anti-fuse FPGA chip and the SRAM-based FPGA chip are connected through PROG, INIT_B, RDWR_B, CSI, CCLK, DATA[15:0], DONE pins; the FLASH chip and the anti-fuse FPGA chip are connected through ADDR[25:0], DATA[15:0], #OE, #CE, #WE pins.
[0009] In one embodiment, each of the three FLASH chips stores data starting from the base address, and the storage area of the FLASH is divided into two parts: one part is the program data storage area, and the other part is the check data storage area.
[0010] In one embodiment, after receiving the program data, the anti-fuse FPGA chip stores three identical program data in three FLASH chips respectively at the same time, and stores the CRC data for verification in the check data storage area as a backup. When the FLASH chip performs a read-back data verification, it compares the check data with the stored program data. If the data is consistent, it is normal.
[0011] A method for realizing single-event upset resistance of a spaceborne device based on FPGA, the method comprising: Step 1: The ground console sends a program upload instruction to the satellite spaceborne device in the space orbit; Step 2: After receiving the command, the on-board device parses it, transmits the parsed control command to the antifuse FPGA chip. The antifuse FPGA chip sends the erase command for the corresponding sector address to the three FLASH chips simultaneously, waits to read the FLASH status information. After the erasure is completed, the antifuse FPGA chip sends an instruction indicating that the uploading function is ready externally. The on-board device packs the ready instruction and sends it back to the ground console; Step 3: After receiving the instruction indicating that the uploading function of the on-board device is ready, the ground console starts to transmit the program file to the satellite for the uploading operation; Step 4: After parsing the program file, the on-board device transmits the obtained program data to the antifuse FPGA chip. The antifuse FPGA chip performs CRC and IDCODE checks on the program data, and at the same time writes the program data into the three FLASH chips. During the data writing process of the three FLASH chips, the stored data is synchronously read to compare the read and written data to ensure the correctness of the stored data; Step 5: If the CRC and IDCODE checks of the uploaded program by the antifuse FPGA chip are correct, and the data read by each FLASH chip passes the check, the data starts to be refreshed through the refresh chip. If the check data is incorrect, the on-board device starts to send an instruction for retransmitting the program data to the ground console until the uploaded program data passes the check successfully; Step 6: After the satellite successfully completes the program uploading operation, the antifuse FPGA chip periodically checks whether there is new uploaded program data for the on-board device. If there is new uploaded program data, steps 1 to 6 are repeated. When there is new program data being uploaded, the antifuse FPGA chip pulls down the PROG pin connected to the signal processing FPGA according to the timing requirements during the refresh to initialize the signal processing FPGA. When there is no new program data uploaded by the ground control station, the antifuse FPGA chip reads the program data from the three FLASH chips at regular intervals according to the timer for a two-out-of-three vote, and refreshes the voted program to the signal processing FPGA at regular intervals. This refresh process does not pull down the PROG pin between the refresh chip and the signal processing FPGA to prevent the loss of intermediate states.
[0012] The above-mentioned on-board device single-event upset resistant system and implementation method based on FPGA. In this application, an antifuse FPGA chip is used as the refresh chip, and three FLASH chips are used as program backup configuration chips, which greatly improves the protection ability of the device against single-event upsets. At the same time, a mechanism to prevent program data corruption is provided. The three FLASH chips are used to complete the program backup function, and the correctness of the data is voted by a two-out-of-three method to prevent abnormal program data caused by abnormalities in the configuration chips, greatly reducing the risk of program abnormalities. At the same time, a function for retransmitting the on-board device program is designed to ensure that the on-board device program can operate normally in the space environment. Description of the Drawings
[0013] Figure 1 It is a structural block diagram of a single event upset resistant system for on - board equipment based on FPGA in an embodiment; Figure 2 It is a data storage structure diagram of a FLASH configuration chip in an embodiment; Figure 3 It is a schematic flowchart of a method for realizing single event upset resistance of on - board equipment based on FPGA in an embodiment; Figure 4 It is a schematic flowchart of program data flow control in an embodiment; Figure 5 It is a schematic flowchart of a timing refresh signal processing FPGA program in another embodiment. Detailed Embodiments
[0014] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0015] In one embodiment, as Figure 1 shown, a single event upset resistant system for on - board equipment based on FPGA is provided, including: one anti - fuse FPGA chip, one SRAM - type FPGA chip and three FLASH chips; The FLASH chips are connected to the anti - fuse FPGA chip through pins ADDR[25:0], DATA[15:0], #OE, #CE, #WE, and the anti - fuse FPGA chip is connected to the SRAM - type FPGA through pins INIT_B, RDWR_B, CSI, CCLK, DONE, DATA[15:0]. It should be noted that the labels FLASH1, FLASH2, and FLASH3 in this drawing are not used to describe the order of storing data, but only for distinction.
[0016] The anti - fuse FPGA chip, as the carrier for solidifying the refresh control program, is used to implement the program refresh of the SRAM FPGA chip; The SRAM - type FPGA chip is used to complete signal processing; The three FLASH chips are used to solidify three identical SRAM FPGA programs; After the anti-fuse FPGA chip is powered on normally, it reads the backup programs from three FLASH chips respectively and compares the three backup programs. When at least two kinds of data are found to be consistent, voting begins, and the same data is written into the SRAM-based FPGA chip to complete the configuration of the FPGA chip. At the same time, the FPGA chip is refreshed regularly.
[0017] In the above satellite-borne equipment single-event upset resistant system based on FPGA, in this application, three FLASH chips are used to solidify three identical SRAM FPGA programs, and the two-out-of-three voting method is used to judge the correctness of the data. In the space radiation environment, single-event upsets may cause errors in the data of a certain FLASH chip. However, through the two-out-of-three voting mechanism, as long as the data of two chips is consistent, it can be considered as correct data, effectively eliminating the influence of single-event upsets on the data of a single chip, improving the accuracy and reliability of the program data, and enhancing the single-event upset resistance ability of the system. At the same time, the anti-fuse FPGA chip, as the refresh control chip, solidifies the refresh control program. It can read the backup program from three FLASH chips after the equipment is powered on normally, write the correct data into the SRAM-based FPGA chip to complete the configuration, and can also refresh the FPGA chip regularly. Regular refresh can timely detect and correct data errors that may occur due to single-event upsets in the SRAM-based FPGA chip, avoid the accumulation of errors leading to equipment anomalies, and further enhance the single-event upset resistance ability of the system in the space radiation environment. In this application, multiple chips are used to implement different functions, and three FLASH chips are used for program storage as backup. This hardware redundancy design provides multiple guarantees for the system. Even if a certain chip fails due to radiation, other chips can still ensure the basic functions of the system, ensuring the stability of the system and reducing the risk of system collapse caused by single-event upsets. After reading the program data in the FLASH chip, the anti-fuse FPGA chip conducts comparison and voting, can timely detect and correct the error data, and ensures that the program data for system operation is always correct by writing the correct data into the SRAM-based FPGA chip. This data verification and repair mechanism can effectively prevent the spread and accumulation of data errors caused by single-event upsets in the system, thereby improving the stability of the system and enabling the system to operate continuously and stably in the complex space radiation environment. In addition, traditional single-event upset resistant methods often use space-grade radiation-hardened chips, but such chips are costly and have fewer available resources. In this application, mainly anti-fuse FPGA chips and FLASH chips are used, and the single-event upset resistant function is realized through ingenious design and the collaborative work of multiple chips, without the need to use a large number of expensive space-grade radiation-hardened chips, thus greatly reducing the cost.
[0018] In one embodiment, the antifuse FPGA chip, as a refresh control chip, dynamically refreshes the SRAM-based FPGA chip through the SELECTMAP interface. The refresh control chip uses the master mode of SELECTMAP, and the SRAM-based one uses the slave mode. The data bit width of the SELECTMAP interface can reach up to 32 bits at most, and it supports the transmission and loading of files in formats such as.bit,.rbt,.bin,.mcs, and.hex.
[0019] In a specific embodiment, the data bit width of the SELECTMAP interface can reach up to 32 bits at most, enabling a higher data transmission rate. When dynamically refreshing the SRAM-based FPGA chip, a large amount of refresh data and control instructions can be quickly transmitted. Compared with interfaces with a lower data bit width, the refresh operation time can be greatly shortened, the refresh efficiency can be improved, and thus data that may undergo single-event upsets can be updated and corrected more promptly, reducing the risk of data error accumulation caused by single-event upsets and the likelihood of software operation errors and hardware circuit damage. At the same time, it supports the transmission and loading of files in multiple formats such as.bit,.rbt,.bin,.mcs, and.hex, and the refresh control chip can flexibly process different types of program data files. During the development and operation of spaceborne devices, various sources and forms of program data may be involved. The multi-format support can ensure the compatibility of the refresh control chip with various data formats, eliminating the need for complex data format conversions, improving the versatility and adaptability of the system, and helping to better solve the abnormal problems that may occur with FPGA program data in spaceborne devices. The antifuse FPGA chip, as the refresh control chip, is set to the master mode, and the SRAM-based FPGA chip is in the slave mode. This master-slave mode can achieve precise control of the refresh process. The refresh control chip can send refresh instructions and data to the SRAM-based FPGA chip methodically according to preset rules and frequencies, ensuring the orderly progress of the dynamic refresh operation. Through the SELECTMAP interface, the master chip can precisely control the refresh timing and content of the slave chip, avoiding data conflicts or errors during the refresh process, effectively improving the single-event upset resistance ability, and ensuring the stable operation of the spaceborne device. Using the SELECTMAP interface for dynamic refresh can monitor and update the data in the SRAM-based FPGA chip in real time. In the radiation environment where spaceborne devices are located, single-event upsets may occur at any time. Dynamic refresh can promptly detect and correct data bit changes caused by single-event upsets, keeping the data in the FPGA chip in the correct state at all times, preventing the impact of incorrect data on the operation of spaceborne devices, and thus solving the problem of abnormal program operation and calculation errors in the FPGA due to single-event upsets in the background technology.
[0020] In one embodiment, the antifuse FPGA chip is connected to the SRAM-based FPGA chip, and the three FLASH chips are connected to the antifuse FPGA chip.
[0021] In one embodiment, the antifuse FPGA chip is connected to the SRAM-based FPGA chip through pins PROG, INIT_B, RDWR_B, CSI, CCLK, DATA[15:0], and DONE; the FLASH chip is connected to the antifuse FPGA chip through pins ADDR[25:0], DATA[15:0], #OE, #CE, and #WE.
[0022] In one embodiment, each of the three FLASH chips stores data starting from the base address, and the storage area of the FLASH is divided into two parts: one part is the program data storage area, and the other part is the check data storage area.
[0023] In one embodiment, after receiving the program data, the antifuse FPGA chip stores three identical copies of the program data in the three FLASH chips respectively and simultaneously, and stores the verified CRC data in the check data storage area as a backup. When the FLASH chip performs a read-back data verification, it compares the check data with the stored program data. If the data is consistent, it is normal.
[0024] In a specific embodiment, as Figure 2 shown, the figure contains three FLASH chips, and each chip stores data starting from the base address. The storage area of the FLASH is divided into two parts: one part is the storage area for program data, and the other part is the storage area for check data. When the refresh chip receives the program data, it stores three identical copies of the data in the three FLASH chips respectively and simultaneously, and stores the verified CRC data in the check data storage area as a backup. When the FLASH chip performs a read-back data verification, it compares the verified data with the stored data. If the data is consistent, it is normal. Each FLASH chip stores data starting from the base address, providing a stable and independent storage space for the program data. Since there are three FLASH chips, even if one of the FLASH chips has an error in the program data due to single-event upset or other reasons in a radiation environment, the program data in the other two FLASH chips can be used for comparison and correction. Through a two-out-of-three voting method, error data can be effectively identified, ensuring that the correct program data is obtained for the configuration and refresh of the SRAM-based FPGA chip, and reducing the risk of abnormal program data caused by single-event upset.
[0025] The verification data storage area is used to store verification data corresponding to program data. Verification algorithms such as checksum and cyclic redundancy check (CRC) can be used to generate the verification data. When reading the program data, the corresponding verification data is read simultaneously for verification, which can quickly detect whether the program data has errors during storage or transmission. If data errors are found during verification, an operation to obtain correct data from other FLASH chips can be triggered in a timely manner, further improving the accuracy and integrity of the data, and ensuring the correctness of the program data loaded into the SRAM-based FPGA chip.
[0026] After the storage area is partitioned, it is convenient to manage and monitor each storage area separately. When an abnormality occurs in the program data storage area or the verification data storage area of a certain FLASH chip, the faulty chip can be quickly determined through the verification mechanism and the voting mechanism, and it can be isolated to avoid further impact of the error data on the system. At the same time, the system can continue to operate relying on other normal FLASH chips, ensuring that the basic functions of the spaceborne equipment are not affected, and improving the reliability and fault tolerance of the system.
[0027] In one embodiment, as Figure 3 shown, a method for realizing single event upset resistance of a spaceborne device based on FPGA is provided, including: Step 1: The ground console sends a program uploading instruction to the spaceborne device of the satellite in the space orbit; Step 2: After receiving the instruction, the spaceborne device parses it and transmits the parsed control instruction to the anti-fuse FPGA chip. The anti-fuse FPGA chip sends an erase command for the corresponding sector address to the three FLASH chips simultaneously, waits to read the FLASH status information, and after the erasure is completed, the anti-fuse FPGA chip sends an instruction indicating that the uploading function is ready externally. The spaceborne device packets the ready instruction and sends it back to the ground console; Step 3: After receiving the instruction indicating that the uploading function of the spaceborne device is ready, the ground console starts to transmit the program file to the satellite for the uploading operation; Step 4: After parsing the program file, the spaceborne device transmits the obtained program data to the anti-fuse FPGA chip. The anti-fuse FPGA chip performs CRC and IDCODE verification on the program data, and at the same time writes the program data into the three FLASH chips. During the data writing process of the three FLASH chips, the stored data is read synchronously for comparison of the read and written data to ensure the correctness of the stored data; Step 5: If the CRC and IDCODE verification of the uploaded program by the anti-fuse FPGA chip is correct, and the data read by each FLASH chip is verified normally, the data starts to be refreshed through the refresh chip. If the verification data is incorrect, the spaceborne device starts to send a program data retransmission instruction to the ground console until the verification of the uploaded program data is successful; Step 6: After the satellite successfully completes the program uploading operation, the antifuse FPGA chip periodically checks whether there is new program upload data for the on-board equipment. If there is new program upload data, repeat Steps 1 to 6. When there is new program data being uploaded, the antifuse FPGA chip pulls down the PROG pin connected to the signal processing FPGA according to the timing requirements during the refresh process to initialize the signal processing FPGA. When there is no new program data uploaded from the ground control station, the antifuse FPGA chip reads the program data from the three FLASH chips at regular intervals according to the timer, performs a two-out-of-three vote, and refreshes the voted program into the signal processing FPGA at regular intervals. This refresh process does not pull down the PROG pin between the refresh chip and the signal processing FPGA to prevent the loss of intermediate states.
[0028] In a specific embodiment, in Step 4, the antifuse FPGA chip performs CRC (Cyclic Redundancy Check) and IDCODE check on the program data. CRC check can detect whether errors have occurred in the data during transmission, and IDCODE check helps to ensure the integrity and correctness of the program data. In the space radiation environment, effects such as single-event upsets may cause data transmission errors. Through these two check methods, anomalies in the program data can be detected in a timely manner. During the data writing process of the three FLASH chips, the stored data is read and checked simultaneously to ensure the correctness of the stored data, further enhancing the reliability of the data. Because even if the data is interfered with when being written into the FLASH chip, problems can be found through the read check.
[0029] In Step 5, if the CRC and IDCODE checks of the program uploaded by the antifuse FPGA chip are incorrect, or the data checks read from each FLASH chip are abnormal, the on-board equipment will send a program data retransmission instruction to the ground console, so that when it is detected that there are problems with the program data, the ground console can be required to retransmit the data in a timely manner, avoiding abnormal operation of the on-board equipment caused by using incorrect program data. The on-board equipment will continuously request the ground console to retransmit the program data until the uploaded program data passes the check successfully. This continuous check and retransmission mechanism ensures that the program data finally loaded into the on-board equipment is correct and error-free, providing a solid guarantee for the normal operation of the on-board equipment.
[0030] In step six, when new program data is uploaded, during the refresh process, the antifuse FPGA chip will pull down the PROG pin connected to the signal processing FPGA according to the timing requirements to initialize the signal processing FPGA, ensuring that the new program data can be correctly loaded and run, and avoiding interference from old program data or intermediate states to the new program. When there is no new program data uploaded from the ground control station, the antifuse FPGA chip will read program data from the three FLASH chips according to the timer timing for two-out-of-three voting, and refresh the voted program into the signal processing FPGA at regular intervals. Moreover, during this refresh process, the PROG pin is not pulled down to prevent the loss of intermediate states. The regular refresh mechanism can timely correct program data errors caused by single-event upsets and other reasons, while avoiding the impact of unnecessary initialization operations on the device operating state, ensuring the stable operation of the spaceborne equipment.
[0031] From step one to step three, instruction interactions occur between the ground console and the spaceborne equipment. After receiving the program upload instruction, the spaceborne equipment parses it and gets ready to receive program data. The antifuse FPGA chip will send an erase command to the three FLASH chips to ensure that the FLASH chips have enough space to store the new program data, laying a foundation for subsequent program upload and operation. Steps four and five complete the process of program data transmission, verification, and storage. The ground console transmits the program file to the satellite, and the spaceborne equipment transmits the program data to the antifuse FPGA chip for verification and synchronously writes the program data into the three FLASH chips. Through a strict verification and storage mechanism, the accuracy and reliability of the program data are guaranteed. The regular detection mechanism in step six enables the spaceborne equipment to timely detect the need for new program upload and repeat the entire program upload process. This continuous monitoring and updating capability ensure that the program of the spaceborne equipment can be updated in a timely manner according to needs to adapt to different mission requirements and space environment changes.
[0032] In a specific embodiment, as Figure 4 shown, it is a data flow control diagram, which describes functions such as the upload, verification, and refresh of the satellite program. The following is the description of steps S301 to S306: Step S301, the spaceborne equipment receives the upload instruction from the ground console; Step S302, the program refresh chip receives the upload instruction and controls the FLASH to be erased; Step S303, the console waits for the spaceborne equipment to be ready and starts transmitting program data, and the refresh chip starts verifying the data; Step S304, if the data verification is successful, the data is written into the FLASH, if the data verification fails, an instruction is sent to the console for program retransmission; Step S305, after the upload is completed, it starts to detect whether there is a new upload program at the front end. If there is, repeat S301~S304. If not, continue to the next operation; Step S306, the refresh chip regularly refreshes the data in the FLASH into the signal processing FPGA.
[0033] like Figure 5 As shown in the figure, it is a flow chart of the timing refresh signal processing FPGA program. According to steps S4001 to S4006 in the figure, the timing refresh signal processing FPGA program flow is implemented. The implementation steps are as follows: Step S4001: The refresh control chip generates a timing refresh signal; Step S4002: After the refresh control chip control module receives the timing refresh instruction, it starts to read the program data from the three FLASHs; Step S4003: The three FLASHs output the program data respectively; Step S4004: Compare and vote on the data read from the three FLASHs; Step S4005: Transmit the data with the correct vote to the SELECTMAP timing control module for program refresh; Step S4006: After the program is refreshed successfully, continue to detect the timing signal and repeat steps S4001~S4005.
[0034] It should be understood that although Figure 1 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0035] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0036] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention. It should be pointed out that, for a person of ordinary skill in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A single event upset resistant system for on-board equipment based on FPGA, characterized in that The system includes an antifuse FPGA chip, a SRAM-based FPGA chip, and three FLASH chips; The antifuse FPGA chip serves as the carrier for solidifying the refresh control program of the refresh control chip, and is used to implement the program refresh of the SRAM FPGA chip; The SRAM-based FPGA chip is used to complete signal processing; The three FLASH chips are used to solidify three identical SRAM FPGA programs; After the device is normally powered on, the antifuse FPGA chip reads the backup programs from the three FLASH chips respectively and compares the three backup programs. When at least two kinds of data are found to be consistent, voting starts, and the same data is written into the SRAM-based FPGA chip to complete the configuration of the FPGA chip, and at the same time, the FPGA chip is refreshed regularly.
2. The system according to claim 1, wherein The antifuse FPGA chip, as the refresh control chip, performs dynamic refresh on the SRAM-based FPGA chip through the SELECTMAP interface. The refresh control chip uses the master mode of SELECTMAP, and the SRAM-based FPGA chip uses the slave mode; the data bit width of the SELECTMAP interface is up to 32 bits at most, and supports the transmission and loading of files in the formats of.bit,.rbt,.bin,.mcs,.hex.
3. The system according to claim 1, characterized in that, The antifuse FPGA chip is connected to the SRAM-based FPGA chip, and the three FLASH chips are connected to the antifuse FPGA chip.
4. The system according to claim 3, characterized in that, The antifuse FPGA chip and the SRAM-based FPGA chip are connected through the PROG, INIT_B, RDWR_B, CSI, CCLK, DATA[15:0], DONE pins; the FLASH chip and the antifuse FPGA chip are connected through the ADDR[25:0], DATA[15:0], #OE, #CE, #WE pins.
5. The system according to claim 1, wherein Each of the three FLASH chips stores data starting from the base address, and the storage area of the FLASH is divided into two parts: one part is the program data storage area, and the other part is the check data storage area.
6. The system according to claim 5, characterized in that After receiving the program data, the antifuse FPGA chip stores the three identical program data in the three FLASH chips respectively, and stores the CRC data for verification in the check data storage area as a backup. When the FLASH chip performs the read-back data verification, the check data is compared with the stored program data, and if the data is consistent, it is normal.
7. A method for implementing a single event upset resistant system for on-board equipment based on FPGA according to any one of claims 1 to 6, characterized in that, The method includes: Step 1: The ground console sends a program uploading instruction to the satellite on-board equipment in the space orbit; Step 2: After receiving the instruction, the on-board equipment parses it, transmits the parsed control instruction to the antifuse FPGA chip, and the antifuse FPGA chip sends the erase command of the corresponding sector address to the three FLASH chips simultaneously, waits to read the FLASH status information. After the erasure is completed, the antifuse FPGA chip sends out an instruction indicating that the uploading function is ready, and the on-board equipment packages the ready instruction and sends it back to the ground console; Step 3: After receiving the instruction that the uploading function of the on-board equipment is ready, the ground console starts to transmit the program file to the satellite for uploading operation; Step 4: After parsing the program file, the on-board equipment transmits the obtained program data to the anti-fuse FPGA chip. The anti-fuse FPGA chip performs CRC and IDCODE checks on the program data, and at the same time writes the program data into three FLASH chips. During the data writing process of the three FLASH chips, the stored data is synchronously read for comparison of read and write data to ensure the correctness of the stored data; Step 5: If the CRC and IDCODE checks of the anti-fuse FPGA chip's uploaded program are correct and the data read by each FLASH chip passes the check, the data starts to be refreshed through the refresh chip. If the check data is incorrect, the on-board equipment starts to send an instruction to the ground console to retransmit the program data until the uploaded program data passes the check successfully; Step 6: After the satellite successfully completes the program uploading operation, the anti-fuse FPGA chip periodically checks whether there is new uploaded program data in the on-board equipment. If there is new uploaded program data, steps 1 to 6 are repeated. When there is new program data being uploaded, the anti-fuse FPGA chip pulls down the PROG pin connected to the signal processing FPGA according to the timing requirements during the refresh to initialize the signal processing FPGA. When there is no new program data uploaded by the ground control station, the anti-fuse FPGA chip reads the program data from the three FLASH chips for two-out-of-three voting according to the timer, and refreshes the voted program to the signal processing FPGA regularly. During this refresh process, the PROG pin between the refresh chip and the signal processing FPGA is not pulled down to prevent loss of intermediate states.
Citation Information
Patent Citations
Method and system for monitoring single event upset effect of FPGA (field programmable gate array) and correcting reloading
CN103971732A
Implementation method of satellite-borne multi-FPGA configuration refreshing technology and satellite-borne processor
CN116644023A
Implementation system and method for improving single event upset protection capability based on FPGA
CN118708401A
Cited By
Satellite routing transponder based on FPGA self-refreshing
CN121603088A
FPGA program memory cold standby circuit and program programming method
CN122220158A
Spaceborne digital processing device and method capable of resisting single event upset
CN122387740A