Dual-computer hot standby fault-tolerant system and task synchronization method of micro-nano satellite on-board computer

By designing a dual-machine hot standby fault tolerance system for micro-nano satellites, using heartbeat signal monitoring and USART serial interface to achieve task synchronization and switching, the reliability of micro-nano satellites in high-radiation environments is solved, the reliability and life of the task is improved, and the seamless switching of dual-machines and high-real-time task processing is realized.

CN120216263APending Publication Date: 2025-06-27NANJING UNIV OF SCI & TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510231357.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Micro-nano satellite-borne computers are prone to single-particle radiation effects in high-radiation environments, resulting in device damage and unreliable tasks. Traditional multi-mode redundancy solutions are costly and not universal, and lack dual-machine hot standby task synchronization methods suitable for Freertos operating systems.

Method used

A dual-machine hot standby fault-tolerant system for micro-nano satellite satellite computers is designed, and two identical satellite computers are used as main and backup machines. Task synchronization and switching are achieved through heartbeat signal monitoring and USART serial interfaces to realize dual-machine task synchronization under the Freertos operating system.

Benefits of technology

It significantly improves the reliability and life of micro-nano satellites in orbit missions, reduces the task delay in dual-machine hot standby situations, and realizes seamless switching between dual-machines and high real-time task processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120216263A_ABST
    Figure CN120216263A_ABST
Patent Text Reader

Abstract

The invention discloses a micro / nano satellite on-board computer dual-computer hot standby fault-tolerant system and a task synchronization method, two same processors are adopted on a single board to serve as a main processor and a standby processor, the processors are LCSoC3233 based on SPARC V8, the processor of the main computer serves as a main on-board processor to carry out on-board object control and data processing, and the processor of the standby computer serves as a main on-board processor to carry out on-board data processing. The processor of the standby machine is also used as a main satellite-borne processor to perform satellite-borne object control and data processing, meanwhile, data output is shielded, the processor of the standby machine is only used as a backup to improve the reliability of the satellite-borne processor, when the host fails, main and standby switching can be performed, and double machines perform data interaction through serial port communication, so that the state of dual-machine task synchronization is achieved; therefore, the on-satellite task process is not influenced during the main / standby switching. The function of maintaining the satellite-borne reliability is achieved through processor-level redundancy, and the problem that a current satellite-borne computing machine generates many faults when encountering the single event effect is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of satellites, and particularly relates to a dual-computer hot standby fault-tolerant system and task synchronization method for a micro-nano satellite on-board computer. Background Art

[0002] Since the late 1980s, micro-nano satellites have become the focus of attention internationally. Due to their low cost and fast speed, and the ability to achieve tasks that large satellites cannot do through satellite networking, multiple satellites in one launch, etc., they have been widely used in important fields such as scientific research, observation, and military. The main function of micro-nano satellites is to achieve specific space on-orbit tasks. With the increasing complexity of micro-nano satellite space tasks and the rise of space on-orbit service technologies, the spacecraft on-orbit operation and service technology has developed rapidly. On-orbit operation and service refer to the on-orbit activities of spacecraft using the tools or devices carried by themselves in orbit space to perform actions or tasks on space targets, and the involved contents include research hotspots such as on-orbit service, active debris removal, formation cooperation, and deep space exploration. Traditional aerospace-grade devices cannot meet the existing space on-orbit service tasks due to their high prices and low computing power limits. Therefore, more and more commercial (COTS) components are used in micro-nano satellite on-board computers. At the same time, the space environment where the on-board computer is located is full of high-energy particle radiation. In this high-radiation environment, single-event radiation effects (SEE) will occur in electronic components, which will cause abnormal storage, data anomalies, logical judgment anomalies, etc. of the devices, and even damage. Due to the influence of space radiation, in order to complete and reliably implement these tasks, it is of great significance to improve the fault tolerance of micro-nano satellite on-board computers and the reliability and control continuity of space on-orbit services.

[0003] Referring to relevant materials, due to the cost and power consumption limitations of micro-nano satellites, traditional multi-mode redundancy will consume a large amount of power and cost, which is contrary to the design concept and is not universal, and is not conducive to the rapid development and production of micro-nano satellites. At the same time, there is a severe lack of relevant patents for on-board computer dual-computer hot standby task synchronization under the Freertos operating system in China. Summary of the Invention

[0004] The present invention proposes a dual-computer hot standby fault-tolerant system and task synchronization method for a micro-nano satellite on-board computer, aiming to solve the reliability problems of existing on-board computers, as well as the task synchronization, task recovery, and dual-computer switching problems in dual-computer hot standby technology, and to achieve dual-computer task synchronization based on the Freertos operating system.

[0005] The technical solution for realizing the present invention is: a dual-computer hot standby fault-tolerant system for a micro-nano satellite on-board computer, which uses two completely identical on-board computers as the primary and standby computers, and is characterized in that: it includes a clock module, a storage module, and other payload modules.

[0006] The processor of the host performs on-board service control and data processing, and sends a heartbeat signal to the processor of the standby machine through ordinary GPIO pins; the TX of the USART serial interface of the host's processor is connected to the RX of the USART serial interface of the standby machine's processor, and the RX of the USART serial interface of the host's processor is connected to the TX of the USART serial interface of the standby machine's processor. The processor of the standby machine is used to back up the task functions of the processor of the host to achieve the purpose of improving reliability. It monitors the heartbeat signal of the processor of the host through an interrupt, performs power transfer processing through the main-standby switching method when detecting a failure of the processor of the host, and transmits the on-board task synchronization data of the processor of the host through the USART serial interface. The storage module is used to store on-board data and data that needs to be synchronized, and the clock module is used to provide the clocks of the main and standby processors.

[0007] A task synchronization method for a dual-redundancy fault-tolerant system of an on-board computer of a micro-nano satellite includes the following steps:

[0008] Step 1: The host and the standby machine are powered on simultaneously. The host creates an on-board task and creates a high-priority synchronization task before the core task. The synchronization task is mainly responsible for information synchronization, and the absolute delay period is 10 ms; the priority of each synchronization task is higher than that of the corresponding core task. The absolute delay period of the core task is 40 ms, and after the synchronization task runs to completion, it releases a semaphore. The core task executes only after receiving the semaphore released by the corresponding synchronization task, ensuring that the synchronization task runs first and the synchronization task and the core task are executed synchronously.

[0009] Step 2: The host runs the on-board task and stores the on-board status, and periodically sends a heartbeat signal to the standby machine to indicate that it is in a healthy state; the standby machine runs the on-board task and stores the on-board status, and periodically sends a heartbeat signal to the host to indicate that it is in a healthy state; if the host does not send a heartbeat signal within the period, then perform main-standby power transfer, the host is transferred to the standby machine, and the standby machine is transferred to the host, and enter Step 3; if the heartbeat is normal, then enter Step 4.

[0010] Step 3: The host sends a low-level signal to the NRST pin of the standby machine to reset and restart the standby machine; when the main-standby power transfer occurs and the standby machine restarts, all task data needs to be synchronized to the standby machine, and then enter Step 4.

[0011] Step 4: The host sends a synchronization confirmation message to the standby machine through the USART interface through the synchronization task, and waits for the standby machine's synchronization task to reply within 10 ms. If there is no reply, then it is not synchronized; enter Step 5; if there is a reply and the standby machine responds normally, then the two machines are synchronized and enter Step 6.

[0012] Step 5: If not synchronized, the host synchronization task will notify the core task of the unsynchronization. After receiving the unsynchronization notice, the host core task determines whether the standby machine has been restarted before synchronization. If it has been restarted, go to Step 7; otherwise, go to Step 8.

[0013] Step 6: The primary and standby machines enter the next core task after synchronization.

[0014] Step 7: If the standby machine has been restarted before synchronization communication, the host compares all current data units with the initial values of all data units, packs the inconsistent data of each data unit, and sends it to the standby machine.

[0015] Step 8: If the standby machine has not been restarted during the unsynchronization period, the host compares all current data units with the inconsistent data units during synchronization, packs the data, and sends it to the standby machine.

[0016] Compared with the prior art, the remarkable advantages of the present invention are as follows:

[0017] (1) The present invention uses commercial off-the-shelf devices (COTS), which can greatly reduce the satellite development cost. At the same time, the commercial off-the-shelf devices are mature and reliable, with stronger computing power and lower power consumption compared to radiation-hardened devices.

[0018] (2) The primary and standby machines of the system of the present invention are mutually hot standby, that is, both the host and the standby machine are running normally, and the operation results of the standby machine are not output. The two machines monitor each other's heartbeats. When the heartbeat signal of the other machine is abnormal, that is, when the host or the standby machine fails, the primary and standby machines are immediately switched, and the faulty machine is switched to the standby machine for restart and recovery, which can significantly improve the reliability and lifespan of the micro-nano satellite in-orbit mission.

[0019] (3) The micro-nano satellite dual-machine hot standby task synchronization method of the present invention can greatly reduce the delay of the task running steps of the two machines after the primary and standby switching in the case of dual-machine hot standby of the micro-nano satellite, realize seamless switching of the two machines, make the paces of the two machines basically the same, and achieve high-real-time task processing in orbit. Description of the Drawings

[0020] Figure 1 is the overall structure and information flow schematic diagram of the present invention.

[0021] Figure 2 is the task process diagram in the case of dual-machine task synchronization of the present invention.

[0022] Figure 3 is the on-board dual-machine task priority diagram of the present invention

[0023] Figure 4 is the schematic diagram of the core task structure and the checkpoint task synchronization frame structure in the present invention.

[0024] Figure 5It is the task process flow chart in the case of unsynchronized dual machines in the present invention.

[0025] Figure 6 It is the heart - beat monitoring flow chart of dual machines in the present invention.

[0026] Figure 7 It is the host synchronization process flow chart in the present invention.

[0027] Figure 8 It is the standby machine synchronization process flow chart in the present invention.

[0028] Figure 9 It is the task data synchronization flow chart after the host or standby machine restarts due to a fault in the present invention. Detailed implementation manners

[0029] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0030] Unless otherwise clearly defined and limited, terms such as "connection" and "fixation" shall be understood in a broad sense. For example, "fixation" can be a fixed connection, a detachable connection, or integrated; "connection" can be a mechanical connection or an electrical connection. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0031] In addition, the technical solutions between various embodiments of the present invention can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.

[0032] Next, the detailed implementation manners, as well as the technical difficulties and inventive points of the present invention, will be further introduced in combination with the design examples.

[0033] In order to improve the reliability of on-orbit services of micro-nano satellites, reduce the impact of space radiation on electronic devices, and solve problems such as low cost and low power consumption, rapid task switching in case of dual-machine failure, real-time synchronization of task data, and rapid recovery from faults. By studying and analyzing the advantages and disadvantages of various redundancy technologies, and combining the advantages and disadvantages of four redundancy technologies, a dual-active hot standby redundancy scheme is designed under the Freertos operating system. By achieving dual-machine synchronization at the task level between the two machines, accurate fault monitoring, and the performance requirements of rapid primary-backup switching, the design and development of a highly reliable on-board computer for micro-nano satellites are realized. The present invention proposes a dual-active hot standby redundancy system for an on-board computer of a micro-nano satellite and its task synchronization method.

[0034] A dual-active hot standby fault-tolerant system for an on-board computer of a micro-nano satellite uses two identical on-board computers as the primary and backup machines, and includes two identical primary and backup machine processors, a clock module, a communication interface module, an instruction output module, a storage module, an analog quantity acquisition module, and other payload modules.

[0035] The processors of the primary machine and the backup machine both adopt the LCSoC3233 processor based on SPARC V8. The transmission baud rate range of the USART serial interface for dual-machine communication should be between 1200 and 115200 bps.

[0036] The processor of the primary machine serves as the primary on-board processor to control on-board affairs and process data, and sends a heartbeat signal to the processor of the backup machine through ordinary GPIO pins; the connection relationship between the primary and backup machines is that the TX of the USART serial interface of the processor of the primary machine is connected to the RX of the USART serial interface of the processor of the backup machine, and the RX of the USART serial interface of the processor of the primary machine is connected to the TX of the USART serial interface of the processor of the backup machine. The processor of the backup machine is used to back up the task functions of the processor of the primary machine to achieve the purpose of improving reliability. By monitoring the heartbeat signal of the processor of the primary machine through an interrupt, when a fault occurs in the processor of the primary machine, the switching of power is processed through the primary-backup switching method, and the transmission of on-board task synchronization data of the processor of the primary machine is carried out through the USART serial interface. The storage module is used to store on-board data and data that needs to be synchronized. The clock module is used to provide the clock for the primary and backup machine processors. The instruction output module outputs OC instructions. The communication interface module is used for communication between the on-board computer and other subsystems of the micro-nano satellite. The analog quantity acquisition module performs external analog quantity acquisition and internal voltage quantity acquisition of the on-board computer. The peripheral circuit of the processor of the primary machine includes a crystal oscillator clock circuit and a watchdog circuit. The information flow is that the processor of the primary machine forms serial communication with the core board of the processor of the backup machine through the core board of the processor of the primary machine to transmit heartbeat signals and dual-machine task synchronization information.

[0037] The task synchronization method of the dual - machine hot - standby fault - tolerant system for the on - board computer of a micro - nano satellite is described in detail below. The specific design includes using the Freertos operating system, task checkpoints, information interaction between the two machines, task synchronization, master - slave switching, etc.

[0038] Combined with Figure 1 , in terms of hardware, the two machines use the same processor chip, have symmetric external interfaces, and the same external devices. It includes using the same: clock module, storage module, communication interface module, instruction output module, and other payload modules. The master and slave machines are hot - standby for each other, that is, both the master machine and the slave machine are running normally, and the operation results of the slave machine are not output. When the master machine fails, the slave machine is immediately switched to the master machine for output, and the master machine is switched to the slave machine for fault recovery.

[0039] Combined with Figure 4 In terms of software, the tasks that need to be processed on the two machines in space are the same, and the task running order is the same; the tasks processed by the on - board software in space can be roughly divided into the following different types;

[0040] i. Real - time and delayed telecommand reception tasks

[0041] ii. Real - time and delayed telemetry acquisition tasks

[0042] iii. Temperature control tasks

[0043] iv. Solar panel control tasks

[0044] v. Antenna control tasks

[0045] vi. Power control tasks

[0046] vii. TT&C single - machine control tasks

[0047] viii. Orbit control tasks

[0048] ix. Attitude control tasks

[0049] x. Other payload control tasks

[0050] According to the above - mentioned hardware and software design situations to achieve dual - machine hot - standby, the present invention provides a task synchronization method for the dual - machine hot - standby fault - tolerant system of the on - board computer of a micro - nano satellite, and the steps are as follows:

[0051] Step 1: The master and slave machines respectively divide the on - board task data that needs to be hot - standby into several data structures according to the task types and task scales, and save the initial values in all data structures after startup. The absolute delay period of each core task of the master and slave machines is 40 ms.

[0052] When the master and slave machines create on - board tasks, a high - priority synchronization task is created before the core task, such as Figure 2, The synchronization task is mainly responsible for information synchronization, with an absolute delay period of 10 ms. The priority of each synchronization task is higher than that of the corresponding core task, and a semaphore is released after the synchronization task finishes running. The core task will execute only after receiving the semaphore released by the corresponding synchronization task, ensuring that the synchronization task runs first and the synchronization task and the core task are executed synchronously.

[0053] The master and standby tasks are created and the tasks are assigned different priorities in a certain order from high to low as Figure 3 , To ensure that the main core tasks run in a fixed order in a loop and create conditions for task synchronization. Each core task is created according to the Figure 4 structure shown, which are respectively task entry, task initialization, start of task loop, initialization of synchronization data frame, task running, end of loop, and end of task.

[0054] Step 2: The host and the standby are powered on simultaneously as Figure 6 , The host performs on-orbit task operation and on-orbit status storage and periodically sends a heartbeat signal to the processor of the standby to indicate that it is in a healthy state; the standby performs on-orbit task operation and on-orbit status storage and periodically sends a heartbeat signal to the host to indicate that it is in a healthy state; if the host does not send a heartbeat signal within the period, the master-slave power transfer is performed, the host's power is transferred to the standby, and the standby's power is transferred to the host, and it enters Step 3; if the heartbeat is normal, it enters Step 4.

[0055] Step 3: After the master-slave power transfer, the standby is restarted. During the restart process, a low-level signal is sent to the NRST pin of the standby's processor through the host's processor to reset and restart the standby's processor; then it enters Step 4.

[0056] Step 4: The process of dual-machine task synchronization is as Figure 5 and Figure 7 The process is as follows: The host synchronization task sends a synchronization confirmation message to the standby, including the next core task number, and requests a reply on whether it is synchronized. Set a 10 ms time to wait for the standby to reply. If the standby does not reply after the timeout, the host determines that it is not synchronized and enters Step 5; if there is a reply and the standby responds normally, the dual-machine synchronization enters Step 6.

[0057] Step 5: If it is not synchronized, the host synchronization task will notify the core task that it is not synchronized. After receiving the unsynchronized notification, the host core task sends a synchronization information data packet to the standby at regular intervals through the checkpoint.

[0058] The standby receives the synchronization confirmation information request from the host through the synchronization task. If it does not receive it within 10 ms, it determines that it is not synchronized.

[0059] The standby core task runs normally. If the standby core task receives a synchronization confirmation message from the host synchronization task and generates an interruption, as Figure 5 and Figure 8After the standby machine parses the current running task number sent by the host for synchronization tasks, it sends data to the host to inform the current deletion task number. At the same time, it immediately performs task scheduling, deletes the current task, then inserts the tasks to be synchronized into the task ready list, runs the synchronization task, and then re-creates the deleted tasks again. And when running again, it receives the synchronization data from the host for data recovery.

[0060] If the reply message from the standby machine is in the synchronized state, the host saves the current values of all data structures. If the reply message from the standby machine is in the out-of-sync state, the host parses the feedback data from the standby machine to know which task data needs to be synchronized, marks these tasks, and sends the data units that are inconsistent with the standby machine data for data synchronization during runtime.

[0061] If the reply message from the standby machine is in the out-of-sync state, it is necessary to determine whether the standby machine has been restarted before synchronization. If it has been restarted, go to Step Seven; otherwise, go to Step Eight.

[0062] Step Six: The master and standby machines synchronize to enter the next core task.

[0063] Step Seven: If the standby machine is in the out-of-sync state, the standby machine performs the first synchronization communication and has been restarted during the out-of-sync period, such as Figure 9 , then the host compares all current data units with the initial values of all data units, groups the data with inconsistent data units, and sends it to the standby machine.

[0064] Step Eight: If the standby machine has not been restarted during the out-of-sync period, the host compares all current data units with the data units that are inconsistent during synchronization, groups the data, and sends it to the standby machine.

Claims

1. A dual hot standby fault-tolerant system for micro-nano satellite onboard computers, using two identical onboard computers as the main and standby computers, characterized in that: Including clock module, storage module and other load modules; The processor of the host performs on-board transaction control and data processing, and sends a heartbeat signal to the processor of the standby machine through a common GPIO pin; the TX of the USART serial interface of the processor of the host is connected to the RX of the USART serial interface of the processor of the standby machine, and the RX of the USART serial interface of the processor of the host is connected to the TX of the USART serial interface of the processor of the standby machine. The processor of the standby machine is used to back up the task function of the processor of the host to achieve the purpose of improving reliability, monitor the heartbeat signal of the processor of the host through interruption, and perform power-off processing through the main-standby switching mode when a fault of the processor of the host is detected, and transmit the on-board task synchronization data of the processor of the host through the USART serial interface, the storage module is used to store on-board data and data that needs to be synchronized, and the clock module is used to provide the clock of the main and standby processors.

2. The dual-computer hot standby fault-tolerant system for micro-nano satellite onboard computers according to claim 1 is characterized in that: It also includes an instruction output module connected to the main and standby processors, and the instruction output module performs OC instruction output.

3. The dual-machine hot standby fault-tolerant system for micro-nano satellite onboard computers according to claim 2 is characterized in that: It also includes a communication interface module connected to the main and standby processors, and the communication interface module is used for communication between the onboard computer and other subsystems of the micro-nano satellite.

4. The dual-computer hot standby fault-tolerant system for micro-nano satellite onboard computers according to claim 3 is characterized in that: It also includes an analog quantity acquisition module connected to the main and standby processors, and the analog quantity acquisition module performs external analog quantity acquisition and internal voltage quantity acquisition of the satellite service computer.

5. The dual-machine hot standby fault-tolerant system for micro-nano satellite onboard computers according to claim 4 is characterized in that: The processors of the host and the backup machine are both LCSoC3233 processors based on SPARC V8.

6. The dual hot standby fault-tolerant system for micro-nano satellite onboard computers according to claim 5 is characterized in that: The USART serial interface transmission baud rate range should be between 1200 and 115200 bps.

7. The dual-computer hot standby fault-tolerant system for micro-nano satellite onboard computers according to claim 6 is characterized in that: The peripheral circuits of the main and standby processors include a crystal oscillator clock circuit and a watchdog circuit. The host processor forms a serial communication by connecting the host processor core board and the standby processor core board to transmit heartbeat signals and dual-machine task synchronization information to each other.

8. The task synchronization method of the dual hot standby fault-tolerant system of micro-nano satellite onboard computers according to any one of claims 1 to 7, characterized in that: The following steps are involved: Step 1: The host and the standby are powered on at the same time. The host creates an onboard task and creates a high-priority synchronization task before the core task. The synchronization task is mainly responsible for information synchronization, and the absolute delay period is 10ms. Each synchronization task has a higher priority than the corresponding core task, and the absolute delay period of the core task is 40ms. After the synchronization task is completed, the semaphore is released. The core task is executed only after receiving the semaphore released by the corresponding synchronization task, ensuring that the synchronization task runs first and the synchronization task and the core task are executed synchronously. Step 2: The host performs on-board missions and on-board status storage and periodically sends a heartbeat signal to the standby machine to indicate that it is in a healthy state; the standby machine performs on-board missions and on-board status storage and periodically sends a heartbeat signal to the host machine to indicate that it is in a healthy state; if the host machine does not send a heartbeat signal within the period, the master-standby switch is performed, the master machine switches to the standby machine, and the standby machine switches to the master machine, and then proceeds to step 3; If the heartbeat is normal, proceed to step 4; Step 3: The host sends a low-level signal to the NRST pin of the standby machine to reset and restart the standby machine. When the master and standby machines are switched and the standby machine is restarted, all task data needs to be synchronized with the standby machine and then proceed to step 4. Step 4: The host sends synchronization confirmation information to the standby machine through the USART interface through the synchronization task, and waits for the standby machine's synchronization task reply within 10ms. If there is no reply, it will not be synchronized; go to step 5; if there is a reply and the standby machine responds normally, the dual-machine synchronization will go to step 6; Step 5: If not synchronized, the host synchronization task will notify the core task of not synchronizing. After the host core task receives the not synchronizing notification, the host determines whether the standby machine has been restarted before synchronization. If it has been restarted, it proceeds to step 7, otherwise it proceeds to step 8. Step 6: The master and standby machines synchronously enter the next core task; Step 7: If the standby machine has been restarted before synchronous communication, the host compares all current data units with the initial values ​​of all data units, groups the inconsistent data of each data unit into data packets, and sends them to the standby machine; Step 8: If the standby machine has not been restarted during the period of being out of sync, the host compares all current data units with all inconsistent data units during synchronization, packages the data, and sends it to the standby machine.

Citation Information

Cited By

  • Servo controller for low-orbit constellation feed antenna

    CN122052890A