Power-down-safe Flash parameter two-out-of-three storage method
By building storage structures and free sector tables in the spacecraft Flash storage system, three-mode redundant operation and backup writing are realized, which solves the problems of power failure safety and wear balance, and improves the system's reliability and storage efficiency.
Patent Information
- Application Number
- CN202510384646.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2025-07-18
AI Technical Summary
The existing spacecraft Flash storage system is difficult to achieve power-down safety protection and three-mode redundancy protection, and the storage space occupies a large amount of time, which cannot effectively solve the problem of wear balance.
Using a design that separates the underlying Flash operations from the upper user program, three-mode redundant operations are realized by building a storage structure and an idle sector table, and backup content is written to the other two locations when writing data. The sector is selected using sliding windows and mutually different random number algorithms, and the Flash read cache area is built to optimize data reading and writing.
It realizes data security in power outage, extends the service life of Flash, reduces storage space, and improves the reliability and radiation resistance of the system.
Smart Images

Figure CN120335718A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for storing Flash parameters by taking two out of three for power-off safety, belonging to the technical field of hardware design. Background Art
[0002] In spacecraft software, the problems that need to be solved for FLASH file storage generally include the following:
[0003] Problem 1: Power-off safety. The power-off reliability of a file system refers to the ability of the file system to correctly recover and maintain the integrity and consistency of data in the event of an unexpected power-off or unstable power supply. Power-off safety is a very important aspect in the design of a file system because the file system needs to be able to cope with unexpected situations such as power-off to avoid data corruption or loss.
[0004] Problem 2: Wear leveling. In FLASH, each erase and write operation (erasing data from a sector in the storage medium and writing new data) will affect the physical grid and gradually reduce its reliability and lifespan. Since some sectors may be written frequently, this effect gradually expands, and eventually these sectors may fail earlier, resulting in data loss or inaccessibility.
[0005] Problem 3: Due to the operating environment of spacecraft software, it is necessary to perform triple modular redundancy reinforcement on the code in the software to achieve single event upset resistance and improve the reliability of on-orbit operation, while the conventional FLASH file storage method has not achieved this work.
[0006] Problem 4: The storage space resources in a spacecraft are very tight. If the relevant storage management system occupies a large amount of space, then the space left for application programs will be very small.
[0007] In existing FLASH file systems such as FAT and EXT2, the storage space is directly divided into several sectors, so the occupied space is extremely small, but at the same time, the power-off safety protection and wear leveling ability are lost. Conventional log file systems such as JFFS and YAFFS perform each change to the FLASH by appending a new log, and traversing the log is required to reconstruct the file during reading. This design effectively solves the power-off safety, and at the same time, the characteristic of log cycling can evenly distribute the FLASH wear to the storage, ensuring wear leveling. However, the price is sacrificing system performance. File systems based on sectors and bounded logs such as NTFS have better running speed and power-off safety, but the system scale is large, occupying more storage space, and due to the strong correlation between the storage location and data, it is impossible to guarantee FLASH wear leveling.
[0008] The traditional FLASH storage method cannot solve the above four problems well. The FLASH file storage method proposed in this paper ensures power-off safety through logging and transaction technologies, buffer management, verification, and data integrity protection measures. At the same time, it ensures the physical wear leveling of FLASH and extends the service life of FLASH through appropriate sector selection strategies, sector erasure operations, sector remapping, etc. Summary of the Invention
[0009] The technical problem to be solved by the present invention is: to overcome the deficiencies of the prior art and provide a two-out-of-three Flash parameter storage method with power-off safety, aiming to solve the problems that it is difficult to achieve power-off safety protection and triple modular redundancy protection in the spacecraft Flash storage system in the prior art.
[0010] The technical solution of the present invention is:
[0011] The present invention discloses a power-off safe Flash storage method, including:
[0012] Constructing a storage structure; the storage structure includes a number of data pairs; a data pair includes a number of key-value pairs and their corresponding contents, and the data pairs are linked by pointers; each data pair is mapped to one or more physical Flash sectors;
[0013] Constructing a Flash free sector table;
[0014] When writing data to a Flash sector, it is judged whether the data length of the written data is less than the size of the Flash sector corresponding to the target storage structure. If so, a new key-value pair and corresponding data are written in the corresponding storage structure; otherwise, a free Flash sector is selected from the Flash free sector table for data storage; when the data writing is completed, the same backup content is written to two other positions; when reading data, the data is read from three positions where the same content is written and a two-out-of-three verification is performed to obtain the read content.
[0015] Further, in the above method, the storage structure includes a header block, a root directory, directories, and files; where
[0016] The header block, root directory, directories, and files are all composed of one or more data pairs;
[0017] The header block serves as the starting position of the storage structure;
[0018] The first data pair of the root directory is linked to the last data pair of the header block by a pointer;
[0019] The last data pair of the root directory is linked to the first data pair of the directory by a pointer;
[0020] The first data pair of the file is linked by a pointer to the last data pair of its directory.
[0021] The directory includes a directory name key-value pair used to indicate that the type of this data pair is a directory.
[0022] The file includes a file flag key-value pair used to indicate that the type of this data pair is a file, and the stored content includes the sector where the file is located and the offset address within the sector.
[0023] Further, in the above method, when reading data from a Flash sector, according to the file name, starting from the first data pair of the file read, traverse the linked list formed by all file data pairs, determine the location of the target data by comparing the file name key in the key-value pair with the target file name, find the data pair node where the target data is located, and then find the corresponding physical Flash sector according to the data pair node to read the data.
[0024] Further, in the above method, construct a Flash read buffer to avoid frequently reading data directly from the Flash sector; if the data to be read is already in the Flash read buffer, directly read the data from the Flash read buffer; if it is not in the Flash read buffer and the data to be read is less than the maximum data volume of a single read operation, put the data into the Flash read buffer, otherwise directly read the data from the Flash sector to the target address; the capacity of the Flash read buffer can be dynamically adjusted according to system requirements.
[0025] Further, in the above method, the content of the key-value pair within each data pair includes the data pair storage data length, data pair type, data, and a pointer to the next data pair.
[0026] Further, in the above method, each physical Flash sector corresponds to a key-value pair used to record the number of change times of the physical Flash sector; whenever a physical Flash sector is erased or new data is written, the value of the corresponding key-value pair increases.
[0027] Further, in the above method, select an idle Flash sector from the Flash free sector table. Specifically, when using the sliding window method to select sectors, use the algorithm for generating distinct random numbers to select sectors in the free table; the sliding window method is used to sequentially scan the free sector table, and the algorithm for generating distinct random numbers ensures that the selected sectors are evenly distributed.
[0028] Further, in the above method, when performing a write operation, first find the write location; when inserting a new data pair node into the original data pair chain, first write the data into the new data pair node, and then update the pointer of the previous data pair to point to the newly created data pair and then to the subsequent data pair.
[0029] Further, in the above method, when reading a file or directory, according to the file or directory ID, traverse the directory data pairs to find the ID of the target file; find the relevant data in the corresponding data pair according to the ID of the target file.
[0030] Further, in the above method, when completing the file writing, according to the block allocation strategy, additionally write the same backup content to two other locations; the block allocation strategy can be dynamically adjusted according to system requirements to ensure that the backup content is distributed in different physical regions.
[0031] The beneficial effects of the present invention compared with the prior art are as follows:
[0032] (1) The present invention adopts the technical means of separating the underlying Flash operation from the upper-layer user program design, and realizes the triple modular redundancy operation directly at the underlying layer, solving the technical problem that software designers are prone to make errors when operating Flash.
[0033] (2) When writing data, the present invention first writes the data into a new data pair, and then inserts the new data pair into the data pair chain. It realizes the technical effect of only successfully writing data or not writing data, and solves the technical problem of power-off safety.
[0034] (3) The present invention uses an idle sector table to manage the unused sectors in Flash, and selects the used sectors in the way of a sliding window. At the same time, an algorithm for generating mutually different random numbers is used to generate the starting position of the sectors selected in the idle table, realizing the technical effect of uniform use times of each Flash sector, and solving the technical problem that the service life of Flash is reduced due to frequent use of individual sectors.
[0035] (4) The code quantity of the present invention is much less than that of other storage methods, realizing the technical effect of occupying less Flash and memory space, and solving the technical problem that other storage methods occupy more storage space.
[0036] (5) The present invention solves the power-off safety problem and anti-radiation problem in the existing Flash storage technology of spacecraft. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 is the storage structure diagram of the present invention;
[0038] Figure 2 is the schematic flow diagram of the write operation of the file in the present invention;
[0039] Figure 3 is the schematic diagram of the principle of the sliding window for sector allocation in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0040] The implementation of the present invention will be described in detail below with reference to specific drawings.
[0041] The present invention discloses a power-off safe Flash storage method, including:
[0042] Construct a storage structure; the storage structure includes a number of data pairs; a data pair includes a number of key-value pairs and their corresponding contents, and the data pairs are linked by pointers; each data pair is mapped to one or more physical Flash sectors;
[0043] Construct a Flash free sector table;
[0044] When writing data to a Flash sector, determine whether the length of the data to be written is less than the size of the Flash sector corresponding to the target storage structure. If so, write a new key-value pair and the corresponding data in the corresponding storage structure; otherwise, select a free Flash sector from the Flash free sector table for data storage; when the data writing is completed, additionally write the same backup content to two other positions; when reading data, read the data from the three positions where the same content is written and perform a two-out-of-three verification to obtain the read content.
[0045] Preferably, the storage structure includes a header block, a root directory, directories, and files; wherein,
[0046] The header block, root directory, directories, and files are all composed of one or more data pairs;
[0047] The header block serves as the starting position of the storage structure;
[0048] The first data pair of the root directory is linked to the last data pair of the header block by a pointer;
[0049] The last data pair of the root directory is linked to the first data pair of the directory by a pointer;
[0050] The first data pair of the file is linked to the last data pair of the directory where it is located by a pointer;
[0051] A directory includes a directory name key-value pair used to indicate that the type of this data pair is a directory;
[0052] A file includes a file flag key-value pair used to indicate that the type of this data pair is a file, and the stored content includes the sector where the file is located and the offset address within the sector.
[0053] Preferably, when reading data from a Flash sector, according to the file name, traverse the linked list formed by the entire file data pairs starting from the data pair of the first read file. By comparing the file name key value in the key-value pair with the target file name, determine the location of the target data, find the data pair node where the target data is located, and then find the corresponding physical Flash sector according to the data pair node for data reading.
[0054] Preferably, construct a Flash read buffer to avoid frequent direct data reading from the Flash sector; if the data to be read is already in the Flash read buffer, directly read the data from the Flash read buffer; if it is not in the Flash read buffer and the data to be read is less than the maximum data volume of a single read operation, put the data into the Flash read buffer, otherwise directly read the data from the Flash sector to the target address; the capacity of the Flash read buffer can be dynamically adjusted according to system requirements.
[0055] Preferably, the content of the key-value pair within each data pair includes the data pair stored data length, data pair type, data, and a pointer to the next data pair.
[0056] Preferably, each physical Flash sector corresponds to a key-value pair for recording the number of change times of the physical Flash sector; whenever a physical Flash sector is erased or new data is written, the value of the corresponding key-value pair increases.
[0057] Preferably, select an idle Flash sector from the Flash free sector table. Specifically, when using the sliding window method to select sectors, use the algorithm for generating distinct random numbers to select sectors in the free table; the sliding window method is used to sequentially scan the free sector table, and the distinct random number algorithm ensures that the selected sectors are evenly distributed.
[0058] Preferably, when performing a write operation, first find the write position; when inserting a new data pair node into the original data pair chain, first write the data into the new data pair node, and then update the pointer of the previous data pair to point to the newly created data pair and point to the subsequent data pair.
[0059] Preferably, when reading a file or directory, according to the file or directory ID, traverse the directory data pairs to find the ID of the target file; find the relevant data in the corresponding data pair according to the ID of the target file.
[0060] Preferably, when completing file writing, according to the block allocation strategy, additionally write the same backup content to two other locations; the block allocation strategy can be dynamically adjusted according to system requirements to ensure that the backup content is distributed in different physical regions.
[0061] Embodiment
[0062] Separate the underlying Flash operations from the application software through an intermediate layer, and automatically perform triple modular redundancy reinforcement during direct underlying operations, providing convenience for the development of application programs.
[0063] Use a data structure to implement data storage and protect the power-off safety during data reading and writing.
[0064] Maintain the idle Flash sectors with a table, and use distinct random numbers to select the sectors to be used, avoiding frequent use of a certain sector.
[0065] The present invention discloses a two-out-of-three storage method for Flash parameters with power-off safety, including:
[0066] Step 1: Divide the total number of sectors of the Flash into three parts with the same number of sectors (the extra sectors are not used). When performing a write operation on the underlying Flash, write the same data simultaneously in the three parts, and the address interval between the same data is the total number of bytes of each part of the sectors. When reading data, read the data from the three parts simultaneously and perform a two-out-of-three determination to read the final data.
[0067] Step 2: Use a dictionary structure as the basic data structure required for Flash file storage, which is called a data pair in this method. Each data pair consists of several key-value pairs, and each key-value pair consists of a key and a value. The data pairs are linked by pointers stored in the key-value pairs. When performing a write operation, first find the write position. When inserting a new data pair node into the original data pair chain, do not directly interrupt the connection between the old data pair node and the subsequent data pair node. Instead, first write the data into a newly created data pair node. After completing the data writing of this section of the data pair node, then point the parent node pointer of the insertion position to the newly created data pair, and point the newly created data pair to the subsequent data pair. The unnecessary data pairs are automatically discarded. In this way, even if a power-off occurs during the process and the data writing is not completed, the original data will not be lost.
[0068] Step 3: When a write operation needs to allocate a new idle sector, select a new sector from the maintained idle sector table. To ensure the balanced usage of each sector of the Flash and avoid frequent use of a few sectors, each time the sliding window method is used to select a sector, an algorithm for generating distinct random numbers is used to generate the starting position for selecting a sector in the idle table.
[0069] In this embodiment, the selected Flash model is am29lv(16bit).
[0070] Figure 1 It is a storage structure diagram of a two-out-of-three storage method for Flash parameters with power-off safety provided by an embodiment of the present invention. The specific steps S101 to S103 are detailed as follows:
[0071]
[0071] When storing a file, first, a header block is required as the starting point of the entire data pair chain. The header block consists of several data pairs, which are connected by pointers pointing to the next data pair.
[0072] Store a pointer to the root directory in the last data pair of the header block. The directory also consists of several data pairs connected by pointers.
[0073]
[0072] Store a pointer in the header data pair of the file that connects to the data pairs in the directory. In a data pair within the file, a key-value pair stores the file data. Figure 1 Only a single data pair is used as an example to illustrate the connection method between the file, directory, and header block structures.
[0074] Figure 2
[0073] The following is a flowchart for writing data to a file. The specific steps S201 to S203 are detailed as follows:
[0075] Figure 1 In the original file structure, the pointers stored in the key-value pairs are connected to data pair 1, data pair 2, and a series of subsequent data pairs. At this time, the data stored in data pair 1 and data pair 2 needs to be rewritten.
[0076] When rewriting, first, add pointers to updated content data pairs 3 and 4 in the data pair before the change position, and complete the update of the key-value pair content in data pairs 3 and 4. At this time, if a system power failure occurs, it will not affect the content of the original data pairs 1 and 2.
[0077]
[0074] After writing is completed, disconnect the connection with data pairs 1 and 2 to complete the writing of the file. At this time, if a power failure occurs, the file has been updated and will not affect data security.
[0078] Figure 3 Figure 2 The following is a method for selecting a sliding window when free sectors are needed. The size of the sliding window can be adjusted. When selecting a free window in the maintained free sector table, use distinct random numbers to select the sector positions, avoiding frequent use of individual sectors.
[0079] Although the content of the present invention has been described in detail through the above preferred embodiments, it should be recognized that the above description should not be considered as a limitation of the present invention. After those skilled in the art have read the above content, various modifications and substitutions to the present invention will be obvious. Therefore, the protection scope of the present invention should be defined by the appended claims.
[0080]
[0075] The content not described in detail in the specification of the present invention belongs to the well-known technology of those skilled in the art.
Claims
1. A power-off safe Flash storage method, characterized in that including: Constructing a storage structure; the storage structure includes a number of data pairs; a data pair includes a number of key-value pairs and their corresponding contents, and data pairs are linked by pointers; each data pair is mapped to one or more physical Flash sectors; Constructing a Flash free sector table; When writing data to a Flash sector, determine whether the length of the data to be written is less than the size of the Flash sector corresponding to the target storage structure. If so, write a new key-value pair and the corresponding data to the corresponding storage structure; otherwise, select a free Flash sector from the Flash free sector table for data storage; When the data writing is completed, write the same backup content to two other locations; when reading data, read the data from the three locations where the same content is written respectively and perform a two-out-of-three check to obtain the read content.
2. The Flash storage method with power-off safety according to claim 1, wherein: The storage structure includes a header block, a root directory, directories, and files; among them, The header block, root directory, directories, and files are all composed of one or more data pairs; The header block serves as the starting position of the storage structure; The first data pair of the root directory is linked to the last data pair of the header block by a pointer; The last data pair of the root directory is linked to the first data pair of the directory by a pointer; The first data pair of the file is linked to the last data pair of the directory where it is located by a pointer; A directory includes a directory name key-value pair used to indicate that the type of this data pair is a directory; A file includes a file flag key-value pair used to indicate that the type of this data pair is a file, and the stored content includes the sector where the file is located and the offset address within the sector.
3. A power-down safe Flash storage method according to claim 1, characterized in that: When reading data from a Flash sector, according to the file name, traverse the linked list formed by the entire file data pairs starting from the data pair that reads the file for the first time. By comparing the file name key in the key-value pair with the target file name, determine the position of the target data, find the data pair node where the target data is located, and then find the corresponding physical Flash sector according to the data pair node for data reading.
4. A power-off safe Flash storage method according to claim 1, characterized in that: Construct a Flash read buffer to avoid directly reading data from Flash sectors frequently; if the data to be read is already in the Flash read buffer, directly read the data from the Flash read buffer; If it is not in the Flash read buffer and the data to be read is less than the maximum data volume of a single read operation, put the data into the Flash read buffer, otherwise directly read the data from the Flash sector to the target address; The capacity of the Flash read buffer can be dynamically adjusted according to system requirements.
5. A power-off safe Flash storage method according to claim 1, characterized in that: The content of the key-value pair within each data pair includes the data storage length of the data pair, the data pair type, the data, and a pointer to the next data pair.
6. A power-off safe Flash storage method according to claim 1, characterized in that: Each physical Flash sector corresponds to a key-value pair used to record the number of changes to the physical Flash sector; whenever a physical Flash sector is erased or new data is written, the value of the corresponding key-value pair is incremented.
7. A power-down safe Flash storage method according to claim 1, characterized in that: Select free Flash sectors from the Flash free sector table. Specifically, when using the sliding window method to select sectors, use the algorithm for generating distinct random numbers to select sectors from the free table; the sliding window method is used to sequentially scan the free sector table, and the algorithm for generating distinct random numbers ensures that the selected sectors are evenly distributed.
8. A power-down safe Flash storage method according to claim 1, characterized in that: When performing a write operation, first find the write location; when inserting a new data pair node into the original data pair chain, first write the data to the new data pair node, and then update the pointer of the previous data pair to point to the newly created data pair and to the subsequent data pair.
9. A power-down safe Flash storage method according to claim 1, characterized in that: When reading a file or directory, based on the file or directory ID, traverse the directory data pairs to find the ID of the target file; based on the ID of the target file, find the relevant data in the corresponding data pair.
10. A power-down safe Flash storage method according to claim 1, characterized in that: When completing a file write, according to the block allocation policy, additionally write the same backup content to two other locations; The block allocation policy can be dynamically adjusted according to system requirements to ensure that the backup content is distributed in different physical regions.