Method and system for micro-restarting attitude and orbit control failure module based on operating system
By monitoring and optimizing the attitude orbit control module, the reconstruction package is generated for checksum matching, and the stability problems caused by the attitude orbit control module due to CPU failure are solved, the stability and reliability of the satellite system are improved, hardware wear is reduced, and task completion efficiency is improved.
Patent Information
- Application Number
- CN202510266570.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-07-18
AI Technical Summary
The attitude orbit control module of the existing technology in-orbit satellite operating system fails the original CPU program due to power supply noise, electrical interference, etc., affecting the stability and reliability of the satellite. Frequent restarts lead to hardware wear, and the module update cannot be performed while maintaining continuous operation.
By monitoring the attitude orbit control module, the reconstruction package is optimized and generated. After the satellite performs checksum matching, the module is updated during the low task load period and performs performance testing to ensure data integrity and security. The optimized module file is selected to use when meeting performance requirements.
It realizes that without affecting the normal operation of the satellite, timely repairing attitude and orbit control module abnormalities, improving system stability and reliability, reducing the impact of failures, improving task completion efficiency, and extending satellite life.
Smart Images

Figure CN120336080A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of satellite on-orbit reconstruction, and specifically, to a method and system for micro restarting a posture and orbit control failure module based on an operating system operation. Background Art
[0002] During the long-term operation of the attitude and orbit control module of an on-orbit satellite operating system, situations such as power supply noise, electrical interference, extreme temperature changes, or resource exhaustion may occur. These situations are likely to cause the original CPU program to fail, specifically manifested as: the attitude calculation algorithm fails or the attitude control strategy fails, and even phenomena such as the attitude and orbit control module being reconstructed during satellite orbit change or the satellite tumbling may occur. This not only affects the normal operation of a single satellite but also may seriously affect the performance of the entire constellation system, resulting in a decline in the reliability and stability of system services.
[0003] The current method is to shut down the entire operating system and start it after an overall update to restore normal operation. Although this method is simple and direct, it also has obvious deficiencies. Especially when the satellite needs to maintain continuous operation, it will cause the system to temporarily interrupt service, affecting the execution of tasks and the continuity of data. In addition, frequent restarts may also cause additional wear on the hardware, reducing the overall lifespan and reliability of the satellite.
[0004] In order to extend the service life of the satellite operating system and protect the hardware, there is an urgent need for a new technology that can achieve micro restart by updating the problematic module of the operating system without affecting the normal operation of the satellite. This technology can significantly improve the stability, reliability, and fault handling ability of the satellite operating system, providing a more solid technical guarantee for future satellite systems. Summary of the Invention
[0005] Aiming at the deficiencies in the prior art, the purpose of the present invention is to provide a method and system for micro restarting a posture and orbit control failure module based on an operating system operation.
[0006] According to a method for micro restarting a posture and orbit control failure module based on an operating system operation provided by the present invention, it includes:
[0007] Step S1: Enable the satellite to monitor the attitude and orbit control module, and when the original CPU program makes an error, enter the micro restart process;
[0008] Step S2: Optimize the attitude and orbit control module, and after packing the files before and after optimization, transmit them to the satellite;
[0009] Step S3: Enable the satellite to verify the two reconstruction packages;
[0010] Step S4: Determine whether the kernel version and the standard library version match. If so, write the module files of the two reconstruction packages to the file system; otherwise, discard the reconstruction package.
[0011] Step S5: Have the system use the optimized attitude and orbit control module file for performance testing within a predetermined time period. If the test passes, continue to use it; otherwise, use the attitude and orbit control module file before optimization.
[0012] Preferably, the satellite continuously monitors the attitude and orbit control module of the operating system through the self-check function and ground remote control instructions.
[0013] Preferably, the self-check function includes setting thresholds for the CPU cache, context switching frequency, interrupt rate, and saturation. If an anomaly occurs, transmit the data to the ground via the satellite-ground link. Ground engineers combine the context of the CPU executing tasks and the abnormal behavior of the satellite to determine whether the original CPU program has an error; the ground remote control instructions include telemetry data analysis and remote diagnosis.
[0014] Preferably, step S2 includes that after the ground control center optimizes the attitude and orbit control module according to the detected problems and completes the test, generate module files for the optimized attitude and orbit control module and the unoptimized attitude and orbit control module using the gcc compiler, and package the header, data, and test into a reconstruction package. Turn the data into a check code through the window sliding hash method, and transmit the two reconstruction packages to the satellite by the uplink method.
[0015] Preferably, step S2 further includes:
[0016] Mark functions in the module source code with keywords; compile the source code using gcc, and generate a module file after specifying the option to generate a shared library;
[0017] The ground sending end divides the data into windows of a fixed size, applies a hash function to each window data segment to generate a series of hash values, and concatenate or further hash the hash values to generate the final check code.
[0018] Preferably, step S3 includes comparing the type identification code, unique identifier, and digital signature;
[0019] After receiving the reconstruction package, the satellite terminal compares the check codes to determine data integrity. If the verification fails, the ground resends the reconstruction package and returns the log of the detailed process content. After the verification is successful, determine whether it is a software update or a module update by docking the type identification code and unique identifier of the received reconstruction package, check the digital signature, and initially store it in different regions according to different types.
[0020] Preferably, the satellite terminal repeats step S3 to generate a hash value sequence of the data and a final check code, compares them with the received check code. If the comparison result is consistent, it determines that the data is complete; otherwise, it determines that the data is incorrect or tampered with, and marks the error content through a window segment.
[0021] Preferably, step S4 includes:
[0022] The satellite terminal determines whether the kernel version and the standard library version match the module by identifying the dependency relationship in the two reconstruction packages. If the versions do not match, it discards the package and returns a complete process report to the ground; after finding that the modules match, the system writes the two module files to the file system.
[0023] Preferably, step S5 includes:
[0024] Verify the update function and perform performance testing, and send the complete reconstruction process report to the ground. The satellite continues to execute the established tasks and stores the reconstruction package;
[0025] If the test result solves the previous problem but the optimization index does not meet the requirements, it will not be rolled back, and only the reconstruction process and relevant test results will be returned; if the previous problem cannot be fixed, the system will delete the updated and optimized attitude and orbit control module, start the original performance attitude and orbit control module rewritten for update testing, and record the failure reason at the same time.
[0026] After the module is executed, all designed test cases are executed in sequence; for each execution of a test case, the system collects relevant data in real time, including memory usage, input / output response time, and execution results of functions; repeat the execution of key test cases multiple times and compare the consistency of multiple test results.
[0027] According to a system for micro restart of an attitude and orbit control failure module based on an operating system provided by the present invention, it includes:
[0028] Module M1: enables the satellite to monitor the attitude and orbit control module, and enters the micro restart process when the CPU original program goes wrong;
[0029] Module M2: optimizes the attitude and orbit control module, and packages and transmits the files before and after optimization to the satellite;
[0030] Module M3: enables the satellite to check the two reconstruction packages;
[0031] Module M4: determines whether the kernel version and the standard library version match. If so, it writes the module files of the two reconstruction packages to the file system; otherwise, it discards the reconstruction package;
[0032] Module M5: The system performs performance tests using the optimized attitude and orbit control module file within a predetermined period. If the test passes, it continues to use the optimized file; otherwise, it uses the non-optimized attitude and orbit control module file.
[0033] Preferably, the satellite continuously monitors the attitude and orbit control module of the operating system through self-check functions and ground remote control commands.
[0034] Preferably, the self-check function includes setting thresholds for CPU cache, context switching frequency, interrupt rate, and saturation. If an anomaly occurs, the data is transmitted to the ground via the satellite-ground link. Ground engineers combine the context of the CPU's executed tasks and the satellite's abnormal behavior to determine whether there is an error in the CPU's original program; the ground remote control commands include telemetry data analysis and remote diagnosis.
[0035] Preferably, Module M2 includes that after the ground control center optimizes the attitude and orbit control module based on the detected problems and completes the test, it generates module files for the optimized and non-optimized attitude and orbit control modules using the gcc compiler, packages the header, data, and test into a reconstruction package, converts the data into a checksum through the window-sliding hashing method, and transmits the two reconstruction packages to the satellite by uplink.
[0036] Preferably, Module M2 further includes:
[0037] Mark functions in the module source code with keywords; compile the source code using gcc, and generate a module file after specifying the option to generate a shared library;
[0038] The ground sender divides the data into windows of a fixed size, applies a hash function to each window data segment to generate a series of hash values, and concatenates or further processes the hash values to generate the final checksum.
[0039] Preferably, Module M3 includes a comparison type identification code, a unique identifier, and a digital signature;
[0040] After receiving the reconstruction package, the satellite terminal compares the checksum to determine data integrity. If the verification fails, the ground resends the reconstruction package and returns the log of the detailed process content. After successful verification, it determines whether it is a software update or a module update based on the type identification code and unique identifier of the received reconstruction package, checks the digital signature, and initially stores it in different areas according to different types.
[0041] Preferably, the satellite terminal repeats Module M3 to generate a sequence of hash values and the final checksum of the data, compares it with the received checksum. If the comparison result is consistent, it determines that the data is complete; otherwise, it determines that the data is incorrect or tampered with, and marks the error content through window segments.
[0042] Preferably, the module M4 includes:
[0043] The satellite terminal determines whether the kernel version and the version of the standard library match the module by identifying the dependency relationships in the two reconstructed packages. If the versions do not match, the package is discarded, and a complete process report is returned to the ground. After finding the module match, the system writes the two module files to the file system.
[0044] Preferably, the module M5 includes:
[0045] Verify the update function and perform performance tests, and send the complete reconstruction process report to the ground. The satellite continues to execute the established tasks and stores the reconstructed packages.
[0046] If the test results solve the previous problems but the optimization metrics do not meet the requirements, no rollback is performed, and only the reconstruction process and relevant test results are returned. If the previous problems cannot be fixed, the system deletes the updated and optimized attitude and orbit control module and starts the original performance attitude and orbit control module rewritten for update testing, while recording the reasons for failure.
[0047] After the module is executed, all the designed test cases are executed in sequence; for each execution of a test case, the system collects relevant data in real time, including memory usage, input / output response time, and the execution results of the functions; the key test cases are repeatedly executed multiple times to compare the consistency of the test results of multiple times.
[0048] Compared with the prior art, the present invention has the following beneficial effects:
[0049] 1. The present invention can not only timely repair the anomalies of the attitude and orbit control module, improve the stability of the system, but also improve the module performance through continuous optimization; during the whole process, the system ensures the integrity and security of the updated data through multiple verifications and tests.
[0050] 2. Through the collaborative work of the ground and the satellite terminal, the present invention can quickly respond to and handle the problems encountered during on-orbit operation, reduce the impact of satellite failures on the mission, improve the on-orbit reliability of the satellite and the mission completion efficiency, and provide an efficient, reliable and secure solution for the maintenance and optimization of the satellite operating system.
[0051] 3. When the ground detects that the original program of the CPU of the attitude and orbit control module of the satellite operating system is incorrect, the software engineer writes an optimized attitude and orbit control module file and sends it to the satellite together with the original version. After the satellite performs verification and matching, the module is updated during a period with a low task load, and the module performance is verified through testing. If it meets the standards, it is officially used; otherwise, the original version is used, which has high flexibility and practicability.
[0052] Other beneficial effects of the present invention will be described in the specific implementation manners through the introduction of specific technical features and technical solutions. Those skilled in the art should be able to understand the beneficial technical effects brought by the technical features and technical solutions through these introductions. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] By reading the following detailed description of non-limiting embodiments with reference to the accompanying drawings, other features, objects, and advantages of the present invention will become more apparent:
[0054] Figure 1 It is a flowchart of the micro restart of the operating system running attitude and orbit control failure module in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] The present invention will be described in detail below with reference to specific embodiments. The following embodiments will help those skilled in the art to further understand the present invention, but do not limit the present invention in any form. It should be noted that those of ordinary skill in the art can make several changes and improvements without departing from the concept of the present invention. These all belong to the protection scope of the present invention.
[0056] Referring to Figure 1 As shown, a method for micro restart of an operating system running attitude and orbit control failure module, the method for on-orbit reconstruction of the operating system includes:
[0057] Step S1: The satellite continuously monitors the attitude and orbit control module of the operating system through the self-check function and ground remote control commands. If the original CPU program fails, the micro restart process will start;
[0058] The operating system monitors the running status of the satellite software in the constellation through the self-check function and ground remote control commands. When it is detected that the original CPU program fails, resulting in abnormal or significant performance degradation of the attitude and orbit control module of the satellite operating system, the system will record these abnormalities and trigger the process.
[0059] The self-check function sets thresholds for the CPU cache, context switching frequency, interrupt rate, and saturation. If an abnormality occurs, the data will be transmitted to the ground through the satellite-ground link. Ground engineers combine the context of the CPU executing tasks and the abnormal behavior of the satellite to determine whether the original CPU program has failed.
[0060] The ground remote control commands generally refer to telemetry data analysis (the satellite regularly transmits telemetry data to the ground station) and remote diagnosis (sending specific diagnostic commands, requiring the satellite to perform self-check operations and return the results).
[0061] Step S2: Software engineers rewrite the original performance and the attitude and orbit control module after test optimization according to the recorded content, and package them together with all the test files on the ground and send them to the above satellite;
[0062] At the ground control center, after software engineers optimize the attitude and orbit control module according to the detected problems and complete the tests, they use the gcc compiler to generate module files for both the optimized attitude and orbit control module and the original one, package the header, data, and tests into a reconstruction package, convert the data into a checksum through the window-sliding hashing method, and transmit the two reconstruction packages to the satellite by means of high- and low-speed uplink injection.
[0063] Specifically, first, keywords are used to mark the functions in the module source code. After using gcc to compile the source code and specifying the option to generate a shared library, a module file will be generated.
[0064] The reconstruction package contains the following contents:
[0065]
[0066] The ground sender first divides the data into windows of a fixed size, then applies a hash function to each window data segment to generate a series of hash values, and then concatenates these hash values or further performs hash processing to generate the final checksum.
[0067] Step S3: The satellite verifies the two reconstruction packages and compares the type identification code, unique identifier, and digital signature;
[0068] When the satellite terminal receives the reconstruction package, it first compares the checksum to determine the data integrity. If the verification fails, the ground needs to resend the reconstruction package and return the log of the detailed process content. After the verification is successful, it determines whether it is a software update or a module update by checking the type identification code and unique identifier of the received reconstruction package, then checks the digital signature, and initially stores it in different areas according to the type.
[0069] The satellite terminal repeats the right step S2 to generate a sequence of hash values and the final checksum of the data, compares it with the received checksum. If they are the same, the data is complete; otherwise, the data is incorrect or tampered with. After a small range of marking of the error content through the window segment, it is handed over to the ground for easy viewing.
[0070] Step S4: Determine whether the kernel version and standard library version match by identifying the dependency relationship, and then write the module files of the two reconstruction packages into the file system;
[0071] The satellite terminal determines whether the kernel version and the version of the standard library match the module by identifying the dependency relationship in the two reconstruction packages. If the versions do not match, the package is discarded and a complete process report is returned to the ground. After finding that the modules match, the system writes the two module files into the file system.
[0072] Step S5: The system selects a time window with low task load to update using the test-optimized attitude and orbit control module file, verifies the module performance through testing. If the optimization is completed, it is officially used; otherwise, the original attitude and orbit control file is used.
[0073] Verify the update function and perform performance testing to ensure that the indicators of the new version of the module can reach the expected test results on the ground, and send the complete reconstruction process report to the ground. The satellite continues to execute the established tasks and stores the reconstruction package for a long time. If the test results can solve the previous problems but the optimization indicators do not meet the requirements, do not roll back, but only return the reconstruction process and relevant test results. If the previous problems cannot be fixed, the system will delete the updated and optimized attitude and orbit control module, start the update test of the original performance attitude and orbit control module rewritten, and record the failure reasons for subsequent analysis;
[0074] After the module is executed, all the designed test cases will be executed in sequence. Each time a test case is executed, the system will collect relevant data in real time, including memory usage, input / output response time, and the execution results of functions. And the key test cases will be executed repeatedly multiple times, and the consistency of the multiple test results will be compared.
[0075] The present invention can achieve a micro restart of the operating system by updating the attitude and orbit control module due to an error in the original CPU program. Update when the attitude and orbit control module is not executing tasks and there is enough time for updating, without affecting the normal operation of satellite services, effectively improving the stability and reliability of the satellite operating system.
[0076] The above is the basic embodiment of the present invention. The technical solution of the present invention will be further described below through a preferred embodiment.
[0077] Embodiment 1
[0078] The method for reconstructing the satellite operating system of the present invention includes the following steps:
[0079] Step 1: The satellite continuously monitors the attitude and orbit control module of the operating system through the self-check function and ground remote control instructions. If it is an error in the original CPU program, the micro restart process will start;
[0080] Step 2: In the ground control center, after the software engineer optimizes the attitude and orbit control module according to the monitored problems and completes the testing, both the optimized attitude and orbit control module and the original attitude and orbit control module are used to generate module files using the gcc compiler, and the header, data, and tests are packaged into a reconstruction package. The data is converted into a checksum through the window sliding hash method, and the two reconstruction packages are transmitted to the satellite through the high and low speed upload method.
[0081] Step 3: When the satellite terminal receives the reconstruction package, it first compares the checksum to determine data integrity. If the verification fails, the ground needs to resend the reconstruction package and return the log of the detailed process content. After successful verification, it determines whether it is a software update or a module update by identifying the type identification code and unique identifier of the received reconstruction package, then checks the digital signature, and initially stores it in different areas according to the type;
[0082] Step 4: The satellite terminal determines whether the kernel version and the version of the standard library match the module by identifying the dependency relationship between the two reconstruction packages. If the versions do not match, the package is discarded and a complete process report is returned to the ground. After finding that the modules match, the system writes the two module files to the file system;
[0083] Step 5: The system selects a time window with a low task load to update using the optimized attitude and orbit control module file after testing;
[0084] Step 6: Verify the update function and perform performance testing to ensure that the indicators of the new version of the module can reach the expected test results on the ground, and send the complete reconstruction process report to the ground. The satellite continues to execute the established tasks and stores the reconstruction package for a long time. If the test results can solve the previous problems, but the optimization indicators do not meet the requirements, do not roll back, only return the reconstruction process and relevant test results. If the previous problems cannot be fixed, the system will delete the updated and optimized attitude and orbit control module, start the update test of the original performance attitude and orbit control module rewritten, and record the failure reasons for subsequent analysis.
[0085] This method of micro restarting the failed module based on the operating system provides an efficient and reliable solution to ensure the stability and performance optimization of the satellite in orbit. First, by continuously monitoring the attitude and orbit control module of the operating system, anomalies in the attitude and orbit control module can be detected in a timely manner, and this information is recorded and sent to the ground. According to these recorded contents, if the ground engineers find that the original CPU program is abnormal, they rewrite and optimize the attitude and orbit control module, and package the optimized module together with the original version and send it to the satellite. After receiving it, the satellite performs a series of strict verifications, including checksum comparison, type identification code and digital signature verification, to ensure the integrity and security of the data.
[0086] On the satellite side, the system determines whether the kernel version and the standard library version match by identifying the dependency relationship, ensuring the correctness and compatibility of the module file. Then, a time window with a low task load is selected for the update to reduce the impact on normal tasks. The updated module is verified through a series of tests to ensure that it can achieve the expected optimization effect. If the updated module fails the test, the system will automatically roll back to the original version to ensure the stable operation of the system.
[0087] The beneficial effects of this method are as follows. It can not only promptly repair the anomalies of the attitude and orbit control module, improving the system stability, but also enhance the module performance through continuous optimization. During the whole process, the system ensures the integrity and security of the updated data through multiple verifications and tests. In addition, through the collaborative work of the ground and satellite terminals, it can quickly respond to and handle the problems encountered during on-orbit operation, reduce the impact of satellite failures on the mission, and improve the on-orbit reliability of the satellite and the mission completion efficiency. Overall, this method provides an efficient, reliable, and secure solution for the maintenance and optimization of the satellite operating system.
[0088] The present invention also provides a system for micro restarting a failed attitude and orbit control module based on the operation of an operating system. The system for micro restarting a failed attitude and orbit control module based on the operation of an operating system can be implemented by executing the process steps of the method for micro restarting a failed attitude and orbit control module based on the operation of an operating system. That is, those skilled in the art can understand the method for micro restarting a failed attitude and orbit control module based on the operation of an operating system as the preferred implementation manner of the system for micro restarting a failed attitude and orbit control module based on the operation of an operating system.
[0089] Specifically, a system for micro restarting a failed attitude and orbit control module based on the operation of an operating system includes:
[0090] Module M1: Enables the satellite to monitor the attitude and orbit control module and enter the micro restart process when the original CPU program goes wrong;
[0091] Module M2: Optimizes the attitude and orbit control module, packs the files before and after optimization, and transmits them to the satellite;
[0092] Module M3: Enables the satellite to verify the two reconstruction packages;
[0093] Module M4: Judges whether the kernel version and the standard library version match. If so, writes the module files of the two reconstruction packages into the file system; otherwise, discards the reconstruction package;
[0094] Module M5: Enables the system to perform performance tests using the optimized attitude and orbit control module files within a predetermined time period. If the test passes, continue to use them; otherwise, use the attitude and orbit control module files before optimization.
[0095] The satellite continuously monitors the attitude and orbit control module of the operating system through the self-check function and ground remote control commands.
[0096] The self-check function includes setting thresholds for the CPU cache, context switching frequency, interrupt rate, and saturation. If an anomaly occurs, the data is transmitted to the ground through the space-ground link. Ground engineers combine the context of the CPU executing tasks and the abnormal behavior of the satellite to judge whether the original CPU program has gone wrong. The ground remote control commands include telemetry data analysis and remote diagnosis.
[0097] The module M2 includes that after the ground control center optimizes the attitude and orbit control module according to the detected problems and completes the tests, it generates module files for the optimized and unoptimized attitude and orbit control modules using the gcc compiler, and packs the packet headers, data, and tests into a reconstructed packet. It turns the data into a checksum through the window-sliding hashing method, and transmits the two reconstructed packets to the satellite by the uplink method.
[0098] The module M2 further includes:
[0099] Mark functions in the module source code with keywords; compile the source code using gcc, and generate a module file after specifying the option to generate a shared library;
[0100] The ground sender divides the data into windows of a fixed size, applies a hash function to each window data segment to generate a series of hash values, and concatenates or further performs hash processing on the hash values to generate a final checksum.
[0101] The module M3 includes a comparison type identification code, a unique identifier, and a digital signature;
[0102] After receiving the reconstructed packet, the satellite terminal compares the checksum to judge data integrity. If the verification fails, the ground resends the reconstructed packet and returns the log of the detailed process content. After the verification is successful, it judges whether it is a software update or a module update by the type identification code and unique identifier of the received reconstructed packet, checks the digital signature, and initially stores it in different areas according to different types.
[0103] The satellite terminal repeats module M3 to generate a sequence of hash values and a final checksum of the data, compares it with the received checksum. If the comparison result is consistent, it determines that the data is complete; otherwise, it determines that the data is incorrect or tampered with, and marks the error content through window segments.
[0104] The module M4 includes:
[0105] The satellite terminal determines whether the kernel version and the version of the standard library match the module by identifying the dependency relationship in the two reconstructed packets. If the versions do not match, it discards the packet and returns a complete process report to the ground; after finding that the modules match, the system writes the two module files to the file system.
[0106] The module M5 includes:
[0107] Verify the update function and perform performance tests, and send a complete reconstructed process report to the ground. The satellite continues to execute the established tasks and stores the reconstructed packet;
[0108] If the test result solves the previous problem but the optimization index does not meet the requirements, it will not be returned, and only the reconstruction process and relevant test results will be returned; if the previous problem cannot be fixed, the system will delete the updated and optimized attitude and orbit control module and start the update test of the original performance attitude and orbit control module rewritten, and record the reason for failure at the same time;
[0109] After the module is executed, all the designed test cases are executed in sequence; for each executed test case, the system collects relevant data in real time, including memory usage, input and output response time, and the execution result of the function; the key test cases are repeatedly executed multiple times to compare the consistency of the test results of multiple times.
[0110] Those skilled in the art know that in addition to implementing the system and its various devices, modules, and units provided by the present invention in the form of pure computer-readable program code, the method steps can be logically programmed to enable the system and its various devices, modules, and units provided by the present invention to be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers to achieve the same function. Therefore, the system and its various devices, modules, and units provided by the present invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be regarded as the structure within the hardware component; the devices, modules, and units for implementing various functions can also be regarded as either software modules for implementing the method or the structure within the hardware component.
[0111] The specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art can make various changes or modifications within the scope of the claims, which does not affect the essence of the present invention. Without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other arbitrarily.
Claims
1. A method for micro restart of an attitude and orbit control failure module based on the operation of an operating system, characterized in that, Including: Step S1: Enable the satellite to monitor the attitude and orbit control module. When the original CPU program fails, enter the micro restart process; Step S2: Optimize the attitude and orbit control module, and transfer the optimized and non-optimized files to the satellite after packaging; Step S3: Enable the satellite to verify the two reconstruction packages; Step S4: Determine whether the kernel version and the standard library version match. If so, write the module files of the two reconstruction packages to the file system; otherwise, discard the reconstruction package; Step S5: Enable the system to perform a performance test using the optimized attitude and orbit control module file within a predetermined time period. If the test passes, continue to use it; otherwise, use the non-optimized attitude and orbit control module file.
2. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 1, wherein The satellite continuously monitors the attitude and orbit control module of the operating system through the self-check function and ground remote control commands.
3. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 2, wherein The self-check function includes setting thresholds for the CPU cache, context switching frequency, interrupt rate, and saturation. If an abnormality occurs, the data is transmitted to the ground through the satellite-ground link. Ground engineers combine the context of the CPU executing tasks and the abnormal behavior of the satellite to determine whether the original CPU program has failed; the ground remote control commands include telemetry data analysis and remote diagnosis.
4. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 1, wherein The step S2 includes that after the ground control center optimizes the attitude and orbit control module according to the detected problems and completes the test, it generates module files for the optimized and non-optimized attitude and orbit control modules using the gcc compiler, packages the header, data, and test into a reconstruction package, converts the data into a checksum through the window sliding hash method, and transmits the two reconstruction packages to the satellite by uplink.
5. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 4, wherein The step S2 further includes: Marking functions in the module source code with keywords; compiling the source code using gcc and specifying the option to generate a shared library to generate a module file; The ground sending end divides the data into windows of a fixed size, applies a hash function to each window data segment to generate a series of hash values, and concatenates or further performs hash processing on the hash values to generate a final checksum.
6. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 1, wherein The step S3 includes comparing the type identification code, unique identifier, and digital signature; After receiving the reconstruction package, the satellite terminal compares the checksum to determine data integrity. If the verification fails, the ground resends the reconstruction package and returns the log of the detailed process content. After successful verification, it determines whether it is a software update or a module update by docking the type identification code and unique identifier of the received reconstruction package, checks the digital signature, and initially stores it in different areas according to different types.
7. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 6, wherein The satellite terminal repeats step S3 to generate a sequence of hash values and a final checksum of the data, compares it with the received checksum. If the comparison result is consistent, it determines that the data is complete; otherwise, it determines that the data is incorrect or has been tampered with, and marks the error content through the window segment.
8. The method for micro restart of the attitude and orbit control failure module based on the operating system according to claim 1, characterized in that, The step S4 includes: The satellite terminal determines whether the kernel version and the standard library version match the module by identifying the dependency relationships in the two reconstruction packages. If the versions do not match, the package is discarded, and a complete process report is returned to the ground; after discovering that the module matches, the system writes the two module files to the file system.
9. The method for micro restart of the attitude and orbit control failure module based on the operating system as claimed in claim 1, wherein The step S5 includes: Verify the update function and perform performance tests, and send the complete refactoring process report to the ground. The satellite continues to execute the established tasks and stores the refactoring package; If the test results solve the previous problems but the optimization metrics do not meet the requirements, do not roll back, but only return the refactoring process and relevant test results; if the previous problems cannot be fixed, the system will delete the updated and optimized attitude and orbit control module and start the performance test of the re-written original attitude and orbit control module, and record the reasons for failure at the same time; After the module is executed, all designed test cases are executed in sequence; for each executed test case, the system collects relevant data in real time, including memory usage, input / output response time, and execution results of functions; the key test cases are executed repeatedly multiple times to compare the consistency of the test results of multiple times.
10. A system based on micro restart of the attitude and orbit control failure module during the operation of the operating system, characterized in that, Including: Module M1: Enable the satellite to monitor the attitude and orbit control module and enter the micro restart process when the original CPU program goes wrong; Module M2: Optimize the attitude and orbit control module, and package and transmit the files before and after optimization to the satellite; Module M3: Enable the satellite to verify the two refactoring packages; Module M4: Judge whether the kernel version and the standard library version match. If so, write the module files of the two refactoring packages to the file system, otherwise discard the refactoring package; Module M5: Enable the system to perform performance tests using the optimized attitude and orbit control module file within a predetermined time period. If the test passes, continue to use it; otherwise, use the attitude and orbit control module file before optimization.
Citation Information
Cited By
Health management method and system of satellite attitude and orbit control unit and electronic equipment
CN120817257A