Software control and on-orbit reinjection method and device for satellite load master control system
Through the collaborative work of DSP and FPGA, the software on-orbit focus of the satellite payload master system is realized, solving the complexity and reliability problems caused by additional circuits, improving the stability of the system and simplifying the hardware design.
Patent Information
- Application Number
- CN202510262279.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-03-06
AI Technical Summary
The software on-orbit heavy-pressing method of existing satellite payload master control systems requires additional on-orbit heavy-pressing circuits, resulting in reduced circuit complexity and reliability.
Through the collaborative work of DSP and FPGA, software on-orbit focus is realized using programmable logic gate arrays, and mutual monitoring and reset mechanisms are adopted. When one party fails to load, the other party resets or switches the backup storage unit to ensure system stability.
It realizes software on-track heavy-to-door without additional circuits, improves system stability and reliability, simplifies hardware design, and meets the needs of software updates and function upgrades.
Smart Images

Figure CN120371602A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of satellite control technology, and particularly to a software control and on-orbit reloading method and device for a satellite payload main control system.
Background Art
[0002] In recent years, with the rapid development of satellite technology, the satellite payload main control system has an increasing demand for software updates and function upgrades. Traditional on-orbit software reloading schemes usually rely on additional on-orbit reloading circuits. Although the on-orbit software reloading function is achieved, it increases the circuit complexity and hardware cost of the satellite payload main control system, and at the same time reduces the stability and reliability of the system.
[0003] In addition, there is another scheme in the prior art, that is, using an FPGA (Field-Programmable Gate Array) soft core to replace a DSP (Digital Signal Processor) as the satellite payload main control system. This scheme integrates the functions of the DSP into the FPGA soft core by utilizing the programmable logic resources of the FPGA, thus streamlining the hardware structure of the satellite payload main control system. However, this scheme still requires additional circuits to assist the FPGA soft core to achieve the on-orbit software reloading function, and cannot fundamentally solve the problems of circuit complexity and system reliability.
[0004] Therefore, there is an urgent need for an on-orbit software reloading scheme that does not require additional on-orbit reloading circuits, can streamline the circuit structure of the satellite payload main control system, and enhance the stability and reliability of the system, so as to meet the urgent needs of the satellite payload main control system for software updates and function upgrades.
Summary of the Invention
[0005] Embodiments of this application provide a software control and on-orbit reloading method and device for a satellite payload main control system, aiming to solve the technical problems of increased circuit cost and reduced reliability caused by the on-orbit software reloading method of the satellite payload main control system in related technologies.
[0006] In a first aspect, embodiments of this application provide a software control and on-orbit reloading method for a satellite payload main control system, including:
[0007] Obtain an on-orbit software reloading instruction from a satellite management platform;
[0008] In response to the on-orbit software reloading instruction, download the on-orbit software reloading package of the satellite management platform, and write the on-orbit software reloading package into a target Flash storage unit through a programmable logic gate array, where the target Flash storage unit is currently in an idle state;
[0009] Upon completion of writing the software in-orbit reload package, generate a software power-on loading instruction, where the software power-on loading instruction indicates a re-power-on loading from the target Flash storage unit;
[0010] Based on the software power-on loading instruction, perform software power-on loading on the programmable logic gate array and the digital signal processor;
[0011] If the result of the software power-on loading is that the programmable logic gate array is successfully powered on and the digital signal processor fails to be powered on, call the programmable logic gate array to reset the digital signal processor;
[0012] If the result of the software power-on loading is that the digital signal processor is successfully powered on and the programmable logic gate array fails to be powered on, generate a first reset instruction for the programmable logic gate array, and based on the first reset instruction, call the digital signal processor to reset the programmable logic gate array;
[0013] If the result of the software power-on loading is that both the programmable logic gate array and the digital signal processor fail to be powered on, generate a second reset instruction, and based on the second reset instruction, restart the satellite payload main control system.
[0014] In an embodiment of the present application, optionally, the calling the programmable logic gate array to reset the digital signal processor includes:
[0015] Pull the MP / MC pin of the digital signal processor to the MP mode through the programmable logic gate array to reset the digital signal processor, so that the digital signal processor starts the corresponding running program from the external interface provided by the programmable logic gate array.
[0016] In an embodiment of the present application, optionally, when the digital signal processor is successfully powered on, generate a watchdog signal in the digital signal processor at each specified time interval, and send the watchdog signal to the programmable logic gate array; and
[0017] After the programmable logic gate array is successfully powered on, monitor whether the programmable logic gate array has not received the watchdog signal beyond the specified time interval;
[0018] If the programmable logic gate array has not received the watchdog signal beyond the specified time interval, generate a first reset signal in the programmable logic gate array;
[0019] Reset the digital signal processor based on the first reset signal, so that the digital signal processor is powered on and reloaded.
[0020] In an embodiment of the present application, optionally, the resetting the programmable logic gate array by invoking the digital signal processor based on the first reset instruction includes:
[0021] Based on the first reset instruction, the digital signal processor runs a Flash switching program through a magnetic latching relay to switch the first Flash storage unit currently accessed by the programmable logic gate array to a spare second Flash storage unit, and the second Flash storage unit is the target Flash storage unit;
[0022] The digital signal processor sends a second reset signal to the programmable logic gate array through the PROG_B_O pin of the programmable logic gate array, so that the programmable logic gate array responds to the acquisition of the second reset signal, reads the code stream again in the second Flash storage unit and starts.
[0023] In an embodiment of the present application, optionally, the determining the result of the software power-on loading of the satellite payload main control system further includes:
[0024] After the digital signal processor is successfully powered on and loaded, start monitoring and timing for the programmable logic gate array through the OTP ROM of the digital signal processor;
[0025] If the timing duration of the start monitoring and timing exceeds a predetermined time threshold, it is determined that the power-on loading of the programmable logic gate array fails.
[0026] In a second aspect, an embodiment of the present application provides a software control and on-orbit refueling device for a satellite payload main control system, including:
[0027] A software on-orbit refueling instruction acquisition unit, configured to acquire a software on-orbit refueling instruction from a satellite management platform;
[0028] An on-orbit refueling package writing unit, configured to download the software on-orbit refueling package of the satellite management platform in response to the software on-orbit refueling instruction, and write the software on-orbit refueling package into a target Flash storage unit through a programmable logic gate array, where the target Flash storage unit is currently in an idle state;
[0029] A power-on loading instruction generation unit, configured to generate a software power-on loading instruction in response to the completion of the writing of the software on-orbit refueling package, where the software power-on loading instruction instructs to perform a re-power-on loading from the target Flash storage unit;
[0030] The power-on loading execution unit performs software power-on loading on the programmable logic gate array and the digital signal processor based on the software power-on loading instruction;
[0031] The first execution unit is used to, if the result of the software power-on loading is that the power-on loading of the programmable logic gate array is successful and the power-on loading of the digital signal processor fails, call the programmable logic gate array to reset the digital signal processor;
[0032] The second execution unit is used to, if the result of the software power-on loading is that the power-on loading of the digital signal processor is successful and the power-on loading of the programmable logic gate array fails, generate a first reset instruction for the programmable logic gate array, and based on the first reset instruction, call the digital signal processor to reset the programmable logic gate array;
[0033] The third execution unit is used to, if the result of the software power-on loading is that both the programmable logic gate array and the digital signal processor fail in power-on loading, generate a second reset instruction, and based on the second reset instruction, restart the satellite payload main control system.
[0034] In an embodiment of the present application, optionally, the first execution unit is used to:
[0035] Pull the MP / MC pin of the digital signal processor to the MP mode through the programmable logic gate array, reset the digital signal processor, and enable the digital signal processor to start the corresponding running program from the external interface provided by the programmable logic gate array.
[0036] In an embodiment of the present application, optionally, the device further includes:
[0037] The watchdog signal reporting unit is used to, when the power-on loading of the digital signal processor is successful, generate a watchdog signal in the digital signal processor at each specified time interval, and send the watchdog signal to the programmable logic gate array; and
[0038] The monitoring unit is used to, after the power-on loading of the programmable logic gate array is successful, monitor whether the programmable logic gate array has not received the watchdog signal beyond the specified time interval;
[0039] The fourth execution unit is used to, if the programmable logic gate array has not received the watchdog signal beyond the specified time interval, generate a first reset signal in the programmable logic gate array, and based on the first reset signal, reset the digital signal processor to enable the digital signal processor to perform power-on loading again.
[0040] In an embodiment of the present application, optionally, the second execution unit includes:
[0041] A Flash switching unit, configured to, based on the first reset instruction, run a Flash switching program through the digital signal processor via a magnetic latching relay, and switch a first Flash storage unit currently accessed by the programmable logic gate array to a standby second Flash storage unit, where the second Flash storage unit is the target Flash storage unit;
[0042] A restart execution unit, configured to send a second reset signal to the programmable logic gate array through the PROG_B_O pin of the programmable logic gate array via the digital signal processor, so that the programmable logic gate array, in response to obtaining the second reset signal, rereads the bitstream in the second Flash storage unit and starts.
[0043] In an embodiment of the present application, optionally, the loading result determination unit includes:
[0044] A timing monitoring unit, configured to perform startup monitoring timing on the programmable logic gate array through the OTP ROM of the digital signal processor after the digital signal processor is successfully powered on and loaded;
[0045] A timing judgment unit, configured to determine that the power-on loading of the programmable logic gate array fails if the timing duration of the startup monitoring timing exceeds a predetermined time threshold.
[0046] In a third aspect, an embodiment of the present application provides a satellite payload main control system, which applies the software control and on-orbit refueling method for a satellite payload main control system according to any one of the first aspects above, and includes:
[0047] A digital signal processor, which runs its own startup program using an external interface and is configured to perform signal processing tasks for the satellite payload main control system;
[0048] A programmable logic gate array, configured to load and execute a program for the satellite payload main control system and provide the external interface for the digital signal processor;
[0049] A first Flash storage unit and a second Flash storage unit, which are respectively connected to the programmable logic gate array, and both the first Flash storage unit and the second Flash storage unit are configured to store the bitstream data of the programmable logic gate array and the boot program and application program of the digital signal processor;
[0050] A magnetic latching relay, which is respectively connected to the first Flash storage unit and the second Flash storage unit and is connected to the digital signal processor, is configured to run a Flash switching program based on an instruction of the digital signal processor to switch the current Flash storage unit of the programmable logic gate array between the first Flash storage unit and the second Flash storage unit;
[0051] Wherein, the programmable logic gate array and the digital signal processor are configured to perform software power-on loading again based on a software power-on loading instruction, and the software power-on loading instruction is generated in response to an action of the programmable logic gate array writing a software in-orbit reload package from a satellite management platform into a target Flash storage unit during the in-orbit reload process of the satellite payload main control system software, and the target Flash storage unit is an idle unit among the first Flash storage unit and the second Flash storage unit;
[0052] The programmable logic gate array is configured to pull the MP / MC pin of the digital signal processor that fails in power-on loading to the MP mode and then reset the digital signal processor when its own power-on loading is successful, so that the digital signal processor restarts the corresponding running program from the external interface;
[0053] The digital signal processor is configured to, when its own power-on loading is successful, run a Flash switching program through the magnetic latching relay and then control the programmable logic gate array to reread a bitstream in the switched current Flash storage unit and start through the PROG_B_O pin of the programmable logic gate array;
[0054] The satellite payload main control system is configured to perform its own restart operation when both the programmable logic gate array and the digital signal processor fail in power-on loading.
[0055] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, and the computer-executable instructions are used to execute the method described in the first aspect above.
[0056] In the above technical solution, in view of the technical problems of increased circuit cost and reduced reliability caused by the introduction of additional circuits in the software in-orbit reloading method of the satellite payload main control system in the related technology, the software control and in-orbit reloading method for the satellite payload main control system proposed in this application, when the satellite payload main control system needs in-orbit reloading, after downloading the software in-orbit reloading package to the idle Flash storage unit, the existing DSP and FPGA in the satellite payload main control system work together to control each other to reset, so as to realize the switching of the current Flash storage unit to the idle Flash storage unit, and realize the smooth in-orbit reloading of the satellite payload main control system. Specifically, this solution realizes the in-orbit software in-orbit reloading function of the satellite payload control system through the mechanism of mutual monitoring and reset of DSP and FPGA, and avoids the problem of relying on additional in-orbit reloading circuits in the traditional solution. When the FPGA is successfully powered on and loaded while the DSP loading fails, the FPGA can actively reset the DSP to restart it from the external interface; on the contrary, if the DSP is successfully loaded while the FPGA loading fails, the DSP resets the FPGA through the Flash switching program to reload the bitstream from the backup Flash storage unit. In addition, when both of them fail to load, the system will automatically execute a restart operation to ensure that the system can resume normal operation. In this way, while improving the startup stability of the software in-orbit reloading of the satellite payload control system, there is no need to inject additional new circuit structures, avoiding additional cost overhead and ensuring the reliability of the satellite payload control system.
[0057] In summary, when the satellite payload main control system needs in-orbit reloading, this application realizes smooth in-orbit reloading through the cooperation of DSP and FPGA without adding additional in-orbit reloading circuits, which not only simplifies the hardware design, but also significantly improves the stability and reliability of the system, meeting the urgent needs of the satellite payload main control system for software update and function upgrade.
BRIEF DESCRIPTION OF THE DRAWINGS
[0058] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0059] Figure 1 Shows a flowchart of a software control and in-orbit reloading method for a satellite payload main control system according to an embodiment of the present application;
[0060] Figure 2 Shows a schematic diagram of a satellite payload main control system according to an embodiment of the present application.
DETAILED DESCRIPTION OF THE EMBODIMENTS
[0061] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0062] Figure 1 The flowchart of the software control and on-orbit reloading method for the main control system of satellite payloads according to an embodiment of the present application is shown.
[0063] The main control system of satellite payloads includes a programmable logic gate array and a digital signal processor, as Figure 1 shown, the software control and on-orbit reloading method for the main control system of satellite payloads according to an embodiment of the present application includes:
[0064] Step 102, obtain the software on-orbit reloading instruction from the satellite management platform.
[0065] The main control system of satellite payloads is one of the core components of the satellite and is responsible for controlling and managing the operation of satellite payloads (such as communication, remote sensing, navigation and other devices). Its main functions include data acquisition, signal processing, task scheduling, fault diagnosis and recovery, etc. The performance of the main control system of satellite payloads directly affects the mission execution ability and reliability of the satellite. The satellite management platform is the ground control party of the main control system of satellite payloads. When it is necessary to perform on-orbit software reloading on the main control system of satellite payloads, the satellite management platform will send a software on-orbit reloading instruction to the main control system of satellite payloads, requiring the main control system of satellite payloads to implement on-orbit software reloading based on the software on-orbit reloading instruction.
[0066] Step 104, in response to the software on-orbit reloading instruction, download the software on-orbit reloading package of the satellite management platform, and write the software on-orbit reloading package into the target Flash storage unit through the programmable logic gate array, where the target Flash storage unit is currently in an idle state.
[0067] When the software on-orbit reloading package is read, the on-orbit reloading of the main control system of satellite payloads can be realized. The function of writing the software on-orbit reloading package into the target Flash storage unit is mainly reflected in the following aspects.
[0068] First, software update and function upgrade. The target Flash storage unit, as an idle storage space, is used to store the latest software on-orbit reloading package from the satellite management platform. By writing the software on-orbit reloading package into the target Flash storage unit, the software update and function upgrade of the main control system of satellite payloads can be realized, ensuring that the system can run the latest program version and meet the mission requirements.
[0069] Second, system redundancy and reliability improvement. The main control system of satellite payloads usually adopts a dual-Flash storage unit design (such as the first Flash storage unit and the second Flash storage unit), where one is used as the currently operating unit and the other is used as the standby unit. After writing the on-orbit software reload package into the idle target Flash storage unit, the system can switch to this unit for operation when needed, thus achieving seamless software updates and avoiding system interruptions or failures caused by software updates. This design improves the redundancy and reliability of the system.
[0070] Third, achieve seamless switching for on-orbit software reload. By writing the on-orbit software reload package into the target Flash storage unit, the system can generate a software power-on loading instruction after the writing is completed, indicating to restart from the target Flash storage unit. This mechanism ensures that the system can smoothly switch to the new version of software during the on-orbit software reload process without affecting the normal operation of the system.
[0071] Fourth, support on-orbit software updates. During the on-orbit operation of the satellite, it may be necessary to update the software to fix vulnerabilities, optimize performance, or add new functions. After writing the on-orbit software reload package into the target Flash storage unit, the system can complete the software update without interrupting the mission, significantly improving the maintainability and flexibility of the satellite's on-orbit operation.
[0072] Fifth, ensure the continuity of system operation. During the on-orbit software reload process, the system can still work normally from the currently operating Flash storage unit, and after the on-orbit software reload package is written into the target Flash storage unit, the system can switch to the new version of software at an appropriate time. This design avoids system interruptions or function failures that may occur during software updates and ensures the continuity of system operation.
[0073] Sixth, support recovery from abnormal situations. If an abnormality occurs during the on-orbit software reload process (such as loading failure), the system can recover by switching to the new version of software in the target Flash storage unit or by restarting the operation to resume normal operation. This mechanism enhances the fault tolerance and stability of the system.
[0074] In summary, the role of writing the on-orbit software reload package into the target Flash storage unit is to achieve software updates, improve system reliability, support on-orbit updates, ensure system continuity, and enhance system fault tolerance. It is a key step in the software control and on-orbit reload method of the main control system of satellite payloads.
[0075] Step 106: Generate a software power-on loading instruction in response to the completion of writing the software in-orbit refueling package, where the software power-on loading instruction instructs to perform a re-power-on loading from the target Flash storage unit.
[0076] After the writing of the software in-orbit refueling package is completed, it indicates that the satellite payload main control system currently has the basic conditions for implementing software in-orbit refueling. At this time, a software power-on loading instruction can be generated, requiring the satellite payload main control system to switch to the target Flash storage unit during re-power-on loading to obtain the software in-orbit refueling package, so as to successfully complete software in-orbit refueling.
[0077] Step 108: Perform software power-on loading on the programmable logic gate array and the digital signal processor based on the software power-on loading instruction.
[0078] Specifically, the programmable logic gate array is used to implement the hardware logic function for the satellite payload main control system, support parallel processing and high-speed data stream control, and its own flexibility enables it to adapt to various task requirements. The digital signal processor is responsible for high-speed digital signal processing tasks for the satellite payload main control system, such as data compression, filtering, modulation and demodulation, etc. The digital signal processor has powerful mathematical operation capabilities and is suitable for processing complex algorithms.
[0079] Generally speaking, the process of re-power-on loading of the satellite payload main control system mainly includes the steps of re-power-on loading of the programmable logic gate array and the digital signal processor respectively.
[0080] However, there is a risk of power-on loading failure for the programmable logic gate array and the digital signal processor respectively during re-power-on loading.
[0081] First, a hardware failure occurs. For example, the power supply voltage is unstable or fluctuates too much, resulting in the DSP or FPGA being unable to start normally, or the power supply module fails and cannot provide sufficient current or voltage; for example, the Flash storage unit is damaged or data is lost, resulting in the DSP or FPGA being unable to read the correct startup program or configuration bitstream, or the Flash storage unit interface is poorly contacted or damaged, resulting in data transmission failure; for example, the DSP or FPGA chip is damaged due to radiation, temperature change or mechanical stress and cannot work normally; for example, the traces on the PCB (printed circuit board) are broken or short-circuited, resulting in signal transmission failure, or poor soldering or component aging affects the normal operation of the circuit.
[0082] Second, software or configuration issues. For example, there are logical errors in the startup program or application program of the DSP or FPGA, resulting in crashes during the loading process, or the program code is incompatible with the hardware and cannot run correctly; for example, the configuration bitstream of the FPGA is damaged or incomplete, resulting in the FPGA being unable to be loaded correctly, or the configuration bitstream does not match the current hardware version, resulting in a loading failure; for example, the firmware version of the DSP or FPGA is too old or has vulnerabilities, resulting in a loading failure.
[0083] Third, environmental factors. For example, high-energy particle radiation in space may cause single-event upsets (SEUs) in the internal registers or memories of the DSP or FPGA, thus affecting the loading process; for example, extreme temperatures (too high or too low) may cause the chip performance to degrade or fail, thus affecting the power-on loading; for example, severe vibrations or shocks during the launch may cause the hardware connections to become loose or damaged, affecting the loading process.
[0084] Fourth, system design issues. For example, the startup timing design of the DSP or FPGA is unreasonable, resulting in signal synchronization failures during the loading process; for example, the reset signal fails to trigger correctly, resulting in the DSP or FPGA being unable to complete initialization; for example, the communication interface (such as SPI, I2C, etc.) between the DSP and the FPGA fails, resulting in data transmission failures during the loading process.
[0085] Fifth, external interference issues. For example, electromagnetic interference inside or outside the satellite may cause signal transmission errors, affecting the loading process; for example, excessive power supply noise may interfere with the normal operation of the DSP or FPGA, resulting in a loading failure.
[0086] Sixth, human issues. For example, the ground station sends incorrect instructions or configuration parameters, resulting in a loading failure of the DSP or FPGA; for example, during the in-orbit software update process, the new version of the software has defects or is incompatible with the hardware, resulting in a loading failure.
[0087] Due to the various possible problems mentioned above, the results of the software power-on loading of the satellite payload master control system may be as follows: the programmable logic gate array in the satellite payload master control system is successfully power-on loaded; the digital signal processor is successfully power-on loaded, and the programmable logic gate array fails to be power-on loaded; both the programmable logic gate array and the digital signal processor fail to be power-on loaded. In the face of these possible failure situations, to ensure the stability of the satellite payload master control system, respective corresponding reset mechanisms can be set for different failure situations.
[0088] Step 110, if the result of the software power-on loading is that the programmable logic gate array in the satellite payload main control system is successfully powered on and the digital signal processor in the satellite payload main control system fails to be powered on, call the programmable logic gate array to reset the digital signal processor.
[0089] That is, the programmable logic gate array is used as the control party for resetting the digital signal processor. Specifically, the MP / MC pin of the digital signal processor is pulled to the MP mode by the programmable logic gate array to reset the digital signal processor, so that the digital signal processor starts the corresponding running program from the external interface provided by the programmable logic gate array. That is, after the FPGA detects that the DSP loading fails, it resets the DSP by controlling the MP / MC pin of the DSP, so that it restarts from the external interface.
[0090] Step 112, if the result of the software power-on loading is that the digital signal processor is successfully powered on and the programmable logic gate array fails to be powered on, generate a first reset instruction for the programmable logic gate array, and based on the first reset instruction, call the digital signal processor to reset the programmable logic gate array.
[0091] That is, the digital signal processor is used as the control party for resetting the programmable logic gate array. Specifically, based on the first reset instruction, the digital signal processor runs the Flash switching program through the magnetic latching relay to switch the first Flash storage unit currently accessed by the programmable logic gate array to the spare second Flash storage unit, and the second Flash storage unit is the target Flash storage unit; the digital signal processor sends a second reset signal to the programmable logic gate array through the PROG_B_O pin of the programmable logic gate array, so that the programmable logic gate array responds to the acquisition of the second reset signal and reads the code stream again and starts in the second Flash storage unit. That is, the DSP switches the Flash storage unit of the FPGA through the magnetic latching relay and sends a reset signal to make the FPGA reload the code stream from the spare storage unit.
[0092] It should be added that the method for determining that the programmable logic gate array fails to be powered on includes: after the digital signal processor is successfully powered on, start the startup monitoring timing for the programmable logic gate array through the OTP ROM of the digital signal processor; if the timing duration of the startup monitoring timing exceeds a predetermined time threshold, determine that the programmable logic gate array fails to be powered on.
[0093] Specifically, by using the OTP ROM (One-Time Programmable Read-Only Memory) of the DSP to monitor the startup process of the FPGA, the loading status of the FPGA can be detected in real time. If the FPGA fails to complete startup within the predetermined time, the system can immediately determine that the FPGA loading has failed. In fact, this is a mechanism for monitoring and timing the startup of the Field-Programmable Gate Array (FPGA) through the OTP ROM of the Digital Signal Processor (DSP). This mechanism avoids the problems of relying on manual intervention or complex hardware circuits for status detection in traditional methods, improving the automation level and response speed of the system. By setting a predetermined time threshold, the system can quickly make a judgment when the FPGA loading is abnormal, avoiding the entire system getting into an uncontrollable state due to the failure of FPGA loading. This active monitoring mechanism significantly improves the fault tolerance of the system, ensuring that when a component (such as FPGA) in the main control system of the satellite payload fails, the system can take recovery measures in a timely manner, thereby enhancing the overall reliability. Moreover, using the OTP ROM of the DSP for timing monitoring does not require additional hardware circuits or complex logic designs to detect the FPGA loading status, simplifying the hardware structure of the main control system of the satellite payload, reducing the complexity and cost of the system, and at the same time reducing the possibility of hardware failures.
[0094] In addition, once the FPGA loading failure is detected, the system can immediately trigger the corresponding recovery mechanism (such as resetting the FPGA or switching to the backup storage unit), thus shortening the fault recovery time. For example, in the space environment, the FPGA may fail to load due to factors such as radiation and temperature changes. Through the timing monitoring mechanism, the system can quickly identify and respond to these abnormal situations. This fast response mechanism ensures that the system can quickly resume normal operation when a fault occurs, reducing the mission interruption time, and also improving the adaptability of the system in extreme environments, ensuring that the satellite can still operate stably in the complex space environment, especially suitable for the main control system of satellite payloads with high real-time requirements. At the same time, by using the OTP ROM of the DSP to achieve automatic monitoring and judgment of the FPGA loading status, the dependence on ground station commands is reduced, enhancing the autonomous operation ability of the system. During the on-orbit operation of the satellite, the intervention of the ground station may be affected by communication delays or interruptions, and this autonomous monitoring mechanism can ensure the normal operation of the system without human intervention. Finally, through automatic monitoring and fault detection, the system can detect and solve problems at an early stage, avoiding the further deterioration of faults, thereby reducing the need for on-orbit maintenance.
[0095] In summary, by using the OTP ROM of the DSP to monitor and time the startup of the FPGA, the hardware design is simplified, and the automation, reliability, and fault recovery capabilities of the system are improved. It is especially suitable for the main control system of satellite payloads with extremely high requirements for real-time performance and stability. This design reduces the system complexity and cost while significantly enhancing the system's adaptability and autonomous operation capabilities in complex environments.
[0096] Step 114, if the result of the software power-on loading is that both the programmable logic gate array and the digital signal processor fail to be powered on and loaded, generate a second reset instruction, and based on the second reset instruction, restart the main control system of the satellite payload.
[0097] In this way, the system automatically performs a restart operation and attempts to resume normal operation. Through this mutual monitoring and reset mechanism, this application effectively solves the problem of failed power-on loading of the DSP and FPGA, and improves the reliability and stability of the main control system of the satellite payload.
[0098] Through the above technical solutions,
[0099] When the main control system of the satellite payload needs in-orbit refueling, after downloading the software in-orbit refueling package to the idle Flash storage unit, the existing DSP and FPGA in the main control system of the satellite payload work together and control each other to perform a reset, so as to realize the switching of the current Flash storage unit to the idle Flash storage unit, and realize the smooth in-orbit refueling of the main control system of the satellite payload. Specifically, this solution realizes the in-orbit software in-orbit refueling function of the satellite payload control system through the mutual monitoring and reset mechanism of the DSP and FPGA, and avoids the problem of relying on an additional in-orbit refueling circuit in the traditional solution. When the FPGA is successfully powered on and loaded while the DSP fails to be loaded, the FPGA can actively reset the DSP to restart it from the external interface; conversely, if the DSP is successfully loaded while the FPGA fails to be loaded, the DSP resets the FPGA through the Flash switching program to reload the bitstream from the standby Flash storage unit. In addition, when both fail to be loaded, the system will automatically perform a restart operation to ensure that the system can resume normal operation. In this way, while improving the startup stability of the in-orbit software refueling of the satellite payload control system, there is no need to inject an additional new circuit structure, avoiding additional cost overhead and ensuring the reliability of the satellite payload control system.
[0100] To sum up, when the main control system of the satellite payload needs in-orbit refueling, this application realizes smooth in-orbit refueling through the cooperation of the DSP and FPGA without the need to additionally increase the in-orbit refueling circuit, which not only simplifies the hardware design, but also significantly improves the stability and reliability of the system, meeting the urgent needs of the main control system of the satellite payload for software update and function upgrade.
[0101] It should be added that, when the digital signal processor is successfully powered on and loaded, a watchdog signal is generated at specified time intervals in the digital signal processor and sent to the programmable logic gate array; and after the programmable logic gate array is successfully powered on and loaded, it monitors whether the programmable logic gate array has not received the watchdog signal beyond the specified time interval; if the programmable logic gate array has not received the watchdog signal beyond the specified time interval, a first reset signal is generated in the programmable logic gate array; based on the first reset signal, the digital signal processor is reset to cause the digital signal processor to be powered on and loaded again.
[0102] Specifically, when the DSP is running normally, it will periodically generate a watchdog signal and send it to the FPGA. This mechanism can monitor the running state of the DSP in real time to ensure its normal operation. If the FPGA does not receive the watchdog signal within the specified time interval, it is determined that the DSP is running abnormally, and a reset signal is generated to reset the DSP to cause it to be powered on and loaded again. This mechanism can quickly detect and recover from DSP faults, preventing the system from remaining in an abnormal state for a long time. Through the watchdog signal mechanism, the system can take timely measures when the DSP fails to prevent the spread of faults or system crashes, significantly improving the reliability and stability of the system. This mechanism does not require external intervention and is completely monitored and reset by the FPGA independently, enhancing the autonomous operation ability of the system, especially suitable for scenarios such as on-orbit satellites where manual intervention is difficult. The watchdog signal mechanism implemented by software does not require additional hardware circuits, simplifies the system design, and reduces costs and complexity. In extreme environments such as space, the DSP may malfunction due to factors such as radiation and temperature changes. The watchdog signal mechanism can effectively handle these situations to ensure the stable operation of the system in complex environments. In summary, this mechanism realizes real-time monitoring of the running state of the DSP and rapid fault recovery through the watchdog signal, improves the reliability, autonomy, and environmental adaptability of the system, while simplifying the hardware design and reducing costs.
[0103] Figure 2 The schematic diagram of the main control system of the satellite payload according to an embodiment of the present application is shown.
[0104] As Figure 2 shown, an embodiment of the present application provides a main control system for a satellite payload, which applies Figure 1 the software control and on-orbit refueling method for the main control system of the satellite payload, including: a digital signal processor, a programmable logic gate array, a first Flash storage unit, a second Flash storage unit, and a magnetic latching relay.
[0105] Among them, the digital signal processor runs its own startup program using an external interface to perform signal processing tasks for the main control system of the satellite payload.
[0106] The programmable logic gate array is used to load and execute a program for the main control system of the satellite payload and provide the external interface for the digital signal processor.
[0107] The first Flash storage unit and the second Flash storage unit are respectively connected to the programmable logic gate array, and both are used to store the bitstream data of the programmable logic gate array and the boot program and application program of the digital signal processor.
[0108] The magnetic latching relay is respectively connected to the first Flash storage unit and the second Flash storage unit, and is connected to the digital signal processor, and is configured to run a Flash switching program based on an instruction of the digital signal processor to switch the current Flash storage unit of the programmable logic gate array between the first Flash storage unit and the second Flash storage unit.
[0109] Among them, the programmable logic gate array and the digital signal processor are configured to perform a software power-on load again based on a software power-on load instruction, and the software power-on load instruction is generated in response to an action that the programmable logic gate array writes a software in-orbit reload package from a satellite management platform into a target Flash storage unit during the in-orbit reload process of the main control system software of the satellite payload, and the target Flash storage unit is an idle unit among the first Flash storage unit and the second Flash storage unit.
[0110] The programmable logic gate array is configured to pull the MP / MC pin of the digital signal processor that fails to power on load to the MP mode and then reset the digital signal processor when its own power-on load is successful, so that the digital signal processor restarts the corresponding running program from the external interface. The digital signal processor is configured to control the programmable logic gate array to reread the bitstream and start in the switched current Flash storage unit through the PROG_B_O pin of the programmable logic gate array after running the Flash switching program through the magnetic latching relay when its own power-on load is successful. The main control system of the satellite payload is configured to perform its own restart operation when both the programmable logic gate array and the digital signal processor fail to power on load.
[0111] Such as Figure 2As shown, during normal startup, the FPGA reads the program code stream from the Flash storage unit (Flash1 or Flash2) selected by the magnetic latching relay. After the FPGA program runs successfully, it pulls the MP / MC pin of the DSP to the MP mode (the pin is pulled up), and performs a hard reset on the DSP to make it start running the program from the external interface (XINTF) implemented by the FPGA.
[0112] In a possible design, the host computer sends an FPGA hard reset instruction, and the DSP performs a hard reset on the FPGA by controlling the PROG_B_O pin of the FPGA, and the main control system restarts.
[0113] In another possible design, after power-on, the DSP defaults to start in the MC state (the pin is pulled down) and starts from the internal OTP ROM of the DSP. The program in the OTP ROM executes simple timing logic. If the FPGA has not started normally after a certain time, the DSP will switch the Flash chip select and perform a hard reset on the FPGA to restart the system.
[0114] If the FPGA fails to start successfully, the DSP runs the FPGA Flash switching program from its internal OTP ROM, switches the Flash chip select of the FPGA through the magnetic latching relay after a certain delay, and resets the FPGA.
[0115] When it is necessary to switch the startup Flash, the DSP controls the Flash chip select signal through the magnetic latching relay and switches to the corresponding Flash storage unit. The DSP performs a hard reset on the FPGA through the PROG_B_O pin of the FPGA, and the FPGA reads the code stream again from the switched Flash and starts. On this basis, the process of the DSP resetting the FPGA includes: the host computer sends a DSP hard reset instruction, the DSP sends a hard reset signal to the FPGA, and the FPGA executes the corresponding logic to reset the DSP.
[0116] In another possible design, if the DSP program runs incorrectly and fails to send a watchdog signal to the FPGA periodically, the FPGA will passively execute the DSP hard reset logic to reset the DSP.
[0117] The above describes the complete processes of boot startup, program operation, slicing function, reset logic, and in-orbit refueling logic in the main control system of the satellite payload. Through the collaborative work of the DSP and the FPGA, the system can achieve automatic reset and in-orbit refueling under different fault scenarios, ensuring the high reliability and stability of the main control system of the satellite payload.
[0118] Optionally, the FPGA uses the XC7K325T chip. The XC7K325T chip supports high-speed signal processing and complex algorithm implementation, and is suitable for high-performance applications such as communication, radar, and image processing. It adopts 28nm process technology with low power consumption, and is suitable for power-sensitive application scenarios. Moreover, the XC7K325T chip has rich programmable logic resources, supports user-defined functions, can adapt to various application requirements, is applicable to high-reliability fields such as aerospace, and supports radiation-hardened design and fault-tolerant mechanisms. In the present invention, as one of the core components, the XC7K325T, through collaborative work with the DSP, realizes the efficient boot, operation, and fault recovery functions of the satellite payload main control system, significantly improving the reliability and flexibility of the system.
[0119] Optionally, the DSP uses the F2812 chip. The F2812 chip is a 32-bit fixed-point digital signal processor with a main frequency of 150MHz and 32-bit fixed-point arithmetic capabilities. It is suitable for complex control algorithms and signal processing tasks, supports high-precision data acquisition and motor control, is applicable to industrial environments and aerospace fields, and supports anti-interference design and fault-tolerant mechanisms. In the present invention, as one of the core components, the F2812, through collaborative work with the FPGA, realizes the efficient boot, operation, and fault recovery functions of the satellite payload main control system, significantly improving the reliability and flexibility of the system.
[0120] The embodiment of the present application provides a software control and on-orbit refueling device for a satellite payload main control system, including:
[0121] A software on-orbit refueling instruction acquisition unit, configured to acquire a software on-orbit refueling instruction from a satellite management platform;
[0122] An on-orbit refueling package writing unit, configured to, in response to the software on-orbit refueling instruction, download the software on-orbit refueling package of the satellite management platform, and write the software on-orbit refueling package into a target Flash storage unit through a programmable logic gate array, where the target Flash storage unit is currently in an idle state;
[0123] A power-on loading instruction generation unit, configured to generate a software power-on loading instruction in response to the completion of writing of the software on-orbit refueling package, where the software power-on loading instruction instructs to perform a power-on reload from the target Flash storage unit;
[0124] A power-on loading execution unit, based on the software power-on loading instruction, performs software power-on loading on the programmable logic gate array and the digital signal processor;
[0125] The first execution unit is configured to, if the result of the software power-on loading is that the power-on loading of the programmable logic gate array is successful and the power-on loading of the digital signal processor fails, call the programmable logic gate array to reset the digital signal processor;
[0126] The second execution unit is configured to, if the result of the software power-on loading is that the power-on loading of the digital signal processor is successful and the power-on loading of the programmable logic gate array fails, generate a first reset instruction for the programmable logic gate array, and based on the first reset instruction, call the digital signal processor to reset the programmable logic gate array;
[0127] The third execution unit is configured to, if the result of the software power-on loading is that both the programmable logic gate array and the digital signal processor fail in power-on loading, generate a second reset instruction, and based on the second reset instruction, restart the main control system of the satellite payload.
[0128] In an embodiment of the present application, optionally, the first execution unit is configured to:
[0129] Pull the MP / MC pin of the digital signal processor to the MP mode through the programmable logic gate array, reset the digital signal processor, and enable the digital signal processor to start the corresponding running program from the external interface provided by the programmable logic gate array.
[0130] In an embodiment of the present application, optionally, the device further includes:
[0131] A watchdog signal reporting unit, configured to generate a watchdog signal in the digital signal processor at each specified time interval and send the watchdog signal to the programmable logic gate array when the power-on loading of the digital signal processor is successful; and
[0132] A monitoring unit, configured to monitor whether the programmable logic gate array has not received the watchdog signal beyond the specified time interval after the power-on loading of the programmable logic gate array is successful;
[0133] The fourth execution unit is configured to, if the programmable logic gate array has not received the watchdog signal beyond the specified time interval, generate a first reset signal in the programmable logic gate array, and based on the first reset signal, reset the digital signal processor to enable the digital signal processor to be re-powered on and loaded.
[0134] In an embodiment of the present application, optionally, the second execution unit includes:
[0135] A Flash switching unit, configured to, based on the first reset instruction, run a Flash switching program through the digital signal processor via a magnetic latching relay, and switch a first Flash storage unit currently accessed by the programmable logic gate array to a standby second Flash storage unit, where the second Flash storage unit is the target Flash storage unit;
[0136] A restart execution unit, configured to send a second reset signal to the programmable logic gate array through the PROG_B_O pin of the programmable logic gate array via the digital signal processor, so that in response to obtaining the second reset signal, the programmable logic gate array reads the code stream again in the second Flash storage unit and starts up.
[0137] In an embodiment of the present application, optionally, the loading result determination unit includes:
[0138] A timing monitoring unit, configured to, after the digital signal processor is successfully powered on and loaded, perform startup monitoring timing on the programmable logic gate array through the OTP ROM of the digital signal processor;
[0139] A timing judgment unit, configured to determine that the power-on loading of the programmable logic gate array fails if the timing duration of the startup monitoring timing exceeds a predetermined time threshold.
[0140] This device uses the solution described in any one of the above embodiments, and thus has all the above technical effects, which will not be elaborated here.
[0141] In addition, an embodiment of the present application provides a computer-readable storage medium storing computer-executable instructions, and the computer-executable instructions are used to perform the following steps:
[0142] Obtain a software in-orbit reloading instruction from a satellite management platform;
[0143] In response to the software in-orbit reloading instruction, download a software in-orbit reloading package of the satellite management platform, and write the software in-orbit reloading package into a target Flash storage unit through the programmable logic gate array, where the target Flash storage unit is currently in an idle state;
[0144] In response to the completion of writing the software in-orbit reloading package, generate a software power-on loading instruction, where the software power-on loading instruction instructs to perform a re-power-on loading from the target Flash storage unit;
[0145] Based on the software power-on loading instruction, perform software power-on loading on the programmable logic gate array and the digital signal processor;
[0146] If the result of the software power-on loading is that the programmable logic gate array is successfully powered on and loaded, and the digital signal processor fails to be powered on and loaded, call the programmable logic gate array to reset the digital signal processor;
[0147] If the result of the software power-on loading is that the digital signal processor is successfully powered on and loaded, and the programmable logic gate array fails to be powered on and loaded, generate a first reset instruction for the programmable logic gate array, and based on the first reset instruction, call the digital signal processor to reset the programmable logic gate array;
[0148] If the result of the software power-on loading is that both the programmable logic gate array and the digital signal processor fail to be powered on and loaded, generate a second reset instruction, and based on the second reset instruction, restart the satellite payload main control system.
[0149] It should be noted that the functions or steps that can be realized by the above computer-readable storage medium or computer device can be correspondingly referred to the relevant descriptions in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0150] The technical solution of the present application has been described in detail above with reference to the drawings. When the satellite payload main control system needs in-orbit refueling, after downloading the software in-orbit refueling package to the idle Flash storage unit, the existing DSP and FPGA in the satellite payload main control system work together to control each other to reset, so as to realize switching the current Flash storage unit to the idle Flash storage unit, and realize the smooth in-orbit refueling of the satellite payload main control system. At the same time, there is no need to additionally increase the in-orbit refueling circuit, which not only simplifies the hardware design, but also significantly improves the stability and reliability of the system, and meets the urgent needs of the satellite payload main control system for software update and function upgrade.
[0151] It should be understood that although the terms first, second, etc. may be used in the embodiments of the present application to reset signals, these reset signals should not be limited to these terms. These terms are only used to distinguish the reset signals from each other. For example, without departing from the scope of the embodiments of the present application, the first reset signal may also be referred to as the second reset signal, and similarly, the second reset signal may also be referred to as the first reset signal.
[0152] Depending on the context, the word "if" as used herein can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".
[0153] The terms used in the embodiments of the present application are for the purpose of describing specific embodiments only and are not intended to limit the present application. The singular forms "a", "the" and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise.
[0154] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical or other forms.
[0155] In addition, each functional unit in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0156] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database or other medium used in the various embodiments provided by the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0157] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A software control and on-orbit refueling method for a satellite payload main control system, the satellite payload main control system comprising a programmable logic gate array and a digital signal processor, characterized in that, Including: Obtaining an on-orbit software reload instruction from a satellite management platform; In response to the on-orbit software reload instruction, downloading an on-orbit software reload package of the satellite management platform, and writing the on-orbit software reload package into a target Flash storage unit through a programmable logic gate array, wherein the target Flash storage unit is currently in an idle state; In response to the completion of writing the on-orbit software reload package, generating a software power-on loading instruction, wherein the software power-on loading instruction instructs to perform a power-on reload from the target Flash storage unit; Based on the software power-on loading instruction, performing software power-on loading on the programmable logic gate array and the digital signal processor; If the result of the software power-on loading is that the programmable logic gate array is successfully powered on and the digital signal processor fails to be powered on, calling the programmable logic gate array to reset the digital signal processor; If the result of the software power-on loading is that the digital signal processor is successfully powered on and the programmable logic gate array fails to be powered on, generating a first reset instruction for the programmable logic gate array, and based on the first reset instruction, calling the digital signal processor to reset the programmable logic gate array; If the result of the software power-on loading is that both the programmable logic gate array and the digital signal processor fail to be powered on, generating a second reset instruction, and based on the second reset instruction, restarting the satellite payload main control system.
2. The method according to claim 1, wherein The calling the programmable logic gate array to reset the digital signal processor includes: Pulling the MP / MC pin of the digital signal processor to the MP mode through the programmable logic gate array to reset the digital signal processor, so that the digital signal processor starts a corresponding running program from an external interface provided by the programmable logic gate array.
3. The method according to claim 2, wherein Also including: When the digital signal processor is successfully powered on, generating a watchdog signal at a specified time interval in the digital signal processor, and sending the watchdog signal to the programmable logic gate array; And After the programmable logic gate array is successfully powered on, monitoring whether the programmable logic gate array has not received the watchdog signal beyond the specified time interval; If the programmable logic gate array has not received the watchdog signal beyond the specified time interval, generating a first reset signal in the programmable logic gate array; Based on the first reset signal, resetting the digital signal processor to cause the digital signal processor to perform a power-on reload.
4. The method according to any one of claims 1 to 3, characterized in that, The calling the digital signal processor to reset the programmable logic gate array based on the first reset instruction includes: Based on the first reset instruction, running a Flash switching program through the digital signal processor via a magnetic latching relay to switch a first Flash storage unit currently accessed by the programmable logic gate array to a standby second Flash storage unit, and the second Flash storage unit is the target Flash storage unit; Send a second reset signal to the programmable logic gate array through the PROG_B_O pin of the programmable logic gate array by the digital signal processor, so that the programmable logic gate array responds to the acquisition of the second reset signal, reads the code stream again in the second Flash storage unit and starts up.
5. The method according to claim 4, wherein The determination of the result of the software power-on loading of the satellite payload main control system further includes: After the digital signal processor is successfully powered on and loaded, start monitoring the timing of the programmable logic gate array through the OTP ROM of the digital signal processor; If the timing duration of the start monitoring timing exceeds a predetermined time threshold, it is determined that the power-on loading of the programmable logic gate array fails.
6. A software control and on-orbit refueling device for the main control system of satellite payloads, characterized in that, Includes: A software in-orbit refueling instruction acquisition unit for acquiring a software in-orbit refueling instruction from a satellite management platform; An in-orbit refueling package writing unit for downloading the software in-orbit refueling package of the satellite management platform in response to the software in-orbit refueling instruction, and writing the software in-orbit refueling package into a target Flash storage unit through the programmable logic gate array, wherein the target Flash storage unit is currently in an idle state; A power-on loading instruction generation unit for generating a software power-on loading instruction in response to the completion of the writing of the software in-orbit refueling package, wherein the software power-on loading instruction instructs to perform a re-power-on loading from the target Flash storage unit; A power-on loading execution unit for performing software power-on loading on the programmable logic gate array and the digital signal processor based on the software power-on loading instruction; A first execution unit for, if the result of the software power-on loading is that the power-on loading of the programmable logic gate array is successful and the power-on loading of the digital signal processor fails, calling the programmable logic gate array to reset the digital signal processor; A second execution unit for, if the result of the software power-on loading is that the power-on loading of the digital signal processor is successful and the power-on loading of the programmable logic gate array fails, generating a first reset instruction for the programmable logic gate array, and based on the first reset instruction, calling the digital signal processor to reset the programmable logic gate array; A third execution unit for, if the result of the software power-on loading is that the power-on loadings of both the programmable logic gate array and the digital signal processor fail, generating a second reset instruction, and based on the second reset instruction, restarting the satellite payload main control system.
7. The device according to claim 6, characterized in that The first execution unit is used for: Pull the MP / MC pin of the digital signal processor to the MP mode through the programmable logic gate array to reset the digital signal processor, so that the digital signal processor starts the corresponding running program from the external interface provided by the programmable logic gate array.
8. The device according to claim 7, characterized in that The device further includes: A watchdog signal reporting unit for generating a watchdog signal in the digital signal processor at each specified time interval and sending the watchdog signal to the programmable logic gate array when the digital signal processor is successfully powered on and loaded; and The monitoring unit is used to monitor whether the programmable logic gate array fails to receive the watchdog signal beyond the specified time interval after the programmable logic gate array is successfully powered on and loaded; The fourth execution unit is used to generate a first reset signal in the programmable logic gate array if the programmable logic gate array fails to receive the watchdog signal beyond the specified time interval, and reset the digital signal processor based on the first reset signal to cause the digital signal processor to be powered on and loaded again.
9. A main control system for satellite payloads, characterized in that, Applying the software control and on-orbit refueling method for the satellite payload main control system according to any one of claims 1 to 5 above, including: The digital signal processor runs its own startup program using an external interface and is used to execute signal processing tasks for the satellite payload main control system; The programmable logic gate array is used to load and execute programs for the satellite payload main control system and provide the external interface for the digital signal processor; The first Flash storage unit and the second Flash storage unit are respectively connected to the programmable logic gate array, and both the first Flash storage unit and the second Flash storage unit are used to store the bitstream data of the programmable logic gate array and the boot program and application program of the digital signal processor; The magnetic latching relay is respectively connected to the first Flash storage unit and the second Flash storage unit and is connected to the digital signal processor, and is configured to run a Flash switching program based on the instruction of the digital signal processor to switch the current Flash storage unit of the programmable logic gate array between the first Flash storage unit and the second Flash storage unit; Wherein, the programmable logic gate array and the digital signal processor are configured to perform software power-on and loading again based on a software power-on and loading instruction, and the software power-on and loading instruction is generated in response to the action that the programmable logic gate array writes the software on-orbit refueling package from the satellite management platform into the target Flash storage unit during the on-orbit refueling process of the satellite payload main control system software, and the target Flash storage unit is the idle unit among the first Flash storage unit and the second Flash storage unit; The programmable logic gate array is configured to pull the MP / MC pin of the digital signal processor that fails to be powered on and loaded to the MP mode after its own power-on and loading is successful, and then reset the digital signal processor to cause the digital signal processor to restart the corresponding running program from the external interface; The digital signal processor is configured to run a Flash switching program through the magnetic latching relay after its own power-on and loading is successful, and then control the programmable logic gate array to re-read the bitstream and start in the switched current Flash storage unit through the PROG_B_O pin of the programmable logic gate array; The satellite payload main control system is configured to perform its own restart operation when both the programmable logic gate array and the digital signal processor fail to be powered on and loaded.
10. A computer-readable storage medium, characterized in that, Stores computer-executable instructions configured to perform the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Configuration method and system used for satellite-bone SRAM (Static Random Access Memory) type FPGA (Field Programmable Gate Array) working on track for long time
CN102779079A
Satellite in-orbit program re-injection system
CN107203399A
In-orbit reorganization method for satellite-borne load unit software
CN108052355A
Program on-orbit loading refreshing method based on triple modular redundancy
CN111176908A
ZYNQ on-orbit loading reconstruction method and system oriented to commercial satellite field
CN116302635A