High-reliability data storage monitoring device and method for embedded equipment

By using a storage device with a combination of NVM and FLASH in embedded devices, combined with CRC checksum majority voting strategies, the data error problem caused by single-particle flip is solved, and data storage with high reliability and flexibility is achieved, improving the airworthiness of the equipment.

CN120492218APending Publication Date: 2025-08-15JINCHENG NANJING ELECTROMECHANICAL HYDRAULIC PRESSURE ENG RES CENT AVIATION IND OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510537205.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Traditional data storage methods are susceptible to single-particle flip in extreme environments, resulting in data errors, affecting embedded device control, and insufficient storage space or speed, which cannot meet the storage requirements of complex systems.

Method used

A storage device composed of multiple memory chips, including NVM and FLASH, uses CRC checksum majority voting strategies to realize redundant storage and data monitoring, and enhance the anti-single-particle flip capability.

Benefits of technology

It improves the reliability and flexibility of data storage, meets the storage requirements of complex systems, reduces costs, and enhances the airworthiness of embedded devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120492218A_ABST
    Figure CN120492218A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of aviation electromechanical control. Relates to a high-reliability data storage monitoring device and method for embedded equipment. The device is specifically a storage module, the storage module comprises a first storage chip, a second storage chip and a third storage chip, the storage content of each chip is reasonably configured through a mode of combining NVM and FLASH of the two chips, rapid storage of fault data can be guaranteed, huge data operated by equipment can be stored, the stored data is more comprehensive, and the storage efficiency is improved. And data support is provided for later equipment maintenance and troubleshooting. According to the method, the multiple storage chips are combined with the strategy of controlling program backup and majority voting, redundant storage of data is achieved, the reliability of stored data is improved, and the single event upset resistance is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of aviation electromechanical control and relates to a high-reliability data storage and monitoring device and method for embedded devices. Background Art

[0002] In the civil aviation field, affected by extreme environments such as space radiation, when high-energy charged particles pass through the chip, transient charges may be generated on the memory cells in the chip, thereby interfering with the data stored in the memory cells, i.e., single-particle upsets. Traditional data storage methods are easily affected by single-particle upsets, resulting in storage data errors, affecting the control of the entire embedded device, threatening the safety of the aircraft, and limiting the airworthiness of embedded devices in the civil aviation field. At the same time, traditional data storage methods either have less storage space or slower storage speeds, and are unable to meet the storage requirements of complex systems. It is difficult to provide comprehensive, standardized, and accurate system data for later system operation monitoring and troubleshooting. Therefore, the present invention proposes a storage device and storage strategy based on multiple memory chips to enhance the ability of embedded devices to resist single-particle upsets, ensure the reliability of data storage detection, and improve the airworthiness of embedded devices. Summary of the Invention

[0003] Purpose of the Invention

[0004] The present invention provides a data storage monitoring method suitable for embedded devices, aiming to solve the problems of less storage data and poor reliability of traditional storage methods and improve the ability of embedded devices to resist single event upsets.

[0005] Technical Solution

[0006] A high-reliability data storage and monitoring device for embedded devices, the device being specifically a storage module comprising a first storage chip, a second storage chip, and a third storage chip. The first storage chip is used to store product fault data and control data, while the second and third storage chips have the same function of storing product operation cycle data, backup programs, and control data. The control data is used for majority voting. High-reliability device control and data storage monitoring are achieved through the redundant design of the first, second, and third storage chips, combined with CRC checking and a majority voting strategy.

[0007] Furthermore, the first storage chip is specifically an NVM.

[0008] Furthermore, the second storage chip and the third storage chip are specifically FLASH.

[0009] Furthermore, before the device is powered on, a CRC check is performed on the control program in the on-chip FLASH. If the check fails, the backup program in the external FLASH is called;

[0010] Furthermore, the key control data of the device is determined by majority voting between NVM and external FLASH;

[0011] Furthermore, the data in the NVM and the external FLASH can be matched and analyzed through the system running time.

[0012] A high-reliability data storage monitoring method for an embedded device comprises the following steps:

[0013] Step 1: Before entering the control state, the embedded device confirms that the hardware device is normal and verifies the control program in the on-chip storage unit to identify single-particle upset issues. Specifically: The system is powered on and each module is initialized. After initialization, a power-on self-test is performed to check whether the embedded device's data acquisition, communication, storage and other modules are normal. A cyclic redundancy check is also performed on the control program in the embedded device's on-chip memory. If the check fails, step 2 is executed; if the check passes, step 3 is executed.

[0014] Step 2: The embedded device identifies a control program error caused by a single-event upset in the on-chip memory and takes appropriate redundancy measures. Specifically, it reads the backup control program from the second memory chip, FLASH, and performs a CRC check. If the check succeeds, the backup control program is copied to the embedded on-chip memory. If the check fails, the backup control program is read from the third memory chip, FLASH, and the process is repeated.

[0015] Step 3: After both the embedded software and hardware power-on self-tests pass normally, the device enters normal control mode. During normal operation, the device stores operational data in the second and third memory chips at regular intervals. This operational data includes instructions received from the host computer, data from various sensors, device operating time, power-on and power-off times, and periodic test results.

[0016] Step 4: During normal operation, monitor key functions at regular intervals. If abnormal data is detected, a periodic fault detection report is issued, and key data before and after the fault is stored in NVM. Key functions should include communication, data acquisition, and interrupt functions; key data should include device control status, module temperature, module voltage and current, and periodic detection results.

[0017] Step 5: During normal operation of the device, if no problems are found in the periodic detection, the control data in the NVM and two external FLASH are read. After comparing these three sets of control data, a majority vote is performed and the final control data is output to the controller for execution;

[0018] Furthermore, step 6 is included: after the device is operating normally, the maintenance function is entered to download the NVM and external FLASH storage data, and the fault data in the NVM is matched with the normal operating data of the external FLASH according to the device working time to analyze the cause of the system fault.

[0019] The beneficial effects of this application are:

[0020] Compared to traditional single-chip memory devices, this device can fully leverage the advantages of NVM storage data read and write speeds and FLASH storage space, complementing each other to achieve performance optimization. It has strong flexibility and scalability, and can meet the storage requirements of complex systems and environments. At the same time, compared to single memory chips with fast read and write speeds and large capacity, this device can reduce costs and improve efficiency.

[0021] Compared with traditional storage strategies, this method has the following benefits:

[0022] 1. By combining two chips and rationally configuring the storage content of each chip, it can not only ensure the rapid storage of fault data, but also store the huge data of equipment operation, making the stored data more comprehensive and providing data support for later equipment maintenance and troubleshooting.

[0023] 2. Through multiple memory chips combined with control program backup and majority voting strategies, redundant data storage is achieved, the reliability of stored data is improved, and the ability to resist single-particle upset is increased.

[0024] This method is also applicable to the aerospace field and is used to improve the single-event upset resistance of spacecraft equipment. It has good scalability. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is the data flow diagram of embedded devices and storage modules;

[0026] Figure 2 It is a flow chart. DETAILED DESCRIPTION

[0027] In order to make the purpose, technical solutions and advantages of the implementation of the present invention clearer, the technical solutions in the embodiments of the present invention will be described in more detail below in conjunction with the embodiments of the present invention. In the examples, the same or similar reference numerals throughout represent the same or similar originals or elements with the same or similar functions. The described embodiments are part of the embodiments of the present invention, not all of the embodiments. The embodiments described below by reference are illustrative and intended to be used to explain the present invention, and should not be understood as limiting the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. The following is a detailed description in conjunction with the embodiments of the present invention.

[0028] like Figure 1 As shown, the present invention provides a reliability data storage monitoring method applicable to embedded devices, comprising:

[0029] 1. NVM module: NVM mainly stores control data and pre- and post-fault data, and communicates with embedded devices via 422. NVM chips have the advantage of fast storage speed, allowing for rapid recording of pre- and post-fault data.

[0030] 2. External FLASH Module: The external FLASH mainly stores backup control programs, periodic operation data, and control data. The external FLASH module has a large storage space, which can store the system's periodic operation data. At the same time, the backup control program can also replace the original control program if the CRC check of the on-chip program fails, achieving redundancy.

[0031] 3. Control data acquisition: When the device performs system control, it reads control data from the NVM and external FLASH, and after a majority vote, inputs the control data into the controller for system control.

[0032] The technical solution of the present invention includes performing CRC check before system control and mobilizing the backup control program in the external FLASH if the check fails, thereby improving the single-particle upset resistance of the embedded device; using NVM and external FLASH chips as storage modules to realize the storage of fault data and periodic operation data of the embedded device; and improving the reliability of the control data by reading the control data in the NVM and external FLASH and performing majority voting.

[0033] The present invention provides a reliability data storage monitoring method applicable to embedded devices, such as Figure 2 Shown, including:

[0034] Step 1: Power on the system and perform a CRC check on the control program in the on-chip memory of the embedded device. If the check fails, proceed to step 2; if the check passes, proceed to step 3;

[0035] Step 2: Read the backup control program in an external FLASH and copy the backup control program to the embedded on-chip memory;

[0036] Step 3: Store the system operation data periodically into two external FLASHs;

[0037] Step 4: Periodically monitor key functions. If a fault occurs, store the key data before and after the fault in NVM.

[0038] Step 5: Read the control data from the NVM and two external FLASHs, perform a majority vote, and then output it to the controller for execution.

[0039] Step 6: Enter the maintenance function and download the NVM and external FLASH storage data. Based on the system working time, match the NVM system fault data with the external FLASH system operation data to analyze the cause of the system fault.

[0040] Step 7: End.

[0041] Example 1:

[0042] In the specific implementation on the DSP28335 platform, we use external NVM (SM14CA8-NF45) and external FLASH (SM25P64) chips as storage modules, accessed through address mapping and SPI communication respectively. The following are the specific implementation steps and detailed description:

[0043] Step 1: Power on the controller and perform a CRC check on the control program stored in the on-chip FLASH. If it fails, the control program in the external FLASH is copied to the on-chip FLASH.

[0044] Step 2: The controller executes the control program and periodically monitors key functions. If a fault occurs, the data before and after the fault is stored in NVM in 50ms.

[0045] Step 3: Store the system operation data into two external FLASHs with a period of 1s;

[0046] Step 4: Read the control data from the NVM and two external FLASHs, perform a majority vote, and then output it to the controller for execution.

[0047] Step 5: Enter the maintenance function and download the NVM and external FLASH storage data. Based on the system working time, match the NVM system fault data with the external FLASH system operation data to analyze the cause of the system fault.

[0048] Step 6: End.

[0049] Example 2

[0050] A high-reliability data storage and monitoring device for embedded devices, the device being specifically a storage module, comprising a first storage chip, a second storage chip, and a third storage chip. The first storage chip is used to store product fault data and control data, the second storage chip and the third storage chip have the same function, and are used to store product operation cycle data, backup programs, and control data. The control data is used for majority voting. Through the redundant design of the first storage chip, the second storage chip, and the third storage chip, combined with CRC checking and majority voting strategies, high-reliability device control and data storage monitoring are achieved, thereby improving the embedded device's ability to resist single-particle upsets.

[0051] In one embodiment of the present invention, the first storage chip is specifically an NVM. NVM has the advantages of radiation resistance, long service life, and fast read and write speed, and can be used to store data before and after a failure of an embedded device.

[0052] In one embodiment of the present invention, the second storage chip and the third storage chip are specifically FLASH, which has the advantages of large capacity, long life, low power consumption, etc., and can be used to store backup control programs and equipment operation data.

[0053] A high-reliability data storage monitoring method for an embedded device comprises the following steps:

[0054] Step 1: Before entering the control state, the embedded device confirms that the hardware is functioning properly and verifies the control program in the on-chip memory unit to identify single-event upsets. Specifically: The system is powered on and each module is initialized. After initialization, a power-on self-test is performed to check whether the embedded device's data acquisition, communication, and storage modules are functioning properly. A cyclic redundancy check (CRC) is also performed on the control program in the embedded device's on-chip memory. If the check fails, step 2 is executed; if the check passes, step 3 is executed. (This step can identify problems such as hardware damage and incorrect on-chip control programs, effectively preventing safety hazards caused by software and hardware damage.)

[0055] Step 2: The embedded device identifies a control program error caused by a single-particle upset in the on-chip memory and takes corresponding redundancy measures. Specifically, it reads the backup control program in the second memory chip FLASH and performs a CRC check. If the check succeeds, the backup control program is copied to the embedded on-chip memory. If the check fails, the backup control program in the third memory chip FLASH is read and the steps are repeated. (This step can reduce the impact of the control program on the single-particle upset caused by the on-chip memory program error by copying the backup control program, thereby achieving redundancy and improving the ability to resist single-particle upsets.)

[0056] Step 3: After the embedded software and hardware power-on self-tests are normal, the device enters the normal control mode. During normal operation, the device stores the operating data in the second storage chip and the third storage chip respectively according to a fixed period. The operating data includes instructions received from the host computer, data from each sensor, device operating time, power-on and power-off times, periodic detection results, etc. (This step can monitor the operating data of the embedded device and perform backup storage to improve the reliability of the stored data. The operating data can also be used to analyze the device status, further optimize the control program, and improve the performance of the device).

[0057] Step 4: During normal equipment operation, key functions are monitored at fixed intervals. If abnormal data is found, a periodic fault detection report is issued, and key data before and after the fault is stored in NVM. Key functions should include communication functions, data acquisition functions, interrupt functions, etc. Key data should include equipment control status, module temperature, module voltage and current, and periodic test results. (This step quickly identifies equipment faults through periodic monitoring and records data before and after the fault, providing a basis for subsequent fault cause analysis and fault location.)

[0058] Step 5: During normal operation, if no problems are found in the periodic detection, the control data in the NVM and two external FLASH are read. After comparing these three sets of control data and performing a majority vote, the final control data is output to the controller for execution. (This step reduces the impact of a single-event upset on a single memory chip by storing the control data in three memory chips and using a majority vote strategy, ensuring the accuracy of the control data and enhancing the ability to resist single-event upsets.)

[0059] Step 6: After the device is operating normally, enter the maintenance function and download the data stored in NVM and external FLASH. Based on the device's operating time, match the fault data in NVM with the normal operating data of the external FLASH to analyze the cause of the system failure. (This step is for post-maintenance. After a device failure occurs, the content stored in different memory chips can be correlated and analyzed. This allows for quick and accurate analysis of the cause of the failure, fault location, and optimization of the control program.)

[0060] Step 7: End.

[0061] In addition, unless otherwise defined, the technical or scientific terms used in the description of this application should have the ordinary meanings understood by those of ordinary skill in the art to which this application belongs. The words "upper," "lower," "left," "right," "center," "vertical," "horizontal," "inner," and "outer" used in the description of this application are only used to indicate relative directions or positional relationships, and do not imply that the device or component must have a specific orientation, be constructed, or operate in a specific orientation. When the absolute position of the described object changes, its relative positional relationship may also change accordingly. Therefore, they should not be understood as limitations on this application. The words "first," "second," "third," and similar terms used in the description of this application are used only for descriptive purposes to distinguish different components and should not be understood to indicate or imply relative importance. The words "one," "an," or "the" used in the description of this application should not be understood as absolute limitations on quantity, but should be understood as meaning the presence of at least one. The words "include" or "comprises" used in the description of this application mean that the element or object listed before the word includes the elements or objects listed after the word and their equivalents, but does not exclude other elements or objects.

[0062] In addition, it should be noted that, unless otherwise clearly stipulated and limited, the words "install", "connect", "connect" and similar terms used in the description of this application should be understood in a broad sense. For example, the connection can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, an indirect connection through an intermediate medium, or a connection between two components. Technical personnel in the field can understand their specific meanings in this application according to the specific circumstances.

[0063] The above description is only a specific embodiment of the present invention and is not intended to limit the present invention. Within the spirit and principles of the present invention, any technician familiar with the profession may use the technical content disclosed above to change or modify it into an equivalent embodiment with equivalent changes and apply it to other fields. However, any simple modification, equivalent change and modification made to the above embodiment based on the technical essence of the present invention without departing from the content of the technical solution of the present invention, any modification, equivalent replacement, improvement, etc. made should be included in the scope of protection of the present invention.

Claims

1. A high-reliability data storage and monitoring device for embedded devices, characterized in that: The device is specifically a storage module, which includes a first storage chip, a second storage chip, and a third storage chip. The first storage chip is used to store product fault data and control data. The second storage chip and the third storage chip have the same function and are used to store product operation cycle data, backup programs and control data. The control data is used for majority voting. Through the redundant design of the first storage chip, the second storage chip, and the third storage chip, combined with CRC check and majority voting strategy, high-reliability equipment control and data storage monitoring are achieved.

2. The device according to claim 1, wherein The first storage chip is specifically an NVM.

3. The device according to claim 1, wherein The second storage chip and the third storage chip are specifically FLASH.

4. The device according to claim 1, wherein Before powering on the device, a CRC check is performed on the control program in the on-chip FLASH. If the check fails, the backup program in the external FLASH is called.

5. The device according to claim 1, wherein The key control data of the device is determined by majority voting between NVM and external FLASH.

6. The device according to claim 1, wherein The data in NVM and external FLASH can be matched and analyzed through system runtime.

7. A high-reliability data storage monitoring method for embedded devices using the apparatus of claim 1, characterized in that: The following steps are involved: Step 1: Before entering the control state, the embedded device confirms whether the hardware device is normal and verifies the control program on the on-chip storage unit to identify single-event upset problems. Specifically: the system is powered on and each module is initialized. After initialization, a power-on self-test is performed to check whether the embedded device's data acquisition, communication, and storage modules are normal. A cyclic redundancy check is also performed on the control program in the embedded device's on-chip memory. If the check fails, step 2 is executed; if the check passes, step 3 is executed. Step 2: The embedded device identifies a control program error caused by a single-event upset in the on-chip memory and takes appropriate redundancy measures. Specifically, the device reads the backup control program in the second memory chip FLASH and performs a CRC check. If the check succeeds, the backup control program is copied to the embedded on-chip memory. If the check fails, the device reads the backup control program in the third memory chip FLASH and repeats the steps. Step 3: After the embedded software and hardware power-on self-tests are normal, the device enters the normal control mode. During normal operation, the device stores the operating data in the second storage chip and the third storage chip respectively according to a fixed period. The operating data includes the instructions sent by the host computer, the data of each sensor, the device operating time, the number of power-on and power-off times, and the periodic detection results. Step 4: During normal operation of the device, key functions are monitored at fixed intervals. If abnormal data is found, a periodic fault detection is reported, and key data before and after the fault is stored in NVM. The key functions should include communication function, data acquisition function, and interrupt function. The key data should include device control status, temperature of each module, voltage and current of each module, and periodic detection results. Step 5: During normal operation of the device, if no problems are found in the periodic detection, the control data in the NVM and the two external FLASH are read. After comparing these three sets of control data and performing a majority vote, the final control data is output to the controller for execution.

8. The method according to claim 7, wherein It also includes step 6: after the device is operating normally, enter the maintenance function, download the NVM and external FLASH storage data, match the fault data in the NVM with the normal operating data of the external FLASH according to the device working time, and analyze the cause of the system fault.