On-orbit autonomous health management and fault recovery method and device for responder
Through the transponder's on-orbit health management method of satellite real-time monitoring and dynamic mode switching, the communication interruption caused by single-particle flip of the transponder is solved, the transponder's on-orbit life and protection capabilities are improved, and the maintenance cost is reduced.
Patent Information
- Application Number
- CN202510868835.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-09-05
AI Technical Summary
Existing transponders are susceptible to spatial radiation when operating in orbit, and the probability of single-particle flip failure is high, resulting in interruption of communication links. The existing protection strategies lack dynamic response capabilities and frequent operations accelerate device aging, increasing maintenance costs and security risks.
Through satellite in-orbit real-time monitoring of the transponder, single-particle recovery measures are implemented in hierarchical stages, the transponder status is judged in real time based on telemetry data, dynamically switch working modes, reduce frequent reset and switching operations, and improve independent control flexibility and life.
The intelligent health management of transponders on-orbit health has been realized, the on-orbit working life of transponders has been improved, the impact of frequent operations has been reduced, the protection capability of on-orbit functions has been enhanced, and the maintenance costs and risks have been reduced.
Smart Images

Figure CN120601946A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of aerospace electronic technology, and in particular relates to a method and device for autonomous on-orbit health management and fault recovery of a transponder. Background Art
[0002] As the core device for communication between satellites and ground tracking and control stations, relay satellites, etc., the performance of the transponder is directly related to the operational safety and mission execution of the spacecraft. The current transponder hardware design uses a technical solution that combines large-scale reconfigurable FPGA devices with high-speed AD acquisition chips. Although this solution is highly integrated and reconfigurable, it is limited by the manufacturing process level of large-scale reconfigurable FPGAs, making the transponder extremely susceptible to the space radiation environment during on-orbit operation. Under the bombardment of high-energy particles in space, the probability of single-event upsets (SEUs) in FPGA devices increases significantly. Once a single-event upset fault occurs in a critical logic unit, it will directly lead to the interruption of the communication link between the satellite and the ground, posing a serious threat to the normal operation of the satellite. In the existing on-orbit protection system, the transponder's protection strategy mainly relies on satellite on-orbit periodic refresh, FPGA reload, or reset operation when the satellite flies over high-risk radiation areas such as the North and South Poles. The above protection measures have significant limitations: First, the protection mechanism is too fixed and lacks the ability to dynamically respond to different fault scenarios, making it difficult to achieve precise protection; second, frequent switching and resetting operations will not only interfere with the normal operation of the satellite, but also accelerate the aging of the transponder's internal components, shorten the equipment's on-orbit service life, and increase the maintenance cost and safety risks of the satellite's long-term operation. Therefore, it is urgent to innovate on-orbit protection technology to achieve intelligent management of the transponder's health status and efficient fault recovery. Summary of the Invention
[0003] To solve the above problems, the present invention proposes a method and device for autonomous health management and fault recovery of transponders on orbit. The method acquires data by real-time monitoring of the transponder by the satellite on orbit. From the perspective of large-scale satellite system applications, the method implements hierarchical single-particle recovery measures for the transponder on orbit, thereby improving the flexibility of the satellite's autonomous control of the transponder on orbit and effectively extending the transponder's on-orbit service life, reducing the long-term frequent resetting and switching operations of the transponder on orbit, and effectively preventing the impact of single particles on the transponder's on-orbit functions.
[0004] A first aspect of the present invention provides a method for autonomous on-orbit health management and fault recovery of a transponder, comprising the following steps: The control cycle based on the satellite module acquires the working telemetry data of the transponder by collecting; obtaining key telemetry data and important telemetry data by extracting the working telemetry data, and obtaining functional status data representing the transponder based on the key telemetry data and the important telemetry data and saving the data in real time; determining and obtaining a working state of a transponder and controlling the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles; Based on the working status of the transponder, the working mode of the satellite module is switched to the autonomous monitoring mode and the recovery mode through the interaction module and the above steps are repeated.
[0005] Preferably, the key telemetry data is the corresponding indicator data characterizing the on-orbit operation status of the transponder, including at least: downlink measurement frame count and remote control command count.
[0006] Preferably, the important telemetry data is indicator data associated with communication quality, including at least: remote control ranging signal-to-noise ratio, Doppler frequency deviation, code group status, refresh status, and switch status.
[0007] Preferably, the step of determining and obtaining the working state of the transponder and controlling the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles further comprises: If the critical telemetry data is greater than a first preset threshold, a reset command is sent through the satellite module and actuates the transponder reset; if the important telemetry data is greater than a second preset threshold, a switch operation is sent through the satellite module and actuates the switch operation; The satellite module is driven to monitor the transponder and collect working telemetry data. The specific rules are as follows: if the working telemetry data is in an unavailable state or the working telemetry data is not dynamically increased, a reset instruction is sent through the satellite module to drive the transponder to reset. If the number of transponder resets is greater than a first preset threshold, a transponder switch operation is sent and driven through the satellite module.
[0008] Preferably, the step of operating the transponder switch further includes: exiting the autonomous monitoring mode through the satellite module and sending the operating data of the satellite module to the interactive module.
[0009] Preferably, the control period is the periodic time of the satellite module's on-orbit services and attitude control, and the preset value is any one of 250 milliseconds, 500 milliseconds, and 1 second. The working telemetry data at least includes: obtaining the transponder's reply data through the asynchronous serial port, obtaining the transponder's first telemetry data through the external analog quantity acquisition interface, obtaining the transponder's second telemetry data through the external digital quantity acquisition interface, and obtaining the transponder's third telemetry data through the external bus communication.
[0010] Preferably, the step of switching the working mode of the satellite module to the autonomous monitoring mode and the recovery mode through the interaction module based on the working status of the transponder further includes: Based on the downlink measurement frame count and the remote control instruction count of the working state, a remote control instruction is generated through manual judgment and the working mode of the satellite module is driven to switch to the autonomous monitoring mode and the recovery mode.
[0011] A second aspect of the present invention provides an on-orbit autonomous health management and fault recovery device for a transponder, comprising: A telemetry data acquisition module, used for acquiring the working telemetry data of the transponder by collecting data based on the control cycle of the satellite module; The data processing includes obtaining key telemetry data and important telemetry data by extracting the working telemetry data, and obtaining functional status data representing the transponder based on the key telemetry data and the important telemetry data and saving the data in real time; The driving module determines and obtains the working status of the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles, controls the transponder, and switches the working mode of the satellite module through the interaction module based on the working status of the transponder.
[0012] The third aspect of the present invention provides an on-orbit autonomous health management and fault recovery device for a transponder, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, the steps of any one of the above-mentioned methods for on-orbit autonomous health management and fault recovery of a transponder are implemented.
[0013] A fourth aspect of the present invention provides a computer-readable storage medium having instructions stored thereon, which, when executed by a processor, implement any of the above-mentioned methods for autonomous on-orbit health management and fault recovery of a transponder.
[0014] Due to the adoption of the above technical solution, the present invention has the following advantages and positive effects compared with the existing technology: data is obtained by real-time monitoring of the transponder by the satellite in orbit, and from the perspective of large-scale satellite system application, the transponder on-orbit single-particle recovery measures are implemented in a hierarchical manner, thereby improving the flexibility of the satellite's on-orbit autonomous control of the transponder and effectively improving the on-orbit working life of the transponder, reducing the long-term frequent resetting and switching operations of the transponder on orbit, and effectively preventing the impact of single particles on the on-orbit function of the transponder. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The specific embodiments of the present invention are further described in detail below with reference to the accompanying drawings, wherein: Figure 1 This is a main flow chart of a method for autonomous on-orbit health management and fault recovery of a transponder in the present invention; Figure 2 A flowchart illustrating a method for autonomous on-orbit health management and fault recovery of a transponder according to the present invention; Figure 3 Schematic diagram of an on-orbit autonomous health management and fault recovery device for a transponder according to the present invention. DETAILED DESCRIPTION
[0016] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments. The advantages and features of the present invention will become more apparent from the following description and claims. It should be noted that the drawings are greatly simplified and not to exact ratios, and are intended solely to facilitate and clearly illustrate the embodiments of the present invention.
[0017] It should be noted that all directional indications in the embodiments of the present invention (such as up, down, left, right, front, back, etc.) are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.
[0018] First embodiment See also Figure 1 and Figure 3 The first aspect of the present invention provides a method for autonomous on-orbit health management and fault recovery of a transponder, comprising the following steps: S100: acquiring the working telemetry data of the transponder by collecting data based on the control cycle of the satellite module; S200: obtaining key telemetry data and important telemetry data by extracting the working telemetry data, obtaining functional status data representing the transponder based on the key telemetry data and important telemetry data, and saving the data in real time; S300: determining and obtaining the operating state of the transponder and controlling the transponder within a third preset number of consecutive control cycles based on the key telemetry data and the important telemetry data; S400: Based on the working status of the transponder, the working mode of the satellite module is switched to the autonomous monitoring mode and the recovery mode through the interaction module and the above steps are repeated.
[0019] See also Figure 3 The present invention is applied to a system for autonomous health management and fault recovery of transponders on orbit. The system includes a satellite communication processing module, a satellite command sending module, and a satellite module power supply module. The satellite communication processing module obtains telemetry data of two transponders through an asynchronous serial port and extracts working parameter data therefrom, while monitoring the single-particle upset anomalies of the transponders and the corresponding recovery methods. The satellite command sending module has the function of sending reset instructions, power on and off instructions, etc. to the two transponders. The satellite module power supply part has the function of powering two transponders on orbit and the function of always powering one transponder at any time on orbit.
[0020] See also Figure 1 , the specific steps include: S100: Acquire transponder operating telemetry data through acquisition based on the satellite module's control period. The control period is the periodic time of the satellite module's on-orbit services and attitude control. The preset value is any one of 250 milliseconds, 500 milliseconds, and 1 second, which is not limited in this embodiment. Acquire transponder response data through the asynchronous serial port of the device's primary or backup transponder. Acquire first transponder telemetry data through an external analog acquisition interface, acquire second transponder telemetry data through an external digital acquisition interface, and acquire third transponder telemetry data through external bus communication. The asynchronous serial port has an interface rate of 115200 bps.
[0021] S200: Extract key telemetry data and important telemetry data based on the operating telemetry data. Acquire and save in real time data representing the functional status of the transponder based on the key telemetry data and important telemetry data. The key telemetry data is indicator data representing the on-orbit operational status of the transponder, including at least downlink measurement frame count and remote control command count. The important telemetry data is indicator data associated with communication quality, including at least remote control ranging signal-to-noise ratio, Doppler frequency deviation, code group status, refresh status, and switch status.
[0022] S300: Based on the key telemetry data and important telemetry data, the operating status of the transponder is determined and controlled within a third preset number of consecutive control cycles. The third preset number of consecutive control cycles can be set to 10 to 15 task control cycles. Specific rules are as follows: If the key telemetry data exceeds a first preset threshold, a reset command is sent via the satellite module to reset the transponder. If the important telemetry data exceeds a second preset threshold, a switch operation is initiated via the satellite module. The satellite module is driven to monitor the transponder and acquire working telemetry data. Specific rules are as follows: If working telemetry data is unavailable or does not increase dynamically, a reset command is sent via the satellite module to reset the transponder. If the number of transponder resets exceeds a first preset threshold, a switch operation is initiated via the satellite module. The reset operation is triggered again every 10 seconds. If the transponder is reset five times within half an hour, one hour, or five times in a row, the transponder is turned off. A power-on operation is triggered 30 seconds after the successful shutdown. The above parameters can also be other and are not limited in this embodiment. The transponder power on / off operation drives the satellite to autonomously exit the monitoring mode and send the operation data of the satellite module to the interaction module, so as to avoid the transponder failure that cannot be recovered and frequently enters the power on / off infinite loop.
[0023] S400: Based on the working status of the transponder, the interactive module switches the working mode of the satellite module to the autonomous monitoring mode and the recovery mode, and the above steps are repeated. The interactive module sends a command to the satellite module to drive the working mode to the autonomous monitoring mode and the recovery mode.
[0024] Preferably, the key telemetry data is the corresponding indicator data characterizing the on-orbit operating status of the transponder, including at least: downlink measurement frame count and remote control command count.
[0025] By quantifying the communication and control processes, reliable and available data is provided to the on-orbit transponder, achieving maximum state visibility and controllability with minimal data.
[0026] Preferably, the important telemetry data is indicator data associated with communication quality, including at least: remote control ranging signal-to-noise ratio, Doppler frequency deviation, code group status, refresh status, and switch status.
[0027] Efficient diagnosis of the system is inferred through signal-to-noise ratio data; communication parameters are adjusted based on real-time parameters (such as frequency, power, and coding) to achieve dynamic performance tuning; sudden failures are avoided through trend prediction to improve on-orbit reliability.
[0028] See also Figure 2 Preferably, the step of determining and obtaining the operating status of the transponder and controlling the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles further includes: If the critical telemetry data is greater than a first preset threshold, a reset command is sent through the satellite module and the transponder is driven to reset. If the important telemetry data is greater than a second preset threshold, a switch operation is driven through the satellite module. The satellite module is driven to monitor the transponder and collect working telemetry data. The specific rules are: if the working telemetry data is in an unobtainable state or the working telemetry data is not dynamically increased, a reset instruction is sent through the satellite module and the transponder is driven to reset. If the number of transponder resets is greater than a first preset threshold, the transponder switch operation is sent and driven through the satellite module.
[0029] If the number of resets exceeds a first preset threshold, the transponder may have a permanent hardware fault. At this point, the system switches to actuated switching to prevent infinite reset cycles that could waste resources or damage the device due to overheating. By prioritizing soft recovery with hard switching as a backup, efficient fault management is achieved on-orbit, significantly improving the transponder's on-orbit survivability. Commands are executed through the satellite module, ensuring the reliable delivery of control commands. Combined with continuous monitoring of telemetry data, this forms a closed loop of detection, repair, and verification, enhancing system robustness.
[0030] Preferably, the step of operating the transponder switch further includes: exiting the autonomous monitoring mode through the satellite module and sending the operating data of the satellite module to the interactive module.
[0031] By transferring operational authority to the interactive module through the satellite module, ground personnel can directly issue instructions based on real-time data, enhancing the initiative and accuracy of fault handling.
[0032] Preferably, the control period is the periodic time of the satellite module's on-orbit services and attitude control, and the preset value is any one of 250 milliseconds, 500 milliseconds, and 1 second. The working telemetry data at least includes: obtaining the transponder's reply data through the asynchronous serial port, obtaining the transponder's first telemetry data through the external analog quantity acquisition interface, obtaining the transponder's second telemetry data through the external digital quantity acquisition interface, and obtaining the transponder's third telemetry data through the external bus communication.
[0033] Rapid response to dynamic faults reduces the risk of missed detection and ensures real-time performance. Full-dimensional monitoring covering instruction execution, physical status, and communication quality ensures comprehensive equipment monitoring. Interface redundancy and data cross-validation enhance system fault tolerance and achieve reliability. Periodic dynamic adjustment optimizes resource allocation, extending equipment life and ensuring high efficiency.
[0034] Preferably, the step of switching the working mode of the satellite module to the autonomous monitoring mode and the recovery mode through the interaction module based on the working status of the transponder further includes: Based on the downlink measurement frame count and remote control command count of the working status, remote control commands are generated through manual judgment and the working mode of the satellite module is driven to switch to the autonomous monitoring mode and the recovery mode.
[0035] Avoid automated misjudgments and make dynamic decisions for complex scenarios; switch modes on demand to reduce system redundancy and maximize resource efficiency; combine human intervention and data verification to ensure the reliability of critical tasks.
[0036] Second embodiment See also Figure 3 The second aspect of the present invention provides an on-orbit autonomous health management and fault recovery device for a transponder, comprising: A telemetry data acquisition module, used for acquiring the working telemetry data of the transponder by collecting data based on the control cycle of the satellite module; The data processing includes obtaining key telemetry data and important telemetry data by extracting the working telemetry data and obtaining functional status data representing the transponder based on the key telemetry data and the important telemetry data and saving the data in real time; The driving module determines and obtains the working status of the transponder within a third preset number of consecutive control cycles based on the key telemetry data and the important telemetry data, controls the transponder, and switches the working mode of the satellite module through the interaction module based on the working status of the transponder.
[0037] The telemetry data acquisition module's multi-interface collaboration (asynchronous serial port, analog / digital acquisition, and bus communication) comprehensively captures transponder data, including command execution status (e.g., remote control command count), physical health parameters (e.g., voltage / temperature), and communication quality indicators (e.g., signal-to-noise ratio, Doppler frequency deviation). This data covers device functionality, performance, and environmental conditions. The data processing module extracts key telemetry data (e.g., downlink frame count, command response latency) and important telemetry data (e.g., signal-to-noise ratio, code group status) from this massive volume of telemetry data, generating functional status data and storing it in real time. This provides a basis for subsequent analysis while reducing data redundancy.
[0038] Third embodiment The third aspect of the present invention provides an on-orbit autonomous health management and fault recovery device for a transponder, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the steps of any one of the above-mentioned methods for on-orbit autonomous health management and fault recovery of a transponder are implemented.
[0039] Reduce dependence on ground control and improve independent operation capabilities in orbit; hardware environmental resistance design + software redundancy judgment criteria to enhance system fault tolerance; dynamic resource allocation and precise fault location to balance real-time performance and resource consumption.
[0040] Fourth embodiment A fourth aspect of the present invention provides a computer-readable storage medium having instructions stored thereon, which, when executed by a processor, implement any one of the above-mentioned methods for autonomous on-orbit health management and fault recovery of a transponder.
[0041] This computer-readable storage medium achieves technical generalization capability, on-orbit sustainability, and engineering applicability through standardized carriers, intelligent and adaptive design.
[0042] In the description of this application, it should be noted that the terms "inner" and "outer" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, or the orientations or positional relationships in which the product of this application is typically placed when in use. These terms are intended solely to facilitate the description of this application and simplify the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on this application. Furthermore, the terms "first" and "second" and the like are used solely for distinction and should not be construed as indicating or implying relative importance.
[0043] It should also be noted that, unless otherwise expressly specified or limited, the terms "disposed" and "connected" should be understood broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to direct connections, indirect connections through an intermediate medium, or internal connections between two components. Those skilled in the art will understand the specific meanings of these terms in this application based on the specific circumstances.
[0044] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the identification content specifically executed by the above-described system and device can refer to the corresponding process in the aforementioned method embodiment.
[0045] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings, but the present invention is not limited to the above embodiments. Even if various changes are made to the present invention, if these changes fall within the scope of the claims of the present invention and their equivalents, they still fall within the scope of protection of the present invention.
Claims
1. A method for autonomous on-orbit health management and fault recovery of a transponder, characterized in that: The steps include: The control cycle based on the satellite module acquires the working telemetry data of the transponder by collecting; obtaining key telemetry data and important telemetry data by extracting the working telemetry data, and obtaining functional status data representing the transponder based on the key telemetry data and the important telemetry data and saving the data in real time; determining and obtaining a working state of a transponder and controlling the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles; Based on the working status of the transponder, the working mode of the satellite module is switched to the autonomous monitoring mode and the recovery mode through the interaction module and the above steps are repeated.
2. The method for autonomous on-orbit health management and fault recovery of a transponder according to claim 1, characterized in that: The key telemetry data is the corresponding indicator data that characterizes the on-orbit operating status of the transponder, and at least includes: downlink measurement frame count and remote control command count.
3. The method for autonomous on-orbit health management and fault recovery of a transponder according to claim 1, characterized in that: The important telemetry data is indicator data associated with communication quality, including at least: remote control ranging signal-to-noise ratio, Doppler frequency deviation, code group status, refresh status, and switch status.
4. The method for autonomous on-orbit health management and fault recovery of a transponder according to claim 1, characterized in that: The step of determining and obtaining the operating state of the transponder and controlling the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles further includes: If the critical telemetry data is greater than a first preset threshold, a reset command is sent through the satellite module and actuates the transponder reset; if the important telemetry data is greater than a second preset threshold, a switch operation is sent through the satellite module and actuates the switch operation; The satellite module is driven to monitor the transponder and collect working telemetry data. The specific rules are as follows: if the working telemetry data is in an unavailable state or the working telemetry data is not dynamically increased, a reset instruction is sent through the satellite module to drive the transponder to reset. If the number of transponder resets is greater than a first preset threshold, a transponder switch operation is sent and driven through the satellite module.
5. The method for autonomous on-orbit health management and fault recovery of a transponder according to claim 4, characterized in that: The step of transponder switch operation further includes: exiting the autonomous monitoring mode through the satellite module and sending the operating data of the satellite module to the interaction module.
6. The method for autonomous on-orbit health management and fault recovery of a transponder according to claim 1, characterized in that: The control period is the periodic time of the satellite module's on-orbit services and attitude control, and the preset value is any one of 250 milliseconds, 500 milliseconds, and 1 second. The working telemetry data at least includes: obtaining the transponder's reply data through the asynchronous serial port, obtaining the transponder's first telemetry data through the external analog quantity acquisition interface, obtaining the transponder's second telemetry data through the external digital quantity acquisition interface, and obtaining the transponder's third telemetry data through the external bus communication.
7. The method for autonomous on-orbit health management and fault recovery of a transponder according to claim 1, characterized in that: The step of switching the working mode of the satellite module to the autonomous monitoring mode and the recovery mode through the interaction module based on the working status of the transponder further includes: Based on the downlink measurement frame count and the remote control instruction count of the working state, a remote control instruction is generated through manual judgment and the working mode of the satellite module is driven to switch to the autonomous monitoring mode and the recovery mode.
8. An on-orbit autonomous health management and fault recovery device for a transponder, characterized in that: include: A telemetry data acquisition module, used for acquiring the working telemetry data of the transponder by collecting data based on the control cycle of the satellite module; The data processing includes obtaining key telemetry data and important telemetry data by extracting the working telemetry data, and obtaining functional status data representing the transponder based on the key telemetry data and the important telemetry data and saving the data in real time; The driving module determines and obtains the working status of the transponder based on the key telemetry data and the important telemetry data within a third preset number of consecutive control cycles, controls the transponder, and switches the working mode of the satellite module through the interaction module based on the working status of the transponder.
9. An on-orbit autonomous health management and fault recovery device for a transponder, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is executed by a processor, the steps of the method for autonomous on-orbit health management and fault recovery of a transponder as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having instructions stored thereon, characterized in that: When the instructions are executed by the processor, the on-orbit autonomous health management and fault recovery method of the transponder as described in any one of claims 1 to 7 is implemented.