Method and system for constructing, solving and verifying use security domain of power supply and distribution system
By constructing and verifying the safety domain of the spacecraft power supply and distribution system, the challenge of safety assessment of the power supply and distribution system under complex environments and mission conditions has been solved, ensuring the safe operation of the spacecraft, avoiding the occurrence of failures, and realizing the precise quantification and verification of the safety domain boundary of the spacecraft power supply and distribution system.
Patent Information
- Application Number
- CN202511481721.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-16
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies have failed to effectively identify and assess the safety risks of spacecraft power supply and distribution systems under complex environments and mission conditions, leading to potential failure modes that affect spacecraft lifespan and safety.
By collecting characteristic parameters of the power supply and distribution system, a safety domain test and verification sample library is constructed, data simulation is performed, a safety domain test and verification platform is established, the safety domain boundary of spacecraft equipment is iteratively corrected, and the confidence level of the safety domain boundary is calculated using a full-link semi-physical verification system to ensure the safe operation of the system under extreme conditions.
It enables risk identification and safety assessment of power supply and distribution systems under complex environments and multi-mission conditions, avoids the aggravation of spacecraft failures, ensures the power supply and distribution safety of spacecraft equipment, and provides a practical safety domain analysis and verification method.
Smart Images

Figure CN121502993A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of spacecraft power supply and distribution, and particularly relates to a method and system for constructing, solving and verifying a safe domain for a power supply and distribution system. BACKGROUND
[0002] Spacecraft equipment refers to a system launched into space by a space flight vehicle such as a launch vehicle, a space shuttle, etc., and orbiting the earth or other planets like a natural satellite. Artificial satellites are the most numerous and widely used spacecraft, which can provide communication, navigation, and remote sensing services.
[0003] The power supply and distribution system is the bottom line for the safe operation of spacecraft equipment in orbit, and once a safety problem occurs, it will cause irreversible damage to the entire spacecraft equipment, leading to serious safety accidents.
[0004] Specifically, spacecraft, as major space equipment, undergoes complex environments and various task conditions. On the ground, it will be subjected to various environments such as water vapor, storage, moving, transportation, temperature, and salt spray, and during the launch process, it will be subjected to severe overload, vibration, noise, and impact environments. After entering orbit, it mainly faces the threats of high vacuum, microgravity, high-low temperature alternating temperature, ultraviolet radiation, space particle radiation, earth magnetic field, electromagnetic environment between its own single machines, and electromagnetic interference from others in wartime. If the complex environmental risks are not fully identified, various failure modes of the spacecraft can be introduced, some of which belong to fatal failures, resulting in safety problems, which may terminate or shorten the service life of the spacecraft.
[0005] Therefore, the safe use of these products largely determines the reliability and safety of the entire satellite.
[0006] Specifically, spacecraft, as major space equipment, undergoes complex environments and various task conditions. On the ground, it will be subjected to various environments such as water vapor, storage, moving, transportation, temperature, and salt spray, and during the launch process, it will be subjected to severe overload, vibration, noise, and impact environments. After entering orbit, it mainly faces the threats of high vacuum, microgravity, high-low temperature alternating temperature, ultraviolet radiation, space particle radiation, earth magnetic field, electromagnetic environment between its own single machines, and electromagnetic interference from others in wartime. If the complex environmental risks are not fully identified, various failure modes of the spacecraft can be introduced, some of which belong to fatal failures, resulting in safety problems, which may terminate or shorten the service life of the spacecraft.
[0007] The United States "Amazon" - 4A satellite design life of 15 years, launched into orbit within a month of the power system failure, which may lead to its loss of nearly 50% of the ability. Europe 1 Galileo in orbit validation satellite, namely Galileo IOV due to sudden power interruption caused 2 channel stop broadcast navigation signal, into the safety mode. Domestic Zhongxing 18 satellite and other catastrophic failures occurred during the life of the serious consequences of multiple star failure, paid a heavy price. After the thorough analysis, found that these accidents are related to the use of equipment safety domain is not clear, safety use specification is not perfect, has not covered the complex environment and task working conditions, the equipment in orbit with the equipment of high reliability requirements are not adapted.
[0008] Hnyilicza E first proposed the static security region of power grid in 1975. In the early 1980s, Academician Yu Yixin team of Tianjin University began to study the methodology of power grid security region. The establishment, solution and application of security region have made certain research results in the fields of power system, network and integrated energy system, but the research in the field of spacecraft equipment is still blank. It is urgent to explore the maximum allowable range and maximum capacity of spacecraft system, and successfully apply security region analysis to the field of spacecraft equipment.
[0009] Comparison of existing technologies at home and abroad and the closest existing results: Patent document CN104008275A discloses an improved dynamic security region fitting construction method of power system, and specifically provides an improved dynamic security region fitting construction method of power system. The scheme establishes an actual power system dynamic model, determines the corresponding fault of the dynamic security region to be solved, and presets the upper and lower limits of active power of power injection node as the search range of the upper critical point of dynamic security region boundary. The quasi-orthogonal point selection method is used to determine the initial value of the critical point, and the critical points under different initial values are combined and fitted to obtain the expression of hyperplane, which can construct a more reasonable, reliable and accurate hyperplane equation. The technical scheme focuses on improving the fitting process of dynamic security region boundary. Based on the fitting goodness index, it is judged whether the critical points under different initial values can be fitted into a hyperplane. The initial value is a scalar, and the fitting construction of the security region boundary cannot be performed for the initial value of the vector type.
[0010] Patent document CN102368610A discloses an evaluation method based on power distribution system safety domain, and specifically provides an evaluation method based on power distribution system safety domain in power system; the scheme obtains power distribution system safety domain and safety boundary according to the capacity of main transformer in power distribution system and the tie-in relationship between main transformers, judges whether the working point is in the power distribution system safety domain according to the distance between the working point and the safety boundary, if yes, obtains the load shortage or margin Li of the tie-in unit, and the process ends; if no, adjusts the load of the main transformer until the working point returns to the power distribution system safety domain. The requirement of real-time online operation can be met. The technical scheme is based on the relative position of system working point in the safety domain, obtains and evaluates the power distribution safety domain boundary, has the advantages of reducing the calculation amount and meeting the requirement of online real-time operation, and has the disadvantage that it is only suitable for fixed system topology or fixed safety domain, and has poor dynamic adaptability and flexibility.
[0011] Patent document CN107579843A discloses a method for constructing a safety domain model of a flexible power distribution network, and specifically provides a method for constructing a safety domain model of a flexible power distribution network; the scheme includes: (1) obtaining the full-network feeder segment capacity constraint, main transformer capacity constraint and flexible switching station port adjustment amount constraint of the flexible power distribution network under N#0 safety constraint; (2) obtaining the full-network feeder segment capacity constraint, main transformer capacity constraint and flexible switching station port adjustment amount constraint of the flexible power distribution network under N#1 safety constraint; obtaining the safety domain model, and taking the effective constraint in the safety domain model as equal to obtain the effective safety boundary equation of the flexible power distribution network, thereby providing technical guidance for the construction and development of the flexible power distribution network in the future. The scheme focuses on the construction of the safety domain model of the flexible power distribution network, obtains the safety boundary equation of the power distribution network by the effective constraint in the model, and has the defects that the model is not accurate enough, and the modeling method depends on the topology structure of the system to be built, and has poor flexibility. The safety domain based on the system characteristic parameters is quite different from the operation vector constructed in the patent.
[0012] Patent document CN103310163A discloses a data processing device and method using safety domain and sub-safety domain, and specifically provides a data processing device having a safety operation domain and a sub-safety operation domain. When operating in the safety domain, data inaccessible when operating in the sub-safety domain can be accessed. If the selection domain is not allowed in the selection, a domain check error is triggered. The scheme mainly describes the data processing device, and focuses on the processing method of data access between multiple operation domains of the safety domain and the sub-safety domain, and prevents unauthorized access of safety code. The technical scheme adopted in the patent has little relevance to the patent.
[0013] Patent document CN103607403A discloses a method, apparatus, and system for using a security domain in a NAT network environment, aiming to solve the problem of poor security in existing technologies when using security domains in a NAT network environment. The access control gateway obtains a first packet sent by the NAT device from a client; when it determines that the client is already logged in, it decapsulates the first packet to obtain a second packet carrying a virtual IP address; wherein, the virtual IP address is assigned to the client by the access control gateway when the client logs in, and the virtual IP addresses assigned by the access control gateway to different clients are different; the second packet is sent to the security domain device so that the security domain device can determine whether the client has security domain access rights based on the virtual IP address carried in the second packet. This solution mainly addresses the security vulnerability in NAT networks where different user IPs cannot be identified after being translated by the NAT device. By decapsulating the first packet to form the second packet and sending it to the security domain device, it solves the problem of whether the client has security domain access rights. The technical solution adopted in this patent is not very relevant to this.
[0014] Patent document CN105743651A discloses a method, apparatus, and application terminal for using card applications within a chip security domain. The main purpose of this solution is to lower the barrier to entry for application terminals using card applications within a chip security domain, increase the card application promotion capabilities of application terminals, and ensure the security, consistency, integrity, and non-repudiation of card application usage. Based on the application terminal's card application access request, a list of available card applications is obtained from a trusted service management platform; based on the list of available card applications, a digital certificate authorized for use is applied for from a security certification center; a binding relationship is established between the digital certificate and the list of available card applications; the digital certificate and an SDK package containing APDU instructions for each card application are sent to the application terminal; authentication and authorization are performed by calling the digital certificate sent by the SDK package when the application terminal needs to use the card application, and the list of available card applications is returned. This technical solution focuses on verifying card application access permissions by establishing a binding relationship between the digital certificate and the list of available card applications; the technical solution adopted in this patent is not significantly related to this.
[0015] Patent document CN103282911A discloses a method for interaction between a normal domain and a security domain with a trust zone, a management method for trust application downloads, a management server, a device, and a system using this method. This solution, based on a trust application download management server, allows a service loader to access a device equipped with a trust platform and establish a data communication channel; it controls the delegation of download permissions for trust applications, and when a device requests a trust application download, it allows the trust application to be downloaded to that device, thus comprehensively managing the download of trust applications and allowing them to be downloaded securely. This technical solution focuses on the trust zone interaction method between the normal domain and the security domain, and does not involve the construction, solution, and verification of the security domain, and is not particularly relevant to the technical solution of this patent.
[0016] "Trajectory and Attitude Cooperative Control of Reusable Launch Vehicles Oriented to the Safety Domain," Tianjin Science and Technology Yearbook, 2019, first proposed a framework for trajectory reconstruction and attitude cooperative control of aircraft oriented to the safety domain. Considering the complex characteristics of multiple constraints, model uncertainty, and some unknown states affecting the safe and stable reentry flight of Reusable Launch Vehicles (RLVs), it significantly enhances the reliability and safety of system operation. It proposes a high-precision, fast flight controller design method based on multivariable disturbance compensation, providing a non-decoupling design approach that effectively avoids forced artificial decoupling of various aircraft channels. Compared to traditional PID control, the system has stronger anti-interference capabilities and faster convergence speed. However, this solution aims to improve the operational reliability and safety of launch vehicle control systems and is not directly related to the technology presented in this patent.
[0017] Patent document CN115793493A discloses an on-orbit flight simulation test method for a spacecraft power supply and distribution subsystem. This method includes: acquiring actual data of the spacecraft power supply and distribution subsystem's on-orbit flight; constructing a digital model of the spacecraft and a simulation mission model of the spacecraft power supply and distribution subsystem based on the actual data, and configuring the simulation mission model parameters; simulating the on-orbit flight of the spacecraft power supply and distribution subsystem using simulation software based on the digital model of the spacecraft and the simulation mission model, and obtaining simulation results; and testing and evaluating the safety margin of the spacecraft power supply and distribution subsystem using a solar cell array simulator and a semi-physical simulation system based on the simulation results. This invention, by establishing a digital model of the spacecraft and a simulation mission scenario, obtains simulation data of the spacecraft power supply and distribution subsystem's on-orbit flight, providing reliable data support for the safety margin assessment of the spacecraft power supply and distribution subsystem, and improving the accuracy of the safety margin assessment. This technical solution focuses on building a model of the power supply and distribution system based on actual data, and using the model to simulate and assess its on-orbit flight state. Its drawback is that it only characterizes or provides the state points for safe operation of the system in orbit, and does not comprehensively consider the influencing factors during use, resulting in low engineering practicality. This patent, however, uses different state-space constraints and multi-parameter correlation constraints of the power supply and distribution system to reflect the requirements of different space environments, mission conditions, and product characteristics, constructing a safe operating domain for the power supply and distribution system, and quantitatively solving and verifying the boundary conditions for its safe operation. Summary of the Invention
[0018] To address the shortcomings of existing technologies, the purpose of this invention is to provide a method and system for constructing, solving, and verifying security domains in power supply and distribution systems.
[0019] A method for constructing, solving, and verifying security domains in a power supply and distribution system according to the present invention includes: Step S1: Collect characteristic parameters of the power supply and distribution system, extract the operating point vector of the characteristic parameters, and then construct a safety domain test verification sample library; Step S2: Based on the security domain test and verification sample library, perform data simulation to obtain simulation results; based on the simulation results, establish a security domain test and verification platform; construct a full-link semi-physical verification system, traverse the test samples in the security domain test and verification sample library, and obtain verification results; Step S3: Based on the verification results, according to the spacecraft's environmental factors, mission scenarios and product usage characteristics, iteratively correct the safety domain boundary of the spacecraft equipment to obtain the corrected safety domain boundary; Step S4: Based on the corrected security domain boundary, the confidence level of the security domain boundary is calculated using the full-link semi-physical verification system.
[0020] Preferably, in step S1, the characteristic parameters are power supply and distribution system parameters; the characteristic parameters include: bus voltage, bus current, solar array output current, battery pack voltage, battery pack charging current, battery pack discharging current, power controller temperature, battery pack temperature, solar cell circuit temperature, shunt MEA parameters, battery cell voltage, discharge switch status, distributor temperature and satellite separation signal; The operating point vector is used to describe the operating status of the power supply and distribution system parameters; The security domain test verification sample library, which is a logical unit formed by associating the running point vectors of feature parameters, is used to verify the security domain.
[0021] Preferably, in step S2, the full-link semi-physical verification system is a semi-physical simulation system; Based on the simulation results, a security domain test and verification platform is established, including: Step B1: Build a full-link digital model based on simulation software and import the security domain test verification sample library; the simulation software includes: MATLAB or Simulink; Step B2: Configure simulation environment parameters; the simulation environment parameters include: spatial radiation intensity, extreme temperature range and vibration spectrum; the spatial radiation intensity is 1000 W / m²; the extreme temperature range is -50℃ to +80℃; the vibration spectrum is 5~2000 Hz; Step B3: Run the simulation and monitor the system status in real time. Determine if the simulation results are abnormal. If the result is yes, record it as a fault sample. If the result is no, do not process it. Step B4: Compare the simulation results with the preset security threshold, generate the initial value of the security domain boundary, and output it to the full-link semi-physical verification system.
[0022] Preferably, step S3 includes: Step S3.1: Take any power supply and distribution characteristic parameter operating point vector as the starting point, and traverse all characteristic operating point vectors in sequence to obtain the correlation relationship between each operating point vector; Step S3.2: Randomly select the running point vector as the free variable, fix other non-correlated parameters, and based on the correlation between the running point vectors, repeatedly perform safety judgment on the system by adjusting the characteristic parameter values of the free variable and the correlated variable until the running result reaches the critical safety state, that is, the safety domain boundary.
[0023] Preferably, the operating point vector of the power distribution characteristic parameters is V0, where V0 = [bus voltage 38 V, battery temperature 45℃]; The safety judgment is as follows: If the bus voltage (a free variable) is adjusted to the critical value V_critical, and the battery pack charging current (a related variable) is less than or equal to the maximum current, and the power controller temperature is less than or equal to the safe temperature, then the system is considered to be in a safe state. If the result is yes, the system is considered to be in a critical safe state. If the result is no, the system is considered to be in a critical safe state, and the current bus voltage value is recorded as the boundary of the safe domain. Then, the critical point is approximated using a bisection method until the accuracy meets the accuracy requirements. The accuracy requirement is ±0.5 V; the critical value V_critical is 40 V; the maximum current is 10 A; and the safe temperature is 70 °C.
[0024] A system for constructing, solving, and verifying a power supply and distribution system using security domains, provided by the present invention, includes: Module M1: Collects characteristic parameters of the power supply and distribution system, extracts the operating point vector of the characteristic parameters, and then constructs a safety domain test verification sample library; Module M2: Based on the security domain test and verification sample library, perform data simulation to obtain simulation results; establish a security domain test and verification platform based on the simulation results; construct a full-link semi-physical verification system, traverse the test samples in the security domain test and verification sample library, and obtain verification results; Module M3: Based on the verification results, the safety domain boundary of the spacecraft equipment is iteratively corrected according to the environmental factors, mission scenarios and product usage characteristics of the spacecraft, to obtain the corrected safety domain boundary; Module M4: Based on the corrected security domain boundary, the confidence level of the security domain boundary is calculated through the full-link semi-physical verification system.
[0025] Preferably, in module M1, the characteristic parameters are power supply and distribution system parameters; the characteristic parameters include: bus voltage, bus current, solar array output current, battery pack voltage, battery pack charging current, battery pack discharging current, power controller temperature, battery pack temperature, solar cell circuit temperature, shunt MEA parameters, battery cell voltage, discharge switch status, distributor temperature and satellite separation signal; The operating point vector is used to describe the operating status of the power supply and distribution system parameters; The security domain test verification sample library, which is a logical unit formed by associating the running point vectors of feature parameters, is used to verify the security domain.
[0026] Preferably, in module M2, the full-link semi-physical verification system is a semi-physical simulation system; Based on the simulation results, a security domain test and verification platform is established, including: Module B1: Build a full-link digital model based on simulation software and import the security domain test verification sample library; the simulation software includes: MATLAB or Simulink; Module B2: Configure simulation environment parameters; the simulation environment parameters include: spatial radiation intensity, extreme temperature range and vibration spectrum; the spatial radiation intensity is 1000 W / m²; the extreme temperature range is -50℃ to +80℃; the vibration spectrum is 5~2000 Hz; Module B3: Runs the simulation and monitors the system status in real time, determines whether the simulation results are abnormal, records the result as a fault sample if the result is yes, and does not process it if the result is no. Module B4: Compares the simulation results with the preset security threshold, generates the initial value of the security domain boundary, and outputs it to the full-link semi-physical verification system.
[0027] Preferably, module M3 includes: module M3.1: taking any power supply and distribution characteristic parameter operating point vector as the starting point, and sequentially traversing all characteristic operating point vectors to obtain the correlation relationship between each operating point vector; Module M3.2: Randomly select the running point vector as the free variable, fix other non-correlated parameters, and based on the correlation between the running point vectors, repeatedly make safety judgments on the system by adjusting the characteristic parameter values of the free variable and the correlated variable until the running result reaches the critical safety state, that is, the boundary of the safety domain.
[0028] Preferably, the operating point vector of the power distribution characteristic parameters is V0, where V0 = [bus voltage 38 V, battery temperature 45℃]; The safety judgment is as follows: If the bus voltage (a free variable) is adjusted to the critical value V_critical, and the battery pack charging current (a related variable) is less than or equal to the maximum current, and the power controller temperature is less than or equal to the safe temperature, then the system is considered to be in a safe state. If the result is yes, the system is considered to be in a critical safe state. If the result is no, the system is considered to be in a critical safe state, and the current bus voltage value is recorded as the boundary of the safe domain. Then, the critical point is approximated using a bisection method until the accuracy meets the accuracy requirements. The accuracy requirement is ±0.5 V; the critical value V_critical is 40 V; the maximum current is 10 A; and the safe temperature is 70 °C.
[0029] Compared with the prior art, the present invention has the following beneficial effects: 1. The spacecraft equipment power supply and distribution system proposed in this invention uses a safety domain construction method to establish a full-link electrical digital model from power generation, transmission, transformation, distribution to the load end, conduct quantitative assessment and verification of deviation, identify weak links and potential risks, and use these models to simulate different failure scenarios in complex space environments and under multiple missions and operating conditions.
[0030] 2. This invention focuses on dimensionality reduction and speed-up methods, and extends the security domain to the entire spacecraft equipment operation state space. Based on visual observation, it summarizes the rules and reveals the mechanism. Furthermore, this invention uses network theory, geometry, and graph theory to study the essence of power distribution security boundary problems, and simplifies the methods of security domain calculation and security analysis.
[0031] 3. This invention is based on the security domain test instance verification of the information security system, completes the full-link semi-physical test, verifies the system-level spacecraft energy management strategy, and supports the simulation function of various system fault states and fault recovery under extreme conditions.
[0032] 4. This invention can carry out risk identification of power supply and distribution systems in multi-mission scenarios, and safety domain analysis and verification of spacecraft equipment under complex environments and operating conditions. It solves the problem of effectively assessing the operational safety of power supply and distribution systems under complex environments and operating conditions, and has practical engineering value.
[0033] 5. In view of the objective reality that the power supply and distribution system is the bottom line for the safe operation of spacecraft equipment in orbit, this invention explores the maximum allowable range and maximum capacity of spacecraft system operation, avoids the aggravation and spread of spacecraft equipment failures, and prevents unpredictable consequences, thus ensuring the power supply and distribution safety of spacecraft equipment. Attached Figure Description
[0034] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 A schematic diagram of the overall process of the spacecraft equipment power supply and distribution system using the security domain provided by the present invention; Figure 2 A schematic diagram illustrating the construction of a security domain for a spacecraft equipment power supply and distribution system provided by this invention; Figure 3 A schematic diagram illustrating the security domain solution for the power supply and distribution system of spacecraft equipment provided by this invention; Figure 4 This is a schematic diagram illustrating the use of a security domain in the power supply and distribution system for spacecraft equipment provided by the present invention. Detailed Implementation
[0035] The present invention will now be described in detail with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the present invention, but do not limit the invention in any way. It should be noted that those skilled in the art can make several changes and improvements without departing from the concept of the present invention. These all fall within the protection scope of the present invention.
[0036] This invention includes methods, apparatus, and systems for constructing, solving, and verifying the safety domain of a spacecraft equipment power supply and distribution system, based on the space environment, mission conditions, and product usage characteristics. Specifically, the space environment, mission conditions, and usage characteristics of the power supply and distribution products are crucial boundary conditions determining the safety domain. For example, the more severe the space environment, the more complex the mission conditions, and the higher the requirements for product usage characteristics, the more compact the system's safety domain will be. By using different state-space constraints and multi-parameter correlation constraints to reflect the requirements of different space environments, mission conditions, and product characteristics, the safety domain of the spacecraft equipment power supply and distribution system is constructed, and the boundary conditions for its safe operation are quantitatively solved and verified.
[0037] In other words, this invention can conduct risk identification of the power supply and distribution system of spacecraft equipment in multi-mission scenarios, and analyze and verify the safety domain of spacecraft equipment under complex environments and operating conditions, so as to ensure the power supply and distribution safety of spacecraft equipment.
[0038] According to the present invention, a method for constructing, solving, and verifying security domains in a power supply and distribution system is provided. The software system flow includes: Step S1: Collect characteristic parameters of the power supply and distribution system, extract the operating point vector of the characteristic parameters, and then construct a safety domain test verification sample library; Step S2: Based on the security domain test and verification sample library, perform data simulation to obtain simulation results; based on the simulation results, establish a security domain test and verification platform; construct a full-link semi-physical verification system, traverse the test samples in the security domain test and verification sample library, and obtain verification results; Step S3: Based on the verification results, iteratively correct the safety domain boundary of the spacecraft equipment to obtain the corrected safety domain boundary; Step S4: Based on the corrected security domain boundary, the confidence level of the security domain boundary is calculated using the full-link semi-physical verification system.
[0039] In step S3, the boundary of the safety domain is obtained by iteratively solving based on the spacecraft's environmental factors, multi-mission scenarios, and product usage characteristics. In step S1, the characteristic parameters include: bus voltage, bus current, solar array output current, battery pack voltage, battery pack charging current, battery pack discharging current, power controller temperature, battery pack temperature, solar cell circuit temperature, shunt MEA parameters, individual battery cell voltage, discharge switch status, distributor temperature, and satellite-rocket separation signal. The operating point vector is used to describe the operating status of the power supply and distribution system parameters; The security domain test verification sample library is formed by associating the running point vectors of feature parameters to form independent logical units, which are used to verify the verification of security domain test evolution.
[0040] Specifically, in step S1, the security domain test verification sample library is constructed using the run point vector as follows: Step A1: Define operating scenarios and conditions. Specifically, based on the spacecraft's mission profile, the space environment it may encounter, and potential failure modes, comprehensively identify and define the typical and extreme operating scenarios and conditions that the power supply and distribution system may face.
[0041] The mission profile includes the launch phase, on-orbit operation, and orbit change; the space environment includes: illuminated areas, shaded areas, high and low temperatures, and radiation zones.
[0042] Step A2: Generate basic operating point vectors. Specifically, for each defined operating scenario and condition, use the design parameters of the power supply and distribution system, historical telemetry data, ground test data, or preliminary system simulation models to generate one or more basic operating point vectors representing that scenario / condition.
[0043] Step A3: Parameter Combination and Expansion. Specifically, design experiments, such as Design of Experiments (DOE), Latin hypercube sampling, or Monte Carlo methods, are used to systematically combine and vary the characteristic parameters within a reasonable range. Furthermore, reasonable perturbations are applied to key parameters to expand the vector coverage and simulate uncertainty.
[0044] Step A4: Data labeling and structuring. Specifically, each generated running point vector is labeled in detail, including its corresponding running scenario, working condition, expected system state, etc. The labeled data is then classified, indexed, and stored to obtain a safety domain test verification sample library.
[0045] In step S2, the security domain test verification platform is used to load and run the security domain test sample library on the simulator, supporting the stable operation of the test samples; The connection between the security domain test and verification platform and the establishment of the full-link semi-physical verification system is as follows: the security domain test and verification platform is a fully digital simulation test platform. The full-link model in this platform is defined as: a complete dynamic mathematical model covering the spacecraft power supply and distribution system from energy generation, i.e., solar cell arrays, energy storage, i.e. battery packs, power conversion, i.e. power controllers, and power distribution, i.e. power distributors to the load end, i.e. onboard equipment, including: electrical characteristics, thermodynamic characteristics and electromagnetic compatibility models of each subsystem.
[0046] For example, a solar cell array model can describe the nonlinear relationship between its output power and irradiance and temperature, while a battery pack model can characterize the correlation between charging and discharging efficiency and temperature and aging. This end-to-end model can be embedded into a semi-physical system, replacing the mathematical model with a physical unit, thus enhancing the accuracy and confidence level of the end-to-end simulation.
[0047] The full-link semi-physical verification system is also known as a semi-physical simulation system. The verification results, that is, under the same environment and working conditions, the static and dynamic boundaries of the system are obtained. The higher the confidence level of the security domain boundary, the smaller the security domain. Based on the simulation results, a security domain test and verification platform is established. The specific process includes: Step B1: Build a full-link digital model based on simulation software and import the security domain test verification sample library; the simulation software includes: MATLAB or Simulink.
[0048] Step B2: Configure simulation environment parameters, including spatial radiation intensity, extreme temperature range, vibration spectrum, etc.
[0049] In this embodiment, the spatial radiation intensity is 1000 W / m²; the extreme temperature range is -50℃ to +80℃; and the vibration spectrum is 5~2000 Hz.
[0050] Step B3: Run the simulation and monitor the system status in real time. If any abnormalities occur, such as bus voltage exceeding the limit or battery pack overheating, record them as fault samples. The bus voltage exceeding the limit is greater than 42V; the battery pack overheating is greater than 60℃.
[0051] Step B4: Compare the simulation results with the preset security threshold, generate the initial value of the security domain boundary, and output it to the full-link semi-physical verification system; In step S3, the safety domain boundary of the spacecraft equipment is iteratively corrected, which is specifically implemented as follows: Step S3.1: Randomly select the operating point vector of the power supply and distribution characteristic parameters as the starting point, such as the initial vector V0 = [bus voltage 38 V, battery temperature 45℃]. Iterate through all characteristic operating point vectors in sequence and determine the correlation between parameters through Pearson correlation coefficient analysis.
[0052] For example, the temperature of the battery pack is strongly positively correlated with the charging and discharging current, with a ratio r=0.92, and the output current of the solar cell array is linearly related to the irradiance. Step S3.2: Randomly select the running point vector as a free variable, fix other non-correlated parameters, and based on the correlation relationship in step S3.1, synchronously bias the correlated variables.
[0053] The free variable is the bus voltage; the other non-associated parameter is the distributor temperature; and the associated variable is the battery pack charging current.
[0054] The specific security judgment logic is as follows: If the bus voltage is adjusted to the critical value V_critical, i.e., 40 V, the battery pack charging current I_charge ≤ I_max, i.e., 10 A, and the power controller temperature T_controller ≤ T_safe, i.e., 70℃, then the system is determined to be in a safe state. If any parameter exceeds the threshold, it is determined to be in a critical safe state, and the bus voltage value at this time is recorded as the boundary of the safe domain. The critical point is gradually approximated by the bisection method until the accuracy meets the requirements, specifically ±0.5 V.
[0055] First, based on on-orbit and ground test data, a safety domain test verification sample library is constructed according to environment, operating conditions and performance. Secondly, a safety domain test and verification platform was established based on the simulation data of the semi-physical system. Based on the established digital models of key products, a full-link semi-physical verification system was constructed to conduct comprehensive tests on the key performance of the spacecraft's power supply and distribution system, accumulating test samples. Secondly, the safety domain boundary of the spacecraft equipment is iteratively revised using the verification results. The safety domain analysis model of the spacecraft equipment is iterated by using safety domain experimental verification to obtain the safety domain values of key parameters, thereby gradually refining the safety boundary and improving the confidence level of the safety domain. Finally, a confidence level verification scheme for the security domain boundary is formulated. Using the modified security domain boundary, another security domain test is conducted based on the semi-physical verification system to calculate the confidence level of the security domain boundary.
[0056] According to the present invention, a method, apparatus, and system for constructing, solving, and verifying a security domain for a spacecraft equipment power supply and distribution system include: First, extract the characteristic parameters of safe operation of the power supply and distribution system and create point vectors. Second, based on the space environment, mission conditions, and usage characteristics of the power supply and distribution products, conduct analysis and form a usage state space. Third, use multi-parameter correlation to solve and determine the safe operation boundary of the point vectors of the power supply and distribution system in the state space. Finally, verify the correctness of the usage safety domain based on a semi-physical system.
[0057] Specifically, the space environment should cover situations such as atomic oxygen, space irradiation, and high and low temperatures; the mission conditions should cover remote sensing imaging, inter-satellite-to-ground communication, and rapid maneuvering requirements; and the product usage characteristics should cover power supply and distribution flow, telemetry and communication information flow, and pointing accuracy and stability control flow.
[0058] Specifically, the spacecraft equipment power supply and distribution system is constructed using a security domain. Key parameters such as electromechanical and thermal parameters that describe the operating state of the power supply and distribution system are used to create an operating point vector. Each operating point vector describes one of its operating states.
[0059] Specifically, the spacecraft equipment power supply and distribution system uses a safety domain construction. By combining the space environment, mission conditions, and usage characteristics of the power supply and distribution products, the maximum possible envelope of the operating point vector, such as bus voltage, current, and temperature, is determined. All safe operating points are aggregated to form a safety domain, thereby determining the usage state space.
[0060] Specifically, the safety domain is dynamic, and the safety boundary changes with the spatial environment and the task conditions to form different safety domains. Different state space constraints and multi-parameter correlation constraints are used to reflect the requirements of different spatial environments, task conditions and product usage characteristics.
[0061] Specifically, the solution of the safety domain for the power supply and distribution system of spacecraft equipment refers to the method of reducing the problem size by using high-dimensional safety domain simplification for the power supply and distribution system and key individual units, and solving the safety domain boundary with a high confidence level, including analytical methods, simulation methods and synthetic methods.
[0062] Specifically, the analytical method described above conducts multi-parameter correlation constraint analysis through mathematical derivation, characterized by rapidly deriving the analytical expression of the safety boundary.
[0063] Specifically, the simulation method searches for the boundary points of the security domain one by one along a certain direction, resulting in accurate simulation and higher confidence in the obtained security boundaries.
[0064] Specifically, the comprehensive method integrates the advantages of the analytical method and the simulation method. The analytical method simplifies the derivation process and constraints to determine the safety boundary. The simulation method corrects the safety boundary and can quickly determine the high-confidence safety domain.
[0065] Specifically, the spacecraft equipment power supply and distribution system uses a security domain verification method, device and system to verify the correctness of the security domain based on a semi-physical system, correct the security domain obtained by solving the calculation, iterate the spacecraft equipment's security domain analysis model, and improve the confidence level of the security domain boundary.
[0066] Specifically, the device refers to a digital model product based on a spacecraft power supply and distribution system, as well as a real stand-alone product.
[0067] Specifically, the semi-physical system utilizes data from the analytical method, the simulation method, and the integrated method, along with data from digital model products and real products, to construct a power supply and distribution full-link security domain verification platform. This platform can conduct static and dynamic boundary tests on the entire power supply and distribution system of spacecraft equipment under different space environments and mission conditions.
[0068] The safety domain of an equipment system precisely characterizes the maximum permissible operating range of the system under given safety criteria. The system safety domain is a closed set of all operating points (states) in the state space that satisfy the safety criteria; all states within the domain are safe, while those outside the boundary are unsafe. Characterizing the maximum permissible operating range (domain) of the system and determining its maximum capability are fundamental scientific problems in the study of the safe operation of spacecraft equipment.
[0069] The present invention relates to a method, apparatus and system for constructing, solving and verifying a security domain for a spacecraft equipment power supply and distribution system, comprising: a method and apparatus for constructing, solving and verifying a security domain for a spacecraft equipment power supply and distribution system based on the space environment, mission conditions and product performance; (1) The space environment, mission conditions, and product performance are described in the following steps: Spacecraft equipment power supply and distribution systems face extremely harsh environments. On the ground, they will be subjected to various environments such as water vapor, storage, handling, transportation, temperature, and salt spray. During the launch process, they will be subjected to severe overload, vibration, noise, and impact environments. After entering orbit, they will mainly face the impact of high vacuum, microgravity, alternating high and low temperatures, ultraviolet radiation, space particle radiation, the Earth's magnetic field, the electromagnetic environment between their own units, and the threat of electromagnetic interference from other parties during wartime.
[0070] (2) The spacecraft equipment power supply and distribution system is constructed using a security domain, and the steps are as follows: Establish a safety domain model for equipment use. Extract key parameters, study and construct the operating points of the spacecraft system, and describe its operating state; by distinguishing the working environment of the spacecraft, determine the value range of the operating point parameters, and then determine the state space of the safety domain; integrate various safety constraints of the spacecraft system, search for critically safe operating points, and construct the safety domain boundary, including the safety boundary and the state space boundary; based on the safety domain boundary, obtain the safety domain results.
[0071] There are correlations among multiple parameters at the operational point. A single parameter may not be sufficient to accurately determine the spacecraft's safety status. Only by considering the correlations among multiple parameters can a comprehensive assessment of the spacecraft's safety status be made. The safety constraints considered in constructing the safety domain will take into account the correlations among multiple parameters at the operational point.
[0072] First, the parameters describing the spacecraft's operational state are constructed into a vector to establish the spacecraft system's operational points; each operational point describes an operational state of the spacecraft system. Second, based on the spacecraft's operating environment, the maximum possible range of values for each parameter in the operational points is determined, thereby defining the state space containing the spacecraft system's safety domain. Third, based on the multi-parameter correlation constraints of the spacecraft system, all critically safe operational points are searched to construct the safety domain boundary. Finally, all safe operational points are found, forming the safety domain; all critically safe operational points constitute the safety boundary; all operational points outside the safety domain are unsafe.
[0073] (3) The spacecraft equipment power supply and distribution system uses the security domain solution, and the steps are as follows: Analytical methods refer to deriving analytical expressions for safety boundaries from the constraints of the spacecraft's operating environment, working conditions, and the performance requirements of its key products through mathematical derivation. However, the derivation process requires simplification and neglects some constraints, resulting in lower confidence levels and a tendency to misjudge unsafe operating points as safe ones.
[0074] Simulation methods involve searching for the boundary points of the security region one by one along a certain direction. Simulation methods offer higher accuracy and confidence, but are slow to compute and struggle to obtain complete security region boundaries.
[0075] The comprehensive method refers to iteratively refining the safety domain boundary of spacecraft equipment using verification results. By utilizing safety domain experimental verification to obtain key parameter safety domain values, the safety domain analysis model of the spacecraft equipment is iterated, thereby gradually refining the safety boundary and increasing the confidence level of the safety domain. (4) The spacecraft equipment power supply and distribution system uses security domain verification, and the steps are as follows: Take any operating point where all safety analyses pass; take any parameter from that operating point as a free variable, keep other parameters fixed, and repeatedly perform safety analyses by changing the free variable until the analysis results reach a critical safety state; compare this point with the safety boundary of the safety domain to determine if the point is on the safety boundary; continue changing the free variable and compare it with the safety boundary again to determine if the point is outside the safety domain. Under the same environmental and operating conditions, the higher the confidence level of the safety domain boundary, the smaller the safety domain, which may prevent the performance of critical products from being fully utilized.
[0076] The present invention also provides a system for constructing, solving, and verifying security domains in a power supply and distribution system. The system for constructing, solving, and verifying security domains in a power supply and distribution system can be implemented by executing the process steps of the method for constructing, solving, and verifying security domains in a power supply and distribution system. That is, those skilled in the art can understand the method for constructing, solving, and verifying security domains in a power supply and distribution system as a preferred embodiment of the system for constructing, solving, and verifying security domains in a power supply and distribution system.
[0077] A system for constructing, solving, and verifying a power supply and distribution system using security domains, provided by the present invention, includes: Module M1: Collects characteristic parameters of the power supply and distribution system, extracts the operating point vector of the characteristic parameters, and then constructs a safety domain test verification sample library; Module M2: Based on the security domain test and verification sample library, perform data simulation to obtain simulation results; establish a security domain test and verification platform based on the simulation results; construct a full-link semi-physical verification system, traverse the test samples in the security domain test and verification sample library, and obtain verification results; Module M3: Based on the verification results, the safety domain boundary of the spacecraft equipment is iteratively corrected according to the environmental factors, mission scenarios and product usage characteristics of the spacecraft, to obtain the corrected safety domain boundary; Module M4: Based on the corrected security domain boundary, the confidence level of the security domain boundary is calculated through the full-link semi-physical verification system.
[0078] Those skilled in the art will understand that, besides implementing the system and its various devices, modules, and units provided by this invention in the form of purely computer-readable program code, the same functions can be achieved entirely through logical programming of the method steps, making the system and its various devices, modules, and units of this invention function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, the system and its various devices, modules, and units provided by this invention can be considered as a hardware component, and the devices, modules, and units included therein for implementing various functions can also be considered as structures within the hardware component; alternatively, the devices, modules, and units for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0079] Specific embodiments of the present invention have been described above. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art can make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. Unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.
Claims
1. A method for constructing, solving, and verifying security domains in a power supply and distribution system, characterized in that, include: Step S1: Collect characteristic parameters of the power supply and distribution system, extract the operating point vector of the characteristic parameters, and then construct a safety domain test verification sample library; Step S2: Based on the security domain test and verification sample library, perform data simulation to obtain simulation results; based on the simulation results, establish a security domain test and verification platform; construct a full-link semi-physical verification system, traverse the test samples in the security domain test and verification sample library, and obtain verification results; Step S3: Based on the verification results, according to the spacecraft's environmental factors, mission scenarios and product usage characteristics, iteratively correct the safety domain boundary of the spacecraft equipment to obtain the corrected safety domain boundary; Step S4: Based on the corrected security domain boundary, the confidence level of the security domain boundary is calculated using the full-link semi-physical verification system.
2. The method for constructing, solving, and verifying security domains in a power supply and distribution system according to claim 1, characterized in that, In step S1, the characteristic parameters are power supply and distribution system parameters; the characteristic parameters include: bus voltage, bus current, solar array output current, battery pack voltage, battery pack charging current, battery pack discharging current, power controller temperature, battery pack temperature, solar cell circuit temperature, shunt MEA parameters, battery cell voltage, discharge switch status, distributor temperature and star-rocket separation signal. The operating point vector is used to describe the operating status of the power supply and distribution system parameters; The security domain test verification sample library, which is a logical unit formed by associating the running point vectors of feature parameters, is used to verify the security domain.
3. The method for constructing, solving, and verifying security domains in a power supply and distribution system according to claim 2, characterized in that, In step S2, the full-link semi-physical verification system is a semi-physical simulation system; Based on the simulation results, a security domain test and verification platform is established, including: Step B1: Build a full-link digital model based on simulation software and import the security domain test verification sample library; the simulation software includes: MATLAB or Simulink; Step B2: Configure simulation environment parameters; the simulation environment parameters include: spatial radiation intensity, extreme temperature range and vibration spectrum; the spatial radiation intensity is 1000 W / m²; the extreme temperature range is -50℃ to +80℃; the vibration spectrum is 5~2000 Hz; Step B3: Run the simulation and monitor the system status in real time. Determine if the simulation results are abnormal. If the result is yes, record it as a fault sample. If the result is no, do not process it. Step B4: Compare the simulation results with the preset security threshold, generate the initial value of the security domain boundary, and output it to the full-link semi-physical verification system.
4. The method for constructing, solving, and verifying security domains in a power supply and distribution system according to claim 1, characterized in that, Step S3 includes: Step S3.1: Take any power supply and distribution characteristic parameter operating point vector as the starting point, and traverse all characteristic operating point vectors in sequence to obtain the correlation relationship between each operating point vector; Step S3.2: Randomly select the running point vector as the free variable, fix other non-correlated parameters, and based on the correlation between the running point vectors, repeatedly perform safety judgment on the system by adjusting the characteristic parameter values of the free variable and the correlated variable until the running result reaches the critical safety state, that is, the safety domain boundary.
5. The method for constructing, solving, and verifying security domains in a power supply and distribution system according to claim 4, characterized in that, The operating point vector of the power distribution characteristic parameters is V0, where V0 = [bus voltage 38 V, battery temperature 45℃]; The safety judgment is as follows: If the bus voltage (a free variable) is adjusted to the critical value V_critical, and the battery pack charging current (a related variable) is less than or equal to the maximum current, and the power controller temperature is less than or equal to the safe temperature, then the system is considered to be in a safe state. If the result is yes, the system is considered to be in a critical safe state. If the result is no, the system is considered to be in a critical safe state, and the current bus voltage value is recorded as the boundary of the safe domain. Then, the critical point is approximated using a bisection method until the accuracy meets the accuracy requirements. The accuracy requirement is ±0.5 V; the critical value V_critical is 40 V; the maximum current is 10 A; and the safe temperature is 70 °C.
6. A system for constructing, solving, and verifying a power supply and distribution system using a security domain, characterized in that, include: Module M1: Collects characteristic parameters of the power supply and distribution system, extracts the operating point vector of the characteristic parameters, and then constructs a safety domain test verification sample library; Module M2: Based on the security domain test and verification sample library, perform data simulation to obtain simulation results; establish a security domain test and verification platform based on the simulation results; construct a full-link semi-physical verification system, traverse the test samples in the security domain test and verification sample library, and obtain verification results; Module M3: Based on the verification results, the safety domain boundary of the spacecraft equipment is iteratively corrected according to the environmental factors, mission scenarios and product usage characteristics of the spacecraft, to obtain the corrected safety domain boundary; Module M4: Based on the corrected security domain boundary, the confidence level of the security domain boundary is calculated through the full-link semi-physical verification system.
7. The system for constructing, solving, and verifying a power supply and distribution system using a security domain, as described in claim 6, is characterized in that... In module M1, the characteristic parameters are power supply and distribution system parameters; the characteristic parameters include: bus voltage, bus current, solar array output current, battery pack voltage, battery pack charging current, battery pack discharging current, power controller temperature, battery pack temperature, solar cell circuit temperature, shunt MEA parameters, battery cell voltage, discharge switch status, distributor temperature and star-rocket separation signal. The operating point vector is used to describe the operating status of the power supply and distribution system parameters; The security domain test verification sample library, which is a logical unit formed by associating the running point vectors of feature parameters, is used to verify the security domain.
8. The system for constructing, solving, and verifying a power supply and distribution system using a security domain, as described in claim 7, is characterized in that... In module M2, the full-link semi-physical verification system is a semi-physical simulation system; Based on the simulation results, a security domain test and verification platform is established, including: Module B1: Build a full-link digital model based on simulation software and import the security domain test verification sample library; the simulation software includes: MATLAB or Simulink; Module B2: Configure simulation environment parameters; the simulation environment parameters include: spatial radiation intensity, extreme temperature range and vibration spectrum; the spatial radiation intensity is 1000 W / m²; the extreme temperature range is -50℃ to +80℃; the vibration spectrum is 5~2000 Hz; Module B3: Runs the simulation and monitors the system status in real time, determines whether the simulation results are abnormal, records the result as a fault sample if the result is yes, and does not process it if the result is no. Module B4: Compares the simulation results with the preset security threshold, generates the initial value of the security domain boundary, and outputs it to the full-link semi-physical verification system.
9. The system for constructing, solving, and verifying a power supply and distribution system using a security domain, as described in claim 5, is characterized in that... The module M3 includes: Module M3.1: Taking any power supply and distribution characteristic parameter operating point vector as the starting point, iterates through all characteristic operating point vectors in sequence to obtain the correlation relationship between each operating point vector; Module M3.2: Randomly select the running point vector as the free variable, fix other non-correlated parameters, and based on the correlation between the running point vectors, repeatedly make safety judgments on the system by adjusting the characteristic parameter values of the free variable and the correlated variable until the running result reaches the critical safety state, that is, the boundary of the safety domain.
10. The system for constructing, solving, and verifying a power supply and distribution system using security domains according to claim 9, characterized in that, The operating point vector of the power distribution characteristic parameters is V0, where V0 = [bus voltage 38 V, battery temperature 45℃]; The safety judgment is as follows: If the bus voltage (a free variable) is adjusted to the critical value V_critical, and the battery pack charging current (a related variable) is less than or equal to the maximum current, and the power controller temperature is less than or equal to the safe temperature, then the system is considered to be in a safe state. If the result is yes, the system is considered to be in a critical safe state. If the result is no, the system is considered to be in a critical safe state, and the current bus voltage value is recorded as the boundary of the safe domain. Then, the critical point is approximated using a bisection method until the accuracy meets the accuracy requirements. The accuracy requirement is ±0.5 V; the critical value V_critical is 40 V; the maximum current is 10 A; and the safe temperature is 70 °C.
Citation Information
Patent Citations
Evaluation method based on distribution system security region
CN102368610A
Method for interworking trust between a trusted region and an untrusted region, method, server, and terminal for controlling the downloading of trusted applications, and control system applying same
CN103282911A
Data processing apparatus and method using secure domain and less secure domain
CN103310163A
Method, device and system for using safety domain in NAT network environment
CN103607403A
Improved fitting construction method of power system dynamic security region
CN104008275A