Satellite configuration whole-process management method and system
By introducing satellite development assurance levels and closed-loop control processes, combined with digital management, the systemic deficiencies in satellite configuration management were resolved, achieving efficient and reliable management of the satellite development process.
Patent Information
- Application Number
- CN202511794750.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-03-10
Smart Images

Figure CN121639141A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of spacecraft systems engineering and project management technology, and more specifically, to a method and system for managing the entire process of satellite configuration. Background Technology
[0002] Satellite development is characterized by long cycles, high technical difficulty, multidisciplinary integration, and complex supply chains, posing significant challenges to configuration management during the development process. Traditional configuration management focuses primarily on the later-stage control of product data and the recording of physical status, lacking deep integration with development processes, safety, and airworthiness requirements. This makes it difficult to cope with the frequent changes, upgrades, and serialization needs throughout the satellite's lifecycle.
[0003] In the civil aviation field, SAE ARP4754A, "Guideline for the Development of Civil Aircraft and Systems" (hereinafter referred to as "ARP4754A"), has proven to be an effective standard for managing the development process of highly complex and integrated systems. However, ARP4754A and its application practices are mainly concentrated in the aviation field. Currently, there is a lack of mature and systematic solutions for creatively applying its core concepts and systems engineering methods to satellite configuration management. The main obstacles to applying ARP4754A to satellite configuration management are as follows: First, the aviation field has long development cycles and cautious iterations, while satellite development cycles are relatively short and often employ rapid iteration, small-batch, or single-satellite customization models. The traditional ARP4754A process appears cumbersome in the satellite development field. Second, aircraft systems are highly integrated and emphasize "airworthiness," while satellites emphasize "on-orbit reliability" and "space environment adaptability." The "development assurance levels" in ARP4754A lack a direct corresponding system in satellites. Furthermore, satellites cannot be physically repaired after they are in orbit, so their modification control must be more stringent. The modification control procedures of ARP4754A are difficult to apply directly to satellite high-frequency technology updates.
[0004] Therefore, there is an urgent need for a satellite configuration management method and system that can apply ARP4754A to the field of satellite configuration management, and solve the problems of unsystematic satellite configuration control, insufficient hierarchical targeting, disordered change control, lack of audit supervision and incomplete traceability in the existing technology. Summary of the Invention
[0005] Based on existing technologies, the objective of this invention is to provide a method and system for managing the entire satellite configuration process, which can draw on and adapt to the concept of ARP4754A in the aerospace field, and realize precise, efficient and controlled management of satellite configuration throughout its entire life cycle, from conceptual design to on-orbit operation and maintenance.
[0006] According to the present invention, the above-mentioned tasks are solved by a satellite configuration full-process management method and system.
[0007] In a first aspect, the present invention provides a method for managing the entire satellite configuration process, the method comprising the following steps: Define the satellite development assurance level (DAL), which includes: Class A represents mission-critical systems in the satellite; failure of these systems will lead to mission failure or satellite damage. Class B represents critical functional systems within the satellite; failure of these systems would affect the execution of the satellite mission. Classes C and D represent auxiliary or redundant systems in the satellite; Based on the product breakdown structure of the satellite, configuration items are selected and defined, configuration identifiers are established for each configuration item, and the satellite development assurance level for each configuration item is defined; Define and control the satellite configuration baseline; Establish a satellite configuration change control process, including the following steps: Submit a change request; Conduct an impact analysis on the amendment request; The Configuration Control Committee reviews and makes decisions, which may include approval, conditional approval, rejection, or postponement. For approved change requests, the changes shall be implemented in accordance with the resolution of the configuration control committee and the updated design documents; Perform the prescribed verification activities to demonstrate that the changes achieved the intended effect and did not introduce any unintended consequences; and After verification is closed, update all affected configuration files, records, and baselines.
[0008] Furthermore: For configuration items of satellite DAL-A level, multiple rounds of independent testing, analysis, simulation and verification are performed to ensure that the verification fully covers all failure modes. Any changes to the configuration items must be reviewed by the full meeting of the configuration control committee and must be unanimously approved. The configuration items are fully audited at least once a quarter, and the audit content includes process compliance and / or record integrity. For DAL-B class satellite configuration items, key functional testing and analysis are performed, with a focus on verifying interfaces and performance. Any changes to these configuration items must be reviewed by core members of the Configuration Control Committee. These configuration items are audited at least once every six months, with the audit focusing on key milestones and change processes. For configuration items of satellite DAL-C / D class, routine testing and inspection are performed to ensure that the functions meet the requirements. Changes to the configuration items can be approved by an authorized representative through a fast track, but the changes must be recorded and tracked. The configuration items are audited at a low frequency, with sampling audits conducted annually and / or at key milestones, and priority is given to issues that have not been closed.
[0009] Furthermore, the method further includes the following steps: Introduce a design quality assurance role to oversee and audit the management activities related to the satellite configuration; and Record and maintain all satellite configuration-related data in real time, and establish a traceability chain from top-level satellite requirements to product realization, as well as from on-orbit anomaly feedback to design improvements.
[0010] Furthermore, the configuration baseline includes: Demand baseline, which is configured to capture and validate top-level functional and / or performance requirements at the satellite and system levels; The design baseline, configured as a review node for the corresponding satellite design phase, freezes validated design definitions; and The product configuration baseline is configured for the factory review of the corresponding satellite product, defining the physical and / or functional status of the satellite that is ultimately approved for launch.
[0011] Furthermore, the review nodes in the satellite design phase include preliminary design review and / or critical design review.
[0012] Furthermore, the oversight audit includes: The process of establishing and modifying the configuration baseline is subject to compliance checks. The completeness and accuracy of the configuration records, including issue reports and / or change requests, are subject to sampling audits; and Formal audits will be conducted at key stages throughout the satellite configuration process to ensure consistency between the physical state of the configuration and the documentation. These key stages include satellite assembly, testing, and / or delivery.
[0013] Furthermore, the sampling rules for the supervisory audit are as follows: For change requests, the sampling ratio is set to be no less than 10%, with a focus on sampling configuration items with high satellite development assurance levels; For baseline establishment and changes, a comprehensive audit of all key baselines, including requirement baselines and / or product configuration baselines, shall be conducted; and For issue reports, the sampling rate is set at 5% to 15%, with priority given to sampling issues that are not closed or recurring.
[0014] Furthermore, the closed-loop process for rectifying non-compliance items identified in the supervisory audit includes: The design quality assurance role records non-conformities and identifies the responsible unit; The responsible unit shall complete the root cause analysis of the non-conformities within the specified time and submit an analysis report; Develop a corrective and preventive action plan and have it reviewed by the aforementioned design quality assurance role; The responsible unit implements the rectification, and the design quality assurance role tracks and verifies the rectification process; After rectification, the design quality assurance role confirmed the effectiveness of the rectification and closed the non-conformities; and The rectification process for the aforementioned non-conformities will be entered into the digital platform.
[0015] A second aspect of the present invention provides a satellite configuration end-to-end management system, the system comprising: The plan definition module is configured to create and maintain satellite configuration management plans; Configuration identification module, which is configured to manage the identification of product breakdown structure and configuration items; The baseline management module is configured to establish, control, and publish the requirements baseline, design baseline, and product configuration baseline. The control module is modified to execute the closed-loop configuration change control flow. The process assurance and audit module is configured to support design quality assurance roles in performing configuration management compliance audit activities. The status recording and traceability module is configured to enable centralized storage of configuration data, status reporting, and full lifecycle traceability.
[0016] Furthermore, the system is built on a digital platform configured to provide data storage, a process engine, a user interface, and an integration interface.
[0017] The satellite configuration whole-process management method and system proposed in this invention have at least the following beneficial effects: The method and system proposed in this invention establish for the first time in the satellite field a development assurance level system (satellite DAL level) that corresponds to the aviation ARP4754A standard and is specifically adapted to the characteristics of satellites. It uses the consequences of satellite functional failure and mission relevance as the classification standard, providing a theoretical basis and practical foundation for the subsequent graded management and control of satellites.
[0018] The method and system proposed in this invention provide real-time differentiated verification intensity, change control strictness, and audit frequency for configuration items at different levels, solving the problems of inefficiency and / or insufficient control caused by the traditional "one-size-fits-all" approach to satellite configuration management.
[0019] The method and system proposed in this invention establish a complete closed-loop change process and introduce a design quality assurance role as an independent supervisory and auditing role to achieve supervision of the entire process and ensure the rationality and controllability of decisions throughout the process.
[0020] In summary, the method and system proposed in this invention map the ARP4754A standard from the aerospace field to the satellite field, constructing a rigorous, efficient, and digital configuration management system. Through hierarchical differentiated management corresponding to the satellite DAL level, as well as the introduction of closed-loop control and supervisory audit roles, it significantly improves the quality, reliability, and management efficiency of satellite development. It can effectively adapt to the multidisciplinary, long-cycle, and high-reliability development requirements of complex aerospace products such as satellites, providing an efficient and feasible solution for configuration management of various satellite systems, especially large-scale satellite constellations. Attached Figure Description
[0021] To further illustrate the advantages and other features of the various embodiments of the present invention, a more specific description of the embodiments of the present invention will be presented with reference to the accompanying drawings. It is understood that these drawings depict only typical embodiments of the invention and are therefore not intended to limit its scope. In the drawings, identical or corresponding parts will be indicated by the same or similar reference numerals for clarity.
[0022] Figure 1 The overall flowchart of the satellite configuration management method according to an embodiment of the present invention is shown.
[0023] Figure 2 A flowchart illustrating the closed-loop control process for satellite configuration changes according to an embodiment of the present invention is shown.
[0024] Figure 3 A schematic diagram of the module composition of the satellite configuration full-process management system according to an embodiment of the present invention is shown.
[0025] List of reference numerals 100-Satellite Configuration Full-Process Management System 101 Plan Definition Module 102 Configuration Identification Module 103 Baseline Management Module 104 Change the control module 105 Process Assurance and Audit Module 106 Status Recording and Traceability Module Detailed Implementation It should be noted that the components in the various figures may be shown exaggeratedly for illustrative purposes and are not necessarily to scale. In each figure, the same reference numerals are used for components that are identical or have the same function.
[0026] In this invention, the various embodiments are merely intended to illustrate the solutions of the invention and should not be construed as limiting.
[0027] In this invention, unless otherwise specified, the quantifiers “a” and “one” do not exclude scenarios involving multiple elements.
[0028] It should also be noted that, in the embodiments of the present invention, only a portion of the components or parts may be shown for clarity and simplicity. However, those skilled in the art will understand that, under the teachings of the present invention, necessary components or parts can be added as needed for specific scenarios. Furthermore, unless otherwise stated, features in different embodiments of the present invention can be combined with each other. For example, a feature in the second embodiment can replace a corresponding or functionally identical or similar feature in the first embodiment, and the resulting embodiment will also fall within the scope of disclosure or description of this application.
[0029] It should also be noted that within the scope of this invention, the terms "same", "equal", and "equal to" do not mean that the two values are absolutely equal, but allow for a certain reasonable error. In other words, the terms also cover "substantially the same", "substantially equal", and "substantially equal to".
[0030] In this invention, the modules of the system according to the invention can be implemented using software, hardware, firmware, or a combination thereof. When a module is implemented using software, its function can be implemented through computer program flow. For example, the module can be implemented using code segments (such as code segments in languages like C and C++) stored in a storage device (such as a hard disk, memory, etc.), wherein the corresponding function of the module can be implemented when the code segment is executed by a processor. When a module is implemented using hardware, its function can be implemented by setting a corresponding hardware structure. For example, the module's function can be implemented by hardware programming a programmable device such as a field-programmable gate array (FPGA), or by designing an application-specific integrated circuit (ASIC) that includes multiple transistors, resistors, capacitors, and other electronic devices. When a module is implemented using firmware, the module's function can be written into a read-only memory such as an EPROM or EEPROM in the form of program code, and the corresponding function of the module can be implemented when the program code is executed by a processor. In addition, some functions of the module may need to be implemented by separate hardware or by working in cooperation with the hardware. For example, the detection function is implemented by a corresponding sensor (such as a proximity sensor, accelerometer, gyroscope, etc.), the signal transmission function is implemented by a corresponding communication device (such as a Bluetooth device, infrared communication device, baseband communication device, Wi-Fi communication device, etc.), the output function is implemented by a corresponding output device (such as a display, speaker, etc.), and so on.
[0031] Furthermore, the steps of the methods of the present invention are not limited in terms of the execution order of the method steps. Unless otherwise specified, the method steps may be executed in different orders.
[0032] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.
[0033] ARP 4754A, "Civil Aircraft and Systems Development Guidelines," defines Development Assurance Levels (DALs) in the aerospace field. Aerospace DALs are classified into five levels, A to E, based on the severity of the impact of system failure on aircraft safety, performance, and operation. The definitions of each level and the corresponding consequences of failure are as follows: Level A is the highest level, defined as a "catastrophic failure level," corresponding to an aircraft-level "catastrophic failure condition." At this level, if development errors in system functions or projects are exposed during operation, they will directly lead to the extreme consequences of aircraft crashing and loss of life. This is the most serious type of failure that threatens flight safety and requires the most stringent development assurance process to control the risk of development errors.
[0034] Level B is defined as a "hazardous failure level," corresponding to an aircraft-level "hazardous / serious failure condition." Development errors in system functions or projects can significantly reduce the aircraft's safety margin and may lead to serious accidents. Although they may not directly cause the destruction of the aircraft or loss of life, they will greatly increase the difficulty for the crew to respond and the flight risks, requiring high-intensity development and process control.
[0035] Level C is defined as a "major failure level," corresponding to the "major failure condition" at the aircraft level. Development errors in system functions or projects can lead to a decline in aircraft performance or a significant increase in crew workload. Although they do not directly threaten flight safety, they can affect flight efficiency and operational stability, requiring a moderately intensive development assurance process to ensure development quality.
[0036] Level D is defined as a "minor failure level," corresponding to "minor failure conditions" at the aircraft level. Development errors in system functions or projects cause only minor impacts, such as the failure of non-critical auxiliary functions. This does not affect aircraft safety performance or increase the crew's workload, and only basic development assurance processes are required to meet the requirements.
[0037] Level E is the lowest level, defined as a "no-impact failure level." Errors in the development of system functions or projects have no substantial impact on aircraft safety, performance, or operation. Typical scenarios include passenger entertainment system malfunctions and non-critical information recording deviations. No specific development assurance measures are required; commercially available components can be used, or the development process can be simplified. Failure will not have any adverse consequences for flight.
[0038] In this invention, the Satellite Development Assurance Level (hereinafter referred to as Satellite DAL) is a graded control indicator formed by mapping and adapting the core logic, definition, and corresponding development assurance process of aerospace DAL, combined with the characteristics of the satellite field. Its definition is based on the correlation between the satellite system function and the satellite mission objective, and is divided according to the severity of the impact of system failure on satellite mission execution and satellite safety. The specific definition is as follows: Level A is the highest level, defined as "mission critical system level". It corresponds to the core systems in the satellite that directly determine the success or failure of the mission and the safety of the satellite itself, such as attitude control system and power supply system. Failure of such systems will directly lead to the complete failure of the satellite mission or the destruction of the satellite. Level B is defined as "Important Functional System Level", which corresponds to the key functional systems in the satellite that support the execution of core missions, such as data transmission systems and thermal control systems. Although the failure of such systems will not directly cause damage to the satellite, it will significantly affect the normal execution of satellite missions, resulting in a decrease in mission efficiency or the inability to achieve some mission objectives. C / D level is defined as "auxiliary or redundant system level", which corresponds to the systems in the satellite that provide support for the core system and important functional system or have redundant backup, such as some ground communication auxiliary modules, non-critical redundant power supply modules, etc. The failure of such systems will only have a minor impact, and the substantial interference with the satellite mission can be avoided through redundant design or functional replacement, and will not lead to mission execution obstruction or satellite safety risks.
[0039] Figure 1 A general flowchart of the satellite configuration management method according to an embodiment of the present invention is shown. Figure 1 As shown, in one embodiment of the present invention, the satellite configuration management process begins with the launch of the satellite project, and specifically includes the following steps: Establish a satellite configuration management plan. At the initial stage of satellite project initiation, formulate a top-level "Satellite Configuration Management Plan". This plan not only defines the technical methods for configuration identification, baseline management, change control, and status recording, but also clarifies its connection with satellite development assurance levels, and stipulates the interface relationships and coordination mechanisms between configuration management activities and other project plans such as system development plans, safety plans, and verification plans, serving as the basis and guideline for all subsequent activities.
[0040] Based on the Satellite Configuration Management Plan, the product breakdown structure of the satellite is defined, and configuration items (CIs) are selected and defined from top to bottom. A unique identifier is assigned to each configuration item, and its association with relevant requirements, design documents, interface control documents, and other configuration documents is established. Configuration identifiers cover all levels from satellite system, subsystem, and unit to critical hardware and software. For each configuration item, its corresponding satellite Data Access Element (DAL) is clearly defined, and different verification strengths, change control stringency, and audit frequencies are determined accordingly.
[0041] Define and control the satellite configuration baseline, and establish and freeze the following three types of core baselines at key milestones in satellite development: Demand baselines are configured to capture and validate top-level functional and performance requirements at the satellite and system levels.
[0042] The design baseline is configured to correspond to nodes such as preliminary design review and critical design review, freezing the validated detailed design definition.
[0043] The product configuration baseline is configured to correspond to the product factory review and define the physical and functional state of the satellite that will be finally approved for launch.
[0044] In one embodiment of the invention, all baseline establishment and changes must go through a strict change control process.
[0045] Establish a closed-loop satellite configuration change control process, which is a closed-loop process in parallel with baseline management, and involves applying for, analyzing, deciding on, implementing and verifying all proposed changes.
[0046] A Design Quality Assurance (DQA) role is introduced to oversee and audit the management activities of the satellite configuration. This activity is carried out throughout the satellite configuration item definition, configuration baseline management and change control processes to ensure that the entire process is executed correctly.
[0047] Record and maintain all satellite configuration-related data in real time, and establish a traceability chain from top-level satellite requirements to product realization, as well as from on-orbit anomaly feedback to design improvements.
[0048] The process culminates in the end of on-orbit satellite operation and maintenance. Simultaneously, anomalies and upgrade requests arising during the on-orbit operation and maintenance phase will serve as new inputs to the change control process, forming a closed loop from operational feedback to design improvements.
[0049] In one embodiment of the invention, for the configuration items of the DAL-A class satellite: The highest level of verification intensity is adopted, including multiple rounds of independent testing, analysis, simulation and verification, to ensure that the verification fully covers all failure modes; The highest level of change control is applied; any change must be reviewed by the full meeting of the Configuration Control Committee and must be unanimously approved. The highest audit frequency is adopted, with at least one comprehensive audit conducted every quarter, covering process compliance and record integrity.
[0050] In one embodiment of the invention, for the configuration items of the DAL-B class satellite: A moderate level of verification intensity was adopted, including critical functional testing and analysis, with a focus on verifying interfaces and performance; A moderate level of change control is adopted, and any changes must be reviewed by core members of the configuration control committee; Adopt a moderate audit frequency, conducting audits at least once every six months, focusing on key milestones and process changes.
[0051] In one embodiment of the invention, for the configuration terms of satellite DAL-C / D class: Adopt basic verification strength, including routine testing and inspection, to ensure that the functionality meets the requirements; Basic change control stringency is adopted; changes can be approved by authorized representatives through a fast track, but changes must be documented and tracked. Adopt a lower audit frequency, conduct sample audits annually and / or at key milestones, and prioritize issues that have not been closed.
[0052] Figure 2 A flowchart illustrating the closed-loop control process for satellite configuration changes according to an embodiment of the present invention is shown. This closed-loop process ensures that all changes to the baselined configuration undergo systematic and standardized evaluation, decision-making, and implementation. Figure 2 As shown, in one embodiment of the present invention, the process includes: To submit a change request, any relevant party (such as the designer, manufacturer, and / or tester) can submit a change request through a standardized form, specifying the content of the change, the reason for the change, and the preliminary solution.
[0053] An impact analysis will be conducted on the change requests. A cross-functional expert team will be established to perform a comprehensive impact analysis of the change requests and issue an impact analysis report. The analysis dimensions include: Technical impact: This change affects performance, interfaces, security, and reliability; Project impact: The impact of this change on schedule and cost; and Scope of impact: This change affects all affected configuration items, documents, and delivered products.
[0054] The configuration control committee reviews and makes decisions based on the aforementioned impact analysis report. The decision results include approval, conditional approval, rejection, or shelving.
[0055] Change approval and implementation: For approved change requests, changes are implemented in accordance with the resolutions of the Configuration Control Committee and the updated design documents. Specifically, changes may involve design modifications, software refactoring, and / or production rework.
[0056] Once validation is complete, perform the prescribed validation activities (such as analysis, testing, and / or review) to demonstrate that the changes achieved the intended effect and did not introduce any unintended consequences. The validation results also need to be verified to ensure accuracy.
[0057] After verification is closed, the status update involves updating all affected configuration files, records, and baselines in the digital configuration management system to ensure the accuracy of the configuration status record. This step marks the closure of this change activity.
[0058] In one embodiment of the invention, a Design Quality Assurance (DQA) role is introduced to supervise and audit the management activities of the satellite configuration. Specifically, the types and frequency of the supervision and audit are set as follows: Regular audits should be conducted, with systematic audits of the satellite configuration management process performed quarterly or semi-annually. Event-driven auditing involves conducting specialized audits at key milestones such as preliminary design review, critical design review, and / or pre-shipment. Random sampling audits are conducted on ongoing change processes.
[0059] In one embodiment of the present invention, the sampling ratio and rules for supervisory auditing are set as follows: The sampling rate for change requests shall not be less than 10%, with a focus on sampling configuration items with high satellite DAL ratings; For baseline establishment and changes, a full audit is conducted on the establishment and changes of each key baseline (such as the demand baseline and product configuration baseline). The sampling rate for issue reports is between 5% and 15%, with priority given to issues that are not closed or recurring.
[0060] In one embodiment of the present invention, after a non-conformity is discovered during the supervision and audit process, a closed-loop process for non-conformity rectification is initiated, specifically including: The DQA role records non-compliance items and identifies the responsible unit; The responsible unit shall complete the root cause analysis of the nonconformities within the specified time (e.g., preferably 5 working days) and submit an analysis report; Develop a corrective and preventive action plan and have it reviewed by the DQA role; The responsible unit implements the rectification, and the DQA role tracks and verifies the rectification process; After rectification, the DQA role confirmed the rectification was effective and closed the non-conformities; and The rectification process for the aforementioned non-conformities will be entered into the digital platform for future traceability.
[0061] In one embodiment of the present invention, the satellite configuration end-to-end management system 100 is built on a unified digital platform (such as an MBSE platform or an enhanced PLM system), which serves as the foundation of the entire system and provides data storage, process engine, user interface and integration interface.
[0062] Figure 3A schematic diagram of the module composition of the satellite configuration end-to-end management system according to an embodiment of the present invention is shown. Figure 3 As shown, in one embodiment of the present invention, the satellite configuration end-to-end management system 100 includes the following modules: The plan definition module 101 is configured to create, maintain and publish the "Satellite Configuration Management Plan", which specifies the interface relationship and coordination mechanism between configuration management activities and other project plans such as system development plan, safety plan, and verification plan, providing top-level guidance and execution criteria for satellite configuration management throughout its entire life cycle.
[0063] Configuration identification module 102 is configured to manage the product breakdown structure of the satellite, select and define configuration items from top to bottom, assign a unique identifier to each configuration item, establish the association between configuration items and configuration documents such as relevant requirements documents, design documents, and interface control documents, and ensure that configuration identification covers all levels from satellite system, subsystem, single unit to key software and hardware, so as to realize the identifiability and association of configuration items.
[0064] The baseline management module 103 is configured to establish, control, and publish requirement baselines, design baselines, and product configuration baselines for key milestones in satellite development. It provides baseline creation, freezing, publishing, and query functions, and can manage multiple types of baselines such as requirements, designs, and products. It also records the version history and change trajectory of the baselines to ensure that the configuration status of the satellite at different development stages is unique, correct, and traceable.
[0065] The change control module 104 is configured as a digital representation of a closed-loop satellite configuration change control process, supporting the submission of change requests, the conduct of cross-dimensional impact analysis, the review and decision-making of the configuration control committee, the approval and implementation of changes, verification and closure, and configuration status updates. Through digital means, the traceability and transparency of the change process are ensured, and the comprehensive impact of changes on technical status, security, reliability, schedule, cost, and interface systems is systematically assessed.
[0066] The Process Assurance and Audit Module 105 is configured to provide tools for DQA roles, supporting DQA roles in carrying out configuration management compliance audit activities. It provides functions such as audit plan development, audit discovery recording, non-conformity tracking, rectification verification, and audit report generation, covering scenarios such as compliance checks on configuration baseline establishment and changes, review of the completeness and accuracy of configuration records, and audit of the consistency between the physical status of satellite key node configurations and document records.
[0067] The status recording and traceability module 106 is configured to automatically collect data from other modules based on a unified digital collaborative platform. This enables centralized storage, real-time maintenance, and status report generation of satellite lifecycle configuration data. It establishes an end-to-end bidirectional traceability chain from top-level satellite requirements to lowest-level product implementation, and from on-orbit anomaly feedback to design improvements. It integrates various data such as configuration items, baselines, change requests, deviation permits, and issue reports, providing accurate and comprehensive configuration information support for project management decisions. For example, it can trace back from requirements to the individual units that fulfilled those requirements, or from on-orbit faults to all relevant design and test records.
[0068] In one embodiment of the present invention, the satellite configuration full-process management system 100 provides services to users with different roles in satellite projects (such as project managers, designers, DQA roles and / or configuration control committee members), and integrates with external demand management, test management and / or supply chain management systems to achieve data interoperability between systems.
[0069] The application scenarios of the method and system of the present invention will be further illustrated below through a specific embodiment of the present invention.
[0070] In a specific embodiment of the present invention, the development of a certain type of high-resolution Earth observation satellite is taken as an example. During the project initiation phase, the "XX Satellite Configuration Management Plan" is prepared according to the method of the present invention, which clearly states that a baseline-based management strategy will be adopted and specifies the control stringency adapted to the satellite DAL allocation (e.g., classifying the attitude control subsystem as Class B).
[0071] Furthermore, the product structure decomposition of the satellite was completed, identifying top-level configuration items such as platform and payload, and assigning a unique code to each configuration item. Following the system requirements review, a preliminary requirements baseline was established.
[0072] Further, in the engineering development phase, a preliminary design baseline is established after the preliminary design review, and a detailed design baseline is established after the critical design review. During this period, if the payload camera interface needs to be changed, a change request is initiated. The Configuration Control Committee organizes experts to conduct a comprehensive impact analysis, assessing its impact on interfaces such as power supply, thermal control, and data transmission, as well as its impact on schedule and cost. After approval, the change is implemented under controlled conditions and verified in relevant tests. DQA engineers sample and review the records of this change process to ensure compliance with established procedures.
[0073] Before the satellite leaves the factory, a product configuration baseline is established. Through a unified digital platform, the final configuration list of the satellite can be generated quickly, and the origin of the requirements for any individual unit and the history of all changes that have been made can be traced.
[0074] Although various embodiments of the invention have been described above, it should be understood that they are presented by way of example only and not as limitations. It will be apparent to those skilled in the art that various combinations, modifications, and alterations can be made without departing from the spirit and scope of the invention. Therefore, the breadth and scope of the invention disclosed herein should not be limited by the exemplary embodiments disclosed above, but should be defined solely by the appended claims and their equivalents.
Claims
1. A satellite configuration whole process management method, characterized by, The method comprises the steps of: defining a satellite development assurance level (DAL) comprising: DAL-A, representing mission critical systems in the satellite, failure of which will result in mission failure or satellite destruction; DAL-B, representing important functional systems in the satellite, failure of which will affect the execution of the satellite mission; and DAL-C and DAL-D, representing auxiliary systems or redundant systems in the satellite; based on a product breakdown structure of the satellite, selecting and defining configuration items, establishing a configuration identification for each of the configuration items, and defining a satellite development assurance level for each of the configuration items; defining and controlling a satellite configuration baseline; establishing a satellite configuration change control process comprising the steps of: submitting a change request; performing an impact analysis on the change request; reviewing and deciding by a configuration control board, the decision comprising approval, conditional approval, rejection or shelving; implementing the change according to the decision of the configuration control board and updated design documents for the approved change request; performing prescribed verification activities to demonstrate that the change achieves the intended effect and does not introduce unintended consequences; and updating all affected configuration files, records and baseline after verification closure.
2. The method of claim 1, wherein: for a configuration item of DAL-A of the satellite, performing multiple rounds of independent testing, analysis, simulation and verification to ensure that verification covers all failure modes comprehensively, any change to the configuration item must be reviewed by a full meeting of the configuration control board and requires unanimous approval, and a full audit of the configuration item is performed at least once per quarter, the audit including process compliance and / or record completeness; for a configuration item of DAL-B of the satellite, performing critical function testing and analysis, focusing on interface and performance verification, any change to the configuration item must be reviewed by core members of the configuration control board, and an audit of the configuration item is performed at least once per half year, the audit focusing on critical nodes and change process; and for a configuration item of DAL-C / D of the satellite, performing routine testing and inspection to ensure that the function meets requirements, changes to the configuration item can be approved by authorized representatives through a fast track, but the changes are recorded and tracked, and a lower frequency of audit is performed on the configuration item, with sampling audits at yearly and / or key milestones, with a focus on open issues.
3. The method of claim 1, wherein, The method further comprises the steps of: introducing a design quality assurance role to supervise and audit management activities of the satellite configuration; and maintaining real-time records of all satellite configuration related data, establishing a traceability chain from top level requirements of the satellite to product implementation, and from in-orbit anomaly feedback to design end improvement.
4. The method of claim 1, wherein, The configuration baseline comprises: a requirement baseline configured to capture and confirm top level functional and / or performance requirements at satellite level and system level; a design baseline configured to freeze verified design definition corresponding to review nodes of the satellite design phase; and a product configuration baseline configured to define a physical and / or functional state of the satellite finally approved for launch corresponding to a launch review of the satellite product.
5. The method of claim 4, wherein, The review nodes of the satellite design phase comprise a preliminary design review and / or a critical design review.
6. The method of claim 1, wherein, The supervision and audit comprises: Conducting compliance check on the configuration baseline establishment and change process; Sampling auditing the completeness and accuracy of configuration records including problem report and / or change request; and Formally auditing the consistency between configuration physical state and documentation at important nodes in the whole satellite configuration process, including satellite assembly, test and / or delivery.
7. The method of claim 6, wherein, The sampling rules of the supervision audit are: For change request, the sampling ratio is set no less than 10%, and the configuration items of high satellite development assurance level are sampled in priority; For baseline establishment and change, the whole content of key baseline including requirement baseline and / or product configuration baseline is supervised and audited; And For problem report, the sampling ratio is set 5% to 15%, and the problems which are not closed or repeatedly occurred are sampled in priority.
8. The method of claim 7, wherein, The rectification closed-loop process for the items not meeting the requirements of the supervision audit includes: The design quality assurance role records the items not meeting the requirements and clarifies the responsible unit; The responsible unit completes the root cause analysis of the items not meeting the requirements within the specified time and submits the analysis report; The rectification and prevention measures plan is made and audited by the design quality assurance role; The responsible unit implements the rectification, and the design quality assurance role tracks and verifies the rectification process; After the rectification, the design quality assurance role confirms the rectification effective and closes the items not meeting the requirements; and The rectification process of the items not meeting the requirements is recorded in the digital platform.
9. A satellite configuration life cycle management system, characterized by, The system includes: A plan definition module configured to create and maintain the satellite configuration management plan; A configuration identification module configured to manage the product breakdown structure and the identification of configuration items; A baseline management module configured to establish, control and release the requirement baseline, design baseline and product configuration baseline; A change control module configured to perform the closed-loop configuration change control process; A process assurance and audit module configured to support the design quality assurance role to conduct configuration management compliance audit activities; A state record and traceability module configured to realize the centralized storage, state reporting and whole life cycle traceability of configuration data.
10. The system of claim 9, wherein, The system is built based on a digital platform configured to provide data storage, process engine, user interface and integrated interface.