Reinforcing system and method suitable for inertial navigation electronic equipment in aerospace environment

By employing a dual-redundancy design with primary and backup channels and an autonomous reconfiguration unit, the problem of single-event rollover failure in inertial navigation electronic equipment in the aerospace environment has been solved. This achieves high reliability and low-cost radiation hardening of the equipment, ensuring that it can quickly return to normal operation after a failure.

CN121876958APending Publication Date: 2026-04-17XIAN FLIGHT SELF CONTROL INST OF AVIC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XIAN FLIGHT SELF CONTROL INST OF AVIC
Filing Date
2025-12-09
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Inertial navigation electronic equipment is susceptible to single-event upsets in the aerospace environment, which can cause the equipment to malfunction. Moreover, the existing technology relies on aerospace-grade components, which are expensive and cannot meet the requirements of aircraft for low cost and high reliability.

Method used

It adopts a dual-redundancy design with a main channel and a backup channel, combined with an autonomous reconfiguration unit. It identifies single-particle flip faults through self-monitoring and comparison, and performs channel switching and autonomous reconfiguration when a fault occurs to ensure normal operation of the equipment.

Benefits of technology

It achieves high reliability and low-cost radiation hardening of inertial navigation electronic equipment in the aerospace environment, ensuring that the equipment can quickly return to normal operation after failure and meet the long-endurance mission requirements of aerospace vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121876958A_ABST
    Figure CN121876958A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of avionics, and particularly relates to a reinforcing system and method suitable for inertial navigation electronic equipment in an aerospace environment. The system adopts an autonomously reconfigurable dual-redundancy self-monitoring architecture design, and compared with traditional inertial navigation electronic equipment, through complete fault detection, monitoring of faults caused by single event upset and seamless switching between channels, it is ensured that the inertial navigation electronic equipment can still work continuously, coherently and normally when the faults occur, and the reliability of the inertial navigation electronic equipment is improved. And meanwhile, by utilizing autonomous reconstruction of the power supply, the single event upset fault is further solved, and the influence of the single event upset fault on inertial navigation equipment is eliminated. According to the method, the aerospace environment adaptability design of the inertial navigation electronic equipment is effectively realized on the system architecture level, the principle is simple and clear, the realization difficulty is relatively low, and the method is a standardized, high-reliability, comprehensive and low-cost radiation-proof reinforcement method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of avionics technology, specifically relating to a ruggedization system and method for inertial navigation electronic equipment suitable for aerospace environments. Background Technology

[0002] Inertial navigation electronic equipment (INS) is a core component of aerospace vehicles, primarily responsible for providing various motion information such as position, velocity, heading, attitude, angular rate, and acceleration. It serves as a crucial information source for the core navigation equipment and flight control system during launch, orbit insertion, on-orbit operation, and reentry / return phases in the aerospace environment. The aerospace environment is a cosmic radiation environment. According to relevant data, single-event effects caused by cosmic radiation result in electronic system failure rates as high as 40%. One of the most common failure modes of single-event effects is single-event upset (SEU), which alters the logic state of processors, programmable logic chips, and memory devices, affecting their normal function and causing damage and harm to INS. In severe cases, it can even threaten the safety of the entire spacecraft. Therefore, the development of INS for the aerospace environment must consider radiation hardening design.

[0003] Radiation hardening of electronic devices is typically carried out at the device level, mainly using aerospace-grade components with single-event upset resistance, such as anti-fuse devices. However, aerospace-grade components are expensive, and most have high power consumption and large size, which does not meet the cost, power consumption, and size requirements of spacecraft. Therefore, there is an urgent need to explore a system-level space radiation hardening and protection solution. At the same time, the trend of low-Earth orbit internet constellation applications demanding lower costs is becoming increasingly apparent, further highlighting the importance of system-level radiation hardening solutions.

[0004] In the aerospace environment, when a single event upset (SOME) occurs, the value of one or more register bits in a digital device will flip, i.e., a preset 0 becomes 1 and a 1 becomes 0. If the occurrence of this fault can be accurately monitored and recorded, and it can be ensured that the inertial navigation electronic equipment can still maintain normal operation when the fault occurs, and even further, the fault caused by the SOME can be resolved, then the aerospace environment adaptability of the inertial navigation electronic equipment can be effectively improved. To achieve this function, we can start from the system level and take radiation hardening measures in the architecture design of the inertial navigation electronic equipment. Summary of the Invention

[0005] The purpose of this invention: A ruggedization system and method for inertial navigation electronic equipment (INS) in aerospace environments are proposed to improve the mission reliability of INS in aerospace environments, meet the high reliability requirements of long-endurance full-orbit operation of onboard INS for aerospace vehicles, and solve the survival problem of INS in complex aerospace radiation environments.

[0006] Technical solution: A ruggedized system for inertial navigation electronic equipment suitable for aerospace environments includes: a main channel and a backup channel. Both the main channel and the backup channel include a monitoring branch, a command branch, a mission clock synchronization unit, and an autonomous reconfiguration unit. The mission clock synchronization units of the main channel and the backup channel are connected via a bus to achieve mission clock synchronization between the main and backup channels. The main channel mission clock synchronization unit distributes clock signals to the main channel monitoring branch and the main channel command branch. The main channel monitoring branch receives and processes data, compares the processed data with the data from the main channel command branch, and sends the comparison result to the main channel command branch. The main channel command branch processes data... The system receives, processes, and compares the data with the data processed by the main channel monitoring branch. It also compares the comparison results of the main channel command branch with those of the main channel monitoring branch and outputs the processed data. The backup channel task clock synchronization unit distributes clocks to the backup channel monitoring branch and the backup channel command branch. The backup channel monitoring branch receives, processes, and compares the data with the data processed by the backup channel command branch and sends the comparison results to the backup channel command branch. The backup channel command branch receives, processes, and compares the data with the data processed by the backup channel monitoring branch. The autonomous reconfiguration unit performs autonomous reconfiguration on its assigned channel.

[0007] A hardening method for inertial navigation electronic equipment suitable for aerospace environments, the method being executed using the aforementioned system, the method comprising: Step 1: Compare the comparison results of the main channel command branch with the comparison results of the main channel monitoring branch. If they match, the main channel command branch outputs the solved data. Step 2: Compare the comparison results of the main channel command branch with the comparison results of the main channel monitoring branch. If they are inconsistent, the main channel command branch sends a fault power-off signal and a normal start reset signal to the autonomous reconfiguration unit, triggering the autonomous reconfiguration unit to perform autonomous reconfiguration of the main channel and send fault status information to the backup channel command branch. During the autonomous reconfiguration of the main channel, when the backup channel is in normal condition, after receiving the fault status information of the main channel, the backup channel will take over the faulty main channel and output the calculated data to the outside world. After the main channel is autonomously reconfigured, it will serve as a backup channel.

[0008] Furthermore, in step 2, after the main channel is autonomously reconstructed, the missing solution data during the autonomous reconstruction of the main channel is obtained through the backup channel and used for subsequent data solution.

[0009] Furthermore, step 1 also includes: The comparison results of the backup channel command branch are compared with the comparison results of the backup channel monitoring branch. If they are inconsistent, the backup channel command branch sends a fault power-off signal and a normal start reset signal to the autonomous reconfiguration unit to trigger the autonomous reconfiguration unit to perform autonomous reconfiguration of the backup channel and send fault status information to the main channel command branch. Once the backup channel has completed its autonomous reconfiguration, it will continue to serve as a backup channel.

[0010] Furthermore, after the backup channel completes its autonomous reconstruction, the missing solution data during the backup channel's autonomous reconstruction is obtained through the main channel and used for subsequent data calculation.

[0011] Furthermore, in step 2, during the autonomous reconfiguration process, the power supply hardware circuit of the fault channel is shut down by the faulty electrical signal control. After shutdown, the power supply hardware circuit will automatically restart multiple times. At the same time, the normal start-up clear signal is used to clear the number of restarts after multiple successful restarts, so as to avoid the false accumulation of the number of restarts.

[0012] Furthermore, the number of restarts is less than or equal to N, where N is the set number of restarts.

[0013] Furthermore, if the restart attempt fails after N attempts, the channel is considered to have suffered an unrecoverable failure and will be taken offline.

[0014] Beneficial effects: 1. This invention provides a hardening system and method for inertial navigation electronic equipment (INS) suitable for aerospace environments. This ensures that the INS can accurately monitor and identify single-event upsets (SEORs) and maintain normal operation even after an SEOR occurs. Furthermore, the system can autonomously eliminate SEOR faults and restore normal functionality, thus effectively achieving aerospace environment adaptability design for INS at the system architecture level. The method is simple and clear in principle, easy to implement, and represents a standardized, highly reliable, and comprehensive design approach.

[0015] 2. This invention achieves protection and reinforcement against single-event upset effect at the system architecture level of inertial navigation electronic equipment in aerospace environment, avoiding the high cost of using aerospace-grade components, and achieving low cost and good economic effect. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. The drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1This is a schematic diagram of a ruggedized system for inertial navigation electronic equipment suitable for aerospace environments, according to the present invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] The features and illustrative embodiments of various aspects of the present invention will now be described in detail. Numerous specific details are set forth in the following detailed description to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of the invention by illustrating examples of the invention. The invention is by no means limited to any specific setups and methods set forth below, but covers any improvements, substitutions, and modifications to structures, methods, and devices without departing from the spirit of the invention. Well-known structures and techniques are not shown in the drawings and the following description to avoid unnecessarily obscuring the invention.

[0020] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly, encompassing both direct connection and indirect connection via an intermediate medium. Those skilled in the art can understand the specific meaning of these terms in this invention based on the specific circumstances.

[0021] It should be noted that, unless otherwise specified, the embodiments of the present invention and the features thereof can be combined with each other, and the various embodiments can be referenced and cited in each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0022] The present invention will be further described in detail below with reference to the embodiments and accompanying drawings, but the embodiments of the present invention are not limited thereto.

[0023] Spacecraft require inertial navigation systems (INS) with a reliability of 0.9 or higher for one year of on-orbit missions. Traditional single-channel strapdown INS systems, however, have a reliability of approximately 0.8, failing to meet the demands of the space environment. Traditional INS systems are all single-channel designs; in the event of a channel failure, redundancy is directly degraded, lacking autonomous power control and channel reconfiguration. This invention proposes a ruggedized system for INS electronic equipment suitable for space environments. Compared to traditional INS systems, it incorporates a dual-redundancy design. During redundancy switching, continuous availability of output navigation information is ensured. A mirrored storage of historical INS data between redundancies is invented, guaranteeing that restarting the INS channel allows for rapid alignment using historical data. Strict monotonic synchronization of mission clocks between channels ensures seamless switching between the two channels. The single-channel self-monitoring design method refers to using a "command-monitor" self-monitoring pair for task-level data comparison. This allows for accurate monitoring and recording of single-event upsets (SWEs) in critical data, and the issuance of inconsistency signals to control the subsequent behavior of the inertial navigation electronic equipment (INS). For the first time, a redundancy system is designed on the INS, addressing the issues of continuous INS information output and rapid alignment of reconstructed channels during redundancy switching, based on the characteristics of the INS. Therefore, when the INS is affected by radiation in a space-air environment and experiences a SWEs fault, self-monitoring comparison can quickly identify the SWEs fault, initiate redundancy switching to ensure the availability of the INS, and simultaneously power-off restart the faulty channel to eliminate the impact of the SWEs fault on the system. The dual-redundancy design approach effectively addresses the problem of a single channel failure and equipment inability to maintain normal operation after a single-event upset (SWE) occurs in the aerospace environment from the system architecture level. This ensures that the inertial navigation electronic equipment can immediately resume normal operation and continuously maintain navigation status and performance after a single fault. The autonomous reconfiguration design approach refers to the ability to autonomously reconfigure the faulty channel by automatically powering it down after the self-monitoring system detects that a SWE has occurred and the dual-redundancy primary and backup channels have switched. This restores the faulty channel to normal operation and resolves the fault caused by the SWE.

[0024] Seamless switching of inertial data redundancy: The inertial navigation electronic equipment (INS) employs a dual-redundancy architecture with primary and backup channels to address the issue of equipment malfunction and inability to maintain normal operation after a single-event upset (SEE). The redundant architecture INS must ensure continuous availability of output data from the inertial navigation system; therefore, seamless switching of inertial data is crucial during redundancy transitions.

[0025] The dual-redundancy architecture inertial navigation electronic equipment has two redundancies: a primary channel and a backup channel. During normal operation, both the primary and backup channels are in a hot-operation state, synchronously sampling and performing inertial calculations. They write operational data to the designated storage area of ​​the other channel via inter-channel cross-data transmission links according to the basic task clock cycle. Only the primary channel has control over the device's external output information. When the primary channel fails, it goes offline, and the backup channel comes online and becomes the primary channel, gaining control over external output information. After the failed channel autonomously reconfigures and restarts, it reads the inertial data currently written by the backup channel from the primary channel's storage area, performs calculations directly, and immediately enters navigation output mode, ensuring the continuity and smoothness of the entire navigation system. It is worth noting that the primary and backup channels need to be completely independent and electrically isolated, with clocks from different sources. However, the task clocks must be precisely synchronized so that the primary and backup channels can perform sampling and inertial calculations synchronously. This ensures the consistency of the calculation results between the primary and backup channels, achieves seamless connection of inertial information during channel switching, and ensures the availability and continuity of navigation data output. Therefore, the seamless switching of inertial data in this invention involves the primary and backup channels transmitting the task clock generated by this channel to the other channel. Relying on the master-slave calibration synchronization clock algorithm, it is possible to ensure precise synchronization of the task clocks even though the primary and backup channel clocks are from different sources.

[0026] Single-channel self-monitoring single-event fault: The inertial navigation electronic equipment employs a "command-monitor" self-checking pair fault monitoring method for each channel to monitor single-event faults. Each redundancy channel performs navigation task calculations and uses a self-checking pair fault monitoring method to cover any possible processor faults. A processor self-checking pair consists of a command branch and a monitoring branch, both of which use the same circuit design and have identical resource configurations.

[0027] The instruction branch and the monitoring branch operate in synchronous mode (with the same clock source) and exchange data information with each other through dual-port RAM. Under normal operating conditions, their information input sources and software calculation processes are the same, so the calculation results should also be the same. The monitoring branch compares its own calculation results with the calculation results passed by the instruction branch (through information transmission via dual-port RAM). If a fault is detected, the channel will be disconnected through channel fault logic.

[0028] In addition to monitoring faults in the navigation calculation process through a self-monitoring system formed by the command and monitoring branches, multiple monitoring circuits are set up to further monitor potential faults online. These include watchdog monitoring (independent of the command and monitoring branches), power supply monitoring, and clock monitoring. Through these monitoring measures, the fault monitoring coverage is further improved. Furthermore, considering the potential impact of CMOS device latch-up faults on the power supply and to prevent the spread of faults, a current-limiting protection circuit is also set up for the power supply circuit.

[0029] The interface control module handles the input / output functions of the RS-422 bus, 1553B bus, and discrete signals. The interface control function is primarily implemented through an FPGA, which not only performs the usual RS-422 bus and 1553B data packet packing and unpacking operations but also performs interface status monitoring: for the bus and discrete signals output from the computer board, it detects any potential output faults through online loopback monitoring; and it monitors for internal faults (such as FPGA chip latch-up) through a watchdog timer. The interface control module uploads the fault monitoring results to the fault monitoring module for processing.

[0030] The potential for single-event upsets (SEUs) is addressed by implementing triple modular redundancy (TMR) within the FPGA's internal logic.

[0031] The fault synthesis circuit integrates the monitoring results of this channel and the remote channel, and controls the on / off state of each output signal of this computer board, thereby controlling the disconnection / connection of this channel. In addition, the fault shutdown signal also controls the power supply circuit to connect and disconnect the power supply to this channel.

[0032] Power supply autonomous reconfiguration: Based on the mechanism of single-event effects causing faults in space radiation, it can be known that single-event upset faults and single-event latch-up faults that do not cause burnout can be eliminated by applying a power off operation.

[0033] The inertial navigation electronic equipment is designed for autonomous reconfiguration. It automatically shuts down and restarts faulty channels by powering them off, thus eliminating the associated single-event faults. When the self-monitoring comparison results of a channel are inconsistent and the primary and backup channels with dual redundancy have switched over, it indicates that the equipment may have been affected by a single-event upset. The primary channel has experienced a fault caused by a single-event upset, and the backup channel takes over control of the equipment's external output information, degrading the dual-channel inertial navigation electronic equipment to single-channel operation. To further eliminate single-event upset (SWE) faults and restore the function of the faulty main channel, this invention proposes an autonomous reconfiguration method. This method automatically shuts down and restarts the power supply to the faulty channel by comparing inconsistent fault-based power-off signals and normal startup reset signals. Specifically, the fault-based power-off signal controls the shutdown of the power supply hardware circuitry of the faulty channel. After shutdown, the power supply hardware circuitry automatically restarts, and the number of restarts is counted. If a restart fails after reaching the set number of restarts, the fault of the channel is considered unrecoverable through restarting, and the faulty channel is permanently offline. If a restart succeeds before reaching the set number of restarts, the faulty channel function returns to normal, and the restart count is reset to zero by the normal startup reset signal to avoid erroneous accumulation of restart counts. This hardware-software combined approach enables autonomous reconfiguration of the power supply to the faulty channel, providing inertial navigation electronic equipment with the ability to eliminate SWEs.

[0034] like Figure 1 The present invention discloses a ruggedized system for inertial navigation electronic equipment suitable for aerospace environments, comprising: a main channel and a backup channel, wherein both the main channel and the backup channel include a monitoring branch, a command branch, a mission clock synchronization unit, and an autonomous reconfiguration unit. Among them, the main channel task clock synchronization unit and the backup channel task clock synchronization unit are connected by a bus to realize task clock synchronization between the main and backup channels; The main channel task clock synchronization unit is used to distribute clocks to the main channel monitoring branch and the main channel command branch; the main channel monitoring branch is used to receive and process data, compare it with the data processed by the main channel command branch, and send the comparison result to the main channel command branch; the main channel command branch is used to receive and process data, compare it with the data processed by the main channel monitoring branch, compare the comparison result of the main channel command branch with the comparison result of the main channel monitoring branch, and output the processed data. The backup channel task clock synchronization unit is used to distribute clocks to the backup channel monitoring branch and the backup channel command branch; the backup channel monitoring branch is used to receive and process data, compare it with the data processed by the backup channel command branch, and send the comparison result to the backup channel command branch; the backup channel command branch is used to receive and process data, and compare it with the data processed by the backup channel monitoring branch. The autonomous reconfiguration unit is used to autonomously reconfigure the channel it belongs to.

[0035] The present invention provides a hardening method for inertial navigation electronic equipment suitable for aerospace environments, which is executed by means of the above-described system, the method comprising: Step 1: Compare the comparison results of the main channel command branch with the comparison results of the main channel monitoring branch. If they match, the main channel command branch outputs the solved data. Step 2: Compare the comparison results of the main channel command branch with the comparison results of the main channel monitoring branch. If they are inconsistent, the main channel command branch sends a fault power-off signal and a normal start reset signal to the autonomous reconfiguration unit, triggering the autonomous reconfiguration unit to perform autonomous reconfiguration of the main channel and send fault status information to the backup channel command branch. During the autonomous reconfiguration of the main channel, when the backup channel is in normal condition, after receiving the fault status information of the main channel, the backup channel will take over the faulty main channel and output the calculated data to the outside world. After the main channel is autonomously reconfigured, it will serve as a backup channel.

[0036] In step 2, after the main channel is autonomously reconstructed, the missing solution data during the autonomous reconstruction of the main channel is obtained through the backup channel and used for subsequent data solution.

[0037] Step 1 also includes: The comparison results of the backup channel command branch are compared with the comparison results of the backup channel monitoring branch. If they are inconsistent, the backup channel command branch sends a fault power-off signal and a normal start reset signal to the autonomous reconfiguration unit to trigger the autonomous reconfiguration unit to perform autonomous reconfiguration of the backup channel and send fault status information to the main channel command branch. Once the backup channel has completed its autonomous reconfiguration, it will continue to serve as a backup channel.

[0038] After the backup channel completes its autonomous reconstruction, the missing solution data from the backup channel's autonomous reconstruction process is obtained through the main channel and used for subsequent data calculation.

[0039] In step 2, during the autonomous reconfiguration process, the power supply hardware circuit of the fault channel is shut down by the faulty electrical signal control. After shutdown, the power supply hardware circuit will automatically restart multiple times. At the same time, the normal start-up clear signal is used to clear the number of restarts after multiple successful restarts, so as to avoid the false accumulation of the number of restarts.

[0040] During the autonomous refactoring process, the number of restarts is less than or equal to N, where N is the set number of restarts.

[0041] If the channel fails to restart successfully after N restart attempts, an unrecoverable failure will occur, causing the channel to go offline.

[0042] The following will refer to the appendices in the embodiments of the present invention. Figure 1The specific implementation method will be described more clearly and completely. The implementation steps are as follows: Step 1: Data Input Inertial navigation electronic equipment receives inertial data for data calculation and processing, generates mission navigation information, and provides the aircraft with various motion information such as position, velocity, heading, attitude, angular rate, and acceleration.

[0043] Step 2: Task clock synchronization The primary and backup channels send their respective task clocks to each other via a dual-redundant channel clock transmission link. When one channel identifies itself as the backup channel and the other channel is the primary channel, and the rising edge of the task clock sent by the primary channel arrives, the backup channel also outputs its own task clock as a rising edge, thus synchronizing with the rising edge of the task clock sent by the primary channel. This provides a synchronous working clock for each branch to receive, process, and compare data, enabling synchronous sampling, inertial processing, and self-monitoring comparison of data between the primary and backup channels.

[0044] Step 3: Data Reception Inertial data is synchronously distributed to the primary and backup channels according to the task clock cycle. The primary channel command branch and monitoring branch, as well as the backup channel command branch and monitoring branch, all receive the data synchronously to ensure the consistency and continuity of data reception and sampling.

[0045] Step 4: Data Solving The primary and backup channels' command and monitoring branches perform inertial calculations on the received data through the data processing module to generate the necessary task navigation information. This information is used for both the external output of the primary channel's command branch data and the self-monitoring comparison between the primary and backup channels. Simultaneously, the primary and backup channels' command branches rely on cross-data links between redundancies to write their respective channel's work site data to the designated storage area of ​​the other channel, ensuring seamless migration and connection of navigation information after channel switching.

[0046] Step 5: Self-monitoring and comparison The primary and backup channel command branches and monitoring branches exchange inertial data calculation information via the address and data lines of the dual-port RAM. The two branches compare their own calculation information with the information sent by the other branch. If they match, the functions of both the command and monitoring branches are considered correct, and the command branch outputs mission navigation information. If they do not match, a single-event upset (SED) function malfunction is considered to have occurred in one of the branches. In this case, the command branch sends a fault-down signal and a normal start-up reset signal, triggering the autonomous reconfiguration unit's behavior.

[0047] Step 6: Autonomous Restructuring The autonomous reconfiguration unit mainly consists of power management and power supply. Power management is the core functional module for autonomous reconfiguration. It receives fault power-down signals and normal startup reset signals from the command branch. If the fault power-down signal is triggered, the hardware circuitry for autonomous reconfiguration takes effect, controlling the power supply switch to turn off. After shutdown, the power supply hardware circuitry will automatically restart. If the set number of restarts is reached and restart still fails, an unrecoverable fault is considered to have occurred, and the power management module permanently shuts off power, taking that channel offline. If the set number of restarts is not reached and the device returns to normal, the restart count is reset to zero to prevent accidental accumulation of restart counts. Power supply is controlled by the power management module. When the fault power-down signal is not triggered, power is output normally; when the fault power-down signal is triggered, power output is shut off, waiting for the device to restart. The number of restarts can be 3.

[0048] Step 7: Data Output The command branch of the main channel has control over the information output by the device. Therefore, when the self-monitoring comparison is consistent, the command branch of the main channel outputs the task navigation information after data calculation. When the self-monitoring comparison is inconsistent, it is considered that a single-event fault has occurred. At this time, channel switching is performed, and the backup channel takes over the control of the information output and outputs the information. When the main channel recovers, the inertial data written by the backup channel at the current time is read from the storage area of ​​the main channel, calculated directly, and immediately enters the navigation output mode.

[0049] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A ruggedized system for an inertial navigation electronics unit for space and atmospheric environments, comprising: include: The system comprises a main channel and a backup channel, each including a monitoring branch, a command branch, a task clock synchronization unit, and an autonomous reconfiguration unit. The main channel task clock synchronization unit and the backup channel task clock synchronization unit are connected via a bus to achieve task clock synchronization between the main and backup channels. The main channel task clock synchronization unit distributes clocks to the main channel monitoring branch and the main channel command branch. The main channel monitoring branch receives and processes data, compares it with the data processed by the main channel command branch, and sends the comparison result to the main channel command branch. The main channel command branch receives and processes data and compares it with the main channel command branch. The system compares the calculated data from the main channel command branch with the comparison results from the main channel monitoring branch, and outputs the calculated data. The backup channel task clock synchronization unit distributes clocks to the backup channel monitoring branch and the backup channel command branch. The backup channel monitoring branch receives and calculates the data, compares it with the calculated data from the backup channel command branch, and sends the comparison results to the backup channel command branch. The backup channel command branch receives and calculates the data, and compares it with the calculated data from the backup channel monitoring branch. The autonomous reconfiguration unit performs autonomous reconfiguration on the channel it is assigned to.

2. A method for hardening inertial navigation electronic equipment suitable for aerospace environments, said method being performed by means of the system described in claim 1, characterized in that, The method includes: Step 1: Compare the comparison results of the main channel command branch with the comparison results of the main channel monitoring branch. If they match, the main channel command branch outputs the solved data. Step 2: Compare the comparison results of the main channel command branch with the comparison results of the main channel monitoring branch. If they are inconsistent, the main channel command branch sends a fault power-off signal and a normal start reset signal to the autonomous reconfiguration unit, triggering the autonomous reconfiguration unit to perform autonomous reconfiguration of the main channel and send fault status information to the backup channel command branch. During the autonomous reconfiguration of the main channel, when the backup channel is in normal condition, after receiving the fault status information of the main channel, the backup channel will take over the output of the calculated data on behalf of the faulty main channel. After the main channel is autonomously reconfigured, it will serve as a backup channel.

3. The method according to claim 2, characterized in that, In step 2, after the main channel is autonomously reconstructed, the missing solution data during the autonomous reconstruction of the main channel is obtained through the backup channel and used for subsequent data solution.

4. The method according to claim 2, characterized in that, Step 1 also includes: The comparison results of the backup channel command branch are compared with the comparison results of the backup channel monitoring branch. If they are inconsistent, the backup channel command branch sends a fault power-off signal and a normal start reset signal to the autonomous reconfiguration unit to trigger the autonomous reconfiguration unit to perform autonomous reconfiguration of the backup channel and send fault status information to the main channel command branch. Once the backup channel has completed its autonomous reconfiguration, it will continue to serve as a backup channel.

5. The method according to claim 2, characterized in that, After the backup channel completes its autonomous reconstruction, the missing solution data from the backup channel's autonomous reconstruction process is obtained through the main channel and used for subsequent data calculation.

6. The method according to claim 2, characterized in that, In step 2, during the autonomous reconfiguration process, the power supply hardware circuit of the fault channel is shut down by the faulty electrical signal control. After shutdown, the power supply hardware circuit will automatically restart multiple times. At the same time, the normal start-up clear signal is used to clear the number of restarts after multiple successful restarts, so as to avoid the false accumulation of the number of restarts.

7. The method according to claim 2, characterized in that, The number of restarts is less than or equal to N, where N is the set number of restarts.

8. The method according to claim 2, characterized in that, If the channel fails to restart successfully after N restart attempts, it is considered to have suffered an unrecoverable failure and will be taken offline.