Satellite-borne system reliability protection method and device based on software and hardware cooperation and storage medium

By using the voting mechanism of FPGA dynamic reconfiguration and multi-copy storage system, the reliability and localization issues of traditional spaceborne computer systems in the space environment are solved, realizing efficient and reliable autonomous adaptation and data protection of the spaceborne system, and improving the stability and resource utilization efficiency of on-orbit missions.

CN122019464APending Publication Date: 2026-05-12SHANGHAI SPACEFLIGHT ELECTRONICS & COMM EQUIP RES INST
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI SPACEFLIGHT ELECTRONICS & COMM EQUIP RES INST
Filing Date
2026-02-03
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Traditional spaceborne computer systems suffer from problems such as insufficient reliability of storage systems, inadequate protection against single-event effects, unmet domestic requirements, and insufficient on-orbit reconfigurability in the space environment, making it difficult to meet the needs of long-term on-orbit missions.

Method used

Dynamic reconfiguration is achieved using FPGA (Field-Programmable Gate Array) devices, combined with a multi-copy storage system and voting mechanism, to realize hardware-software collaborative reliability protection. This includes switching between collaborative hardening mode and independent operation mode, and dynamically adapting to radiation environment and fault conditions through hardware-level voting and software verification and error correction.

Benefits of technology

It has improved the reliability and efficiency of the spaceborne system, achieved on-orbit autonomous adaptability, ensured data integrity and system stability, optimized resource consumption and power consumption, and enhanced the long-term autonomous survivability of spacecraft.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122019464A_ABST
    Figure CN122019464A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of spaceborne computers, in particular to a software and hardware cooperation-based spaceborne system reliability protection method and device and a storage medium, and the method comprises the following steps: S1, responding to a configuration instruction from a spaceborne processor, and carrying out dynamic reconfiguration on an FPGA (Field Programmable Gate Array) between a cooperative reinforcement mode and an independent operation mode; s2, in the collaborative reinforcement mode, the FPGA executes parallel access on the multiple storage copies, a multi-bit dynamic voting mechanism with the voting bits capable of being dynamically configured is adopted, real-time hardware-level voting is conducted on read-out data or state feedback signals, a voting result is obtained, and the voting result is submitted to a satellite-borne processor; and S3, in the independent operation mode, the satellite-borne processor schedules background tasks, and data inspection, verification and error correction operations are executed on the single specified storage copy through a single-path operation interface provided by the FPGA. Through dynamic mode switching and hardware-level synchronous voting, the problem of time sequence asynchronization of redundant devices is solved, and the on-orbit autonomous maintenance and adaptive capacity is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of spaceborne computer technology, and in particular to a method, device and storage medium for reliability protection of spaceborne systems based on hardware and software collaboration. Background Technology

[0002] In response to the call for integrated space-ground networking and routing switching, demands for inter-satellite connectivity and intelligent aerospace have emerged. Traditional spaceborne computer systems typically employ commercial processors (such as PowerPC and ARM) combined with radiation hardening measures. However, due to the unique characteristics of the space environment (such as single-event effects and total dose radiation), the reliability of commercial chips is insufficient to meet the requirements of long-term on-orbit missions. Furthermore, traditional spaceborne systems face the following technical bottlenecks in areas such as storage management, mission scheduling, and fault-tolerant design: 1) Insufficient reliability of the storage system: Traditional onboard storage systems typically employ triple modular redundancy check (TMR) or software verification mechanisms (such as EDAC) to improve data reliability. However, hardware TMR solutions suffer from inconsistent device response times, leading to asynchronous storage operations and potentially causing state transitions or data inconsistencies. Software verification (such as cyclic redundancy check (CRC) and Hamming codes) consumes significant CPU resources, resulting in a decrease in read / write efficiency (typically reduced to 25%–50% of the original performance).

[0003] 2) Insufficient protection against single-event effects (SEE): High-energy particles in space can trigger single-event upsets (SEUs) or single-event locks (SELs) in memory cells. Traditional solutions rely on hardware redundancy (such as antifuse FPGAs) or software error correction mechanisms, but they cannot dynamically adapt to different space radiation environments. For example, during peak solar activity, the probability of single-event effects increases significantly, and traditional fixed redundancy modes cannot optimize resource utilization.

[0004] 3) The need for localization and self-reliance: In recent years, the localization of aerospace electronic systems has become an inevitable trend. However, domestically produced high-performance aerospace-grade processors (such as MpSOC) still need improvement in areas such as radiation resistance and multi-core scheduling optimization. Traditional solutions are insufficient to meet the needs of long-life missions such as future deep space exploration and high-orbit satellites.

[0005] 4) Insufficient on-orbit reconfigurability: Traditional spaceborne systems typically employ a fixed architecture, making it impossible to adjust storage management strategies or fault-tolerant modes on-orbit. For example, when a storage chip experiences performance degradation due to radiation damage, the system cannot dynamically switch to a more reliable redundancy mode and must rely on ground intervention, thus reducing the system's autonomous survivability.

[0006] To address the aforementioned issues, this invention proposes a highly reliable, efficient, and dynamically adaptable reliability protection scheme for spaceborne systems. By combining a domestically developed hardware platform with software and hardware co-optimization technology, it enhances the long-term stable operation capability of spaceborne computers in complex space environments. Summary of the Invention

[0007] The purpose of this invention is to address the shortcomings of existing technologies by providing a reliability protection method for spaceborne systems based on hardware and software collaboration, comprising the following steps: S1: In response to configuration instructions from the onboard processor, the programmable logic device (FPGA) dynamically reconfigures between cooperative hardened mode and stand-alone operation mode; S2: In the collaborative hardening mode, the programmable logic device FPGA performs parallel access to several storage replicas in the multi-replica storage system, and adopts a multi-bit dynamic voting mechanism with dynamically configurable voting bits to perform real-time hardware-level voting on the read data or status feedback signals from several storage replicas, obtain the voting results, and submit the voting results to the onboard processor. S3: In the independent operation mode, the onboard processor schedules background tasks and performs data inspection, verification and error correction operations on a single designated storage copy in the multi-replica storage system through the single-channel operation interface provided by the programmable logic device FPGA.

[0008] Preferably, in step S1, the programmable logic device (FPGA) dynamically reconfigures itself between a cooperative hardened mode and an independent operation mode, including: S11: The programmable logic device FPGA securely terminates all ongoing memory access operations; S12: The programmable logic device FPGA receives and parses the configuration instructions from the onboard processor, and extracts the target mode identifier and mode parameters; S13: Based on the target mode identifier, reconstruct the internal data path and control logic; if switching to the collaborative hardening mode, activate the parallel path connected to all storage replicas, configure the hardware voter according to the voting bits in the mode parameters, and enable the synchronization timing engine; if switching to the independent operation mode, direct the onboard processor access path to the specified single storage replica through the internal multiplexer, and bypass the voting and synchronization logic. S14: After the reconstruction is completed, the programmable logic device FPGA sends a mode switching completion confirmation to the onboard processor.

[0009] Preferably, in step S2, real-time hardware-level voting is performed on the read data from several storage replicas to obtain the voting results, including: S21: The programmable logic device FPGA dynamically sets the decision rules of the hardware voter according to the number of voting bits in the configuration instruction; S22: When a storage access request is received from the onboard processor, the programmable logic device FPGA synchronous timing engine generates strictly synchronized control signals and sends them in parallel to all storage replicas; S23: The programmable logic device FPGA collects the responses of each memory copy in parallel. For read operations, it collects the read data of each memory copy; for write or erase operations, it monitors the status feedback signals returned by each memory copy. S24: The hardware voting device votes on the read data or status feedback signal in real time according to the decision rules, and generates the voting result.

[0010] Preferably, in step S24, real-time voting is performed on the read data, including: The hardware voter is activated when the preset timeout period is reached or when all stored copies of data are ready. The hardware voter compares the read data of each storage copy in parallel, either bit-wise or word-wise. According to the voting threshold determined by the decision rule, each data bit is voted on: if the number of identical copies of a data bit reaches the voting threshold, the valid value of that bit is determined to be that value. After voting on each candidate's vote, the voting result is generated, and the differences between each copy of the data and the voting result are recorded.

[0011] Preferably, in step S24, real-time voting is performed on the state feedback signal, including: The programmable logic device (FPGA) continuously acquires the status feedback signals returned by each memory copy; The hardware voting unit votes on the operation status feedback signal according to the voting threshold determined by the decision rules; If the number of replicas with consistent states reaches the voting threshold, the operation is considered complete, and a consistent state is output as the voting result. If the voting threshold is not reached, the operation is considered unsynchronized, and replicas with inconsistent states are marked or an error handling process is triggered.

[0012] Preferably, in step S3, data inspection, verification, and error correction operations are performed on a single designated storage replica in the multi-replica storage system, including: S31: The onboard processor schedules background inspection tasks with low priority and sends instructions to the programmable logic device FPGA to switch to independent operation mode and specify a single storage copy to be inspected. S32: The onboard processor reads data from a specified storage copy into a memory buffer in blocks through the single-channel operation interface of the programmable logic device FPGA; S33: The onboard processor performs checksum verification and error correction code decoding on the read data at the software level to determine the data block status; S34: If there are correctable errors in the data block, the corrected data is generated and written back to the original storage location through the single-channel interface of the programmable logic device FPGA. S35: Update the health status record and system log of this storage copy.

[0013] Preferably, in step S33, the onboard processor performs checksum verification and error correction code decoding on the read data at the software level to determine the data block status, including: S331: Perform checksum calculation on the main content of the data block, generate a real-time checksum, and compare it with the original stored checksum extracted from the data block to verify data integrity. S332: Perform decoding operations based on the error correction code associated with the data block, and determine whether the data block is in an error-free state, an error-correctable state, or an error-uncorrectable state based on the decoding result; S333: Combine the verification result of the check code and the decoding result of the error correction code to determine the final state of the data block; S334: Perform state processing based on the final state.

[0014] Preferably, in step S334, state processing is performed based on the final state, including: If the data block is in a correctable error state, the error bits are corrected in the memory buffer according to the position and correct value information provided by the error correction code decoding result, and the corrected data block is generated. If a data block is in an uncorrectable error state, an alarm is triggered and an attempt is made to recover the data using other redundant copies, or the corresponding storage block is marked as a bad block.

[0015] Based on the same concept, the present invention also provides a computer device, including a memory and a processor, wherein the memory stores computer-readable instructions, and when executed by the processor, the computer-readable instructions cause the processor to perform the steps of a hardware-software co-operation-based spaceborne system reliability protection method as described in the embodiments.

[0016] Based on the same concept, the present invention also provides a storage medium storing computer-readable instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps of a hardware-software co-operation-based spaceborne system reliability protection method as described in any one of the embodiments.

[0017] Compared with the prior art, the beneficial effects of the present invention are: (1) This invention uses a programmable logic device (FPGA) to respond to instructions from the onboard processor and dynamically reconfigures between the collaborative hardening mode and the independent operation mode, thereby realizing the on-orbit adaptive adjustment of the onboard storage management strategy. This method allows for flexible switching to a high-reliability synchronous voting mode or a low-overhead background maintenance mode based on the mission stage, radiation environment, or fault condition. This ensures the extremely high reliability of core mission data while optimizing system power consumption and resource usage, and enhances the spacecraft's long-term on-orbit autonomous survival and adaptability.

[0018] (2) In the collaborative hardening mode, the present invention uses FPGA to perform parallel access to the multi-copy storage system and adopts a multi-bit dynamic voting mechanism with dynamically configurable voting bits to perform real-time hardware-level synchronization and adjudication of read data and status feedback signals. This method fundamentally eliminates the timing asynchrony problem caused by the inherent difference in the response time of storage devices, avoids the risk of state transitions or data inconsistencies that may be caused by traditional hardware redundancy (such as TMR), and improves the reliability of storage access to the hardware level. At the same time, since the voting logic is implemented by FPGA hardware and is transparent to the upper-layer software, the storage read and write efficiency is improved by several times compared with traditional software fault-tolerant solutions.

[0019] (3) In the independent operation mode, the onboard processor schedules background tasks and performs data inspection, verification, and error correction on designated storage replicas through a single-channel operation interface provided by the FPGA. This mechanism achieves "unobtrusive" health maintenance and autonomous repair of the storage medium. It can proactively detect and correct soft errors caused by single-event effects without affecting the execution of front-end real-time tasks, maintain the data health of each storage replica, and provide a reliable data foundation for the collaborative hardening mode. Combined with dynamic mode switching capabilities, this invention ensures that the system can seamlessly switch to the maintenance and recovery phase when encountering anomalies, and automatically return to the high-performance hardening mode after completion, achieving a unity of high reliability, high real-time performance, and high autonomy. Attached Figure Description

[0020] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention.

[0021] Figure 1 This is a flowchart of a spaceborne system reliability protection method based on hardware and software collaboration according to the present invention; Figure 2 This is another flowchart of a spaceborne system reliability protection method based on hardware and software collaboration according to the present invention; Figure 3This is a data reading voting diagram of a spaceborne system reliability protection method based on hardware and software collaboration according to the present invention. Figure 4 This is a write / erase voting diagram for a spaceborne system reliability protection method based on hardware and software collaboration according to the present invention. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention. Obviously, the described embodiments are only some, not all, of the embodiments described in this application. All other embodiments obtained by those skilled in the art based on the embodiments in this application without creative effort are within the scope of protection of this application.

[0023] Those skilled in the art will understand that, unless otherwise stated, the singular forms “a” and “an” used herein, and “the”, may also include the plural forms. It should be further understood that the term “comprising” as used in this specification means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0024] First Embodiment The hardware architecture of this embodiment mainly includes a spaceborne processor, a programmable logic device (FPGA), and a multi-copy storage system, all of which use domestically produced components to achieve independent control.

[0025] The onboard processor uses the domestically produced FT-DM6672V series high-performance radiation-resistant multi-core MpSOC chip as the onboard processor. This processor integrates two high-performance computing cores DSP and a dedicated coprocessor core PPC, runs the Fengyun Yihui real-time operating system, and is responsible for executing upper-layer applications such as space mission management, mission planning, and attitude control, as well as generating access requests and mode configuration instructions for the storage system.

[0026] The AX2K series radiation-hardened antifuse FPGA, which is independently developed, is used as a high-reliability coprocessor. The FPGA is connected to the MpSOC through the high-speed synchronous external memory interface EMIF and integrates key reliability protection logic. The logic unit scale reaches 2 million gates.

[0027] More preferably, the programmable logic device FPGA includes: The mode configuration and interface management module is responsible for receiving and parsing configuration instructions from the MpSOC and controlling the dynamic reconfiguration of the entire FPGA between collaborative hardened mode and independent operation mode. The synchronous timing engine, in collaborative hardened mode, generates strictly synchronized clock, chip select, address, and command signals to ensure that all memory replicas operate synchronously. The configurable multi-bit dynamic voter is the core logic unit, which can be dynamically instantiated into hardware voting circuits with different input bit lengths (such as 3, 5, 7) and voting thresholds (such as majority voting) according to configuration instructions. In standalone operation mode, the single-path access path acts as a transparent channel, directing MpSOC access to a designated single storage copy.

[0028] The multi-replica storage system adopts a device-level redundancy architecture, and is configured with 6 domestically produced high-capacity SPI NOR Flash memories (model: JFM25QL256, 32MB capacity per chip) to form a multi-replica storage system. The SPI chip clock, chip select and data lines are directly connected to the FPGA's general-purpose I / O pins, and the physical layer access control is implemented by the FPGA's internal logic.

[0029] After power-on initialization, MpSOC sends default configuration instructions to the FPGA through preset startup code. Typically, the system is initialized to cooperative hardened mode and the voting mode is set to two out of three. After the FPGA completes logic loading and path configuration, it returns to the ready state to MpSOC and enters normal operation preparation.

[0030] Please see Figure 1 and Figure 2 As shown, this embodiment provides a method for reliability protection of a spaceborne system based on hardware and software collaboration, including the following steps: S1: In response to configuration instructions from the onboard processor MpSOC, the programmable logic device FPGA dynamically reconfigures between cooperative hardened mode and stand-alone operation mode.

[0031] Preferably, in step S1, the programmable logic device (FPGA) dynamically reconfigures itself between a cooperative hardened mode and an independent operation mode, including: S11: The programmable logic device (FPGA) securely terminates all ongoing memory access operations; S12: The programmable logic device FPGA receives and parses the configuration instructions from the onboard processor, and extracts the target mode identifier (such as cooperative hardening or independent operation) and mode parameters (such as specified replica ID, voting bits, etc.). S13: Based on the target mode identifier, reconstruct the internal data path and control logic; if switching to the collaborative hardening mode, activate the parallel path connected to all storage replicas, configure the hardware voter according to the voting bits in the mode parameters, and enable the synchronization timing engine; if switching to the independent operation mode, direct the onboard processor access path to the specified single storage replica through the internal multiplexer, and bypass (disable) the voting and synchronization logic. S14: After reconfiguration is complete, the programmable logic device FPGA sends a confirmation of mode switching completion to the onboard processor.

[0032] S2: In the collaborative hardening mode, the programmable logic device FPGA performs parallel access to several memory replicas in the multi-replica memory system, and adopts a multi-bit dynamic voting mechanism with dynamically configurable voting bits to perform real-time hardware-level voting on the read data or status feedback signals from several memory replicas, obtain the voting results, and submit the voting results to the on-board processor.

[0033] Preferably, in step S2, real-time hardware-level voting is performed on the read data from several storage replicas to obtain the voting results, including: S21: The programmable logic device (FPGA) dynamically sets the decision rules of the hardware voter according to the number of voting bits in the configuration instruction; S22: When a memory access request is received from the onboard processor, the FPGA synchronous timing engine generates strictly synchronized control signals and sends them in parallel to all memory replicas. S23: The programmable logic device FPGA collects the responses of each memory copy in parallel. For read operations, it collects the read data from each memory copy; for write or erase operations, it monitors the status feedback signals returned by each memory copy. S24: The hardware voter votes on the read data or status feedback signal in real time according to the decision rules and generates the voting result.

[0034] Please see Figure 3 As shown, in step S24, real-time voting is performed on the read data, including: When the preset timeout period is reached or the data of all storage replicas is ready, the hardware voter is started. Specifically, in this embodiment, the MpSOC sends a mode configuration instruction {target mode: collaborative hardening; voting bits: 5; voting threshold: 3} to the FPGA according to the high reliability requirements of the task. The FPGA completes dynamic reconfiguration, activates the parallel path connected to the 5 storage replicas (e.g., F1-F5 are selected), and instantiates the corresponding 3 out of 5 hardware voting circuit. The application task of the MpSOC generates a data read request (including the target address) and sends it to the FPGA. The FPGA parses it as a read operation. The FPGA's synchronous timing engine generates a set of strictly synchronized chip select, clock and command signals, and sends them to F1-F5 at the same time to start parallel reading. The FPGA monitors the data readiness status. When the data of all 5 replicas is ready (or the waiting timeout is reached), the data is sent to the dynamic voter. The hardware voter compares the read data from each storage copy in parallel, either bit-wise or word-wise. Specifically, in this embodiment, the voter performs real-time hardware voting on the data bit-wise. For example, for a certain bit, if F1, F2, and F3 read '1', and F4 and F5 read '0', according to the "three out of five" rule, the voting result for that bit is '1'. According to the voting threshold determined by the judgment rules, each data bit is voted on: if the number of identical copies of a certain data bit reaches the voting threshold, then the valid value of that bit is determined to be that value. After voting bit by bit, a voting result is generated. Simultaneously, the differences between each copy of the data and the voting result are recorded (e.g., marking F4 and F5 as inconsistent with the result at that bit). This information can be used to assess the health status of the storage medium. The FPGA, with the correct data after voting and a "hardware vote valid" status flag, returns it to the MpSOC via the EMIF bus. The entire process is transparent to the upper-layer software, and the access latency is close to that of single-chip access.

[0035] Please see Figure 4 As shown, in step S24, real-time voting is performed on the state feedback signal, including: The programmable logic device FPGA continuously acquires the status feedback signals returned by each memory replica. Specifically, in this embodiment, after the MpSOC initiates a write command, the FPGA drives the three target memory replicas to start writing synchronously. After each Flash replica completes its operation, it updates its status register. The hardware voter votes on the operation status feedback signal according to the voting threshold determined by the decision rules. Specifically, in this embodiment, the FPGA continuously polls the least significant bit (LSB) in each replica status register as the "busy / ready" judgment benchmark, and the status voting logic in the FPGA performs real-time "two out of three" voting on the three collected LSB status bits. If the number of replicas with consistent states reaches the voting threshold, the operation is considered complete, and a consistent state is output as the voting result. If the voting threshold is not reached, the operation is considered unsynchronized, and replicas with inconsistent states are marked or an error handling process is triggered. Specifically, in this embodiment, the voter only determines that the write operation is complete when at least two replicas' LSBs show "ready". The FPGA then feeds back a unified "operation successful" state to the MpSOC. This mechanism forces a majority of replicas to complete the current operation before the system can enter the next state, thereby completely eliminating the risk of upper-layer software misjudging the operation as complete (i.e., "jumping the state") due to the response delay of a single replica.

[0036] S3: In standalone operation mode, the onboard processor schedules background tasks and performs data inspection, verification and error correction operations on a single specified storage copy in the multi-replica storage system through a single operation interface provided by the programmable logic device FPGA.

[0037] Preferably, in step S3, data inspection, verification, and error correction operations are performed on a single designated storage replica in the multi-replica storage system, including: S31: The onboard processor schedules the background inspection task with low priority and sends an instruction to the programmable logic device FPGA to switch to the independent operation mode and specify the single storage copy to be inspected. Specifically, in this embodiment, the task first sends the instruction {target mode: independent operation; specified copy ID: 2} to the FPGA to switch the system to the independent operation mode and specify the inspection target. S32: The onboard processor reads the data of the specified storage copy into the memory buffer in blocks through the single-channel operation interface of the programmable logic device FPGA. Specifically, in this embodiment, after the FPGA completes reconfiguration, the inspection task reads the data of the specified area of ​​Flash No. 2 into the memory buffer in blocks of 256B through the single-channel interface. S33: The onboard processor performs checksum verification and error correction code decoding on the read data at the software level to determine the status of the data block; S34: If a data block contains correctable errors, corrected data is generated and written back to the original storage location via the single-channel interface of the FPGA. Specifically, in this embodiment, based on the error location and correct value provided by the BCH decoder, the two error bits are corrected in the memory buffer. Subsequently, the CRC32 value of the corrected data block is recalculated. The complete, corrected 256B data block (including the updated CRC) is written back to the original physical address of Flash 2 via the FPGA's single-channel interface. If the decoder determines it to be an uncorrectable error, a system alarm is triggered. The inspection task can attempt a temporary mode switch to recover data from other redundant copies. If recovery is successful, the data is written back; if it fails, the logical block is marked in the bad block table. S35: Update the health status record and system log of this storage copy. Specifically, in this embodiment, update the record: "Replica #2, address range XXXX-YYYY, detected and corrected a 2-bit error at [timestamp]". The error count of this replica is updated for subsequent reliability analysis. After the inspection is completed, the FPGA can be instructed to switch back to "cooperative hardening mode".

[0038] Preferably, in step S33, the onboard processor performs checksum verification and error correction code decoding on the read data at the software level to determine the data block status, including: S331: Perform checksum calculation on the main content of the data block to generate an actual checksum, and compare it with the original stored checksum extracted from the data block to verify data integrity. Specifically, in this embodiment, calculate a CRC32 checksum for each 256B data block and compare it with the original CRC value stored at the end of the block. For example, if a comparison fails, it indicates that there is an error in the data. S332: Decoding operation is performed based on the BCH error correction code associated with the data block. The data block is determined to be in an error-free state, an error-correctable state, or an error-uncorrectable state based on the decoding result. Specifically, in this embodiment, the BCH(511, 493) software decoding library is called to decode the data block. S333: Combine the verification result of the check code and the decoding result of the error correction code to determine the final state of the data block; S334: Perform state processing based on the final state. Specifically, in this embodiment, the decoder output may be: "A 2-bit error was detected, located at offset addresses 0x123 and 0x456. It is correctable. The combined checksum comparison failure and the BCH decoding result are "correctable". It is determined that the data block is in a correctable error state."

[0039] Preferably, in step S334, state processing is performed based on the final state, including: If the data block is in a correctable error state, the error bits are corrected in the memory buffer based on the position and correct value information provided by the error correction code decoding result, generating a corrected data block. Specifically, in this embodiment, if it is a correctable error: the error bits are directly corrected in the memory buffer based on the BCH decoding result. Then, the entire corrected data block is written back to the original address of "copy #1" through the FPGA's single-channel interface. One correction event is recorded. If a data block is in an uncorrectable error state, an alarm is triggered and an attempt is made to recover the data from other redundant replicas, or the corresponding storage block is marked as a bad block. Specifically, in this embodiment, if it is an uncorrectable error: a system alarm is triggered. The inspection task can attempt to recover the data block from other redundant replicas (read via temporary switching mode). If the recovery is successful, it is written back to "Replica #1"; if it fails, the logical block is marked in the bad block table of "Replica #1" to avoid subsequent use. After completing the inspection of a replica, the health status record of that replica is updated. MpSOC can then decide on subsequent maintenance strategies based on this, such as initiating more frequent inspections of replicas with high error rates, or notifying the ground control center.

[0040] Second Embodiment Based on the same concept, this embodiment also provides a computer device, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor performs the steps of a hardware-software co-operation-based spaceborne system reliability protection method as described in the embodiment.

[0041] Based on the same concept, the present invention also provides a storage medium storing computer-readable instructions, characterized in that, when the computer-readable instructions are executed by one or more processors, the one or more processors cause the one or more processors to perform the steps of a hardware-software co-operation-based spaceborne system reliability protection method as described in any one of the embodiments.

[0042] It is understood that, regarding the aforementioned method for ensuring the reliability of a spaceborne system based on hardware and software collaboration, if all components are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer server or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this invention. The aforementioned storage medium includes: USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media capable of storing program code.

[0043] Computer-readable storage media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable storage medium may also be any readable medium other than a readable storage medium that can transmit, propagate, or transfer a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0044] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A method for reliability protection of a spaceborne system based on hardware and software collaboration, characterized in that, Includes the following steps: S1: In response to configuration instructions from the onboard processor, the programmable logic device (FPGA) dynamically reconfigures between cooperative hardened mode and stand-alone operation mode; S2: In the collaborative hardening mode, the programmable logic device FPGA performs parallel access to several storage replicas in the multi-replica storage system, and adopts a multi-bit dynamic voting mechanism with dynamically configurable voting bits to perform real-time hardware-level voting on the read data or status feedback signals from several storage replicas, obtain the voting results, and submit the voting results to the onboard processor. S3: In the independent operation mode, the onboard processor schedules background tasks and performs data inspection, verification and error correction operations on a single designated storage copy in the multi-replica storage system through the single-channel operation interface provided by the programmable logic device FPGA.

2. The method for reliability protection of spaceborne systems based on hardware and software collaboration according to claim 1, characterized in that, In step S1, the programmable logic device (FPGA) dynamically reconfigures itself between cooperative hardened mode and independent operation mode, including: S11: The programmable logic device (FPGA) securely terminates all ongoing memory access operations; S12: The programmable logic device FPGA receives and parses the configuration instructions from the onboard processor, and extracts the target mode identifier and mode parameters; S13: Based on the target mode identifier, reconstruct the internal data path and control logic; if switching to the collaborative hardening mode, activate the parallel path connected to all storage replicas, configure the hardware voter according to the voting bits in the mode parameters, and enable the synchronization timing engine; if switching to the independent operation mode, direct the onboard processor access path to the specified single storage replica through the internal multiplexer, and bypass the voting and synchronization logic. S14: After the reconstruction is completed, the programmable logic device FPGA sends a mode switching completion confirmation to the onboard processor.

3. The reliability protection method for spaceborne systems based on hardware and software collaboration according to claim 1, characterized in that, In step S2, real-time hardware-level voting is performed on the read data from several storage replicas to obtain the voting results, including: S21: The programmable logic device FPGA dynamically sets the decision rules of the hardware voter according to the number of voting bits in the configuration instruction; S22: When a storage access request is received from the onboard processor, the programmable logic device FPGA synchronous timing engine generates strictly synchronized control signals and sends them in parallel to all storage replicas; S23: The programmable logic device FPGA collects the responses of each memory copy in parallel. For read operations, it collects the read data of each memory copy; for write or erase operations, it monitors the status feedback signals returned by each memory copy. S24: The hardware voting device votes on the read data or status feedback signal in real time according to the decision rules, and generates the voting result.

4. The method for reliability protection of spaceborne systems based on hardware and software collaboration according to claim 3, characterized in that, In step S24, real-time voting is performed on the read data, including: The hardware voter is activated when the preset timeout period is reached or when all stored copies of data are ready. The hardware voter compares the read data of each storage copy in parallel, either bit-wise or word-wise. According to the voting threshold determined by the decision rule, each data bit is voted on: if the number of identical copies of a data bit reaches the voting threshold, the valid value of that bit is determined to be that value. After voting on each candidate's vote, the voting result is generated, and the differences between each copy of the data and the voting result are recorded.

5. The method for reliability protection of spaceborne systems based on hardware and software collaboration according to claim 3, characterized in that, In step S24, the status feedback signal is voted on in real time, including: The programmable logic device (FPGA) continuously acquires the status feedback signals returned by each memory copy; The hardware voting unit votes on the operation status feedback signal according to the voting threshold determined by the decision rules; If the number of replicas with consistent states reaches the voting threshold, the operation is considered complete, and a consistent state is output as the voting result. If the voting threshold is not reached, the operation is considered unsynchronized, and replicas with inconsistent states are marked or an error handling process is triggered.

6. The method for reliability protection of spaceborne systems based on hardware and software collaboration according to claim 1, characterized in that, In step S3, data inspection, verification, and error correction operations are performed on a single designated storage replica in the multi-replica storage system, including: S31: The onboard processor schedules background inspection tasks with low priority and sends instructions to the programmable logic device FPGA to switch to independent operation mode and specify a single storage copy to be inspected. S32: The onboard processor reads data from a specified storage copy into a memory buffer in blocks through the single-channel operation interface of the programmable logic device FPGA; S33: The onboard processor performs checksum verification and error correction code decoding on the read data at the software level to determine the data block status; S34: If there are correctable errors in the data block, the corrected data is generated and written back to the original storage location through the single-channel interface of the programmable logic device FPGA. S35: Update the health status record and system log of this storage copy.

7. The method for reliability protection of spaceborne systems based on hardware and software collaboration according to claim 6, characterized in that, In step S33, the onboard processor performs checksum verification and error correction code decoding on the read data at the software level to determine the data block status, including: S331: Perform checksum calculation on the main content of the data block, generate a real-time checksum, and compare it with the original stored checksum extracted from the data block to verify data integrity. S332: Perform decoding operations based on the error correction code associated with the data block, and determine whether the data block is in an error-free state, an error-correctable state, or an error-uncorrectable state based on the decoding result; S333: Combine the verification result of the check code and the decoding result of the error correction code to determine the final state of the data block; S334: Perform state processing based on the final state.

8. The method for reliability protection of spaceborne systems based on hardware and software collaboration according to claim 7, characterized in that, In step S334, state processing is performed based on the final state, including: If the data block is in a correctable error state, the error bits are corrected in the memory buffer according to the position and correct value information provided by the error correction code decoding result, and the corrected data block is generated. If a data block is in an uncorrectable error state, an alarm is triggered and an attempt is made to recover the data using other redundant copies, or the corresponding storage block is marked as a bad block.

9. A computer device, characterized in that, The system includes a memory and a processor, wherein the memory stores computer-readable instructions that, when executed by the processor, cause the processor to perform the steps of a hardware-software co-operation-based spaceborne system reliability protection method as described in any one of claims 1 to 8.

10. A storage medium storing computer-readable instructions, characterized in that, When the computer-readable instructions are executed by one or more processors, the one or more processors perform the steps of a hardware-software co-operational spaceborne system reliability protection method as described in any one of claims 1 to 8.