MCU anti-radiation light module control system based on multi-level redundancy and safe starting mechanism

The optical module control system, with its multi-level redundancy and safe startup mechanism, solves the problems of single-event effect and total dose effect caused by irradiation in high-density optical transceiver systems, and achieves stable operation of a highly reliable optical communication system.

CN122219287BActive Publication Date: 2026-07-24HEFEI FENGZHIYI SEMICON CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HEFEI FENGZHIYI SEMICON CO LTD
Filing Date
2026-05-19
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In high-density optical transceiver systems, microcontrollers and their peripheral circuits are susceptible to single-event effects and total dose effects caused by penetration by external high-energy particles, leading to memory bit flipping or drift of peripheral analog parameters. Existing redundancy mechanisms fail under harsh conditions, and the microcontroller reset and optical output channel have poor synchronization, causing abnormal optical power in the link and device overload.

Method used

The MCU radiation-resistant optical module control system, which employs multi-level redundancy and a safe startup mechanism, synchronously collects photoelectric observation data, calculates disturbance significance fingerprints, allocates redundant copies to different storage addresses, performs background scanning and safe boot, and generates comprehensive error indicators to ensure the independence and synchronization of the microcontroller under abnormal conditions.

Benefits of technology

It effectively blocks common-mode failures caused by spatial neighborhood coupling and multi-source thermoelectric crosstalk, improves the fault tolerance and independence of the microcontroller in harsh environments, avoids the timing misalignment risk during abnormal reset of the microcontroller, and achieves highly reliable and stable operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122219287B_ABST
    Figure CN122219287B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of optical communication technology comprising multiple transceiving channels, and discloses an MCU anti-radiation optical module control system based on multi-level redundancy and a safe starting mechanism, comprising: collecting photoelectric observation data and firmware events in the control link to construct a multi-dimensional state observation sequence; extracting a disturbance significance fingerprint according to the channel space coordinates and the above sequence; calculating the topological weight of the key variables based on the fingerprint, and accordingly performing address dispersion and rewriting repair on the redundant copies; distributing the background scanning of the logical segments according to the above weight to obtain the memory error load; summarizing each error load into a comprehensive error index, and only when the index is strictly zero, issuing an enable signal to control the emission current and the watchdog; and when starting, performing sequence checking and jumping on multiple application images according to the fingerprint. The present application effectively improves the fault tolerance independence and running stability of the dense photoelectric transceiver array.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of optical communication technology, which includes multiple transceiver channels, and more specifically, to a radiation-resistant optical module control system for an MCU based on multi-level redundancy and a secure startup mechanism. Background Technology

[0002] In recent years, with the increasing demand for communication in harsh environments, the integration of parallel optoelectronic transceiver arrays (such as onboard optical modules) has been continuously improved. In such high-density optical transceiver systems, a single microcontroller is typically used to centrally schedule multiple transceiver channels. When subjected to penetration by external high-energy particles, the microcontroller and its peripheral circuits are prone to single-event effects and total dose effects, causing memory bit flips or drift of peripheral analog parameters.

[0003] To address the aforementioned interference, existing technologies typically employ conventional fault-tolerant mechanisms such as triple mode redundancy and watchdog reset. However, in high-density packaging, multiple transceiver channels are located close to each other, sharing control buses, power return paths, and heat dissipation paths. When a localized area experiences transient thermal interference or particle penetration, the bias current and temperature of the associated channels are highly susceptible to synchronous shifts with the microcontroller's internal memory array. This causes the conventional triple mode redundancy replicas to be simultaneously damaged due to their overly concentrated distribution, thus compromising the objectivity and independence of the majority voting mechanism.

[0004] Furthermore, existing microcontroller bootloaders primarily focus on code integrity verification when handling abnormal resets. However, the output drive capacitors of external light-emitting devices exhibit an objective level-holding effect, meaning the microcontroller's reset action often cannot be strictly synchronized with the rapid blocking of the optical output channel. While the microcontroller is still performing time-consuming application image verification and jump analysis, the external light-emitting device may still be in an uncontrolled residual emission state, easily leading to abnormal link optical power or even device overload. Currently, there is still a lack of effective integrated control strategies to address the complex challenges caused by spatial multi-source crosstalk and hardware / software response timing misalignments. Summary of the Invention

[0005] This invention provides a radiation-resistant MCU control system based on multi-level redundancy and a safe startup mechanism, which solves the technical problems mentioned in the background art.

[0006] This invention provides a radiation-resistant MCU optical module control system based on multi-level redundancy and a secure boot mechanism. It is applied to an optical module system comprising a microcontroller, memory area, watchdog timer, multiple transceiver channels, and multiple application program images, and is configured to execute: The physical coordinate attributes of the multiple transceiver channels are obtained, and photoelectric observation data and firmware event records are synchronously collected in the control loop to construct a multi-dimensional state observation sequence. The perturbation saliency fingerprint is calculated based on the channel physical coordinate attributes and the multidimensional state observation sequence; Based on the perturbation saliency fingerprint, the topological weights of the key control variables are calculated, and three redundant copies of the key control variables are generated and allocated to different physical addresses in the storage area for storage. When reading the key control variables, data verification and unique recovery value rewriting are performed on the three redundant copies to obtain the redundancy repair load. Based on the topology weights, the scan ratios of each logical segment within the storage area are allocated to perform background scanning, thereby obtaining the memory check error load. The redundant repair load, the memory check error load, and the processor abnormal load are added together to form a comprehensive error index. An enable signal is generated only when the comprehensive error index is zero, so as to allow the transmit current output and the watchdog timer to be fed. At startup, the multiple application images are sequentially verified based on the saved perturbation saliency fingerprint to determine the unique startup object and jump to it.

[0007] The beneficial effects of this invention are as follows: By synchronously acquiring multi-dimensional state observation sequences and extracting disturbance significance fingerprints within the control loop, and deeply binding them with the redundant copy address dispersion mechanism of key control variables, the dynamic background scanning ratio of the storage area, and the secure boot sequence, it not only effectively blocks the common-mode failure chain caused by spatial neighborhood coupling and multi-source thermoelectric crosstalk, but also improves the objective fault tolerance independence of the microcontroller under harsh environments; it also effectively avoids the timing misalignment between the boot program verification time and the residual state of external light-emitting devices during abnormal reset of the microcontroller by utilizing the strict zero-value gating defense line of the comprehensive error index, thus realizing the highly reliable and stable operation of the high-density optical communication system. Attached Figure Description

[0008] Figure 1 This is a flowchart of the MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism of the present invention. Detailed Implementation

[0009] The subject matter described herein will now be discussed with reference to exemplary embodiments. It should be understood that these embodiments are discussed only to enable those skilled in the art to better understand and implement the subject matter described herein, and changes may be made to the function and arrangement of the elements discussed without departing from the scope of this specification. Various processes or components may be omitted, substituted, or added as needed in the examples. Furthermore, features described in some examples may be combined in other examples.

[0010] like Figure 1As shown, a radiation-hardened optical module control system based on multi-level redundancy and a secure boot mechanism is applied to an optical module system that includes a microcontroller, memory area, watchdog timer, multiple transceiver channels, and multiple application program images. It is configured to execute: The physical coordinate attributes of the multiple transceiver channels are obtained, and photoelectric observation data and firmware event records are synchronously collected in the control loop to construct a multi-dimensional state observation sequence. The perturbation saliency fingerprint is calculated based on the channel physical coordinate attributes and the multidimensional state observation sequence; Based on the perturbation saliency fingerprint, the topological weights of the key control variables are calculated, and three redundant copies of the key control variables are generated and allocated to different physical addresses in the storage area for storage. When reading the key control variables, data verification and unique recovery value rewriting are performed on the three redundant copies to obtain the redundancy repair load. Based on the topology weights, the scan ratios of each logical segment within the storage area are allocated to perform background scanning, thereby obtaining the memory check error load. The redundant repair load, the memory check error load, and the processor abnormal load are added together to form a comprehensive error index. An enable signal is generated only when the comprehensive error index is zero, so as to allow the transmit current output and the watchdog timer to be fed. At startup, the multiple application images are sequentially verified based on the saved perturbation saliency fingerprint to determine the unique startup object and jump to it.

[0011] This solution is applied to an optical module system that includes a microcontroller, storage area, watchdog timer, multiple transceiver channels, and multiple application images. The microcontroller is an industrial-grade automotive-grade MCU that supports hardware floating-point operations and memory protection units. The storage area includes on-chip Flash, on-chip SRAM, and a one-time programmable memory area. The watchdog timer includes an independent watchdog timer and a window watchdog timer. The multiple transceiver channels are parallel integrated optoelectronic transceiver channels. Each channel includes an independent light-emitting device, photodetector, bias drive circuit, and signal acquisition link. Multiple application images are stored in independent physical partitions of the on-chip Flash, and the factory safe rollback image is stored in the one-time programmable memory area.

[0012] The control link number is , The integer is a positive integer, and the execution cycle of each control link is . , The value ranges from 100 microseconds to 1 millisecond, which is consistent with the closed-loop control cycle of the optical module's transmit current. Each control link completes a full process of status acquisition, calculation, and control command output.

[0013] The total number of multiple transceiver channels is , Each channel is assigned a unique channel number, which is a positive integer greater than or equal to 2. , .

[0014] The total number of key control variables in the system is , Each key control variable is assigned a unique variable number, which is a positive integer. , The key control variables are the control parameters related to optical module transmit current control, bias voltage adjustment, temperature compensation, and channel status management, which directly affect the system's operational safety and communication performance.

[0015] The total number of logical segments pre-divided in the storage area is , Each logical segment is assigned a unique segment number, which is a positive integer. , .

[0016] The total number of candidate application images is 3, and each image is assigned a unique image number. , The factory rollback image number is 0.

[0017] The instantaneous optical power, instantaneous bias current, instantaneous local temperature, and instantaneous reference voltage of each transceiver channel are collected synchronously. The first transceiver channel is in the... The instantaneous photopower of each control element is The unit is watts. The optical signal is converted into a current signal by the photodetector of the corresponding channel, and then acquired by a transimpedance amplifier and a 12-bit or higher analog-to-digital converter. The acquisition trigger signal is uniformly output by the microcontroller's hardware timer to ensure that the synchronization error of the acquisition time of all channels does not exceed [a certain value]. . No. The first transceiver channel is in the... The instantaneous bias current of each control loop is The unit is ampere. Differential voltage is acquired through a high-precision sampling resistor connected in series with the corresponding channel's light-emitting device, and then converted by an instrumentation amplifier and analog-to-digital converter. The acquisition time is strictly synchronized with the acquisition time of the instantaneous optical power. The first transceiver channel is in the... The instantaneous local thermodynamic temperature of each control element is The temperature is measured in Kelvin and is acquired using a surface-mount digital temperature sensor attached to the surface of the corresponding channel's light-emitting device and driving circuit. The temperature sensor has a sampling resolution of no less than 0.0625 Kelvin, and the acquisition time is strictly synchronized with the photoelectric parameter acquisition time. The first transceiver channel is in the... The instantaneous reference voltage of each control loop is The unit is volts. It is obtained by acquiring the reference reference voltage of the corresponding channel drive circuit through the high-precision reference voltage monitoring channel built into the microcontroller. The acquisition time is strictly synchronized with the acquisition time of photoelectric parameters.

[0018] All the collected raw data first undergoes a first-order low-pass filter. The filter formula is as follows: in These are the original collected values ​​of the corresponding physical quantities. The effective value after filtering. The filter coefficient ranges from 0.2 to 0.8. Based on the control loop cycle and hardware noise level calibration, when the acquired value exceeds 5% to 95% of the hardware range, it is determined to be an abnormal acquired value, and the effective value of the previous control loop is used to replace the current abnormal value.

[0019] Calculate the global mean of each collected physical quantity. For the first... The filtered collected values ​​of all channels in each control loop are used to calculate the global average value across all channels. The calculation formula is as follows: in For the first Average optical power across all channels in each control element. This is the average bias current across all channels. This represents the average local temperature across the entire channel. This is the average reference voltage across all channels.

[0020] Calculate the normalized values ​​of each physical quantity and construct a single-channel observation vector. The preset minimum resolvable optical power is... The unit is watts, and the value is equal to the minimum quantization step value of the optical power acquisition link, calculated from the quantization bits and range of the analog-to-digital converter unit; the preset minimum resolvable bias current is... The unit is amperes, and the value is equal to the minimum quantization step value of the bias current acquisition link; the preset minimum resolvable value of the reference voltage is... The unit is volts, and its value is equal to the minimum quantization step value of the reference voltage acquisition link.

[0021] For each channel's acquired physical quantity, normalization is performed, and the calculation formula is as follows: in For the first The first channel in the Normalized optical power of each control element For normalized bias current, To normalize the local temperature, As a normalized reference voltage, all normalized values ​​are dimensionless pure numbers, and their numerical ranges are uniformly constrained. When the calculation result exceeds this range, it is truncated according to the boundary value to ensure that the order of magnitude of all normalized values ​​is completely consistent with the change benchmark.

[0022] The formula for combining all normalized values ​​from the same channel into a single-channel observation vector is as follows: in For the first The first channel in the Single-channel observation vector of each control link This represents the matrix transpose operation. The vector dimension is 4×1, all elements are dimensionless pure numbers, and the normalization benchmark is completely consistent.

[0023] Calculate the event flag occurrence rate and construct a multidimensional state observation sequence. The preset total number of firmware event categories is... , The values ​​are positive integers. Firmware event categories include bus communication exception events, driver circuit overload events, analog-to-digital conversion overflow events, memory access error events, and instruction execution exception events. Each event category is assigned a unique category number. , . No. Class events in the first The cumulative record count of each control link is , It is a non-negative integer, accumulated through the microcontroller's built-in event counter, exception capture register, and interrupt service routine. After each control loop ends, the event count is cleared, and only the event records within the current control loop are retained.

[0024] The occurrence rate of event flags for each event category is calculated using the following formula: in For the first Class events in the first The event flag occurrence rate of each control link is a dimensionless pure number, with a value range of [value range missing]. .

[0025] The occurrence rates of event markers for all event categories are combined into a comprehensive event marker occurrence rate vector, calculated using the following formula: in For the first The comprehensive event flag occurrence rate vector for each control link, with dimension [missing information]. All elements are dimensionless pure numbers, and their values ​​are uniformly within a certain range. .

[0026] By combining the single-channel observation vectors of all channels with the comprehensive event flag occurrence rate vector, a multi-dimensional state observation sequence is constructed. The calculation formula is as follows: in For the first The multidimensional state observation sequence of each control link is in matrix form, containing the physical state information of all channels within the current control link and the event state information of the system firmware.

[0027] Calculate the straight-line distance between channels and the global average distance. The physical coordinate attributes of each channel are , The unit is meters. , , These are the three-dimensional rectangular coordinates of the channels in the optical module hardware layout, with the mechanical reference point of the optical module as the origin. The coordinates of all channels are directly extracted from the hardware layout file of the optical module, and the coordinate accuracy is not less than 0.001 meters.

[0028] The formula for calculating the straight-line distance between any two channels is as follows: in For the first The first channel and the first The straight-line distance between the channels, in meters. This represents the L2 norm operation, and the result is a non-negative real number.

[0029] The global average distance for calculating the pairwise spatial distances across all channels is calculated using the following formula: in This is the global average of the spatial distance across all channels, expressed in meters. hour, The value is set to 0.001 meters to avoid errors caused by dividing by zero.

[0030] Calculate the neighborhood association weight matrix. Preset co-bus markers. Same power supply branch marking Same heat dissipation path marking All are binary markers, with values ​​of 0 or 1. The specific determination rules are as follows: Same as bus markers When the first The first channel and the first When multiple channels are connected to the same control bus, the value is 1; otherwise, it is 0. (Same power supply branch marking) When the first The first channel and the first When multiple channels are powered by the same LDO output from the same power supply branch, the value is 1; otherwise, it is 0. (Same heat dissipation path marking) When the first The first channel and the first When all channels share the same main heat sink and heat conduction structure, the value is 1; otherwise, it is 0.

[0031] The elements of the neighborhood association weight matrix are calculated using the following formula:

[0032] in The neighborhood association weight matrix is ​​the first... Line 1 The elements of the column are dimensionless pure numbers, representing the first... The channel is relative to the first The degree of spatial and hardware coupling between each channel; , , These are the coupling dimension weight coefficients, all of which are dimensionless constants with a value of 1. They can be adjusted according to the hardware coupling strength calibration, and the value range is from 0.5 to 2. This function performs natural exponentiation, taking dimensionless pure numbers as input and outputting dimensionless positive real numbers.

[0033] The neighborhood association weight matrix of the first The row vector is: in It is a 1×M row vector, where all elements are dimensionless pure numbers, and the sum of the elements in each row is 1.

[0034] Calculate the original significance score. Preset the observation weight vector. Flag weight vector Topological weight vector All are dimensionless constant vectors, specifically defined as follows: Observation weight vector The dimension is 4×1, consistent with the dimension of the single-channel observation vector. All elements have a value of 0.25, and the sum is 1. This can be adjusted according to the perturbation sensitivity calibration of the physical quantity. The value of each element ranges from 0 to 1; [This is a] flag weight vector. , dimension Consistent with the dimension of the comprehensive event marker occurrence rate vector, each element takes a value of The sum is 1, and it can be adjusted according to the risk level of the event. The value of each element ranges from 0 to 1; Topological weight vector. The dimension is 1×M, which is the same as the dimension of the neighborhood association weight row vector, and each element takes a value of The sum is 1, and can be adjusted according to the priority of the channel. The value of each element ranges from 0 to 1.

[0035] Perform a second normalization process on the inner product terms corresponding to the three weight vectors to ensure that the values ​​of the three inner product terms are all within the same range. Then calculate the original significance score using the following formula: in The normalized value of the inner product term of the observation vector, with a range of values ​​of 1. ; The inner product term of the event flag vector has a value range of 1. ; The inner product term of the neighborhood weight vector takes values ​​in the range of . ; For the first The first channel in the The original significance scores for each control link are dimensionless pure numbers, with values ​​ranging from [value range missing]. The normalization benchmarks of the three inner product terms are completely consistent, their orders of magnitude are perfectly matched, and the addition operation has a clear physical meaning.

[0036] Calculate the association weights and perturbation significance fingerprints. Perform natural exponential normalization on the original significance scores to obtain the association weights, calculated using the following formula: in For the first The first channel in the The correlation weights of each control link are dimensionless pure numbers, and the sum of the correlation weights of all channels is 1. The range of values ​​is... .

[0037] The formula for calculating the weighted average observation vector across all channels is as follows: in It is the weighted average of the observation vectors of all channels, with a dimension of 4×1. All elements are dimensionless pure numbers, representing the baseline observation state of the entire system.

[0038] The observation bias measure for each channel is calculated using the following formula: in For the first The deviation measure between the observation vector of each channel and the baseline observation state is a dimensionless non-negative real number that characterizes the degree of deviation of the state of that channel.

[0039] The perturbation significance fingerprint for each channel is calculated using the following formula: in For the first The first channel in the The disturbance significance fingerprint of each control link is a dimensionless non-negative real number. The larger the value, the higher the disturbance degree of the channel and its associated channels, and the higher the risk of common-mode failure caused by irradiation.

[0040] Preset disturbance detection threshold , is a dimensionless constant with a value range of 0.1 to 0.5. When the perturbation significance fingerprint of a channel exceeds this threshold, it is determined that there is an abnormal perturbation in the channel, triggering the redistribution of redundant replica addresses and dynamic adjustment of the scan ratio of the corresponding key control variables. The adjustment step size does not exceed 20% of the current value to avoid parameter mutations that could lead to system instability.

[0041] Calculate the topological weights of the key control variables. The set of associated channels corresponding to each key control variable is labeled as follows: , For binary labels, when the first When a channel is the associated control object of this variable, the value is 1; otherwise, it is 0. The rule for determining the associated channel is: the value of this key control variable directly affects the operating status and control effect of the corresponding channel.

[0042] The topological weights of the key control variables are calculated using the following formula: in For the first The key control variables in the first The topological weight of each control link is a dimensionless non-negative real number, which represents the risk level of the variable affected by irradiation disturbance. The larger the value, the higher the risk level.

[0043] Global normalization is performed on the topology weights of all key control variables in the entire system. The calculation formula is as follows: in These are the normalized topological weights. The sum of the normalized topological weights for all variables is 1, and their values ​​range from [value range missing]. This ensures that the benchmark for subsequent weighted calculations is completely consistent.

[0044] Generate a hash digest for redundant copies. The variable identifiers for the key control variables are as follows: , is a fixed-length unsigned 32-bit integer, and the identifier of each variable is globally unique; the replica number of the redundant copy is . The value can be 1, 2, or 3, and each replica corresponds to an independent protected storage sector; the current control link number is... That is, the current control link number , is an unsigned 32-bit integer.

[0045] For the first The perturbation significance fingerprint set of each control link across all channels is used to perform quantitative summary extraction. The quantization digest is a fixed-length 32-bit unsigned integer generated by multiplying the perturbation significance fingerprints of all channels by 10000, rounding them down, and concatenating them into a continuous byte sequence. The 32-bit quantization digest is then calculated using the CRC32 algorithm. The CRC32 algorithm uses the standard IEEE 802.3 polynomial 0x04C11DB7 with an initial value of 0xFFFFFFFF. Both the input and output are inverted, and the final result is XORed with 0xFFFFFFFF to obtain the quantization digest.

[0046] The variable identifier, replica number, quantization summary, and control link number are concatenated into a continuous byte sequence in that order, using big-endian byte order. The concatenation operation is denoted as... This indicates that a sequence of binary bytes of multiple parameters is merged sequentially in byte order.

[0047] Perform a secure hash algorithm operation on the concatenated byte sequence to generate a hash digest. The calculation formula is as follows: in For the first The first variable The copy is in the first The hash digest of each control element is a 256-bit unsigned integer. It is the SHA-256 secure hash algorithm, which strictly follows the NISTFIPS 180-4 standard. The input is a byte sequence of arbitrary length, and the output is a fixed 256-bit hash value.

[0048] The write address for generating redundant copies is determined. The storage area is pre-divided into three independent protected storage sectors, each corresponding to a copy number. The sector division rules are as follows: the three sectors are located in three different physical banks of the on-chip Flash memory, the physical addresses of each sector are non-contiguous, and the interval between them is no less than 4KB. Each sector is configured with independent hardware write protection and read protection mechanisms to prevent irradiation-induced block effects from causing multiple copies to fail simultaneously. The base address of each sector is The unit is bytes, and it is an unsigned 32-bit integer; the number of available words in each sector is... The unit is a word, which is an unsigned 32-bit integer, and the length of a single word (byte) is... The value is 4, which corresponds to the word length of a 32-bit microcontroller, and the unit is bytes / word.

[0049] Convert a 256-bit hash digest to an unsigned 32-bit integer. The conversion rule is: take the lower 32 bits of the hash digest and convert it to an unsigned 32-bit integer in big-endian mode, ensuring that the input for the modulo operation is an unsigned integer of the same dimension.

[0050] The write physical address for each replica is calculated using the following formula:

[0051] in For the first The first variable The copy is in the first The physical address to be written to each control link is in bytes and is an unsigned 32-bit integer. The lower 32 bits of the hash digest are unsigned integers. This is an arithmetic modulo operation. The input is an unsigned 32-bit integer, and the output is an unsigned 32-bit integer with a value range of [value missing]. .

[0052] Overlap verification is performed on the three generated replica addresses. If any two addresses are in the same memory page, the second lowest 32 bits of the hash digest are re-performed modulo operation to generate a new address. This ensures that the three replica addresses are located in three different physical memory pages, thus avoiding page failures caused by single-event effects that could lead to the simultaneous damage of multiple replicas.

[0053] Generate a storage packet with verification and write it to the corresponding address. The key control variables in the first The effective value of each control link is It can be a 32-bit floating-point number or an unsigned 32-bit integer, and the data type is determined according to the physical meaning of the variable; the minimum resolvable value of the variable is... The value is equal to the minimum quantization step value of the control link corresponding to that variable.

[0054] Concatenate the valid variable values, control link number, and replica sequence number into a byte sequence, perform a 16-bit cyclic redundancy check operation to generate a checksum, calculated using the following formula: in The corresponding cyclic redundancy check code is a 16-bit unsigned integer. It uses the standard MODBUS 16-bit CRC algorithm with a polynomial of 0x8005 and an initial value of 0xFFFF. Both input and output are inverted.

[0055] The valid values ​​of variables, control link numbers, copy numbers, and checksums are packaged into a storage package with verification according to a fixed frame format. (Packaging function) The frame format is defined as follows: frame header 2 bytes, fixed at 0xAA55; variable valid value 4 bytes; control link number 4 bytes; copy sequence number 1 byte; check code 2 bytes; frame tail 2 bytes, fixed at 0x55AA; the total length of the storage packet is 15 bytes, and any part less than the length of a single word is padded with 0x00 to an integer multiple of 4 bytes.

[0056] The formula for generating storage packets is: in As a storage packet with verification, it is generated and then written to the corresponding replica write address. After the write operation is complete, a readback verification is performed to ensure the integrity of the written data.

[0057] Calculate the validity indicator of redundant replicas. Read storage packets from the write addresses corresponding to the three replicas and parse out the read variable values. Read out the step number Read the copy number Read the verification code .

[0058] The cyclic redundancy check (CRC) operation is re-performed on the read parameters to obtain the recalculated check code. The calculation formula is as follows: Define indicator functions The function takes the value 1 when the condition inside the parentheses is true, and 0 otherwise.

[0059] The validity indicator for each replica is calculated using the following formula: in For the first The first variable The copy is in the first The validity indicator of each control link takes a value of 0 or 1. A value of 1 indicates that the copy is valid, and a value of 0 indicates that the copy is invalid.

[0060] Calculate the candidate values ​​for the predicted control state. The variable values ​​from the previous effective control cycle are: , for the first The unique recovery value ultimately determined by each control link; the current set of observation data. Including the All observation data of the channel associated with the variable in the multidimensional state observation sequence of each control link.

[0061] Preset control simulation model This is a first-order linear prediction model, individually calibrated for each key control variable. The model calculation formula is as follows:

[0062] in For predicting candidate values ​​for control states, the dimensions are consistent with those of the key control variables; This is a proportionality coefficient, with a value ranging from 0.8 to 1.2; is the differential coefficient, with a value ranging from 0 to 0.3; The observation compensation coefficient ranges from -0.5 to 0.5. The average observation bias of the associated channel is used as a measure. All coefficients are obtained through simulation and actual calibration of the optical module closed-loop control to ensure that the predicted value is consistent with the actual trend of the variable.

[0063] When running for the first time after a cold start or reset, there are no valid values ​​from the previous cycle, and the factory-preset nominal value of the variable is used as the candidate value for predicting the control state.

[0064] Construct a set of candidate values ​​and calculate the overall cost. (Candidate value set) The construction rule is as follows: add the read variable values ​​corresponding to all copies with a validity indicator of 1 to the set. If the set is empty, add the variable values ​​of the previous valid control cycle and the factory default nominal values ​​to the set to ensure that the set contains at least one valid candidate value.

[0065] For each candidate value in the set Calculate the corresponding total cost using the following formula: in Candidate values The corresponding overall cost is a dimensionless integer; the first term is the basic deviation term, which represents the degree of deviation between the candidate value and the predicted value, and its dimension is a dimensionless pure number; the second term is the effective copy matching term, which represents the degree of matching between the candidate value and the effective copy. The two terms are of the same order of magnitude, and the subtraction operation has a clear physical meaning.

[0066] Select a unique recovery value and calculate the redundancy repair load. From the set of candidate values, select the candidate value that minimizes the overall cost as the unique recovery value. The selection formula is as follows: in For the first The variable in the first... The unique recovery value of each control link has the same dimensions as the effective value of the variable.

[0067] When the total cost of multiple candidate values ​​is equal and all are the minimum, the tie-breaker rule is applied: the candidate value with the smallest deviation from the predicted candidate value of the control state is selected first; if the deviations are still equal, the candidate value with the largest number of valid matching copies is selected first; if they are still equal, the variable value of the previous valid control period is selected first.

[0068] The calculation formula for redundant repair load is as follows: in For the first The variable in the first... The redundancy repair load of each control link is a dimensionless pure number, with a value range of [value missing]. ; To prevent a zero minimum value, the value is set to 1e-6 to avoid errors caused by dividing by zero.

[0069] The storage package with verification is regenerated using the unique recovery value. The storage addresses of all replicas are rewritten to complete the repair and synchronization of redundant replicas. After the rewriting is completed, a readback verification is performed to ensure that the repaired replica data is complete and valid.

[0070] Calculate the scan ratio of each logical segment. The logical segmentation rule of the storage area is as follows: based on the principle of physical address contiguousness, the area storing key control variables and runtime code in the storage area is divided into J consecutive logical segments. Each logical segment is of equal size and is an integer multiple of 4KB. Each logical segment corresponds to a unique segment number. The logical segment is not bound to the physical bank of the storage sector. Each logical segment contains the storage addresses of multiple key control variables.

[0071] The normalized topological weights of all relevant variables within the target logic segment are accumulated to calculate the scan ratio of that logic segment. The calculation formula is as follows: in For the first The logical segment is in the first The scan ratio of each control link is a dimensionless pure number, and the sum of the scan ratios of all logic segments is 1, with a value range of [value missing]. ; For the first A set of key control variables contained within each logic segment.

[0072] Calculate memory checksum error load. Read the first... The byte sequence corresponding to this scan within each logical segment is denoted by the byte extraction function. The output is a continuous byte sequence of the corresponding storage area.

[0073] The read byte sequence, segment number, and control link number are concatenated in sequence, and a 32-bit cyclic redundancy check (CRC) operation is performed to obtain the current checksum. The calculation formula is as follows: in For the first The logical segment is in the first The current check code for each control link is a 32-bit unsigned integer; It uses the standard IEEE 802.3 CRC32 algorithm, which is completely consistent with the algorithm used for quantized digest generation.

[0074] The target verification code pre-stored within the security protection zone is This is the standard checksum under ideal conditions where there is no data corruption in this logical segment. It is stored in a one-time programmable memory area and can only be updated during firmware upgrades.

[0075] Calculate the Hamming distance between the current checksum and the target checksum, normalize it to obtain the memory check error load, and the calculation formula is as follows: in For the first The logical segment is in the first The memory check error load of each control link is a dimensionless pure number with a value range of [value missing]. ; This is a function for calculating Hamming distance, which outputs the number of different binary bits between two 32-bit integers, with values ​​ranging from 0 to 32.

[0076] When the memory check error load is greater than 0, the memory error repair process is triggered. The repair benchmark is the pre-stored benchmark image of the corresponding logical segment. After the repair is completed, the check is re-executed to ensure that the error load returns to zero.

[0077] Calculate the maximum number of characters scanned in a single round and the actual number of characters scanned. Call the microcontroller's built-in hardware cycle timer to obtain the measured number of idle cycles of the processor within the current control loop, denoted as . , is an unsigned 32-bit integer representing the number of clock cycles remaining that the processor can use for background scanning after completing the core control task of the current control loop.

[0078] Single-character scanning calibration cycle is , is an unsigned 32-bit integer representing the fixed number of clock cycles required for the processor to scan the storage content of a single word. It is obtained through pre-calibration and has a value of 10 clock cycles.

[0079] The formula for calculating the maximum number of characters scanned in a single round is as follows: in For the first The maximum number of characters that can be scanned in a single round within a control loop is an unsigned 32-bit integer. This is for floor function.

[0080] The formula for calculating the rotational compensation margin is as follows: in For the first The rotation compensation margin for each control link is a non-negative integer, used to compensate for the loss of scan words caused by rounding down, ensuring that the total number of scan words in each control link is equal to the maximum number of scan words in a single round.

[0081] The allocation rule for the rotational compensation margin is as follows: Following the order of logic segment numbers, each control element allocates its entire compensation margin to a designated logic segment. The formula for calculating the number of the designated logic segment is as follows: This ensures that all logic segments have an even distribution of compensation margin within the J control loops, thus avoiding scan omissions.

[0082] The actual number of words scanned for each logical segment is calculated using the following formula: in For the first The logical segment is in the first The actual number of scanned words for each control segment is a non-negative integer, and the sum of the actual scanned words for all logic segments equals [the total number of scanned words]. .

[0083] The execution rules for background scanning are as follows: the scanning task is executed in the processor's idle interrupt, and the scanning is performed in descending order of the scanning ratio of the logical segments. Within each control link, only the storage content of a specified number of words in each logical segment is scanned. Across control links, the scanning address is extended in ascending order of address to ensure that all logical segments complete a full scan within a fixed period.

[0084] Calculate the sum of segment checksum errors and the sum of redundancy repair errors. Calculate the total system-wide segment checksum using the following formula: in For the first The total system segment check error of each control link, is a dimensionless pure number with a value range of [value missing]. .

[0085] The formula for calculating the total redundancy repair errors across the entire system is as follows: in For the first The total redundancy repair error of each control link is a dimensionless pure number with a value range of [value missing]. .

[0086] Calculate processor abnormal load and comprehensive error metrics. Processor abnormal events include instruction fetch errors, data access errors, stack overflow errors, peripheral bus errors, and clock failure events. Each abnormal event is assigned a unique risk weight, with a value ranging from 0.2 to 1, determined according to the risk level of the abnormal event.

[0087] The formula for calculating abnormal processor load is: in For the first The abnormal load of the processor in each control link is a dimensionless pure number, with a value range of [value missing]. ; The total number of processor exception events of all types; For the first Risk weights for anomalous events; For the first The number of times a particular type of abnormal event occurs in the current control loop; For the first The maximum allowed number of times a particular exception event can occur; To prevent a zero minimum value, the value is set to 1e-6.

[0088] The comprehensive error index is calculated using the following formula: in For the first The comprehensive error index for each control link is a dimensionless pure number, and the values ​​of its three components are all within the range of... The normalization benchmark is completely consistent, the addition operation has a clear physical meaning, and the range of values ​​for the comprehensive error index is [missing value]. .

[0089] Generate a zero-error enable signal to control the transmit current output. A zero-error enable signal with a value of 1 is generated only when the overall error index is strictly equal to zero; otherwise, it is forcibly set to zero. The calculation formula is as follows: in For the first The zero-error enable signal for each control loop takes a value of 0 or 1 and is a binary switch signal.

[0090] The hardware implementation rule for the zero-error enable signal is as follows: the signal is connected to both the microcontroller's GPIO pin and the software control register. The GPIO pin is directly hardware interlocked with the driver enable circuit of the light-emitting device. The hardware interlock has a higher priority than the software control, ensuring that even if the software crashes, the light-emitting driver can be forcibly turned off through the hardware signal.

[0091] No. The first transceiver channel is in the... The target control current of each control link is The unit is amperes, which are calculated using the closed-loop power control algorithm of the optical module.

[0092] The final transmit current output command is generated using the following formula: in The output command is the emission current output to the external light-emitting device driver circuit, in amperes. When the zero error enable signal is 0, the output command is forced to 0 amperes, completely shutting off the driving current of the light-emitting device.

[0093] Control the watchdog's feeding operation. The currently booting and running application image is denoted as... The secure pre-stored target hash is denoted as This is the SHA-256 hash value of the application image in an ideal, tamper-free state, stored in a one-time programmable memory area.

[0094] Calculate the Hamming distance between the hash verification code of the current application image and the target hash code. Only when the Hamming distance is zero and the zero-error enable signal is 1, issue a watchdog timer permission; otherwise, block the watchdog timer operation. The calculation formula is:

[0095] in For the first Each control link has an independent watchdog feeding permission, with a value of 0 or 1; It uses the SHA-256 secure hash algorithm, which is completely consistent with the algorithm used to generate hash digests.

[0096] The rules for executing the watchdog operation are as follows: the watchdog feeding command for both the independent watchdog and the window watchdog is only allowed when the watchdog feeding permission is 1. If the watchdog feeding permission for three consecutive control links is 0, the watchdog will trigger a system reset, forcing the system to enter the safe startup process.

[0097] Calculate the hash dissimilarity of the candidate application images. The three candidate application images are stored in three independent physical partitions of the on-chip Flash memory, each partition configured with an independent hardware read protection mechanism. The image version number is... , It is a positive integer. The larger the value, the newer the image version. The version number is stored in the header of each image partition and cannot be tampered with.

[0098] Perform SHA-256 hashing on each candidate application image to obtain the extracted hash verification code. Calculate the Hamming distance between this hash and the target hash code pre-stored in the archive area, and normalize the result to obtain the hash difference. The calculation formula is as follows: in For the first The hash dissimilarity of each candidate application image is a dimensionless pure number with a value ranging from 1 to 2. ; For the first The complete byte sequence of each candidate application image; The target hash code of the corresponding image pre-stored in the sealing area is stored in a one-time programmable storage area.

[0099] Calculate the validity scalar of the candidate application image. Pre-defined digital signature verification function. It uses the ECDSAP-256 elliptic curve digital signature algorithm. The public key is stored in a one-time programmable storage area. When the digital signature of the image is verified, the function returns 1; otherwise, it returns 0.

[0100] The verification flag of the image is It is stored in the header of the mirror partition, and the default valid flag constant is . , is a fixed 32-bit unsigned integer, and the flag verification is successful only when the verification flag bit of the mirror is completely consistent with the valid flag constant.

[0101] The validity scalar of candidate application images is calculated using the following formula:

[0102] in For the first The validity scalar value for each candidate application image takes the value 0 or 1. A value of 1 indicates that the image is complete, valid, and has not been tampered with, and can be used as a startup object; a value of 0 indicates that the image is invalid and cannot be used as a startup object.

[0103] Calculate the candidate score and the downgrade score. Calculate the candidate score for each valid candidate application image using the following formula:

[0104] in For the first The candidate score for each candidate application image is a non-negative integer ranging from 0 to 4. The larger the value, the higher the startup priority. The newer the valid image, the higher the candidate score.

[0105] The factory-safe rollback image is stored in a one-time programmable storage area and is immutable. It is only used as a fallback bootloader when all candidate application images are invalid. The degradation score of the factory-safe rollback image is calculated using the following formula: in The downgrade score for the factory safety rollback image is a dimensionless positive real number, ranging from 1 to 4, which is completely consistent with the range of candidate scores, ensuring that the comparison benchmarks of the two are completely matched. When all candidate images are invalid, the downgrade score reaches the maximum value of 4, becoming the highest priority startup object.

[0106] Select a unique boot target and perform a safe jump. Among all candidate scores and downgrade scores, select the image partition corresponding to the highest value as the unique boot target. The selection formula is as follows: in This is the unique number corresponding to the startup object.

[0107] When multiple images have the same score and are all at the maximum value, a tie-breaker rule is applied: the candidate application image with the smaller number is selected first; if all candidate images have the same score, the factory rollback image is selected first to ensure the uniqueness of the startup object.

[0108] Throughout the entire process of initiating the jump, the light control current of all channels is unconditionally clamped to zero level. The clamping formula is as follows: in The current for controlling the light emission during the startup phase is measured in amperes. The clamping operation is implemented through hardware GPIO interlocking. The clamping starts from the moment the power-on reset signal takes effect and continues until the mirror jump is completed, the system enters normal operation, and the zero-error enable signal is set to 1. This completely avoids the risk of uncontrolled light emission during startup.

[0109] Based on the startup object's ID, obtain the corresponding safe jump address. The jump address mapping function is as follows: The output is the reset vector address of the corresponding image partition. The microcontroller executes the jump instruction to enter the running process of the corresponding image and complete the safe boot process.

[0110] After the jump is complete, the system performs a full state initialization and verification. Only when the comprehensive error index is zero is the hardware clamp on the luminous current released, and the system enters the normal closed-loop control process. A first-order inertial smoothing filter is applied to the calculated disturbance significance fingerprint to avoid misjudgments caused by noise from a single acquisition or normal service adjustments. The filter calculation formula is as follows: in is the filtered perturbation significance fingerprint, and is a dimensionless non-negative real number; The filter coefficient has a value range of 0.3 to 0.7 and is calibrated according to the control loop cycle and service adjustment frequency; during cold start, the initial filter value is set to 0.

[0111] The filtered disturbance significance fingerprint is used for subsequent topology weight calculation, redundant replica address allocation, and scan ratio adjustment. Only when the filtered disturbance significance fingerprints of three consecutive control loops exceed a preset disturbance judgment threshold will the exception be applied. Only when the time is right will the redundancy replica address reallocation and scan ratio dynamic adjustment be triggered to avoid frequent fluctuations in system parameters caused by a single disturbance.

[0112] For the Flash storage area with redundant copies, wear leveling and periodic refresh mechanisms are implemented to avoid storage cell aging caused by frequent erase and write operations, while eliminating silent data errors caused by storage charge drift due to irradiation.

[0113] The wear-leveling address rotation rule is as follows: each protected memory sector is divided into 16 physical blocks, and the number of erase / write operations for each physical block is counted separately, denoted as . ,in Number the sectors The physical block is numbered, and the erase / write count of the corresponding physical block is updated after each write operation.

[0114] The wear leveling correction formula for write addresses is:

[0115] in This is the final write address after wear leveling correction; This represents the number of words in a single physical block, ensuring that the addresses of different physical blocks do not overlap.

[0116] The periodic refresh rules for redundant replicas are as follows: every 1000 control steps, a full readback verification is performed on all redundant replicas. If the verification error load is greater than 0, the replicas are immediately rewritten to repair the error. Every 10000 control steps, a full refresh and rewrite is performed on all storage sectors to eliminate storage data degradation caused by irradiation.

[0117] To shorten the image verification time during the startup phase and avoid the risk of system loss of control during verification, all candidate application images are divided into fixed-size blocks, with each image divided into... Each block consists of a contiguous storage block, each 4KB in size, and each block corresponds to an independent pre-stored target hash and digital signature, stored in a one-time programmable storage area.

[0118] The execution rules for block verification are as follows: After the system is powered on and reset, the core startup code block at the head of the image partition is first verified. After the verification passes, the light current hardware clamp and system clock initialization are immediately executed. Then, incremental verification is performed on the remaining image blocks in the background. Only when all block verifications pass is the hash difference of the image determined to be 0; otherwise, it is determined to be an invalid image.

[0119] The formula for calculating the hash dissimilarity of a single mirror block is: in For the first The first mirror image The hash difference of each block; This is the byte sequence corresponding to the block; This is the pre-stored target hash code for the corresponding block.

[0120] The formula for calculating the hash dissimilarity of a fully mirrored hash is: The hash difference of the full mirror is only zero when all blocks have a hash difference of 0. The value is 0 only if the value is 0 otherwise the value is greater than 0.

[0121] For different value ranges of the comprehensive error index, a graded degradation process is implemented to maximize system availability while ensuring system security.

[0122] The hierarchical processing rules are as follows: when At this time, the system is in normal operating condition, sends a zero-error enable signal, and allows full-power transmit current output and normal dog feeding operation; when When the system is in a slightly abnormal state, the zero error enable signal is set to 0, the transmit current of all channels is forcibly limited to 10% of the nominal value, memory error repair and redundant copy rewriting are triggered at the same time, unnecessary background tasks are prohibited, and the error repair process is executed first. when When the system is in a moderately abnormal state, the zero error enable signal is set to 0, the transmit current of all channels is clamped to 0 Amperes, a full memory scan and full copy verification and repair are triggered, and the watchdog timer is started to disable countdown. If the comprehensive error index does not return to zero within 5 consecutive control links, the watchdog timer is reset. when When the system is in a severely abnormal state, the zero-error enable signal is set to 0, immediately triggering a hardware reset, forcing the system to enter the safe boot process, and simultaneously latching the abnormal state register for subsequent fault tracing.

[0123] For hardware failures caused by irradiation, such as single-event lockout, peripheral bus deadlock, and abnormal power supply voltage, implement hardware-level emergency handling procedures.

[0124] The processor's built-in hardware anomaly monitoring module monitors power supply voltage, core temperature, peripheral bus status, and phase-locked loop (PLL) lock status in real time. When a bus deadlock or current overload caused by a single-event lockout is detected, it immediately triggers a peripheral hardware reset and forcibly shuts down the power supply to all light-emitting devices. The calculation formula is as follows: in This is the enable signal for the light-emitting driver power supply, and its value is either 0 or 1. This is a flag for detecting single-particle locking events. It takes a value of 1 when a locking event is detected, and 0 otherwise.

[0125] If the lock event is not cleared after the peripheral hardware is reset, the system will be immediately triggered to perform a full reset. At the same time, the abnormal status information will be written to the non-volatile storage area. After the reset, the safe boot process will be entered. The light current clamp will only be released after the full hardware self-test passes.

[0126] In response to power outages caused by abnormal power supply, a power outage protection and non-volatile data storage mechanism is implemented to prevent damage to critical data and loss of system status due to power outages.

[0127] The microcontroller's built-in power-down detection module monitors the supply voltage in real time. When the supply voltage drops below a preset power-down threshold, a non-maskable interrupt is triggered, and the interrupt service routine immediately performs the following operations: Force the light emission current of all channels to be clamped to 0 Amperes and turn off the drive power supply; Write the key control variables, disturbance significance fingerprints, topology weights, and abnormal state information of the current control loop into the backup partition of the non-volatile storage area; After the write operation is complete, a system soft reset is triggered to prevent data write errors during power outages.

[0128] After the system is powered on and reset, it first reads the valid data of the backup partition and verifies the data integrity. If the verification passes, it restores the system state of the previous valid control link to avoid the loss of control parameters caused by cold start. If the verification fails, it initializes the system state with the factory preset nominal values.

[0129] The configuration rules for standalone watchdog and windowed watchdog are as follows: The independent watchdog is driven by a low-speed RC clock inside the microcontroller with a clock frequency of 32kHz and an overflow time set to 10 times the control loop cycle, ensuring that the watchdog feeding operation can be completed under normal operating conditions and that a reset can be triggered in time under abnormal conditions. The window watchdog is driven by the system kernel clock, and the upper and lower limits of the window are set to 60% to 100% of the control loop cycle. The watchdog feeding operation is only allowed within the window range to avoid abnormal watchdog feeding caused by program crashes.

[0130] The recovery rules after an abnormal reset are as follows: After a system reset, first read the reset status register to determine the reset source. If the reset source is a watchdog reset, a software abnormal reset, or a hardware lock reset, then perform the following operations: Forcefully enable hardware clamping of the emission current to prevent any emission current output; Read the abnormal state information of the non-volatile storage area, and perform a full memory scan and redundant copy verification and repair; Perform full block verification on all application images and select the highest priority valid image to start; After three consecutive watchdog resets, the system forcibly starts the factory safe rollback image, latches the fault state, and prohibits the output of transmitting current until a full hardware self-test and parameter recalibration are performed.

[0131] To address parameter deviations caused by cumulative irradiation effects, hardware aging, and temperature drift, the system implements an online calibration and parameter self-calibration process to ensure the long-term stability and accuracy of the algorithm.

[0132] The self-calibration process is automatically triggered every 100,000 control steps, or when the system detects an ambient temperature change exceeding 20 Kelvin. The calibration process includes: Turn off the transmit current output of all channels, clamp to 0 Amperes, and enter calibration mode; Collect the dark current, dark power, reference voltage, and temperature sensor reference values ​​of all channels, and update the calibration coefficients of the physical quantity acquisition. Perform memory scan calibration and update the single-word scan calibration cycle. ; The parameters of the execution control simulation model are self-calibrated, and the proportional, derivative, and compensation coefficients of the model are updated based on historical operating data to ensure the accuracy of the predicted values. After calibration is complete, the updated calibration coefficients are written to the calibration partition of the non-volatile storage area, the pre-stored target check code is updated, the calibration mode is exited, and the system enters normal operation.

[0133] The formula for updating the calibration coefficients is: in The updated calibration coefficients; The original calibration coefficient; The nominal reference value of a physical quantity; These are the measured values ​​collected in calibration mode.

[0134] The embodiments of this example have been described above. However, this example is not limited to the specific implementation methods described above. The specific implementation methods described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms based on the guidance of this example, and all of them are within the protection scope of this example.

Claims

1. A radiation-resistant optical module control system based on multi-level redundancy and secure boot mechanism, applied to an optical module system including a microcontroller, storage area, watchdog timer, multiple transceiver channels, and multiple application program images, characterized in that... Configured for execution: The physical coordinate attributes of the multiple transceiver channels are obtained, and photoelectric observation data and firmware event records are synchronously collected in the control loop to construct a multi-dimensional state observation sequence. The perturbation saliency fingerprint is calculated based on the channel physical coordinate attributes and the multidimensional state observation sequence; Based on the perturbation saliency fingerprint, the topological weights of the key control variables are calculated, and three redundant copies of the key control variables are generated and allocated to different physical addresses in the storage area for storage. When reading the key control variables, data verification and unique recovery value rewriting are performed on the three redundant copies to obtain the redundancy repair load. Based on the topology weights, the scan ratios of each logical segment within the storage area are allocated to perform background scanning, thereby obtaining the memory check error load. The redundant repair load, the memory check error load, and the processor abnormal load are added together to form a comprehensive error index. An enable signal is generated only when the comprehensive error index is zero, so as to allow the transmit current output and the watchdog timer to be fed. At startup, the multiple application images are sequentially verified based on the saved perturbation saliency fingerprint to determine the unique startup object and jump to it.

2. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to claim 1, characterized in that, Constructing a multidimensional state observation sequence includes: The instantaneous optical power, instantaneous bias current, instantaneous local temperature, and instantaneous reference voltage of each transceiver channel are collected synchronously, and the average values ​​are calculated respectively. The sum of the instantaneous optical power and the preset minimum resolvable optical power is divided by the sum of the corresponding mean and the minimum resolvable optical power, and the natural logarithm is taken to obtain the normalized optical power. Similarly, the normalized bias current and normalized reference voltage are calculated by combining the corresponding preset minimum resolvable values. The instantaneous local temperature is subtracted from the corresponding mean and then divided by the corresponding mean to obtain the normalized local temperature. The above normalized values ​​are combined to form a single-channel observation vector. Obtain the firmware event record count for each category, divide it by the total count plus one (with zero-prevention denominator) to obtain the event flag occurrence rate; combine all the single-channel observation vectors with all the event flag occurrence rates to form the multidimensional state observation sequence.

3. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to claim 2, characterized in that, Calculate the perturbation saliency fingerprint, including: The spatial straight-line distance between each pair of the transceiver channels is calculated using the physical coordinate attributes of each channel, and the global average distance is obtained. The quotient of the spatial straight-line distance divided by the global average distance is negative and then subjected to natural exponentiation. It is then multiplied by the sum of the preset same bus marker, same power branch marker, same heat dissipation path marker and the number 1 to obtain the basic weight factor. The global proportion of the basic weight factor is calculated to obtain the neighborhood association weight. The original significance score is obtained by summing the inner product of the single-channel observation vector, the comprehensive event flag occurrence rate vector, and the row vector containing the neighborhood association weight with the preset observation weight vector, flag weight vector, and topology weight vector, respectively. The original significance score is normalized using the natural index to obtain the association weight; the second norm of the target observation difference is calculated by combining the observation vector of each channel with the association weight, and the perturbation significance fingerprint is obtained by weighted summation.

4. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to claim 3, characterized in that, The key control variables are generated into three redundant copies and stored at different physical addresses in the storage area, including: The topological weight is obtained by weighting and summing the perturbation significance fingerprints of the key control variables in their associated channels and dividing by the number of associated channels. The variable identifier, copy number, quantitative summary of the perturbation significance fingerprint, and current control link number are concatenated and then substituted into a secure hash algorithm to obtain a hash digest. For each pre-divided protected storage sector, the hash digest is used to perform arithmetic modulo on the number of available words in each sector, and then appended to the interval base address to generate three non-overlapping copy write addresses. Extract the valid values ​​of the variables at this time, the control link number, and the replica sequence number, merge them to obtain the cyclic redundancy check code, package them into a storage package with verification, and write it to the corresponding replica write address.

5. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to claim 4, characterized in that, Data verification and unique recovery value rewriting are performed on the three redundant copies to obtain the redundancy repair load, including: Verify whether the read check code attached to the read storage packet with check is consistent with the recalculated check code, and whether the read link number matches the current control link number. If they match, output a validity indicator with a value of one; otherwise, output zero. By combining the variable values ​​from the previous effective control cycle with the current observation data, and substituting them into the preset control deduction model, the candidate values ​​for predicting the control state are calculated. In the set of candidate values, the absolute value of the difference between each candidate value and the predicted candidate value of the control state is calculated and divided by the minimum distinguishable quantity of the variable to obtain the basic deviation term; the replica frequency statistic, which is equivalent to the candidate value and whose validity indicator is one, is subtracted to obtain the overall cost. The candidate value that minimizes the overall cost is selected as the unique recovery value; the total number of abnormal replicas whose content deviates from the unique recovery value but whose validity indicator is one is divided by the total number of valid replicas with a validity indicator of one to obtain the redundancy repair load, and the storage packet is rewritten using the unique recovery value.

6. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to claim 5, characterized in that, Based on the topology weights, a scan ratio is allocated for each logical segment within the storage area to perform a background scan, resulting in a memory check error load, including: The topological weights of all relevant variables within the target logic segment are summed and divided by the total topological weights of all system variables to obtain the scan ratio. The current read byte, segment number and control link number are concatenated in the current logical segment, and a cyclic redundancy check is performed to obtain the current check code; the Hamming distance deviation between the current check code and the target check code pre-stored in the security protection zone is calculated and normalized to obtain the memory check error load. The processor's built-in timer is invoked to obtain the measured idle period, which is divided by the single-word scan calibration period and rounded down to obtain the maximum number of scanned words in a single round. The maximum number of scanned words is multiplied by the above scan ratio to obtain the primary allocation baseline quota, which is combined with the rotation compensation margin to form the actual number of scanned words finally assigned by the instruction for background scanning.

7. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to claim 6, characterized in that, Synthetic error indicators and control, including: The segment check error sum is obtained by multiplying the scan ratio of each logical segment by the corresponding memory check error load; the redundancy repair error sum is obtained by multiplying the topology weight of each variable by the corresponding redundancy repair load. The comprehensive error index is obtained by adding the segment check error, the redundancy repair error, and the processor abnormal load obtained through the exception register. A zero error enable signal with a value of one is issued only when the comprehensive error index is strictly equal to zero; otherwise, it is forcibly set to zero. The system calculates the target control current for transmission, multiplies it by the zero-error enable signal, and generates a transmission current output command to be sent to external devices. Calculate the Hamming distance between the hash verification code of the currently booting application and the securely stored target hash code. If the Hamming distance is zero and the zero error enable signal is one, then issue a watchdog feed permission; otherwise, block the watchdog feed operation.

8. The MCU radiation-resistant optical module control system based on multi-level redundancy and safe startup mechanism according to any one of claims 1 to 7, characterized in that, Identify and jump to a unique launch target, including: For each candidate application image, a hash algorithm is executed to obtain the extracted hash verification code. The offset Hamming distance is calculated between the extracted hash and the pre-stored target hash code in the storage area and normalized to obtain the hash difference degree. If the hash difference is zero, the underlying digital signature verification passes, and the verification flag is valid and effective, then the validity scalar of the candidate application image is determined to be one; if any one of these is missing, it is determined to be zero. Multiply the validity scalar by the sum of the number of valid candidates with version numbers lower than that of the object plus one to obtain the candidate score for each candidate application image; use one as the numerator and the sum of all validity scalars plus one as the denominator to obtain the downgrade score for the factory safe rollback image used for system recovery. Among all the candidate scores and the downgraded scores, the mirror partition corresponding to the maximum value is selected as the unique start object for jump, and the light emission control current is unconditionally clamped to zero level during the jump transition period.