Hardware supplements for space AI initialization and self-maintenance

CN122579136APending Publication Date: 2026-08-14陈立波
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-20
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

本发明的目的在于克服现有技术的上述不足,提供一种太空人工智能初始化与自身维护的硬件补充方法、系统及电路,全流程通过纯硬件电路固化执行,无中央处理器、无指令执行、无软件代码运行,解决现有方案在太空环境下的能源初始化失效、单粒子锁定防护不足、智能模型退化失控、通信身份易被冒充的问题,实现整星智能系统的全生命周期硬件级自主维护

Benefits of technology

1. 实现能源系统硬件级故障重构,提升初始化运行可靠性:本发明通过纯硬件电路实现太阳翼展开、备用机构切换、紧急能量管制的全流程自动执行,无需软件参与,即使整星中央处理器完全失效,仍可自主完成能源系统故障重构,显著提升能源初始化成功率,降低整星断电失效的风险。

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This invention discloses a hardware supplementation method, system, and circuit for the initialization and self-maintenance of space-based artificial intelligence, belonging to the field of on-orbit maintenance technology for spaceborne artificial intelligence. It addresses the problems of existing spaceborne intelligent systems relying on a central processing unit plus software architecture, which are susceptible to operational anomalies due to single-event effects in space, inability to reconstruct energy systems in orbit after energy failures, lack of hardware-level self-checking for intelligent model degradation, and vulnerability to impersonation in communication. The core method of this invention includes: automatically switching to a backup mechanism when energy system initialization fails; entering emergency energy control when available power falls below a threshold; detecting and bypassing a locked power controller; periodically detecting the deviation between the artificial intelligence inference results and the baseline results, loading a backup model if the deviation exceeds a threshold; extracting and comparing physical layer features of the received signal, and entering an identity verification mode if the deviation exceeds a threshold. This invention is entirely hardware-executed, without a central processing unit, instructions, or software operation, possessing high on-orbit reliability and anti-interference capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of on-orbit control and maintenance technology of spaceborne artificial intelligence, specifically involving a hardware supplementation method, system and circuit for space artificial intelligence initialization and self-maintenance. Background Technology

[0002] The initialization and on-orbit self-maintenance of current spaceborne artificial intelligence systems rely entirely on a serial execution architecture of a central processing unit and embedded software, which presents the following prominent problems in the space-orbit environment: 1. Insufficient reliability of energy system initialization: Initialization operations such as solar array deployment and energy system switching rely on software control. The single-event effect in space can easily lead to abnormal software execution. After initialization failure, it is difficult to reconstruct in orbit, which may cause the entire satellite to lose power. 2. Lack of hardware-level single-event lockout protection: Existing power controllers rely on software polling for lockout detection and bypass, resulting in high detection delays. Overcurrent caused by single-event lockout can easily burn out onboard power devices, causing irreversible hardware damage. 3. Lack of effective protection against on-orbit degradation of intelligent models: Space radiation can easily cause memory cell flipping in intelligent accelerators and distortion of model parameters. Existing software self-checking schemes lack real-time performance, making it difficult to detect deviations in inference results in a timely manner, which can easily lead to intelligent decision-making errors and affect the execution of deep space exploration missions. 4. Insufficient communication identity protection capabilities: Existing spaceborne communication identity authentication relies on software encryption algorithms, which are easily cracked and impersonated by signal features. It lacks hardware-level physical layer fingerprint protection capabilities, posing a security risk of being maliciously controlled. 5. Insufficient redundancy protection throughout the entire process: All maintenance logic of the existing software solution relies on the normal operation of the central processing unit. Once the central processing unit fails due to radiation, the entire satellite's intelligent system, energy system, and communication system will run out of control, lacking hardware-level fallback protection capabilities.

[0003] Currently, there is a lack of a fully hardware-based solution for the initialization and self-maintenance of space artificial intelligence that does not require the participation of a central processing unit or software, making it difficult to meet the high-reliability on-orbit management requirements of deep space exploration and low-Earth orbit constellation networking. Summary of the Invention

[0004] 1. Technical problems to be solved The purpose of this invention is to overcome the above-mentioned shortcomings of the prior art and provide a hardware supplementation method, system and circuit for space artificial intelligence initialization and self-maintenance. The entire process is executed through pure hardware circuits, without a central processing unit, instruction execution and software code operation. This solves the problems of energy initialization failure, insufficient protection against single-event locking, intelligent model degradation and loss of control and communication identity being easily impersonated in the space environment of existing solutions, and realizes hardware-level autonomous maintenance of the entire satellite intelligent system throughout its entire life cycle.

[0005] 1. Technical Solution To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a method for initializing and maintaining space artificial intelligence, comprising the following steps: When the energy system fails to initialize, it will automatically switch to the backup mechanism. When all backups fail and the available power is below the survival threshold, it will enter emergency energy control. Detect and bypass the power controller that has locked out; The deviation between the AI ​​inference results and the benchmark results is periodically detected, and a backup decision model is loaded when the deviation exceeds a threshold. The physical layer features of the received signal are extracted and compared with the fingerprint database. When the feature deviation exceeds the threshold, the identity questioning mode is entered.

[0006] Furthermore, the entry into emergency energy control includes: shutting down all non-essential loads, sending a distress signal, cutting off the main system power, and retaining power to the wake-up circuit only to enter deep sleep mode; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code execution.

[0007] Furthermore, the power controller that detects and bypasses the lockout includes: determining the lockout when the output voltage change rate is zero when the light intensity changes, and immediately switching to the backup channel after physically disconnecting the power bus of the controller in one go; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code execution.

[0008] Furthermore, the periodic detection of AI inference result deviation includes: periodically sending the factory-fixed test vectors into the AI ​​accelerator for comparison with the factory-fixed benchmark results; if the error rate exceeds the threshold, the direct memory access controller loads a simplified decision model from the backup backup area to take over key decisions for power management, thermal management, and communication management; the backup backup area stores the factory-fixed simplified decision model, which uses an independent, unaccelerated, conservative inference path and does not rely on aging units; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

[0009] Furthermore, the extraction of physical layer features of the received signal includes: extracting at least one of carrier frequency stability, modulation error vector amplitude, and phase noise features; the entry into identity verification mode includes: discarding all non-urgent data packets, responding only to data packets with an urgent identifier, and requesting the other party to re-authenticate; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

[0010] Furthermore, the method also includes: after each successful authentication, the collected radio frequency fingerprint features and historical features are weighted and averaged, the updated fingerprint is stored in the dynamic fingerprint area, and the original baseline fingerprint is retained; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

[0011] Secondly, the present invention provides a hardware supplement system for space artificial intelligence initialization and self-maintenance that implements the above method, including an energy initialization fault reconstruction circuit, a single-event lock protection circuit, an artificial intelligence self-test circuit, and a communication identity anti-spoofing charging circuit; all processes of the system are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code operation; The energy initialization fault reconfiguration circuit is used to automatically switch to the backup mechanism when the energy system initialization fails and to enter emergency energy control when the available power is lower than the survival threshold. The single-particle lockout protection circuit is used to detect and bypass the power controller in the event of lockout. The artificial intelligence self-testing circuit is used to periodically detect the deviation between the artificial intelligence inference result and the benchmark result, and load the backup decision model when the deviation exceeds the threshold. The communication identity anti-spoofing charging circuit is used to extract the physical layer features of the received signal and compare them with the fingerprint database. When the feature deviation exceeds the threshold, it enters the identity questioning mode.

[0012] Thirdly, the present invention provides a hardware supplementary circuit for initializing and maintaining space artificial intelligence in accordance with the above method, including a timeout detection circuit, a backup switching control circuit, a maximum available power recalculation circuit, a survival threshold comparison circuit, an emergency control state machine circuit, a maximum power point tracking output voltage change rate detection circuit, a power bus isolation circuit, an artificial intelligence self-test timer circuit, a test vector comparison circuit, an error rate threshold comparison circuit, a backup model loading circuit, an RF fingerprint extraction circuit, a fingerprint comparison circuit, and an identity challenge triggering circuit; all processes of the circuit are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code execution; The timeout detection circuit is used to output a failure signal if the unfolding signal is not received within a preset time. The backup switching control circuit is composed of a relay drive circuit, with its input terminal connected to the output terminal of the timeout detection circuit. It is used to immediately switch to the backup deployment mechanism after receiving a failure signal. The maximum available power recalculation circuit consists of an adder and a comparator. Its input is connected to the output of the backup switching control circuit. It is used to recalculate the current available power after all backups fail. The survival threshold comparison circuit has its input connected to the output of the maximum available power recalculation circuit, and is used to compare the available power with the survival threshold to output an emergency control trigger signal. The emergency control state machine circuit is implemented by a one-hot code state machine. Its input is connected to the output of the survival threshold comparison circuit and is used to execute the emergency energy control process after receiving a trigger signal. The maximum power point tracking output voltage change rate detection circuit consists of a differential circuit and a zero-crossing comparator. Its input is connected to the power controller output bus. It is used to detect the output voltage change rate when the illumination changes, and outputs a lock signal when the change rate is zero. The power bus isolation circuit is composed of solid-state relays. Its input terminal is connected to the lock signal output terminal, which is used to physically cut off the power bus of the maximum power point tracking controller in one go after receiving the lock signal. The artificial intelligence self-test timer circuit has its input terminal directly connected to the local hardware clock output terminal, which is used to trigger self-test according to a preset period. The test vector comparison circuit has its input end directly connected to the output end of the artificial intelligence accelerator and the output end of the benchmark test vector memory. It is used to compare the current inference result of the artificial intelligence accelerator with the benchmark result that is fixed at the factory and output the error rate. The error rate threshold comparison circuit has its input connected to the output of the test vector comparison circuit, and is used to compare the error rate with a preset threshold to output a degradation trigger signal. The backup model loading circuit consists of a direct memory access controller, with its input terminal connected to the degradation trigger signal output terminal. It is used to load a simplified decision model from the backup area of ​​the backup decision model after receiving the degradation trigger signal. The radio frequency fingerprint extraction circuit consists of a fast Fourier transform hardware accelerator and a feature extraction circuit. Its input is connected to the radio frequency receiving bus and is used to extract the physical layer features of the received signal. The fingerprint comparison circuit has its input end connected to the output end of the radio frequency fingerprint extraction circuit and the output end of the fingerprint database memory. It is used to compare the extracted features with the fingerprint database reference features one by one and output the deviation value. The identity verification trigger circuit has its input end connected to the output end of the fingerprint comparison circuit, and is used to compare the deviation value with a preset threshold to output an identity verification signal.

[0013] Furthermore, the emergency control state machine circuit outputs in sequence: non-essential load shutdown signal, distress signal transmission enable signal, main system power cut-off signal, and deep sleep entry signal.

[0014] Furthermore, the circuit also includes a fingerprint adaptive update circuit. The input of the fingerprint adaptive update circuit is connected to the output of the fingerprint comparison circuit and the authentication pass signal. It is used to perform a weighted average of the extracted radio frequency fingerprint features and the historical features in the dynamic fingerprint area after each successful authentication and write it back.

[0015] 1. Beneficial effects Compared with the prior art, the present invention has the following advantages: 1. Achieve hardware-level fault reconstruction of the energy system and improve the reliability of initial operation: This invention realizes the automatic execution of the entire process of solar panel deployment, backup mechanism switching and emergency energy control through pure hardware circuits without the need for software intervention. Even if the entire satellite's central processor fails completely, it can still autonomously complete the fault reconstruction of the energy system, significantly improving the success rate of energy initialization and reducing the risk of the entire satellite failing due to power failure.

[0016] 2. Significantly shortens the response time of single-event lockout protection and reduces the risk of hardware damage: This invention uses a pure hardware differential circuit to detect the output voltage change rate of the power controller in real time, which greatly reduces the lockout detection and response delay. It can complete physical disconnection and backup channel switching before overcurrent damage to power devices, and can cope with the hardware burnout problem caused by single-event lockout in space.

[0017] 3. Possesses hardware-level intelligent model on-orbit health management capabilities, reducing the risk of decision-making errors: This invention periodically compares the intelligent inference results with the fixed benchmark vector through pure hardware circuitry, detects inference deviations caused by model parameter distortion in real time, and automatically loads a backup conservative model in hardware when the threshold is exceeded. Without the need for central processing unit and software intervention, it can cope with intelligent decision-making errors caused by space radiation and ensure the core safety of deep space exploration missions.

[0018] 4. Possesses physical layer hardware-level identity protection capabilities, with strong resistance to cracking and impersonation: This invention extracts the radio frequency physical layer features of the received signal through pure hardware circuitry to achieve hardware fingerprint identity authentication. It does not require software encryption algorithms and can cope with cracking and signal impersonation attacks. At the same time, it adapts to feature drift caused by the aging of on-orbit devices through fingerprint adaptive update circuitry, which has obvious protection advantages compared with existing software solutions.

[0019] 5. Possesses full-scenario hardware-level backup protection capabilities, enhancing operational stability in extreme environments: All initialization and maintenance processes in this invention are executed through hardware circuitry, independent of the normal operation of the central processing unit, operating system, and software. Even if the main satellite system is interrupted, it can still autonomously complete core operations such as energy backup, fault isolation, and emergency distress calls, providing reliable hardware-level safety redundancy for deep space exploration satellites. Detailed Implementation

[0020] The present invention will be further described in detail below with reference to specific embodiments. Those skilled in the art can implement the technical solutions of the present invention, solve corresponding technical problems, and achieve the intended technical effects based on the content disclosed in these embodiments.

[0021] All circuits in this embodiment are designed using radiation-resistant complementary metal-oxide-semiconductor (CMOS) technology to meet the total dose radiation and single-event effect protection requirements of the space on-orbit environment. All circuits are implemented using pure digital logic and analog front-end circuits, without embedded processors, instruction sets, or software code storage and execution units. Example

[0022] This embodiment provides a hardware supplement system for space artificial intelligence initialization and self-maintenance, including an energy initialization fault reconstruction circuit, a single-event lock protection circuit, an artificial intelligence self-test circuit, and a communication identity anti-spoofing charging circuit; all processes of the system are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

[0023] The energy initialization fault reconfiguration circuit includes a timeout detection circuit, a backup switching control circuit, a maximum available power recalculation circuit, a survival threshold comparison circuit, and an emergency control state machine circuit. The timeout detection circuit is implemented using a 32-bit hardware counter and comparator. Its input is directly connected to a real-time clock counter driven by a 1MHz radiation-resistant hardware crystal oscillator, and the arrival signal output of the deployment status monitoring circuit. The preset timeout is 30 seconds; if no arrival signal is received within the timeout period, an initialization failure signal is output directly. The backup switching control circuit is implemented using a radiation-resistant relay driver circuit and a multiplexer. Upon receiving a failure signal, it immediately outputs a drive signal to switch to the backup deployment mechanism, supporting up to four levels of backup mechanism switching. The maximum available power recalculation circuit is implemented using a 16-bit hardware adder and comparator. It immediately recalculates the current total available power of the satellite after all backup mechanisms fail. The survival threshold comparison circuit is implemented using a 16-bit hardware comparator. The preset survival threshold is 5W; when the available power is below the threshold, an emergency control trigger signal is output directly. The emergency control state machine circuit is implemented using a 5-state unique hot code hardware state machine, which outputs in sequence: non-essential load shutdown signal, distress signal transmission enable signal, main system power cut-off signal, and deep sleep entry signal.

[0024] The single-event lockout (SET) circuit includes a maximum power point tracking (MPPT) output voltage change rate detection circuit and a power bus isolation circuit. The MPPT output voltage change rate detection circuit uses a high-speed differential amplifier and a zero-crossing comparator. If the output voltage change rate remains zero during illumination changes, a lockout signal is immediately output. The power bus isolation circuit uses a radiation-resistant solid-state relay. Upon receiving the lockout signal, it quickly physically disconnects the corresponding power bus and switches to a backup channel.

[0025] The AI ​​self-test circuit includes an AI self-test timer circuit, a test vector comparison circuit, an error rate threshold comparison circuit, and a backup model loading circuit. The AI ​​self-test timer circuit is implemented using a 32-bit hardware counter with a preset self-test period of 10 minutes, automatically outputting a self-test trigger signal upon timing. The test vector comparison circuit is implemented using a 1024-bit parallel hardware comparator, comparing the current inference result of the AI ​​accelerator bit-by-bit with the baseline result stored in the one-time programmable memory and outputting the error rate. The error rate threshold comparison circuit is implemented using a 16-bit hardware comparator with a preset error rate threshold of 0.1%, immediately outputting a degradation trigger signal when the threshold is exceeded. The backup model loading circuit is implemented using a 32-bit hardware direct memory access controller, automatically loading and starting the simplified decision model from the one-time programmable memory backup area upon receiving the degradation trigger signal, taking over the critical decision-making authority for the entire satellite.

[0026] The communication identity fraud prevention circuit includes an RF fingerprint extraction circuit, a fingerprint comparison circuit, an identity challenge triggering circuit, and a fingerprint adaptive update circuit. The RF fingerprint extraction circuit is implemented using a 512-point fully pipelined Fast Fourier Transform hardware accelerator and a feature extraction circuit, extracting three core physical layer features in real time: carrier frequency stability, modulation error vector amplitude, and phase noise. The fingerprint comparison circuit is implemented using a 16-bit parallel Euclidean distance calculation circuit and a comparator, calculating the deviation between the extracted features and the baseline features. The identity challenge triggering circuit is implemented using a 16-bit hardware comparator, with a preset deviation threshold of 3%. When the threshold is exceeded, an identity challenge trigger signal is immediately output, controlling the RF transceiver circuit to execute the corresponding filtering and re-authentication process. The fingerprint adaptive update circuit is implemented using a 16-bit fixed-coefficient multiplier and adder. After successful authentication, it performs a weighted average of historical features and current features according to a 7:3 weighting, and automatically writes the result back to the dynamic fingerprint area memory.

[0027] The working process of this embodiment is as follows: 1. During the solar array deployment initialization process, the timeout detection circuit monitors the deployment completion signal. If no completion signal is received after 30 seconds, the initialization is deemed to have failed, and the system immediately switches to the backup deployment mechanism. If all backup mechanisms fail, the current available power of the entire satellite is recalculated. When the available power is lower than the 5W survival threshold, the emergency control state machine automatically executes the emergency energy control procedure. 2. The single-particle lockout protection circuit monitors the output voltage change rate of each maximum power point tracking controller in real time. When the light intensity changes, if the output voltage change rate of a certain controller remains zero, it is determined to be a single-particle lockout. The power bus of that controller is immediately and physically cut off at one time, and the circuit seamlessly switches to the backup power channel. 3. The AI ​​self-test timer circuit automatically triggers self-testing every 10 minutes, sending 1024 sets of test vectors stored in the one-time programmable memory into the onboard intelligent accelerator in parallel. The inference results are compared bit by bit with the benchmark results to calculate the inference error rate. When the error rate exceeds the 0.1% threshold, the hardware direct memory access controller automatically loads the factory-stored simplified decision model and takes over the key decisions of the satellite's power management, thermal control management, and communication management. 4. The communication identity anti-spoofing charging circuit extracts the physical layer features of the received radio frequency signal in real time and compares them with the baseline fingerprint database embedded in the one-time programmable memory. When the feature deviation exceeds the 3% threshold, the identity questioning mode is automatically triggered: all non-urgent data packets are discarded, only data packets with urgent identifiers are responded to, and the re-authentication process is triggered at the same time. After each successful authentication, the radio frequency fingerprint features collected this time are weighted and averaged with the historical features of the dynamic fingerprint area in a 7:3 ratio, and the updated fingerprint is stored in the dynamic fingerprint area. Example

[0028] The difference between this embodiment and Embodiment 1 is that the parameters such as the number of stages, survival threshold, self-test cycle, error rate threshold, and deviation threshold of the backup deployment mechanism can all be configured through a one-time programmable fuse array before the chip leaves the factory. Once configured, it cannot be modified by software and can be adapted to different exploration missions and deep space exploration scenarios with different cycles.

Claims

1. A method for initializing and maintaining space artificial intelligence, characterized in that, Includes the following steps: When the energy system fails to initialize, it will automatically switch to the backup mechanism. When all backups fail and the available power is below the survival threshold, it will enter emergency energy control. Detect and bypass the power controller that has locked out; The deviation between the AI ​​inference results and the benchmark results is periodically detected, and a backup decision model is loaded when the deviation exceeds a threshold. The physical layer features of the received signal are extracted and compared with the fingerprint database. When the feature deviation exceeds the threshold, the identity questioning mode is entered.

2. A hardware supplementation system for space artificial intelligence initialization and self-maintenance, characterized in that, It includes an energy initialization fault reconstruction circuit, a single-event lockout protection circuit, an artificial intelligence self-test circuit, and a communication identity anti-fraud charging circuit; all processes of the system are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code execution; The energy initialization fault reconfiguration circuit is used to automatically switch to the backup mechanism when the energy system initialization fails and to enter emergency energy control when the available power is lower than the survival threshold. The single-particle lockout protection circuit is used to detect and bypass the power controller in the event of lockout. The artificial intelligence self-testing circuit is used to periodically detect the deviation between the artificial intelligence inference result and the benchmark result, and load the backup decision model when the deviation exceeds the threshold. The communication identity anti-spoofing charging circuit is used to extract the physical layer features of the received signal and compare them with the fingerprint database. When the feature deviation exceeds the threshold, it enters the identity questioning mode.

3. A hardware supplementary circuit for initialization and self-maintenance of space artificial intelligence, characterized in that, It includes a timeout detection circuit, a backup switching control circuit, a maximum available power recalculation circuit, a survival threshold comparison circuit, an emergency control state machine circuit, a maximum power point tracking output voltage change rate detection circuit, a power bus isolation circuit, an artificial intelligence self-test timer circuit, a test vector comparison circuit, an error rate threshold comparison circuit, a backup model loading circuit, an RF fingerprint extraction circuit, a fingerprint comparison circuit, and an identity challenge triggering circuit; all processes of the circuit are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code execution; The timeout detection circuit is used to output a failure signal if the unfolding signal is not received within a preset time. The backup switching control circuit is composed of a relay drive circuit, with its input terminal connected to the output terminal of the timeout detection circuit. It is used to immediately switch to the backup deployment mechanism after receiving a failure signal. The maximum available power recalculation circuit consists of an adder and a comparator. Its input is connected to the output of the backup switching control circuit. It is used to recalculate the current available power after all backups fail. The survival threshold comparison circuit has its input connected to the output of the maximum available power recalculation circuit, and is used to compare the available power with the survival threshold to output an emergency control trigger signal. The emergency control state machine circuit is implemented by a one-hot code state machine. Its input is connected to the output of the survival threshold comparison circuit and is used to execute the emergency energy control process after receiving a trigger signal. The maximum power point tracking output voltage change rate detection circuit consists of a differential circuit and a zero-crossing comparator. Its input is connected to the power controller output bus. It is used to detect the output voltage change rate when the illumination changes, and outputs a lock signal when the change rate is zero. The power bus isolation circuit is composed of solid-state relays. Its input terminal is connected to the lock signal output terminal, which is used to physically cut off the power bus of the maximum power point tracking controller in one go after receiving the lock signal. The artificial intelligence self-test timer circuit has its input terminal directly connected to the local hardware clock output terminal, which is used to trigger self-test according to a preset period. The test vector comparison circuit has its input end directly connected to the output end of the artificial intelligence accelerator and the output end of the benchmark test vector memory. It is used to compare the current inference result of the artificial intelligence accelerator with the benchmark result that is fixed at the factory and output the error rate. The error rate threshold comparison circuit has its input connected to the output of the test vector comparison circuit, and is used to compare the error rate with a preset threshold to output a degradation trigger signal. The backup model loading circuit consists of a direct memory access controller, with its input terminal connected to the degradation trigger signal output terminal. It is used to load a simplified decision model from the backup area of ​​the backup decision model after receiving the degradation trigger signal. The radio frequency fingerprint extraction circuit consists of a fast Fourier transform hardware accelerator and a feature extraction circuit. Its input is connected to the radio frequency receiving bus and is used to extract the physical layer features of the received signal. The fingerprint comparison circuit has its input end connected to the output end of the radio frequency fingerprint extraction circuit and the output end of the fingerprint database memory. It is used to compare the extracted features with the fingerprint database reference features one by one and output the deviation value. The identity verification trigger circuit has its input end connected to the output end of the fingerprint comparison circuit, and is used to compare the deviation value with a preset threshold to output an identity verification signal.

4. The method according to claim 1, characterized in that, The entry into emergency power control includes: shutting down all non-essential loads, sending a distress signal, cutting off the main system power, and entering deep sleep mode while retaining power only for the wake-up circuit; all processes of the method are executed automatically by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

5. The method according to claim 1, characterized in that, The power controller that detects and bypasses lockout includes: determining lockout when the output voltage change rate is zero when the light intensity changes, and immediately switching to the backup channel after physically disconnecting the power bus of the controller; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

6. The method according to claim 1, characterized in that, The periodic detection of AI inference result deviation includes: periodically sending the factory-fixed test vectors into the AI ​​accelerator for comparison with the factory-fixed benchmark results; if the error rate exceeds the threshold, the direct memory access controller loads a simplified decision model from the backup decision model area to take over key decisions for power management, thermal management, and communication management; the backup decision model area stores the factory-fixed simplified decision model, which uses an independent, unaccelerated, conservative inference path and does not rely on aging units; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

7. The method according to claim 1, characterized in that, The extraction of physical layer features of the received signal includes: extracting at least one of carrier frequency stability, modulation error vector amplitude, and phase noise features; the entry into identity verification mode includes: discarding all non-urgent data packets, responding only to data packets with an urgent identifier, and requiring the other party to re-authenticate; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

8. The method according to claim 1, characterized in that, The method further includes: after each successful authentication, the collected radio frequency fingerprint features are weighted and averaged with historical features, the updated fingerprint is stored in the dynamic fingerprint area, and the original baseline fingerprint is retained; all processes of the method are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

9. The circuit according to claim 3, characterized in that, The emergency control state machine circuit outputs the following signals in sequence: non-essential load shutdown signal, distress signal transmission enable signal, main system power cut-off signal, and deep sleep entry signal.

10. The circuit according to claim 3, characterized in that, It also includes a fingerprint adaptive update circuit, the input of which is connected to the output of the fingerprint comparison circuit and the authentication pass signal. This circuit is used to perform a weighted average of the extracted radio frequency fingerprint features and the historical features in the dynamic fingerprint area after each successful authentication and then write it back.