Emergency backstop and endgame decisions for artificial intelligence strategies

CN122802007APending Publication Date: 2026-09-22陈立波
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610524666.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-20
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

本发明的目的在于克服现有技术的上述不足,提供一种人工智能策略的紧急兜底与终末决策方法及系统,全流程通过纯硬件电路固化执行,无中央处理器、无指令执行、无软件代码运行,不依赖星载主系统的正常运行,解决现有软件实现的紧急兜底机制易受太空辐射干扰失效、响应延迟高、极端故障场景下无法正常工作的问题,实现致命故障下的硬件级紧急兜底与安全终末决策

Benefits of technology

1. 不依赖主系统运行,极端故障场景下可正常工作:本发明的所有流程均由独立的纯硬件电路实现,无需依赖星载主中央处理器、操作系统与主系统的正常运行,即使主系统因致命故障完全瘫痪,仍可正常执行紧急兜底与终末决策流程,为深空探测任务提供了可靠的硬件级安全兜底。

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The application discloses an emergency bottom-up and terminal decision method and system of an artificial intelligence strategy, belongs to the technical field of spaceborne artificial intelligence safety management and control, and aims to solve the problems that the existing spaceborne artificial intelligence system has no hardware-level emergency bottom-up mechanism, the fault protection realized by software is easy to be interfered with and invalidated by space radiation, and the equipment is easy to be out of control and the task data is easy to be lost under an extreme fault scene. The core method of the application comprises the following steps: when a hardware safety island detects a fatal fault, setting a strategy emergency stop register, broadcasting an emergency stop frame to all target chips, emptying a local strategy queue and zeroing a strategy input interface, and executing terminal decision after completing energy budget allocation. The whole process is automatically executed by a pure hardware circuit, no central processing unit is involved, no instruction is executed, and no software code is run, the hardware-level bottom-up capability under an extreme fault scene is achieved, and the core data safety and equipment safety of a deep space exploration task can be effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of spaceborne artificial intelligence safety management technology, specifically involving an emergency fallback and final decision-making method and system for artificial intelligence strategies. Background Technology

[0002] In deep space exploration missions, onboard systems may encounter fatal failures such as space debris impacts, extreme radiation shocks, and power system malfunctions, leading to main system paralysis and loss of control over artificial intelligence strategies. Currently, fault protection and emergency handling for onboard systems are mostly implemented in software, with the central processing unit running fault handling programs to complete emergency shutdowns and fallback operations.

[0003] However, in the extreme environment of space, cosmic rays and single-event effects can easily cause central processing unit failure and software program malfunction. When a fatal failure occurs, the emergency fallback mechanism implemented in the software often fails to function properly, unable to complete critical operations such as emergency strategy termination and core data protection, easily leading to equipment loss of control and permanent loss of core mission data. At the same time, the software-implemented fault response delay is relatively high, making it impossible to complete emergency fallback operations immediately after a fatal failure occurs, resulting in a high risk of fault propagation.

[0004] Currently, there is no fully hardware-based emergency backup and final decision-making solution for artificial intelligence strategies that do not rely on the main system, and therefore cannot meet the high reliability and safety backup requirements of deep space exploration missions under extreme failure scenarios. Summary of the Invention

[0005] 1. Technical problems to be solved The purpose of this invention is to overcome the above-mentioned shortcomings of the prior art and provide an emergency backup and final decision-making method and system for artificial intelligence strategies. The entire process is executed through pure hardware circuitry, without a central processing unit, instruction execution, or software code operation. It does not rely on the normal operation of the onboard main system and solves the problems of existing software-implemented emergency backup mechanisms being susceptible to space radiation interference, having high response delays, and being unable to work properly in extreme failure scenarios. It achieves hardware-level emergency backup and safe final decision-making in the event of a fatal failure.

[0006] 1. Technical Solution To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides an emergency fallback and final decision-making method for artificial intelligence strategies, comprising the following steps: When a fatal fault is detected by the hardware safety island, the policy emergency abort register is set; Broadcast an emergency abort frame to all target chips; Clear the local AI policy queue and force the AI ​​policy input interface to zero; Perform energy budget allocation; Implement final decisions.

[0007] Furthermore, the fault detection, emergency stop, and energy distribution processes are all automatically executed by pure hardware circuits without software intervention; the policy emergency stop register is also coupled to the authorized personnel intervention signal output terminal of the physical control console, and is automatically set when authorized personnel trigger a forced intervention signal.

[0008] Furthermore, the energy allocation is performed by pure hardware circuitry; the energy allocation includes: reading the current remaining energy, the real-time power consumption of each load, the estimated energy required for the single in-line package and the estimated energy required for sending the final farewell; the energy allocation priority for the single in-line package is higher than the farewell sending energy.

[0009] Furthermore, the method also includes: after sending the final decision request, the pure hardware circuit starts a hardware timer and waits for a preset time window. If a response is received from Earth within the window period, the Earth instruction is executed. If the timer expires and no response is received, the preset default selection is executed.

[0010] Furthermore, the fatal fault refers to a hardware failure that causes the system to malfunction, which is detected and output in real time by the hardware security island.

[0011] Furthermore, the entire process of fatal fault detection, emergency abort register setting, broadcast frame transmission, policy queue clearing, energy budget allocation, and final decision execution in the method is automatically executed by pure hardware circuitry in the order of steps described in claim 1, without the participation of software logic.

[0012] Furthermore, the priority order of the energy budget allocation is a fixed order that is fixed once at the chip factory and cannot be modified by software. The priority from high to low is as follows: power supply for the core wake-up circuit, data storage for the single-in-line package core, transmission of emergency distress signals, and finally, transmission of farewell data.

[0013] Secondly, the present invention provides an emergency fallback and final decision-making system for implementing the above-mentioned artificial intelligence strategy, characterized in that it includes a hardware safety island interface circuit, an emergency abort register circuit, a broadcast circuit, an energy budget allocation circuit, and a final decision execution circuit; the output terminal of the hardware safety island interface circuit is connected to the input terminal of the emergency abort register circuit, the output terminal of the emergency abort register circuit is connected to the input terminal of the broadcast circuit, the output terminal of the broadcast circuit is connected to the input terminal of the energy budget allocation circuit, and the output terminal of the energy budget allocation circuit is connected to the input terminal of the final decision execution circuit; all processes of the system are automatically executed by pure hardware circuits, without the participation of a central processing unit, without instruction execution, and without software code execution.

[0014] Furthermore, the emergency stop register circuit automatically sets and outputs an emergency stop trigger signal in pure hardware when the fault detection input is valid; the broadcast circuit has its input electrically connected to the emergency stop register circuit and sends an emergency stop frame to all target chips, including the local chip, when the trigger signal is valid; the energy budget allocation circuit includes a remaining energy input, a single-in-line package energy estimation input, and a goodbye transmission energy estimation input, and outputs energy allocation control signals in pure hardware according to a preset priority.

[0015] Furthermore, the final decision execution circuit includes a hardware timer, an Earth instruction receiver, and a preset default decision storage terminal. The pure hardware starts the timer after sending the final decision request. If a response is received from Earth within the window period, the Earth instruction is executed. If no response is received within the window period, the preset default selection is executed.

[0016] 1. Beneficial effects Compared with the prior art, the present invention has the following advantages: 1. It does not rely on the main system to operate and can work normally under extreme failure scenarios: All processes of this invention are implemented by independent pure hardware circuits, without relying on the normal operation of the onboard main central processor, operating system and main system. Even if the main system is completely paralyzed due to a fatal failure, it can still perform emergency backup and final decision-making processes normally, providing a reliable hardware-level safety backup for deep space exploration missions.

[0017] 2. The entire process is executed purely in hardware, with strong anti-interference capabilities and fast response speed: All fault detection, emergency stop, energy allocation and decision execution processes in this invention are implemented by pure hardware circuits, which are not easily affected by cosmic rays or single-event effects, and will not cause problems such as program crashes or processing logic failures; at the same time, all operations are executed in parallel hardware, which greatly reduces response latency and can complete the emergency stop of the strategy at the first time after a fatal failure occurs, avoiding the spread of faults and equipment loss of control.

[0018] 3. Possesses hardware-level policy abort capability, completely avoiding the risk of loss of control: When a fatal fault is detected, this invention can immediately set the emergency abort register through pure hardware circuitry, broadcast an emergency abort frame, clear the local policy queue, and force the policy input interface to be zeroed, thus completely blocking the execution of all artificial intelligence policies at the hardware level, without the risk of loss of control due to the continued execution of policies in software solutions.

[0019] 4. Possesses the ability to allocate energy budgets with fixed priorities to ensure the completion of core tasks: This invention completes energy budget allocation through pure hardware circuitry. The allocation priority is fixed once at the chip factory and cannot be modified by software. It can prioritize the energy supply for core terminal tasks such as single-in-line package, core data storage, and critical distress signal transmission, avoiding the permanent loss of core task data in the event of extreme failures and preserving the results of the exploration mission to the greatest extent.

[0020] 5. Possesses dual trigger modes and autonomous terminal decision-making capabilities, with strong adaptability: This invention supports two modes: automatic triggering due to hardware safety island failure and mandatory intervention triggering by authorized personnel, which can adapt to different emergency scenarios; at the same time, through hardware timers and preset default decisions, it can complete autonomous terminal decisions in extreme scenarios without ground response, without ground intervention, and is suitable for the use scenarios of ultra-long communication delays in deep space exploration. Detailed Implementation

[0021] The present invention will be further described in detail below with reference to specific embodiments. Those skilled in the art can implement the technical solutions of the present invention, solve corresponding technical problems, and achieve the intended technical effects based on the content disclosed in these embodiments.

[0022] All circuits in this embodiment are designed using radiation-hardened complementary metal-oxide-semiconductor (CMOS) technology, adapting to the total dose radiation and single-event effect protection requirements of the space on-orbit environment. They are pure hardware safety circuits independent of the main onboard system, and can be powered on and run independently without the participation of the main central processing unit. All circuits are implemented using pure digital logic circuits, without embedded processors, instruction sets, or software code storage and execution units. Energy allocation priority, default decisions, and time window parameters are all fixed by a one-time programmable fuse array during chip manufacturing and cannot be modified by software. Example 1

[0023] This embodiment provides an emergency fallback and final decision-making system for artificial intelligence strategies, including a hardware safety island interface circuit, an emergency abort register circuit, a broadcast circuit, an energy budget allocation circuit, and a final decision execution circuit. The output of the hardware safety island interface circuit is connected to the input of the emergency abort register circuit, the output of the emergency abort register circuit is connected to the input of the broadcast circuit, the output of the broadcast circuit is connected to the input of the energy budget allocation circuit, and the output of the energy budget allocation circuit is connected to the input of the final decision execution circuit. All processes of the system are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

[0024] The emergency stop register circuit is implemented using an irreversible latch register with a hardware set terminal. The fault detection input terminal is connected to the fatal fault output terminal of the hardware safety island and the authorized personnel intervention signal output terminal of the physical control console. When the hardware safety island detects a fatal fault or an authorized personnel triggers a forced intervention signal, the register is automatically set by pure hardware and an emergency stop trigger signal is output. Once the register is set, it cannot be reset by software and can only be reset by ground physical authorization signals.

[0025] The broadcast circuit is implemented using a satellite bus hardware interface. The input is electrically connected to the emergency stop register circuit. When the emergency stop trigger signal is valid, it automatically broadcasts an emergency stop frame to all target chips in the cluster, including the local chip, to notify all nodes to stop executing the artificial intelligence strategy.

[0026] The local policy control circuit has its input end connected to the emergency stop trigger signal output end. When the trigger signal is valid, the pure hardware immediately clears all the stored contents of the local artificial intelligence policy queue, and at the same time forces the artificial intelligence policy input interface to be pulled low to zero, thus blocking the input of all new policies and the execution of old policies from the hardware level.

[0027] The energy budget allocation circuit includes a 32-bit hardware adder, comparator, and priority sorting logic. It has a remaining energy input terminal, a single-in-line package (SIIP) energy estimation input terminal, a farewell transmission energy estimation input terminal, and a core wake-up circuit power consumption input terminal. The pure hardware completes the energy allocation according to the factory-fixed priority order, with the priority from high to low as follows: core wake-up circuit power supply, SIIP core data storage, emergency distress signal transmission, and finally farewell data transmission, ensuring reliable storage of core task data under extreme failure conditions.

[0028] The final decision execution circuit includes a 32-bit hardware timer, an Earth command receiver, and a preset default decision storage terminal. After the energy budget allocation is completed, the pure hardware sends a final decision request to the Earth terminal and starts the hardware timer at the same time, with a preset time window of 72 hours. If a reply instruction is received from the Earth terminal within the window period, the final operation is executed according to the Earth command. If the timer expires and no reply is received from the Earth terminal, the factory-fixed preset default decision is automatically loaded and executed. The default decisions include core data single-row through-hole packaging, cyclic transmission of emergency distress signals, power-off of unnecessary loads, and low-power monitoring of the core wake-up circuit.

[0029] The working process of this embodiment is as follows: 1. The hardware safety island monitors the operating status of the onboard system in real time. When a fatal fault is detected, it outputs a valid fault signal to the emergency abort register circuit through the hardware safety island interface circuit. 2. The emergency stop register circuit is automatically set by pure hardware and outputs an emergency stop trigger signal. At the same time, the broadcast circuit broadcasts an emergency stop frame to all target chips. 3. When the trigger signal is valid, the hardware immediately clears the local AI policy queue and forces the AI ​​policy input interface to zero, completely blocking the execution of all policies; 4. The energy budget allocation circuit reads the current remaining energy and the estimated energy consumption of each task in pure hardware, and completes the energy budget allocation according to the fixed priority order; 5. The final decision execution circuit sends a final decision request to the Earth end and starts a hardware timer at the same time; 6. If a response is received from Earth within the 72-hour window, the terminal operations will be executed according to Earth's instructions; if no response is received after the timeout, the factory-set default decision will be executed, completing terminal operations such as core data encapsulation, emergency distress transmission, and low-power monitoring. Example 2

[0030] The difference between this embodiment and Embodiment 1 is that the final decision execution circuit also includes a black box trigger circuit. When the emergency stop trigger signal is valid, the pure hardware immediately triggers the key data solidification operation of the onboard black box, writing the system state and mission data before the failure into a non-volatile radiation-resistant memory at once, further ensuring the security of the core mission data. Even if the equipment fails completely, the key detection data can still be retained through the black box.

Claims

1. An emergency fallback and final decision-making method for artificial intelligence strategies, characterized in that, Includes the following steps: When a fatal fault is detected by the hardware safety island, the policy emergency abort register is set; Broadcast an emergency abort frame to all target chips; Clear the local AI policy queue and force the AI ​​policy input interface to zero; Perform energy budget allocation; Implement final decisions.

2. An emergency fallback and final decision-making system for implementing the artificial intelligence strategy of claim 1, characterized in that, The system includes a hardware safety island interface circuit, an emergency abort register circuit, a broadcast circuit, an energy budget allocation circuit, and a final decision execution circuit. The output of the hardware safety island interface circuit is connected to the input of the emergency abort register circuit, the output of the emergency abort register circuit is connected to the input of the broadcast circuit, the output of the broadcast circuit is connected to the input of the energy budget allocation circuit, and the output of the energy budget allocation circuit is connected to the input of the final decision execution circuit. All processes of the system are automatically executed by pure hardware circuits, without the participation of a central processing unit, instruction execution, or software code execution.

3. The system according to claim 2, characterized in that, The emergency abort register circuit automatically sets the fault detection input and outputs an emergency abort trigger signal in pure hardware when the fault detection input is valid; the broadcast circuit has its input electrically connected to the emergency abort register circuit and sends an emergency abort frame to all target chips, including the local chip, when the trigger signal is valid. The energy budget allocation circuit includes a remaining energy input terminal, a single-in-line package energy estimation input terminal, and a goodbye transmission energy estimation input terminal, and outputs energy allocation control signals in pure hardware according to preset priorities.

4. The method according to claim 1, characterized in that, The fault detection, emergency stop, and energy allocation processes are all executed automatically by pure hardware circuits without software intervention; the policy emergency stop register is also coupled to the authorized personnel intervention signal output terminal of the physical control console, and is automatically set when authorized personnel trigger a forced intervention signal.

5. The method according to claim 1, characterized in that, The energy distribution is performed by pure hardware circuitry; Energy allocation includes: reading the current remaining energy, the real-time power consumption of each load, the estimated energy required for single-in-line package and the estimated energy required for sending the final farewell; the energy allocation priority for single-in-line package is higher than the energy for farewell transmission.

6. The method according to claim 1, characterized in that, Also includes: After sending the final decision request, the hardware circuit starts a hardware timer and waits for a preset time window. If a response is received from Earth within the window, the Earth's instructions are executed. If the timer expires and no response is received, the preset default selection is executed.

7. The method according to claim 1, characterized in that, The fatal fault refers to a hardware failure that causes the system to malfunction, which is detected and output in real time by the hardware security island.

8. The system according to claim 2, characterized in that, The final decision execution circuit includes a hardware timer, an Earth command receiver, and a preset default decision storage terminal. The pure hardware starts the timer after sending the final decision request. If a response is received from Earth within the window period, the Earth command is executed. If no response is received within the window period, the preset default selection is executed.

9. The method according to claim 1, characterized in that, The entire process of fatal fault detection, emergency abort register setting, broadcast frame transmission, policy queue clearing, energy budget allocation, and final decision execution in the method is automatically executed by pure hardware circuitry in the order of steps described in claim 1, without the participation of software logic.

10. The method according to claim 1, characterized in that, The priority order of the energy budget allocation is a fixed order that is fixed once at the chip factory and cannot be modified by software. The priority from high to low is: power supply for the core wake-up circuit, data storage for the single-in-line package core, transmission of emergency distress signals, and finally, transmission of farewell data.