Space-based quasi-judicial adjudication method and apparatus
Patent Information
- Application Number
- CN202511892134.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-12-10
- Filing Date
- 2025-12-16
- Publication Date
- 2026-09-25
AI Technical Summary
然而, 在天基场景下,容易由于星间链路的特点,造成用于地面场景下的基于冗余的拟态裁决机制因超时而导致瞬间失效:(1)星间链路的丢包率常高于20%,以3副本的冗余计算,平均仅收2.3份,无法满足K=3门限,裁决器收不到足够的副本将会一直等待,导致整网频繁超时重传陷入“响应停滞”,固定超时既忽视传播时延又忽略重传代价,结果空等失效报文或过早丢弃有效票,双倍浪费星上能源;(2)当裁定平局无多数派时缺乏后续判别策略,只能重新调度或等待超时,任务延迟进一步增加;(3)星上没有即时清洗机制,异常执行体需数小时后由地面回注隔离指令,期间继续参与任务,错误输出持续扩散
[0017]本发明的有益效果是:本发明提供的天基拟态裁决方法和装置,针对高动态星间链路“高丢包、长时延、资源受限”导致的响应停滞与误判问题,结合实时丢包状态、传播-处理-重传代价和结果分组差异,采用链路自适应的星载拟态裁决框架,通过对星间链路丢包率进行动态建模,实现执行体副本数依据链路状态调整、超时阈值参考传播代价设定,同时通过星上隔离机制抑制执行体故障与潜在协同攻击带来的错误扩散,在天基场景下实现低冗余、高成功、自愈的一致性计算,可降低能源与带宽开销,提高裁决成功率并缩短任务中断时间。用于星上分布式安全关键任务的容错判决。
Smart Images

Figure CN122824418A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of satellite network security technology, and in particular to a space-based mimicry adjudication method and apparatus. Background Technology
[0002] Mimicry defense is a fault-tolerant technique based on heterogeneous redundancy. Under the same input, multiple hardware or software modules with different structures but identical functions (called heterogeneous executors) are deployed and run in parallel. Their outputs are compared through an adjudication mechanism, and the result with the majority agreement is taken as the final system conclusion. Mimicry adjudication is based on the axiom of large numbers. Due to the significant differences in the internal structure of each executor, design flaws or targeted attacks are unlikely to simultaneously affect most modules, so the correct outputs account for the majority, thus suppressing common-cause failures and improving system reliability. Mimicry adjudication is the core comparison step in the above process: by collecting the outputs of all heterogeneous executors, if the number of a certain output exceeds half of the total number of executors, that output is directly adopted. This mechanism can quickly identify outliers, shield against transient errors or malicious results caused by attacks on individual nodes, and ensure the consistency and availability of distributed computing.
[0003] With the rapid development of low-Earth orbit satellite internet (such as Starlink, OneWeb, and Hongyan constellation), satellite networks have become an important part of the global information infrastructure. However, due to the limited satellite node resources, inter-satellite links (ISL) use wireless laser or millimeter-wave communication, which has characteristics such as high dynamism, high propagation delay, and significant fluctuations in asymmetric packet loss rate.
[0004] Currently, for terrestrial links, mimicry adjudication typically employs a "fixed redundancy combined with ground-based majority voting" model. Due to stable latency and relatively constant redundancy, redundant copies can generally all return on time. Timeout thresholds can be pre-defined for long-term use, and the adjudication logic only requires counting and majority comparison, making implementation simple and reducing computational and storage overhead. This approach maintains a low false positive rate in stable networks such as data centers and industrial control systems. However, in the space-based scenario, due to the characteristics of inter-satellite links, the redundancy-based mimicry adjudication mechanism used in the ground scenario is prone to instantaneous failure due to timeout: (1) The packet loss rate of inter-satellite links is often higher than 20%. With 3 copies of redundancy, only 2.3 copies are received on average, which cannot meet the K=3 threshold. The adjudicator will not receive enough copies and will keep waiting, resulting in frequent timeouts and retransmissions of the entire network, falling into "response stagnation". Fixed timeout ignores both the propagation delay and the cost of retransmission. As a result, it waits for invalid messages or discards valid tickets too early, wasting twice the space-based energy; (2) When the adjudication is a tie with no majority, there is no subsequent judgment strategy. It can only be rescheduled or wait for timeout, which further increases the task delay; (3) There is no immediate cleaning mechanism on the satellite. Abnormal execution entities need to be injected with isolation instructions from the ground several hours later. During this period, they continue to participate in the task, and the error output continues to spread.
[0005] Therefore, there is an urgent need for a novel mimicry defense adjudication method that adapts to the characteristics of highly dynamic inter-satellite links and takes into account high reliability, low redundancy, and latency tolerance, in order to solve the problems of "response stagnation" and "misjudgment" in satellite networks and improve the security resilience of space-based systems. Summary of the Invention
[0006] In order to solve the problems existing in the prior art, the present invention provides the following technical solution.
[0007] The first aspect of this invention provides a space-based mimicry adjudication method, comprising: The redundancy of the execution unit is determined based on the link packet loss rate and the number of votes expected to be returned by the execution unit. The timeout threshold is determined based on the longest onboard processing time and the longest Starlink propagation time. Within the timeout threshold period, collect the votes for the results returned by the executor. If the number of votes collected reaches the expected number of votes, put the votes with the same result into the same group and determine whether the number of votes in each group exceeds half. If so, output the result corresponding to the group with the most votes as the decision result. Otherwise, select the two groups with the smallest difference and output the result corresponding to the group with the most votes as the decision result. If the number of votes collected does not reach the expected number of votes, add the candidate executor to the executor pool and start secondary scheduling.
[0008] Preferably, determining the redundancy of the execution entity based on the link packet loss rate and the number of votes for the expected return result includes: Based on the initial number of scheduled executors, determine the number of votes required for the expected executor to return a result that meets the preset value; Based on the fact that the link packet loss rate is negatively correlated with the redundancy of the executor, and that the number of votes expected to be returned by the executor is positively correlated with the redundancy of the executor, the redundancy of the executor is calculated. If the calculated redundancy of the executor is less than the number of initially scheduled executors, then the number of initially scheduled executors is used as the final redundancy of the executor; otherwise, the calculated redundancy of the executor is used as the final redundancy of the executor.
[0009] Preferably, determining the timeout threshold based on the longest on-board processing time and the longest Starlink propagation time includes: Calculate the longest processing time on the satellite based on the maximum latency of a single processing cycle and the upper limit of processing jitter. Calculate the longest Starlink propagation time based on the redundancy overhead multiple and the average propagation waiting time. The larger of the longest on-board processing time and the longest Starlink propagation time is selected as the timeout threshold.
[0010] Preferably, the method further includes: After each round of adjudication, the enforcement body is updated according to the following formula. fractions : , , like Then the on-board scheduler will execute the body Remove from the execution pool; in, , It is an empirical constant. For the ruling, For the execution body The returned result This is the cleaning threshold.
[0011] Preferably, the method further includes: If, during secondary scheduling, the number of votes collected within the timeout threshold period does not reach the expected number of votes, a "link unreachable" report is sent to the upper layer.
[0012] A second aspect of the present invention provides a space-based mimicry adjudication device, comprising: The redundancy determination module is used to determine the redundancy of the execution unit based on the link packet loss rate and the number of votes for the expected return result of the execution unit; The timeout threshold determination module is used to determine the timeout threshold based on the longest on-board processing time and the longest Starlink propagation time. The decision determination module is used to collect the votes for the results returned by the executor within the current timeout threshold period. If the number of votes collected reaches the expected number of votes, the votes with the same result are placed in the same group, and it is determined whether the number of votes in each group exceeds half. If so, the result corresponding to the group with the most votes is output as the decision result. Otherwise, the two groups with the smallest difference are selected, and the result corresponding to the group with the most votes is output as the decision result. If the number of votes collected does not reach the expected number of votes, the candidate executor is added to the executor pool, and secondary scheduling is initiated.
[0013] Preferably, the redundancy determination module is used for: Based on the initial number of scheduled executors, determine the number of votes required for the expected executor to return a result that meets the preset value; Based on the fact that the link packet loss rate is negatively correlated with the redundancy of the executor, and that the number of votes expected to be returned by the executor is positively correlated with the redundancy of the executor, the redundancy of the executor is calculated. If the calculated redundancy of the executor is less than the number of initially scheduled executors, then the number of initially scheduled executors is used as the final redundancy of the executor; otherwise, the calculated redundancy of the executor is used as the final redundancy of the executor.
[0014] Preferably, the timeout threshold determination module is used for: Calculate the longest processing time on the satellite based on the maximum latency of a single processing cycle and the upper limit of processing jitter. Calculate the longest Starlink propagation time based on the redundancy overhead multiple and the average propagation waiting time. The larger of the longest on-board processing time and the longest Starlink propagation time is selected as the timeout threshold.
[0015] Preferably, the apparatus further includes an execution pool update module, used for: After each round of adjudication, the enforcement body is updated according to the following formula. fractions : , , like Then the on-board scheduler will execute the body Remove from the execution pool; in, , It is an empirical constant. For the ruling, For the execution body The returned result This is the cleaning threshold.
[0016] Preferably, the device further includes a secondary scheduling module, used for: If, during secondary scheduling, the number of votes collected within the timeout threshold period does not reach the expected number of votes, a "link unreachable" report is sent to the upper layer.
[0017] The beneficial effects of this invention are as follows: The space-based mimicry adjudication method and apparatus provided by this invention address the response stagnation and misjudgment problems caused by "high packet loss, long latency, and resource constraints" in highly dynamic inter-satellite links. Combining real-time packet loss status, propagation-processing-retransmission costs, and result grouping differences, it adopts a link-adaptive spaceborne mimicry adjudication framework. By dynamically modeling the inter-satellite link packet loss rate, it adjusts the number of replicas of the execution unit based on the link status and sets the timeout threshold based on the propagation cost. Simultaneously, it suppresses the error propagation caused by execution unit failures and potential coordinated attacks through on-board isolation mechanisms. This achieves low-redundancy, high-success, and self-healing consistent computation in space-based scenarios, reducing energy and bandwidth consumption, improving adjudication success rate, and shortening mission downtime. It is used for fault-tolerant adjudication of on-board distributed security-critical missions. Attached Figure Description
[0018] Figure 1 This is a schematic flowchart of the space-based mimicry adjudication method described in this invention; Figure 2 This is a schematic diagram of the functional structure of the space-based mimicry adjudication device described in this invention. Detailed Implementation
[0019] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0020] The method provided by this invention can be implemented in a terminal environment that may include one or more of the following components: a processor, a memory, and a display screen. The memory stores at least one instruction, which is loaded and executed by the processor to implement the method described in the following embodiments.
[0021] A processor may include one or more processing cores. The processor uses various interfaces and lines to connect various parts of the terminal, and performs various functions and processes data by running or executing instructions, programs, code sets or instruction sets stored in memory, and by calling data stored in memory.
[0022] Memory can include random access memory (RAM) or read-only memory (ROM). Memory can be used to store instructions, programs, code, code sets, or instructions.
[0023] The display screen is used to show the user interface of each application.
[0024] In addition, those skilled in the art will understand that the structure of the terminal described above does not constitute a limitation on the terminal. The terminal may include more or fewer components, or combine certain components, or have different component arrangements. For example, the terminal may also include radio frequency circuits, input units, sensors, audio circuits, power supplies, and other components, which will not be described in detail here.
[0025] To address the problems existing in related technologies, this invention proposes a space-based mimicry adjudication method based on joint estimation of link state, latency cost, and result similarity weighting. By adjusting the replica size, waiting window, and ticket selection rules as needed, and by isolating inconsistent nodes on the satellite in real time, it can reduce idle waiting and retransmission, shorten the average latency, and block the spread of errors, thereby achieving low redundancy, high success rate, and rapid self-healing adjudication in space-based scenarios.
[0026] This method can be applied to scenarios such as low-Earth orbit satellite constellations, inter-satellite collaborative computing, and space-based distributed security systems. It is suitable for inter-satellite link environments with high dynamics, high latency, and high packet loss. The output results of heterogeneous executors in the mimicry defense system have high reliability, low redundancy, and latency tolerance consistency, which can improve the availability, reliability, and security of the system under harsh space communication conditions.
[0027] Example 1 like Figure 1 As shown, this embodiment of the invention provides a space-based mimicry adjudication method, which may include the following steps: S101, determine the redundancy of the execution unit based on the link packet loss rate and the expected number of votes for the execution unit's return results. The redundancy of the execution unit can be understood as the total number of execution unit replicas that need to be sent. In this embodiment of the invention, dynamic redundancy can be calculated, dynamically increasing the number of execution unit replicas based on the real-time estimated link packet loss rate, so that the number of votes for the execution unit's return results can reach the expected number of votes for the execution unit's return results, thereby ensuring that the required number of votes for the execution unit's return results can still be collected with a high probability even under link fluctuations.
[0028] S102, based on the longest onboard processing time and the longest Starlink propagation time, determines the timeout threshold. The timeout threshold can be understood as the longest time the arbiter waits to receive the result from the returning executor in this round of scheduling. If the timeout occurs, the received results that do not meet the expected number of votes will be discarded and a rescheduling will be triggered.
[0029] S103: Collect the votes for the results returned by the executor within the timeout threshold period. If the number of votes collected reaches the expected number of votes, put the votes with the same result into the same group and determine whether the number of votes in each group exceeds half. If so, output the result corresponding to the group with the most votes as the decision result. Otherwise, select the two groups with the smallest difference and output the result corresponding to the group with the most votes as the decision result. If the number of votes collected does not reach the expected number of votes, add the candidate executor to the executor pool and start secondary scheduling.
[0030] During the results collection phase, a time period equal to a timeout threshold is set. Within this time period, the votes for the results returned by the executor are collected. When the number of collected votes first reaches the expected number or the timeout threshold is reached, the collection of votes for the results returned by the executor immediately stops, and the process proceeds to the next decision-making phase. In the decision-making phase, if any group receives more than half the votes, a "majority" group is considered to exist. The votes of all "majority" groups are compared, and the result corresponding to the group with the most votes is taken as the final decision, i.e., decided according to the "majority". Conversely, if no group receives more than half the votes, a "majority" group is considered not to exist. The two groups with the smallest similarity are then selected, and the result corresponding to the group with the most votes is taken as the final decision. In other words, vote selection is based on similarity metrics.
[0031] The order of steps S101 and S102 can be interchanged.
[0032] In one embodiment of the present invention, determining the redundancy of an execution entity based on the link packet loss rate and the number of votes for the expected return result of the execution entity may include the following steps: Based on the initial number of scheduled executors, determine the number of votes required for the expected executor to return a result that meets the preset value; Based on the fact that the link packet loss rate is negatively correlated with the redundancy of the executor, and that the number of votes expected to be returned by the executor is positively correlated with the redundancy of the executor, the redundancy of the executor is calculated. If the calculated redundancy of the executor is less than the number of initially scheduled executors, then the number of initially scheduled executors is used as the final redundancy of the executor; otherwise, the calculated redundancy of the executor is used as the final redundancy of the executor.
[0033] In this embodiment of the invention, as an example, it can be implemented in the following manner: Assuming the inter-satellite link propagation delay follows a uniform distribution and the packet loss rate follows a Markov chain, then 1) Estimated packet loss rate based on real-time onboard measurements ∈[0,1], the number of votes for the expected result returned by the executor is determined according to the following formula. Or, the minimum number of valid results: , in, The number of execution entities for this task is determined by the scheduling algorithm, which is also the initial number of copies of the scheduled execution entities. This indicates rounding up to the nearest integer.
[0034] 2) To ensure that the number of successfully received messages is no less than [amount missing] Calculate the total number of executable copies to be sent. : , The total number of execution bodies is calculated after taking into account the requirements of link status and the threshold for the number of adjudications. This indicates rounding up, and If the calculation yields Then take Ensure that the initial scheduling constraints are met; otherwise, proceed according to... The scheduling task is issued.
[0035] Through the above dynamic redundancy calculation, the system can automatically generate more execution unit replicas when the packet loss environment deteriorates, and avoid excessive redundancy when the link is good, thus achieving a success rate of ≥ 100% in successfully received votes. Minimum overhead guarantee.
[0036] In this embodiment of the invention, determining the timeout threshold based on the longest on-board processing time and the longest Starlink propagation time may include the following steps: Calculate the longest processing time on the satellite based on the maximum latency of a single processing cycle and the upper limit of processing jitter. Calculate the longest Starlink propagation time based on the redundancy overhead multiple and the average propagation waiting time. The larger of the longest on-board processing time and the longest Starlink propagation time is selected as the timeout threshold.
[0037] In this embodiment of the invention, as an example, the timeout threshold is determined jointly by the propagation delay and the packet loss rate, and can be calculated using the following formula: , The meanings of the symbols in this formula are as follows: Maximum latency for a single processing operation (e.g., encoding / decoding, queue buffering, protocol stack processing), in seconds; The physical delay of a signal propagating through a hardware link (such as the delay of light propagation in an optical fiber), in seconds; : Link packet loss rate, ranging from [0,1]; : Indicates the average total propagation latency. On average, it takes 1 / (...) to successfully deliver one packet. Each transmission requires a one-way propagation delay. Therefore, the average total propagation wait time is The unit is seconds; Treat the local processing latency of the execution unit as a Gaussian distribution. To encompass the slowest node that is still within the statistical range, in Leave in addition The margin, therefore, is used as " "As the upper limit of jitter in the pure processing stage, equal The unit is seconds; Redundant data added to mitigate packet loss or error correction, measured in bits or bytes; : The original data volume, in bits or bytes; : The redundancy overhead introduced to combat packet loss. It can cover the slowest processing time on the satellite plus 95% of the processing jitter, ensuring that extreme values of the "local link" are also covered. This represents the average total time for each "link segment". and The maximum value in the timeout threshold ensures that the arbiter's waiting time covers at least the longer of the "local slowest" and "link heaviest" cases, thus preventing the premature discarding of valid results or the indefinite waiting for invalid messages.
[0038] In an embodiment of the present invention, as an example, the results collection and adjudication can be implemented in the following manner.
[0039] 1) Results Collection The results collection phase begins with a duration of [duration missing]. The timing and initialization of the counter. Each time a result that passes the integrity check is received , Increase by 1, For the first The result returned by the executor ). and according to The value is assigned to the corresponding result group. When valid is first reached ( (or timer reaches) If this happens, immediately stop accepting packages and proceed to the adjudication stage.
[0040] 2) Swift adjudication Received The results are compared element by element, and those with the same content are grouped together to obtain a set. ={ There are a total of m groups, among which ={ }, .make , like Direct output If the result is satisfactory, the decision is finalized; otherwise, the voting phase begins.
[0041] 3) Ticket selection stage For any two groups , ≠ Calculate its normalized variance: , Select the two groups with the smallest differences:
[0042] Select the result corresponding to the group with the most votes from the two groups as the final output: , Decision Maker Release The representative results are selected, and the remaining groups are marked as suspicious, and then proceed to the error cleaning process.
[0043] In one embodiment of the present invention, the space-based mimicry adjudication method may further include the following steps: After each round of adjudication, the enforcement body is updated according to the following formula. fractions : , , like Then the on-board scheduler will execute the body Remove from the execution pool; in, , It is an empirical constant. For the ruling, For the execution body The returned result This is the cleaning threshold.
[0044] Using the above method, on-board error cleaning can be achieved.
[0045] In one embodiment of the present invention, when the timer reaches the timeout threshold and the number of votes returned by the collected executors does not reach the expected number of votes, a secondary scheduling is initiated. Backup executors are added to the executor selection set to expand the candidate pool, and the instantaneous packet loss rate is re-estimated. Calculate the new number of replicas: , according to Select the node, re-copy and distribute the task, and return to the "Result Collection" step. If two consecutive scheduling attempts still fail to meet the requirements... The system reports "link unreachable" to the upper level, and the constellation management unit decides whether to downgrade the output or switch the inter-satellite path to ensure business continuity.
[0046] Example 2 like Figure 2 As shown, another aspect of the present invention also includes a functional module architecture that is completely consistent with the aforementioned method flow. That is, the embodiments of the present invention also provide a space-based mimicry adjudication device, including: The redundancy determination module 201 is used to determine the redundancy of the execution unit based on the link packet loss rate and the number of votes for the expected return result of the execution unit; The timeout threshold determination module 202 is used to determine the timeout threshold based on the longest on-board processing time and the longest Starlink propagation time. The decision determination module 203 is used to collect the votes of the results returned by the executor within the current timeout threshold period. If the number of votes collected reaches the expected number of votes, the votes with the same result are placed in the same group, and it is determined whether the number of votes in each group exceeds half. If so, the result corresponding to the group with the most votes is output as the decision result. Otherwise, the two groups with the smallest difference are selected, and the result corresponding to the group with the most votes is output as the decision result. If the number of votes collected does not reach the expected number of votes, the candidate executor is added to the executor pool and secondary scheduling is initiated.
[0047] Furthermore, the redundancy determination module is used to: determine the number of votes for the expected execution body return results that reach a preset value based on the number of initial scheduled execution bodies; calculate the redundancy of the execution body according to the fact that the link packet loss rate is negatively correlated with the redundancy of the execution body, and the number of votes for the expected execution body return results is positively correlated with the redundancy of the execution body; if the calculated redundancy of the execution body is less than the number of initial scheduled execution bodies, then the number of initial scheduled execution bodies is used as the final redundancy of the execution body; otherwise, the calculated redundancy of the execution body is used as the final redundancy of the execution body.
[0048] Furthermore, the timeout threshold determination module is used to: calculate the longest on-board processing time based on the maximum latency of a single on-board processing and the upper limit of processing jitter; calculate the longest Starlink propagation time based on the redundancy overhead multiple and the average propagation waiting time; and select the larger of the longest on-board processing time and the longest Starlink propagation time as the timeout threshold.
[0049] Furthermore, the space-based mimicry adjudication device provided by the present invention may further include an execution pool update module, used to: update the execution pool according to the following formula after each round of adjudication. fractions : , , like Then the on-board scheduler will execute the body Remove from the execution pool; in, , It is an empirical constant. For the ruling, For the execution body The returned result This is the cleaning threshold.
[0050] Furthermore, the space-based mimicry adjudication device provided by the present invention may also include a secondary scheduling module, used to: if the number of votes collected within the timeout threshold period in the secondary scheduling does not reach the expected number of votes, report "link unreachable" to the upper layer.
[0051] The device can be implemented using the space-based mimicry adjudication method provided in Embodiment 1 above. For the specific implementation method, please refer to the description in Embodiment 1, which will not be repeated here.
[0052] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention. Clearly, those skilled in the art can make various alterations and modifications to the invention without departing from its spirit and scope. Thus, if these modifications and modifications of the invention fall within the scope of the claims and their equivalents, the invention is also intended to include these modifications and modifications.
Claims
1. A space-based mimicry adjudication method, characterized in that, include: The redundancy of the execution unit is determined based on the link packet loss rate and the number of votes expected to be returned by the execution unit. Determine the timeout threshold based on the longest onboard processing time and the longest Starlink propagation time. Within the timeout threshold period, collect the number of votes returned by the executor. If the number of votes collected reaches the expected number of votes, put the votes with the same result into the same group and determine whether the number of votes in each group exceeds half. If so, output the result corresponding to the group with the most votes as the adjudication result. Otherwise, select the two groups with the smallest difference and output the result corresponding to the group with the most votes as the adjudication result. If the number of votes collected does not reach the expected number of votes, the candidate executor will be added to the executor pool, and secondary scheduling will be initiated.
2. The space-based mimicry adjudication method as described in claim 1, characterized in that, The determination of the redundancy of the execution unit based on the link packet loss rate and the number of votes for the expected return result of the execution unit includes: Based on the initial number of scheduled executors, determine the number of votes required for the expected executor to return a result that meets the preset value; Based on the fact that the link packet loss rate is negatively correlated with the redundancy of the executor, and that the number of votes expected to be returned by the executor is positively correlated with the redundancy of the executor, the redundancy of the executor is calculated. If the calculated redundancy of the executor is less than the number of initially scheduled executors, then the number of initially scheduled executors is used as the final redundancy of the executor; otherwise, the calculated redundancy of the executor is used as the final redundancy of the executor.
3. The space-based mimicry adjudication method as described in claim 1, characterized in that, The determination of the timeout threshold based on the longest on-board processing time and the longest Starlink propagation time includes: Calculate the longest processing time on the satellite based on the maximum latency of a single processing cycle and the upper limit of processing jitter. Calculate the longest Starlink propagation time based on the redundancy overhead multiple and the average propagation waiting time. The larger of the longest on-board processing time and the longest Starlink propagation time is selected as the timeout threshold.
4. The space-based mimicry adjudication method as described in claim 1, characterized in that, The method further includes: After each round of adjudication, the enforcement body is updated according to the following formula. fractions : , , like Then the on-board scheduler will execute the body Remove from the execution pool; in, , It is an empirical constant. For the ruling, For the execution body The returned result This is the cleaning threshold.
5. The space-based mimicry adjudication method as described in claim 1, characterized in that, The method further includes: If, during secondary scheduling, the number of votes collected within the timeout threshold period does not reach the expected number of votes, then a "link unreachable" report is sent to the upper layer.
6. A space-based mimicry adjudication device, characterized in that, include: The redundancy determination module is used to determine the redundancy of the execution unit based on the link packet loss rate and the number of votes for the expected return result of the execution unit; The timeout threshold determination module is used to determine the timeout threshold based on the longest on-board processing time and the longest Starlink propagation time. The adjudication result determination module is used to collect the number of votes returned by the executor within the current timeout threshold period. If the number of votes collected reaches the expected number of votes, the votes with the same result are placed in the same group, and it is determined whether the number of votes in each group exceeds half. If so, the result corresponding to the group with the most votes is output as the adjudication result; otherwise, the two groups with the smallest difference are selected, and the result corresponding to the group with the most votes in the two groups is output as the adjudication result. If the number of votes collected does not reach the expected number of votes, the candidate executor will be added to the executor pool, and secondary scheduling will be initiated.
7. The space-based mimicry adjudication device as described in claim 6, characterized in that, The redundancy determination module is used for: Based on the initial number of scheduled executors, determine the number of votes required for the expected executor to return a result that meets the preset value; Based on the fact that the link packet loss rate is negatively correlated with the redundancy of the executor, and that the number of votes expected to be returned by the executor is positively correlated with the redundancy of the executor, the redundancy of the executor is calculated. If the calculated redundancy of the executor is less than the number of initially scheduled executors, then the number of initially scheduled executors is used as the final redundancy of the executor; otherwise, the calculated redundancy of the executor is used as the final redundancy of the executor.
8. The space-based mimicry adjudication device as described in claim 6, characterized in that, The timeout threshold determination module is used for: Calculate the longest processing time on the satellite based on the maximum latency of a single processing cycle and the upper limit of processing jitter. Calculate the longest Starlink propagation time based on the redundancy overhead multiple and the average propagation waiting time. The larger of the longest on-board processing time and the longest Starlink propagation time is selected as the timeout threshold.
9. The space-based mimicry adjudication device as described in claim 6, characterized in that, The device further includes an execution pool update module for: After each round of adjudication, the enforcement body is updated according to the following formula. fractions : , , like Then the on-board scheduler will execute the body Remove from the execution pool; in, , It is an empirical constant. For the ruling, For the execution body The returned result This is the cleaning threshold.
10. The space-based mimicry adjudication device as described in claim 6, characterized in that, The device further includes a secondary scheduling module for: If, during secondary scheduling, the number of votes collected within the timeout threshold period does not reach the expected number of votes, then a "link unreachable" report is sent to the upper layer.