Anomaly handling system and method for space environment, and detection apparatus
By deploying detection devices and interrupt controllers on spacecraft to generate statistical data and handle anomalies, the problem of data errors caused by single-event upsets is solved, ensuring the stability and reliability of space equipment and avoiding the shortcomings of existing technologies.
Patent Information
- Application Number
- PCT/CN2025/074869
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-24
- Filing Date
- 2025-01-24
- Publication Date
- 2026-01-02
AI Technical Summary
In the space environment, data errors or damage caused by single-event upsets can affect the normal operation of space equipment. Existing technologies such as metal masks or metal shields cannot completely eliminate this problem and increase costs and equipment weight.
The system employs a detection device and an interrupt controller, generates statistical data through a statistical unit, detects single-event upsets in the storage device, and generates an interrupt signal for anomaly handling. Combined with radiation-resistant material protection for the detection device, the impact of single-event upsets on the detection results is reduced.
It enables accurate detection and timely processing of single-event flips, reducing the risk of data errors and damage, ensuring the normal operation of spacecraft, and avoiding increased costs and weight.
Smart Images

Figure CN2025074869_02012026_PF_FP_ABST
Abstract
Description
Anomaly processing system, method and detection device for space environment TECHNICAL FIELD
[0001] The present application relates to the field of aerospace technology, and particularly relates to an anomaly processing system, method and detection device for space environment. BACKGROUND
[0002] In the space environment, radiation includes radiation from cosmic rays and high-energy particles, which can have an impact on memory devices, causing single event upset events. Single event upset refers to the behavior of a storage unit (such as a bit in a memory) in an electronic device (such as a storage device, an integrated circuit, etc.) that is caused by cosmic rays, causing the internal state of the storage unit to flip from 0 or 1 to another state. This flip can cause data errors or damage, affecting the normal operation of the device. In devices that operate in space for a long time, such as satellites, space platforms, space shuttles, etc., the reliability and stability of data are crucial. Therefore, the severity of single event upset cannot be ignored.
[0003] Currently, metal masks or metal shields are often added to the design of spacecraft storage devices to reduce the impact of cosmic rays on memory, but these measures cannot completely eliminate single event upset events caused by radiation. Once a single event upset occurs in a spacecraft, it is likely to affect the normal operation of the spacecraft. SUMMARY
[0004] The disclosure provides an anomaly processing system for a space environment, comprising a detection device, an interrupt controller and a to-be-tested storage device, the to-be-tested storage device and the detection device are arranged on a computing load of a spacecraft, the to-be-tested storage device is provided with a statistical unit and at least two registers; the statistical unit is used for reading monitoring data from a specified position of the to-be-tested storage device, generating statistical data according to the monitoring data and reference data written in the specified position in advance by the statistical unit, and storing the statistical data in the at least two registers, wherein the reference data comprises data with a specified number of bits; the statistical unit is specifically used for determining the number of bits in the monitoring data that are not the specified number, and generating the statistical data according to the number of bits in the monitoring data that are not the specified number and the total number of bits in the monitoring data; the detection device is used for reading the statistical data from the at least two registers through an internal bus of the spacecraft, determining an anomaly detection result for the to-be-tested storage device according to the statistical data, generating an interrupt signal based on the anomaly detection result, and sending the interrupt signal to the interrupt controller, wherein the anomaly detection result is used to represent the severity of a single event upset of the to-be-tested storage device under the influence of particle radiation in the space environment; and the interrupt controller is used for anomaly processing according to the interrupt signal.
[0005] Optionally, the detection device is provided with a master central processing unit (CPU) and a basic storage device; and the master CPU and the basic storage device are externally provided with anti-radiation materials.
[0006] Optionally, the detection device is specifically used for determining whether the statistical data stored in the at least two registers are consistent; in response to determining that the statistical data stored in the at least two registers are consistent, determining an anomaly detection result for the to-be-tested storage device according to the statistical data; and in response to determining that the statistical data stored in the at least two registers are inconsistent, re-reading monitoring data from the specified position and re-generating statistical data according to the re-read monitoring data and the reference data.
[0007] Optionally, for each of the at least two registers, a plurality of pieces of statistical data generated by the statistical unit according to the monitoring data read from the specified location and the reference data are stored in the register; the detection device is specifically configured to: determine whether the statistical data generated by the statistical unit in the last preset number of times are consistent; in response to determining that the statistical data generated by the statistical unit in the last preset number of times are consistent, determine an abnormality detection result for the storage device to be tested according to the statistical data; and in response to determining that the statistical data generated by the statistical unit in the last preset number of times are inconsistent, re-read the monitoring data from the specified location and re-generate the statistical data according to the re-read monitoring data and the reference data.
[0008] Optionally, the interrupt controller is specifically configured to trigger the mainboard CPU of the computing load to perform interrupt response based on the interrupt signal, so that the mainboard CPU performs abnormality processing based on the interrupt signal.
[0009] The present disclosure provides an abnormality processing method for a space environment, a spacecraft is provided with a detection device, an interrupt controller and a storage device to be tested, comprising: the detection device reads the statistical data from at least two registers of the storage device to be tested through an internal bus of the spacecraft, the statistical data is generated and stored in the at least two registers by a statistical unit of the storage device to be tested from a specified location of the storage device to be tested, reading monitoring data, and generating according to the monitoring data and reference data written in the specified location in advance, wherein the reference data includes a plurality of data with specified numerical values, and the statistical data is generated by the statistical unit according to the number of bit positions in the monitoring data that are not the specified numerical values and the total number of bit positions in the monitoring data after determining the number of bit positions in the monitoring data that are not the specified numerical values; determining an abnormality detection result for the storage device to be tested according to the statistical data, wherein the abnormality detection result is used to represent the severity of the single event upset of the storage device to be tested under the influence of particle radiation in the space environment; generating an interrupt signal based on the abnormality detection result, and sending the interrupt signal to the interrupt controller, so that the interrupt controller performs abnormality processing according to the interrupt signal.
[0010] Optionally, before determining the anomaly detection result for the to-be-tested storage device according to the statistical data, the method further comprises: determining whether the statistical data stored in the at least two registers are consistent; and determining the anomaly detection result for the to-be-tested storage device according to the statistical data, specifically comprising: in response to determining that the statistical data stored in the at least two registers are consistent, determining the anomaly detection result for the to-be-tested storage device according to the statistical data; and in response to determining that the statistical data stored in the at least two registers are inconsistent, re-reading the monitoring data from the specified location and re-generating the statistical data according to the re-read monitoring data and the reference data.
[0011] Optionally, for each of the at least two registers, a plurality of pieces of statistical data generated by the statistical unit according to the monitoring data read from the specified location and the reference data are stored in the register; before determining the anomaly detection result for the to-be-tested storage device according to the statistical data, the method further comprises: determining whether the statistical data generated by the statistical unit in the last preset number of times are consistent; and determining the anomaly detection result for the to-be-tested storage device according to the statistical data, specifically comprising: in response to determining that the statistical data generated by the statistical unit in the last preset number of times are consistent, determining the anomaly detection result for the to-be-tested storage device according to the statistical data; and in response to determining that the statistical data generated by the statistical unit in the last preset number of times are inconsistent, re-reading the monitoring data from the specified location and re-generating the statistical data according to the re-read monitoring data and the reference data.
[0012] The present disclosure provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the anomaly processing method.
[0013] The present disclosure provides a detection device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the anomaly processing method when executing the program. BRIEF DESCRIPTION OF DRAWINGS
[0014] The accompanying drawings, which are included to provide a further understanding of the present disclosure and constitute a part of this specification, illustrate exemplary embodiments of the present disclosure and are used to explain the present disclosure.
[0015] FIG. 1 is a schematic diagram of an anomaly processing system for a space environment according to an embodiment of the present disclosure.
[0016] FIG. 2 is a flowchart of an anomaly processing method according to an embodiment of the present disclosure.
[0017] FIG. 3 is a schematic diagram of the detection apparatus of FIG. 1 according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0018] For the purpose of describing the present disclosure, technical solutions and advantages, the technical solutions of the present disclosure will be described in detail below with reference to specific embodiments of the present disclosure and corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the scope of protection of the present disclosure.
[0019] To cope with single event upsets, storage devices in space environment usually take some measures for protection. By using error detection and error checking and correction (ECC), data errors in the memory caused by single event upsets can be detected and corrected. By adding metal masks or metal shields in the design of the storage device, the impact of cosmic rays on the memory can be reduced. However, these solutions still have some shortcomings. The implementation of ECC or metal shielding measures will increase the cost, especially in the case of mass production, which may affect the overall cost-effectiveness. Moreover, the metal shielding solution may increase the weight and size of the device, which may be disadvantageous for the spacecraft design in space missions. However, in fact, these technologies cannot completely eliminate single event upset events caused by radiation, which makes it particularly important to detect and warn single event upsets. Therefore, how to detect and warn single event upsets so as to timely handle the abnormal situation of single event upsets of the spacecraft and avoid the risk of data errors or damage to ensure the normal operation of the space equipment is a problem to be solved.
[0020] The technical solutions provided by the embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.
[0021] FIG. 1 is a schematic diagram of an abnormality processing system for space environment provided in the present disclosure, which includes a detection apparatus, an interrupt controller and a storage device to be tested.
[0022] Among them, the storage device to be tested, the interrupt controller and the detection apparatus can be deployed on the computing payload of the spacecraft (such as satellite, space platform, space shuttle, etc.). In the embodiments according to the present disclosure, the computing payload can refer to the hardware device carried on the spacecraft, such as computer, camera, router, etc.
[0023] The detection device is provided with a main control central processing unit (CPU) and a basic storage device, which can include a solid state disk (SSD) and a double data rate (DDR) memory. The main control CPU and the basic storage device of the detection device are externally provided with anti-radiation materials for protection, thereby reducing the risk of single event upset events of the detection device affecting abnormal detection results.
[0024] In the present disclosure, the to-be-tested storage device can include one or more of an SSD, a DDR, and a graphics memory of a graphics processing unit (GPU), and of course, other storage devices can also be included, which are not limited in the present disclosure. In actual applications, the above-mentioned to-be-tested storage device can also be protected by anti-radiation materials, but cannot completely avoid single event upset.
[0025] For each storage device, a statistical unit and at least two registers can be arranged in the storage device. The statistical unit can previously send a write request to the to-be-tested storage device, so as to write reference data to a specified position in the to-be-tested storage device for storage.
[0026] During the operation of the spacecraft, the statistical unit can send a data reading request to the to-be-tested storage device at a preset time interval, so as to read monitoring data from the specified position of the to-be-tested storage device. Then, the statistical unit can generate statistical data according to the read monitoring data and the reference data previously written in the specified position by the statistical unit, and store the statistical data in the at least two registers.
[0027] In actual applications, the above-mentioned reference data includes data with a specified number of bits (such as 0 or 1). When the statistical unit reads the monitoring data from the specified position of the to-be-tested storage device, the number of bits in the monitoring data that are not the specified number (i.e., the number of changed bits) can be determined. Then, according to the number of bits in the monitoring data that are not the specified number and the total number of bits in the monitoring data, the statistical data can be determined.
[0028] For example, when the reference data is all 0 data, after the statistical unit reads the monitoring data, the number of non-zero bits (bits with a value of 1) in the monitoring data can be calculated as a ratio of the total number of bits in the monitoring data, so as to obtain the statistical data.
[0029] For another example, when the reference data is all 1 data, after the statistical unit reads the monitoring data, the number of zero bits (bits with a value of 0) in the monitoring data can be calculated as a ratio of the total number of bits in the monitoring data, so as to obtain the statistical data.
[0030] Of course, the above reference data can also be several random numbers. When the monitoring data is read by the statistical unit, the monitoring data can be compared with the reference data to determine the number of bit positions that have undergone flipping, and the statistical data can be determined according to the number of bit positions that have undergone flipping and the total number of bit positions.
[0031] In the process of detecting the to-be-detected storage device, the detection device can read the statistical data from the register through the internal bus of the spacecraft, and determine an abnormal detection result for the to-be-detected storage device according to the statistical data. The abnormal detection result is used to represent the severity of the single event upset of the to-be-detected storage device under the influence of particle radiation in the space environment. The severity can be determined according to the proportion of bit positions that have undergone flipping in the statistical data.
[0032] In actual applications, the detection device can determine two kinds of abnormal detection results, i.e., abnormal presence and abnormal absence, based on the statistical data. When the abnormal presence occurs, a warning is given and a processing measure is taken. When the abnormal absence occurs, no warning is given and no processing measure is taken.
[0033] When the proportion of bit positions that have undergone flipping is greater than a preset threshold, it means that the single event upset is relatively serious, and thus the detection result of abnormal presence is obtained. When the proportion of bit positions that have undergone flipping is less than the preset threshold, it means that the single event upset is not serious, and thus the detection result of abnormal absence is obtained. The above preset threshold can be adjusted according to actual conditions, which is not limited in the present disclosure.
[0034] In addition, the detection device can also divide the severity of the single event upset according to the proportion of bit positions that have undergone flipping in the statistical data, so as to obtain abnormal detection results of different levels. Then, different interrupt signals are generated based on the abnormal detection results of different levels, and a warning or a processing measure is given through the mainboard CPU of the computing load.
[0035] For example, the detection device can divide the detection result corresponding to the statistical data in which the proportion of bit positions that have undergone flipping is 0% to 20% into low risk, divide the detection result corresponding to the statistical data in which the proportion of bit positions that have undergone flipping is 20% to 40% into medium risk, divide the detection result corresponding to the statistical data in which the proportion of bit positions that have undergone flipping is 40% to 60% into high risk, and divide the detection result corresponding to the statistical data in which the proportion of bit positions that have undergone flipping is more than 60% into extremely high risk.
[0036] For the low-risk abnormal detection result, the mainboard CPU can enhance data redundancy and error correction code (ECC), that is, improve the data redundancy, and strengthen the error detection and correction capability to cope with possible data damage or errors; for the medium-risk abnormal detection result, the mainboard CPU can reduce the service process clock frequency, reduce or stop the service operation, reduce the write and read operations of the service process to the memory device by reducing the running frequency of the device, so as to reduce the risk of data error of the service process; for the high-risk abnormal detection result, the mainboard CPU can perform master-slave switching and system restart, that is, switch to a standby system or restart the device to ensure that the system can quickly recover to a reliable state after a single event upset; for the extremely high-risk abnormal detection result, the mainboard CPU can send a warning signal to the ground terminal, and send a warning signal to the system operator to remind manual intervention and inspection.
[0037] Further, the above statistical data can be verified by multiple calculations, and when the results of multiple calculations are inconsistent, automatic recalculation is performed to reduce the influence of single event upset events of the statistical unit on the statistical results.
[0038] Specifically, for each register, the register stores statistical data generated by a plurality of statistical units according to monitoring data read from a specified position and reference data. Before determining the abnormal detection result, the detection device can determine whether the statistical data generated by the statistical unit in the last preset number of times is consistent. If consistent, the detection device can determine the abnormal detection result for the to-be-tested storage device according to the statistical data, otherwise, the monitoring data is re-read from the specified position, and the plurality of statistical data is re-generated according to the re-read monitoring data and the reference data. After the re-generated plurality of statistical data is verified again, the abnormal detection result is determined based on the verified statistical data.
[0039] In addition, in order to reduce the single event upset probability of the calculation result itself, the single event upset calculation result is backed up in multiple copies in each to-be-detected register. For example, register A and register B in FIG. 1 are used to save statistical results and backups respectively.
[0040] On this basis, the statistical data can use multiple backup calculation results. When the main control CPU reads the results from each register, it needs to read each calculation result and backup (register A and register B) and check whether the data is consistent, which can reduce the influence of single event upset events of the register of the statistical result on the statistical result.
[0041] Specifically, before determining the abnormality detection result, the detection device can determine whether the statistical data stored in the at least two registers are consistent. If yes, the abnormality detection result for the storage device under test is determined according to the statistical data, otherwise, the monitoring data at the specified position is re-read, and the statistical data is re-generated according to the re-read monitoring data and the reference data, and then the consistency of the re-generated statistical data in each register is checked again, until the consistency is passed, and the abnormality detection result is determined based on the passed statistical data.
[0042] That is, when the statistical data in each register is inconsistent, and / or the most recent statistical data in any one register is inconsistent, it indicates that the statistical data is not accurate, and at this time, the statistical data needs to be re-acquired and the abnormality detection result is determined after passing the check.
[0043] After the detection device determines the abnormality detection result, an interrupt signal can be generated based on the abnormality detection result, and the interrupt signal is sent to the interrupt controller, wherein different abnormality detection results can correspond to different interrupt signals.
[0044] It should be noted that the operations performed by the above detection device can be completed by the main control CPU of the detection device. That is, the main control CPU of the detection device reads the statistical data from the register, determines the abnormality detection result for the storage device under test according to the statistical data, and generates an interrupt signal based on the abnormality detection result, and sends the interrupt signal to the interrupt controller.
[0045] After receiving the interrupt signal, the interrupt controller can perform abnormality processing based on the interrupt signal.
[0046] Specifically, the interrupt controller can act as an interrupt agent, and when an interrupt signal from the main control CPU is detected on the pin, the mainboard CPU with a calculation load is triggered to respond to the interrupt.
[0047] The mainboard CPU can execute interrupt logic according to a pre-registered interrupt processing program, such as sending an abnormality processing notification and other warning operations, recording logs, powering off and other emergency operations; the interrupt controller can also directly connect to the NMI (Nonmaskable Interrupt) pin or power hibernate of the mainboard CPU, perform emergency interrupt, and make the mainboard CPU directly enter the power-off mode or hibernate mode, thereby protecting the calculation task result from being disturbed in a single particle high radiation intensity environment.
[0048] The mainboard CPU can perform warning or trigger safety measures according to the interrupt level when receiving the interrupt signal by listening to the interrupt controller. The processing measures taken for different interrupt levels (or abnormality detection results) have been described above, and the present disclosure will not be described in detail here.
[0049] Further, the disclosure also provides an abnormality processing method applied to the detection device.
[0050] FIG. 2 is a schematic diagram of an abnormality processing method provided in the disclosure, including the following steps S201-S203.
[0051] In step S201, the detection device reads the statistical data from at least two registers of the to-be-tested storage device through an internal bus of the spacecraft, wherein the statistical data is generated by a statistical unit of the to-be-tested storage device according to monitoring data read from a specified position of the to-be-tested storage device and reference data written in the specified position in advance and stored in the registers.
[0052] In step S202, an abnormality detection result of the to-be-tested storage device is determined according to the statistical data, wherein the abnormality detection result is used to represent the severity of the single event upset of the to-be-tested storage device under the influence of particle radiation in the space environment.
[0053] In step S203, an interrupt signal is generated based on the abnormality detection result, and the interrupt signal is sent to the interrupt controller, so that the interrupt controller performs abnormality processing according to the interrupt signal.
[0054] As can be seen from the above method, the statistical data can be calculated by the statistical unit inside the to-be-tested storage device. Since the statistical unit and the detection device are isolated from each other, the influence of the single event upset inside the detection device on the statistical data is avoided, and the abnormality detection result obtained is more accurate. Based on the abnormality detection result, the single event upset of the to-be-tested storage device can be processed or warned in time, the interference and damage of the single event upset time to the data in the spacecraft are avoided, and the safe operation of the spacecraft is further ensured. In the embodiment according to the disclosure, the statistical unit can be realized by an embedded CPU, a customized SOC (System on Chip), a programmable gate array FPGA (field-programmable gate array), etc.
[0055] The present disclosure also provides a schematic structural diagram of a detection device corresponding to FIG. 2, as shown in FIG. 3. As shown in FIG. 3, at the hardware level, the detection device comprises a processor, an internal bus, a network interface, a memory and a non-volatile memory, and can also comprise other hardware required by the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs to implement the abnormality processing method described above in FIG. 2. Of course, in addition to the software implementation, the present disclosure does not exclude other implementation manners, such as a logic device or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or a logic device.
[0056] For a technical improvement, it can be obvious whether the improvement is in hardware (e.g., improvement of circuit structures of diodes, transistors, switches, etc.) or in software (e.g., improvement of method processes). However, with the development of technology, many improvements of method processes nowadays can be considered as direct improvements of hardware circuit structures. Designers almost always obtain the corresponding hardware circuit structures by programming the improved method processes into hardware circuits. Therefore, it cannot be said that an improvement of a method process cannot be implemented by a hardware entity module. For example, a programmable logic device (PLD) (e.g., a field programmable gate array (FPGA)) is an integrated circuit whose logic function is determined by user programming of the device. A designer programs a digital system "onto" a PLD by himself / herself, without having to ask a chip manufacturer to design and manufacture a special integrated circuit chip. Moreover, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented by using "logic compiler" software, which is similar to the software compiler used when developing programs, and the original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there are many kinds of HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc., and the most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. It should be clear to those skilled in the art that only a little logical programming of the method processes in the above-mentioned hardware description languages and programming into integrated circuits can easily obtain hardware circuits that implement the logical method processes.
[0057] The controller can be implemented in any suitable way, for example, the controller can take the form of a microprocessor or processor and a computer readable medium storing computer readable program code, such as software or firmware, executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20 and Silicone Labs C8051F320, the memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that, in addition to being implemented in pure computer readable program code, the controller can also be implemented to perform the same functions in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers and embedded microcontrollers, etc. by logically programming the method steps. Therefore, such a controller can be considered as a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can even be considered as both a software module implementing a method and a structure within a hardware component.
[0058] The systems, apparatuses, modules or units illustrated by the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0059] For the sake of description, the above apparatuses are described in functional division and are described respectively as various units. Of course, the functions of the units can be implemented in the same or multiple software and / or hardware when implementing the present disclosure.
[0060] Those skilled in the art will understand that the embodiments of the present disclosure can be provided as a method, a system or a computer program product. Therefore, the present disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0061] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0062] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart block or blocks.
[0063] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0064] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0065] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, for storing, in general, data and / or program instructions. The memory can also include non-volatile memory, such as read-only memory (ROM), electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or non-volatile random access memory (NVRAM) for storing, in general, data and / or program instructions. The memory is an example of computer readable media.
[0066] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0067] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but also other elements not explicitly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0068] Those skilled in the art will appreciate that embodiments of the present disclosure can be provided as a method, system or computer program product. Accordingly, the present disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) containing computer usable program code.
[0069] The present disclosure can be described in the general context of computer-executable instructions, such as program modules, being executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform particular tasks or implement particular abstract data types. The present disclosure can also be practiced in distributed computing environments where tasks are performed by remote processing devices that are connected through a communication network. In a distributed computing environment, program modules can be located in both local and remote computer storage media including storage devices.
[0070] The various embodiments in the present disclosure are described in a progressive manner, and the same or similar parts among the various embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, the system embodiments are described simply because they are basically similar to the method embodiments, and the relevant parts can be referred to the description of the method embodiments.
[0071] The above only describes the embodiments of the present disclosure and is not intended to limit the present disclosure. The present disclosure can have various modifications and changes for those skilled in the art. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present disclosure shall be included in the scope of the claims of the present disclosure.
Claims
1. An anomaly handling system for a space environment, wherein, The anomaly handling system includes: a detection device, an interrupt controller, and a storage device under test. The storage device under test, the interrupt controller, and the detection device are deployed on the computing payload of the spacecraft. The storage device under test is equipped with a statistical unit and at least two registers. The statistical unit is used to read monitoring data from a specified location of the storage device under test, generate statistical data based on the monitoring data and reference data pre-written to the specified location by the statistical unit, and store the statistical data in the at least two registers. The reference data includes data with several bits having specified values. Specifically, the statistical unit is used to determine the number of bits in the monitoring data that are not the specified values, and generate the statistical data based on the number of bits in the monitoring data that are not the specified values and the total number of bits in the monitoring data. The detection device is used to read the statistical data from the at least two registers via the spacecraft's internal bus, determine the abnormal detection result for the storage device under test based on the statistical data, and generate an interrupt signal based on the abnormal detection result and send the interrupt signal to the interrupt controller, wherein the abnormal detection result is used to characterize the severity of the single-event flip under the influence of particle radiation in the space environment. The interrupt controller is used to perform exception handling based on the interrupt signal.
2. The exception handling system as described in claim 1, wherein, The detection device is equipped with a main control central processing unit (CPU) and basic storage devices. The main control CPU and the basic storage device are externally equipped with radiation-resistant materials.
3. The exception handling system as described in claim 1, wherein, The detection device is specifically used for: Determine whether the statistical data stored in the at least two registers are consistent; In response to determining that the statistical data stored in the at least two registers are consistent, an anomaly detection result for the storage device under test is determined based on the statistical data; In response to the determination that the statistical data stored in at least two registers are inconsistent, the monitoring data is reread from the specified location, and the statistical data is regenerated based on the reread monitoring data and the baseline data.
4. The exception handling system as described in claim 1, wherein, For each of the at least two registers, the register stores a number of statistical data generated by the statistical unit based on monitoring data read from the specified location and the baseline data; The detection device is specifically used for: Determine whether the statistical data generated by the statistical unit the most recent preset number of times are consistent; In response to determining that the statistical data generated by the statistical unit the most recent preset number of times are consistent, an anomaly detection result for the storage device under test is determined based on the statistical data. In response to the determination that the statistical data generated by the statistical unit the most recent preset number of times are inconsistent, the monitoring data is reread from the specified location, and the statistical data is regenerated based on the reread monitoring data and the baseline data.
5. The exception handling system as described in claim 1, wherein, The interrupt controller is specifically used to trigger the motherboard CPU of the computing load to perform an interrupt response based on the interrupt signal, so that the motherboard CPU performs exception handling based on the interrupt signal.
6. An anomaly handling method for the space environment, wherein, The spacecraft is equipped with detection devices, an interrupt controller, and a storage device for testing, including: The detection device reads statistical data from at least two registers of the storage device under test via the spacecraft's internal bus. The statistical data is generated and stored in the at least two registers by the statistical unit of the storage device under test, which reads monitoring data from a designated location on the storage device under test, based on the monitoring data and reference data pre-written to the designated location. The reference data includes a number of bits with specified values. The statistical data is generated by the statistical unit after determining the number of bits in the monitoring data that are not the specified values, based on the number of bits in the monitoring data that are not the specified values and the total number of bits in the monitoring data. Based on the statistical data, anomaly detection results are determined for the storage device under test, wherein the anomaly detection results are used to characterize the severity of single-event upsets occurring in the storage device under test under the influence of particle radiation in the space environment. Based on the anomaly detection result, an interrupt signal is generated and sent to the interrupt controller so that the interrupt controller can perform anomaly handling according to the interrupt signal.
7. The method of claim 6, wherein, Before determining the anomaly detection results for the storage device under test based on the statistical data, the method further includes: Determine whether the statistical data stored in the at least two registers are consistent; Based on the statistical data, the anomaly detection results for the storage device under test are determined, specifically including: In response to determining that the statistical data stored in the at least two registers are consistent, an anomaly detection result for the storage device under test is determined based on the statistical data; In response to the determination that the statistical data stored in at least two registers are inconsistent, the monitoring data is reread from the specified location, and the statistical data is regenerated based on the reread monitoring data and the baseline data.
8. The method of claim 6, wherein, For each of the at least two registers, the register stores a number of statistical data generated by the statistical unit based on monitoring data read from the specified location and the baseline data; Before determining the anomaly detection results for the storage device under test based on the statistical data, the method further includes: Determine whether the statistical data generated by the statistical unit the most recent preset number of times are consistent; Based on the statistical data, the anomaly detection results for the storage device under test are determined, specifically including: In response to determining that the statistical data generated by the statistical unit the most recent preset number of times are consistent, an anomaly detection result for the storage device under test is determined based on the statistical data. In response to the determination that the statistical data generated by the statistical unit the most recent preset number of times are inconsistent, the monitoring data is reread from the specified location, and the statistical data is regenerated based on the reread monitoring data and the baseline data.
9. A computer-readable storage medium, wherein, The storage medium stores a computer program, which, when executed by a processor, implements the method described in any one of claims 6 to 8.
10. A detection device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the program, it implements the method described in any one of claims 6 to 8.
Citation Information
Patent Citations
Single event upset fault processing method based on AT697 processor
CN103984630A
Single-particle flip detection system and method for programmable SOC device in space radiation environment
CN106484581A
Spatial single event effect instant recovery method specific to real-time communication equipment
CN108832990A
Single event effect test analysis method and device of memory and test system
CN111599402A
Abnormality processing system and method for space environment and detection device
CN118377645A