Скачать презентацию Fault Tolerant Computer for the AUTOMATED TRANSFER VEHICLE Скачать презентацию Fault Tolerant Computer for the AUTOMATED TRANSFER VEHICLE

e8ae4704a828a5e1dcd2a3f5f8c151f0.ppt

  • Количество слайдов: 21

Fault Tolerant Computer for the AUTOMATED TRANSFER VEHICLE Chandan Kumar EE 585: Fault Tolerant Fault Tolerant Computer for the AUTOMATED TRANSFER VEHICLE Chandan Kumar EE 585: Fault Tolerant Computing EE 585 Current Fault Tolerant Techniques

Outline n n n Background of ATV Contraints Fault Tolerant Computer Fault Tolerance Implementation Outline n n n Background of ATV Contraints Fault Tolerant Computer Fault Tolerance Implementation FTC development model Conclusion and perspectives EE 585 Current Fault Tolerant Techniques 2

Background of ATV n n Automated Transfer Vehicle-a servicing vehicle for the ISS 1 Background of ATV n n Automated Transfer Vehicle-a servicing vehicle for the ISS 1 st ATV(Jules Verne) Being developed by ESA To be launched aboard Ariane 5 by late 2007 EE 585 Current Fault Tolerant Techniques 3

Functions of ATV n n n Deliver fuel and logistics General supplies Water and Functions of ATV n n n Deliver fuel and logistics General supplies Water and oxygen Conduct experiments Conduct orbit adjustment Serves as a waste collector EE 585 Current Fault Tolerant Techniques 4

n n On orbit life of 180 days Expendable burns up upon re-entry EE n n On orbit life of 180 days Expendable burns up upon re-entry EE 585 Current Fault Tolerant Techniques 5

Various capacities of ATV AUTOMATED TRANSFER VEHICLE (late 1997 baseline) Dry cargo (max. 11. Various capacities of ATV AUTOMATED TRANSFER VEHICLE (late 1997 baseline) Dry cargo (max. 11. 2 m 3 in 8 racks plus 4 m 3 in center aisle) 1102 kg (5500 kg max. ) Maximum refuel for Russian Service Module 860 kg Maximum H 2 O for Russian Service Module 840 kg Maximum N 2, O 2 for Russian Service Module 100 kg Max. propellant available for reboost 4080 kg Rendezvous & docking propellant (400 N thrust, 310 s Isp) 2680 kg Cargo Carrier (CC) 4011 kg Optional CC refueling, water, gas transfer equipment 1246 kg ATV Dry mass (including system margin) 5581 kg EE 585 20500 kg maximum launch wt. Current Fault Tolerant Techniques 6

ATV Constraints n n n Tolerance to hardware faults Tolerance to software faults Safety ATV Constraints n n n Tolerance to hardware faults Tolerance to software faults Safety concept EE 585 Current Fault Tolerant Techniques 7

Fault Tolerant Computer n n n Developed by Matra Marconi Space Resides in the Fault Tolerant Computer n n n Developed by Matra Marconi Space Resides in the avionics module Triple FTC and MSU(Monitoring and Safing Unit) EE 585 Current Fault Tolerant Techniques 8

Vital/Nominal breakdown EE 585 Current Fault Tolerant Techniques 9 Vital/Nominal breakdown EE 585 Current Fault Tolerant Techniques 9

Fault detection and the subsequent action n 1. 2. 3. Upon detection of a Fault detection and the subsequent action n 1. 2. 3. Upon detection of a critical failure or an unsafe situation, The Monitoring and Safing Unit (MSU) isolates the ATV’s nominal system and commands a Collision Avoidance Manoeuvre (CAM). This brings the ATV on a safe trajectory within the monitoring corridor towards the ISS. Once the Collision Avoidance Manoeuvre is completed, the MSU points the vehicle towards the Sun, thus ensuring sufficient power from the solar panels during the ‘survival’ mode that the vehicle enters. EE 585 Current Fault Tolerant Techniques 10

Allocation of S/W entities EE 585 Current Fault Tolerant Techniques 11 Allocation of S/W entities EE 585 Current Fault Tolerant Techniques 11

Fault Tolerance Implementation Characterised with respect to n Fault containment layers and sub layers Fault Tolerance Implementation Characterised with respect to n Fault containment layers and sub layers n Inter-channel synchronisation n Time determinism n Fault passivation and reconfiguration EE 585 Current Fault Tolerant Techniques 12

Fault Containment approach n n Nominal/Vital segregation Intra-vital segregation EE 585 Current Fault Tolerant Fault Containment approach n n Nominal/Vital segregation Intra-vital segregation EE 585 Current Fault Tolerant Techniques 13

n Inter-channel synchronisation approach n Time determinism EE 585 Current Fault Tolerant Techniques 14 n Inter-channel synchronisation approach n Time determinism EE 585 Current Fault Tolerant Techniques 14

n Fault reconfiguration approach 2. Channel passivation after failure Application passivation after software failure n Fault reconfiguration approach 2. Channel passivation after failure Application passivation after software failure n Hardware/software allocation 1. EE 585 Current Fault Tolerant Techniques 15

FTC development model n 1. 2. EE 585 FTC hardware implementation Computer internal design FTC development model n 1. 2. EE 585 FTC hardware implementation Computer internal design Inter-computer link design Current Fault Tolerant Techniques 16

FTC channel architecture EE 585 Current Fault Tolerant Techniques 17 FTC channel architecture EE 585 Current Fault Tolerant Techniques 17

Conclusion and perspectives n n New generation fault tolerant computer-combines high perfomance, compact/low cost Conclusion and perspectives n n New generation fault tolerant computer-combines high perfomance, compact/low cost design and tolerance to application software faults. Integrating software fault tolerance is a significant cost saving factor. Technically mature product. Fully suitable to ATV Open architecture and performance margins make it adaptable to the needs of future reusable launch vehicles EE 585 Current Fault Tolerant Techniques 18

References n n n R. Roques, A. Correge, C. Boleat - Fault Tolerant Computer References n n n R. Roques, A. Correge, C. Boleat - Fault Tolerant Computer for the Automated Transfer Vehicle http: //www. esa. int/SPECIALS/ATV/index. html http: //en. wikipedia. org/wiki/Automated_Transfer_ Vehicle EE 585 Current Fault Tolerant Techniques 19

References Contd. EE 585 Current Fault Tolerant Techniques 20 References Contd. EE 585 Current Fault Tolerant Techniques 20

Questions? ? ? EE 585 Current Fault Tolerant Techniques 21 Questions? ? ? EE 585 Current Fault Tolerant Techniques 21