Abstract
The increasing operational requirements for onboard autonomy in satellite control systems necessitates structural methods that support the design of a complete and reliable supervisory system. This paper presents the design strategy used to develop a supervisor for the attitude control system for the Danish Ørsted satellite. The main topic is handling of faults arising in onboard instrumentation, ie. how to detect faults and how to prevent propagation into failures with potential mission loss as a consequence. Formal methods are used to ensure complete coverage of all potential fault types and to guarantee that the design criteria are met in the final implementation.
| Original language | English |
|---|---|
| Title of host publication | IEE Colloquium (Digest) |
| Publisher | IEE |
| Publication date | 1997 |
| Pages | 1-13 |
| Publication status | Published - 1997 |