Command & Data Handling
L3-CDH-PROC-BOOT CRITICAL COMMAND CONTROL Level 3 · hardware

Boot and Recovery Subsystem

Boot_Recovery_Firmware_Subsystem

Triple-redundant non-volatile boot firmware storage with voting loader, safe-mode fallback images, and multi-stage boot sequence management for processor initialization and recovery from faults.

Purpose

Guarantee that every processor module can reliably boot into operational software regardless of the cause of reset (power-on, watchdog timeout, commanded reset, or SEL recovery). Maintains multiple firmware images including a golden safe-mode image that cannot be overwritten, ensuring recovery is always possible.

Context

Boot reliability is essential for 100-year autonomous operation. The boot subsystem stores firmware in triple-redundant radiation-hardened PROM/EEPROM with voting on readout. A multi-stage boot sequence first runs POST, then loads a minimal safe-mode kernel, and finally transitions to full flight software. If any stage fails, the system falls back to the previous safe stage. The golden image is mask-programmed and physically write-protected.

Principles

Typical implementations

Lunar considerations

Specifications

Functional

primary functionStore boot firmware, manage multi-stage boot sequence, and provide guaranteed recovery to safe-mode operation
inputsReset signal from L3-CDH-PROC-WDT or power-on reset circuit, Reset cause indication (power-on, watchdog, commanded, SEL recovery), Updated firmware images from L2-CDH-SW via L2-CDH-STOR, Boot configuration parameters from MRAM registers
outputsBoot firmware code stream to L3-CDH-PROC-CPU, POST results (pass/fail with diagnostic codes), Boot stage completion signals, Boot telemetry and error logs to L2-CDH-STOR
boot time total s30
post duration s5
firmware image count4
golden image size mb4
full image size mb16
hash verification time s2

Physical

mass kg1.0
dimensions0.10m x 0.08m x 0.02m per boot module (3 redundant copies)
materialsRadiation-hardened EEPROM and OTP PROM in ceramic packages, Anti-fuse PROM for golden image (physically write-protected), MRAM modules for boot configuration registers, Hermetic module enclosure with EMI shielding
operating temp c-40 to +85
survival temp c-55 to +125
radiation tolerance krad300
data retention years100
vacuum compatibleTrue

Operational

power consumption w2
thermal range c-40, 85
lifetime years100
mtbf hours500000

Interfaces

Provides

  • Radiation-Hardened Processor ModulesBoot firmware code streamcritical
    Voted boot code delivered to processor instruction memory for initialization sequence execution.
  • Central Processing SystemBoot status and POST resultsessential
    Boot completion status, POST diagnostic results, and firmware version information.

Requires

  • Watchdog Timer SubsystemReset cause signalscritical
    Reset type indication to select appropriate boot path (cold start, warm restart, or safe-mode fallback).
  • Flight Software FrameworkUpdated firmware imagesessential
    New flight software images uploaded from Earth for installation into updateable boot slots.
  • Power Generation SystemBoot powercritical
    Early-available power rail that stabilizes before main processor power, enabling boot sequencing.
Share

Cite this entry

Lunar Ark Codex. "Boot and Recovery Subsystem" (L3-CDH-PROC-BOOT). Retrieved 10 September 2026, from https://lunarark.com/entry/L3-CDH-PROC-BOOT

Licensed CC-BY-SA 4.0. You may reuse and adapt this entry with attribution, under the same licence.

View in the graph Back to the Ark