Error Detection and Correcting Memory

Error detection and correcting (EDAC) memory provides a foundational defense against radiation-induced corruption in spacecraft onboard memory. The selected EDAC scheme must detect and correct error patterns within its designed capability and identify errors that exceed that capability. Common single-error-correction, double-error-detection schemes correct single-bit errors and detect double-bit errors, but other schemes may provide different correction and detection capabilities. The EDAC scheme must be integrated with both the fault management system and the spacecraft's cyber-protection mechanisms, enabling coordinated responses to uncorrectable multi-bit errors that go beyond time-delayed ground monitoring of EDAC telemetry. This integration is security-relevant because multi-bit memory errors, whether radiation-induced or adversarially induced through deliberate fault injection, can corrupt flight software, configuration data, or security-critical parameters in ways that create exploitable system states if not detected and responded to promptly and autonomously. The spacecraft must use the selected EDAC architecture to detect and correct errors during memory access and, where applicable, perform periodic memory scrubbing to detect and remove latent correctable errors. The implementation must identify the affected memory address or region for detected uncorrectable errors involving two or more bits, to the extent supported by the memory architecture, with higher-order detection or correction provided where required by mission risk. Detection of an uncorrectable error must trigger a timely onboard fault-management or cyber-protection response that prevents continued use or propagation of suspect data and autonomously minimizes adverse effects without waiting for ground detection. Subsequent diagnosis and recovery may be autonomous, ground-directed, or combined according to mission requirements.

ID: CM0045
Tier: II
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should identify the onboard memory and storage regions whose corruption could affect spacecraft safety, mission operation, or security and define the required error detection, correction, and recovery protections for each. Where EDAC is selected, requirements must specify its correction and detection capability, any applicable scrubbing interval, and its integration with fault management and cyber-protection mechanisms. Requirements should specify that uncorrectable-error detection invoke an autonomous containment or fault-management response not dependent on initial ground recognition. Applicable responses may include isolation or retirement of the affected region, remapping, reload from a trusted copy, failover, reset, or fault-management escalation. Contract language should require that the EDAC architecture be documented as a security engineering deliverable, including the mapping of EDAC-protected memory regions to the software and data they contain, the integration interfaces with fault management and cyber-protection functions, and the response logic for detected uncorrectable errors. Evaluation criteria should assess offerors' proposed EDAC schemes, the adequacy of detection order for the mission's radiation environment, and the completeness and security relevance of the fault management and cyber-protection integration design. Verification should include radiation environment testing or analysis demonstrating EDAC performance, and functional testing confirming that detected uncorrectable errors trigger the correct autonomous responses.

Pre-Operations Developer/Supplier

EDAC architecture must be selected and integrated during the hardware design phase, as the choice of EDAC scheme, the memory technologies it protects, and the scrubbing mechanism are determined by component selection and board-level design decisions that cannot be effectively changed after hardware fabrication. The EDAC scheme must be selected using the mission radiation environment and lifetime, device-specific radiation test or analysis results, expected upset rates, multiple-bit and multiple-cell upset behavior, memory organization and interleaving, and the consequences of uncorrectable corruption. The correction and detection capability must be sufficient when combined with the selected scrubbing, redundancy, and fault-response architecture. Integration between the EDAC controller and the fault management system must be designed to provide actionable fault indications, including the memory address, error type, and correction or detection status for each event, enabling the fault management system to correlate EDAC events with system behavior and initiate appropriate responses. Repeated, concentrated, or otherwise anomalous EDAC events in security-critical memory regions should be correlated with radiation conditions, spacecraft location and operating state, device health, system anomalies, and available cyber indicators. Statistical analysis may identify patterns inconsistent with expected background behavior, but EDAC data alone cannot determine whether the cause is deliberate fault injection, radiation, hardware degradation, or another fault mechanism. Where memory scrubbing is used, the interval must limit the probability that additional errors accumulate in the same protected codeword before the existing error is detected and corrected, accounting for expected upset rates, multiple-bit upset behavior, memory interleaving, and system resource constraints.