A rail transit interlocking system completeness test case generation method and system
By combining STPA and symbolic finite state machines with LTL attributes, completeness test cases for the rail transit interlocking system are generated, which solves the problems of long time consumption and system state explosion in the existing technology and realizes efficient safety requirement testing.
Patent Information
- Application Number
- CN202411111928.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-14
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-08-14
AI Technical Summary
In the existing technology, the testing method of rail transit interlocking system has the problems of being too time-consuming and unable to effectively deal with the system state explosion. In addition, the equivalence class partitioning idea cannot be applied to systems with discrete inputs and outputs.
The STPA technology is used to analyze the safety requirements of the rail transit interlocking system, convert them into linear temporal logic attributes, and use symbolic finite state machines to model them. Equivalence class division is combined with LTL attributes to generate complete test cases.
By reducing the number of test cases, shortening the test time, improving the test efficiency, and ensuring that the system meets the safety requirements when facing various situations, a test case generation method for discrete input and output systems is provided.
Smart Images

Figure CN118746976B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of rail transit interlocking system, and particularly to a rail transit interlocking system completeness test case generation method and system. BACKGROUND
[0002] Rail transit interlocking system is an important part of railway transportation, which is responsible for ensuring the safe and efficient operation of trains in the railway network. However, with the increase of system size and complexity, it has become a challenge to ensure the safety of the interlocking system.
[0003] In the prior art, the equivalence class division idea has been applied to systems with infinite input and finite output. However, for systems with discrete input and output such as rail transit interlocking systems, existing methods have not been able to apply the equivalence class division idea to process the input and output expressions of these systems.
[0004] Therefore, the test methods for rail transit interlocking systems have the problems of simple algorithm (mainly exhaustive method) and long time consumption. At the same time, most test methods cannot effectively deal with the problem of system state explosion. SUMMARY
[0005] The main purpose of the present application is to overcome the above-mentioned defects in the prior art, and to provide a rail transit interlocking system completeness test case generation method and system. The STPA technology is used to analyze the rail transit interlocking system systematically, identify unsafe control behaviors, and derive safety requirements. Based on the derived safety requirements, complete LTL properties are obtained. And based on the symbolic finite state machine, combined with LTL properties, complete consistency testing is done. In generating test cases, the rail interlocking system is divided into equivalence classes for the first time, reducing the number of generated test cases and shortening the test time.
[0006] The present application adopts the following technical solutions:
[0007] A rail transit interlocking system completeness test case generation method, characterized in that it comprises:
[0008] Applying the STPA method to analyze the safety requirements of the rail transit interlocking system, and converting the safety requirements into linear temporal logic properties;
[0009] Modeling the rail transit interlocking system using a symbolic finite state machine to obtain a reference model, calculating all evaluation functions in the rail transit interlocking system, and generating symbolic traces in the reference model according to the evaluation functions;
[0010] Improving the reference model and performing equivalence class division on the input and output events of the reference model in combination with the linear temporal logic properties;
[0011] generating test cases based on the improved reference model, executing the test cases on the system under test, and detecting whether the system under test meets the safety requirements of the rail transit interlocking system.
[0012] analyzing the safety requirements of the rail transit interlocking system using the STPA method, specifically including:
[0013] System modeling: modeling the control structure and control process of the rail transit interlocking system;
[0014] Control structure analysis: identifying the relationships and interactions between multiple control components of the control structure;
[0015] Control process analysis: analyzing the control process of the rail transit interlocking system, including identifying the control logic of signal lights, the switching process of turnouts, and the control strategy for train entry and exit;
[0016] Identifying safety constraints: identifying control operations and environmental conditions that lead to adverse events based on the control structure and control process;
[0017] Analyzing and evaluating risks: analyzing the identified safety constraints, evaluating the potential impact of the safety constraints on the safety of the rail transit interlocking system, and determining unsafe control behaviors that lead to accidents;
[0018] Deriving safety requirements: negating the unsafe control behaviors to obtain the safety requirements of the rail transit interlocking system.
[0019] Converting the unsafe control behaviors into linear temporal logic properties according to defined rules.
[0020] Modeling the rail transit interlocking system using symbolic finite state machines to obtain a reference model SFSM RIS =(S RIS , s1, R RIS , I RIS , O RIS , D RIS ,∑ I RIS ,∑ O RIS ), S RIS is the state space and S RIS ={s0, s1, s2}, s0 is the initial state, s1 is the controller processing path request state, s2 is the controller adjusting path state, I RIS is the variable symbol of input events, O RIS is the variable symbol of output events, D RIS is the union of all variable type domains,∑I RIS is the input alphabet of the reference model. O RIS is the output alphabet of the reference model.
[0021] All evaluation functions in the rail transit interlocking system are calculated, the symbolic traces in the reference model are generated according to the evaluation functions, and each input / output expression v in the rail transit interlocking system is mapped to the corresponding type value σ(v) in the reference model by the evaluation function σ.
[0022] The reference model is improved, and the input / output events of the reference model are divided into equivalence classes in combination with the linear temporal logic properties, and the specific method is as follows:
[0023] The set of input / output expressions ∑ that satisfy the safety requirements is constructed as follows:
[0024] ∑ = ∑ I RIS ∪ ∑ O RIS ∪ AP
[0025] wherein ∑ O RIS represents the input alphabet of the reference model, ∑ O RIS represents the output alphabet of the reference model, and AP represents the set of atomic propositions converted by the linear temporal logic properties;
[0026] All input / output classes are divided according to the set of input / output expressions ∑.
[0027] All specific traces that satisfy the above input / output classes, i.e., evaluation functions σ, are calculated, and the evaluation function set φ is calculated according to the input / output classes respectively.
[0028] Test cases are generated based on the symbolic traces of the improved reference model, and the specific method is as follows:
[0029] Step a. A minimum state cover set V containing the improved reference model is constructed as the set of test cases, which is a set of symbolic traces on the input / output expressions of the reference model;
[0030] Step b. For each pair of different symbolic traces α, β ∈ V, a symbolic distinguishing trace γ is found, and α.γ and β.γ are added to the test cases;
[0031] Step c. The test cases are expanded by a set T composed of symbolic traces, each trace being composed of a prefix of the state cover set V and a suffix of an arbitrary symbolic trace of the set A of all input / output equivalence classes.
[0032] execute the test case on the measured system, detect whether the measured system meets the safety requirements of the rail transit interlocking system, in particular:
[0033] execute the test case generated by the steps a, b and c on the measured system respectively, if the measured system does not output a fault, the test is passed, that is, the measured system meets the safety requirements of the rail transit interlocking system, if the measured system outputs a fault, the test fails, and the measured system needs to be corrected.
[0034] The measured system refers to the improved reference model with a fault domain, the fault domain is various error behaviors, the fault domain uses all input conditions and output expressions in the reference model, and adds mutations of all potential input and output expressions expected to occur in fault implementation.
[0035] A rail transit interlocking system completeness test case generation system comprises:
[0036] An STPA analysis module analyzes the safety requirements of the rail transit interlocking system by using the STPA method, and converts the safety requirements into linear temporal logic properties;
[0037] A modeling module models the rail transit interlocking system by using a symbolic finite state machine to obtain a reference model, calculates all evaluation functions in the rail transit interlocking system, and generates symbolic traces in the reference model according to the evaluation functions;
[0038] An equivalence class division module improves the reference model, and divides the input and output events of the reference model into equivalence classes in combination with the linear temporal logic properties;
[0039] A test module generates test cases based on the symbolic traces of the improved reference model, executes the test cases on a measured system, and detects whether the measured system meets the safety requirements of the rail transit interlocking system.
[0040] From the above description of the present application, compared with the prior art, the present application has the following beneficial effects:
[0041] The present method uses STPA (System-Theoretic Process Analysis) as a systematic safety analysis technology. STPA can comprehensively and deeply understand the operation mechanism of the system through strict hierarchical analysis of the system, and ensure that the safety requirements analyzed are complete.
[0042] After the safety requirements are determined, in order to carry out the consistency test, the method uses LTL (Linear Temporal Logic) to convert these safety requirements into formal language and as attribute requirements. The benefit of formalizing safety requirements is that it can not only be used for consistency testing, but also guarantees the completeness of the test. As a logical language, LTL can clearly describe the behavior constraints of the system, thereby ensuring that the system can meet the safety requirements when facing various situations.
[0043] In the test case generation phase, the method designs an innovative consistency testing method. First, the symbolic finite state machine is used to model the rail transit interlocking system, and the state and transition rules of the system are formally represented. Then, combined with the LTL safety requirements, test cases are further generated.
[0044] The method first applies the idea of equivalence class division to the generation of test cases for the rail transit interlocking system. By reasonably dividing the equivalence classes, the number of test cases generated can be effectively reduced, thereby reducing the test time and improving the test efficiency. In addition, the equivalence class division idea of the method also provides reference and reference for the test case generation method of other systems with discrete input and output. BRIEF DESCRIPTION OF DRAWINGS
[0045] Figure 1 Flowchart of the method of the present application
[0046] Figure 2 Path diagram in the rail transit interlocking system
[0047] Figure 3 Control structure diagram of the rail transit interlocking system
[0048] Figure 4 State machine diagram of the rail transit interlocking system
[0049] The present application will be further described in detail below in combination with the drawings and specific embodiments. DETAILED DESCRIPTION
[0050] The present application will be further described in detail below in combination with the drawings and specific embodiments.
[0051] The rail transit interlocking system is a key system for managing railway train operation, ensuring the safe and smooth running of trains on the track. It includes signal systems, turnout control systems, train detection equipment and other main components. Its main function is to ensure the safe running of trains by controlling signals, turnouts and track circuits and other equipment. The system dynamically adjusts the signal state and turnout position according to the train's position, speed and direction of travel, etc. to avoid collisions between trains or other unexpected events.
[0052] In a railway network, tracks are divided into sections. Each section includes elements such as sections, switches, and intersections, which provide the physical path for trains. Switches have two positions to secure the path and direction of train travel and can be locked to prevent them from moving.
[0053] A signal is an entity that conveys information to trains. Each signal is associated with a specific route in a specific direction and usually has two states: red and green. By default, the signal is set to red, indicating that trains cannot enter the path.
[0054] Requisitioning a route (also called an approach route) is the process of requesting resources for a train and allocating them to a specific train. Releasing a route is the process of releasing resources after a train has used them. When a train enters a section, its automatic monitoring system communicates with the interlocking system to request an approach route. The interlocking system evaluates the request based on the route information and approves, cancels, or revokes it based on safety criteria.
[0055] like Figure 2 As shown in the figure, there are 7 track sections and two switches. When a train applies to pass through the B1-B3-B7 path, the interlocking controller of the rail transit interlocking system first checks whether the path and the sections involved conflict with the applications of other trains. If there is a conflict or the sections in the path are already occupied by other trains, the path cannot be requisitioned. Once the path application is successful, the controller will mark the path and section as being in use, lock the switches to the corresponding position, and set the signal light to green to indicate that the train can enter safely. If the switch fails, the train cannot enter and the application information for the section is revoked. At the same time as the train enters, the signal light turns red to prevent other trains from entering. The interlocking system will continuously monitor the path information, switch status and signal status to promptly detect and prevent emergencies.
[0056] When the train leaves the section, the interlocking system will first turn all signals to red, unlock the switches, and release the use rights of the section so that other trains can continue to use it.
[0057] The present invention proposes a method for generating a rail transit interlocking system integrity test case, comprising the following steps:
[0058] 1) The STPA method is used to analyze the safety requirements of the rail transit interlocking system and convert the safety requirements into linear temporal logic attributes.
[0059] In this step, the STPA method is applied to analyze the safety requirements of the rail transit interlocking system, including:
[0060] System modeling: Model the control structure and control process of the rail transit interlocking system, including signal system, turnout control, train control, etc.
[0061] Control structure analysis: Identify the relationships and interactions between multiple control components of the control structure, i.e., analyze the control structure of the rail transit interlocking system, identify the signal, turnout, track, etc. control components, and their relationships and interactions.
[0062] Control process analysis: Analyze the control process of the rail transit interlocking system, including identifying the control logic of the signal lights, the switching process of the turnouts, the control strategy of the train entering and leaving the station, etc.
[0063] Identify safety constraints: Based on the control structure and control process, identify control operations and environmental conditions that can lead to adverse events. For example, based on the control structure and control process of the rail transit interlocking system, identify control operations and environmental conditions that can lead to train collisions, turnout failures, etc.
[0064] Analyze and evaluate risks: Analyze the identified safety constraints, evaluate the potential impact of safety constraints on the safety of the rail transit interlocking system, and determine unsafe control behaviors that can lead to accidents.
[0065] Propose safety improvement measures: Based on the analysis of potential risks, propose suggestions and measures to improve the safety of the rail transit interlocking system to mitigate or eliminate potential safety risks.
[0066] Derive safety requirements: Based on the unsafe control behaviors, derive the safety requirements of the rail transit interlocking system.
[0067] See Figure 3 , the control structure is a hierarchical system model that includes system components (controllers, sensors, actuators, and controlled processes), feedback and control action flow, and system input and output. It imposes constraints on the behavior of the system. We use the boundary information and hazard information of the system to construct the control structure. The interlocking controller sends control actions to each path controller.
[0068] Sensors are responsible for capturing path state, train information, signal light information, turnout state information, and section information. Control actions and corresponding feedback include turnout locking and unlocking, and the corresponding feedback is the locking state of the turnout. The turnout controller uses an algorithm to safely perform locking and unlocking operations. The algorithm is based on the process model to issue control actions. The process model of the entire system includes six variables: train position, section state, path state, turnout state, and signal light state.
[0069] For example, based on the control structure, the following 4 accidents are identified through STPA analysis:
[0070] A1: Rear-end collision;
[0071] A2: Head-on collision;
[0072] A3: Side collision;
[0073] A4: Derailment;
[0074] For these 4 possible accidents, the causes that can lead to the accident are analyzed, which are the hazards in the system. A hazard is a system state that, together with an unsafe control action, leads to an accident. This case identified the following 5 hazards and the possible accidents that can result from them:
[0075] H1: Allow a train to enter an occupied route [A1];
[0076] H2: The interlocking system simultaneously claims two or more paths that conflict with each other [A1, A2, A3];
[0077] H3: One or more switches are not aligned to the required position [A1, A2, A3, A4];
[0078] H4: In a path that has already been claimed, one or more switches are not locked [A1, A2, A3, A4];
[0079] H5: The path is revoked while a train is in the path [A1, A2, A3, A4];
[0080] System-level safety constraints are derived from hazards, as follows:
[0081] SC1: Once a train occupies a path, no other train can enter [H1];
[0082] SC2: The path controller cannot claim any mutually conflicting paths [H2];
[0083] SC3: All switches belonging to the claimed path section must be aligned to the corresponding position and locked [H3, H4];
[0084] SC4: The path that a train is occupying cannot be revoked [H5];
[0085] An unsafe control action (UCA) is a control action that, in a particular situation and worst-case scenario, can lead to a hazard. For a railway transit interlocking system, the present invention identifies 32 unsafe control actions. As shown in Table 1 below, after each UCA we add the hazard identification (H1, H2, or H3) that the UCA leads to. For example, UCA1 leads to H2.
[0086] Table 1 Unsafe control actions and related hazards:
[0087]
[0088]
[0089] On the basis of the above unsafe control behavior, the safety requirements in the system can be obtained, which cannot be violated. If violated at will, it may cause danger and further affect the safety of human life. Table 2 shows the safety requirements in the interlocking system.
[0090] Table 2 Safety requirements:
[0091]
[0092]
[0093] At this point, all safety requirements in the interlocking system are derived. The STPA technology is used in the application to comprehensively analyze the safety requirements of the interlocking system, ensuring the completeness of the safety requirements.
[0094] The application converts unsafe control behavior into linear temporal logic properties according to a plurality of defined rules.
[0095] Through unsafe control behavior (UCA) and safety requirements (SSR), control actions (CA) that may cause harm are identified and handled. Attention is paid to the harm (H) related to the control action and the process model variable (PMV), which includes state variables (train occupied section, train application for occupation section, etc.) and key variables (signal value, train position information, etc.).
[0096] Firstly, the unsafe control behavior is divided into a four-tuple (CA, Cs, C, TC) for describing the control action causing harm and the key combination of the related process model variable. Among them:
[0097] CA represents the control action causing harm H∈HA (harm set).
[0098] Cs=∪(P1=v1,…P n =v n ) is the combination of state variables and key variables of the control action CA, that is, the combination of PMV. ∪ represents the meaning of mathematical union (which can be understood as the meaning of combination), P represents various state variables, and V represents various key variables.
[0099] C is to provide or not to provide the control action, and in different cases, corresponding rules are formulated according to the provided (C1) or not provided (C2) control action.
[0100] TC is the type of providing the control action CA, which is divided into any time, too early or too late.
[0101] For example, unsafe control actions UCA6, UCA11, UCA12, and UCA16 can be further expressed using formal methods:
[0102] UCA6: When [a route section is requisitioned but the train does not leave the route section] occurs, providing RUCA6=<release the section>[any; too early; too late] is dangerous.
[0103] UCA 11 : When [Segment is occupied] occurs, provide RUCA 11 =<releasing this path>[any; too early; toolate] is dangerous.
[0104] UCA 12 : Provide RUCA when [turnouts are not all aligned to the correct position] occurs 12 = <Taking this path> [any; too early; too late] is dangerous.
[0105] UCA 16 : When [All switches are in the specified position but not locked] occurs, RUCA is not provided 16 = <Locked switches> can be dangerous.
[0106] The following rules are specified for automatically generating refined security requirements (RSSR).
[0107] Rule 1: When a critical combination Csi occurs, <Cs=∪(P1=v1,…P n =v n )>, the controller should never provide control action CAi. The conversion formula is: LTL i =G(Cs i →! (controlAction==CA i )), where Cs=∪(P1=v1,…P n =v n ), i represents any number between 1 and n, G represents the future state in the global scope, and controlAction represents the control action, namely RUCA mentioned above.
[0108] Rule 2: Before the critical combination Csi occurs, the controller should not provide control action CAi too early. The conversion formula is:
[0109] LTL i =G(((controlAction==CA i)→Csi)&! ((controlAction==CA i )∪Cs i )).
[0110] Rule 3: It states that after the critical combination Csi occurs, the controller should not provide the control action CAi too late. The conversion formula is: LTL i =G((Cs i →(controlAction==CA i ))&! (Cs i ∪(controlAction==CA i ))).
[0111] Rule 4: defines a type of software safety requirement: the occurrence of a critical combination value means that the controller must immediately provide a control action CAi in the next time without delay. The conversion formula is:
[0112] LTL i =G(Cs i →X(controlAction==CA i )), where Cs=∪(P1=v1,…P n =v n ), X represents the next state.
[0113] The following four examples are given based on the four rules for the 31 software security requirements mentioned above to illustrate how these four rules can be used to convert security requirements into LTL.
[0114] RSSR 12 :<Release the path> must be when [the switches are not all aligned to the correct position], and [any; too early; too late] are not provided. Any; too early; too late are any time, too early, and too late respectively.
[0115] Applying Rule 1, this can be converted to:
[0116] LTL 12 =G([Switch not all aligned to the correct position]→!(controlAction==release the path));
[0117] RSSR 25 :<The traffic light turns to red> must be [too late] when [the section is occupied and the traffic light is green] and is not provided.
[0118] LTL 25= G(((controlAction == signal light change to red) -> [section occupied, signal light green] &!((controlAction == signal light change to red) U [section occupied, signal light green]))).
[0119] = G(((controlAction == signal light change to red) -> [section occupied, signal light green] &!((controlAction == signal light change to red) U [section occupied, signal light green]))).
[0120] RSSR 24 : <signal light change to green> must not be provided when [all points not locked, signal light red]. Using rule 3, we can transform it to: LTL 24 = G(([all points not locked, signal light red] -> (controlAction == signal light change to green)) &!([all points not locked, signal light red] U (controlAction == signal light change to green))).
[0121] RSSR 26 : <signal light change to red> must be provided when [section occupied, signal light green]. Using rule 2, we can transform it to:
[0122] LTL 26 = G([section occupied, signal light green] -> X(controlAction == signal light change to red))
[0123] Here we only give four examples, most of the 31 safety requirements can be transformed by rule 1 and rule 2, we do not list them one by one.
[0124] 2) The reference model is obtained by modeling the rail transit interlocking system using symbolic finite state machine, calculating all evaluation functions in the rail transit interlocking system, and generating symbolic traces in the reference model according to the evaluation functions.
[0125] Symbolic finite state machine definition (SFSM)
[0126] The symbolic finite state machine is used for modeling the rail transit interlocking system, which can abstract the interlocking system in the computer, simulate the behavior of the real interlocking system, and guide the generation of test cases as a reference model. The symbolic finite state machine is a tuple M = (S, s0, R, I, O, D, ∑ I ,∑ O ). Among them:
[0127] The finite set S represents the state space, including various system states abstracted, and s0∈S is the initial state of the system.
[0128] The finite set I contains input variable symbols, and the finite set O contains output variable symbols. The sets I and O must be disjoint. We use Var to abbreviate I∪O.
[0129] An input event is an event or request that causes the system to undergo a parameter change, an environmental change, or an internal event. An output event is the processing or behavior of the system in response to these events or requests. For example, in a rail interlocking system, when a train is approaching a station, it sends a path request to the path controller. The path request is an input event, and the processing of the path controller, either granting or rejecting the request, is an output event. More specific examples are given in Figure 4 .
[0130] The set D represents the union of all variable type domains.
[0131] The input alphabet ∑ I is a finite set of input conditions, each of which is a first-order formula without quantifiers over input variables.
[0132] The input-output expressions are the machine language expressions that are converted from the natural language input-output events.
[0133] The finite output alphabet ∑ O is a set of output expressions, which are first-order formulas without quantifiers over input variables and at least one output variable. We allow constants, function symbols, and arithmetic operators in these expressions.
[0134] The set represents the transition relation. The following example models a simple SFSM for reference.
[0135] Example 1:
[0136] Figure 4 In this example, we use some states of the rail interlocking system (RIS) to illustrate the symbolic finite state machine. In the RIS, s0 is the initial state, in which the path controller is idle and waiting for a train to apply for a path.
[0137] s1 is the state in which the controller processes the path request. In this state, the path controller processes the train's path application and checks for conflicts in the path.
[0138] s2 is the state in which the controller adjusts the path. In this state, the controller converts the switches in the corresponding path to the appropriate position and locks them based on the successfully applied path information.
[0139] The state machine diagram for this example is shown below:
[0140] The following transitions (also called traces) appear in the figure, where the input event precedes the output event, e.g. train application path / controller checks path status, where the train application path is the input event and the controller checks path status is the output event. For the sake of convenience, the input and output events are identified in italics in the following.
[0141] The reference model SFSM modeled in the above figure is: SFSM RIS = (S RIS , s1, R RIS , I RIS , O RIS , D RIS ,∑ I RIS ,∑ O RIS )
[0142] The reference model SFSM is obtained by modeling the railway traffic interlocking system using the symbolic finite state machine RIS = (S RIS , s1, R RIS , I RIS , O RIS , D RIS ,∑ I RIS ,∑ O RIS ), S RIS is the state space and S RIS = {s0, s1, s2}, s0 is the initial state, s1 is the controller handles path request state, s2 is the controller adjusts path state, I RIS is the variable symbol of input events, O RIS is the variable symbol of output events, D RIS is the union on all variable type domains,∑ I RIS is the input alphabet,∑ O RIS is the output alphabet. Its variable symbols are I RIS = {x}, O RIS = {y}, the type domain D RIS , which indicates the input range. The input alphabet of RIS can be rewritten as:
[0143] ∑ I RIS = {train application path, path has conflict, path has no conflict, switch fault, all switch positions are correct and locked};
[0144] The input alphabet above does not convert input events into input expressions. For ease of understanding, the input events are converted into input expressions in sequence: PREserve, Conflict, No Conflict, Point Error, AllPoint = Right and Lock. The formal input alphabet is:
[0145] ∑ I RIS ={PReserve, Conflict, No Conflict, Point Error, All Point=Right and Lock};
[0146] Likewise, the output alphabet can be expressed as:
[0147] ∑ O RIS ={Controller checks the path status, controller cancels the route application, controller adjusts the switch position, controller feedback fault information, signal light turns green, train is allowed to enter} Similarly, we convert the output events into output expressions in sequence:
[0148] Pcheck, PCancel, Switch Point, Feedback Error, Green. The formal output alphabet is:
[0149] ∑ O RIS ={Pcheck, PCancel, Switch Point, Feedback Error, Green};
[0150] The conversion relationship can be expressed as:
[0151] R RIS ={(s0, train applies for a route, controller checks the route status, s1),(s1, there is a conflict in the route, controller cancels the route application, s0),(s1, switch failure, controller feedback failure information, s2),(s2, there is no conflict in the route, controller adjusts the switch position, s1),(s2, all switches are in the correct position and locked, the signal light turns green, and the train is allowed to enter, s0)}.
[0152] The evaluation function σ maps each input-output expression v (represented by input event I and output event O) to its corresponding type value σ(v). For the expression ψ from Var, Denote σ as a model of ψ.
[0153] Example 2:
[0154] The valuation function is a way of modeling specific input events and corresponding output events in the system. It represents a specific input-output event. For example, a valuation function It represents a specific example of when there is a section conflict in the path, the system cancels the controller's application for the route, and prevents the train from entering. That is, sigma is a specific example of (phi, psi) = (x = there is a conflict in the path, y = the controller cancels the application for the route), and psi represents the output expression, and phi represents the input expression. For the event of there being a conflict in the path, whether it is a section 1 conflict or a section 2 conflict, the system will determine that there is a conflict in the path and trigger this input event. Therefore, and are all models describing (phi, psi) = (x = there is a conflict in the path, y = the controller cancels the application for the route).
[0155] The role of the valuation function is to identify and classify specific input-output events. The identification of these events plays a guiding role in the generation of symbolic traces and concrete traces, and also provides a basis for further improving the reference system SFMS. At the same time, it also provides a basic idea for the equivalence class division later. In this step, all valuation functions in the system are calculated for subsequent use.
[0156] For any set X, we use X * to represent the set of finite sequences, and X ω to represent the set of infinite sequences, which are used to describe test sequences and formulas related to safety requirements.
[0157] The reference model M of the present application (hereinafter referred to as SFSM M, or referred to as M for short) represents a model of the system operating normally without faults or errors, and its symbolic trace is a finite sequence:
[0158] tau = (phi1 / psi1)...(phi n / psi n ) belongs to (sum I x sum O ) * satisfies:
[0159]
[0160] The symbolic trace is a finite sequence composed of multiple consecutive (phi i , psi i ), which represents an execution path during testing. For example, in the SFSM shown in Figure 4 , if the system needs to test the path from state s0 to s1 and then to s2, it needs to test the following three sequences in order:
[0161] (φ1, ψ1) = (x = train applied route, y = controller checked route status), (φ2, ψ2) = (x = route is conflict free, y = controller adjusted switch position), (φ3, ψ3) = (x = all switch positions are correct and locked, y = signal light turned green, train allowed to enter). For this test, the symbolic trace τ is the concatenation of these three sequences, i.e., τ = (φ1, ψ1). (φ2, ψ2). (φ3, ψ3).
[0162] Using (φ i / ψ i ) to denote these input-output expressions, φ i represents the input and ψ i represents the output. The set of symbolic traces of M is denoted by T(M) (used later).
[0163] Example 3:
[0164] Some symbolic traces of the interlocking system reference model (SFSM RIS) are as follows:
[0165] τ1= ε, ε represents the empty set.
[0166] τ2= (x = route is conflict free, y = controller canceled applied route). (x = route is conflict free, y = controller canceled applied route). (x = route is conflict free, y = controller canceled applied route);
[0167] A symbolic path of the SFSM M is an infinite sequence composed of symbolic traces.
[0168] In the field of modeling formalisms of systems, the behavior (or language) of the SFSM M is usually defined by its concrete traces set and denoted by .
[0169] A concrete trace of M is a finite sequence of valuation functions
[0170] κ= σ 1 ...σ n ∈ (D Var ) * ;
[0171] such that M has a symbolic trace τ = (φ1 / ψ1)...(φ n / ψ n ) satisfying:
[0172] If this condition is satisfied, κ is called a witness of τ and the shorthand notation
[0173] Example 4:
[0174] For the symbolic trace τ2, is the concrete input event where the condition (x = conflict in path) occurs, and is also the witness of the symbolic trace τ2, as shown in Example 3. The symbolic trace ranges over a larger set of concrete traces, with the concrete trace representing a concrete event belonging to this range.
[0175] The concrete paths of M are an infinite sequence of concrete traces.
[0176] As in the field of system modeling formalisms, the behavior (or language) of an SFSM M is defined by its set of concrete traces, and is denoted as Two SFSMs are (language) equivalent if and only if they have the same set of concrete traces.
[0177] To describe the safety requirements of a given SFSM M, the linear temporal logic LTL is used. The syntax of an LTL formula φ is given by the following grammar: where φ ∈ AP represents an atomic proposition, written as a symbolic expression from Var.
[0178] The LTL properties in the foregoing have been derived. Here, it is only necessary to convert the derived LTL into the set of atomic propositions AP.
[0179] Here, the traces that include safety requirements are referred to as proposition traces, in order to distinguish them from the symbolic traces and concrete traces introduced earlier. A safety property is a set of proposition traces P, satisfying
[0180]
[0181] Intuitively, any proposition trace that violates a safety property P (i.e. ) can be identified by a finite prefix π' < π, called a bad prefix, such that any subsequent input event of π' never satisfies the safety property P. Safety properties are exactly those safety requirements that can be detected on finite traces. Therefore, the present invention is a conformance test for safety properties. The set of all safety properties is exactly the set of atomic propositions AP.
[0182] Example 5:
[0183] For the example of the reference model RIS in Figure 4 , two safety properties are considered. In natural language, they are formulated as two requirements:
[0184] R1: When there is a conflict in the path, the train cannot forcibly take the path.
[0185] R2: When all the switches are not all aligned to the correct position, the train cannot take the path.
[0186] The conversion to LTL is
[0187] φ1≡(y≠train_occupying_path)W(x=path_conflict)
[0188] φ2≡(y≠train_occupying_path)W(x=all_switches_not_aligned)
[0189] According to the definition of the operator W, the formula φ1 expresses one of the following two cases: on the infinite transition condition (trace), either (x=path_conflict) never occurs and (y≠train_occupying_path) holds globally, or (x=path_conflict) eventually occurs, but at that time it is ensured that (y≠train_occupying_path) holds at least on the trace prefix ending with (x=path_conflict), i.e., before x=path_conflict. The process of transforming R2 into φ2 is also like that of R1. The atomic propositions that appear in φ1 and φ2, respectively, are AP1={y≠train_occupying_path, x=path_conflict} and AP2={y≠train_occupying_path, x=all_switches_not_aligned}.
[0190]
[0191] Proposition abstraction is a method that maps valuation functions to sets of atomic propositions that are satisfied, which helps to identify which specific traces correspond to which LTL safety requirements. Through this method, when testing specific traces, it can be verified at the same time whether the valuation function satisfies its corresponding LTL safety requirements.
[0192] Let AP be a set of atomic propositions. A proposition abstraction ω maps specific traces to the sets of atomic propositions that they satisfy. For a valuation σ belonging to D Var , ω(σ) is the set of atomic propositions that are satisfied by the valuation function σ, denoted as:
[0193] ω: (D Var )→2 AP ;
[0194] By recursive definition, ω can be extended to valuation sequences and specific traces:
[0195] ω: (D Var ) * →(2 AP ) * , ω(ε)=ε and ω(σ.κ)=ω(σ).ω(κ), where σ∈D Var , κ∈(D Var ) * .
[0196] Example 6: For the specific trace in Example 4:
[0197]
[0198] AP = {y ≠ train cannot requisition path, x = there is a conflict in the path};
[0199] The following is the abstracted proposition trace:
[0200] ω(κ2) = {y → train cannot requisition path}. {y → train cannot requisition path}. {y → train cannot requisition path};
[0201] For a safety formula φ and a finite proposition trace π' ∈ (2 AP ) * , π' is a bad prefix of φ if and only if This means that any infinite proposition trace with π' as a prefix will be a model of , i.e., violates the safety property. When none of the concrete traces of M can be abstracted by ω as a bad prefix of φ (i.e., ), the SFSM M is a model of the LTL safety formula φ (written as ).
[0202] In this step, the proposition abstraction that satisfies all safety requirements is found.
[0203] In black-box testing, the purpose of introducing a fault domain is to limit the possible error behaviors of the system, so as to ensure that the test suite can effectively cover various cases of the system. By defining the fault domain, testers can more targetedly design test cases to verify the system's processing ability for various fault conditions.
[0204] The error behavior of the system under test may deviate from the reference SFSM, including:
[0205] Error or changed input expressions;
[0206] Error or changed output expressions;
[0207] Transmission faults, including additional, missing or incorrect transitions;
[0208] Additional or missing states.
[0209] The normal SFSM model, plus the various error behaviors that may occur, constitutes the fault domain, which is defined as a set of SFSM i , with the following properties:
[0210] M i has at most m ≥ n states. n represents the number of states in M, and m represents the number of states in M i , because M represents the model of the system when it is running normally and no faults occur, M iThe state when an error can occur so m ≥ n, (equal when no error occurs). Both are natural numbers greater than or equal to 0.
[0211] M i Reference the input I and output O expressions from M.
[0212] M i Use the input expressions (∑ I ) and output expressions (∑ O ).
[0213] These M i constitute the fault domain, in which the test case generation and execution are performed in the test phase. We call the fault domain containing the SFSM M and various M i the system under test SFSM M' (hereinafter referred to as M').
[0214] The alphabet of the fault domain D is the union of all input conditions, output expressions, and atomic propositions of the formula to be verified ∑ = ∑ I ∪ ∑ O ∪ AP.
[0215] Because the fault domain contains possible error behaviors, M' can perform a transmission fault and use input and output expressions that have never been referenced by the reference model M. In addition, M' can use input and output expressions from the alphabet of the reference model with arbitrary transitions. For the actual construction of the fault domain D, all input conditions and output expressions that occur in the reference model can be collected, and all potential mutations of input and output expressions that are expected to occur in the fault implementation can be added.
[0216] 3) Improve the reference model and divide the input and output events of the reference model into equivalence classes in combination with linear temporal logic properties.
[0217] In this step, the basic method of equivalence class construction is as follows:
[0218] 1. Let ∑ = ∑ I ∪ ∑ O ∪ AP, ∑ is the set of all expressions that occur in the input and output expressions and LTL specifications. Among them, ∑ I represents the input alphabet, ∑ O represents the output alphabet, and AP represents the set of atomic propositions, i.e., the set of LTL safety formulas.
[0219] 2. For any set P , define a new formula that is a combination of formulas from P and negated formulas from the complement ∑ \ P:
[0220]
[0221] where e represents any expression belonging to the set P.
[0222] 3. Construct a set of input / output expressions ∑ = {σ | σ∈D Var The set of all formulas φ that are models:
[0223]
[0224] where D Var represents the input / output expressions in the global scope, 2 ∑ represents the safety properties in ∑, φ P represents the formulas φ that satisfy the safety properties P.
[0225] 4. For each φ∈P, define an input / output equivalence class io(φ):
[0226]
[0227] 5. Let φ = {io(φ) | φ∈P} represent the set of all input / output equivalence classes.
[0228] The details are as follows:
[0229] The set of input / output expressions ∑ that satisfy the safety requirements constructed in Step 1 is:
[0230] ∑ = ∑ I RIS ∪ ∑ O RIS ∪ AP;
[0231] where, ∑ O RIS represents the input alphabet of the reference model, ∑ O RIS represents the output alphabet of the reference model, AP represents the set of atomic propositions of the linear temporal logic property transformation; the set ∑ contains the concrete traces.
[0232] P in Step 2 is the set of all traces in ∑. Suppose P1 is an input / output equivalence class, for example, it can be the large category of path existence problems, because no matter whether there is a section conflict or the turnout position is incorrect or not locked, the system will not allow the train to occupy the corresponding path, and they all have the same output. Therefore, these events can be classified into the large category of path existence problems. When testing, we can simply test a few representative test cases in the same class instead of testing all test cases. This reduces the time-consuming of testing.
[0233] In order to better understand the above formulas, the following three Boolean values are defined:
[0234] B.occ i B.occ represents the occupancy state of section i, which is true if section i is occupied and false if section i is not occupied.
[0235] B-occ≡¬B.occ i ¬B.occ = false means that all sections are not occupied. It is obvious that the negation of B-occ P.occ represents that there is at least one section in the path which is occupied.
[0236] P.pos i P.pos represents the position state of turnout i, which is true if turnout i is in the right position and false if turnout i is not in the right position.
[0237] P-pos≡¬P.pos i ¬P.pos = true means that all turnouts are in the right position. It is obvious that the negation of P-pos P.occ represents that there is at least one turnout in the path which is not in the right state.
[0238] P.lock i P.lock represents the lock state of turnout i, which is true if turnout i is locked and false if turnout i is not locked.
[0239] P-lock≡¬P.lock i ¬P.lock = true means that all turnouts are locked. It is obvious that the negation of P-lock P.occ represents that there is at least one turnout in the path which is not locked.
[0240] Then the formula of the big class (i.e. P1) of the path which has problems should be:
[0241]
[0242] This means that, no matter whether a section is occupied or a turnout has a fault, it will be classified into the P1 class.
[0243] Thus, the second step is to classify all the input-output big classes according to the set of input-output expressions ∑.
[0244] The third step is to find all the specific traces which satisfy the above input-output big classes, i.e. the evaluation functions σ, and to find the set of evaluation functions φ according to the input-output big classes respectively.
[0245] The fourth step is to define these sets φ as the equivalence class evaluation sets io(φ) respectively.
[0246] Furthermore, in situations where the system under test may use faulty input expressions, it is not sufficient to create input classes using only a subset of the input events appearing in the reference model, as faulty input events must also be considered. Furthermore, different atomic propositions may apply to different inputs that satisfy the same input event. Therefore, the paths of the input / output equivalence classes depend on the complete input and output alphabets specified by the fault domain, as well as the atomic propositions appearing in the formulas to be verified.
[0247] For the valuation set io(φ), the following relationship exists:
[0248]
[0249] ~ ∑ It is defined as an equivalence relation that satisfies the requirement D Var ×D Var The form of σ~ ∑ σ' means σ and σ' satisfy ~ ∑ This equivalence relationship, (equivalent to the symbol) means that the two are equivalent. In short, when the two evaluation functions are a subset of the alphabet They are equivalent only if they have the same expression in the model. Two classes io(φ with P≠P' P ),io(φ P' ) are disjoint, since any expression e in P\P' must be represented by io(φ P ) in each σ (i.e. ) satisfies, and io(φ P' ) must satisfy vice versa.
[0250] For alphabets with symbols ∑=∑ I ∪∑ O The reference model SFSM M of ∪AP is assumed to have been improved so that its symbol trace is represented by the set T(M) of input / output sequences, obtaining the improved reference model.
[0251] For an SFSM M, if there exists a pair of symbol traces α, β∈T(M) that satisfy the following condition, then they are called distinguishable traces of M: there exists a symbol input / output sequence γ∈T(M) such that α.γ is a symbol trace of M, but β.γ is not; and vice versa. This condition is expressed as follows:
[0252]
[0253] If α and β are distinguishable, we say that γ in the formula distinguishes α and β, and use △(α,β) to represent the set of all distinguishing sequences:
[0254]
[0255] If a. g is a symbolic trace of M, then all concrete traces of a. g are contained in L(M). Conversely, if then no concrete trace of a. g is in L(M).
[0256] Correspondingly, for a proposition abstraction w, there is also a definition of the distinguished set of abstract traces:
[0257]
[0258] In black-box testing, since the state of the system under test is unknown, in order to distinguish different states and identify whether the current test reaches the target state we want, a distinguished trace is needed to distinguish different states.
[0259] 4) Generating test cases based on the symbolic traces of the improved reference model, executing the test cases on the system under test, and detecting whether the system under test meets the safety requirements of the rail interlocking system.
[0260] Generating test cases based on the symbolic traces of the improved reference model, specifically:
[0261] Step a. Construct a minimal state cover set V containing the improved reference model as the set of test cases, which is a set of symbolic traces on the input / output expressions of the reference model; ensure that the test cases can cover every state in the system.
[0262] Step b. Find a symbolic distinguished trace g for each pair of different symbolic traces a, b e V, and add a. g, b. g to the test cases; ensure that different states in the system can be identified. At the same time, because the test aims to test whether the system under test M' is equivalent to the reference model M, if equivalent, it is a consistency test that meets the safety requirements, if not equivalent, the test fails. Therefore, the goal of the test cases created in steps a and b is also to check whether the state cover set V of the reference model M can cover every state in the system under test M' and can be used for the same g distinction of the reference model. If not, the test fails, because the internal state space and transition structure of the system under test M' are very different from the reference model M, so the system under test must not be equivalent to the model.
[0263] Step c. Extend the test cases by a set T consisting of symbolic traces, each trace consisting of a prefix of the state cover set V and a suffix of any symbolic trace of the set A of all input / output equivalence classes.
[0264] Execute test cases on the system under test to check whether the system under test meets the safety requirements of the rail transit interlocking system. Specifically:
[0265] Execute the test cases generated in steps a, b, and c on the system under test respectively. If the system under test does not output a fault, the test passes, that is, the system under test meets the safety requirements of the rail transit interlocking system; if the system under test outputs a fault, the test fails and the system under test needs to be corrected.
[0266] Specifically, the test case generation procedures for steps a, b, and c above are as follows:
[0267] 1. The test case set (TS) contains the minimum state cover set V of M, where ε∈V.
[0268] 2. For any two different symbol traces α, β∈V, there exists γ∈△(α, β) such that α.γ, β.γ∈TS.
[0269] 3.TS is constructed by the following collection:
[0270]
[0271] 4. For satisfaction For any α∈V and β∈T∩T(M), there exists γ∈△(α,β) such that α.γ, β.γ∈TS.
[0272] 5. For satisfying α∈Pref(β) and For any α, β∈T∩T(M), there exists γ∈△(α, β) such that α.γ, β.γ∈TS.
[0273] State Covering Set The set of symbolic traces of the input / output expressions of M is guaranteed to exist for any state s∈S of M, such that an input-output expression υ∈V exists such that s0-after-υ = s. In short, it guarantees that the system can reach every state after executing the state coverage set V. This further ensures that the generated test cases will not affect the test results due to missing states. Here, the empty trace ε is also included in the state coverage because it can reach the initial state.
[0274] Let M, M'∈D(I,O,D,∑ I ,∑ O ,AP,n,m) are two symbolic finite state machines (SFSMs) in the same fault domain, where M is the reference model with n states and M' is the system under test. If the reference model M and the system under test M' are equivalent in the test, it is necessary to:
[0275] TS∩T(M)=TS∩T(M').
[0276] Intuitively, this means that M and M' have exactly the same pass rate for the corresponding symbolic test cases.
[0277] In the present application, the system under test M' is a modified reference model with added fault domains, which are all the erroneous behaviors that occur, using all the input conditions and output expressions that occur in the reference model, and adding all the potential input and output expressions that are expected to occur in the fault implementation.
[0278] In addition, if the system under test has transmission faults, these faults can cause a violation of the safety requirements satisfied by the reference model. This will be tested by the test cases created in steps 4 and 5, because omega (alpha) is a propositional abstraction that is associated with safety requirements, so executing these test cases will detect transmission faults to prevent the system from violating safety requirements.
[0279] After all the test cases are executed, if the test does not fail, the system under test behaves the same as the real system and satisfies the safety requirements, and is safe. If the test fails, it means that there is an error in the system, and the system needs to be further corrected.
[0280] Based on this, the present application also provides a track interlocking system completeness test case generation system, which adopts the track interlocking system completeness test case generation method described above, and comprises:
[0281] An STPA analysis module is configured to analyze safety requirements of the track interlocking system by using the STPA method, and convert the safety requirements into linear temporal logic properties.
[0282] A modeling module is configured to model the track interlocking system by using a symbolic finite state machine to obtain a reference model, calculate all evaluation functions in the track interlocking system, and generate symbolic traces in the reference model according to the evaluation functions.
[0283] An equivalence class division module is configured to improve the reference model, and divide input and output events of the reference model into equivalence classes in combination with the linear temporal logic properties.
[0284] A test module is configured to generate test cases based on the symbolic traces of the improved reference model, execute the test cases on the system under test, and detect whether the system under test satisfies the safety requirements of the track interlocking system.
[0285] The above is only a specific embodiment of the present application, but the design concept of the present application is not limited thereto, and any non-essential modification of the present application using this concept shall be deemed as an act of infringing the protection scope of the present application.
Claims
1. A method for generating completeness test cases for a rail transit interlocking system, characterized in that: include: Apply the STPA method to analyze the safety requirements of rail transit interlocking systems and convert the safety requirements into linear temporal logic attributes; Modeling the rail transit interlocking system using a symbolic finite state machine to obtain a reference model, calculating all valuation functions in the rail transit interlocking system, and generating symbol traces in the reference model based on the valuation functions; Improve the reference model and divide the input and output events of the reference model into equivalence classes in combination with the linear temporal logic attributes; Generating a test case based on the symbolic trace of the improved reference model, executing the test case on the system under test, and detecting whether the system under test meets the safety requirements of the rail transit interlocking system; The STPA method is used to analyze the safety requirements of the rail transit interlocking system, including: System modeling: Modeling the control structure and control process of rail transit interlocking systems; Control structure analysis: identifying the relationships and interactions between multiple control components of the control structure; Control process analysis: Analyze the control process of the rail transit interlocking system, including the control logic of signal lights, the switching process of switches, and the control strategy for trains entering and leaving the station; Identify safety constraints: Based on the control structure and the control process, identify the control operations and environmental conditions that lead to adverse events; Analyze and assess risks: Analyze identified safety constraints, assess their potential impact on the safety of the rail transit interlocking system, and identify unsafe control behaviors that may lead to accidents; Derivation of safety requirements: inverting the unsafe control behavior to obtain the safety requirements of the rail transit interlocking system; The reference model is improved, and the input and output events of the reference model are divided into equivalence classes in combination with the linear temporal logic attributes, as follows: The set of input and output expressions ∑ that are constructed to meet the security requirements is: ∑=∑ I RIS ∪∑ O RIS ∪AP Among them, ∑ O RIS represents the input alphabet of the reference model, ∑ O RIS represents the output alphabet of the reference model, AP represents the set of atomic propositions of the linear temporal logic attribute transformation; Divide all input and output categories according to the set ∑ of the input and output expressions; Find all specific traces that satisfy the above input and output categories, i.e., the valuation functions σ, and find their valuation function sets φ according to the above input and output categories; The test cases are generated based on the symbolic trace of the improved reference model, specifically: Step a. Constructing a minimum state cover set V of the improved reference model as a set of test cases, which is a set of symbol traces on the input / output expressions of the reference model; Step b. Find a symbolic distinguishing trace γ for each pair of distinct symbolic traces α, β∈V and add α.γ, β.γ to the test case; Step c. Extend the test case by a set T of symbolic traces, where each trace consists of a prefix of the state coverage set V and a suffix of any symbolic trace of the set A of all input / output equivalence classes.
2. A rail transit interlocking system integrity test case generation method according to claim 1, characterized in that: The unsafe control behavior is converted into linear temporal logic attributes according to a plurality of defined rules.
3. A rail transit interlocking system integrity test case generation method according to claim 1, characterized in that: The rail transit interlocking system is modeled using a symbolic finite state machine to obtain a reference model SFSM RIS =(S RIS ,s1,R RIS , I RIS , O RIS , D RIS ,∑ I RIS ,∑ O RIS ), S RIS is the state space and S RIS ={s0, s1, s2}, s0 is the initial state, s1 is the controller processing path request state, s2 is the controller adjusting path state, I RIS is the variable symbol of the input event, O RIS is the variable symbol of the output event, D RIS is the union of all variable type domains, ∑ I RIS is the input alphabet, ∑ O RIS is the output alphabet.
4. A rail transit interlocking system integrity test case generation method according to claim 1, characterized in that: Calculate all valuation functions in the rail transit interlocking system, generate symbolic traces in the reference model based on the valuation functions, and map each input-output expression v in the rail transit interlocking system to a corresponding type value σ(v) in the reference model through the valuation function σ.
5. A rail transit interlocking system integrity test case generation method according to claim 1, characterized in that: Executing the test case on the system under test to detect whether the system under test meets the safety requirements of the rail transit interlocking system is specifically: Executing the test cases generated in steps a, b, and c on the system under test respectively. If the system under test does not output a fault, the test is passed, that is, the system under test meets the safety requirements of the rail transit interlocking system. If the output of the system under test fails, the test fails and the system under test needs to be corrected.
6. A rail transit interlocking system integrity test case generation method according to claim 1, characterized in that: The system under test refers to the improved reference model with the addition of fault domains, where the fault domains are various erroneous behaviors that occur. The fault domains adopt all input conditions and output expressions that appear in the reference model and add mutations of all potential input and output expressions that are expected to appear in the fault implementation.
7. A rail transit interlocking system integrity test case generation system, characterized in that: include: The STPA analysis module uses the STPA method to analyze the safety requirements of the rail transit interlocking system and converts the safety requirements into linear temporal logic attributes; a modeling module, which models the rail transit interlocking system using a symbolic finite state machine to obtain a reference model, calculates all valuation functions in the rail transit interlocking system, and generates symbolic traces in the reference model based on the valuation functions; An equivalence class division module improves the reference model and divides the input and output events of the reference model into equivalence classes in combination with the linear temporal logic attributes; A testing module generates test cases based on the symbolic trace of the improved reference model, executes the test cases on the system under test, and detects whether the system under test meets the safety requirements of the rail transit interlocking system.
Citation Information
Patent Citations
Function security hazard and information security threat analysis method based on STPA model
CN110008607A
Completeness test case generation method based on symbolized finite-state machine
CN118409972A