Triple-redundancy flight control system safety analysis method based on timed automaton

By constructing the clock model and fault model of the three-dimensional flight control system based on time automatons, and using formal verification tools to automatically verify the safety attributes of the system, the problem of strong subjectivity of the analysis results in traditional methods is solved, and more efficient and accurate safety analysis is achieved.

CN120491424AActive Publication Date: 2025-08-15XIAN FLIGHT SELF CONTROL INST OF AVIC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510537178.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-08-15
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

The traditional Sanyudu flight control system safety analysis method is highly subjective, and the accuracy of the analysis results depends on the personal level of the engineer. It is difficult to comprehensively and accurately analyze the system's fault logic relationship, especially in systems with dynamic reconstruction characteristics, fault timing correlation and logic correlation, which makes it difficult to ensure the accuracy and comprehensiveness of safety analysis.

Method used

Using a time-automatic method, the clock model and fault model of the Sanyudu flight control system are constructed, and the security properties of the system are automatically verified through formal verification tools to ensure the safety of the system design.

Benefits of technology

It improves the comprehensiveness and accuracy of safety analysis of Sanyudu flight control system, reduces the work burden of designers, improves verification efficiency, and can be applied to verification methods of similar systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120491424A_ABST
    Figure CN120491424A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of civil aircraft flight control system verification, and particularly relates to a three-redundancy flight control system safety analysis method based on a timed automaton. Comprising the steps of determining a clock period and a random drift range of each component; the method comprises the following steps of: constructing a clock model by adopting a time automaton and a clock period and a random drift range of a component of a three-redundancy flight control system, wherein the modeling semantics of the time automaton comprises location, guard, invariant and channel; based on the architecture and the clock model of the three-redundancy flight control system, constructing a formal model of the three-redundancy flight control system based on the timed automaton; constructing a fault model on the basis of the formal model of the three-redundancy flight control system based on the timed automaton, wherein faults comprise crash, bus transmission and transient faults; performing safety analysis on the three-redundancy flight control system to obtain safety attributes based on the three-redundancy flight control system, and expressing the safety attributes as formalized protocols; and verifying whether the fault model meets the formalized specification or not by adopting a formalized verification tool.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of civil aircraft flight control system verification, and in particular relates to a safety analysis method for a triple-redundant flight control system based on a timed automaton. Background Art

[0002] The triple-redundant flight control system distributes flight control function master / backup decisions and fault handling across three flight control computers (FCMs) and four flight control actuators (ACEs) to achieve system reliability. Therefore, these seven components and their associated bus transmissions must agree on the system's master / backup decisions, such as which flight control computer (FCM) is currently the master. Internal failures in a triple-redundant flight control system are frequent and random, and the seven components operate on independent clocks. Consequently, the diverse combinations of system failures and the asynchronous nature of the components can lead to the possibility of concurrent failures and clock asynchrony.

[0003] Traditional system safety analysis methods are highly subjective, and the accuracy of the analysis results is highly dependent on the engineer's own level of expertise. For the same system, different engineers may develop very different safety analysis models due to differences in knowledge and thinking. Furthermore, for a triple-redundant flight control system with dynamic reconfiguration characteristics and fault timing and logic dependencies, manually analyzing the system's fault logic relationships has become unrealistic. Even if analysis is possible, its comprehensiveness and accuracy are difficult to guarantee. Failure to conduct adequate safety analysis of the triple-redundant flight control system will further impact aircraft safety in the future. Summary of the Invention

[0004] The purpose of the invention is to provide a safety analysis method for a triple-redundant flight control system based on a timed automaton to improve the comprehensiveness and accuracy of fault logic relationships.

[0005] Technical solution:

[0006] A safety analysis method for a triple-redundant flight control system based on timed automata includes:

[0007] Step 1: Determine the clock period and random drift range of each component based on the crystal oscillator frequency and drift of the clocks used by the seven components of the triple-redundant flight control system;

[0008] Step 2: Construct a clock model using a timed automaton and the clock periods and random drift ranges of the components of the triple-redundant flight control system. The modeling semantics of the timed automaton include location, guard, invariant, and channel.

[0009] Step 3: Based on the architecture and clock model of the triple-redundant flight control system, construct a formal model of the triple-redundant flight control system based on timed automata;

[0010] Step 4: Construct a fault model based on the formal model of the triple-redundant flight control system based on timed automata. Faults include freeze, bus transmission, and transient faults.

[0011] Step 5: Perform safety analysis on the triple-redundant flight control system, obtain safety attributes based on the triple-redundant flight control system, and express them as formal specifications;

[0012] Step 6: Use formal verification tools to verify whether the fault model meets the formal specifications.

[0013] Preferably, in step 1, the clock period of the component is taken as the crystal oscillator frequency of the clock used by the component, and the random drift range of the clock of the component is taken from the crystal oscillator drift of the clock used by the component.

[0014] Preferably, step 2 specifically includes:

[0015] Step 21: Use timed automaton semantics to construct a clock array. The clock array contains 7 elements, corresponding to the 7 components of the triple-redundant flight control system.

[0016] Step 22: For each clock array element, use timed automaton semantics to construct the clock's starting location and loop location;

[0017] Step 23: Add guard and invariant conditions of the timed automaton between the starting location and the loop location based on the clock period and random drift range, where the guard condition is "t>[clock period - maximum drift]" and the invariant condition is "t<=[clock period + maximum drift]";

[0018] In step 24, using timed automaton semantics, add a clock channel to the guard to send a signal.

[0019] Preferably, step 3 specifically includes:

[0020] Step 31: Perform an object-oriented abstraction summary on the functional architecture of the triple-redundant flight control system, abstracting the flight control computer FCM and the flight control actuator ACE classes. Based on these classes, create empty templates for the flight control computer FCM and the flight control actuator ACE based on the timed automaton.

[0021] Step 32: Fill the flight control computer FCM master / slave switching function logic into the flight control computer FCM empty template based on the timed automaton to form a flight control computer FCM formal model template;

[0022] Step 33: Fill the flight control actuation electronic ACE master / standby voting function logic into the empty template of the flight control actuation electronic ACE based on the timed automaton to form a formalized model template of the flight control actuation electronic ACE;

[0023] Step 34: Create three instances based on the flight control computer FCM formal model template to form a triple-redundant flight control computer FCM;

[0024] Step 35: Create four instances based on the flight control actuation electronic ACE formal model template to form a quad-redundant flight control actuation electronic ACE;

[0025] Step 36: Drive the 3-redundant flight control computer FCM and the 4-redundant flight control actuator ACE based on the clock array, where each clock array element corresponds to a corresponding instance, and each instance receives the signal from the clock channel channel in step 24, forming a formal model of the 3-redundant flight control system.

[0026] Preferably, step 4 specifically includes:

[0027] Step 41: Based on the modeling semantics of the timed automaton, set the crash, bus transmission and transient faults. The faults are independent and may occur at any time.

[0028] Step 42: Add the set fault to the formal model of the triple-redundant flight control system based on timed automata to obtain a fault model.

[0029] Preferably, in step 41,

[0030] The crash failure is caused by multiple consecutive clock drives, and the functional logic of this component fails to run successfully;

[0031] Bus transmission failure means that the data sent by the component is incorrect or the data received by the component is incorrect;

[0032] A transient fault is a fault that occurs suddenly at a certain moment and returns to normal immediately at the next moment.

[0033] Preferably, step 5 specifically includes:

[0034] Step 51: Perform safety analysis on the triple-redundant flight control system to form safety attributes;

[0035] Step 52: Use the formal specification semantics of timed automata, TCTL, invariant form, and system runtime to describe the security attributes as a formal specification.

[0036] Preferably, step 6 specifically includes:

[0037] If the fault model satisfies the formal specification, the formal verification result is satisfied; otherwise, the formal verification result is not satisfied. The operating scenario of the fault model that does not meet the formal specification is a counterexample. The counterexample content is the operating sequence of the triple-redundant flight control system. The sequence includes the key nodes of component clock triggering, component functional logic operation, and fault occurrence, which is used by system designers to understand and modify the system design.

[0038] Beneficial effects:

[0039] The method of the present invention, for a triple-redundant flight control system, uses a fault formal modeling and verification method and utilizes model checking to exhaustively search all state spaces of the triple-redundant flight control system, including various asynchronous clock trigger timings and interleaved execution sequences, to ensure the safety of the system design. The method has the following beneficial effects: 1. Automatically verifies whether the triple-redundant flight control system meets safety attributes under various faults and their combinations; 2. Reduces the workload of designers and increases verification efficiency and accuracy; 3. Has strong versatility and can be applied to verification methods of similar systems in other fields; 4. Improves the safety of the triple-redundant flight control system. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] To more clearly illustrate the technical solutions implemented in the present invention, the following briefly explains the drawings required for use in the present invention. It is obvious that the drawings described below are only some embodiments of the present invention, and those skilled in the art can derive other drawings based on these drawings without inventive effort.

[0041] Figure 1 Schematic diagram of the formal modeling principle of the injection fault of the triple-redundant flight control system provided by the embodiment of the present invention.

[0042] Figure 2 A schematic diagram of clock modeling based on a timed automaton provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0043] To make the purpose, technical solutions and advantages of the present invention more clearly understood, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other in any manner.

[0044] As explained in the above background technology, traditional system safety analysis methods for triple-redundant flight control systems are highly subjective, and the accuracy of the analysis results is highly dependent on the engineer's own level of skill. For the same system, due to differences in knowledge and thinking methods, the safety analysis models established by different engineers may vary greatly. In addition, for triple-redundant flight control systems with dynamic reconstruction characteristics, fault timing correlation, and logical correlation, it has become unrealistic to analyze the system's fault logical relationships through manual reasoning. Even if analysis is possible, its comprehensiveness and accuracy are difficult to guarantee.

[0045] The technical solution provided by the embodiment of the present invention uses a fault formal modeling and verification method for a triple-redundant flight control system, and utilizes mathematical methods to exhaustively traverse various asynchronous clock trigger timings and interleaved execution sequences of the triple-redundant flight control system to ensure the safety of the system design. The automated verification of whether the triple-redundant flight control system meets safety properties under various faults and their combinations reduces the workload of designers and increases verification efficiency and accuracy. The solution is highly versatile and can be applied to verification methods for similar systems in other fields, thereby improving the safety of the triple-redundant flight control system.

[0046] The present invention provides the following specific embodiments that can be combined with each other. The same or similar concepts or processes may not be described in detail in some embodiments.

[0047] The safety analysis method of a triple-redundant flight control system provided in an embodiment of the present invention includes the following steps:

[0048] Step 1: Determine the clock period and random drift range of each component based on the crystal oscillator frequency and drift of the clocks used by the seven components of the triple-redundant flight control system, including three flight control computers (FCMs) and four flight control actuators (ACEs);

[0049] Step 2: Construct a clock model using a timed automaton and the clock periods and random drift ranges of the components of the triple-redundant flight control system. The modeling semantics of the timed automaton include location, guard, invariant, and channel.

[0050] Step 3: Based on the architecture and clock model of the triple-redundant flight control system, a formal model of the triple-redundant flight control system based on timed automata is constructed;

[0051] Step 4: construct a fault model based on the formal model of the triple-redundant flight control system based on timed automata. Faults include freeze, bus transmission, and transient faults.

[0052] Step 5: Perform safety analysis on the triple-redundant flight control system, obtain safety attributes based on the triple-redundant flight control system, and express them as formal specifications;

[0053] Step 6: Use formal verification tools to verify whether the fault model meets the formal specifications, that is, whether the triple-redundant flight control system meets the safety properties.

[0054] In another embodiment of the present invention, in the above step 1, the clock period of the component is obtained from the crystal oscillator frequency of the clock used by the component, and the random drift range of the clock of the component is obtained from the crystal oscillator drift of the clock used by the component.

[0055] In step 2, the clock model is constructed by using the period and random drift range of the clock of the components of the time automaton and the triple-redundant flight control system, referring to Figure 2 A time automation mechanism is used to construct a clock template, which contains two locations, initial and stick. The local time t<=[clock period + maximum drift] of this template is set as the invariant condition of the location, and t>[clock period - maximum drift] is set as the guard condition of the location migration. The randomness of the migration constitutes the randomness of the clock drift. Whenever the migration is successful, the local time t is reset to 0 and the timing of the next cycle begins.

[0056] In one embodiment of the present invention, the specific implementation process of step 2 above may include:

[0057] Step 21: construct a clock array using timed automaton semantics. The clock array contains 7 elements, corresponding to the 7 components of the triple-redundant flight control system.

[0058] Step 22: For each clock array element, construct the clock's starting location and loop location using timed automaton semantics;

[0059] Step 23: Add guard and invariant conditions of the timed automaton between the start location and the loop location based on the clock period and random drift range, where the guard condition is "t>[clock period - maximum drift]" and the invariant condition is "t<=[clock period + maximum drift]";

[0060] In step 24, using timed automaton semantics, add a clock channel to the guard to send a signal.

[0061] In another embodiment of the present invention, the specific implementation process of the above step 3 may include:

[0062] Step 31, performing an object-oriented abstract summary on the functional architecture of the triple-redundant flight control system, abstracting two classes, the flight control computer FCM and the flight control actuator ACE, and thereby creating empty templates of the flight control computer FCM and the flight control actuator ACE based on a timed automaton;

[0063] Step 32: Fill the flight control computer FCM master / slave switching function logic into the flight control computer FCM empty template based on the timed automaton to form a flight control computer FCM formal model template;

[0064] Step 33: Fill the flight control actuation electronic ACE master / standby voting function logic into the flight control actuation electronic ACE empty template based on the timed automaton to form a flight control actuation electronic ACE formal model template;

[0065] Step 34: Create three instances based on the flight control computer FCM formal model template to form a triple-redundant flight control computer FCM;

[0066] Step 35: Create four instances based on the flight control actuation electronic ACE formalized model template to form a quad-redundant flight control actuation electronic ACE.

[0067] In step 36, the triple-redundant flight control computer (FCM) and the quadruple-redundant flight control actuator (ACE) are driven based on the clock array. Each clock array element corresponds to a corresponding instance, and each instance receives a signal from the clock channel (channel) in step 24, forming a formal model of the triple-redundant flight control system.

[0068] In an embodiment of the present invention, the specific implementation process of step 4 may include:

[0069] Step 41: Based on the modeling semantics of the timed automaton, a deadlock, bus transmission, and transient fault are set. The faults are independent and may occur at any time.

[0070] Among them, the crash fault is that the clock is driven multiple times continuously and the functional logic of this component fails to run successfully;

[0071] Bus transmission failure means that the data sent by the component is incorrect or the data received by the component is incorrect;

[0072] A transient fault is a fault that occurs suddenly at a certain moment and immediately returns to normal at the next moment;

[0073] Step 42, add the set fault to the formal model of the triple-redundant flight control system based on time automaton to obtain a fault model. Figure 1 As shown, the black dot in the figure indicates the location of the fault.

[0074] In an embodiment of the present invention, the specific implementation process of step 5 may include:

[0075] Step 51: Perform a safety analysis on the triple-redundant flight control system to form safety attributes. For example, at any time when the triple-redundant flight control system is in operation, all three flight control computers (FCMs) cannot be backup systems.

[0076] Step 52: Use the formal specification semantics of timed automata, TCTL, invariant form, and system runtime to describe the security attributes as a formal specification.

[0077] In an embodiment of the present invention, the specific implementation process of step 6 may include:

[0078] In step 6, if the fault model satisfies the formal specification, the formal verification result is satisfied; otherwise, the formal verification result is not satisfied.

[0079] The operating scenarios of the fault model that do not meet the formal specification form counterexamples. The counterexample content is the operating sequence of the triple-redundant flight control system. The sequence includes the key nodes of component clock triggering, component functional logic operation and fault occurrence, which makes it easier for system designers to understand and modify the system design.

[0080] For example, in the formally verified counterexample, the component operation and failure sequence of the triple-redundant flight control system is as follows: "In the current system, FCM1 is already the master FCM. First, the FCM1 clock is triggered, but the "self-master" flag sent by FCM1 to FCM2 fails during transmission, and the "self-master" flag is mistakenly transmitted from True to False. Then, the FCM2 clock is triggered. After receiving the information that the "self-master" flag is False from FCM1, FCM2 mistakenly believes that the triple-redundant flight control system does not have a master FCM, so it upgrades itself to the master FCM. At this time, two master FCMs, FCM1 and FCM2, appear in the triple-redundant flight control system." This violates the safety property that the system cannot have two or more master FCMs. The key nodes of component clock triggering, component functional logic operation, and failure occurrence shown in this counterexample can help system designers quickly understand and modify the fault handling method of the triple-redundant flight control system.

[0081] This method has the characteristics of strong design operability and good verification effect, and can greatly improve the effect of safety analysis of triple-redundant flight control system.

[0082] In some possible implementations of the embodiments of the present invention, the specified safety analysis method for a triple-redundant flight control system uses all tools that can support timed automaton-based modeling.

[0083] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the field can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present invention, and these modifications or replacements should all be covered by the scope of protection of the present invention.

Claims

1. A safety analysis method for a triple-redundant flight control system based on a timed automaton, characterized in that: include: Step 1: Determine the clock period and random drift range of each component based on the crystal oscillator frequency and drift of the clocks used by the seven components of the triple-redundant flight control system; Step 2: Construct a clock model using a timed automaton and the clock periods and random drift ranges of the components of the triple-redundant flight control system. The modeling semantics of the timed automaton include location, guard, invariant, and channel. Step 3: Based on the architecture and clock model of the triple-redundant flight control system, construct a formal model of the triple-redundant flight control system based on timed automata; Step 4: Construct a fault model based on the formal model of the triple-redundant flight control system based on timed automata. Faults include freeze, bus transmission, and transient faults. Step 5: Perform safety analysis on the triple-redundant flight control system, obtain safety attributes based on the triple-redundant flight control system, and express them as formal specifications; Step 6: Use formal verification tools to verify whether the fault model meets the formal specifications.

2. The method according to claim 1, characterized in that In step 1, the clock period of the component is taken as the crystal oscillator frequency of the clock used by the component, and the random drift range of the clock of the component is taken from the crystal oscillator drift of the clock used by the component.

3. The method according to claim 2, characterized in that Step 2 specifically includes: Step 21: Use timed automaton semantics to construct a clock array. The clock array contains 7 elements, corresponding to the 7 components of the triple-redundant flight control system. Step 22: For each clock array element, use timed automaton semantics to construct the clock's starting location and loop location; Step 23: Add guard and invariant conditions of the timed automaton between the starting location and the loop location based on the clock period and random drift range. The guard condition is "t>[clock period - maximum drift]", and the invariant condition is "t<=[clock period + maximum drift]". In step 24, using timed automaton semantics, add a clock channel to the guard to send a signal.

4. The method according to claim 3, characterized in that Step 3 specifically includes: Step 31: Perform an object-oriented abstraction summary on the functional architecture of the triple-redundant flight control system, abstracting the flight control computer FCM and the flight control actuator ACE classes. Based on these classes, create empty templates for the flight control computer FCM and the flight control actuator ACE based on the timed automaton. Step 32: Fill the flight control computer FCM master / slave switching function logic into the flight control computer FCM empty template based on the timed automaton to form a flight control computer FCM formal model template; Step 33: Fill the flight control actuation electronic ACE master / standby voting function logic into the empty template of the flight control actuation electronic ACE based on the timed automaton to form a formalized model template of the flight control actuation electronic ACE; Step 34: Create three instances based on the flight control computer FCM formal model template to form a triple-redundant flight control computer FCM; Step 35: Create four instances based on the flight control actuation electronic ACE formal model template to form a quad-redundant flight control actuation electronic ACE; Step 36: Drive the 3-redundant flight control computer FCM and the 4-redundant flight control actuator ACE based on the clock array, where each clock array element corresponds to a corresponding instance, and each instance receives the signal from the clock channel channel in step 24, forming a formal model of the 3-redundant flight control system.

5. The method according to claim 4, characterized in that Step 4 specifically includes: Step 41: Based on the modeling semantics of the timed automaton, set the crash, bus transmission and transient faults. The faults are independent and may occur at any time. Step 42: Add the set fault to the formal model of the triple-redundant flight control system based on timed automata to obtain a fault model.

6. The method according to claim 5, characterized in that In step 41, The crash failure is caused by multiple consecutive clock drives, and the functional logic of this component fails to run successfully; Bus transmission failure means that the data sent by the component is incorrect or the data received by the component is incorrect; A transient fault is a fault that occurs suddenly at a certain moment and returns to normal immediately at the next moment.

7. The method according to claim 6, characterized in that Step 5 specifically includes: Step 51: Perform safety analysis on the triple-redundant flight control system to form safety attributes; Step 52: Use the formal specification semantics of timed automata, TCTL, invariant form, and system runtime to describe the security attributes as a formal specification.

8. The method according to claim 7, characterized in that Step 6 specifically includes: If the fault model satisfies the formal specification, the formal verification result is satisfied; otherwise, the formal verification result is not satisfied. The operating scenario of the fault model that does not meet the formal specification is a counterexample. The counterexample content is the operating sequence of the triple-redundant flight control system. The sequence includes the key nodes of component clock triggering, component functional logic operation, and fault occurrence, which is used by system designers to understand and modify the system design.

Citation Information

Patent Citations

  • Triplex redundancy-based realization method for fly-by-light fight control system

    CN102736630A

  • Clock equipment failure early warning method and device based on clock control quantity

    CN119276406A

  • Safe start-up of a network

    WO2007000007A1

  • Method for diagnosis of failures in a network

    WO2013044282A1