An automatic generation method for test cases of spacecraft controller software based on models

Through the model modeling and search method based on UML state graph generation test paths, combined with combined testing and adaptive random testing methods, the problem of lack of unified description methods and relying on experience to design test scenarios in spacecraft controller software testing is solved, and efficient automatic generation and comprehensive coverage of test cases are achieved.

CN114328188BActive Publication Date: 2025-05-27BEIHANG UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111506160.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-10
Publication Date
2025-05-27
Estimated Expiration
2041-12-10

AI Technical Summary

Technical Problem

In the functional testing of spacecraft controller software, the existing methods lack a unified description method and cannot independently generate test scenarios. The design of the test scenario depends on the experience of the testers and cannot guarantee the full coverage of the needs of autonomous functions.

Method used

A model modeling method based on UML state graph is adopted, model information is stored through directed graphs, and a test path that meets the coverage criteria is generated using search methods. Equivalent classes are generated in combination with combined test ideas, and a uniformly distributed test scenario is generated under the guidance of adaptive random testing.

Benefits of technology

It realizes unified modeling and automatic generation of test cases of spacecraft software testing requirements, solves the problem that test scenario design depends on experience, and ensures that the test scenario can effectively cover all the needs of autonomous functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114328188B_ABST
    Figure CN114328188B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for automatically generating test cases for a spacecraft controller software based on a model, including: 1), formalizing and modeling the test requirements of a space vehicle, and modeling the states of the spacecraft and their transitions in the test requirements with a UML state diagram to obtain a standard model; 2), preprocessing the standard model, and converting the test information contained in the state diagram into a directed graph for storage; 3), obtaining test paths under different coverage criteria through the directed graph; 4), dividing the system input and output for each test path, and performing an equivalent class partitioning on the input space of this path. 5), performing an assignment operation on each equivalent class to obtain a sequence of specific test cases on this logical sequence. The present invention solves the disadvantage that there is no unified description method for spacecraft software requirements; it solves the disadvantage that in the current test process, the design of test scenarios completely depends on the experience of testers and cannot guarantee that the designed test scenarios effectively cover all the requirements of autonomous functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of software testing, and is a method for automatically generating test cases for the functional testing of spacecraft controller software. Background Art

[0002] Software testing technology aims to verify whether software meets requirements, and has gradually developed along with the development of software and hardware. Software testing discovers software faults and repairs defects before the software is officially put into use by executing test cases, and is an indispensable link in software development.

[0003] More attention should be paid to the testing of software in safety-critical fields, such as the controller software on spacecraft. Whether the controller software runs correctly directly determines whether the spacecraft can complete its main tasks, and may even be related to the safety of astronauts. Such software must be fully tested before use to minimize the possibility of failures.

[0004] In the field of spacecraft software testing, there have been many related works. These works mainly focus on the inspection of software code, that is, white-box testing. Such white-box testing is an essential link for software testing, but it cannot directly check whether the spacecraft controller software runs correctly according to the expected functions.

[0005] With the continuous evolution of China's space vehicle design technology, space vehicles have evolved from being hardware-dominated to software-dominated based on data, and space vehicles have been upgraded from the original electronic systems to integrated electronic systems supported by cyber-physical technology. In recent years, with the continuous upgrading of China's space vehicle technology and equipment, satellites can independently complete specific tasks according to mission plans and space environments. Space vehicles can not only complete corresponding tasks according to ground instructions, but also adjust tasks according to changes in the cosmic space environment. The improvement of the autonomy and intelligence level of space vehicles also poses new requirements for their ground testing. The testing focus has changed from mainly verifying the hardware functional performance indicators in the past to mainly verifying the mission completion ability of space vehicles in real space scenarios.

[0006] The ground testing of space vehicles is mostly carried out in a simulated cosmic space environment. At present, there are two problems in the functional testing of space vehicle software: 1) Relying on the understanding of requirement documents to manually design test scenarios, lacking a unified description method for designing multi-domain and multi-objective test requirements, and unable to generate autonomous test scenarios; 2) The design of test scenarios completely depends on the experience of testers, and it is impossible to ensure that the designed test scenarios can effectively cover all the requirements of autonomous functions.

[0007] In model-based testing, a software model is an abstraction and characterization of software features using formal methods. Common software models that can be used for test case generation include: finite state machine (FSM), Markov chain model, UML model, and timed automata model, etc. Among them, the UML model is more widely used. In the method of automatic test case generation based on the UML model, most of them convert the UML diagram into other intermediate forms, such as graphs or tables, and then use various algorithms for test case generation, including depth-first and breadth-first search algorithms and genetic algorithms, etc.

[0008] Suppose there are m parameters to be tested in a certain system, and each parameter has a 1 , a 2 , …, a m different values respectively. Then, to conduct a comprehensive test, n = a 1 ×a 2 ×…×a m experiments are required. Generally, this value is relatively large, and it is almost impossible to conduct a comprehensive experiment, that is, the problem of combinatorial explosion. Combinatorial testing is a scientific and practical software testing method that fully considers various factors and their interactions. This method can effectively detect software faults by designing a small number of test cases and selecting a small number of combinations for testing in a huge combination space.

[0009] Suppose there are n parameters in a certain system, and the specific value c i of each parameter is selected from a finite discrete set T i , and there are a i = |T i | (1 ≤ i ≤ n) different parameter values in this set. Let A be an m×n matrix, A = (a i ) m×n , and its j-th column represents the parameter c j , and its value is taken from the finite symbol set T j (j = 1, 2, …, n), that is, a ij ∈T j . If any two columns, the i-th column and the j-th column, of A satisfy that all pairwise combinations of the symbols of T i and the symbols of T j appear at least once in the binary ordered pairs formed by the i-th column and the j-th column, then A is called a pairwise combination coverage table (2-way coverage table), denoted as CA(m, 2, a 1 ×a 2 ×…×a n ), where m is the number of generated test cases, 2 represents a 2-way coverage table, and when a 1 = a 2 = … = a nWhen it is equal to a, it is denoted as CA(m, 2, a n ). If it is the smallest positive integer that can ensure the above conditions are met, then A can be called the minimum pairwise combination coverage table, and each row of A is a test case. The method of using the pairwise combination coverage table for test design is called the pairwise combination coverage method, pairwise combination testing, or 2-way combination testing. Similarly, the three-way combination coverage table (3-way coverage table), four-way combination coverage table (4-way coverage table), etc. can be defined, and they are collectively called the multi-factor combination coverage table or τ-way coverage. The method of using the multi-factor combination coverage table for experimental design is called the multi-factor combination coverage method, τ-way combination coverage method, or τ-way combination testing.

[0010] Considering that existing research has pointed out that software inputs that can trigger software failures often concentrate in a certain continuous region in the input domain, so those test cases that are farther from the test cases that do not trigger software defects have a greater chance of covering software defects. Thus, the Adaptive Random Testing (ART) technology points out that software test cases need to be distributed as evenly as possible in the input domain. The Fixed Sized Candidate Set ART (FSCS-ART) algorithm is a classic distance-based ART (D-ART) algorithm. First, a test case is randomly generated within the input domain and placed in the test case set E. Then, k candidate test cases are randomly generated (candidate set C = {C 1 , C 2 , …, C k ,}) and the shortest distance between each candidate test case c i (1 ≤ i ≤ k) and all test cases in the test case set (E = {E 1 , E 2 , …, E q}) is calculated, and the candidate test case with the largest shortest distance is selected and placed in the test case set E. The above process of generating the next test case is continuously executed until enough test cases are generated in E.

[0011] However, the above current methods for generating test cases cannot be directly applied to spacecraft controller software. First, the working state of the spacecraft is relatively complex. From the time the spacecraft enters the orbit to the satellite entering the normal working mode, a series of activities are required to control the spacecraft in the middle. During this process, the satellite is controlled by environmental changes and ground command transmissions, makes corresponding actions, and sometimes gives feedback signals. Second, in the current model-based test methods, the aim is to generate the paths required by the test system to fully cover the states or transitions of the system, without generating specific test values and considering the spatial distribution of the generated specific test cases. Summary of the Invention

[0012] One object of the present invention is to: to make up for the deficiencies of the above method, the present invention proposes a method for automatically generating test cases for spacecraft controller software based on a model. The method proposes a method of using UML state diagrams to model spacecraft controller software. Based on this model, a directed graph is used to store model information. Then, under the guidance of certain coverage criteria, a search method is used to find test paths that meet the conditions in the graph. In each test path, using the idea of combinatorial testing, a number of non-overlapping equivalent classes are generated, and each equivalent class is a sequence composed of logical conditions. Furthermore, a certain number of test scenarios are generated from the logical sequence. In this process, the test scenarios are obtained by assigning values to each logical condition on the test path one by one. In the process of assignment, the idea of adaptive random testing is used to generate test scenarios with a specific distribution under a specific logical sequence.

[0013] The technical solution of the present invention is: a method for automatically generating test cases for spacecraft controller software based on a model, including the following steps:

[0014] Step 1): Formal modeling of the test requirements of the spacecraft. Under the uniformly specified rules, use UML state diagrams to model the states of the spacecraft and their transitions in the test requirements, and then the construction of the state diagram can be completed to obtain a standard model without ambiguity;

[0015] Among them, if a more complex working mode contains other sub-working modes, a composite state diagram can be used to represent it.

[0016] Step 2): Preprocessing of the above standard model. Convert the test information contained in the state diagram into a directed graph for storage.

[0017] Among them, the composite state diagram contains hierarchical information, so it is necessary to flatten the composite state diagram according to the characteristics of the spacecraft itself;

[0018] Step 3): Through the directed graph obtained in Step 2), test paths under different coverage criteria can be obtained - each path composed of nodes and edges from the starting node to the ending node in the directed graph can represent a test path for spacecraft software testing;

[0019] Step 4): Divide the input and output of the system for each test path obtained in Step 3), and perform equivalent class partitioning on the input space of this path. This step will generate different logical sequences on any test path, and these logical sequences logically cover the transition conditions of any test path sufficiently;

[0020] Step 5): For each equivalence class (i.e., each logical sequence) obtained in Step 4), perform an assignment operation to obtain a sequence of specific test cases on this logical sequence, where the test cases include test inputs and the expected software outputs. In the process of generating specific test inputs, use the method of Adaptive Random Testing to generate a sequence of test cases that are as evenly distributed as possible in the input domain.

[0021] Among them, the flattening of the composite state diagram described in Step 2) is specifically as follows: For a certain composite state s c , the following symbol regulations are adopted: The starting state inside the composite state is s c-I , which contains n sub-states s ci (1 ≤ i ≤ n), where the sub-state connected to the starting state is s c1 ; The principle of flattening is:

[0022] a) A transition t entering the composite state s c , whose source state is s 1 , and the target state may be the composite state s c or its sub-state s ci ; If the target state of the transition t is the composite state s c , then after flattening, a new transition t' will be generated from its source state s 1 to the sub-state s c1 connected to the starting state; If the target state of the transition t is the sub-state s ci , then after flattening, a new transition t'' will be generated from its source state s 1 to the sub-state s ci ; Then delete the original transition t and add the entry action of the composite state as the transfer action of the new transition t' or t'';

[0023] b) A transition T leaving the composite state s c , whose target state is s 2 , and its source state may be the composite state s c or its sub-state s ci ; If the source state of the transition T is s c , then after unfolding, n new transitions T ci from all its sub-states s 2 to the target state s i (1 ≤ i ≤ n) will be generated; If the source state of the transition T is the sub-state s ci , then after unfolding, a transition from this sub-state s ci to the target state s 2 will be generated.The new transition T'; then delete the original transition T and add the exit action of the composite state as the new transition T i or the transition action of T';

[0024] c) The initial state in the composite state is deleted during flattening;

[0025] d) After flattening, make the do event of the composite state s c become the do event of each sub-state.

[0026] Among them, for the sufficient coverage of the transition conditions of any one of the test paths described in step 4), a method of combining the idea of combinatorial testing with the transition logic conditions in the state diagram is adopted. The specific process is as follows:

[0027] Suppose a certain test path has m transitions, and each transition has a 1 , a 2 , …, a m disjoint logical conditions, and triggering this transition only requires satisfying any one of the logical conditions;

[0028] Among them, the non-overlapping logical conditions on each transition are obtained by decomposing the logical conditions of the signal events on the transition into several non-overlapping sub-logical conditions of an initial logical condition; then combine the different sub-logical conditions of the logical conditions of the signal events on different transitions, and use the method of combinatorial testing to achieve sufficient coverage of the conditions on the test path.

[0029] The beneficial effects of the present invention are as follows:

[0030] The process of modeling the software test requirements of the spacecraft starts from the functions of the software and finally generates a model that can be used for testing, solving the shortcoming that the spacecraft software requirements lack a unified description method. The proposed automatic test case generation framework can effectively solve the shortcoming that in the current test process, the design of the test scenario completely depends on the experience of the testers and cannot guarantee that the designed test scenario can effectively cover all the requirements of the autonomous functions. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 Automatic Test Case Generation Framework for Model-Based Spacecraft Software

[0032] Figure 2 Composite State in the State Diagram DETAILED DESCRIPTION OF THE INVENTION

[0033] The present invention will be further described below with reference to the accompanying drawings. First, in combination with the attached Figure 1 , the overall framework of the automatic generation of test cases in the present invention will be described.

[0034] A method for automatically generating software test cases for a space vehicle based on a model proposed by the present invention. This method includes a modeling method for the software test requirements of a spacecraft and a test framework for generating test cases from the model. The overall framework diagram for automatically generating software test cases for a space vehicle is as shown in Figure 1 shown.

[0035] In practical applications, the functional testing of spacecraft controller software usually highly depends on the experience of testers, and different testers may also have different understandings of test requirements. The present invention provides a set of standard requirement modeling methods and a framework for automatically generating test cases from the model to solve these problems.

[0036] Software testers should analyze test requirements and, according to certain rules, correspond different information in the test process to different elements in the UML state diagram to achieve the modeling process; the next is the process of generating a directed graph from the state diagram, abstracting the model obtained in the previous step into a specific data structure (directed graph); then search the directed graph to obtain all paths composed of alternating points and edges from the starting point to the ending point; next, perform equivalence class partitioning on each path in the path set; finally, generate specific test case inputs on each equivalence class and calculate the expected outputs to obtain the test sequence. In the last step, the idea of dynamic random testing is used for guidance.

[0037] Next, the technical solution of the present invention will be described in detail, and its specific implementation steps are as follows:

[0038] 1. Test requirement modeling. Formalize the test requirements of the space vehicle and, under uniformly specified rules, use the UML state diagram to model the states of the spacecraft and their transitions in the test requirements to obtain a non-ambiguous standard model;

[0039] The Unified Modeling Language (UML) is a modeling and specification language, an open method for specifying, visualizing, constructing, and documenting the artifacts of an object-oriented, software-intensive system under development. In the field of software testing, UML models are often used to describe the test requirements of the software under test and can be used to generate test cases. This technology has been widely applied to the automatic generation of test cases.

[0040] The UML state diagram can describe all possible states of an object and the transition conditions of the state when an event occurs, and can capture the life cycle of an object, subsystem, and system. The UML state diagram includes two major elements: states and transitions. States include the actions of the object in that state, and transitions include the events and impacts that trigger the transitions.

[0041] The information received by the spacecraft controller software may come from ground commands or signals from the cosmic environment, etc. The output information of this software is some control signals and feedback to the ground. Compared with the existing ones based on UML state diagrams, for testing, the test inputs and outputs are not the inputs and outputs of the software. For example, the test is carried out in a simulation system, and the cosmic environment changes as the simulation progresses and cannot be artificially input or changed. Instead, these changes can be regarded as the criteria for judging whether the controller software is working properly, that is, they can be used as the outputs of the test.

[0042] The information in the aircraft test requirements can be divided into the following four parts:

[0043] · The working mode of the aircraft;

[0044] · The ground commands received by the aircraft or external interferences;

[0045] · The numerical values of various sensors indicating the state of the aircraft;

[0046] · The feedback signals from the aircraft to the ground.

[0047] The above briefly analyzes the requirements for aircraft testing. Combining the understanding of the various elements of the state diagram, the main information of the aircraft software test requirements is corresponded to the elements in the UML state diagram, and the correspondence is shown in Table 1.

[0048]

[0049] Table 1

[0050] The above table is the test requirement modeling rule in the present invention. By modeling the states and transitions in the life cycle of the controller software according to this rule, the construction of the state diagram can be completed.

[0051] If a more complex working mode contains other sub-working modes, a composite state can be used to represent this relationship. For example, the satellite control system is in a certain control mode (denoted as state S), and this mode can be further divided into two different sub-modes (denoted as state S 1 and S 2 ), and there is a certain logical inclusion relationship between them. When modeling the spacecraft control software, the hierarchical structure of the composite state can intuitively represent this logical relationship. In the state diagram, it can be represented as a nested composite state, see Figure 2 .

[0052] 2. Preprocessing of the model. All the test information is included in the system state diagram and is converted into a directed graph for storage.

[0053] The UML state diagram can be derived into a document in XML format through XMI (XML Metadata Interchange). Information extraction can be performed on this document to extract the state and transition information in the state diagram, and instantiate the node class and edge class to obtain a directed graph. This process is a known technique.

[0054] Furthermore, since the composite state diagram contains hierarchical information, although the hierarchical structure can intuitively represent the state information, when performing semantic parsing on the diagram, it is necessary to flatten the hierarchical relationship in the diagram. Therefore, it is necessary to propose a flattening strategy for the state diagram according to the characteristics of the spacecraft itself:

[0055] For a certain composite state s c , we have the following symbol regulations: the starting state inside the composite state is s c-I , which contains n sub-states s ci (1 ≤ i ≤ n), where the sub-state connected by the starting state is s c1 . The principle of flattening is:

[0056] e) A transition t entering the composite state s c , whose source state is s 1 , and the target state may be the composite state s c or its sub-state s ci . If the target state of the transition t is the composite state s c , then after flattening, a new transition t′ will be generated from its source state s 1 to the sub-state s c1 connected by the starting state; if the target state of the transition t is the sub-state s ci , then after flattening, a new transition t″ will be generated from its source state s 1 to the sub-state s ci . Then delete the original transition t, and add the entry action of the composite state as the transfer action of the new transition t′ or t″.

[0057] f) A transition T leaving the composite state s c , whose target state is s 2 , and its source state may be the composite state s c or its sub-state s ci . If the source state of the transition T is s c , then after expansion, n new transitions T ci from all its sub-states s 2 to the target state s i (1 ≤ i ≤ n) will be generated; if the source state of the transition T is the sub-state s ci , then after expansion, a transition from this sub-state sci Reach the target state s 2 of the new transition T'. Then delete the original transition T and add the exit action of the composite state as the new transition T i or the transition action of T'.

[0058] g) The starting state in the composite state is deleted during flattening.

[0059] h) After flattening, change the do event of the composite state s c to the do event of each sub-state.

[0060] After the composite state diagram is flattened, it can be transformed into a directed graph, that is, store the transitions and state information in the state diagram in the edges and nodes of the directed graph.

[0061] 3. Generation of test paths. Through the directed graph obtained in step 2), test paths under different coverage criteria can be obtained from it.

[0062] The test path represents the process of the satellite from the initial state under some transition conditions, through a series of state transitions, to reach the final control state, which is an abstract concept; each path composed of nodes and edges from the starting node to the ending node in the directed graph can represent a test path for spacecraft software testing.

[0063] According to different test coverage criteria, different test path sets can be found from the directed graph. The test coverage criteria are selected by testers according to the cost and requirements of the test. If only all working states of the spacecraft are expected to be covered in the test, the state coverage criterion can be selected. When implementing, use Depth-First Searching or Breadth-First Searching, guided by whether the nodes are covered, to obtain a non-repeated depth-first / breadth-first tree. This process can refer to the general depth-first and breadth-first search algorithms.

[0064] It should be noted that when a general graph search algorithm performs graph search, it will find a tree. Since not all leaf nodes are ending nodes, that is, the path from the root node of the tree to a leaf node may not be the test path we want. Therefore, when searching for paths, attention needs to be paid to completing the paths.

[0065] Common test coverage criteria include state coverage, transition coverage, basic path coverage, etc. For example, using basic path coverage, all independent paths of the spacecraft from the initial state to the final state can be covered. The set of test scenarios that meet this requirement can achieve basic coverage of the functions of the test.

[0066] 4. Generation of logical sequence. For each test path obtained in step 3), divide the input and output of the system, and perform equivalent class partitioning on the input space of this path.

[0067] Each test path contains several states and transitions. A large number of test information is recorded on the states and state transitions, and this information is respectively related to test inputs and expected test outputs. Among them, the signal event of a transition represents the input of a test case, and the change event and action of this transition, as well as the action of the next state, represent the output of this test case.

[0068] Since a test path involves multiple transitions, the conditions on the signal events of each transition may be relatively complex and may also involve multiple variables. To satisfy the full coverage of the trigger conditions, it is necessary to consider the combination of logical conditions between different transitions. However, if all combinations are covered, it may cause an explosion of condition combinations. Therefore, the present invention adopts the idea of combinatorial testing and proposes a method of combining the idea of combinatorial testing with the transition logical conditions in the state diagram. The specific process is as follows:

[0069] Suppose a certain test path has m transitions, and each transition has a 1 , a 2 , …, a m disjoint logical conditions, and any one of the logical conditions can trigger this transition. Make an analogy between the different logical conditions here and the different values of parameters in traditional combinatorial testing, and use the method of combinatorial testing to combine the logical conditions on the test path.

[0070] Among them, the disjoint logical conditions on each transition are obtained by decomposing the logical conditions of the signal events on the transition. The decomposition principle is to automatically convert the input conditions into the form of disjunctive normal form. The disjunctive normal form logically represents the "or" relationship of multiple logical conditions. The multiple logical conditions are called sub-logical conditions (that is, the disjoint logical conditions on each transition). Any one of the sub-logical conditions being "true" can cause the initial logical condition (the logical condition of the signal event on the transition) to be "true". For example, if A, B, and C are three different parameters, the original logical condition of the signal event on a certain transition is (A > 1 | B < 1) & C = 1. This condition can be converted into the disjunctive normal form: (A > 1 & C = 1) | (B < 1 & C = 1). Finally, all the logical conditions that can make the transition condition take the value of "true" can be obtained as: (i) ¬(A > 1) & (B < 1) & (C = 1); (ii) (A > 1) & ¬(B < 1) & (C = 1); (iii) (A > 1) & (B < 1) & (C = 1).

[0071] In this way, several non - overlapping sub - logical conditions of an initial logical condition can be obtained. Then, combinations are made among different sub - logical conditions of the logical conditions of different transfer signal events, and the method of combinatorial testing is used to achieve full coverage of the conditions on the test path.

[0072] In this way, several logical sequences can be obtained from a test path, and the intensity of combinatorial testing can be changed to achieve different - strength coverage of the state - diagram transition logic.

[0073] 5. Generation of test sequences.

[0074] The logical sequences obtained in the previous step are not specific test cases. It is necessary to parse the test input conditions on the logical sequences to generate specific values that meet the conditions for each parameter. LEX and YACC are tools used in implementing compilers. In the present invention, these tools are used to identify and parse logical conditions, and thus specific parameter values can be generated from logical expressions.

[0075] Logical sequences can generate specific test sequences; each test sequence can also be called a test scenario, which contains several test cases; a test case is a tuple composed of a test input and a test output. The sequence composed of the inputs of test cases, that is, the test input of the test scenario, can be regarded as a point in a high - dimensional space.

[0076] A logical sequence can generate different test sequences without repetition. In order to make the limited test sequences cover the logical conditions on the logical sequence as fully as possible, the idea of adaptive random testing is used to generate test scenarios that are evenly distributed in the input domain formed by the logical sequence.

[0077] Through the above - mentioned steps, the present invention forms a set of modeling methods and a framework for automatically generating test scenarios from models. For the software under test, the method proposed by the present invention hierarchically generates and stores the test paths, logical sequences, and test sequences of the software.

Claims

1. A method for automatically generating test cases for spacecraft controller software based on a model, characterized in that: The method comprises the following steps: Step 1), formal modeling of the test requirements of the spacecraft. Under uniformly specified rules, use a UML state diagram to model the states of the spacecraft and their transitions in the test requirements, that is, complete the construction of the state diagram to obtain an unambiguous standard model; wherein, if a complex working mode contains other sub-working modes, a composite state diagram is used to represent it; Step 2), preprocessing of the above standard model. Convert the test information contained in the state diagram into a directed graph for storage; wherein, the composite state diagram contains hierarchical information, so it is necessary to flatten the composite state diagram according to the characteristics of the spacecraft itself; Step 3), through the directed graph obtained in Step 2), obtain test paths under different coverage criteria - each path composed of nodes and edges from the starting node to the ending node in the directed graph represents a test path for spacecraft software testing; Step 4), divide the input and output of the system for each test path obtained in Step 3), and perform equivalence class partitioning on the input space of this path; this step will generate different logical sequences on any test path, and these logical sequences logically cover the transition conditions of this arbitrary test path sufficiently; Step 5), perform an assignment operation on each equivalence class obtained in Step 4) to obtain a sequence of specific test cases on this logical sequence, where the test case contains the test input and the expected software output; Among them, in step 2), the composite state diagram is flattened, and the specific process is as follows: For a certain composite state s c , the following symbol regulations are adopted: The starting state inside the composite state is s c-I , which contains n sub-states s ci , 1 ≤ i ≤ n, where the sub-state connected to the starting state is s c1 ; The principle of flattening is: a) A transition t that enters the composite state s c with its source state being s 1 and the target state may be the composite state s c or one of its sub - states s ci ; if the target state of the transition t is the composite state s c , then after flattening, a new transition t′ will be generated that connects from its source state s 1 to the starting state of the sub - state s c1 ; If the target state of the transition t is a sub-state s ci , then after flattening, a new transition t″ will be generated from its source state s 1 to the sub-state s ci ; then the original transition t is deleted, and the entry action of the composite state is added as the transfer action of the new transition t′ or t″; b) A transition T that leaves the composite state s c with its target state being s 2 and its source state possibly being the composite state s c or one of its sub - states s ci ; if the source state of the transition T is s c , then after expansion, n new transitions T ci from all of its sub - states s 2 to the target state s i , where 1 ≤ i ≤ n; if The source state of the transition T is the sub-state s ci , then after expansion, a new transition T' is generated from this sub-state s ci to the target state s 2 ; then the original transition T is deleted, and the exit action of the composite state is added as the transition action of the new transition T i or T'; c) The starting state in the composite state is deleted during flattening; d) After flattening, the do events of the composite state s c become the do events of each substate.

2. A method for automatically generating test cases for spacecraft controller software based on a model according to claim 1, characterized in that: The sufficient coverage of the transition conditions of the arbitrary test path described in Step 4) is achieved by combining the idea of combinatorial testing with the transition logic conditions in the state diagram.

3. A method for automatically generating test cases for spacecraft controller software based on a model according to claim 2, characterized in that: The method of combining the idea of combinatorial testing with the transition logic conditions in the state diagram is as follows: Suppose a certain test path has a total of m transitions, and each transition has a 1 , a 2 , …, a m non - overlapping logical conditions, and triggering this transition can be achieved by satisfying any one of the logical conditions; The non-overlapping logical conditions on each transition are obtained by decomposing the logical conditions of the signal events on the transition into several non-overlapping sub-logical conditions of an initial logical condition; then combine the different sub-logical conditions of the logical conditions of the signal events on different transitions, and use the method of combinatorial testing to achieve sufficient coverage of the conditions on the test path.

4. A method for automatically generating test cases for spacecraft controller software based on a model according to claim 1, characterized in that: In the process of generating specific test inputs in Step 5), the method of adaptive random testing is used to generate a sequence of test cases evenly distributed in the input domain.

Citation Information

Patent Citations

  • Hierarchical timed automata flattening algorithm

    CN102799521A

  • Train operation control system safety critical software test case generating method

    CN106814730A