An automatic generation and evaluation method for airborne system signal monitoring voting strategies
By automatically generating and evaluating airborne system signal monitoring voting strategies, and utilizing simulation model libraries and fault tree model libraries, the problem of traditional manual evaluation methods being difficult to adapt to the rapid iteration of civil aviation R&D has been solved. This has enabled automated strategy generation and optimization, improving R&D efficiency and accuracy.
Patent Information
- Application Number
- CN202111593877.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-23
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2041-12-23
AI Technical Summary
Traditional monitoring and voting strategies that rely on expert manual evaluation of each input signal in an airborne system are difficult to apply to the rapid iteration and process assurance requirements of civil aviation R&D, especially given the increasing number of aircraft sensors and the growing degree of distributed design in fly-by-wire flight control systems.
This paper provides an automatic generation and evaluation method for airborne system signal monitoring voting strategies. It matches available monitoring voting strategies by using a monitoring voting algorithm simulation model library, combines signal availability and integrity data, automatically generates and evaluates monitoring voting strategies, and uses a pre-configured monitoring voting algorithm simulation model library and fault tree model library for quantitative evaluation and strategy optimization.
It enables the rapid selection of the optimal monitoring and voting strategy from numerous options, reduces reliance on manual intervention, avoids human error, shortens the development cycle, and is suitable for automated optimization of underlying system requirements development and top-level architecture design.
Smart Images

Figure CN114356701B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to, but is not limited to, the field of system development process model technology, and particularly to an automatic generation and evaluation method for airborne system signal monitoring voting strategies. Background Technology
[0002] The correct implementation of fly-by-wire flight control systems often relies on a large number of signals input from the cockpit and numerous interconnected systems and sensors, making it a complex system among airborne systems.
[0003] To improve the safety of this complex system, a redundant architecture is generally adopted, with redundant signals monitored and voted on to meet user safety requirements for fly-by-wire flight control systems. However, with the increasing number of aircraft sensors and the growing degree of distributed design in fly-by-wire flight control systems, the combinations of signal sources and communication channels are increasing exponentially. The traditional method of monitoring and voting based on expert manual evaluation of each input signal is no longer suitable for the rapid iteration and process assurance requirements of civil aviation R&D. Summary of the Invention
[0004] The purpose of this invention is to provide an automatic generation and evaluation method for airborne system signal monitoring voting strategies, thereby addressing the problem that the traditional method of manually evaluating the monitoring voting strategies for each input signal in an airborne system by experts is no longer suitable for the rapid iteration and process assurance requirements of civil aviation R&D processes.
[0005] The technical solution of the present invention:
[0006] This invention provides a method for automatically generating and evaluating voting strategies for airborne system signal monitoring, comprising:
[0007] Step 1: Match at least one available pre-selected monitoring and voting strategy from the monitoring and voting algorithm simulation model library based on the attribute characteristics of the input signal;
[0008] Step 2: Based on the signal availability data and signal integrity data of the input signal, and the matched monitoring and voting strategy, evaluate whether the security of processing the input signal using the monitoring and voting strategy meets the security target requirements of the voting value, and obtain the recommended monitoring and voting strategy.
[0009] The monitoring and voting algorithm simulation model library is pre-configured and includes multiple simulation models, with different simulation models representing different monitoring and voting algorithms.
[0010] Optionally, in the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above, before step 1, the method further includes:
[0011] Step a: Set input signal attributes according to user input. The input signal attributes include: redundancy quantity, signal data type, signal source type, transmission channel type, signal source name, transmission channel name, signal availability data, signal integrity data, and security indicators of the voting value.
[0012] Optionally, in the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above, step 1 includes:
[0013] Step 11: Perform structural analysis on the input signal based on the signal source name and transmission channel name set by the user to obtain the input signal name;
[0014] Step 12: Match at least one simulation model in the monitoring voting algorithm simulation model library based on the input signal name and input signal attributes;
[0015] Step 13: Generate model input based on the input interface of the matched simulation model, and assign values to the model input;
[0016] Step 14: Based on the assignment results of the model input, run the matched simulation model, obtain the output results of the simulation model, and generate a simulation model matching report.
[0017] Optionally, in the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above, step 11 includes:
[0018] Step 11a: Identify the signal source and transmission channel of each input signal, and perform independent identification on the identified signal source and channel;
[0019] Step 11b: Based on the independence identification result, the structure of the input signal is simplified to obtain the input signal name, and the input signal structure is transmitted in the form of the input signal name.
[0020] Optionally, in the automatic generation and evaluation method of airborne system signal monitoring voting strategy as described above, the monitoring voting algorithm simulation model library is pre-configured with multiple simulation models, and each simulation model has a unique preset number. The preset number field includes: redundancy-data type-signal source type-transmission channel type-sequence number. The preset number is used to indicate the input signal attribute characteristics to which the monitoring voting algorithm of this simulation model is applicable.
[0021] Optionally, in the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above, step 12 includes:
[0022] The system matches the user-defined attributes of the input signal with the preset numbers of the simulation models in the monitoring and voting algorithm simulation model library. The matching process includes determining the redundancy of the input signal, determining whether the input signal data type is discrete or analog, determining the signal source type, and determining the transmission channel type.
[0023] Optionally, in the automatic generation and evaluation method of the airborne system signal monitoring voting strategy as described above, the way to assign values to the model input in step 13 is as follows: under the condition that the fault flags output by the simulation model are all FALSE and the validity flags of the input signals are all TRUE, all the assigned values of the model input are listed.
[0024] Step 14 includes:
[0025] Step 14a: Based on all the assignment results of the model input of the simulation model in step 13, run the matched simulation model to obtain the output result of the simulation model. Eliminate some simulation models from the matched simulation models. The eliminated simulation models include: simulation models where the output fault is TRUE or the input signal validity is FALSE.
[0026] Step 14b: Generate a simulation model matching report based on the matched simulation model and the running results of the simulation model. The matching report lists the running results of the matched simulation model and identifies the simulation model that can match the input signal structure. The identified simulation model is used as the monitoring voting strategy.
[0027] Optionally, in the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above, step 2 includes:
[0028] Step 21: Based on the signal availability data and signal integrity data of the input signal, add fault models to the base events of the fault tree model corresponding to the monitoring voting strategy; the fault tree model library is pre-configured and includes a set of fault tree models corresponding to each simulation model.
[0029] Step 22: For input signals with a common signal source or transmission channel, add a common-mode fault model to the base event of the fault tree model;
[0030] Step 23: Run the fault tree model to generate a security analysis report, including: availability prediction data and integrity prediction data of the voting values of the input signals.
[0031] Optionally, the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above further includes:
[0032] Step 3: Score the recommended monitoring and voting strategy obtained in Step 2 and generate a strategy evaluation report.
[0033] Optionally, in the automatic generation and evaluation method for airborne system signal monitoring voting strategies as described above, step 3 includes:
[0034] The system includes operational efficiency, testing capability, and security scores. The operational efficiency and testing capability scores are preset scores for the recommended monitoring and voting strategy, while the security score is based on the difference between the data obtained from security analysis and the security target requirements.
[0035] Advantages of this invention: The embodiments of this invention provide an automatic generation and evaluation method for airborne system signal monitoring voting strategies. On the one hand, it automatically matches a series of feasible monitoring voting strategies to input signals with known redundancy and communication methods, and quantitatively evaluates and compares the matched monitoring voting strategies, thereby quickly selecting the optimal monitoring voting strategy from numerous options without relying on expert experience. Furthermore, after determining the monitoring voting strategy, the corresponding model in the monitoring voting algorithm simulation model library provided in this invention can be used to automatically generate code, simplifying the subsequent verification work. On the other hand, the analysis results of each strategy can also serve as a basis for refining requirements regarding signal redundancy, communication methods, integrity indicators, and availability indicators. This method is applicable to both the development and verification of underlying system requirements and the simulation and optimization of the architecture during the top-level architecture design and demonstration phases. The technical solution provided by this invention, through the practice of MBSE (Model Based System Engineering), breaks away from the traditional document-based approach to requirements capture, development, confirmation, and verification in product development. By using data and model-driven methods, it automates the entire process from requirements development to monitoring, voting, design, design analysis and optimization, and product implementation. This reduces reliance on manual labor, avoids human-introduced errors, reduces paperwork from solution to product, and shortens the development cycle. Attached Figure Description
[0036] Figure 1 A flowchart illustrating an automatic generation and evaluation method for airborne system signal monitoring voting strategies, provided as an embodiment of the present invention;
[0037] Figure 2 This is a schematic diagram of the preset number of the simulation model in the automatic generation and evaluation method of the airborne system signal monitoring voting strategy provided in the embodiments of the present invention;
[0038] Figure 3 This is a schematic diagram illustrating the configuration of an input signal attribute in an embodiment of the present invention;
[0039] Figure 4 for Figure 3A topology diagram of the signal channel configured with the input signal attributes in the illustrated embodiment;
[0040] Figure 5 This is a schematic diagram illustrating the configuration of another input signal attribute in an embodiment of the present invention;
[0041] Figure 6 for Figure 5 A topology diagram of the signal channel configured with the input signal attributes in the illustrated embodiment;
[0042] Figure 7 To Figure 5 A simplified topology diagram of the input signals configured in the illustrated embodiment.
[0043] Figure 8 This is a schematic diagram of the voting value availability assessment model corresponding to the 4-ADA-01 simulation model.
[0044] Figure 9 This is a schematic diagram of the voting value availability assessment model corresponding to the 4-ADA-02 simulation model modified by the CCF model. Detailed Implementation
[0045] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in this application can be arbitrarily combined with each other.
[0046] The steps illustrated in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases the steps shown or described may be performed in a different order than that presented here.
[0047] As explained in the background section, the traditional method of monitoring and voting on each input signal in an airborne system through expert manual evaluation is no longer suitable for the rapid iteration and process assurance of civil aviation R&D processes, given the increasing number of aircraft sensors and the growing degree of distributed design in fly-by-wire flight control systems.
[0048] To address the problems existing in the traditional signal monitoring voting strategies mentioned above, this invention provides an automatic generation and evaluation method for airborne system signal monitoring voting strategies. This method can automatically generate monitoring voting strategies and evaluate the generated strategies based on the availability and integrity indicators of single-redundancy signals and the security requirements of signals after voting.
[0049] The present invention provides the following specific embodiments, which can be combined with each other. For the same or similar concepts or processes, they may not be described again in some embodiments.
[0050] Figure 1 This is a flowchart illustrating an automatic generation and evaluation method for airborne system signal monitoring voting strategies provided in an embodiment of the present invention. The automatic generation and evaluation method for monitoring voting strategies provided in this embodiment of the present invention may include the following steps:
[0051] Step 1: Match at least one available pre-selected monitoring and voting strategy from the monitoring and voting algorithm simulation model library based on the attribute characteristics of the input signal;
[0052] Step 2: Based on the signal availability data and signal integrity data of the input signal, and the matched monitoring and voting strategy, evaluate whether the security of processing the input signal using the monitoring and voting strategy meets the security target requirements of the voting value, and obtain the recommended monitoring and voting strategy.
[0053] The monitoring and voting algorithm simulation model library is pre-configured and includes multiple simulation models, with different simulation models representing different monitoring and voting algorithms.
[0054] Furthermore, the method provided in this embodiment of the invention, based on steps 1 to 2 above, may further include:
[0055] Step 3: Score the recommended monitoring and voting strategy obtained in Step 2 and generate a strategy evaluation report.
[0056] The purpose of the automatic generation and evaluation method for airborne system signal monitoring voting strategy provided in this embodiment of the invention is:
[0057] On the one hand, a series of feasible monitoring and voting strategies are automatically matched to the input signal with known redundancy and communication methods, and the matched monitoring and voting strategies are quantitatively evaluated and compared. This allows for the rapid selection of a superior monitoring and voting strategy from numerous options without relying on expert experience. On the other hand, after determining the monitoring and voting strategy, the corresponding model in the monitoring and voting algorithm simulation model library provided in this invention can be used to automatically generate code, simplifying the subsequent verification work. Because the models in the model library have already been verified, it is not necessary to verify the model functionality again in specific project applications; only the correctness of the generated code needs to be verified.
[0058] On the other hand, the analysis results of each strategy can also serve as a basis for refining requirements regarding signal redundancy, communication methods, integrity indicators, and availability indicators. In summary, the automatic generation and evaluation method for monitoring and control voting strategies provided in this invention is applicable not only to the development and verification of underlying system requirements but also to the simulation and optimization of the architecture during the top-level architecture design and demonstration phases.
[0059] In this embodiment of the invention, before step 1, the following may also be included:
[0060] Step a: Set the input signal attributes according to user input. The input signal attributes include: redundancy quantity, signal data type (e.g., discrete / analog), signal source type, transmission channel type, signal source name, transmission channel name, signal availability data, signal integrity data, and security indicators of the voting value.
[0061] It should be noted that the prerequisites and core of the method provided in this embodiment of the invention are: two pre-configured model libraries, including: a monitoring voting algorithm simulation model library and a fault tree model library; first, at least one available monitoring voting strategy is matched in the monitoring voting algorithm simulation model library according to the architectural characteristics of the input signal; second, based on the availability and integrity data of the input signal (including loss probability, error probability, and risk time) as the input conditions of the fault tree in the fault tree model library, the availability and integrity of the voting value are calculated, and the security of processing the input signal using the monitoring voting strategy is evaluated to see if the requirements are met.
[0062] Furthermore, the method provided in this embodiment of the invention requires an interactive interface for users to set input signal attributes, and also needs to have comprehensive scoring capabilities. The input signal attributes that users need to set include redundancy quantity, signal data type (discrete / analog), signal source type, transmission channel type, signal source name, transmission channel name, signal availability data, signal integrity data, and the security index of the voting value. In the implementation of comprehensive scoring, scores can be given from three aspects: security analysis results, operational efficiency (simulation model runtime), and testability (fewer test cases required for verification), and a report is generated for users to comprehensively evaluate and select usable monitoring and voting strategies.
[0063] The method provided in the embodiments of the present invention will be described in detail below. Based on the input signal attributes set by the user in the embodiments of the present invention, the specific implementation process of step 1 may include:
[0064] Step 11: Perform structural analysis on the input signal based on the signal source name and transmission channel name set by the user to obtain the input signal name;
[0065] Step 12: Based on the input signal name and input signal attributes, match at least one simulation model from the monitoring voting algorithm simulation model library; the input signal attributes in Step 12 specifically refer to attributes other than the signal source name and transmission channel name.
[0066] Step 13: Generate model input based on the input interface of the matched simulation model, and assign values to the model input;
[0067] Step 14: Based on the assignment results of the model input, run the matched simulation model, obtain the output results of the simulation model, and generate a simulation model matching report.
[0068] In a specific implementation of this invention, step 11 described above may include:
[0069] Step 11a: Identify the signal source and transmission channel of each input signal, and perform independent identification on the identified signal source and channel;
[0070] Step 11b: Based on the independence identification result, the structure of the input signal is simplified to obtain the input signal name, and the input signal structure is transmitted in the form of the input signal name.
[0071] In this embodiment of the invention, a pre-configured monitoring and voting algorithm simulation model library contains multiple pre-configured simulation models, each with a unique preset number. The preset number fields include: redundancy, data type, signal source type, transmission channel type, and sequence number. The preset number indicates the input signal attribute characteristics to which the monitoring and voting algorithm of this simulation model is applicable. For example... Figure 2 The diagram shown illustrates the preset numbering of the simulation model in the automatic generation and evaluation method for airborne system signal monitoring voting strategies provided in this embodiment of the invention. Figure 2 The text provides a detailed explanation of the meaning of each digit in the preset number.
[0072] In a specific implementation of this invention, step 12 above may include: matching the user-set input signal attributes with the preset number of the simulation model in the monitoring voting algorithm simulation model library. The matching process includes determining the redundancy of the input signal, determining whether the input signal data type is discrete or analog, determining the signal source type, and determining the transmission channel type, i.e., determining whether a bus transmission segment is included.
[0073] In this embodiment of the invention, the method for assigning values to the model input in step 13 is as follows: under the condition that all fault flags output by the simulation model are FALSE and all validity flags of the input signals are TRUE, all assigned values to the model input are listed.
[0074] Accordingly, the specific implementation process of step 14 in this embodiment of the invention may include the following steps:
[0075] Step 14a: Based on all the assignment results of the model input of the simulation model in step 13, run the matched simulation model to obtain the output result of the simulation model. Eliminate some simulation models from the matched simulation models. The eliminated simulation models include: simulation models where the output fault is TRUE or the input signal validity is FALSE.
[0076] Step 14b: Generate a simulation model matching report based on the matched simulation model and the running results of the simulation model. The matching report lists the running results of the matched simulation model and identifies the simulation model that can match the input signal structure. The identified simulation model is used as the monitoring voting strategy, that is, the simulation model retained in step 14a.
[0077] In this embodiment of the invention, the specific implementation process of step 2 above may include:
[0078] Step 21: Based on the signal availability data and signal integrity data of the input signal, add fault models to the base events of the fault tree model corresponding to the monitoring voting strategy; the fault tree model library is pre-configured and includes a set of fault tree models corresponding to each simulation model.
[0079] Step 22: For input signals with a common signal source or transmission channel, add a common-mode fault model to the bottom event of the fault tree model;
[0080] Step 23: Run the fault tree model to generate a security analysis report, including: availability prediction data and integrity prediction data of the voting values of the input signals.
[0081] In this embodiment of the invention, the specific implementation of step 3 above may include:
[0082] The system includes operational efficiency, testing capability, and security scores. The operational efficiency and testing capability scores are preset scores for the recommended monitoring and voting strategy, while the security score is based on the difference between the data obtained from security analysis and the security target requirements.
[0083] The automatic generation and evaluation method for airborne system signal monitoring voting strategies provided in this invention has two main advantages. First, it automatically matches a series of feasible monitoring voting strategies to input signals with known redundancy and communication methods, and quantitatively evaluates and compares these strategies. This allows for the rapid selection of a superior monitoring voting strategy from numerous options without relying on expert experience. Second, after determining the monitoring voting strategy, the corresponding model in the monitoring voting algorithm simulation model library provided in this invention can be used to automatically generate code, simplifying subsequent verification work. Third, the analysis results of each strategy can also serve as a basis for refining requirements regarding signal redundancy, communication methods, integrity indicators, and availability indicators. This method is applicable to both the development and verification of underlying system requirements and the simulation and optimization of the architecture during the top-level architecture design and demonstration phases. The technical solution provided by this invention, through the practice of MBSE (Model Based System Engineering), breaks away from the traditional document-based approach to requirements capture, development, confirmation, and verification in product development. By using data and model-driven methods, it automates the entire process of requirements development, monitoring and voting design, design scheme analysis and optimization, and product implementation. This reduces reliance on manual labor, avoids human-introduced errors, reduces paperwork from solution to product, and shortens the development cycle.
[0084] The following detailed description of the implementation of the automatic generation and evaluation method for airborne system signal monitoring voting strategy provided by the present invention will be provided through some specific embodiments.
[0085] Specific Implementation 1, the automatic generation and evaluation method of airborne system signal monitoring voting strategy provided by Specific Implementation 1, mainly includes the following three parts.
[0086] Step 1: Matching the simulation model and generating the pre-selection monitoring voting strategy.
[0087] This step includes: structural analysis of the input signal's attributes, model matching, generating model inputs for the simulation model, and running the simulation model. Specifically, it includes: Step 11, based on the results of the signal attribute analysis, structurally naming the signal and generating the input signal name; Step 12, through attribute analysis of the input signal, determining a suitable simulation model for the input signal, at this point the matched simulation model only represents a formal match; Step 13, assigning values to the model inputs of the matched model and running the model, judging whether the model matches based on the model's output. Only when all fault signals in the model output are FALSE and all validity signals are TRUE is the model matched in a way that has practical meaning.
[0088] In this specific embodiment, different simulation models represent different monitoring and voting algorithms. These models target different input signal redundancy architectures, signal source types, and transmission methods. Therefore, simulation models can be categorized by signal redundancy level into 2, 3, 4, 6, and 8 redundancy models; by signal data type into discrete and analog models, with the former performing consistency comparisons and the latter determining out-of-tolerance judgments; by signal source type into VDT signal, two-position switch signal, multi-contact switch signal, and general signal monitoring and voting models. The VDT signal monitoring and voting model requires sensor high / low endpoints and value validity as input, the two-position switch signal monitoring and voting model must compare and monitor the corresponding signals of a pair of switches, and the multi-contact switch signal monitoring and voting model requires complementary monitoring of a group of contacts on a single switch; and by transmission path into bus signal and hard-wired signal monitoring and voting models, with the bus signal monitoring and voting model requiring bus validity as model input.
[0089] like Figure 2 The simulation models are numbered according to a set rule. Each simulation model has a unique preset number based on its classification characteristics. The final analysis report identifies which model it is by displaying the simulation model number.
[0090] Step two, security analysis.
[0091] In this specific embodiment, the fault tree models in the fault tree model library correspond to each simulation model in the monitoring and voting algorithm simulation model library, and the fault tree model library includes a set of fault tree models corresponding to each simulation model. Therefore, when the matching of simulation models is completed, the fault tree model used for security analysis is also determined accordingly.
[0092] The security analysis process in this step includes the following steps: Step 21, based on the signal availability data and signal integrity data of the input signal, add fault models to the bottom events of the fault tree model corresponding to the strategy; Step 22, for input signals with a common signal source or transmission channel, add common mode fault models to the bottom events of the fault tree model; Step 23, run the fault tree model to obtain the availability prediction data and integrity prediction data of the voting value.
[0093] Step 3: Strategy scoring.
[0094] This specific implementation will ultimately output a strategy evaluation report to the user, scoring the applicable monitoring and voting scheme in terms of security, operational efficiency, and testability.
[0095] For example, all three scores are based on a 5-point scale.
[0096] The security score is calculated based on the difference between the data obtained from the security analysis and the target requirements. The lower the probability of lost or erroneous votes while still meeting the target requirements, the higher the score. One point is awarded if the target requirement is within 20% of the predicted probability of lost or erroneous votes. One point is added for every 20% increase. A score of five points is awarded when the target requirement is twice or more than the predicted value.
[0097] The runtime efficiency score is based on the running time of the voting monitoring simulation model. It is a score inherent to the simulation model itself and is unrelated to the signal attributes configured by the user. The simpler the model and the faster it runs under the same conditions, the higher this score will be.
[0098] The testability score is also the score of the simulation model itself, and is independent of the input signal. The simpler the model logic and structure, the fewer test cases are needed to achieve 100% coverage testing, making it easier to test and verify, and thus resulting in a higher score.
[0099] Since the latter two items are only related to the mathematical simulation model itself, all models in the model library are sorted from high to low according to their running efficiency (or testability). The top 20% get 5 points, the top 20% to 40% get 4 points, the top 40% to 60% get 3 points, the top 60% to 80% get 2 points, and the bottom 20% get 1 point. Specific Implementation Example 2
[0101] The automatic generation and evaluation method for airborne system signal monitoring voting strategies provided in Specific Implementation 2 also includes three parts: the first part is to analyze the input signal and determine the applicable monitoring voting strategy; the second part is to perform security analysis based on the monitored voting strategy and calculate availability and integrity prediction data; and the third part is to evaluate the monitored voting strategy.
[0102] The method steps of this specific embodiment 2 are as follows: Figure 1 The process shown is as follows:
[0103] Step 1: Configure the properties of the input signal.
[0104] This step is completed manually by the user and can be performed through an interactive interface. First, the indicator requirements need to be set, including risk time, availability requirements for voting values, and integrity requirements. Then, the attributes to be set include the signal source for each redundancy signal, the signal transmission channel, and the signal data type (discrete or analog). Finally, the availability and integrity of the signal source and channel are set, as detailed in the following instructions. Figure 3 The diagram shown illustrates the configuration of an input signal attribute in an embodiment of the present invention. Simplification is required when setting up the signal source and transmission channel; two typical cases are described below.
[0105] by Figure 3 Taking the set signal as an example, the input signal is a discrete signal emitted by the contacts corresponding to the three positions of a mechanically redundant (two-blank) rotary switch (redundancy is 2*3). The mechanical part of this rotary switch can be topologically described as follows: Figure 3 Signal source 1 in the diagram, and the three position contacts of each rotary blade can be topologically converted into signal source 2, such as... Figure 4 As shown, Figure 3 The illustrated embodiment shows a topology diagram of the signal channel configured with input signal attributes. ln1, ln2, and ln3 represent the hardwired cables connected to the contacts and the plugs inserted into the signal processing equipment, according to... Figure 4 Channel 1 in the topology. ace1, ace2, and ace3 represent different signal processing devices and their cables and connectors to the computer where the signal voting function is located. Figure 4 Channel 2 of the topology. Sensors with both mechanical and electrical components, such as two-position switches, VDT sensors, and wind vane selectors, can all be configured using this method to facilitate the separate setup of redundancy architectures for the two components.
[0106] To illustrate further, for example, Figure 5 The diagram shown illustrates the configuration of another input signal attribute in an embodiment of the present invention. Figure 6 for Figure 5 This is a topological diagram of the signal channel configuration for the input signal attributes in the illustrated embodiment. Figure 5 Taking the input signal attributes set in the example, this input signal comes from an external cross-linking system with a dual-redundancy architecture. The two redundancies are independent of each other; each signal source emits two signals, which are transmitted to a forwarding device (ACE) via the A429 bus. Therefore, this input signal is a 2*2 redundant bus signal. The external cross-linking device topology is as follows: Figure 6 Signal source 1; the topology of the A429 bus output interface, cable, and ACE of the crosslinking equipment and the A429 bus receiving interface is as follows: Figure 5 Channel 1; the input interface topology of the computer containing the ACE signal processing section, output interface, and monitoring and voting functions is as follows: Figure 6 Channel 2 in the diagram. Almost all external cross-linked devices that can be proven to be independent of each other can be topologically constructed using this method, without distinguishing the internal structure of the cross-linked devices, thus simplifying the signal structure.
[0107] Step 2: Perform structural analysis on the input signal.
[0108] This step is completed automatically through software programming. The main content involves identifying the signal source and transmission channel of each input signal, and independently identifying these signal sources and channels to further simplify the signal structure. Finally, the signal structure is transmitted in the form of the input signal name. In this specific embodiment, the parsed input signal structure is used to generate the input for the simulation model and the input for the fault tree model.
[0109] The input signal naming convention is "src_xxxx1_xxxx2_ch_yyy1_yyy2_input", where the fields xxxx1 and xxxx2 after "src_" represent the signal source, the fields yyy1 and yyy2 after "ch_" represent the channels passed through, and input is the default suffix. There is no fixed length for each field name, as the input signal name is parsed by identifying "src_", "ch_", and "_" to separate fields, and the end of a signal name is determined by recognizing "input".
[0110] The principle of simplifying the input signal structure is to combine completely independent signal sources or channels.
[0111] by Figure 5 Taking the configured 4-redundant bus signal as an example, firstly, according to the user-defined input signal source and transmission channel, the input signals are named, resulting in the following names for the 4 input signals:
[0112] src_src1_ch_trans1_ace1_input,
[0113] src_src1_ch_trans2_ace2_input,
[0114] src_src1_ch_trans3_ace3_input,
[0115] src_src2_ch_trans4_ace4_input.
[0116] As can be seen, the four input signal channels are completely independent of each other, such as Figure 7 As shown, this is for Figure 5 The illustrated embodiment shows a simplified topology diagram of the input signal configuration. Therefore, the input signal structure can be arranged according to... Figure 7 After topology simplification, the simplified input signal names of the four input signals are src_src1_ch_ch1_input, src_src1_ch_ch2_input, src_src1_ch_ch3_input, and src_src2_ch_ch4_input.
[0117] Step 3: Match the monitoring and voting simulation model according to the characteristics of the signal structure.
[0118] This process is automated through software programming. The method involves sequentially determining the attributes of the user-defined input signals. Figure 2 Which number or letter in each byte of (for the simulation model number).
[0119] First, determine the redundancy of the input signal; then, determine whether the input signal data type is discrete or analog; next, determine the type of signal source; and finally, determine whether the transmission channel includes a bus transmission segment.
[0120] For example Figure 3 The input signal attributes set in the configuration are as follows: the input signal is a 6-redundant switching quantity, which is a discrete quantity. The signal source type is a multi-contact switch. The transmission channel between the transfer device ACE and the computer is bus transmission. Therefore, the model corresponding to this input signal should be 6-ACA-01, 6-ACA-02, ...
[0121] For example Figure 5 The input signal attribute is set in the configuration. The input signal is a 4-redundant analog signal and the signal source type is a general device. Whether it is from the signal source to the relay device ACE or from ACE to the computer, it is a bus transmission. Therefore, the model corresponding to this signal should be 4-BDA-01, 4-BDA-02, ...
[0122] Step 4: Generate the model input for the simulation model and assign values.
[0123] This step first generates the corresponding model input based on the input interface of the matched simulation model; then, it assigns values to the generated model input. The principle of assignment is to list all possibilities while ensuring that all fault flags output by the simulation model are FALSE (indicating no fault) and all input signal validity flags are TRUE.
[0124] Table 1 below illustrates the input signals required for each simulation model.
[0125] Table 1 shows the model inputs required for the simulation model, where xx represents multiple models of the same type.
[0126]
[0127]
[0128]
[0129]
[0130] Step 5: Run the simulation model and output the matching results.
[0131] Assign values to the model inputs of the simulation models matched in step 3 according to Table 1, and run these models. Obtain the output results of the simulation models, and exclude models where the output fault is TRUE or the signal validity is FALSE.
[0132] Generate a matching report that lists the results of all run models and indicates which models match the signal architecture input by the user.
[0133] Step 6: Configure the bottom events of the fault tree.
[0134] The monitoring voting model and fault tree are matched one-to-one. Specifically, the fault tree model library includes a set of fault tree models corresponding to each simulation model, but it is necessary to set the fault model of the bottom event (including failure rate, risk time, model type, etc.) and set the CCF (common mode fault model) model of the bottom event according to the intersection of the channels. The simplified four-redundancy signals src_src1_ch_ch1_input, src_src1_ch_ch2_input, src_src1_ch_ch3_input, and src_src2_ch_ch4_input after step 2 are used as examples for explanation.
[0135] Due to the simplification in step 2, the channel corresponding to ch1 is the combined value of trans1 and ace1. Therefore, the integrity and availability data of ch1 should be the sum of the values of trans1 and ace1. The availability and integrity data of the other three signals are obtained using the same principle.
[0136] Figure 8 This is a schematic diagram illustrating the principle of the voting value availability assessment model corresponding to the 4-ADA-01 simulation model. Figure 9 This is a schematic diagram of the voting value availability assessment model corresponding to the 4-ADA-02 simulation model corrected by the CCF model. There are two fault tree models corresponding to this signal architecture matching simulation model, as shown below. Figure 8 and Figure 9 As shown. For Figure 8 In the simulation model shown, the availability index of src1 is assigned to signal source 1 as lost, and the integrity index is assigned to signal source 1 as incorrect. src2 corresponds to signal source 2. ch1 to ch4 correspond to channels 1 to 4 respectively. The availability index is assigned to channel loss, and the integrity index is assigned to channel error, resulting in signal error. For Figure 9 In the simulation model shown, the availability index of src1 is assigned to the loss of signal source 1 and the loss of signal source 2, and the availability index of src2 is assigned to the loss of signal source 3 and the loss of signal source 4. The availability indices of ch1 to ch4 are assigned to the loss of channel 1, the loss of channel 2, the loss of channel 3, and the loss of channel 4, respectively.
[0137] Next, we analyze whether there is a common-mode fault among the base events of the fault tree model. If so, an additional common-mode fault factor needs to be added. The common-mode fault factor is a percentage. If two base events correspond to the same component failure, the common-mode fault factor is 100%. If two signal sources have some common components (such as common interfaces), the ratio of the component failure probability to the overall signal source failure probability is the value of the common-mode fault factor.
[0138] for Figure 9 In the simulation model, signal source 1 and signal source 2 actually represent the same device, so a common-mode fault factor CC1 is added with a value of 100%. Similarly, a common-mode fault factor CC2 is added for signal source 3 and signal source 4.
[0139] This step can be completed automatically by software.
[0140] Step 7: Run the fault tree model and generate a security analysis report.
[0141] Each simulation model has a set of fault tree analysis models to analyze the availability and integrity of voting values. The results of the fault tree models (including predictions of voting value availability and integrity) are compared with the security objectives, eliminating schemes that do not meet the requirements, and finally obtaining all feasible strategies.
[0142] Step 8: Combine all scores to generate a strategy evaluation report.
[0143] After obtaining all feasible strategies, the security of each strategy is scored.
[0144] The security score is based on the difference between the data obtained from the security analysis and the target requirements. The lower the probability of lost or erroneous votes while meeting the target requirements, the higher the score. If the target requirement is within 20% of the predicted probability of lost or erroneous votes, 1 point is awarded. For every 20% increase, 1 point is added. When the target requirement is twice or more than the predicted value, the score is 5 points.
[0145] The evaluation report for this specific embodiment has three scores: operational efficiency, testability, and security.
[0146] The scores for operational efficiency and testability depend entirely on the strategy itself and are therefore pre-stored values in the system. The security score comes from step 7. The evaluation report lists all suitable solution codes and their three scores, from which the user selects the solution best suited for their designed product.
[0147] While the embodiments disclosed in this invention are as described above, the content is merely for the purpose of facilitating understanding of the invention and is not intended to limit the invention. Any person skilled in the art to which this invention pertains may make any modifications and changes to the form and details of the implementation without departing from the spirit and scope disclosed herein; however, the scope of patent protection of this invention shall still be determined by the scope defined in the appended claims.
Claims
1. A method for automatically generating and evaluating voting strategies for airborne system signal monitoring, characterized in that, include: Step 1: Match at least one available pre-selected monitoring and voting strategy from the monitoring and voting algorithm simulation model library based on the attribute characteristics of the input signal; Step 2: Based on the signal availability data and signal integrity data of the input signal, and the matched monitoring and voting strategy, evaluate whether the security of processing the input signal using the monitoring and voting strategy meets the security target requirements of the voting value, and obtain the recommended monitoring and voting strategy. The monitoring and voting algorithm simulation model library is pre-configured and includes multiple simulation models, with different simulation models representing different monitoring and voting algorithms. Step 1 includes: Step 11: Perform structural analysis on the input signal based on the signal source name and transmission channel name set by the user to obtain the input signal name; Step 12: Match at least one simulation model in the monitoring voting algorithm simulation model library based on the input signal name and input signal attributes; Step 13: Generate model input based on the input interface of the matched simulation model, and assign values to the model input; Step 14: Based on the assignment results of the model input, run the matched simulation model, obtain the output results of the simulation model, and generate a simulation model matching report; Step 11 includes: Step 11a: Identify the signal source and transmission channel of each input signal, and perform independent identification on the identified signal source and channel; Step 11b: Based on the independence identification result, the structure of the input signal is simplified to obtain the input signal name, and the structure of the input signal is transmitted in the form of the input signal name; Step 12 includes: The system matches the user-defined input signal attributes with the preset numbers of the simulation models in the monitoring and voting algorithm simulation model library. The matching process includes determining the redundancy of the input signal, determining whether the input signal data type is discrete or analog, determining the signal source type, and determining the transmission channel type. The method for assigning values to the model input in step 13 is as follows: under the condition that all fault flags output by the simulation model are FALSE and all validity flags of the input signals are TRUE, all assigned values to the model input are listed. Step 14 includes: Step 14a: Based on all the assignment results of the model input of the simulation model in step 13, run the matched simulation model to obtain the output result of the simulation model. Eliminate some simulation models from the matched simulation models. The eliminated simulation models include: simulation models where the output fault is TRUE or the input signal validity is FALSE. Step 14b: Generate a simulation model matching report based on the matched simulation model and the running results of the simulation model. The matching report lists the running results of the matched simulation model and identifies the simulation model that can match the input signal structure. The identified simulation model is used as the monitoring voting strategy.
2. The method for automatically generating and evaluating airborne system signal monitoring voting strategies according to claim 1, characterized in that, Before step 1, the following are also included: Step a: Set input signal attributes according to user input. The input signal attributes include: redundancy quantity, signal data type, signal source type, transmission channel type, signal source name, transmission channel name, signal availability data, signal integrity data, and security indicators of the voting value.
3. The method for automatically generating and evaluating airborne system signal monitoring voting strategies according to claim 1, characterized in that, The monitoring and voting algorithm simulation model library contains multiple pre-configured simulation models, and each simulation model has a unique preset number. The preset number includes: redundancy-data type-signal source type-transmission channel type-sequence number. The preset number is used to indicate the input signal attribute characteristics to which the monitoring and voting algorithm of this simulation model is applicable.
4. The method for automatically generating and evaluating airborne system signal monitoring voting strategies according to any one of claims 1 to 3, characterized in that, Step 2 includes: Step 21: Using the signal availability data and signal integrity data of the input signal as input conditions for the fault trees in the fault tree model library, add fault models to the base events of the fault tree model corresponding to the monitoring voting strategy; the fault tree model library is pre-configured and includes a set of fault tree models corresponding to each simulation model. Step 22: For input signals with a common signal source or transmission channel, add a common-mode fault model to the base event of the fault tree model; Step 23: Run the fault tree model to generate a security analysis report, including: availability prediction data and integrity prediction data of the voting values of the input signals.
5. The method for automatically generating and evaluating airborne system signal monitoring voting strategies according to claim 4, characterized in that, Also includes: Step 3: Score the recommended monitoring and voting strategy obtained in Step 2 and generate a strategy evaluation report.
6. The method for automatically generating and evaluating airborne system signal monitoring voting strategies according to claim 5, characterized in that, Step 3 includes: The system includes operational efficiency, testing capability, and security scores. The operational efficiency and testing capability scores are preset scores for the recommended monitoring and voting strategy, while the security score is based on the difference between the data obtained from security analysis and the security target requirements.
Citation Information
Patent Citations
Fault real-time detection method of airborne information system
CN113360306A
Hardware simulation systems and methods for reducing signal dumping time and size by fast dynamical partial aliasing of signals having similar waveform
US20200104443A1