A Method for Analyzing and Verifying the Software Safety Properties of Unmanned Aerial Vehicles Based on a Fault Mode Library
By establishing a software failure mode database and designing static analysis modules and dynamic monitors, the problems of drone software failure detection and analysis are solved, and the safety and reliability of the drone system are improved.
Patent Information
- Application Number
- CN202210255754.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-15
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-03-15
AI Technical Summary
It is difficult for the existing technology to effectively organize and utilize software failure data and generate software failure mode libraries, making it difficult to achieve efficient fault detection and analysis of drone software.
By establishing a software failure mode database, filtering applicable software failure modes, writing security nature regulations, and designing static analysis modules and dynamic monitors, static and dynamic analysis of drone software can be realized.
It improves the security and reliability of the drone system, can detect faults that cannot be recognized by traditional compilers, and reduces the use of drone computing resources.
Smart Images

Figure CN114676047B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of software failure mode and operation verification, and particularly to a method for analyzing and verifying the safety properties of UAV software based on a failure mode library. Background Art
[0002] In modern various equipment systems, products with software as the core have been widely used. With the continuous increase of software components in the system, the system's dependence on software is getting greater and greater, and the requirements for software quality, especially reliability, maintainability, and functionality, are also getting higher and higher. Software quality is the life of software. In recent years, due to software quality problems, there have been numerous cases of serious consequences and economic losses. Especially in the fields of aerospace and others, minor flaws in software may cause huge property losses of astronomical figures and even pose a serious threat to national security. In recent years, UAVs have been widely used in military and civilian fields. Therefore, the safety and reliability of UAVs are also one of the key concerns of society.
[0003] At present, people do not have a very in-depth study on the software failure mode library. A software system is a complex system with multiple tasks and multiple configuration items, and there are various failure modes. There are common failure modes and unique failure modes among different systems. The evaluation center has a large amount of failure data, but lacks the collation and induction of these data, and does not deeply analyze the mechanism of common failures. How to generate a software failure mode library using historical failure data and then use this mode library to better achieve failure detection is a problem worthy of research.
[0004] Runtime verification technology belongs to formal verification technology. It uses logical formulas to describe properties and then converts them into formal structures. Runtime verification tends to check finite paths, that is, whether the running path of the system satisfies the safety property up to the current moment. Since this method was proposed, it has received continuous attention in the academic field and the industrial field. One of its characteristics is that it plays a role during the operation of the software system. It monitors the system in a real operating environment, so it is possible to discover potential defects that are difficult to discover by traditional software testing methods. Summary of the Invention
[0005] In view of this, this application provides a method for analyzing and verifying the safety properties of UAV software based on a failure mode library, which solves the problems in the prior art and improves the safety and reliability of the UAV system.
[0006] A method for analyzing and verifying the safety properties of UAV software provided by this application adopts the following technical solutions:
[0007] A method for analyzing and verifying the safety properties of UAV software based on a failure mode library includes:
[0008] Establish a software fault mode database;
[0009] With reference to the software fault mode database, screen the software fault modes applicable to the target system for software operation in combination with the actual project requirements, and compile a security property specification;
[0010] Design a static analysis module applicable to the target system for software operation with reference to the fault mode library. The static analysis module performs static analysis on the software target system in combination with the fault database to check for common faults and unique errors in the target system;
[0011] Read the security property specification and extract at least part of the information in the security property specification to generate a security property monitor;
[0012] Read the security property specification and extract at least part of the information in the security property specification for instrumentation of monitoring events;
[0013] If the target system triggers a monitoring event, the target system sends data to the monitor, and the monitor analyzes the data to obtain an analysis result, realizing dynamic monitoring.
[0014] Optionally, the steps of establishing the software fault database include software fault mechanism analysis, software fault mode feature recognition, software fault mode feature characterization, and software fault feature matching.
[0015] Optionally, the fault mechanism analysis includes extracting the common and individual characteristics of multiple software fault modes, determining the software fault mode attributes according to the differences between software faults of different equipment, establishing the correlation between the elements of the software fault introduction, trigger, and conduction processes and the software fault attributes, and forming a complete description of the software fault occurrence process.
[0016] Optionally, the software fault mode feature recognition specifically includes:
[0017] Continuously refine the identified features through different feature analysis activities, discover relevant variability, and provide an information basis for software fault mode matching;
[0018] Among them, the features at least include functions, executions, and interfaces.
[0019] Optionally, the software fault mode feature characterization includes designing different feature descriptions for different software fault mode features. The feature descriptions at least include measurement parameters, measurement parameter data acquisition methods, and measurement parameter deviation thresholds, providing a criterion basis for accurate software fault mode matching.
[0020] Optionally, the software fault feature matching includes:
[0021] Establish the mapping between software fault mode attributes and software requirement model elements to provide support for model - based software fault mode matching;
[0022] With the help of software fault mode feature selection technology, eliminate features with low correlation;
[0023] On the basis of the selected software fault mode feature subset, perform matching according to the characterization methods of each feature measurement parameter in the feature subset to obtain software fault modes.
[0024] Optionally, the content of the security property specification includes monitor - generated information and monitor - event instrumentation information;
[0025] The monitor - generated information includes the events to be monitored and the properties expected to be satisfied, which are used to generate a security property monitor. The monitoring properties are written in a temporal logic formula, and the monitoring events are the basic elements in the monitoring properties;
[0026] The monitor - event instrumentation information is the characteristics of the object to be instrumented, which is used for the instrumentation of monitor events. The monitor - event instrumentation information includes at least statement type, variable name, variable type, and function signature. Appropriate instrumentation points are matched according to the characteristics for code instrumentation.
[0027] Optionally, read the security property specification, extract at least part of the information in the security property specification to generate a security property monitor. Specifically, extract the logical formula from the specification and generate an equivalent security property monitor through a conversion algorithm.
[0028] Optionally, establish a distributed system including an unmanned aerial vehicle (UAV), a monitor, and a console. The monitor receives the data sent by the UAV system when a monitor event is triggered, the monitor analyzes the data on the local computing device and obtains the analysis result, and the console intervenes in the UAV according to the analysis result.
[0029] In summary, the present application includes the following beneficial technical effects:
[0030] 1. During the static analysis process, traditional compilers can perform static analysis on code to check for potential problems. However, due to the differences between the fault modes of different target systems, there are individual characteristics in the software fault modes of the target system. There are faults in the software fault mode library of a specific target system that cannot be recognized by traditional compilers, and these faults are relatively common in that target system. Therefore, it is necessary to design a dedicated static analysis module for the target system with reference to the fault mode library of the target system. This process requires modifying the traditional compiler and adding a part of new detection code in the lexical analysis, syntax analysis, and semantic analysis phases. The specific content is related to the faults to be detected. Finally, use the modified compiler to compile the code of the target system, which can not only detect traditional coding errors but also detect errors specific to the target system.
[0031] 2. Considering that embedded systems including drones often have strict timing requirements, and the computing resources of the platform are limited, and there may be strict timing requirements between multiple tasks. At this time, the monitoring task may consume too much computing resources, affecting the execution of the original tasks of the drone. Therefore, in this application, instead of installing the monitor inside the drone system, message sending statements are selected for installation. After installation, when the system runs to this position, a message sending action will be triggered, and relevant information will be sent to the monitor for analysis. The analysis process is completed by a local high-performance computing device, and the console intervenes in the drone according to the analysis results, so that the three of the drone, the monitor, and the console form a distributed platform, and data is transmitted through the network. While monitoring the drone, the occupancy of the drone's computing resources is reduced.
[0032] 3. Against the background of the wide application of drones and the focus on software security, this application combines the software fault mode library and runtime verification technology, organizes and analyzes the existing software failure data to obtain a software fault mode database, screens out the fault modes applicable to the drone system, and conducts more rigorous static detection and dynamic monitoring on them, which helps to improve the safety and reliability of the drone. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the technical solutions of the embodiments of this application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0034] Figure 1 It is a schematic diagram of the analysis process of the system security properties of this application;
[0035] Figure 2 It is a part of the analysis process of the system security properties of this application;
[0036] Figure 3 It is another part of the analysis process of the system security properties of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] The embodiments of this application will be described in detail below with reference to the drawings.
[0038] The following describes the implementation manners of the present application through specific specific examples. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the present application.
[0039] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present application, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using other structures and / or functions in addition to one or more of the aspects described herein.
[0040] It should also be noted that the diagrams provided in the following embodiments only illustrate the basic concept of the present application in a schematic manner. The diagrams only show the components related to the present application and are not drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0041] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0042] An embodiment of the present application provides a method for analyzing and verifying the software safety properties of an unmanned aerial vehicle based on a fault mode library.
[0043] As Figures 1-3 shown, a method for analyzing and verifying the software safety properties of an unmanned aerial vehicle based on a fault mode library includes:
[0044] Establish a software fault mode database.
[0045] Refer to the software fault mode database, and select the software fault modes applicable to the target system for software operation in combination with the actual project requirements, and write the security property specification. The target system of this application is an unmanned aerial vehicle.
[0046] Design a static analysis module applicable to the target system for software operation with reference to the fault mode library. The static analysis module performs static analysis on the software target system in combination with the fault database to check for common faults and unique errors in the target system.
[0047] Read the security property specification and extract at least part of the information in the security property specification to generate a security property monitor.
[0048] Read the security property specification and extract at least part of the information in the security property specification for instrumentation of monitoring events.
[0049] If the target system triggers a monitoring event, the target system sends data to the monitor, and the monitor analyzes the data to obtain an analysis result, realizing dynamic monitoring.
[0050] Classify and summarize the existing software fault data set to obtain a software fault mode database. It includes fault mechanism analysis, software fault mode feature recognition, software fault mode feature characterization, and software fault feature matching.
[0051] The process of the fault mechanism analysis is as follows: Analyze and study the historical software fault data, summarize and classify it, extract the common and individual characteristics of various software fault modes, and determine the software fault mode attributes according to the differences between the software faults of different equipment. The differences between the software faults of equipment can be considered from several aspects such as fault category, fault impact, and fault scope. Based on the association relationship between model elements and fault modes and the software fault mode attributes, establish the association relationship between the elements involved in the introduction, trigger, conduction, and occurrence processes of software faults, and the deduction relationship between these elements, and form a complete description of the software fault occurrence process.
[0052] The software fault mode feature recognition specifically includes: continuously refining the identified features through different feature analysis activities, discovering relevant variability, and providing an information basis for software fault mode matching; wherein, the features include at least functions, executions and interfaces. The detailed description is: the process of software fault mode feature recognition needs to consider feature analysis such as functions, executions, interfaces, and related constraint features; through function analysis activities, execution analysis activities, and interface analysis activities, the identified features are continuously refined and relevant variability is discovered, providing an information basis for improving the accuracy of software fault mode matching. Specifically, the following method is used to extract complete software attributes, based on the method given in the IEEE 1044-2009 standard, combined with the ideas in the GJB 437-88, GJB / Z 1391-2006, and GJB 841-90 standards, from the perspective of being conducive to fault control and management and facing fault data applications, attributes are added, deleted, and modified, and triggered from the perspective that the modification of a certain attribute does not affect other attributes, and the above-extracted attributes are orthogonally adjusted. Finally, fault attribute fields that take into account both efficiency and quality are extracted, which are accurately defined, convenient for collection and conducive to the reuse of fault data in the later stage.
[0053] The software fault mode feature characterization includes designing different feature descriptions for different software fault mode features, and the feature descriptions include at least measurement parameters, measurement parameter data collection methods and measurement parameter deviation thresholds, so as to provide a basis for accurate software fault mode matching. The detailed description is as follows: the software fault mode feature characterization should focus on the determined fault attributes, perform feature descriptions of the attributes, and clarify the attribute values. The features determined in this process should be consistent with the software operation characteristics, reflect the software fault characteristics, consider the future fault data usage scenarios and the difficulty of utilization, be able to reflect the repetitiveness and regularity of the same faults to facilitate multi-dimensional "reuse", and be combined with the needs of different roles in software development activities. If the language describing the features under the same attributes of different fault data expresses the same features or the same connotations, then the different descriptions are summarized and integrated into the same feature, and a suitable "name" is given; for the attributes added for subsequent software development or for management and application considerations, appropriate corresponding features are added according to the above requirements. Finally, a patterned and standardized objective language expression is used to describe the features of the fault data in each attribute.
[0054] The software fault feature matching includes: establishing a mapping between software fault mode attributes and software requirement model elements to provide support for model-based software fault mode matching; using software fault mode feature selection technology to eliminate features with low correlation; based on the selected software fault mode feature subset, matching is performed according to the characterization method of each feature measurement parameter in the feature subset to obtain the software fault mode.
[0055] The content of the security property specification includes monitor-generated information and monitoring event instrumentation information; the monitor-generated information includes the events to be monitored and the properties expected to be satisfied, which are used to generate a security property monitor. The monitoring properties are written in a temporal logic formula, and the monitoring events are the basic elements in the monitoring properties. The monitoring event instrumentation information is the characteristics of the object to be instrumented, which is used for the instrumentation of monitoring events. The monitoring event instrumentation information includes at least the statement type, variable name, variable type, and function signature, and appropriate instrumentation points are matched according to the characteristics for code instrumentation.
[0056] Read the security property specification and extract at least part of the information in the security property specification to generate a security property monitor. Specifically, extract the logical formula from the specification and generate an equivalent security property monitor through a conversion algorithm. Specifically, establish a monitor generation module, which will extract the logical formula from the specification and generate an equivalent security property monitor through a conversion algorithm. The specific construction steps are to convert the temporal logic formula into a generalized Büchi automaton, delete the unreachable nodes and merge equivalent nodes in the graph structure, delete the acceptance conditions in the graph structure, determinize and minimize the automaton, and finally generate a monitor in the form of a deterministic finite automaton. Establish a code instrumentation module, which will extract the instrumentation information from the specification, including the instrumentation location and the instrumentation content. The instrumentation location is determined by the behavior to be monitored.
[0057] During the static analysis process, a traditional compiler can perform static analysis on the code to check for potential problems. However, due to the differences between the failure modes of different target systems, there are individual characteristics in the software failure modes of the target system. There are faults in the software failure mode library of a specific target system that cannot be recognized by the traditional compiler, and these faults are relatively common in that target system. Therefore, it is necessary to design a dedicated static analysis module for the target system with reference to the failure mode library of the target system. This process requires modifying the traditional compiler and adding a part of new detection code in the lexical analysis, syntax analysis, and semantic analysis stages. The specific content is related to the faults to be detected. Finally, use the modified compiler to compile the code of the target system, which can not only detect traditional coding errors but also detect errors specific to the target system.
[0058] In a specific embodiment, the unmanned aerial vehicle system is used as the target system.
[0059] During the static analysis process, design a dedicated static analysis module for the unmanned aerial vehicle with reference to the failure mode library. This process requires modifying the traditional compiler and adding a part of new detection code in the lexical analysis, syntax analysis, and semantic analysis stages. The specific content is related to the faults to be detected. Finally, use the modified compiler to compile the code of the unmanned aerial vehicle, which can not only detect traditional coding errors but also detect errors specific to the unmanned aerial vehicle.
[0060] A distributed system including a drone, a monitor, and a console is established. The monitor receives the data sent by the drone system when a monitoring event is triggered, analyzes the data on the local computing device and obtains an analysis result, and the console intervenes in the drone according to the analysis result.
[0061] Specifically, considering that embedded systems including drones often have strict timing requirements, and the computing resources of the platform are limited, and there may be strict timing requirements between multiple tasks. At this time, the monitoring task may consume too much computing resources and affect the execution of the original tasks of the drone. Therefore, in this application, instead of installing the monitor inside the drone system, message sending statements are selected for installation. After installation, when the system runs to this position, a message sending action will be triggered to send relevant information to the monitor for analysis. The analysis process is completed by the local high-performance computing device, and the console intervenes in the drone according to the analysis result, so that the drone, the monitor, and the console form a distributed platform to transmit data through the network. While monitoring the drone, the occupancy of the computing resources of the drone is reduced.
[0062] Under the background of the wide application of drones and the emphasis on software security, this application combines the software fault mode library and runtime verification technology, organizes and analyzes the existing software failure data to obtain a software fault mode database, screens out the fault modes applicable to the drone system, and conducts more rigorous static detection and dynamic monitoring on them, which helps to improve the safety and reliability of the drone.
[0063] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in this application should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A method for analyzing and verifying the safety properties of UAV software based on a fault mode library, characterized in that, Including: Establish a software failure mode database; Refer to the software failure mode database, combine with the actual project requirements to screen the software failure modes applicable to the target system of software operation, and write safety property specifications; Design a static analysis module applicable to the target system of software operation with reference to the failure mode library. The static analysis module combines the failure database to perform static analysis on the software target system, and checks for common failures and specific errors of the target system; Read the safety property specifications, and extract at least part of the information in the safety property specifications to generate a safety property monitor; Read the safety property specifications, and extract at least part of the information in the safety property specifications for the instrumentation of monitoring events; If the target system triggers a monitoring event, the target system sends data to the monitor. The monitor analyzes the data and obtains an analysis result to achieve dynamic monitoring; Establish a distributed system including an unmanned aerial vehicle, a monitor, and a console. The monitor receives the data sent by the unmanned aerial vehicle system when a monitoring event is triggered. The monitor analyzes the data on the local computing device and obtains an analysis result. The console intervenes in the unmanned aerial vehicle according to the analysis result; The steps of establishing the software failure mode database include software failure mechanism analysis, software failure mode feature recognition, software failure mode feature characterization, and software failure feature matching; The software failure mechanism analysis includes extracting the common and individual characteristics of multiple software failure modes, determining the software failure mode attributes according to the differences between software failures of different equipment, establishing the correlation relationship between the elements of the software failure introduction, trigger, and conduction processes and the software failure attributes, and forming a complete description of the software failure occurrence process; The software failure mode feature recognition specifically includes: Continuously refine the identified features through different feature analysis activities, discover relevant variability, and provide an information basis for software failure mode matching; Among them, the features at least include functions, executions, and interfaces.
2. The method for analyzing and verifying the safety properties of UAV software based on a fault mode library according to claim 1, characterized in that, The software failure mode feature characterization includes designing different feature descriptions for different software failure mode features. The feature descriptions at least include measurement parameters, measurement parameter data acquisition methods, and measurement parameter deviation thresholds, providing a criterion basis for accurate software failure mode matching; 3. The method for analyzing and verifying the safety properties of UAV software based on a fault mode library according to claim 1, characterized in that, The software failure feature matching includes: Establish a mapping between software failure mode attributes and software requirement model elements to provide support for model-based software failure mode matching; With the help of software failure mode feature selection technology, eliminate features with low correlation; On the basis of the selected software failure mode feature subset, perform matching according to the characterization methods of the measurement parameters of each feature in the feature subset to obtain the software failure mode.
4. The method for analyzing and verifying the safety properties of UAV software based on a fault mode library according to claim 1, characterized in that, The content of the safety property specifications includes monitor-generated information and monitoring event instrumentation information; The monitor-generated information includes the events to be monitored and the properties expected to be satisfied, which are used to generate a safety property monitor. The monitoring properties are written by temporal logic formulas, and the monitoring events are the basic elements in the monitoring properties; The monitoring event instrumentation information is the characteristics of the object to be instrumented, which is used for the instrumentation of monitoring events. The monitoring event instrumentation information at least includes statement types, variable names, variable types, function signatures, and appropriate instrumentation points are selected according to the characteristics for code instrumentation.
5. The method for analyzing and verifying the safety properties of UAV software based on a fault mode library according to claim 4, characterized in that, The read security property specification is parsed to extract at least some of the information in the security property specification to generate a security property monitor. Specifically, logical formulas are extracted from the specification, and an equivalent security property monitor is generated through a transformation algorithm.
Citation Information
Patent Citations
Method for constructing information system running rule libraries on basis of association rule mining
CN104376365A