A Formal Verification Method for PPTLI Theorem Proof Based on PVS

Through the PPTLI theorem proof method based on PVS, a PPTLI theorem proof system is constructed, which solves the problem of limitations in the temporal logical expression ability in the existing technology, realizes effective formal verification of the properties of complex systems, and provides comprehensive software and hardware system security and credibility verification guarantees.

CN115080112BActive Publication Date: 2025-05-13XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210575903.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-25
Publication Date
2025-05-13
Estimated Expiration
2042-05-25

AI Technical Summary

Technical Problem

In the existing theorem proof technology, the timing logic used in the underlying layer has its own limitations in expression capabilities, making it difficult to form a comprehensive system and cannot provide comprehensive guarantees for the security and credibility verification of software and hardware systems.

Method used

A formal verification method for PPTLI theorem proof based on PVS is provided. By constructing the basic timing type and index expression type of PPTLI, and equivalently representing linear timing logic, a PPTLI theorem proof system is constructed to perform interactive proof of the PPTLI timing properties to be proofed.

Benefits of technology

This method can provide strong expression capabilities, can be used to describe various complex systems properties, solve the problem of unreliable verification of traditional software testing methods or state-limited model detection methods, and provide comprehensive guarantees for the security and credibility verification of software and hardware systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115080112B_ABST
    Figure CN115080112B_ABST
Patent Text Reader

Abstract

The present invention relates to a formal verification method for PPTLI theorem proof based on PVS, comprising: S101: obtaining the basic timing type of PPTLI and the index expression type of PPTLI through PVS construction, and equivalently representing the linear temporal logic according to the index expression type of PPTLI; S102: obtaining the PPTLI theorem proving system through PVS construction according to the basic timing type of PPTLI and the index expression type of PPTLI; S103: expressing the PPTLI timing property to be proved as a theorem, and using the PVS interactive proof command to use the PPTLI theorem proving system to prove the PPTLI timing property to be proved. The method of the present invention uses PPTLI, a temporal logic with strong expression ability and comprehensive unity, to describe and prove the expected properties of a computer system, which can make up for the shortcomings of existing theorem proving technology to ensure the security and reliability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of formal verification, and in particular relates to a formal verification method for PPTLI theorem proof based on PVS. Background Art

[0002] As computer hardware and software systems continue to develop towards large-scale and high-performance, such systems have gradually become an important means to ensure system security and reliability. In the absence of reliable system verification, how to avoid design errors and construct more reliable systems has gradually become a challenge. When many systems are used in safety-critical scenarios, cases of major accidents caused by potential minor vulnerabilities are not uncommon. In June 1996, when the Ariane 5 launch vehicle conducted its first launch test, the rocket exploded 37 seconds after launch. The reason was that a piece of code inherited from Ariane 4 and unnecessary overflowed during the floating-point conversion process.

[0003] Therefore, in order to reduce the probability of system accidents as much as possible, software testing and formal verification are usually used to test the system properties during the system design process. However, traditional software testing methods generally use continuous simulation and testing to determine whether an error occurs in the system, but cannot guarantee that there are no errors in the system. Formal verification is based on mathematical theory. During the verification process, rigorous and unambiguous mathematical language is used to describe the system model and the expected properties of the system, and theorem proof and other methods are used to strictly reason whether the system meets specific properties, which can ensure the safety and reliability of the system.

[0004] Theorem proof is based on proof theory and is highly abstract. Generally, a temporal logic is used to prove theorems. At this time, the correctness of the program and system is expressed as a temporal proposition, and then the correctness of the proposition is proved by logical deduction. Therefore, the stronger the expression ability of the underlying logic, the more system properties can be described and verified. In recent years, the academic community has carried out theorem proof work with different temporal logics as the underlying logic, and has formed some preliminary technologies, mainly including the construction of proof systems based on theorem proving tools such as PVS, Isabelle, and Coq, with linear temporal logic LTL, propositional interval temporal logic PITL, and propositional projection temporal logic PPTL as research objects.

[0005] Among them, based on the PVS theorem proving tool, the type design is carried out around the basic timing operations U (until) and W (weak until) in the linear temporal logic LTL, and its proof system is constructed, which can carry out theorem proof for models with linear time forms. Based on the Isabelle proof assistant, the proof system built with propositional interval temporal logic PITL as the research object can be used to verify interval properties. Compared with LTL, PITL contains timing operations such as Chop (sequential compound) and Chop-Star (sequential compound star). Based on the Coq theorem proving tool, facing the propositional projection temporal logic PPTL, the proof system is designed for the specification language defined by PPTL. The Projection and Projection-Plus operations in PPTL can describe the concurrent program structure and can flexibly define the operations of PITL.

[0006] In existing theorem proving technologies, the underlying temporal logics have limitations in their expressiveness: for example, LTL cannot express periodic properties, while PITL and PPTL cannot express recursive properties. In addition, the properties that the above temporal logics can express and prove are also different, which leads to certain limitations in proving theorems with different temporal logics when verifying the properties of different systems, making it difficult to form a comprehensive system and unable to provide comprehensive protection for the security and reliability verification of hardware and software systems. Summary of the invention

[0007] In order to solve the above problems existing in the prior art, the present invention provides a formal verification method for PPTLI theorem proof based on PVS. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0008] The present invention provides a formal verification method for PPTLI theorem proof based on PVS, comprising:

[0009] S101: constructing a basic temporal type of PPTLI and an index expression type of PPTLI through PVS, and equivalently representing a linear temporal logic according to the index expression type of PPTLI;

[0010] S102: constructing a PPTLI theorem proving system through PVS according to the basic time series type of the PPTLI and the index expression type of the PPTLI;

[0011] S103: Express the PPTLI timing property to be proved as a theorem, and use the PVS interactive proof command and the PPTLI theorem proving system to prove the PPTLI timing property to be proved.

[0012] In one embodiment of the present invention, the syntax of the basic timing structure of the PPTLI is summarized and defined as follows:

[0013]

[0014] Among them, q represents an atomic proposition, P and Q both represent PPTLI formulas, and the basic sequential operations of PPTLI include the negation of propositional logic. With the conjunction ∧ operator, as well as the sequential operator next state ○, sequential compound addition +, and projection prj, ○P means that P is established in the next state, P + Indicates that P holds true one or more times in succession, (P1,…,P m )prj Q represents the relationship between Q and P1,…,P m Execute in parallel on a certain interval.

[0015] In one embodiment of the present invention, the basic time series type of PPTLI is obtained by constructing PVS, including:

[0016] Step a: interpret and define the PPTLI basic type as a boolean type, wherein the negation operation is consistent with the definition of not in booleans theory, and the conjunction operation is consistent with the definition of and in booleans theory;

[0017] Step b: defining the next state timing operation as a function type X: [PPTLI -> PPTLI], defining the sequential composite plus timing operation as a function type plus: [PPTLI -> PPTLI], and defining the projection timing operation as a function type prj: [list [PPTLI], PPTLI -> PPTLI] through PVS;

[0018] Step c: According to the PPTLI basic type and the basic timing operation, a derived formula is constructed, wherein the derived formula includes all state □ operations and a state in LTL operations as well as sequential composite operations and sequential composite star operations in PITL.

[0019] In one embodiment of the present invention, the index expression of the PPTLI has the following form:

[0020]

[0021] In the formula, Indicates infinity or operation, R indicates that the index item includes ○ i P, P i and P (i) Three basic index items, among which, i P means applying ○ operations to P i times, Pi means P is repeated i times, P (i) It means that P continues to exist for i states starting from the current state.

[0022] In one embodiment of the present invention, the index expression type of PPTLI obtained by constructing PVS includes:

[0023] Step a: According to the index expression of the PPTLI The index item is defined as a function IE: [nat->PPTLI], the infinite or operation is defined as a function OrInf: [IE->PPTLI], and the index expression is obtained. The formal description in PVS is OrInf(R), where R represents a variable of IE type;

[0024] Step b: In PVS, use the RECURSIVE keyword to add the basic index item ○ i P is defined as a function type NextI(P), with the basic index item P i Defined as a function type ChopI(P), the basic index item P (i) Defined as function type ConsI(P);

[0025] Step c: defining index item connectives through PVS, wherein the index item connectives include connection operations representing negation, conjunction, next state, sequential compound addition and projection between index items, and defining the connection operations between the index items as function types INot, IAnd, INext, IPlus and IPrj respectively;

[0026] Step d: construct a special index item type through PVS, wherein the special index item type represents the equivalent conversion between the PPTLI type without index and the index item type, and defines the equivalent conversion between the PPTLI type without index and the index item type as a function type toIE(P).

[0027] In one embodiment of the present invention, the equivalent representation of linear temporal logic according to the index expression type of the PPTLI includes:

[0028] Construct a complex index expression that equivalently represents the until operation U and the weak until operation W in the linear temporal logic, wherein the complex index expression of the until operation U and the weak until operation W has the following form:

[0029]

[0030]

[0031] According to the index expression type and index item connector of the PPTLI, a formal description of the until operation U and the weak until operation W in PVS is obtained.

[0032] In one embodiment of the present invention, the PPTLI theorem proving system includes a proof system constructed by basic temporal structure and a proof system constructed by index expression.

[0033] In one embodiment of the present invention, the proof system of the basic temporal construction includes: propositional tautology axioms, corresponding axioms and inference rules constructed according to the basic temporal operations of the PPTLI, and auxiliary axioms for ensuring the correctness of the properties of state formulas;

[0034] The proof system constructed by the index expression includes corresponding axioms and inference rules constructed according to the infinite OR operation of the PPTLI, and auxiliary axioms for ensuring the correctness of the properties of PPTLI formulas without indices.

[0035] The present invention provides an application of a formal verification method for proving the PPTLI theorem based on PVS as described in any of the above embodiments in system property verification.

[0036] Compared with the prior art, the present invention has the following beneficial effects:

[0037] 1. The PVS-based formal verification method of the PPTLI theorem proof of the present invention is based on the construction of the basic time series type and index expression type in PPTLI to obtain a PPTLI theorem proving system. The PPTLI proving system has powerful expression ability in the theorem proving process, can be used to describe the properties of various complex systems, can be directly used for formal verification of various system properties, and can solve the problems of unreliable verification of most software and hardware systems using traditional software testing methods or model detection methods being limited by states.

[0038] 2. The formal verification method of PPTLI theorem proof based on PVS of the present invention, and the proof system of basic sequential structure constructed by B Proof system Π constructed by index expression I Its rich type system can equivalently define the core operations of LTL, PITL and PPTL, and is applicable to the description, modeling and verification of various software and hardware systems. It can provide a unified theoretical system of theorem proving methods, which can solve the limitations of theorem proving work based on different temporal logics when verifying the properties of different systems, and provide comprehensive protection for the security and reliability verification of software and hardware systems.

[0039] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the following specifically cites a preferred embodiment and describes it in detail with the accompanying drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is a flow chart of a formal verification method of PVS-based PPTLI theorem proof provided by an embodiment of the present invention;

[0041] Figure 2 It is a design principle diagram of a formal verification method for proving the PPTLI theorem based on PVS provided by an embodiment of the present invention;

[0042] Figure 3 It is a type construction flow chart provided by an embodiment of the present invention;

[0043] Figure 4 It is a PPTLI theorem proving flow chart provided by an embodiment of the present invention;

[0044] Figure 5 This is a comparison chart of the time consumption results of theorem proving provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0045] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined purpose of the invention, a formal verification method for proving the PPTLI theorem based on PVS proposed in accordance with the present invention is described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0046] The above and other technical contents, features and effects of the present invention are clearly presented in the following detailed description of the specific implementation modes in conjunction with the accompanying drawings. Through the description of the specific implementation modes, the technical means and effects adopted by the present invention to achieve the predetermined purpose can be more deeply and specifically understood. However, the attached drawings are only for reference and explanation purposes and are not used to limit the technical solutions of the present invention.

[0047] Embodiment 1

[0048] See also Figure 1 , Figure 1 : is a flow chart of a formal verification method of a PPTLI theorem proof based on PVS provided by an embodiment of the present invention. As shown in the figure, the formal verification method of the PPTLI theorem proof based on PVS of this embodiment includes:

[0049] S101: obtain a basic temporal type of PPTLI and an index expression type of PPTLI through PVS construction, and equivalently represent linear temporal logic according to the index expression type of PPTLI;

[0050] S102: According to the basic time series type of PPTLI and the index expression type of PPTLI, a PPTLI theorem proving system is constructed through PVS;

[0051] S103: Express the PPTLI timing property to be proved as a theorem, and use the PVS interactive proof command to use the PPTLI theorem proving system to prove the PPTLI timing property to be proved.

[0052] Furthermore, the formal verification method of the PVS-based PPTLI theorem proof in this embodiment is specifically described.

[0053] It should be noted that the formal verification method of the PVS-based PPTLI theorem proof in this embodiment includes theorems of basic time series construction and theorems of index expression construction. This embodiment summarizes the common theorem examples with typical properties in PPTLI, and the proof of the theorem can be used to verify the expression and proof capabilities of the PVS-based PPTLI theorem proving method. Before introducing the corresponding theorem, it is necessary to describe in detail the common types in PPTLI and the construction process of the proof system.

[0054] Please refer to Figure 2 , Figure 2 1 is a schematic diagram of a design principle of a formal verification method for PPTLI theorem proof based on PVS provided by an embodiment of the present invention. In this embodiment, the design of the PPTLI theorem proving system adopts a hierarchical structure design idea, and divides the PPTLI theorem proving system II into a proof system II of basic sequential structure. B Proof System Π Constructed with Index Expressions I First, PVS is used to construct the PPTLI basic type and index expression type. On this basis, the proof system Π is completed. B , Π I At this time, the PPTLI timing properties to be proved can be described as theorems through PPTLI related types and combined with the proof system Π B , Π I The axioms and inference rules in the PVS theorem prover are used for interactive proof.

[0055] See also Figure 3 , Figure 3It is a type construction flow chart provided by an embodiment of the present invention. In this embodiment, the syntax of the basic timing structure of PPTLI is summarized and defined as follows:

[0056]

[0057] Among them, q represents an atomic proposition, P and Q both represent PPTLI formulas, and the basic sequential operations of PPTLI include the negation of propositional logic. With the conjunction ∧ operator, as well as the sequential operator next state ○, sequential compound addition +, and projection prj, ○P means that P is established in the next state, P + Indicates that P holds true one or more times in succession, (P1,…,P m )prj Q represents the relationship between Q and P1,…,P m Execute in parallel on a certain interval.

[0058] Specifically, the basic time series types of PPTLI are obtained through PVS construction, including:

[0059] Step a: Interpret and define the PPTLI basic type as boolean type, where the negation operation is consistent with the definition of not in booleans theory, and the conjunction operation is consistent with the definition of and in booleans theory;

[0060] Step b: define the next state timing operation as a function type X:[PPTLI->PPTLI], define the sequential compound plus timing operation as a function type plus:[PPTLI->PPTLI], and define the projection timing operation as a function type prj:[list[PPTLI],PPTLI->PPTLI] through PVS;

[0061] Step c: Based on the basic types and basic timing operations of PPTLI, a derived formula is constructed. The derived formula includes all state operations and a state in LTL. operations as well as sequential composite operations and sequential composite star operations in PITL.

[0062] The specific derivation formula definition and PVS description are as follows:

[0063]

[0064] Furthermore, in this embodiment, the index expression of PPTLI has the following form:

[0065]

[0066] In the formula, Indicates infinity or operation, R indicates that the index item includes ○ i P, Pi and P (i) Three basic index items, among which, i P means applying ○ operations to P i times, P i means P is repeated i times, P (i) It means that P continues to exist for i states starting from the current state.

[0067] Specifically, ○ i P, P i and P (i) The three basic index entries have the following forms:

[0068]

[0069] Specifically, the index expression types of PPTLI obtained through PVS construction include:

[0070] Step a: Based on the PPTLI index expression Define the index term as function IE: [nat->PPTLI], define the infinite or operation as function OrInf:[IE->PPTLI], and get the index expression The formal description in PVS is OrInf(R), where R represents a variable of IE type;

[0071] Step b: In PVS, use the RECURSIVE keyword to add the basic index item ○ i P is defined as a function type NextI(P), with the basic index item P i Defined as a function type ChopI(P), the basic index item P (i) Defined as function type ConsI(P). The specific definition of NextI(P) is as follows:

[0072] NextI(P:PPTLI|IFree(P))(n):RECURSIVE PPTLI=

[0073] IF n=0THEN P ELSE X(NextI(P)(n-1))ENDIF

[0074] MEASURE

[0075] Step c: defining index item connectives through PVS, wherein the index item connectives include connection operations representing negation, conjunction, next state, sequential compound addition and projection between index items, and defining the connection operations of negation, conjunction, next state, sequential compound addition and projection between index items as function types INot, IAnd, INext, IPlus and IPrj respectively;

[0076] Step d: construct a special index item type through PVS, the special index item type represents the equivalent conversion between the PPTLI type without index and the index item type, and the equivalent conversion between the PPTLI type without index and the index item type is defined as the function type toIE(P), where toIE(P)(n)<=>P.

[0077] It should be noted that various complex index expressions can be constructed through the three basic index items, such as Etc. Since the PVS specification language has the characteristics of type consistency: OrInf accepts IE type as a parameter, non, next state, and conjunction connectives should represent the connection operation between IEs, and the formula P, as a PPTLI type, also needs to convert the index item type to ensure the correctness of PVS syntax. Therefore, it is necessary to define index item connectives and special index item type toIE(P) through PVS to complete the conversion between PPTLI type and index item type.

[0078] It is worth noting that in order to ensure semantic correctness when constructing the subsequent theorem proving system, it is necessary to design corresponding auxiliary axioms for the additional definition of the conversion between the basic type of the index item and the basic type of the PPTLI. The auxiliary axioms include INotRule, INextRule, IPlusRule, IPrjRule and toIERule. For example, the axiom INextRule represents the equivalence relation: INext(R)(i)<=>X(R(i)).

[0079] Furthermore, the linear temporal logic is equivalently represented according to the index expression type of PPTLI, including:

[0080] Step a: Construct a complex index expression that equivalently represents the until operation U and the weak until operation W in the linear temporal logic, wherein the complex index expression of the until operation U and the weak until operation W has the following form:

[0081]

[0082]

[0083] Specifically, the until operation U and the weak until operation W are basic sequential operations in LTL. PUQ means that P is true in every state before Q is true. PWQ is a weak version of PUQ, which means that P is true in every state before Q is true, or Q never holds in an infinite interval. According to the semantic characteristics, both PUQ and PWQ satisfy the recursive equation X≡Q∨P∧○X. The introduction of index expressions allows PPTLI to describe the properties of recursive expressions, so the above two operations can be equivalently expressed by constructing complex index expressions.

[0084] Step b: According to the index expression type and index item connector of PPTLI, obtain the formal description of the until operation U and the weak until operation W in PVS.

[0085] In this embodiment, based on the index expression type construction and the index item connector design, the formal description of the until operation U and the weak until operation W is as follows:

[0086] U(P,Q):PPTLI=inf and OrInf(IAnd(ConsI(P),NextI(Q)))

[0087] W(P,Q):PPTLI=inf and OrInf(IAnd(ConsI(P),NextI(Q)))or inf and G(P)

[0088] Further, please refer to Figure 4 , Figure 4 It is a PPTLI theorem proving flow chart provided by an embodiment of the present invention. The PPTLI theorem proving is established on the basis of the PPTLI type, and the interactive proof of the time sequence property to be proved is completed by constructing a PPTLI theorem proving system.

[0089] It should be noted that in the PPTLI theorem proving system, the inference rules are designed based on the permanent true reasoning. In order to reflect the characteristics of the permanent true reasoning in the PPTLI theorem proving system on the basis of the ordinary reasoning form of PVS, the derivation symbol It is defined as |-(P):PPTLI=G(P).

[0090] In this embodiment, the PPTLI theorem proving system II includes a proving system II of a basic sequential structure. B Proof system Π constructed by index expression I .

[0091] Specifically, the proof system Π of the basic sequential construction B It includes: propositional tautology axioms, corresponding axioms and inference rules constructed based on the basic temporal operations of PPTLI, and auxiliary axioms used to ensure the correctness of the properties of state formulas. Proof system Π constructed by index expression I It includes corresponding axioms and inference rules constructed according to the infinite OR operation of PPTLI, as well as auxiliary axioms used to ensure the correct properties of PPTLI formulas without indexes.

[0092] Furthermore, the proof system Π of the basic sequential construction B Proof system Π constructed by index expression I Provide specific instructions.

[0093] Proof system Π of basic sequential construction B It is constructed on the basis of the basic timing type of PPTLI, the proof system of basic timing construction Π B It mainly revolves around the three basic sequential operations of next state, sequential compound addition, and projection, and contains 22 axioms and 7 inference rules. Some of the axioms and inference rules are summarized as follows:

[0094] TAUψψ is an eternally true proposition

[0095]

[0096]

[0097]

[0098] CPC(P + ;P + )→P +

[0099]

[0100]

[0101] Among them, the axiom TAU indicates that a series of tautology instances in PPTLI can be used as axioms, using disjunction and negation as basic connectives. The propositional tautology form is extracted as TAU: of the form, described in PVS as TAU:AXIOM|-(Q or not Q or P).

[0102] Take the PVS description of POB, PSF axioms and CPM inference rules as an example. The other axioms are similar. The above axioms and inference rules are described as follows through the PPTLI basic type construction using the AXIOM keyword in PVS:

[0103] POB:AXIOM|-(prj(L1,Q1 or Q2)<=>prj(L1,Q1)or prj(L1,Q2))

[0104] PSF:AXIOM FORALL(S:PPTLI|SF(S)):

[0105] |-(prj(cons(S and P,L2),Q)<=>S and prj(cons(P,L2),Q))

[0106] CPM:AXIOM|-(P=>Q)=>|-(plus(P)=>plus(Q))

[0107] It should be noted that in this embodiment, all variables except S are declared as global variables. S is a state formula, which is a special PPTLI formula. SF(P) represents the judgment of the state formula. For inference rules that cannot be directly described by PVS, such as SUB rules, they can be equivalently implemented by combining the replace command with the name-replace command.

[0108] Proof System Π for Index Expression Construction I It is constructed on the basis of the index expression type. The proof system constructed by the index expression Π I It mainly revolves around the properties of infinite or operations and recursive equations, and includes 8 axioms and 3 inference rules. Some axioms and inference rules are summarized as follows:

[0109]

[0110] Take the INA, INR axioms and REF inference rules as examples. The rest of the axioms are similar. The above axioms are defined as follows through index expression types:

[0111] INA:AXIOM FORALL(P:PPTLI|IFree(P)):|-(OrInf(IAnd(toIE(P),R))

[0112] <=>P and OrInf(R))

[0113] INR:AXIOM|-(OrInf(R)<=>R(0)or OrInf(IInc(R)))

[0114] REF:AXIOM FORALL(P1,P2:PPTLI|IFree(P1)and IFree(P2)):

[0115] |-(Q<=>P2 or P1 and X(Q))and|-(Q=>F(P2))

[0116] =>|-(OrInf(IAnd(ConsI(P1),NextI(P2)))<=>Q)

[0117] Among them, R is declared as a global variable, P, P1, and P2 are PPTLI formulas without indexes, which are special PPTLI formulas. IFree(P) indicates the judgment of PPTLI formulas without indexes. IInc(R) indicates the R[i+1] form of the index type. The IInc(R) forms for the three basic index items are shown below, which are represented as IIncNextI, IIncChopI, and IIncConsI in PVS.

[0118]

[0119] Furthermore, in order to ensure the correctness of the design of the PPTLI theorem proof system, it is necessary to additionally define and design relevant auxiliary axioms for the predicate judgment SF(P) of the state formula, the judgment IFree(P) of the PPTLI formula without an index, and the conversion between IE type and PPTLI type to ensure correctness.

[0120] The state formula does not contain any temporal operators, so SF(P) is true if and only if P contains only atomic propositions and connectives in propositional logic. The specific auxiliary axioms are defined as follows:

[0121] SFBase:AXIOM SF(p)and SF(q)

[0122] SFNot:AXIOM SF(P)<=>SF(not P)

[0123] SFAnd:AXIOM SF(P)and SF(Q)<=>SF(P and Q)

[0124] Similarly, the index-free PPTLI formula does not contain the index i and the infinite or operator. IFree(P) is true if and only if P contains only atomic propositions and connectives in basic temporal constructions. The specific auxiliary axioms are defined as follows:

[0125] IFBase:AXIOM IFree(p)and IFree(q)

[0126] IFNot:AXIOM IFree(P)<=>IFree(not P)

[0127] IFAnd:AXIOM IFree(P)and IFree(Q)<=>IFree(P and Q)

[0128] IFNext:AXIOM IFree(P)<=>IFree(X(P))

[0129] IFPlus:AXIOM IFree(P)<=>IFree(plus(P))

[0130] IFPrj:AXIOM IFree(P)and ListFree(L1)<=>IFree(prj(L1,P))

[0131] The conversion between PPTLI type and IE type is frequently used in the process of theorem proof. The specific auxiliary axioms are defined as follows:

[0132] IBASE:AXIOM(R1=R2)<=>(FORALL(i:nat):R1(i)<=>R2(i))

[0133] INotRule:AXIOM INot(R)(i)<=>not R(i)

[0134] IAndRule:AXIOM IAnd(R1,R2)(i)<=>R1(i)and R2(i)

[0135] INextRule:AXIOM INext(R)(i)<=>X(R(i))

[0136] IPlusRule:AXIOM IPlus(R)(i)<=>Plus(R(i))

[0137] IIncRule:AXIOM IInc(R)(i)<=>R(i+1)

[0138] At this point, the PPTLI theorem proving system has been built. The PPTLI type can be used to describe the theorem corresponding to the PPTLI property to be proved, and the theorem can be proved through the axioms and auxiliary axioms in the PPTLI theorem proving system.

[0139] By way of example, 20 theorems corresponding to the PPTLI timing properties are summarized, some of which are as follows:

[0140]

[0141] Taking the proof of the PPTLI timing property represented by Theorem IT9 as an example, in PVS, the LEMMA keyword can be used to define the theorem as IT9:LEMMAFORALL(P,Q:IFree(P)AND IFree(Q)):|-(U(P,Q)<=>U(P AND NOTQ,Q)),

[0142] The theoretical derivation process is as follows:

[0143]

[0144] In the process of PVS interactive proof of theorem IT9, the user enters specific commands in brackets in the form of command lines. Referring to the theoretical derivation process, the PVS interactive proof command set is summarized as follows:

[0145]

[0146]

[0147] In order to illustrate that the PPTLI theorem proving method of this embodiment can be directly used for formal verification, its expression ability and proof ability are further verified. PVS is used to interactively prove the 20 common PPTLI timing properties summarized above, and the proof situation is summarized based on the proof time consumption as an indicator, and the following is obtained: Figure 5 The comparison chart of the time-consuming results of theorem proof is shown. As shown in the figure, the PPTLI theorem proving system constructed by the formal verification method of PVS-based PPTLI theorem proof in this embodiment can complete the proof of common theorem instances. Among them, the proof process of the theorem constructed by the basic timing structure is generally more direct and time-consuming (0.9 to 3.6 seconds). When the theorem proving process involves an index expression structure, it is sometimes necessary to repeatedly apply a large number of axioms and lemma instances, so that the total time consumption is relatively long (3.2 to 68.8 seconds), but it is still within a reasonable range. This result shows that the PPTLI theorem proving system can still perform correct and effective proofs when faced with theorems with complex structures such as index expressions, achieving an ideal verification effect.

[0148] The formal verification method of PVS-based PPTLI theorem proof in this embodiment obtains a PPTLI theorem proving system based on the construction of basic types and index expression types in PPTLI. The PPTLI proving system has powerful expressive power in the theorem proving process, can be used to describe the properties of various complex systems, can be directly used for formal verification of various system properties, and can solve the problems of unreliable verification using traditional software testing methods for most current software and hardware systems or state limitations of model detection methods.

[0149] The formal verification method of PPTLI theorem proof based on PVS in this embodiment constructs a proof system of basic sequential structure B Proof system Π constructed by index expression IIts rich type system can equivalently define the core operations of LTL, PITL and PPTL, and is applicable to the description, modeling and verification of various software and hardware systems. It can provide a unified theoretical system of theorem proving methods, which can solve the limitations of theorem proving work based on different temporal logics when verifying the properties of different systems, and provide comprehensive protection for the security and reliability verification of software and hardware systems.

[0150] Furthermore, in other embodiments, the application of the formal verification method of the PVS-based PPTLI theorem proof described in the above-mentioned embodiment 1 in system property verification is also provided. Specifically, the corresponding PPTLI timing properties are obtained according to the system to be verified, and the PPTLI timing properties are expressed as theorems. The PVS interactive proof command is used to use the PPTLI theorem proving system to prove the PPTLI timing properties to verify the security of the system. The specific construction of the PPTLI theorem proving system and the proof method are as described in the above-mentioned embodiment 1 and will not be repeated here.

[0151] It should be noted that, in this article, the term "comprises", "comprising" or any other variant is intended to cover non-exclusive inclusion, so that an article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed. In the absence of more restrictions, an element defined by the sentence "comprising a ..." does not exclude the presence of other identical elements in the article or device comprising the element.

[0152] The above contents are further detailed descriptions of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the protection scope of the present invention.

Claims

1. A formal verification method for PPTLI theorem proof based on PVS, characterized in that: include: S101: constructing a basic temporal type of PPTLI and an index expression type of PPTLI through PVS, and equivalently representing a linear temporal logic according to the index expression type of PPTLI; S102: constructing a PPTLI theorem proving system through PVS according to the basic time series type of the PPTLI and the index expression type of the PPTLI; S103: Express the PPTLI timing property to be proved as a theorem, and use the PVS interactive proof command to use the PPTLI theorem proving system to prove the PPTLI timing property to be proved; The index expression of the PPTLI has the following form: In the formula, Indicates infinity or operation, R indicates that the index item includes ○ i P, P i and P (i) Three basic index items, among which, i P means applying ○ operations to P i times, P i means P is repeated i times, P (i) It means that P continues to exist for i states starting from the current state; The index expression types of PPTLI are obtained through PVS construction, including: Step a: According to the index expression of the PPTLI The index item is defined as a function IE: [nat->PPTLI], the infinite or operation is defined as a function OrInf: [IE->PPTLI], and the index expression is obtained. The formal description in PVS is OrInf(R), where R represents a variable of IE type; Step b: In PVS, use the RECURSIVE keyword to add the basic index item ○ i P is defined as a function type NextI(P), with the basic index item P i Defined as a function type ChopI(P), with a basic index item P (i) Defined as function type ConsI(P); Step c: defining index item connectives through PVS, wherein the index item connectives include connection operations representing negation, conjunction, next state, sequential compound addition and projection between index items, and defining the connection operations between the index items as function types INot, IAnd, INext, IPlus and IPrj respectively; Step d: construct a special index item type through PVS, where the special index item type represents the equivalent conversion between the PPTLI type without an index and the index item type, and the equivalent conversion between the PPTLI type without an index and the index item type is defined as a function type toIE(P).

2. The formal verification method of PVS-based PPTLI theorem proof according to claim 1, characterized in that: The syntax of the basic timing structure of PPTLI is summarized as follows: Among them, q represents an atomic proposition, P and Q both represent PPTLI formulas, and the basic sequential operations of PPTLI include the negation of propositional logic. With the conjunction ∧ operator, as well as the sequential operator next state ○, sequential compound addition +, and projection prj, ○P means that P is established in the next state, P + Indicates that P holds true one or more times in succession, (P1,…,P m )prj Q represents the relationship between Q and P1,…,P m Execute in parallel on a certain interval.

3. The formal verification method of PVS-based PPTLI theorem proof according to claim 2, characterized in that: The basic time series types of PPTLI are obtained through PVS construction, including: Step a: interpret and define the PPTLI basic type as a boolean type, wherein the negation operation is consistent with the definition of not in booleans theory, and the conjunction operation is consistent with the definition of and in booleans theory; Step b: defining the next state timing operation as a function type X:[PPTLI->PPTLI], defining the sequential composite plus timing operation as a function type plus:[PPTLI->PPTLI], and defining the projection timing operation as a function type prj:[list[PPTLI],PPTLI->PPTLI] through PVS; Step c: construct a derived formula according to the PPTLI basic type and the basic sequential operation, wherein the derived formula includes all state □ operations and certain state ◇ operations in LTL and sequential compound operations and sequential compound star operations in PITL.

4. The formal verification method of PVS-based PPTLI theorem proof according to claim 1, characterized in that: According to the index expression type of the PPTLI, the linear temporal logic is equivalently represented, including: Construct a complex index expression that equivalently represents the until operation U and the weak until operation W in the linear temporal logic, wherein the complex index expression of the until operation U and the weak until operation W has the following form: According to the index expression type and index item connector of the PPTLI, a formal description of the until operation U and the weak until operation W in PVS is obtained.

5. The formal verification method of PVS-based PPTLI theorem proof according to claim 1, characterized in that: The PPTLI theorem proving system includes a proof system constructed by basic timing and a proof system constructed by index expression.

6. The formal verification method of PVS-based PPTLI theorem proof according to claim 5, characterized in that: The proof system constructed by the basic temporal sequence includes: propositional tautology axioms, corresponding axioms and inference rules constructed according to the basic temporal sequence operations of the PPTLI, and auxiliary axioms for ensuring the correctness of the properties of state formulas; The proof system constructed by the index expression includes corresponding axioms and inference rules constructed according to the infinite OR operation of the PPTLI, and auxiliary axioms for ensuring the correctness of the properties of PPTLI formulas without indices.