A Formal Verification Method and Device for Java Software
By performing lexical, syntax and semantic analysis of Java programs, converting them into intermediate representation languages and using SMT solvers for formal verification, the problem that existing tools are difficult to verify industrial-grade Java programs is solved, and more efficient and automated formal verification is achieved.
Patent Information
- Application Number
- CN202210998284.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-08-19
AI Technical Summary
Existing Java language formal verification tools are difficult to meet the formal verification needs of industrial-grade Java programs, especially when dealing with complex behaviors such as floating-point operations, multi-threading, infinite loops, etc.
A formal verification method for Java software is proposed. Through lexical analysis, syntax analysis and semantic analysis, it is converted into an intermediate representation language for modeling, and formal verification is performed using an SMT solver.
It reduces the difficulty of formal verification of Java language, improves the degree of automation, reduces the dependence on mathematical foundation, and supports floating-point operations and multi-threaded verification.
Smart Images

Figure CN115357492B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of formal methods, and is a formal verification method and device for Java software. Background Art
[0002] Existing formal verification tools for Java source code mainly include LOOP, JACK, TACO, Sireum / Kiasan, ESC / Java2, OpenJML, KeY, Krakatoa, etc. An overview of these tools is shown in Table 1-1. Among them, although LOOP and JACK were very popular in the early 21st century, the projects are now in a deserted state and the websites are no longer available; although TACO verifies statements that are difficult to directly prove mathematically through bounded model checking, it does not support floating-point operations; Sireum\Kiasan claims that it supports floating-point operations, but in fact it does not; OpenJML is a simple and easy-to-use Java formal verification tool based on automatic SMT solving, but the corresponding verification ability is relatively weak.
[0003] Table 1-1 Overview of Common Java Formal Tools
[0004]
[0005]
[0006] The usability of these Java source code verification tools is shown in Table 1-2. Existing formal verification tools for Java source code have problems that are difficult to overcome in both the pre-use environment configuration and the subsequent use process. For example, KeY does not support floating-point operations and multi-threading, making it difficult to apply KeY to formal verification projects of common industrial software.
[0007] Table 1-2 Usability of Common Java Formal Tools
[0008]
[0009] The technical problem of the present invention is as follows:
[0010] The research results show that existing formal verification tools for the Java language are difficult to meet the formal verification requirements of common industrial software. Therefore, the present invention proposes a new formal verification method for Java software to solve the problem that existing tools are difficult to complete the formal verification of industrial-level Java programs:
[0011] 1) The semantics of the Java language are complex, and it is difficult to perform semantic modeling on behaviors such as floating-point operations and multi-threading;
[0012] 2) Formal verification has high requirements for programmers' mathematical foundations;
[0013] 3) It is difficult for SMT solvers to solve constraint conditions under infinite loops;
[0014] 4) KeY does not support floating-point operations and multi-threading, making it difficult to apply KeY to formal verification projects of common industrial software; Summary of the Invention
[0015] To solve the above technical problems, the present invention aims to provide a formal verification method and device for Java software, a formal verification of Java programs for the industrial community, and a method for modeling multi-dimensional state change time series data of the device. The present invention is achieved through the following technical solutions:
[0016] The present invention discloses a formal verification method for Java software, including
[0017] S1: Obtain the Java program source code, and perform lexical analysis, syntax analysis, and semantic analysis on the Java program source code to generate a Java extended abstract syntax tree;
[0018] S2: Parse constants, variables, inheritance relationships, and function qualifiers in the Java extended abstract syntax tree, allocate memory addresses for them, and generate intermediate representation code;
[0019] S3: Automatically model the Java program requirement document and translate it into a corresponding Java formal specification. Among them, the formal specification mainly includes expression invariants and security of the Java program;
[0020] S4: Parse the Java program specification and convert the Java program specification defined by formalization personnel into an SMT expression of the corresponding Java program specification;
[0021] S5: Parse the instruction meaning of the intermediate representation code in step S3, convert the code into symbolic values according to the instruction meaning, and convert the symbolic values into SMT expressions corresponding to the Java program implementation;
[0022] S6: Solve the refinement relationship between the SMT expression of the Java program specification generated in S4 and the SMT expression of the Java program implementation generated in S5. If there is a refinement relationship, it means that the formal verification is passed; otherwise, generate a corresponding counterexample description to obtain the verification result;
[0023] S7: Accept the verification result and generate a formal verification result report.
[0024] As a further improvement, the Java program specification in step S3 of the present invention includes expression invariants and security of the Java program.
[0025] As a further improvement, in step S1 of the present invention, lexical analysis specifically means receiving the Java program source code, scanning and analyzing the input Java source code string according to the predefined Java language grammar rules, converting it into corresponding morphemes, and outputting a sequence of lexical units; the syntax analysis specifically means: obtaining the sequence of lexical units, verifying that this sequence can be generated by the grammar of the source language, and generating an abstract syntax tree from the morphemes in the sequence of lexical units; the semantic analysis specifically means: receiving the abstract syntax tree, collecting the attribute information of identifiers and performing semantic checks on the abstract syntax tree, and simultaneously outputting an abstract syntax tree.
[0026] As a further improvement, the modeling method for automatically modeling the Java program requirement document in step S3 of the present invention is to generate and output the Java program specification required for verification according to the software requirement document.
[0027] As a further improvement, the Java program specification in step S4 of the present invention needs to be converted into an SMT expression using the symbolic execution method.
[0028] As a further improvement, the Java program implementation in step S5 of the present invention needs to be converted into an SMT expression using the symbolic execution method.
[0029] As a further improvement, the formal verification result report in step S7 of the present invention includes the number of errors, the number of successes, a detailed description of the error information, the location of the error code, and the name of the verification method.
[0030] The present invention also discloses a formal verification device for Java software, including:
[0031] Java language compiler: used to obtain the Java program source code, perform lexical analysis, syntax analysis, and semantic analysis on the Java program source code, and generate a Java extended abstract syntax tree;
[0032] Syntax tree parser: used to parse the constants, variables, inheritance relationships, and function qualifiers in the Java extended abstract syntax tree, allocate memory addresses for them, and generate intermediate representation code;
[0033] Document modeler: used to automatically model the Java program requirement document and translate it into the corresponding Java formal specification, where the formal specification mainly includes the expression invariants and security of the Java program;
[0034] Java program specification parser: used to parse the Java program specification and convert the Java program specification defined by the formal personnel into the SMT expression of the corresponding Java program specification;
[0035] Intermediate language interpreter: used to parse the instruction meanings of the intermediate representation code in step S3, convert the code into symbolic values according to the instruction meanings, and convert the symbolic values into SMT expressions implemented by corresponding Java programs;
[0036] SMT solver: used to solve the refinement relationship between the SMT expressions of the Java program specification generated in S4 and the SMT expressions of the Java program implementation generated in S5. If there is a refinement relationship, it indicates that the formal verification is passed; otherwise, a corresponding counterexample description is generated to obtain the verification result;
[0037] Java program vulnerability detection document generator: used to accept the verification result and generate a formal verification result report.
[0038] The beneficial effects of the present invention are as follows:
[0039] 1) Convert Java code into an intermediate representation language, model the intermediate representation language, and then relevant formal verification personnel describe the program specification according to the functional requirement documents of different models and prove it. Since the semantics of the intermediate language is relatively simple and there are fewer undefined behaviors, the formal verification based on the intermediate language of the present invention avoids the need for the formal verification system to model and verify complex Java language models by converting Java code into intermediate representation code, reduces the difficulty of formal verification of the Java language, and also reduces the dependence on the personal qualities of formal verification personnel.
[0040] 2) Through the formal verification method based on the SMT solver, the automation degree of formal verification is improved, and the mathematical difficulty and the threshold of formal verification are reduced;
[0041] 3) For the processing of code with unbounded loops, it can be encoded as constraints in a limited way. By using loop invariants or finite loop unfolding, the loop can be encoded as constraints in a limited way. Description of the Drawings
[0042] Figure 1 It is a flowchart of a Java automatic formal modeling detection and verification method disclosed in an embodiment of the present invention;
[0043] Figure 2 It is a schematic diagram of a device for implementing the Java automatic formal modeling detection and verification method disclosed in an embodiment of the present invention; Detailed Embodiments
[0044] To make the objectives, technical solutions, and advantages of the present invention more clear, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0045] The following further describes the present invention in detail with reference to the accompanying drawings: Figure 1 It is a flowchart of a Java automatic formal modeling detection and verification method disclosed in an embodiment of the present invention;
[0046] Step S1: Perform lexical analysis, syntax analysis, and semantic analysis on the Java program source code to generate a Java extended abstract syntax tree;
[0047] Step S2: With the help of the Java abstract syntax tree generated in Step S1, parse the constants, variables, inheritance relationships, and function qualifiers in the Java abstract syntax tree, allocate memory addresses for them, and generate intermediate language representation code; among them, the intermediate language representation code is LLVM IR in the embodiment.
[0048] Step S3: Automatically model the Java program requirement document and translate it into the corresponding Java formal specification,
[0049] Among them, the format of the Java program requirement document is the xml format of key-value pairs, and specifically needs to include the method name "functionName" and its key-value of the requirement description, the method parameter "functionParameter" and its key-value, the precondition "preCondition" and its key-value, the postcondition "postCondition" and its key-value, and the loop invariant "invariant" and its key-value.
[0050] Among them, the formal specification mainly includes the expression invariant and security of the Java program. In the embodiment, the formal specification is the invariant and security specification of the Java program written using Rosette. Common security definitions such as the non-interference property, and its formal specification is described by the following method:
[0051]
[0052] Step S4: With the help of the intermediate language representation code generated in Step S2, and using a programming language supported by symbolic execution and SMT solvers, write an interpreter for the intermediate code representation described in Step S2. Explore the reachable running states of the Java program on the intermediate language through symbolic execution, convert the Java program from the intermediate language to the corresponding SMT expression, and output it to the SMT solver.
[0053] Among them, the programming language supported by the SMT solver is Rosette in the embodiment.
[0054] The intermediate language interpreter is an LLVM IR interpreter written in Rosette in the embodiment. Part of the LLVM IR interpreter is shown as follows:
[0055]
[0056] Step S5: With the help of the SMT expressions of the Java program specification generated in Step S3 and the SMT expressions of the Java program implementation generated in Step S4, input them into the SMT solver to solve the refinement relationship between the two expressions. If there is a refinement relationship, it means that the formal verification is passed. Otherwise, generate the corresponding counterexample for the subsequent generation of the Java program vulnerability detection document generator.
[0057] Among them, the SMT solver is the Z3 solver in the embodiment.
[0058] Step S6: With the help of the verification result generated in Step S5, generate the corresponding formal verification result report.
[0059] Figure 2 It is a schematic diagram of a device for implementing the Java automatic formal modeling detection and verification method disclosed in an embodiment of the present invention; it includes: a Java language compiler, a syntax tree parser, an intermediate language interpreter, a document modeler, a Java program specification parser, an SMT solver, and a Java program vulnerability detection document generator.
[0060] The Java language compiler is used to receive the Java program source code, compile the Java program source code to obtain an extended abstract syntax tree, then convert the extended abstract syntax tree to a standard Java abstract syntax tree through a predefined pass, and finally input the abstract syntax tree into the syntax tree parser for parsing.
[0061] The syntax tree parser is used to receive the standard Java abstract syntax tree generated by the Java language compiler, and parse out the constants, variables, inheritance relationships, and function qualifiers in the code, allocate memory addresses for them, generate intermediate representation code, and output it to the intermediate language parser.
[0062] The intermediate language interpreter is used to receive the intermediate language generated by the syntax tree parser, parse the instruction meaning of the intermediate language, convert the code into symbolic values according to the instruction meaning, convert the symbolic values into corresponding SMT expressions, and input them into the SMT solver for solving.
[0063] Document modeler: used to automatically model the Java program requirement document and translate it into the corresponding Java formal specification. Among them, the formal specification mainly includes the expression invariants and security of the Java program;
[0064] The Java program specification parser is used to parse the Java program specification. The Java program specification parser converts the Java program specification defined by the formalizer into the corresponding SMT expression for subsequent input into the SMT solver for verifying and solving the refinement relationship.
[0065] The SMT solver is used to receive the SMT expressions generated by the Java program specification and the SMT expressions generated by the intermediate language, and prove the refinement relationship between the two. If the refinement relationship does not hold, a set of counterexamples will be generated to illustrate it, and the proof result will be output to the Java program vulnerability detection document generator.
[0066] The Java program vulnerability detection document generator is used to receive the verification result output by the SMT solver and generate a Java program vulnerability detection document.
[0067] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A formal verification method for Java software, characterized in that, it includes S1: Obtain the Java program source code, perform lexical analysis, syntax analysis, and semantic analysis on the Java program source code to generate a Java extended abstract syntax tree; S2: Parse the constants, variables, inheritance relationships, and function qualifiers in the Java extended abstract syntax tree, allocate memory addresses for them, and generate intermediate representation code; S3: Automatically model the Java program requirement document and translate it into a corresponding Java formal specification. Among them, the formal specification mainly includes the expression invariants and security of the Java program; S4: Parse the Java program specification and convert the Java program specification defined by the formalization personnel into the SMT expression of the corresponding Java program specification; S5: Parse the instruction meaning of the intermediate representation code in step S3, convert the code into symbolic values according to the instruction meaning, and convert the symbolic values into the SMT expressions implemented by the corresponding Java program; S6: Solve the refinement relationship between the SMT expression of the Java program specification generated in S4 and the SMT expression of the Java program implementation generated in S5. If there is a refinement relationship, it means that the formal verification is passed; otherwise, generate a corresponding counterexample description to obtain the verification result; S7: Accept the verification result and generate a formal verification result report.
2. The formal verification method for Java software according to claim 1, characterized in that, the Java program specification in step S3 includes the expression invariants and security of the Java program.
3. The formal verification method for Java software according to claim 1, characterized in that, in step S1, the lexical analysis is specifically to receive the Java program source code, scan and analyze the input Java source code string according to the predefined Java language grammar rules, convert it into corresponding lexemes, and output a sequence of lexical units; the syntax analysis is specifically: obtain the sequence of lexical units and verify that this sequence can be generated by the grammar of the source language, and generate an abstract syntax tree from the lexemes in the sequence of lexical units; the semantic analysis is specifically: accept the abstract syntax tree, collect the attribute information of the identifiers, perform semantic checks on the abstract syntax tree, and output an abstract syntax tree at the same time.
4. The formal verification method for Java software according to claim 1, characterized in that, the modeling method for automatically modeling the Java program requirement document in step S3 is to generate and output the Java program specification required for verification according to the software requirement document.
5. The formal verification method for Java software according to claim 1, characterized in that, the Java program specification in step S4 needs to be converted into an SMT expression using the method of symbolic execution.
6. The formal verification method for Java software according to claim 1, characterized in that, the Java program implementation in step S5 needs to be converted into an SMT expression using the method of symbolic execution.
7. The formal verification method for Java software according to claim 1, characterized in that, the formal verification result report in step S7 includes the number of errors, the number of successes, a detailed description of error information, the location of error codes, and the name of the verification method.
8. A formal verification device for Java software, characterized in that, it includes: Java language compiler: used to obtain the source code of the Java program and perform lexical analysis, syntax analysis, and semantic analysis on the source code of the Java program to generate a Java extended abstract syntax tree; Syntax tree parser: used to parse constants, variables, inheritance relationships, and function qualifiers in the Java extended abstract syntax tree, allocate memory addresses for them, and generate intermediate representation code; Document modeler: used to automatically model the Java program requirement document and translate it into a corresponding Java formal specification. Among them, the formal specification mainly includes the expression invariants and security of the Java program; Java program specification parser: used to parse the Java program specification and convert the Java program specification defined by the formalization personnel into the SMT expression of the corresponding Java program specification; Intermediate language interpreter: used to parse the instruction meaning of the intermediate representation code in step S3, convert the code into symbolic values according to the instruction meaning, and convert it into the SMT expression of the corresponding Java program implementation according to the symbolic values; SMT solver: used to solve the refinement relationship between the SMT expression of the Java program specification generated in S4 and the SMT expression of the Java program implementation generated in S5. If there is a refinement relationship, it means that the formal verification is passed; otherwise, a corresponding counterexample description is generated to obtain the verification result; Java program vulnerability detection document generator: used to receive the verification result and generate a formal verification result report.
Citation Information
Patent Citations
System and method oriented to supermatic formal verification of smart contract of blockchain
CN108536445A
Software verification method and device, computer equipment and storage medium
CN110347588A