Conversion Method from Simulink-StateFlow Model to NuSMV Model

By building Simulink model information table and abstract syntax tree, the Simulink-StateFlow model is automatically converted into NuSMV model, which solves the problem that NuSMV tools cannot directly handle, and improves the efficiency and accuracy of model detection.

CN115391173BActive Publication Date: 2025-07-22BEIJING JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210789598.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-06
Publication Date
2025-07-22
Estimated Expiration
2042-07-06

AI Technical Summary

Technical Problem

NuSMV tools cannot directly process the Simulink-StateFlow model, resulting in low model detection efficiency and accuracy, and manual conversion of models cannot guarantee correctness.

Method used

It provides a conversion method from Simulink-StateFlow model to NuSMV model. By constructing Simulink model information table and abstract syntax tree, it automatically converts it into NuSMV model, including extracting program statements, custom functions and logical order relationships, and generating NuSMV model.

Benefits of technology

The detection efficiency and accuracy of the Simulink-StateFlow model of NuSMV tool is improved, and the problem of waste of manpower and time in manual translation is solved, ensuring the correctness of the conversion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115391173B_ABST
    Figure CN115391173B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for converting a Simulink-StateFlow model into a NuSMV model, which includes the following steps: conducting a requirements analysis on the system to be evaluated and constructing a Simulink-StateFlow model; extracting program statements, custom function statements, and logical sequence relationships in the model, and respectively constructing a program statement data table, a custom function data table, and a logical sequence data table; integrating the model program and sequence to generate a model information table; analyzing the Matlab programming language and constructing Matlab syntax rules; processing the program statements in the model information table according to the syntax rules and parsing them into an abstract syntax tree; processing the abstract syntax tree to determine an algorithm for converting it into NuSMV statements; and processing the model information table according to the conversion algorithm to generate a NuSMV model. The present invention greatly improves the efficiency and accuracy of the NuSMV tool for model checking of the Simulink-StateFlow model, and realizes the safety verification of the Simulink requirements model of the control system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of system security and reliability, and specifically relates to a method for converting a Simulink-StateFlow model into a NuSMV model. Background Art

[0002] Model checking is a formal verification method used to prove the correctness of system properties during program execution. Its main idea is to first establish a finite-state model of the system to be detected, and then use algorithms to exhaustively check the states in the model to determine whether they satisfy the properties to be measured. If not, according to the feedback information, it is judged whether there is actually an execution path in the specific system that violates this property, that is, a counterexample path. The process of model checking includes system modeling, property description, and system verification. System modeling selects a formal description method to transform the system design to be verified into a model acceptable to the verification tool. In modeling, the method of abstraction is used to remove unimportant or irrelevant details to avoid introducing too many details and causing state explosion. The properties to be verified by the system are usually described using logical formulas, such as temporal logic, which can describe the behavioral changes of the system over time. Model checking provides many methods to verify whether the model satisfies the properties, but this does not guarantee that these properties cover all the properties that the system needs to satisfy. Therefore, it is required that designers ensure the completeness of the properties when describing them. System verification is to exhaustively search the state space of the system through model checking algorithms. After the verification is completed, if no state violating the property description is found, it indicates that the model satisfies the expected properties; otherwise, a counterexample path is given for reference.

[0003] Formal verification is a method for verifying the correctness of a system. Compared with traditional verification methods (simulation, emulation, and testing), the main idea of formal verification is to use mathematical formulas, theorems, and systems to verify the correctness of the system. Current formal verification methods can be used to verify hardware systems, software systems, and other systems. Simulink is a visualization simulation tool in MATLAB, which supports system design, simulation, automatic code generation, and continuous testing and verification of embedded systems. In the Simulink modeling process, custom module libraries and solvers can be used to perform dynamic system modeling and simulation. Formal verification of the simulation system model generated by Simulink is a new approach for the reliability verification of automated systems.

[0004] NuSMV is a symbolic model checking tool that constructs and represents system models in an abstract symbolic language. It re-implements and extends the SMV symbolic model checker, aiming to verify the reliability of industrial-scale designs, serve as the backend for other verification tools, and be a research tool for formal verification techniques. Currently, NuSMV has become one of the widely used tools in the field of system and software formal verification, and its practicality and scalability have been unanimously recognized in the industry. However, NuSMV cannot directly process the StateFlow flowcharts and finite state machine models of Simulink. It can only manually translate the source program into a NuSMV input model and then perform formal verification on this model to find defective code. This not only wastes a large amount of human and time costs but also cannot guarantee the correctness of the manually converted model. Due to insufficient support in theoretical aspects such as semantic definitions, the research on the reliability detection of Simulink models at home and abroad mainly focuses on constructing reliability test profiles, such as operation profiles, Markov profiles, usage profiles, etc., and carrying out testing work based on the test profiles. Currently, there is no good formal verification method to support its reliability detection. Summary of the Invention

[0005] In view of the defects existing in the prior art, the present invention provides a conversion method for converting a Simulink-StateFlow model to a NuSMV model, which is used to improve the efficiency and accuracy of the NuSMV tool for reliability detection of the Simulink-StateFlow model and realize the safety verification of the system model.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is:

[0007] A conversion method from a Simulink-StateFlow model to a NuSMV model includes the following steps:

[0008] Step 1: Perform formal analysis of the requirements of the system to be evaluated and construct a Simulink-StateFlow model; generate project engineering files, which include: JSON format files, C language format files, and SVG format files;

[0009] Step 2: Analyze the format characteristics of the JSON format file, extract program statements from the JSON format file, and construct a program statement data table;

[0010] Step 3: Analyze the format characteristics of the C language format file, extract custom function statements from the C language format file, and construct a custom function data table.

[0011] Step 4: Analyze the format features of the SVG format file, read the logical sequence relationship of the program statements extracted in Step 2, and construct a logical sequence data table.

[0012] Step 5: According to the program statement data table and the logical sequence data table constructed in Step 2 and Step 4, use an algorithm to integrate the model program and sequence to generate a Simulink model information table.

[0013] Step 6: Analyze the Matlab programming language used in the program statements and construct the syntax rules of the Matlab language.

[0014] Step 7: Process the program statements in the Simulink model information table according to the Matlab language syntax rules given in Step 6, and parse the program statements into an Abstract Syntax Tree (AST).

[0015] Step 8: Process the Abstract Syntax Tree (AST) to determine the conversion algorithm for converting it into NuSMV statements; according to the conversion algorithm, process the Simulink model information table to generate a NuSMV model.

[0016] In Step 1, the specific content of constructing the Simulink-StateFlow model is: draw the model's blocks, starting points, transitions, connection points, input program statements, and write custom functions.

[0017] After the Simulink state diagram is drawn, through the Simulink menu: File -> Export Model to -> Web, select the export mode as Entire Model-Export to generate a project engineering file; the JSON format file is used to record all the program statements required for state migration filled in during the Simulink modeling process; the C language format file is used to record all the custom function statements filled in during the Simulink modeling process; the SVG format file is used to record all the state migration processes drawn during the Simulink modeling process.

[0018] In step 2, the algorithm for extracting program statements is as follows: traverse the JSON data file sequence, filter out redundant items inspector, extract the items where the program statements are located, filter out redundant characters, and integrate the data structure. According to the characteristics of the JSON format file, the following data structure is defined to represent the data relationship of the program statement data table: [Sid, ExecutionOrder, Program], where Sid represents the identification number of the program, ExecutionOrder represents the branch order information of program execution, ExecutionOrder = {1, 2}. When ExecutionOrder is 1, it means that the branch where the program statement is located is the branch to be executed first. When ExecutionOrder is 2, it means that the execution order of the program statement is after branch 1. Program represents the specific program statement body.

[0019] In step 3, the algorithm for extracting custom function statements is as follows: traverse the C language format file sequence, locate the line where the custom function keyword is located, extract the function name, extract the function body, filter out redundant characters, and integrate the data structure. According to the C language format file and the custom function body format, the following data structure is defined to represent the data relationship of the custom function data table: [FunctionTitle, FunctionBody], where FunctionTitle represents the function name of the custom function, and FunctionBody represents the function body of the custom function.

[0020] In step 4, the reading algorithm used is as follows:

[0021] Step 401: Read in the SVG format file;

[0022] Step 402: Perform logical sorting operations within each graphic block. First, find the starting points of each block diagram within the block, calculate and mark the starting point coordinates, numbers, and types; secondly, find the connection points within each block diagram in the block, calculate and mark the connection point coordinates, types, and numbers; find the transfers within each block diagram in the block, calculate and mark the transfer start and end point coordinates, types, and numbers; for each group of transfers, find the starting and arriving starting points or connection points; finally, read the normalized transfer list information, filter out the intermediate operations of the connection points according to the pre-connected points and post-connected points, and list the logical relationships between the transfers;

[0023] Step 403: Perform a logical sorting operation among each block. First, find the starting point of the overall block diagram, and mark the starting point coordinates, number, and type; find the transitions in the overall diagram, and mark the starting and ending endpoint coordinates, types, and numbers of the transitions; find the upper and lower boundaries of each block within the block, and mark the coordinates, types, and numbers of the block boundaries; for each group of transitions, find the block boundaries where they start and end; read the information of the normalized transition list, and list the logical relationships between the transitions and the blocks based on the pre-block boundary and the post-block boundary.

[0024] Step 404: Integrate the logical relationship information obtained in Steps 402 and 403.

[0025] Define the following data structure to represent the block diagram number relationship corresponding to the program: [Identifier_Front, Identifier_Behind]. Among them, Identifier_Front represents the number of the logical pre-element, and Identifier_Behind represents the number of the logical post-element. At the logical order level, the element Identifier_Front is before the element Identifier_Behind, and there is a directed path between the two.

[0026] Define the following data structure to represent the identification relationship of graphic elements in SVG: [Element_Identifier, Element_ID, Element_ParentID]. Among them, Element_Identifier represents the custom number corresponding to the element in SVG, Element_ID represents the original identification number corresponding to the element in SVG, and Element_ParentID represents the original identification number of the block diagram corresponding to each program statement in the SVG diagram.

[0027] Define the following data structure to represent the status information of the starting points in the graphic elements of SVG: [StartPoint_Identifier, StartPoint_Type, StartPoint_ParentID]. Among them, StartPoint_Identifier represents the custom numbers corresponding to all the starting points in the SVG diagram, StartPoint_Type represents the type of the starting point in the SVG diagram, StartPoint_Type = {block_in, block_out}. When the value of StartPoint_Type is block_in, it means that the starting point is within the block. When the value of StartPoint_Type is block_out, it means that the starting point is outside the block. StartPoint_ParentID represents the original identification number of the block corresponding to each starting point.

[0028] Refer to the above three data structures to generate the logical order data table List_ElementOrder, the element number information table List_IdentifierID, and the start point status information table List_StartPoint, and store the logical information extracted from the SVG diagram into the above tables.

[0029] In step 5, the specific algorithm for integrating the model program and the order is as follows:

[0030] Step 501: Read the start point status information table List_StartPoint, the logical order data table List_ElementOrder, the element number information table List_IdentifierID, and the program statement data table List_JsonProgram;

[0031] Step 502: Integrate the start point information, block diagram information, and program statement information in the data table;

[0032] Step 503: Record the number of program statements in each block diagram;

[0033] Step 504: Use a stack structure to assist in sorting the sequence of all program statements and construct a program data storage stack.

[0034] Step 505: Generate a Simulink model information table, which includes an ordered program statement table List_ProgramOrder and an element branch mapping table Map_Branch.

[0035] In step 6, the specific content of the analysis of the Matlab programming language is: extraction and sorting of program statements, lexical analysis of program statements, judgment of program statement types, adjustment of program statements, removal of redundant items, addition of counters, and generation of a conversion model.

[0036] In step 7, the specific content of parsing the program statements into an abstract syntax tree is: reading the program statements and identifying, recognizing and extracting identifiers, extracting intermediate quantities and identifying functions for operators, assigning weights to each quantity in the program statements, and sorting each quantity of the program statements according to the weights using a stack and a linked list.

[0037] The specific content of step 8 is as follows:

[0038] Step 801: Automatically convert the definition and initialization statements. During the conversion process, the basic types supported by the program statements to be converted include integer type, real type, character data, logical value type, array data, built-in functions of Matlab-Simulink, and custom functions written using the Matlab editor. The integer type includes multi-bit signed and unsigned integer words. The real type includes single-precision floating-point numbers and double-precision floating-point numbers. The types supported by NuSMV include boolean type, integer type, enumeration type, signed word, unsigned word, array type, and set type.

[0039] Among them, the logical value type in the program statement corresponds to the boolean type in NuSMV; the integer type in the program statement corresponds to the integer type in NuSMV; the single-precision floating-point number in the program statement corresponds to the signed word in NuSMV; the double-precision floating-point number in the program statement corresponds to the unsigned word in NuSMV.

[0040] The state variables in the program statement are directly mapped to the state variables in NuSMV, with the same type and the name remaining unchanged. The conversion of the environment variables depends on the state variables. During the model conversion process, according to the actual situation, the environment variables are first expressed through the state variables and then the state variables are converted.

[0041] Step 802: Convert the custom function into a module in NuSMV. The custom function is also written using the Matlab programming language. For the conversion of arithmetic operators in the function statement, it is necessary to verify the result at the same time to make it conform to the value range of NuSMV constants. During the NuSMV verification process, only the Matlab functions that can be recognized by NuSMV in the verification model will be called to participate in the operation and execution. Other Matlab built-in functions used when writing the program statement and custom function cannot be recognized and need to be screened and located during the syntax analysis process and converted into recognizable statements or program steps separately. Then the converted custom function body is returned.

[0042] Step 803: Determine the statement type and automatically convert the assignment statement, loop statement, and judgment statement. For loop and judgment statements, NuSMV uses the case expression to describe the condition transfer process, and each transfer in the state model to be converted is mapped to a conditional expression in NuSMV. For each pending state in the state model, find all the assignment behaviors that change the NuSMV environment variables in the state model and convert them into corresponding case clauses.

[0043] Step 804: Generate the converted NuSMV model.

[0044] Advantages of the present invention: Aiming at the problem that the current Simulink-StateFlow model cannot be used as a direct input and manual reconstruction of the NuSMV model is required for reliability detection, resulting in low efficiency and accuracy of model detection, the present invention parses the Simulink-StateFlow model and constructs a model conversion method for information extraction and syntax tree conversion, automatically converting the Simulink-StateFlow flowchart and finite state machine model into an input model for the NuSMV model detection tool, improving the efficiency and accuracy of model detection of Simulink programs.

[0045] In the field of formal verification, the present invention provides a semantic interoperability path for two models during the conversion process from the Matlab / Simulink-StateFlow system simulation model to the NuSMV verification model, solving the problems of manpower and time waste and inability to guarantee the correctness of conversion existing in the existing manual translation method.

[0046] In the process of information extraction in the early stage, the present invention processes three attached information files of the Simulink-StateFlow model export project, namely JSON files, SVG files, and C files, completely filters out redundancies, and extracts the logical information, statement information, and function information required for conversion.

[0047] The traditional method of extracting information from the XML document of the Simulink-StateFlow model is relatively complex and even requires a large amount of manual coding cost; the present invention proposes to extract the information of the SVG document of the model by means of syntax tree parsing, improving the reading efficiency and saving the conversion time.

[0048] In the process of conversion, the present invention writes a set of methods for extracting the logical information of the graph model drawn by the StateFlow tool, which is applicable to the SVG export files of various information models with different colors and different graph sizes in the drawing.

[0049] In the process of conversion, for the semi-formal language used in Matlab / Simulink modeling to be converted into the SMV model language for formal input, the present invention forms corresponding language conversion rules, and also forms corresponding conversion rules for paragraph statements such as loops and branches and custom functions. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The present invention has the following drawings:

[0051] Figure 1 It is a schematic flowchart of a method for converting a Simulink-StateFlow model to a NuSMV model according to the present invention;

[0052] Figure 2 It is a framework diagram of a method for converting a Simulink-StateFlow model to a NuSMV model according to the present invention. Specific implementation manners

[0053] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0054] Embodiment 1, as Figure 1 and Figure 2 shown, a method for converting a Simulink-StateFlow model to a NuSMV model includes the following steps:

[0055] Step 1, perform a formal analysis of the requirements of the system to be evaluated, and construct a Simulink-StateFlow model;

[0056] The specific content of constructing the Simulink-StateFlow model is: draw the blocks, starting points, transitions, connection points of the model, input program statements, and write custom functions.

[0057] The Simulink-StateFlow model allows users to establish finite states, graphically draw the conditions for state transitions, and use specified commands to design the tasks executed by state transitions, thereby constructing the entire finite state machine system. Perform requirement analysis according to the operating state of the system to be evaluated, construct the overall state transition process of the system in the Simulink tool, draw the blocks, starting points, transitions, and connection nodes of the model, and fill in the program commands required for the corresponding state transitions. Set up custom function statements when necessary to assist the required commands.

[0058] After the Simulink state diagram is drawn, through the Simulink menu: File->Export Model to->Web, select the export mode as Entire Model-Export to generate the corresponding project engineering file. The project engineering file contains three necessary files: one is a JSON format file that records all the program statements required for state transitions filled in during the Simulink modeling process; the second is a C language format file that records all the custom function statements filled in during the Simulink modeling process; the third is an SVG format file that records all the state transition processes drawn during the Simulink modeling process.

[0059] Step 2, parse the Simulink project engineering file constructed and exported in Step 1, analyze the format characteristics of the JSON format file, extract program statements from the JSON format file, and construct a program statement data table;

[0060] The specific extraction algorithm used is as follows: traverse the JSON data file sequence, filter redundant items inspector, extract the items where the program statements are located, filter redundant characters, and integrate the data structure.

[0061] In this embodiment, according to the characteristics of the JSON format file, the following data structure is defined to represent the data relationship of the program statement data table: [Sid, ExecutionOrder, Program], where Sid represents the identification number of the program, ExecutionOrder represents the branch order information of program execution, ExecutionOrder = {1, 2}. When ExecutionOrder is 1, it means that the branch where the program statement is located is the branch to be executed preferentially. When ExecutionOrder is 2, it means that the execution order of the program statement is after branch 1, and Program represents the specific program statement body. Referring to this data structure, a program statement data table List_JsonProgram is generated, and the program statement information is stored in the program statement data table.

[0062] Step 3: Parse the Simulink project engineering file constructed and exported in Step 1, analyze the format characteristics of the C language format file, extract the custom function statements from the C language format file, and construct a custom function data table.

[0063] The specific extraction algorithm used is as follows: traverse the C language format file sequence, locate the line where the custom function keyword is located, extract the function name, extract the function body, filter redundant characters, and integrate the data structure.

[0064] In this embodiment, according to the C language format file and the custom function body format, the following data structure is defined to represent the data relationship of the custom function data table: [FunctionTitle, FunctionBody], where FunctionTitle represents the function name of the custom function, and FunctionBody represents the function body of the custom function. Referring to this data structure, a custom function data table List_CustomFunction is generated, and the custom function information is stored in the custom function data table.

[0065] Step 4: Parse the Simulink project engineering file constructed and exported in Step 1, analyze the format characteristics of the SVG format file, read the logical sequence relationship of the program statements extracted in Step 2, and construct a logical sequence data table. The specific reading algorithm used is as follows:

[0066] Step 401: Read in the SVG format file;

[0067] Step 402, perform a logical sorting operation within each block. First, find the starting points of each block diagram within the block, calculate and mark the starting point coordinates, numbers, and types; second, find the connection points in each block diagram within the block, calculate and mark the connection point coordinates, types, and numbers; find the transfers in each block diagram within the block, calculate and mark the starting and ending endpoint coordinates, types, and numbers of the transfers; for each group of transfers, find the starting and arriving starting points or connection points; finally, read the information of the normalized transfer list, filter out the intermediate operations of the connection points according to the pre-connected point and post-connected point, and list the logical relationships between the transfers.

[0068] Step 403, perform a logical sorting operation between each block. First, find the starting point of the overall block diagram and mark the starting point coordinates, number, and type; find the transfers in the overall diagram and mark the starting and ending endpoint coordinates, types, and numbers of the transfers; find the upper and lower boundaries of each block within the block and mark the coordinates, types, and numbers of the block boundaries; for each group of transfers, find the starting and arriving block boundaries; read the information of the normalized transfer list, and list the logical relationships between the transfers and the blocks according to the pre-block boundary and post-block boundary.

[0069] Step 404, integrate the logical relationship information obtained in Step 402 and Step 403.

[0070] In this embodiment, the following data structure is defined to represent the block diagram number relationship corresponding to the program: [Identifier_Front, Identifier_Behind]. Among them, Identifier_Front represents the number of the logically previous element, and Identifier_Behind represents the number of the logically subsequent element. At the logical order level, the element Identifier_Front is before the element Identifier_Behind, and there is a directed path between the two.

[0071] In this embodiment, the following data structure is defined to represent the identification relationship of the graphic elements in SVG: [Element_Identifier, Element_ID, Element_ParentID]. Among them, Element_Identifier represents the custom number corresponding to the element in SVG, Element_ID represents the original identification number corresponding to the element in SVG, and Element_ParentID represents the original identification number of the block diagram corresponding to each program statement in the SVG diagram.

[0072] In this embodiment, the following data structure is defined to represent the status information of the starting points in the graphic elements of SVG: [StartPoint_Identifier, StartPoint_Type, StartPoint_ParentID]. Among them, StartPoint_Identifier represents the custom number corresponding to all starting points in the SVG diagram, StartPoint_Type represents the type of the starting point in the SVG diagram, and StartPoint_Type = {block_in, block_out}. When the value of StartPoint_Type is block_in, it means that the starting point is inside the block. When the value of StartPoint_Type is block_out, it means that the starting point is outside the block. StartPoint_ParentID represents the original identification number of the block corresponding to each starting point.

[0073] Referring to the above three data structures, the logical order data table List_ElementOrder, the element number information table List_IdentifierID, and the starting point status information table List_StartPoint are generated respectively, and the logical information extracted from the SVG diagram is stored in the above tables.

[0074] Step 5: According to the program statement data table and the logical order data table constructed in Step 2 and Step 4, use the algorithm integration model program and order to generate the Simulink model information table.

[0075] The algorithm for integrating the model program and order is as follows:

[0076] Step 501: Read the starting point status information table List_StartPoint, the logical order data table List_ElementOrder, the element number information table List_IdentifierID, and the program statement data table List_JsonProgram;

[0077] Step 502: Integrate the starting point information, block information, and program statement information in the data table;

[0078] Step 503: Record the number of program statements in each block diagram;

[0079] Step 504: Use a stack structure to assist in sorting the sequence of all program statements and construct a program data storage stack.

[0080] Step 505: Generate the Simulink model information table (including the ordered program statement table List_ProgramOrder and the element branch mapping table Map_Branch).

[0081] Step 6: Analyze the Matlab programming language used in the program statements and construct the syntax rules of the Matlab language.

[0082] In this embodiment, the specific content of analyzing the Matlab programming language is: extraction and sorting of program statements, lexical analysis of program statements, judgment of program statement types, adjustment of program statements, removal of redundant items, addition of counters, and generation of transformation models.

[0083] Step 7: Process the program statements in the Simulink model information table (including the ordered program statement table List_ProgramOrder and the element branch mapping table Map_Branch) according to the syntax rules of the Matlab language given in Step 6, and parse the program statements into an Abstract Syntax Tree (AST).

[0084] Step 8: Process the Abstract Syntax Tree (AST) to determine the transformation algorithm for converting it into NuSMV statements; according to the transformation algorithm, process the Simulink model information table to generate a NuSMV model.

[0085] Furthermore, in Step 7, the specific content of parsing the program statements into an abstract syntax tree is: reading the program statements and identifying, recognizing and extracting identifiers, extracting intermediate quantities and identifying functions for operators, assigning weights to each quantity in the program statements, and sorting each quantity in the program statements according to the weights using a stack and a linked list.

[0086] The specific content of parsing the program statements into a syntax tree can also be completed by using the language parser ANTLR4 and specific Matlab-Simulink rules. The formed Abstract Syntax Tree (AST) is equivalent in form to the result formed by the above solution.

[0087] Furthermore, Step 8 is specifically as follows:

[0088] Step 801: Automatically transform the definition and initialization statements. During the transformation process, the basic types supported by the program statements to be transformed include integer type, real number type, character data, logical value type, array data, built-in functions of Matlab-Simulink, and custom functions written using the Matlab editor. The integer type includes multi-bit signed and unsigned integer words, and the real number type includes single-precision floating-point numbers and double-precision floating-point numbers; the types supported by NuSMV include boolean type, integer type, enumeration type, signed word, unsigned word, array type, and set type.

[0089] Among them, the logical value type (Logical, 0 to 1) in the program statements of the Simulink-StateFlow model corresponds to the boolean type in NuSMV; the integer type (Int / Unit, -2 31 ~2 31 ) in the program statements corresponds to the integer type (integer, -2 31 +1 to 2 31 -1) in NuSMV; the single-precision floating-point number (Single) in the program statements corresponds to the signed word in NuSMV; the double-precision floating-point number (Double) corresponds to the unsigned word in NuSMV.

[0090] The character type and other types in the program statements generally appear in the form of enumeration, corresponding to the enumeration type in NuSMV. The state variables in the program statements can be directly mapped to the state variables in NuSMV, and they have the same type and the same name; the conversion of the environment variables depends on the state variables. During the model conversion process, according to the actual situation, the environment variables are first expressed through the state variables, and then the state variables are converted.

[0091] Step 802, convert the custom function into a module in NuSMV. The custom function is also written in the Matlab programming language. For the conversion of the arithmetic operators in the function statements, it is necessary to verify the results at the same time to make them conform to the value range of the NuSMV constants. During the NuSMV verification process, only the Matlab functions that can be recognized by NuSMV in the verification model will be called to participate in the operation and execution. Other Matlab built-in functions used when writing the program statements and custom functions (such as the deconvolution function decnov, the function zeros for creating an all-zero array, etc.) cannot be recognized and need to be screened and located during the syntax analysis process, and converted into recognizable statements or program steps separately. Then return the converted custom function body.

[0092] Step 803, determine the statement type, and automatically convert the assignment statements, loop statements, and judgment statements. For the loop and judgment statements, the "case" expression in NuSMV is used to describe the process of condition transfer, and each transfer in the state model to be converted is mapped to a conditional expression in NuSMV. For each pending state in the state model, find all the assignment behaviors that change the NuSMV environment variables in the state model and convert them into corresponding case clauses.

[0093] Step 804, generate the converted NuSMV model.

[0094] The above embodiments are only used to illustrate the present invention and are not intended to limit the present invention. Those of ordinary skill in the relevant technical field can also make various changes and modifications without departing from the essence and scope of the present invention. Therefore, all equivalent technical solutions also fall within the protection scope of the present invention.

[0095] The content not detailedly described in this specification belongs to the well-known prior art of those skilled in the art.

Claims

1. A conversion method from Simulink-StateFlow model to NuSMV model, characterized in that, It includes the following steps: Step 1: Conduct a formal analysis of the requirements for the system to be evaluated and construct a Simulink-StateFlow model; generate project engineering files, which include: JSON format files, C language format files, and SVG format files; Step 2: Analyze the format characteristics of the JSON format files, extract program statements from the JSON format files, and construct a program statement data table; Step 3: Analyze the format characteristics of the C language format files, extract custom function statements from the C language format files, and construct a custom function data table; Step 4: Analyze the format characteristics of the SVG format files, read the logical sequence relationship of the program statements extracted in Step 2, and construct a logical sequence data table; Step 5: According to the program statement data table and the logical sequence data table constructed in Step 2 and Step 4, use an algorithm to integrate the model program and sequence, and generate a Simulink model information table; Step 6: Analyze the Matlab programming language used in the program statements and construct the syntax rules of the Matlab language; Step 7: Process the program statements in the Simulink model information table according to the syntax rules of the Matlab language given in Step 6, and parse the program statements into an Abstract Syntax Tree (AST); Step 8: Process the Abstract Syntax Tree (AST) to determine the conversion algorithm for converting it into NuSMV statements; according to the conversion algorithm, process the Simulink model information table to generate a NuSMV model, specifically as follows: Step 801: Automatically convert the definition and initialization statements; during the conversion process, the basic types supported by the program statements to be converted include integer type, real number type, character data, logical value type, array data, built-in functions of Matlab-Simulink, and custom functions written using the Matlab editor. The integer type includes multi-bit signed and unsigned integer words, and the real number type includes single-precision floating-point numbers and double-precision floating-point numbers; the types supported by NuSMV include boolean type, integer type, enumeration type, signed word, unsigned word, array type, and set type; Among them, the logical value type in the program statements corresponds to the boolean type in NuSMV; the integer type in the program statements corresponds to the integer type in NuSMV; the single-precision floating-point number in the program statements corresponds to the signed word in NuSMV; the double-precision floating-point number in the program statements corresponds to the unsigned word in NuSMV; The state variables in the program statements are directly mapped to the state variables in NuSMV, and they have the same type and the same name is maintained; the conversion of environmental variables depends on the state variables. During the model conversion process, according to the actual situation, the environmental variables are first expressed through the state variables, and then the state variables are converted; Step 802: Convert the custom function into a module in NuSMV; the custom function is also written in the Matlab programming language; for the conversion of arithmetic operators in the function statements, it is necessary to verify the result at the same time to make it conform to the value range of NuSMV constants; during the NuSMV verification process, only the Matlab functions that can be recognized by NuSMV in the verification model will be called to participate in the operation and execution, and other Matlab built-in functions used in writing program statements and custom functions cannot be recognized and need to be screened and located during the syntax analysis process and converted into recognizable statements or program steps separately; then return the converted custom function body. Step 803: Determine the statement type and automatically convert assignment statements, loop statements, and judgment statements; for loop and judgment statements, the case expression in NuSMV is used to describe the condition transfer process, and each transfer in the state model to be converted is mapped to a conditional expression in NuSMV; for each pending state in the state model, find all the assignment behaviors that change the NuSMV environment variables in the state model and convert them into corresponding case clauses. Step 804: Generate the converted NuSMV model.

2. The conversion method from Simulink-StateFlow model to NuSMV model according to claim 1, characterized in that: In Step 1, the specific content of constructing the Simulink-StateFlow model is: draw the blocks, starting points, transfers, connection points of the model, input program statements, and write custom functions. After the Simulink state diagram is drawn, through the Simulink menu: File->Export Model to->Web, select the export mode as Entire Model-Export to generate a project engineering file; the JSON format file is used to record all the program statements required for state migration filled in during the Simulink modeling process; the C language format file is used to record all the custom function statements filled in during the Simulink modeling process; the SVG format file is used to record all the state migration processes drawn during the Simulink modeling process.

3. The conversion method from Simulink-StateFlow model to NuSMV model according to claim 1, characterized in that, In Step 2, the specific algorithm for extracting program statements is: traverse the JSON data file sequence, filter redundant items inspector, extract the items where the program statements are located, filter redundant characters, and integrate the data structure; according to the characteristics of the JSON format file, define the following data structure to represent the data relationship of the program statement data table: [Sid, ExecutionOrder, Program], where Sid represents the identification number of the program, ExecutionOrder represents the branch order information of program execution, ExecutionOrder = {1, 2}, when ExecutionOrder is 1, it means that the branch where the program statement is located is the branch to be executed first, when ExecutionOrder is 2, it means that the execution order of the program statement is after branch 1, and Program represents the specific program statement body.

4. The conversion method from Simulink-StateFlow model to NuSMV model according to claim 1, characterized in that In step 3, the algorithm for extracting custom function statements is as follows: traverse the C language format file sequence, locate the line where the custom function keyword is located, extract the function name, extract the function body, filter redundant characters, and integrate data structures; according to the C language format file and the custom function body format, define the following data structure to represent the data relationship of the custom function data table: [FunctionTitle, FunctionBody], where FunctionTitle represents the function name of the custom function, and FunctionBody represents the function body of the custom function.

5. The conversion method from Simulink-StateFlow model to NuSMV model according to claim 1, characterized in that, In step 4, the reading algorithm used is as follows: Step 401: Read in the SVG format file; Step 402: Perform a logical sorting operation within each graphic block; first, find the starting point of each block diagram within the block, calculate and mark the starting point coordinates, number, and type; Secondly, find the connection points in each block diagram within the block, calculate and mark the connection point coordinates, type, and number; Find the transfers in each block diagram within the block, calculate and mark the transfer start and end point coordinates, type, and number; for each group of transfers, find the start and end start or connection points; finally, read the normalized transfer list information, and filter out the intermediate operations of the connection points according to the pre-connected point and post-connected point, and list the logical relationship between the transfers; Step 403: Perform a logical sorting operation between each graphic block; first, find the starting point of the total block diagram and mark the starting point coordinates, number, and type; Find the transfers in the overall diagram and mark the transfer start and end point coordinates, type, and number; find the upper and lower boundaries of each graphic block within the block and mark the coordinates, type, and number of the block boundary; for each group of transfers, find the graphic block boundaries where they start and end; read the normalized transfer list information, and list the logical relationship between the transfers and the graphic blocks according to the pre-graphic block boundary and post-graphic block boundary; Step 404: Integrate the logical relationship information obtained in steps 402 and 403.

6. The conversion method from Simulink-StateFlow model to NuSMV model according to claim 5, characterized in that: Define the following data structure to represent the block diagram number relationship corresponding to the program: [Identifier_Front, Identifier_Behind]; where Identifier_Front represents the number of the logical pre-element, and Identifier_Behind represents the number of the logical post-element. At the logical order level, the element Identifier_Front is before the element Identifier_Behind, and there is a directed path between the two; Define the following data structure to represent the identification relationship of graphic elements in SVG: [Element_Identifier, Element_ID, Element_ParentID]; where Element_Identifier represents the custom number corresponding to the element in SVG, Element_ID represents the original identification number corresponding to the element in SVG, and Element_ParentID represents the original identification number of the block diagram corresponding to each program statement in the SVG diagram; Define the following data structure to represent the status information of the starting points in the graphic elements of SVG: [StartPoint_Identifier, StartPoint_Type, StartPoint_ParentID]; where StartPoint_Identifier represents the custom number corresponding to all starting points in the SVG diagram, StartPoint_Type represents the type of the starting point in the SVG diagram, StartPoint_Type = {block_in, block_out}, when StartPoint_Type takes the value of block_in, it means that the starting point is inside the block, and when StartPoint_Type takes the value of block_out, it means that the starting point is outside the block, and StartPoint_ParentID represents the original identification number of the block corresponding to each starting point; Refer to the above three data structures to generate the logical order data table List_ElementOrder, the element number information table List_IdentifierID, and the starting point status information table List_StartPoint, and store the logical information extracted from the SVG diagram.

7. The conversion method from the Simulink-StateFlow model to the NuSMV model according to claim 6, characterized in that, In step 5, the specific algorithm for integrating the model program and the order is as follows: Step 501: Read the starting point status information table List_StartPoint, the logical order data table List_ElementOrder, the element number information table List_IdentifierID, and the program statement data table List_JsonProgram; Step 502: Integrate the starting point information, block information, and program statement information in the data table; Step 503: Record the number of program statements in each block diagram; Step 504: Use a stack structure to assist in sorting the order of all program statements and construct a program data storage stack; Step 505: Generate the Simulink model information table, and the Simulink model information table includes the ordered program statement table List_ProgramOrder and the element branch mapping table Map_Branch.

8. The conversion method from Simulink-StateFlow model to NuSMV model according to claim 1, characterized in that, In step 6, the specific content of analyzing the Matlab programming language is: extraction and sorting of program statements, lexical analysis of program statements, judgment of program statement types, adjustment of program statements, removal of redundant items, addition of counters, and generation of conversion models.

9. The method for converting a Simulink-StateFlow model to a NuSMV model according to claim 1, wherein, In step 7, the specific content of parsing the program statements into an abstract syntax tree is: reading the program statements and identifying, recognizing and extracting identifiers, extracting intermediate quantities and identifying functions for operators, assigning weights to each quantity in the program statements, and sorting each quantity of the program statements according to the weights using a stack and a linked list.