Aviation Control System SysML State Diagram Model Verification Method and Its Verification System
Through the state machine model verification method designed by the SCXML standard, the complexity problem of SysML state graph model verification is solved, and efficient model checksum error detection is achieved before simulation, ensuring that the model complies with the standards.
Patent Information
- Application Number
- CN202211667583.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-12-23
AI Technical Summary
In the prior art, the SysML state graph model lacks effective verification methods, making it difficult to conduct rigorous semantic analysis and correctness verification, and the model verification method is highly complex and difficult to simulate before implementation.
The state machine model verification method designed by the SCXML standard is adopted to identify the context environment of the aviation control system, build a state diagram and transformation relationship model, and export the state machine files described by the XML language, and verify it in the CSharp language experiment to avoid the conversion of UML state machine to complex intermediate languages.
It reduces the difficulty of implementing model verification, improves model verification efficiency, reduces the test cycle, ensures that the SysML state diagram meets relevant standards, and can detect and troubleshoot hidden errors before model simulation.
Smart Images

Figure CN116305517B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of model verification, and particularly relates to a method and a system for verifying a SysML state diagram model of an aviation control system. Background Art
[0002] SysML (Systems Modeling Language) is a general system architecture modeling language for system engineering applications, which is an extension and expansion of the Unified Modeling Language (UML) in the field of system engineering applications. It can be used for the integrated architecture description, analysis, and design of complex systems composed of software and hardware, data, and people.
[0003] As application systems become more complex, any link of the system may affect the overall operation of the system. For example, an aviation control system is a huge and complex system, and it cannot be guaranteed that its objects can operate safely and steadily throughout their life cycle. Once an abnormal situation occurs, it will cause huge economic and personnel losses. Using SysML modeling can abstractly represent the objects of an application system. By studying the instances of a certain active class in the class model and verifying its behavior model, the operation process of the object during its life cycle can be simulated, and each use case scenario implemented in this way can be rehearsed. SysML state diagrams are used to establish the behavior model of class objects during their life cycle, especially when the objects have state-dependent behaviors. To make the description clear and easy to understand, when SysML gives its own semantic description, it adopts a semi-formal description method, using natural language to describe constraints and detailed semantics, and strives to achieve a balance between strict formality and easy understanding. This means that the SysML model itself lacks accurate semantics, making it difficult to perform strict semantic analysis and correctness verification on it. Therefore, for the graphics described by SysML, there is currently a lack of effective verification and analysis methods, and it is also difficult to perform simulation before the model is implemented. As an important part of the SysML behavior modeling mechanism, state diagrams also have the same problem. To endow SysML with formal semantics, SCXML (State Chart XML) can be used as the formal description language for SysML state diagrams. SCXML is a W3C recommendation standard for complex finite state machines. It supports complex elements such as sub-states, parallel states, concurrency, and synchronization, and can represent all the information of the SysML state diagram architecture. Currently, most state diagram model verification methods are based on complex intermediate languages, such as NuSVM, Spin, etc., which greatly increase the implementation complexity and learning difficulty. Therefore, to solve this problem, it is very urgent and necessary to seek a method for verifying a SysML state diagram model of an aviation control system to achieve formal verification of the SysML state diagram. Summary of the Invention
[0004] In view of the above-mentioned defects in the prior art, the present invention proposes a method for verifying the SysML state diagram model of an aviation control system. The method includes determining the context environment in which the aviation control system operates, identifying the set of states existing in the context environment of the aviation control system, constructing the state diagram of the aviation control system, constructing the internal behavior model of sequential states, constructing the conversion relationship model between sequential states, constructing the behavior model of the aviation control system, exporting the state machine file described in xml language, importing it into the computer program tested in CSharp language, and performing the verification of the state machine. The state machine model verification method designed based on the SCXML standard in the present invention avoids the conversion from the UML state machine to a complex intermediate language, reduces the difficulty of implementing model verification, improves the efficiency of model verification, can avoid repeatedly modifying the model, reduces the test cycle, and ensures that the SysML state diagram complies with relevant standards.
[0005] The present invention provides a method for verifying the SysML state diagram model of an aviation control system, which includes the following steps:
[0006] S1. Determine the context environment in which the aviation control system operates: Determine the first environment upstream of the aviation control system and the second environment downstream of the aviation control system;
[0007] S2. Identify the set of states existing in the context environment of the aviation control system: Identify the state list including all sequential states of the aviation control system in the first environment and mark the corresponding initial state and end state, and identify the state list including all sequential states of the aviation control system in the second environment and mark the corresponding initial state and end state;
[0008] S3. Construct the state diagram of the aviation control system: According to the control system behavior described in the functional specification, establish all preset conversions between the states in the state set, and construct the state diagram of the aviation control system. The conversions between the states in the aviation control system state diagram are connected by broken lines with arrows, and the broken lines represent the conversion relationships between the states in the state set;
[0009] S4. Construct the internal behavior model of sequential states: For the state diagram of the aviation control system, construct the internal behavior model for the internal behaviors of all the sequential states. The internal behavior model describes the internal attributes of the states represented by the sequential states;
[0010] S5. Construct the conversion relationship model between sequential states: For all conversion relationships between sequential states, that is, the broken lines, construct the conversion relationship model. The conversion relationship model describes the triggers, guards, and crossings of the conversions between different sequential states;
[0011] S6. Construct the behavior model of the aviation control system: Based on the state diagram of the aviation control system, the internal behavior model of sequential states, and the conversion relationship model between sequential states, use the SysML state diagram modeling tool to construct the behavior model of the aviation control system;
[0012] S7. Export the state machine file described in xml language: Use the SysML state diagram modeling tool to export the behavior model of the aviation control system into a state machine file described in xml language;
[0013] S8. Conduct the verification of the state machine: Import the state machine file exported in step S7 into the computer program for CSharp language experiments to conduct the verification of the state machine;
[0014] S81. Create a model validator and initialize it;
[0015] S82. Create temporary variables and assign values;
[0016] S83. According to the SCXML standard, create dictionaries for element attribute mapping, element child node mapping, and element parent node mapping, and conduct the legality verification of the attributes, child nodes, and parent nodes of the state machine elements respectively;
[0017] S84. According to the SCXML standard, conduct the verification of the nodes of the state types, the transition nodes of the state nodes, and the history pseudo-states in the state machine respectively;
[0018] S85. According to the SCXML standard, conduct the verification of the initial node attributes, the target attribute values of the nodes, the transition attributes of the initial node, the invoke node values, the type attribute values of the send elements, and the custom executable content in the state machine respectively;
[0019] S86. According to the SCXML standard, conduct the verification of the element attributes, the validity of the parent nodes, and the validity of the constraints in the state machine;
[0020] S87. According to the attributes initialized in step S81, conduct the verification of the syntax of the script content and the syntax of the element expressions in the state machine;
[0021] S88. Return the error list as the verification result of the state machine and output it.
[0022] Furthermore, the specific steps of step S82 include the following steps:
[0023] S821. Assign values to the scm variable, factory variable, dm variable, and ns variable. The scm variable is assigned the scxml attribute value of the model validator, representing the root node of the entire model; the factory variable is assigned the factory attribute value of the model validator, representing the factory object; the dm variable is assigned the factory attribute value of the model validator; the ns variable is assigned the ns attribute of the model validator, representing the xml namespace.
[0024] S822. Create the first dictionary nodeMap: Starting from the root element scxml, recursively traverse the state machine elements using the breadth-first traversal algorithm of the graph, and store the tag names of the traversed state machine elements and the corresponding state machine element objects themselves in key-value pairs.
[0025] S823. Create a stack: Push the scm element onto the stack, execute the reachability algorithm, and return the list of all state machine element objects reachable from the root element, denoted as reachable. The parameter of the reachability algorithm is the scm parameter.
[0026] S824. Batch execute assignment statements: Assign the variables in the first variable set to the objects at the corresponding positions in the first object set in sequence.
[0027] S825. Create the first list allStates: Add all elements in the second variable set contained in the first variable set to the first list allStates. The first list allStates contains all state elements in the state machine model.
[0028] S826. Create the second list allActions: Add all elements in the third variable set contained in the first variable set to the second list allActions. The second list allActions contains all runnable elements in the state machine model.
[0029] S827. Create the third list allElements: Add the root element scxml, the first list allStates, the second list allActions, and all elements in the fourth variable set contained in the first variable set to the third list allElements. The third list allElements contains all elements of the state machine model.
[0030] S828. Create the set execSet: Add the second object set to the set execSet.
[0031] S829. Create and initialize the second dictionary seenState.
[0032] Step S84 specifically includes the following steps:
[0033] S841. Verify the nodes of the state types in the state machine;
[0034] S8411. Traverse the variable states in step S825 in a loop. Assume that the currently traversed state machine element is the state element;
[0035] S8412. Obtain the id attribute of the state element. If the id is empty, generate the first error message; obtain the label name of the state element, and determine whether the state element is a history element. If so, execute steps S8413 to S8418;
[0036] S8413. Obtain all the transition child nodes under the history element. If the number of transition nodes is greater than 1 or equal to 0, generate the second error message; otherwise, execute step S8414;
[0037] S8414. Traverse all the transition child nodes under the history element in a loop, and determine whether the child node has a cond attribute or an event attribute. If so, generate the third error message; otherwise, determine whether the child node has a target attribute. If not, generate the fourth error message; otherwise, execute step S8415;
[0038] S8415. Obtain the transition child node of the state element, and determine whether the transition child node has a cond attribute, an event attribute, and a target attribute. If it has a cond attribute and an event attribute, generate the fifth error message; if it does not have a target attribute, generate the sixth error message; otherwise, execute step S8416;
[0039] S8416. Obtain the target child node associated with the transition child node, and traverse the target child nodes in a loop. If the type of the current target child node is deep and it is not a child node of the state element, generate the seventh error message; otherwise, if the parent node of the target child node is not equal to the parent node of the state element, generate the eighth error message;
[0040] S8417. Determine whether the state element is in the reachable returned in step S823. If not, generate the ninth error message;
[0041] S8418. Determine whether it exists in the second dictionary seenState in step S829 according to the id attribute of the state element. If it exists, generate the tenth error message;
[0042] S842. Verify the transition nodes of the state element in the state machine to determine whether there are redundant transitions;
[0043] S8421. Loop through S825 to create the first list allStates, and execute steps S8422 to S8424 for each element in the first list allStates;
[0044] S8422. Obtain the transition child nodes of the current state element, denoted as the transitions list;
[0045] S8423. Loop through the transitions list. Assume that the current traversed migration element is the i-th one, denoted as the itrans element;
[0046] S8424. Search the transition list in sequence by subscripts 0 to (i - 1). If it is found that the cond attribute and event attribute of a certain migration element do not exist, generate the eleventh error message; if it is found that the cond attribute of a certain migration element does not exist and the event attribute exists, denote it as the earlier element, and compare the event attribute value of the earlier element with the list elements of the event attribute of the itrans element in sequence. If the former includes the latter, generate the twelfth error message;
[0047] S843. Verify the history pseudo-states in the state machine to determine whether there are useless history pseudo-states;
[0048] S8431. Loop through the variable histories in step S824, denoted as the history element;
[0049] S8432. Obtain the parent node of the history element. If the parent node is an atomic state, generate the thirteenth error message;
[0050] S8433. Obtain the set of state child nodes, parallel child nodes, and final child nodes of the parent node. If they do not exist, it means that only the history child node exists under the parent node, and generate the fourteenth error message;
[0051] The specific steps of step S85 are as follows:
[0052] S851. Verify the attributes of the initial node in the state machine according to the SCXML standard;
[0053] S8511. Traverse the first list allStates in step S825 in a loop. Assume the current element is the state element. If the state element has an initial attribute, execute step S8512;
[0054] S8512. Create a fourth list childs, and add the state elements, parallel elements, final elements, and history elements under the state element to the fourth list childs;
[0055] S8513. Obtain the list of values of the initial attribute of the state element. Traverse the elements in the list of values of the initial attribute in a loop and obtain the corresponding state nodes from the second dictionary seenState in step S829. If the state does not exist, generate the fifteenth error message; if the state exists, obtain the corresponding state node from the second dictionary seenState, and determine whether the state node is in the fourth list childs. If it does not exist, generate the sixteenth error message;
[0056] S852. According to the SCXML standard, verify the target attribute values of the nodes in the state machine: Create a third dictionary targetIdMap, and traverse the variable transitions, variable initials in step S824, and the first list allStates in step S824 in sequence to obtain;
[0057] S853. According to the SCXML standard, verify the transition attribute values of the initial nodes in the state machine;
[0058] S8531. Traverse the list of initials in step S824 in a loop. Assume the current traversed element is the initial element. Obtain the list of transition child nodes of the initial element, and determine that the length of the list is not equal to 1, then generate the seventeenth error message, otherwise execute step S8532;
[0059] S8532. Determine whether the transition child node of the initial element has a cond attribute or an event attribute. If it exists, generate the eighteenth error message;
[0060] S8533. Determine whether the grandparent node of the transition child node of the initial element exists. If it exists, obtain the child nodes of the state, parallel, final, and history types under the grandparent node, and store them in the fifth list tmplist;
[0061] S8534. Obtain the target attribute value of the migrated child node of the initial element, and sequentially determine whether the target state corresponding to the attribute value exists in the fifth list tmplist. If it does not exist, generate the nineteenth error message;
[0062] S854. According to the SCXML standard, verify the value of the invoke node in the state machine: Loop through the invokes list of the variable in step S824. Assume the currently traversed element is an invoke element, obtain the type attribute value of the invoke element. If the type attribute value exists, obtain the factory object in step S812 and determine whether it is in the list of registered plugins. If the object corresponding to the type attribute value cannot be found in the plugin list, obtain the idlocation attribute of the invoke element. If the idlocation attribute value exists, generate the twentieth error message; if the idlocation attribute value does not exist, generate the twenty - first error message;
[0063] S855. According to the SCXML standard, verify the type attribute value of the send element in the state machine: Loop through the sends list of the variable in step S824. Assume the currently traversed element is a send element, obtain the type attribute value of the send element. If the attribute value exists, obtain the factory object in step S812 and determine whether it is in the list of registered IOProcessor plugins. If the object corresponding to the type attribute value cannot be found in the plugin list, generate the twenty - second error message;
[0064] S856. According to the SCXML standard, verify the custom executable content in the state machine: Create the sixth list executecontents, and insert the content of the variables onEntries, onExits, transitions, and finalizes in step S824. Loop through the sixth list executecontents. Assume the currently accessed element is an ec element, obtain all child nodes of the ec element, determine whether the ec element is in the second list allActions. If it exists, determine whether the child nodes are in the plugins of the factory object in step S812. If not, generate the twenty - third error message;
[0065] The step S86 specifically includes the following steps:
[0066] S861. According to the SCXML standard, verify the attributes of the elements in the state machine and the validity of the parent nodes: Traverse the third list in step S827 in a loop. Assume that the currently traversed element is the element element. According to the value of the name attribute of the element element, obtain the list of attributes that the element element must define from the element attribute mapping dictionary in step S83, and sequentially determine whether the attributes in the attribute list exist in the name attribute of the element element. If not, generate the twenty-fourth error message; According to the value of the name attribute of the element element, obtain its legal parent node list from the element parent node mapping dictionary in step S83, and determine whether the parent node of the element exists in the element parent node mapping dictionary. If not, generate the twenty-fifth error message;
[0067] S862. According to the SCXML standard, verify the constraint validity of the attributes of the elements in the state machine:
[0068] S8621. Traverse the initials list of variables in step S824 in a loop. Assume that the currently traversed element is the initial element. Obtain the parent node of the initial element and determine whether the parent node has the initial attribute. If so, generate the twenty-sixth error message; Determine whether the initial parent node is an atomic state. If so, generate the twenty-seventh error message;
[0069] S8622. Traverse the states list of variables in step S824 in a loop. Assume that the currently traversed element is the state element. Determine whether the state element is an atomic state. If so, generate the twenty-eighth error message;
[0070] S8623. Traverse the assigns list and the contents list of variables in step S824 in a loop. Assume that the currently traversed element is the e element. If the e element has both the expr attribute and child nodes at the same time, generate the twenty-ninth error message;
[0071] S8624. Traverse the params list of variables in step S824 in a loop. Assume that the currently traversed element is the param element. If the param element has both the expr attribute and the location attribute at the same time, generate the thirtieth error message;
[0072] S8625. Traverse the sends list of variables in step S824 in a loop. Assume that the currently traversed element is the send element and execute step S8629;
[0073] S8626. Loop through the list of variables cancels in step S824. Assume the current traversed element is a cancel element. If the cancel element has a sendid attribute and a sendidexpr attribute, then generate the thirty - first error message;
[0074] S8627. Loop through the list of variables invokes in step S824. Assume the current traversed element is an invoke element and execute step S86210;
[0075] S8628. Loop through the list of variables doneDatas in step S824. Assume the current traversed element is a doneData element. If the doneData element has a param attribute and a content child node, then generate the thirty - second error message;
[0076] S8629. If there are an event attribute and an eventexpr attribute, then generate the thirty - third error message; if there are a target attribute and a targetexpr attribute, then generate the thirty - fourth error message; if there are a type attribute and a typeexpr attribute, then generate the thirty - fifth error message; if there are an id attribute and an idlocation attribute, then generate the thirty - sixth error message; if there are a delay attribute and a delayexpr attribute, then generate the thirty - seventh error message; if there are a delay attribute and a target attribute and the value of the target attribute is internal, then generate the thirty - eighth error message; if there is a content child node and a namelist attribute or a param attribute, then generate the thirty - ninth error message;
[0077] S86210. If there are a type attribute and a typeexpr attribute, generate the fortieth error message; if there are an id attribute and an idlocation attribute, generate the forty - first error message; if there are a type attribute and a typeexpr attribute, generate the forty - second error message; if there are a namelist attribute and a param child node, generate the forty - third error message; if there are a src attribute and a content child node, generate the forty - fourth error message;
[0078] The step S87 specifically includes the following steps:
[0079] S871. Check the syntax of the script content in the state machine: Loop through the list of variables scripts in step S824, and use the script script plugin object registered by the factory object in step S812 to judge the correctness of the syntax of the script element. If the verification fails, then generate the forty - fifth error message;
[0080] S872. Verify the expression syntax of the elements in the state machine;
[0081] S8721. Loop through the lists of variables transitions, ifs, and elseifs used to store the steps of S824. Assume the currently traversed element is the e element, obtain the cond attribute of the e element, and use the DataModel object of step S824 for verification. If the verification fails, a forty-sixth error message will be generated;
[0082] S8722. Create a seventh list exprs to store the variables logs, datas, assigns, contents, and params of step S824. Loop through the seventh list exprs. Assume the currently traversed element is the expression element, obtain the expr attribute of the expression element, and use the DataModel object of step S824 for verification. If the verification fails, a forty-seventh error message will be generated;
[0083] S8723. Loop through the list of variables foreachs used to store the steps of S824. Assume the currently traversed element is the foreach object, obtain the values of array / index / index of the foreach object, and use the DataModel object of step S824 for verification. If the verification fails, a forty-eighth error message will be generated;
[0084] S8724. Loop through the list of variables sends used to store the steps of S824. Assume the currently traversed element is the send object, obtain the values of event, target, type, idlocation, and delayexpr of the send object, and use the DataModel object of step S824 for verification. If the verification fails, a forty-ninth error message will be generated.
[0085] Preferably, the step S823 specifically includes the following steps:
[0086] S8231. Create a list of temporary variables reachable to store the reachable elements as the final return value of the algorithm;
[0087] S8232. Create a first stack object newNodes to store the newly added nodes in the previous traversal process, create a second stack object associateNodes to store the newly associated nodes of the newly added nodes, and add the scm parameter to the first stack object newNodes;
[0088] S8233. Traverse the first stack object newNodes, obtain the initial nodes that each element in the first stack object newNodes can reach, and add the initial nodes to the second stack object associateNodes;
[0089] S8234. Traverse the first stack object newNodes, obtain the transition child nodes under each element in the first stack object newNodes, and add all the target child nodes associated with the transition child nodes to the second stack object associateNodes;
[0090] S8235. Traverse the first stack object newNodes, if the node is a composite state or a parallel state, obtain all the ancestor state nodes of the node, and add them to the second stack object associateNodes;
[0091] S8236. Add all the elements in the second stack object associateNodes to the temporary variable list reachble;
[0092] S8237. Move all the elements in the second stack object associateNodes to the first stack object newNodes;
[0093] S8238. Clear the second stack object associateNodes;
[0094] S8239. Repeat steps S8233 to S8238 until the first stack object newNodes is empty.
[0095] Preferably, in step S82, the first variable set includes variables states, parallels, transitions, initials, finals, onEntries, onExits, histories, raises, ifs, elseifs, elses, foreachs, logs, dataModels, datas, assigns, doneDatas, contents, params, scripts, sends, cancels, invokes, and finalizes; the second variable set includes variables states, paralles, histories, and finals; the third variable set includes variables raises, ifs, elseIfs, elses, foreachs, logs, sends, assigns, scripts, and cancels; the fourth variable set includes variables transitions, initials, onEntries, onExits, dataModes, datas, doneDatas, contents, params, invokes, and finalizes; the first object set includes state objects, parallel objects, transition objects, initial objects, final objects, onentry objects, onexit objects, history objects, raise objects, if objects, elseif objects, else objects, foreach objects, log objects, dataModel objects, data objects, assign objects, donedata objects, content objects, param objects, script objects, send objects, cancel objects, invoke objects, and finalize objects obtained from the first dictionary nodeMap; the second object set includes if objects, elseif objects, else objects, foreach objects, raise objects, send objects, cancel objects, assign objects, script objects, and log objects;
[0096] The state machine elements described in step S83 include scxml element, raise element, if element, elseif element, foreach element, data element, assign element, param element, state element, parallel element, transition element, onentry element, onexit element, finalize element, else element, initial element, history element, final element, datamodel element, donedata element, send element, and invoke element; the element attribute mapping dictionary stores the attribute nodes that must be defined for the state machine elements. The attribute node that must be defined for the raise element is the even node. The attribute nodes that must be defined for the if element and the elseif element are the cond node. The attribute nodes that must be defined for the foreach element include the array node and the item node. The attribute node that must be defined for the data element is the id node. The attribute node that must be defined for the assign element is the location node. The attribute node that must be defined for the param element is the name node; the element child node mapping dictionary stores the legal child nodes defined by the state machine elements. The child nodes defined by the scxml element include the state child node, parallel child node, final child node, datamodel child node, and script child node; the child nodes defined by the state element and the parallel element both include the onentry child node, onexit child node, transition child node, state child node, parallel child node, history child node, datamodel child node, and invoke child node. The child nodes defined by the state element also include the initial child node and the final child node; the child nodes defined by the transition element, onentry element, onexit element, finalize element, if element, elseif element, else element, and foreach element all include all the child nodes in the execSet; the child nodes defined by the initial element and the history element are the transition child node; the child nodes defined by the final element include the entry child node, onexit child node, and donedata child node; the child node defined by the datamodel element is the data child node; the child nodes defined by the donedata element, send element, and invoke element all include the content child node and the param child node. The child nodes defined by the invoke element also include the finalize child node;The element parent node mapping dictionary is obtained by performing an inverse transformation based on the element child node mapping dictionary, and stores the legal parent nodes defined by the state machine elements.;
[0097] Preferably, the internal actions in step S4 include entry actions, exit actions, and general actions. The entry action represents the first executable atomic action for entering the sequence state. The exit action represents the action that must be executed to leave the sequence state. The general action represents the actions that can be executed when the aviation control system is in the sequence state. The trigger in step S5 represents the event that causes the transition between sequence states. The guard represents a Boolean type expression. When the Boolean type expression is true, the guard allows passage, and only then can the transition between sequence states occur. The cross represents the activities, interactions, and other sequence states existing in the aviation control system.
[0098] Preferably, step S81 specifically includes the following steps:
[0099] S811. Parse the xml model file through the System.Xml library, obtain the document object, and assign it to the document property of the model validator;
[0100] S812. Create a factory object and set the plugin object associated with the factory object, and assign the factory object to the factory property of the model validator;
[0101] S813. Use the document object to obtain the root element scxml of the xml document and the corresponding namespace. If the root element scxml does not exist, the entire verification process stops immediately and returns an error of "unable to find the root element scxml"; otherwise, assign the obtained root element scxml and the corresponding namespace to the scxml and ns properties of the model validator respectively;
[0102] S814. Obtain the script child element of the root element, and verify whether the script child element has an src attribute. If not, add the error message "the script child element lacks the src attribute" to the temporary list returned; otherwise, execute step S82.
[0103] Preferably, in the step S8, the first error message is that the attribute of [name of state] cannot be empty; the second error message is that the number of nodes that [name of state] cannot migrate must be exactly one; the third error message is that the migrated nodes of [name of state] cannot have the attributes cond or event; the fourth error message is that the target attribute of the migrated nodes of [name of state] cannot be empty; the fifth error message is that the migrated nodes of the historical pseudo-state [name of state] cannot define the cond and event attributes; the sixth error message is that the target attribute of the migrated nodes of the historical pseudo-state [name of state] cannot be empty; the seventh error message is that the target of the migrated nodes of the historical pseudo-state [name of state] of the deep type is illegal; the eighth error message is that the target of the migrated nodes of the historical pseudo-state [name of state] of the shallow type is illegal; the ninth error message is that [name of state] is unreachable; the tenth error message is that [name of state] is defined repeatedly; the eleventh error message is that there is an unconditional migration of [name of state]; the twelfth error message is the migration of [name of state] with the same event condition; the thirteenth error message is that the atomic state [name of the parent node] contains useless history nodes; the fourteenth error message is that [name of the parent node] contains useless history nodes; the fifteenth error message is that the state corresponding to the initial attribute value of [name of state] does not exist; the sixteenth error message is that the state corresponding to the initial attribute value of [name of state] is illegal; the seventeenth error message is that there must be only one migration path for [initial node]; the eighteenth error message is that the migration path of [initial node] cannot have the cond and event attributes; the nineteenth error message is that the target attribute of the migration path of [initial node] is illegal; the twentieth error message is that the type attribute value of [name of the invoke node] is empty; the twenty-first error message is that the type attribute value of [name of the invoke node] is illegal; the twenty-second error message is that the type attribute value of [name of the send node] is empty; the twenty-third error message is that the executable content of [name of ec] is unknown; the twenty-fourth error message is that the [name] attribute of [name of element] must be defined; the twenty-fifth error message is that the parent node of [name of element] is illegal; the twenty-sixth error message is that the [name of the parent node of initial] has both the initial attribute and the initial child node at the same time; the twenty-seventh error message is that the [name of the parent node of initial] is an atomic state,There cannot be an initial child node. The twenty-eighth error message is that [state name] is an atomic state and there cannot be an initial child node. The twenty-ninth error message is that [name of e] cannot have both an expr attribute and child nodes at the same time. The thirtieth error message is that [name of param] cannot have both expr and location attributes at the same time. The thirty-first error message is that [name of send] cannot have both sendid and sendidexpr attributes at the same time. The thirty-second error message is that [name of donedata] cannot have both paparamran attribute and content child node attribute at the same time. The thirty-third error message is that [name of send] cannot have both event and eventexpr attributes at the same time. The thirty-fourth error message is that [name of send] cannot have both target and targetexpr attributes at the same time. The thirty-fifth error message is that [name of send] cannot have both type and typeexpr attributes at the same time. The thirty-sixth error message is that [name of send] cannot have both id and idlocation attributes at the same time. The thirty-seventh error message is that [name of send] cannot have both delay and delayexpr attributes at the same time. The thirty-eighth error message is that [name of send] cannot have both delay and a target attribute with a value of interval at the same time. The thirty-ninth error message is that [name of send] cannot have both a namelist or param attribute and a content child node at the same time. The fortieth error message is that [name of invoke] cannot have both type and typeexpr attributes at the same time. The forty-first error message is that [name of invoke] cannot have both id and idlocation attributes at the same time. The forty-second error message is that [name of invoke] cannot have both type and typeexpr attributes at the same time. The forty-third error message is that [name of invoke] cannot have both a namelist attribute and a param child node attribute at the same time. The forty-fourth error message is that [name of invoke] cannot have both a src attribute and a content child node attribute at the same time. The forty-fifth error message is that there is a syntax error in the scripts. The forty-sixth error message is that there is a syntax error in the cond script of [name of e]. The forty-seventh error message is that there is a syntax error in the script of the expr attribute value of [name of e]. The forty-eighth error message is that there is a syntax error in the foreach attribute value array / index / index of [name of e].The forty-ninth error message is that there is a syntax error in the attribute values event / target / type / idlocation / delayexpr of [the name of send]; all the first to forty-ninth error messages generated are added to the error list in step S88.
[0104] Preferably, the initial state in step S2 is represented by a small black circle, the end state is represented by a hollow circle with a solid circle, the sequential states other than the initial state and the end state in the state list are represented by rounded rectangles, and all states in the state list must contain at least one name division box to display the state name.
[0105] Preferably, there are several of the first environment and the second environment in step S1, and in step S2, the aviation control system does not necessarily have a definite initial state and end state in the first environment and the second environment where it is located.
[0106] Another aspect of the present invention provides a verification system for the above-mentioned SysML state diagram model verification method of an aviation control system, which includes a context environment state set recognition module, a state diagram construction module, a sequential state internal behavior model construction module, a conversion relationship model construction module between sequential states, an aviation control system behavior model construction module, a state machine file generation module, and a state machine verification module that are communicatively connected to each other;
[0107] The context environment recognition module is used to determine the context environment in which the aviation control system operates and identify the state set existing in the aviation control system in the context environment;
[0108] The state diagram construction module is used to construct the state diagram of the aviation control system;
[0109] The sequential state internal behavior model construction module is used to construct the sequential state internal behavior model;
[0110] The conversion relationship model construction module between sequential states is used to construct the conversion relationship model between the sequential states;
[0111] The aviation control behavior model construction module is used to construct the aviation control behavior model;
[0112] The state machine file generation module is used to export the aviation control system behavior model into a state machine file described in xml language by using a SysML state diagram modeling tool;
[0113] The state machine verification module is used to import the exported state machine file into a computer program tested in CSharp language to perform the verification of the state machine.
[0114] Compared with the prior art, the technical effects of the present invention are as follows:
[0115] 1. A method for validating the SysML state diagram model of an aviation control system designed by the present invention. The proposed method is based on the SCXML standard of the W3C consortium, supports complex elements such as sub-states, parallel states, concurrency, and synchronization, can be used to represent all information of the SysML state diagram architecture, and at the same time supports simple states, composite states, and parallel states, and can perform compliance verification of the model standard for complex states.
[0116] 2. A method for validating the SysML state diagram model of an aviation control system designed by the present invention. Compared with the traditional method for validating the UML state machine model, the proposed method avoids the conversion from the UML state machine to a complex intermediate language. By directly exporting the model as a model file described in XML language, and using the mature DOM technology to parse the XML model and complete the compliance verification of the model standard, it reduces the difficulty of implementing model verification and improves the efficiency of model verification.
[0117] 3. A method for validating the SysML state diagram model of an aviation control system designed by the present invention. By performing validity verification on the model before simulation and use and giving visual prompts, it is convenient to discover and troubleshoot hidden errors in the model, avoid repeated modification of the model, reduce the test cycle, and greatly improve the modeling efficiency; at the same time, ensure that the constructed SysML state diagram complies with relevant standards, and the constructed model can be directly used for simulation calculation, avoiding repeated modeling multiple times. BRIEF DESCRIPTION OF THE DRAWINGS
[0118] Other features, objectives, and advantages of the present application will become more obvious by reading the detailed description of the non-limiting embodiments with reference to the following drawings.
[0119] Figure 1 is the flowchart of the method for validating the SysML state diagram model of the aviation control system of the present invention;
[0120] Figure 2 is the structural schematic block diagram of the system for validating the SysML state diagram model of the aviation control system of the present invention;
[0121] Figure 3 is an example diagram of the SysML state diagram of the satellite altitude control subsystem in a specific embodiment of the present invention;
[0122] Figure 4 is an example diagram of the content of the XML file of the satellite altitude control subsystem model in a specific embodiment of the present invention;
[0123] Figure 5 is an example diagram of the verification result of the satellite altitude control subsystem model in a specific embodiment of the present invention. Detailed implementation manners
[0124] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. In addition, it should be noted that for the convenience of description, only parts related to the invention are shown in the accompanying drawings.
[0125] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and embodiments.
[0126] Figure 1 The SysML state diagram model verification method of the aviation control system of the present invention is shown, and the method includes the following steps:
[0127] S1. Determine the context environment in which the aviation control system operates: Determine the first environment upstream of the aviation control system and the second environment downstream of the aviation control system. There are several in both the first environment and the second environment.
[0128] S2. Identify the state set existing in the context environment of the aviation control system: Identify the state list including all sequential states in the first environment of the aviation control system and mark the corresponding initial state and end state, and identify the state list including all sequential states in the second environment of the aviation control system and mark the corresponding initial state and end state. There may not be a definite initial state and end state in both the first environment and the second environment where the aviation control system is located. The initial state is represented by a small black circle, the end state is represented by a hollow circle with a solid circle, the sequential states other than the initial state and the end state in the state list are represented by a rounded rectangle, and all states in the state list must include at least one name division box to display the state name.
[0129] S3. Construct the state diagram of the aviation control system: According to the control system behavior described in the functional specification, establish all preset conversions between the states in the state set, and construct the state diagram of the aviation control system. The conversions between the states in the aviation control system state diagram are connected by a polyline with an arrow, and the polyline represents the conversion relationship between the states in the state set.
[0130] S4. Construct the internal behavior model of the sequential state: For the state diagram of the aviation control system, construct an internal behavior model for the internal behavior of all sequential states, and the internal behavior model describes the internal attributes of the states represented by the sequential states.
[0131] Internal behaviors include entry behaviors, exit behaviors, and general behaviors. An entry behavior represents the first executable atomic behavior to enter a sequence state. An exit behavior represents the behavior that must be executed to leave a sequence state. A general behavior represents the behavior that can be executed when the aviation control system is in a sequence state.
[0132] S5. Build the conversion relationship model between sequence states: For all conversion relationships between all sequence states, that is, the broken line segments, build a conversion relationship model. The conversion relationship model describes the triggers, guards, and intersections of the conversions between different sequence states.
[0133] A trigger represents an event that causes a conversion between sequence states. A guard represents a Boolean type expression. When the Boolean type expression is true, the guard allows passage, and only then can a conversion between sequence states occur. An intersection represents the activities, interactions, and other sequence states existing in the aviation control system.
[0134] S6. Build the behavior model of the aviation control system: Based on the state diagram of the aviation control system, the internal behavior model of the sequence state, and the conversion relationship model between sequence states, use the SysML state diagram modeling tool to build the behavior model of the aviation control system.
[0135] S7. Export the state machine file described in xml language: Use the SysML state diagram modeling tool to export the behavior model of the aviation control system into a state machine file described in xml language.
[0136] S8. Conduct the verification of the state machine: Import the state machine file exported in step S7 into the computer program for CSharp language experiments to conduct the verification of the state machine.
[0137] S81. Create a model validator and initialize it.
[0138] S811. Parse the xml model file through the System.Xml library, obtain the document object, and assign it to the document property of the model validator.
[0139] S812. Create a factory object and set the plug-in object associated with the factory object, and assign the factory object to the factory property of the model validator.
[0140] S813. Use the document object to obtain the root element scxml of the xml document and the corresponding namespace. If the root element scxml does not exist, the entire verification process stops immediately and returns an error of "The root element scxml cannot be found"; otherwise, assign the obtained root element scxml and the corresponding namespace to the scxml and ns properties of the model validator respectively.
[0141] S814. Obtain the script child element of the root element and verify whether the script child element has an src attribute. If not, add the error message "The script child element lacks the src attribute" to the temporary list returned and record it; otherwise, execute step S82.
[0142] S82. Create a temporary variable and assign a value.
[0143] S821. Perform the assignment of the scm variable, factory variable, dm variable, and ns variable. The scm variable is assigned the value of the scxml attribute of the model validator, representing the root node of the entire model; the factory variable is assigned the value of the factory attribute of the model validator, representing the factory object; the dm variable is assigned the value of the factory attribute of the model validator; the ns variable is assigned the value of the ns attribute of the model validator, representing the xml namespace.
[0144] S822. Create the first dictionary nodeMap: Starting from the root element scxml, use the breadth-first traversal algorithm of the graph to recursively traverse the state machine elements, and store the label names of the traversed state machine elements and the corresponding state machine element objects themselves in the form of key-value pairs.
[0145] S823. Create a stack: Push the scm element onto the stack, execute the reachability algorithm, and return the list of all state machine element objects that can be reached from the root element, denoted as reachable. The parameter of the reachability algorithm is the scm parameter.
[0146] S8231. Create a temporary variable list reachable to store the reachable elements, which is the final return value of the algorithm.
[0147] S8232. Create the first stack object newNodes to store the newly added nodes in the previous traversal process, create the second stack object associateNodes to store the newly added nodes associated with the new nodes, and add the scm parameter to the first stack object newNodes.
[0148] S8233. Traverse the first stack object newNodes, obtain the initial nodes that each element in the first stack object newNodes can reach, and add the initial nodes to the second stack object associateNodes.
[0149] S8234. Traverse the first stack object newNodes, obtain the transition child nodes under each element in the first stack object newNodes, and add all the target child nodes associated with the transition child nodes to the second stack object associateNodes.
[0150] S8235. Traverse the first stack object newNodes. If the node is a composite state or a parallel state, obtain all the ancestor state nodes of the node and add them to the second stack object associateNodes.
[0151] S8236. Add all the elements in the second stack object associateNodes to the temporary variable list reachble.
[0152] S8237. Move all the elements in the second stack object associateNodes to the first stack object newNodes.
[0153] S8238. Clear the second stack object associateNodes.
[0154] S8239. Repeat steps S8233 to S8238 until the first stack object newNodes is empty.
[0155] S824. Execute the assignment statements in batch: Assign the variables in the first variable set to the objects at the corresponding positions in the first object set in sequence; The first variable set includes variables states, parallels, transitions, initials, finals, onEntries, onExits, histories, raises, ifs, elseifs, elses, foreachs, logs, dataModels, datas, assigns, doneDatas, contents, params, scripts, sends, cancels, invokes, and finalizes. The first object set includes the state object, parallel object, transition object, initial object, final object, onentry object, onexit object, history object, raise object, if object, elseif object, else object, foreach object, log object, dataModel object, data object, assign object, donedata object, content object, param object, script object, send object, cancel object, invoke object, and finalize object obtained from the first dictionary nodeMap.
[0156] S825. Create the first list allStates: Add all elements in the second variable set included in the first variable set to the first list allStates. The first list allStates contains all state elements in the state machine model. The second variable set includes the variables states, parallels, histories, and finals.
[0157] S826. Create the second list allActions: Add all elements in the third variable set included in the first variable set to the second list allActions. The second list allActions contains all executable elements in the state machine model. The third variable set includes the variables raises, ifs, elseIfs, elses, foreachs, logs, sends, assigns, scripts, and cancels.
[0158] S827. Create the third list allElements: Add the root element scxml, the first list allStates, the second list allActions, and all elements in the fourth variable set included in the first variable set to the third list allElements. The third list allElements contains all elements of the state machine model. The fourth variable set includes the variables transitions, initials, onEntries, onExits, dataModes, datas, doneDatas, contents, params, invokes, and finalizes.
[0159] S828. Create the set execSet: Add the second object set to the set execSet. The second object set includes if objects, elseif objects, else objects, foreach objects, raise objects, send objects, cancel objects, assign objects, script objects, and log objects.
[0160] S829. Create and initialize the second dictionary seenState.
[0161] S83. According to the SCXML standard, create an element attribute mapping dictionary, an element child node mapping dictionary, and an element parent node mapping dictionary, and perform legality checks on the attributes, child nodes, and parent nodes of the state machine elements respectively.
[0162] The state machine elements include scxml elements, raise elements, if elements, elseif elements, foreach elements, data elements, assign elements, param elements, state elements, parallel elements, transition elements, onentry elements, onexit elements, finalize elements, else elements, initial elements, history elements, final elements, datamodel elements, donedata elements, send elements, and invoke elements; the element attribute mapping dictionary stores the attribute nodes that the state machine elements must define. The attribute node that the raise element must define is the even node. The attribute nodes that the if element and the elseif element must define are the cond nodes. The attribute nodes that the foreach element must define include the array node and the item node. The attribute node that the data element must define is the id node. The attribute node that the assign element must define is the location node. The attribute node that the param element must define is the name node; the element child node mapping dictionary stores the legal child nodes defined by the state machine elements. The child nodes defined by the scxml element include the state child node, the parallel child node, the final child node, the datamodel child node, and the script child node; the child nodes defined by the state element and the parallel element both include the onentry child node, the onexit child node, the transition child node, the state child node, the parallel child node, the history child node, the datamodel child node, and the invoke child node. The child nodes defined by the state element also include the initial child node and the final child node; the child nodes defined by the transition element, the onentry element, the onexit element, the finalize element, the if element, the elseif element, the else element, and the foreach element all include all the child nodes in the execSet collection; the child nodes defined by the initial element and the history element are the transition child nodes; the child nodes defined by the final element include the entry child node, the onexit child node, and the donedata child node; the child node defined by the datamodel element is the data child node; the child nodes defined by the donedata element, the send element, and the invoke element all include the content child node and the param child node. The child nodes defined by the invoke element also include the finalize child node; the element parent node mapping dictionary is obtained by performing an inverse transformation based on the element child node mapping dictionary and stores the legal parent nodes defined by the state machine elements.
[0163] S84. According to the SCXML standard, verify the nodes of the state types, the transition nodes of the state nodes, and the history pseudo-states in the state machine respectively.
[0164] S841. Verify the nodes of the state types in the state machine.
[0165] S8411. Traverse the variable states in step S825 in a loop, assuming that the currently traversed state machine element is a state element.
[0166] S8412. Obtain the id attribute of the state element. If the id is empty, generate the first error message. Obtain the label name of the state element, and determine whether the state element is a history element. If so, execute steps S8413 to S8418.
[0167] S8413. Obtain all the transition child nodes under the history element. If the number of transition nodes is greater than 1 or equal to 0, generate the second error message. Otherwise, execute step S8414.
[0168] S8414. Traverse all the transition child nodes under the history element in a loop, and determine whether the child node has a cond attribute or an event attribute. If it exists, generate the third error message. Otherwise, determine whether the child node has a target attribute. If it does not exist, generate the fourth error message. Otherwise, execute step S8415.
[0169] S8415. Obtain the transition child nodes of the state element, and determine whether the transition child nodes have a cond attribute, an event attribute, and a target attribute. If the cond attribute and the event attribute exist, generate the fifth error message. If the target attribute does not exist, generate the sixth error message. Otherwise, execute step S8416.
[0170] S8416. Obtain the target child nodes associated with the transition child nodes, and traverse the target child nodes in a loop. If the type of the current target child node is deep and it is not a child node of the state element, generate the seventh error message. Otherwise, if the parent node of the target child node is not equal to the parent node of the state element, generate the eighth error message.
[0171] S8417. Determine whether the state element exists in the reachable returned in step S823. If it does not exist, generate the ninth error message.
[0172] S8418. Determine whether it exists in the second dictionary seenState in step S829 according to the id attribute of the state element. If it exists, generate the tenth error message.
[0173] S842. Verify the transition nodes of the state element in the state machine to determine whether there are redundant transitions.
[0174] S8421. Loop through S825 to create the first list allStates, and execute steps S8422 to S8424 for each element in the first list allStates.
[0175] S8422. Obtain the transition child nodes of the current state element, denoted as the transitions list.
[0176] S8423. Loop through the transitions list. Assume that the current traversed migration element is the i-th one, denoted as the itrans element.
[0177] S8424. Search the transition list in sequence by subscripts 0 to (i - 1). If it is found that the cond attribute and event attribute of a certain migration element do not exist, generate the eleventh error message; if it is found that the cond attribute of a certain migration element does not exist and the event attribute exists, denote it as the earlier element, and compare the event attribute value of the earlier element with the list elements of the event attribute of the itrans element in sequence. If the former includes the latter, generate the twelfth error message.
[0178] S843. Verify the history pseudo-states in the state machine to determine whether there are useless history pseudo-states.
[0179] S8431. Loop through the variable histories in step S824, denoted as the history element.
[0180] S8432. Obtain the parent node of the history element. If the parent node is an atomic state, generate the thirteenth error message.
[0181] S8433. Obtain the set of state child nodes, parallel child nodes, and final child nodes of the parent node. If they do not exist, it means that only the history child node exists under the parent node, and generate the fourteenth error message.
[0182] S85. According to the SCXML standard, verify the initial node attributes, the target attribute values of nodes, the transition attribute values of the initial node, the invoke node values, the type attribute values of the send element, and the custom executable content in the state machine respectively.
[0183] S851. According to the SCXML standard, verify the initial node attributes in the state machine.
[0184] S8511. Traverse the first list allStates in step S825 in a loop. Assume the current element is a state element. If the state element has an initial attribute, execute step S8512.
[0185] S8512. Create a fourth list childs, and add the state elements, parallel elements, final elements, and history elements under the state element to the fourth list childs.
[0186] S8513. Obtain the list of initial attribute values of the state element. Traverse the elements in the list of initial attribute values in a loop and obtain the corresponding state nodes from the second dictionary seenState in step S829. If the state does not exist, generate the fifteenth error message; if the state exists, obtain the corresponding state node from the second dictionary seenState, and determine whether the state node is in the fourth list childs. If it does not exist, generate the sixteenth error message.
[0187] S852. According to the SCXML standard, verify the target attribute values of the nodes in the state machine: Create a third dictionary targetIdMap, and traverse the variables transitions, initials in step S824, and the first list allStates in step S824 in sequence to obtain.
[0188] S853. According to the SCXML standard, verify the transition attribute values of the initial node in the state machine.
[0189] S8531. Traverse the list of initials variables in step S824 in a loop. Assume the currently traversed element is an initial element. Obtain the list of transition child nodes of the initial element, and determine that the length of the list is not equal to 1, then generate the seventeenth error message, otherwise execute step S8532;
[0190] S8532. Determine whether the initial element transition child node has a cond attribute or an event attribute. If it exists, generate the eighteenth error message.
[0191] S8533. Determine whether the grandparent node of the migrated child node of the initial element exists. If it exists, obtain the child nodes of the grandparent node of the types state, parallel, final, and history, and store them in the fifth list tmplist.
[0192] S8534. Obtain the value of the target attribute of the migrated child node of the initial element, and sequentially determine whether the target states corresponding to the attribute values exist in the fifth list tmplist. If not, generate the nineteenth error message.
[0193] S854. According to the SCXML standard, verify the value of the invoke node in the state machine: Loop through the invokes list of the variable in step S824. Assume that the currently traversed element is an invoke element, obtain the value of the type attribute of the invoke element. If the value of the type attribute exists, obtain the factory object in step S812 and determine whether it is in its registered plugin list. If the object corresponding to the value of the type attribute cannot be found in the plugin list, obtain the idlocation attribute of the invoke element. If the value of the idlocation attribute exists, generate the twentieth error message; if the value of the idlocation attribute does not exist, generate the twenty - first error message.
[0194] S855. According to the SCXML standard, verify the value of the type attribute of the send element in the state machine: Loop through the sends list of the variable in step S824. Assume that the currently traversed element is a send element, obtain the value of the type attribute of the send element. If the attribute value exists, obtain the factory object in step S812 and determine whether it is in its registered IOProcessor plugin list. If the object corresponding to the value of the type attribute cannot be found in the plugin list, generate the twenty - second error message.
[0195] S856. According to the SCXML standard, verify the custom executable content in the state machine: Create the sixth list executecontents, and insert the contents of the variables onEntries, onExits, transitions, and finalizes in step S824. Loop through the sixth list executecontents. Assume that the currently accessed element is an ec element, obtain all the child nodes of the ec element, determine whether the ec element is in the second list allActions. If it exists, determine whether the child nodes are in the plugins of the factory object in step S812. If not, generate the twenty - third error message.
[0196] S86. Verify the element attributes, parent node validity, and constraint validity in the state machine according to the SCXML standard.
[0197] S861. Verify the attributes of the elements and the parent node validity in the state machine according to the SCXML standard: Traverse the third list in step S827 in a loop. Assume that the currently traversed element is the element element. According to the value of the name attribute of the element element, obtain the list of attributes that the element element must define from the element attribute mapping dictionary in step S83. Then, sequentially determine whether the attributes in the attribute list exist in the name attribute of the element element. If not, generate the twenty-fourth error message. According to the value of the name attribute of the element element, obtain its legal parent node list from the element parent node mapping dictionary in step S83, and determine whether the parent node of the element exists in the element parent node mapping dictionary. If not, generate the twenty-fifth error message.
[0198] S862. Verify the constraint validity of the attributes of the elements in the state machine according to the SCXML standard.
[0199] S8621. Traverse the initials list of variables in step S824 in a loop. Assume that the currently traversed element is the initial element. Obtain the parent node of the initial element and determine whether the parent node has the initial attribute. If so, generate the twenty-sixth error message. Determine whether the initial parent node is an atomic state. If so, generate the twenty-seventh error message.
[0200] S8622. Traverse the states list of variables in step S824 in a loop. Assume that the currently traversed element is the state element. Determine whether the state element is an atomic state. If so, generate the twenty-eighth error message.
[0201] S8623. Traverse the assigns list and the contents list of variables in step S824 in a loop. Assume that the currently traversed element is the e element. If the e element has both the expr attribute and child nodes at the same time, generate the twenty-ninth error message.
[0202] S8624. Traverse the params list of variables in step S824 in a loop. Assume that the currently traversed element is the param element. If the param element has both the expr attribute and the location attribute at the same time, generate the thirtieth error message.
[0203] S8625. Traverse the sends list of variables in step S824 in a loop. Assume that the currently traversed element is the send element, and execute step S8629.
[0204] S8626. Traverse the cancels list of the variable in step S824 in a loop. Assume that the current traversed element is a cancel element. If the cancel element has a sendid attribute and a sendidexpr attribute, then generate the thirty - first error message.
[0205] S8627. Traverse the invokes list of the variable in step S824 in a loop. Assume that the current traversed element is an invoke element, and execute step S86210.
[0206] S8628. Traverse the doneDatas list of the variable in step S824 in a loop. Assume that the current traversed element is a doneData element. If the doneData element has a param attribute and a content child node, then generate the thirty - second error message.
[0207] S8629. If there are an event attribute and an eventexpr attribute, then generate the thirty - third error message; if there are a target attribute and a targetexpr attribute, then generate the thirty - fourth error message; if there are a type attribute and a typeexpr attribute, then generate the thirty - fifth error message; if there are an id attribute and an idlocation attribute, then generate the thirty - sixth error message; if there are a delay attribute and a delayexpr attribute, then generate the thirty - seventh error message; if there are a delay attribute and a target attribute and the value of the target attribute is internal, then generate the thirty - eighth error message; if there is a content child node and a namelist attribute or a param attribute, then generate the thirty - ninth error message.
[0208] S86210. If there are a type attribute and a typeexpr attribute, generate the fortieth error message; if there are an id attribute and an idlocation attribute, generate the forty - first error message; if there are a type attribute and a typeexpr attribute, generate the forty - second error message; if there are a namelist attribute and a param child node, generate the forty - third error message; if there are a src attribute and a content child node, generate the forty - fourth error message.
[0209] S87. Initialize the attributes according to step S81, and verify the syntax of the script content and the element expression syntax in the state machine;
[0210] S88. Return the error list as the state machine verification result and output the verification of the syntax of the script content and the element expression syntax in the state machine.
[0211] S871. Check the syntax of the script content in the state machine: Traverse the variable scripts list in step S824 in a loop, and use the script plugin object registered by the factory object in step S812 to determine the correctness of the script element syntax. If the verification fails, generate the forty-fifth error message.
[0212] S872. Check the expression syntax of the elements in the state machine.
[0213] S8721. Traverse the variable transitions, variable ifs, and variable elseifs lists used to store the content of step S824 in a loop. Assume the currently traversed element is the e element, obtain the cond attribute of the e element, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-sixth error message.
[0214] S8722. Create the seventh list exprs to store the variables logs, variables datas, variables assigns, variables contents, and variables params in step S824. Traverse the seventh list exprs in a loop. Assume the currently traversed element is the expression element, obtain the expr attribute of the expression element, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-seventh error message.
[0215] S8723. Traverse the variable foreachs list used to store the content of step S824 in a loop. Assume the currently traversed element is the foreach object, obtain the values of array / index / index of the foreach object, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-eighth error message.
[0216] S8724. Traverse the variable sends list used to store the content of step S824 in a loop. Assume the currently traversed element is the send object, obtain the values of event, target, type, idlocation, and delayexpr of the send object, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-ninth error message.
[0217] S88. Return the error list and display it.
[0218] The first error message is that the [name of state] attribute cannot be empty; the second error message is that the number of nodes that [name of state] can migrate must be exactly one. The third error message is that the migrated nodes of [name of state] cannot have the attributes cond or event. The fourth error message is that the target attribute of the migrated nodes of [name of state] cannot be empty. The fifth error message is that the migrated nodes of the historical pseudo-state [name of state] cannot define the cond and event attributes. The sixth error message is that the target attribute of the migrated nodes of the historical pseudo-state [name of state] cannot be empty. The seventh error message is that the target of the migrated nodes of the historical pseudo-state [name of state] of the deep type is illegal. The eighth error message is that the target of the migrated nodes of the historical pseudo-state [name of state] of the shallow type is illegal. The ninth error message is that [name of state] is unreachable. The tenth error message is that [name of state] is defined repeatedly. The eleventh error message is that [name of state] has an unconditional migration. The twelfth error message is that [name of state] has migrations with the same event condition. The thirteenth error message is that the atomic state [name of the parent node] contains useless history nodes. The fourteenth error message is that [name of the parent node] contains useless history nodes. The fifteenth error message is that the state corresponding to the initial attribute value of [state name] does not exist. The sixteenth error message is that the state corresponding to the initial attribute value of [state name] is illegal. The seventeenth error message is that the migration path of [initial node] must have only one. The eighteenth error message is that the migration path of [initial node] cannot have the cond and event attributes. The nineteenth error message is that the target attribute of the migration path of [initial node] is illegal. The twentieth error message is that the type attribute value of [name of the invoke node] is empty. The twenty-first error message is that the type attribute value of [name of the invoke node] is illegal. The twenty-second error message is that the type attribute value of [name of the send node] is empty. The twenty-third error message is that the executable content of [name of the ec] is unknown. The twenty-fourth error message is that the [name] attribute of [name of the element] must be defined. The twenty-fifth error message is that the parent node of [name of the element] is illegal. The twenty-sixth error message is that [name of the parent node of initial] has both the initial attribute and the initial child node at the same time. The twenty-seventh error message is that [name of the parent node of initial] is an atomic state and cannot have an initial child node. The twenty-eighth error message is that [state name] is an atomic state and cannot have an initial child node.The twenty-ninth error message is that [name of e] cannot have both the expr attribute and child nodes. The thirtieth error message is that [name of param] cannot have both the expr and location attributes. The thirty-first error message is that [name of send] cannot have both the sendid and sendidexpr attributes. The thirty-second error message is that [name of donedata] cannot have both the paparamran attribute and the content child node attribute. The thirty-third error message is that [name of send] cannot have both the event and eventexpr attributes. The thirty-fourth error message is that [name of send] cannot have both the target and targetexpr attributes. The thirty-fifth error message is that [name of send] cannot have both the type and typeexpr attributes. The thirty-sixth error message is that [name of send] cannot have both the id and idlocation attributes. The thirty-seventh error message is that [name of send] cannot have both the delay and delayexpr attributes. The thirty-eighth error message is that [name of send] cannot have both the delay and the target attribute with a value of interval. The thirty-ninth error message is that [name of send] cannot have both the namelist or param attribute and the content child node. The fortieth error message is that [name of invoke] cannot have both the type and typeexpr attributes. The forty-first error message is that [name of invoke] cannot have both the id and idlocation attributes. The forty-second error message is that [name of invoke] cannot have both the type and typeexpr attributes. The forty-third error message is that [name of invoke] cannot have both the namelist attribute and the param child node attribute. The forty-fourth error message is that [name of invoke] cannot have both the src attribute and the content child node attribute. The forty-fifth error message is that there is a syntax error in the scripts. The forty-sixth error message is that there is a syntax error in the cond script of [name of e]. The forty-seventh error message is that there is a syntax error in the script of the expr attribute value of [name of e]. The forty-eighth error message is that there is a syntax error in the foreach attribute value array / index / index of [name of e]. The forty-ninth error message is that there is a syntax error in the attribute values event / target / type / idlocation / delayexpr of [name of send]; The generated first to forty-ninth error messages are all added to the error list in step S88.
[0219] Another aspect of the present invention further provides a verification system for the above-mentioned verification method of the SysML state diagram model of the aviation control system, as Figure 2 shown, which includes a context environment state set identification module 1, a state diagram construction module 2, a sequential state internal behavior model construction module 3, a conversion relationship model construction module 4 between sequential states, an aviation control system behavior model construction module 5, a state machine file generation module 6, and a state machine verification module 7 that are communicatively connected to each other.
[0220] The context environment identification module 1 is used to determine the context environment in which the aviation control system operates and identify the state set existing in the aviation control system in the context environment.
[0221] The state diagram construction module 2 is used to construct the aviation control system state diagram.
[0222] The sequential state internal behavior model construction module 3 is used to construct the sequential state internal behavior model.
[0223] The conversion relationship model construction module 4 between sequential states is used to construct the conversion relationship model between the sequential states.
[0224] The aviation control behavior model construction module 5 is used to construct the aviation control behavior model.
[0225] The state machine file generation module 6 is used to export the aviation control system behavior model into a state machine file described in xml language by using the SysML state diagram modeling tool.
[0226] The state machine verification module 7 is used to import the exported state machine file into a computer program tested in the CSharp language to perform the verification of the state machine.
[0227] The following will further elaborate on the present invention in conjunction with a satellite altitude control subsystem.
[0228] S1. Define the context environment of the satellite altitude control subsystem. The satellite altitude control subsystem is a subsystem in a satellite orbiting the Earth, mainly used to control the altitude of the satellite orbiting the Earth.
[0229] S2. Identify the list of states existing in the satellite altitude control subsystem and define the states. The satellite altitude control subsystem includes states such as Orbit-Insertion, Acquisition, Slew, Safe, etc., where the simple state 2 is an isolated state specifically added.
[0230] S3. Define the transitions between various states, mainly including the transitions from Orbit-Insertion -> Acquisition, Acquisition -> Slew, Slew -> On-Station, etc.
[0231] S4. Define each state in detail, including the entry actions, actions within the state, and exit actions of the state. For example, the Acquisition state defines the entry behavior onentry as an opaque expression, and the Safe-Mode state defines the action TrackSun within the state.
[0232] S5. Describe in detail the transition nodes between various states, including the events that trigger the transitions, the conditions for the transitions, and the actions corresponding to the transitions. For example, the Acquisition state includes two transition paths. When a > 100, it transitions to the On-Station state, and when a <= 100, it transitions to the Slew state.
[0233] S6. Use a SysML modeling tool or directly write the XML file corresponding to the state machine model through an XML editor to complete the state machine modeling of the satellite altitude control subsystem. The result is as Figure 3 shown.
[0234] S7. Export the state machine model of the satellite altitude control subsystem into the corresponding XML file, the content of which is as Figure 4 shown.
[0235] S8. Input the XML file of the state machine model of the satellite altitude control subsystem into the model validator for model verification. The verification result is as Figure 5 shown.
[0236] A method for validating the SysML state diagram model of an aviation control system designed by the present invention. The proposed method is based on the SCXML standard of the w3c consortium, supports complex elements such as sub-states, parallel states, concurrency, and synchronization, can be used to represent all information of the SysML state diagram architecture, and at the same time supports simple states, composite states, and parallel states, and can perform model standard compliance verification for complex states; compared with the traditional method for validating the UML state machine model, the proposed method avoids the conversion from the UML state machine to a complex intermediate language. By directly exporting the model as a model file described in XML language, the mature DOM technology is used to parse the XML model and complete the model standard compliance verification, which reduces the difficulty of model verification implementation and improves the model verification efficiency; by performing validity verification on the model before model simulation and use and giving visual prompts, it is convenient to discover and troubleshoot hidden errors in the model, avoid repeated modification of the model, reduce the test cycle, and greatly improve the modeling efficiency; at the same time, ensure that the constructed SysML state diagram complies with relevant standards, and the constructed model can be directly used for simulation calculation, avoiding repeated modeling multiple times.
[0237] Finally, it should be noted that the above embodiments are only used to illustrate rather than limit the technical solutions of the present invention. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the present invention can still be modified or equivalently replaced, and any modification or partial replacement without departing from the spirit and scope of the present invention shall be covered by the scope of the claims of the present invention.
Claims
1. A method for validating a SysML state diagram model of an aviation control system, characterized in that, It includes the following steps: S1. Determine the context environment in which the aviation control system operates: Determine the first environment upstream of the aviation control system and the second environment downstream of the aviation control system; S2. Identify the set of states existing in the context environment of the aviation control system: Identify the list of states including all sequential states of the aviation control system in the first environment and mark the corresponding initial state and end state, and identify the list of states including all sequential states of the aviation control system in the second environment and mark the corresponding initial state and end state; S3. Construct the state diagram of the aviation control system: According to the control system behavior, establish all preset transitions between the states in the state set, and construct the state diagram of the aviation control system. The transitions between the states in the aviation control system state diagram are connected by broken lines with arrows, and the broken lines represent the transition relationships between the states in the state set; S4. Construct the internal behavior model of the sequential state: For the aviation control system state diagram, construct the internal behavior model for the internal behavior of all the sequential states. The internal behavior model describes the internal attributes of the states represented by the sequential states; S5. Construct the transition relationship model between sequential states: For all the transition relationships between sequential states, that is, the broken lines, construct the transition relationship model. The transition relationship model describes the triggers, guards, and intersections of the transitions between different sequential states; S6. Construct the behavior model of the aviation control system: Based on the aviation control system state diagram, the internal behavior model of the sequential state, and the transition relationship model between sequential states, use the SysML state diagram modeling tool to construct the behavior model of the aviation control system; S7. Export the state machine file described in xml language: Use the SysML state diagram modeling tool to export the behavior model of the aviation control system into a state machine file described in xml language; S8. Perform the verification of the state machine: Import the state machine file exported in step S7 into the computer program for CSharp language experiment to perform the verification of the state machine; S81. Create a model validator and initialize it; S82. Create a temporary variable and assign a value; S83. According to the SCXML standard, create a dictionary for mapping element attributes, a dictionary for mapping element child nodes, and a dictionary for mapping element parent nodes, and perform the legality verification of the attributes, child nodes, and parent nodes of the state machine elements respectively; S84. According to the SCXML standard, perform the verification of the nodes of the state type, the transition nodes of the state node, and the history pseudo-states in the state machine respectively; S85. According to the SCXML standard, perform the verification of the attributes of the initial node, the target attribute value of the node, the transition attribute value of the initial node, the invoke node value, the type attribute value of the send element, and the custom executable content in the state machine respectively; S86. According to the SCXML standard, perform the verification of the element attributes, the validity of the parent node, and the validity of the constraints in the state machine; S87. According to the attributes initialized in step S81, perform the verification of the syntax of the script content and the syntax of the element expressions in the state machine; S88. Return the error list as the state machine verification result and output it.
2. The method for validating the SysML state diagram model of the aviation control system according to claim 1, wherein The specific steps of step S82 include the following steps: S821. Execute the assignment of the scm variable, factory variable, dm variable, and ns variable. The scm variable is assigned the scxml attribute value of the model validator, representing the root node of the entire model; the factory variable is assigned the factory attribute value of the model validator, representing the factory object; the dm variable is assigned the dm attribute value of the model validator; the ns variable is assigned the ns attribute of the model validator, representing the xml namespace. S822. Create the first dictionary nodeMap: Starting from the root element scxml, use the breadth-first traversal algorithm of the graph to recursively traverse the state machine elements, and store the tag names of the traversed state machine elements and the corresponding state machine element objects themselves in the form of key-value pairs. S823. Create a stack: Push the scm element onto the stack, execute the reachability algorithm, and return the list of all state machine element objects reachable from the root element, denoted as reachable. The parameter of the reachability algorithm is the scm parameter. S824. Batch execute assignment statements: Assign the variables in the first variable set to the objects in the corresponding positions in the first object set in sequence. S825. Create the first list allStates: Add all elements in the second variable set included in the first variable set to the first list allStates. The first list allStates contains all state elements in the state machine model. S826. Create the second list allActions: Add all elements in the third variable set included in the first variable set to the second list allActions. The second list allActions contains all runnable elements in the state machine model. S827. Create the third list allElements: Add the root element scxml, the first list allStates, the second list allActions, and all elements in the fourth variable set included in the first variable set to the third list allElements. The third list allElements contains all elements of the state machine model. S828. Create the set execSet: Add the second object set to the set execSet. S829. Create and initialize the second dictionary seenState. The specific steps of step S84 include the following steps: S841. Verify the nodes of the state type in the state machine. S8411. Loop through the variable states in step S825, assuming that the currently traversed state machine element is a state element. S8412. Obtain the id attribute of the state element. If the id is empty, generate the first error message. Obtain the tag name of the state element and determine whether the state element is a history element. If so, execute steps S8413 to S8418. S8413. Obtain all transition child nodes under the history element. If the number of transition nodes is greater than 1 or equal to 0, generate a second error message; otherwise, execute step S8414; S8414. Loop through all transition child nodes under the history element and determine whether the child nodes have a cond attribute or an event attribute. If so, generate a third error message; otherwise, determine whether the child nodes have a target attribute. If not, generate a fourth error message; otherwise, execute step S8415; S8415. Obtain the transition child nodes of the state element and determine whether the transition child nodes have a cond attribute, an event attribute, and a target attribute. If they have a cond attribute and an event attribute, generate a fifth error message; if they do not have a target attribute, generate a sixth error message; otherwise, execute step S8416; S8416. Obtain the target node target child nodes associated with the transition child nodes. Loop through the target child nodes. If the type of the current target child node is deep and it is not a child node of the state element, generate a seventh error message; otherwise, if the parent node of the target child node is not equal to the parent node of the state element, generate an eighth error message; S8417. Determine whether the state element is in the reachable returned in step S823. If not, generate a ninth error message; S8418. According to the id attribute of the state element, determine whether it exists in the second dictionary seenState in step S829. If so, generate a tenth error message; S842. Verify the transition nodes of the state element in the state machine and determine whether there are redundant transitions; S8421. Loop through S825 to create a first list allStates. For each element in the first list allStates, execute steps S8422 to S8424; S8422. Obtain the transition child nodes of the current state element, denoted as the transitions list; S8423. Loop through the transitions list. Assume that the current traversed migration element is the i-th, denoted as the itrans element; S8424. Search the transition list in sequence by subscripts 0 to (i - 1). If it is found that the cond attribute and the event attribute of a certain migration element do not exist, generate an eleventh error message; if it is found that the cond attribute of a certain migration element does not exist and the event attribute exists, denote it as the earlier element, and compare the event attribute value of the earlier element with the list elements of the event attribute of the itrans element in sequence. If the former includes the latter, generate a twelfth error message; S843. Verify the history pseudo-states in the state machine to determine if there are any useless history pseudo-states; S8431. Traverse the variable histories in step S824 in a loop, denoted as history elements; S8432. Obtain the parent node of the history element. If the parent node is an atomic state, generate the thirteenth error message; S8433. Obtain the state child node, parallel child node, and final child node sets of the parent node. If they do not exist, it means that only the history child node exists under the parent node, and generate the fourteenth error message; The specific steps of step S85 are as follows: S851. Verify the initial node attributes in the state machine according to the SCXML standard; S8511. Traverse the first list allStates in step S825 in a loop. Assume that the current element is a state element. If the state element has an initial attribute, execute step S8512; S8512. Create a fourth list childs and add the state elements, parallel elements, final elements, and history elements under the state element to the fourth list childs; S8513. Obtain the list of values of the initial attribute of the state element. Traverse the elements in the list of values of the initial attribute and obtain the corresponding state node from the second dictionary seenState in step S829. If the state does not exist, generate the fifteenth error message; if the state exists, obtain the corresponding state node from the second dictionary seenState and determine whether the state node is in the fourth list childs. If it does not exist, generate the sixteenth error message; S852. Verify the target attribute values of the nodes in the state machine according to the SCXML standard: Create a third dictionary targetIdMap and traverse the variables transitions, initials in step S824, and the first list allStates in step S824 in sequence to obtain; S853. Verify the transition attribute values of the initial nodes in the state machine according to the SCXML standard; S8531. Traverse the initials list in step S824 in a loop. Assume that the currently traversed element is an initial element. Obtain the list of transition child nodes of the initial element and determine that the length of the list is not equal to 1, then generate the seventeenth error message. Otherwise, execute step S8532; S8532. Determine whether the transition child node of the initial element has a cond attribute or an event attribute. If it exists, generate the eighteenth error message; S8533. Determine whether the grandfather node of the migrated child node of the initial element exists. If it exists, obtain the child nodes of the types state, parallel, final, and history under the grandfather node, and store them in the fifth list tmplist; S8534. Obtain the value of the target attribute of the migrated child node of the initial element, and sequentially determine whether the target state corresponding to the attribute value exists in the fifth list tmplist. If it does not exist, generate the nineteenth error message; S854. According to the SCXML standard, verify the value of the invoke node in the state machine: loop through the invokes list of the variable in step S824. Assume that the currently traversed element is an invoke element, and obtain the value of the type attribute of the invoke element. If the value of the type attribute exists, obtain the factory object in step S812 and determine whether it is in the list of registered plugins. If the object corresponding to the value of the type attribute cannot be found in the plugin list, obtain the idlocation attribute of the invoke element. If the value of the idlocation attribute exists, generate the twentieth error message; if the value of the idlocation attribute does not exist, generate the twenty-first error message; S855. According to the SCXML standard, verify the value of the type attribute of the send element in the state machine: loop through the sends list of the variable in step S824. Assume that the currently traversed element is a send element, and obtain the value of the type attribute of the send element. If the attribute value exists, obtain the factory object in step S812 and determine whether it is in the list of registered IOProcessor plugins. If the object corresponding to the value of the type attribute cannot be found in the plugin list, generate the twenty-second error message; S856. According to the SCXML standard, verify the custom executable content in the state machine: create the sixth list executecontents, and insert the contents of the variables onEntries, onExits, transitions, and finalizes of step S824. Loop through the sixth list executecontents. Assume that the currently accessed element is an ec element, obtain all the child nodes under the ec element, and determine whether the ec element is in the second list allActions. If it exists, determine whether the child nodes are in the plugins of the factory object in step S812. If not, generate the twenty-third error message; The step S86 specifically includes the following steps: S861. According to the SCXML standard, verify the attributes of the elements in the state machine and the validity of the parent nodes: Traverse the third list in step S827 in a loop. Assume that the currently traversed element is the element element. According to the value of the name attribute of the element element, obtain the list of attributes that the element element must define from the element attribute mapping dictionary in step S83, and sequentially determine whether the attributes in the attribute list exist in the name attribute of the element element. If not, generate the twenty-fourth error message; According to the value of the name attribute of the element element, obtain its legal parent node list from the element parent node mapping dictionary in step S83, and determine whether the parent node of the element exists in the element parent node mapping dictionary. If not, generate the twenty-fifth error message; S862. According to the SCXML standard, verify the constraint validity of the attributes of the elements in the state machine: S8621. Traverse the initials list of variables in step S824 in a loop. Assume that the currently traversed element is the initial element. Obtain the parent node of the initial element and determine whether the parent node has the initial attribute. If so, generate the twenty-sixth error message; Determine whether the initial parent node is an atomic state. If so, generate the twenty-seventh error message; S8622. Traverse the states list of variables in step S824 in a loop. Assume that the currently traversed element is the state element. Determine whether the state element is an atomic state. If so, generate the twenty-eighth error message; S8623. Traverse the assigns list and the contents list of variables in step S824 in a loop. Assume that the currently traversed element is the e element. If the e element has both the expr attribute and child nodes at the same time, generate the twenty-ninth error message; S8624. Traverse the params list of variables in step S824 in a loop. Assume that the currently traversed element is the param element. If the param element has both the expr attribute and the location attribute at the same time, generate the thirtieth error message; S8625. Traverse the sends list of variables in step S824 in a loop. Assume that the currently traversed element is the send element, and execute step S8629; S8626. Traverse the cancels list of variables in step S824 in a loop. Assume that the currently traversed element is the cancel element. If the cancel element has the sendid attribute and the sendidexpr attribute, generate the thirty-first error message; S8627. Traverse the invokes list of variables in step S824 in a loop. Assume that the currently traversed element is the invoke element, and execute step S86210; S8628. Traverse the doneDatas list of variables in step S824 in a loop. Assume that the currently traversed element is the doneData element. If the doneData element has the param attribute and the content child node, generate the thirty-second error message; S8629. If the event attribute and the eventexpr attribute exist, generate the thirty-third error message; if the target attribute and the targetexpr attribute exist, generate the thirty-fourth error message; if the type attribute and the type typeexpr attribute exist, generate the thirty-fifth error message; if the id attribute and the idlocation attribute exist, generate the thirty-sixth error message; if the delay attribute and the delayexpr attribute exist, generate the thirty-seventh error message; if the delay attribute and the target attribute exist and the value of the target attribute is internal, generate the thirty-eighth error message; if the content child node and the namelist attribute or the param attribute exist, generate the thirty-ninth error message; S86210. If the type attribute and the typeexpr attribute exist, generate the fortieth error message; if the id attribute and the idlocation attribute exist, generate the forty-first error message; if the type attribute and the typeexpr attribute exist, generate the forty-second error message; if the namelist attribute and the param child node exist, generate the forty-third error message; if the src attribute and the content child node exist, generate the forty-fourth error message; Step S87 specifically includes the following steps: S871. Check the syntax of the script content in the state machine: Loop through the variable scripts list in step S824, and use the script script plugin object registered by the factory object in step S812 to determine the correctness of the script element syntax. If the verification fails, generate the forty-fifth error message; S872. Check the expression syntax of the elements in the state machine; S8721. Loop through the lists of variables transitions, ifs, and elseifs used to store the variables in step S824. Assume that the currently traversed element is the e element, obtain the cond attribute of the e element, and use the DataModel object in step S824 for verification. If the verification fails, the forty-sixth error message will be generated; S8722. Create a seventh list exprs to store the variables logs, datas, assigns, contents, and params in step S824. Loop through the seventh list exprs. Assume that the currently traversed element is the expression element, obtain the expr attribute of the expression element, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-seventh error message; S8723. Traverse the foreachs list used to store the variables in step S824 in a loop. Assume that the currently traversed element is a foreach object. Obtain the value of array / index / index of the foreach object, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-eighth error message. S8724. Traverse the sends list used to store the variables in step S824 in a loop. Assume that the currently traversed element is a send object. Obtain the values of event, target, type, idlocation, and delayexpr of the send object, and use the DataModel object in step S824 for verification. If the verification fails, generate the forty-ninth error message.
3. The method for validating the SysML state diagram model of the aviation control system according to claim 2, wherein The specific steps of step S823 are as follows: S8231. Create a temporary variable list reachable to store reachable elements as the final return value of the algorithm. S8232. Create a first stack object newNodes to store the newly added nodes in the previous traversal process, create a second stack object associateNodes to store the newly associated nodes of the newly added nodes, and add the scm parameter to the first stack object newNodes. S8233. Traverse the first stack object newNodes, obtain the initial nodes that each element in the first stack object newNodes can reach, and add the initial nodes to the second stack object associateNodes. S8234. Traverse the first stack object newNodes, obtain the transition child nodes under each element in the first stack object newNodes, and add all the target child nodes associated with the transition child nodes to the second stack object associateNodes. S8235. Traverse the first stack object newNodes. If the node is a composite state or a parallel state, obtain all the ancestor state nodes of the node and add them to the second stack object associateNodes. S8236. Add all the elements in the second stack object associateNodes to the temporary variable list reachble. S8237. Move all the elements in the second stack object associateNodes to the first stack object newNodes. S8238. Clear the second stack object associateNodes. S8239. Repeat steps S8233 to S8238 until the first stack object newNodes is empty.
4. The method for validating the SysML state diagram model of the aviation control system according to claim 2, wherein In the step S82, the first variable set includes variables states, parallels, transitions, initials, finals, onEntries, onExits, histories, raises, ifs, elseifs, elses, foreachs, logs, dataModels, datas, assigns, doneDatas, contents, params, scripts, sends, cancels, invokes, and finalizes; the second variable set includes variables states, paralles, histories, and finals; the third variable set includes variables raises, ifs, elseIfs, elses, foreachs, logs, sends, assigns, scripts, and cancels; the fourth variable set includes variables transitions, initials, onEntries, onExits, dataModes, datas, doneDatas, contents, params, invokes, and finalizes; the first object set includes state objects, parallel objects, transition objects, initial objects, final objects, onentry objects, onexit objects, history objects, raise objects, if objects, elseif objects, else objects, foreach objects, log objects, dataModel objects, data objects, assign objects, donedata objects, content objects, param objects, script objects, send objects, cancel objects, invoke objects, and finalize objects obtained from the first dictionary nodeMap; the second object set includes if objects, elseif objects, else objects, foreach objects, raise objects, send objects, cancel objects, assign objects, script objects, and log objects; The state machine elements in step S83 include scxml element, raise element, if element, elseif element, foreach element, data element, assign element, param element, state element, parallel element, transition element, onentry element, onexit element, finalize element, else element, initial element, history element, final element, datamodel element, donedata element, send element and invoke element; the element attribute mapping dictionary stores the attribute nodes that must be defined for the state machine elements. The attribute node that must be defined for the raise element is the even node. The attribute nodes that must be defined for the if element and elseif element are the cond nodes. The attribute nodes that must be defined for the foreach element include the array node and item node. The attribute node that must be defined for the data element is the id node. The attribute node that must be defined for the assign element is the location node. The attribute node that must be defined for the param element is the name node; the element child node mapping dictionary stores the legal child nodes defined by the state machine elements. The child nodes defined by the scxml element include state child node, parallel child node, final child node, datamodel child node and script child node; the child nodes defined by the state element and parallel element both include onentry child node, onexit child node, transition child node, state child node, parallel child node, history child node, datamodel child node and invoke child node. The child nodes defined by the state element also include initial child node and final child node; the child nodes defined by the transition element, onentry element, onexit element, finalize element, if element, elseif element, else element and foreach element all include all the child nodes in the execSet; the child nodes defined by the initial element and history element are the transition child node; the child nodes defined by the final element include entry child node, onexit child node and donedata child node; the child node defined by the datamodel element is the data child node; the child nodes defined by the donedata element, send element and invoke element all include content child node and param child node. The child nodes defined by the invoke element also include finalize child node;The element parent node mapping dictionary is obtained through reverse transformation based on the element child node mapping dictionary, and stores the legal parent nodes defined by the state machine elements.; 5. The method for verifying the SysML state diagram model of the aviation control system according to claim 1, wherein The internal behaviors in step S4 include entry behavior, exit behavior, and general behavior. The entry behavior represents the first executable atomic behavior for entering the sequence state. The exit behavior represents the behavior that must be executed to leave the sequence state. The general behavior represents the behavior that can be executed when the aviation control system is in the sequence state. The trigger in step S5 represents the event that causes the transition between sequence states. The gatekeeper represents a Boolean type expression. When the Boolean type expression is true, the gatekeeper allows passage, and only then can the transition between sequence states occur. The cross represents the activities, interactions, and other sequence states existing in the aviation control system.
6. The method for validating the SysML state diagram model of the aviation control system according to claim 1, characterized in that, Step S81 specifically includes the following steps: S811. Parse the xml model file through the System.Xml library, obtain the document object, and assign it to the document property of the model validator. S812. Create a factory object and set the plug-in object associated with the factory object, and assign the factory object to the factory property of the model validator. S813. Use the document object to obtain the root element scxml of the xml document and the corresponding namespace. If the root element scxml does not exist, the entire verification process stops immediately and returns an error of "The root element scxml cannot be found". Otherwise, assign the obtained root element scxml and the corresponding namespace to the scxml and ns properties of the model validator respectively. S814. Obtain the script subelement of the root element and verify whether the script subelement has an src attribute. If it does not exist, record the error message "The script subelement lacks the src attribute" in the returned temporary list. Otherwise, execute step S82.
7. The method for validating the SysML state diagram model of the aviation control system according to claim 2, wherein The first error message in step S8 is that the attribute of 【name of state】 cannot be empty; the second error message is that the number of migration nodes of 【name of state】 must have and can only have one; the third error message is that the migration node of 【name of state】 cannot have attributes cond or event; the fourth error message is that the target attribute of the migration node of 【name of state】 cannot be empty; the fifth error message is that the migration node of the historical pseudo-state 【name of state】 cannot define cond and event attributes; the sixth error message is that the target attribute of the migration node of the historical pseudo-state 【name of state】 cannot be empty; the seventh error message is that the target of the migration node of the historical pseudo-state 【name of state】 of deep type is illegal; the eighth error message is that the target of the migration node of the historical pseudo-state 【name of state】 of shallow type is illegal; the ninth error message is that 【name of state】 is unreachable; the tenth error message is that 【name of state】 is defined repeatedly; the eleventh error message is that there is an unconditional migration of 【name of state】; the twelfth error message is the migration of 【name of state】 with the same event condition; the thirteenth error message is that the atomic state 【name of the parent node】 contains useless history nodes; the fourteenth error message is that 【name of the parent node】 contains useless history nodes; the fifteenth error message is that the state corresponding to the initial attribute value of 【name of state】 does not exist; the sixteenth error message is that the state corresponding to the initial attribute value of 【name of state】 is illegal; the seventeenth error message is that the migration path of 【initial node】 must have only one; the eighteenth error message is that the migration path of 【initial node】 cannot have cond and event attributes; the nineteenth error message is that the target attribute of the migration path of 【initial node】 is illegal; the twentieth error message is that the type attribute value of 【name of the invoke node】 is empty; the twenty-first error message is that the type attribute value of 【name of the invoke node】 is illegal; the twenty-second error message is that the type attribute value of 【name of the send node】 is empty; the twenty-third error message is that the executable content of 【name of ec】 is unknown; the twenty-fourth error message is that the 【name】 attribute of 【name of element】 must be defined; the twenty-fifth error message is that the parent node of 【name of element】 is illegal; the twenty-sixth error message is that the initial attribute and the initial child node exist simultaneously in 【name of the parent node of initial】; the twenty-seventh error message is that 【name of the parent node of initial】 is an atomic stateThere cannot be an initial child node. The twenty-eighth error message is that [state name] is an atomic state and there cannot be an initial child node. The twenty-ninth error message is that [name of e] cannot have both an expr attribute and child nodes at the same time. The thirtieth error message is that [name of param] cannot have both expr and location attributes at the same time. The thirty-first error message is that [name of send] cannot have both sendid and sendidexpr attributes at the same time. The thirty-second error message is that [name of donedata] cannot have both paparamran attribute and content child node attribute at the same time. The thirty-third error message is that [name of send] cannot have both event and eventexpr attributes at the same time. The thirty-fourth error message is that [name of send] cannot have both target and targetexpr attributes at the same time. The thirty-fifth error message is that [name of send] cannot have both type and typeexpr attributes at the same time. The thirty-sixth error message is that [name of send] cannot have both id and idlocation attributes at the same time. The thirty-seventh error message is that [name of send] cannot have both delay and delayexpr attributes at the same time. The thirty-eighth error message is that [name of send] cannot have both delay and a target attribute with a value of interval at the same time. The thirty-ninth error message is that [name of send] cannot have both a namelist or param attribute and a content child node at the same time. The fortieth error message is that [name of invoke] cannot have both type and typeexpr attributes at the same time. The forty-first error message is that [name of invoke] cannot have both id and idlocation attributes at the same time. The forty-second error message is that [name of invoke] cannot have both type and typeexpr attributes at the same time. The forty-third error message is that [name of invoke] cannot have both a namelist attribute and a param child node attribute at the same time. The forty-fourth error message is that [name of invoke] cannot have both a src attribute and a content child node attribute at the same time. The forty-fifth error message is that there is a syntax error in the scripts. The forty-sixth error message is that there is a syntax error in the cond script of [name of e]. The forty-seventh error message is that there is a syntax error in the script of the expr attribute value of [name of e]. The forty-eighth error message is that there is a syntax error in the foreach attribute value array / index / index of [name of e].The forty-ninth error message is that there is a syntax error in the attribute values event / target / type / idlocation / delayexpr of [the name of send]; all the first to forty-ninth error messages generated are added to the error list in step S88.
8. The method for verifying the SysML state diagram model of the aviation control system according to claim 1, wherein In step S2, the initial state is represented by a small black circle, the end state is represented by a hollow circle with a solid circle, and the sequence states other than the initial state and the end state in the state list are represented by rounded rectangles. All states in the state list must contain at least one name division box to display the state name.
9. The method for verifying the SysML state diagram model of the aviation control system according to claim 1, wherein In step S1, there are several of the first environment and the second environment. In step S2, in the first environment and the second environment where the aviation control system is located, there may not necessarily be a definite initial state and end state.
10. A verification system for the verification method of the SysML state diagram model of the aviation control system according to any one of claims 1-9, characterized in that, It includes a context environment state set recognition module, a state diagram construction module, a sequence state internal behavior model construction module, a sequence state transition relationship model construction module, an aviation control system behavior model construction module, a state machine file generation module, and a state machine verification module that are interconnected and communicate with each other; The context environment recognition module is used to determine the context environment in which the aviation control system operates and identify the state set existing in the aviation control system in the context environment. The state diagram construction module is used to construct the aviation control system state diagram. The sequence state internal behavior model construction module is used to construct the sequence state internal behavior model. The sequence state transition relationship model construction module is used to construct the transition relationship model between the sequence states. The aviation control behavior model construction module is used to construct an aviation control behavior model; The state machine file generation module is used to export the aviation control system behavior model into a state machine file described in xml language by using the SysML state diagram modeling tool; The state machine verification module is used to import the exported state machine file into a computer program for CSharp language experiments to perform verification of the state machine.
Citation Information
Patent Citations
Method and system for visually displaying simulation execution
CN114090185A
Embedded software security analysis method and system based on SysML
CN114238084A