A method for formal design and verification of dual-system communication

The formal design and verification method for dual-system communication, which utilizes virtual machine construction and web crawler monitoring, solves the problems of state explosion and high cost in existing technologies, and achieves high-precision and reliable verification of control command transmission and stability of inter-system communication.

CN116633787BActive Publication Date: 2025-12-05SHENYANG QIANCHUAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310785720.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-29
Publication Date
2025-12-05
Estimated Expiration
2043-06-29

AI Technical Summary

Technical Problem

Existing formal verification methods for verifying network communication systems suffer from the problem of state explosion due to their low level of abstraction. Furthermore, the tools are complex to use, requiring a large amount of mathematical theoretical knowledge and manpower, resulting in high verification costs.

Method used

A dual-system communication formal design and verification method is adopted. Through virtual machine construction and web crawler monitoring, network security is monitored, security verification operations are performed, virtual machine models are built, communication interfaces are optimized, and formal design and data consistency analysis are carried out to ensure the timeliness and reliability of control command transmission.

Benefits of technology

It achieves high-precision and reliable control command transmission verification, reduces verification complexity, improves verification efficiency, can quickly output digital results, and ensures the stability and security of inter-system communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116633787B_ABST
    Figure CN116633787B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of information processing, in particular to a kind of double system communication formalization design and verification method, comprising the following steps: step 1: receiving the control instruction of real-time transmission between double systems and monitoring whether the connection application network between double systems is safe;Step 2: the connection application network safety monitoring result between double systems in step 1 is no, disconnect the double system network connection, the monitoring result is yes, the operation of safety verification is executed to the control instruction received in step 1;The present application mainly uses the way of virtual mechanism to bring the verification effect for the control instruction transmitted between systems, based on the setting of such virtual machine, the immediacy of control instruction transmission process verification is satisfied, so that the verification effect brought by control instruction is more reliable and high precision, in the control instruction transmission stage between systems, transmission environment can also be monitored safely, effectively avoid the influence of unstable factors when control instruction is transmitted to system end in network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information processing technology, and specifically to a formal design and verification method for dual-system communication. Background Technology

[0002] With the emergence of mobile internet, IoT, Industry 4.0, BYOD (Bring Your Own Device), and connected vehicles, the security of core systems supporting these applications has received increasing attention. Technologies and methods, such as secure operating systems, trusted execution environments, and trusted virtualization, along with their system architectures, have been designed and implemented by researchers. IPC (Internal Process Communication) systems, as crucial components of core systems like operating systems and hypervisors, are responsible for information communication between processes, virtual machines, and different environments. Their functional correctness, security, and reliability play a decisive role in the overall system security. However, due to human involvement, various errors inevitably arise within these systems. To address and uncover these hidden bugs, developers have employed various methods to improve system security, including testing techniques, software development management methods, and formal verification methods.

[0003] The invention patent application number 201210533633.X discloses a formal method for verification and performance analysis of high-reliability communication systems. The method is characterized by the following steps: Step 1: Analyze the functional implementation structure of the communication system's System-on-Chips (SOC), extract key functional modules, decompose and model the verification modules, and combine higher-order logic theorem proofs and symbolic model verification for combined formal verification; Step 2: Formally verify the interface attributes, I / O ports, and physical layer functional implementations between modules using model verification methods. Based on a symbolic model verification platform, the interface attributes, I / O ports, and physical layer functional implementations between modules are verified hierarchically using model verification methods; Step 3: To address the issue of excessive states that may result from complex functional modules, hierarchical abstraction is performed. Based on the first assumption guarantee theory, an environmental state machine model is established, and a combined verification strategy is implemented; Step 4: Theorem proof methods are used to verify the logic and functional implementation of data communication protocols and parallel application processes; and higher-order logic is used to formally express the temporal attributes and random behavior of the on-chip system.

[0004] This application aims to address the problem that "because model verification methods have a low level of abstraction, they can only perform qualitative verification. If the abstraction is inappropriate or the protocol is complex, it can easily lead to too many states or even state explosion. Currently, formal methods for network communication systems only verify their correctness; to achieve quantitative analysis, simulation models are established."

[0005] However, for scenarios involving communication and collaborative operation with industrial equipment, various formal verification tools have emerged to support different formal verification methods. Tools such as Coq, HOL Light, and Isabelle / HOL are widely used in various systems. These tools can perform reasoning verification on complex systems; however, they also present many challenges for developers and users. Developers often need extensive mathematical knowledge and reasoning strategies to use these tools to complete formal verification work. Furthermore, systems built using these tools require significant manpower for verification. Therefore, reducing the cost of formal verification for system software has become an important research direction. Summary of the Invention

[0006] Technical problems to be solved

[0007] In view of the above-mentioned shortcomings of the existing technology, the present invention provides a formal design and verification method for dual-system communication, which solves the technical problems mentioned in the background.

[0008] Technical solution

[0009] To achieve the above objectives, the present invention provides the following technical solution:

[0010] A formal design and verification method for dual-system communication includes the following steps:

[0011] Step 1: Receive control commands transmitted in real time between the two systems and monitor the security of the application network connecting the two systems;

[0012] Step 2: If the network security monitoring result for the connection between the two systems in Step 1 is negative, disconnect the network connection between the two systems. If the monitoring result is positive, perform a security verification operation on the control command received in Step 1.

[0013] Step 21: Obtain the operating logic of each functional module in the dual system, and execute virtual machine construction according to the operating logic of each functional module in the system;

[0014] Step 22: Capture the direction of control command transmission, use the direction of control command transmission as a trigger signal, and execute the corresponding configuration of the virtual machine and the trigger signal;

[0015] Step 3: Trigger the specified virtual machine to run according to the direction of control command transmission. The virtual machine will feed back the received control commands to the virtual machine, driving the virtual machine to run according to the control commands;

[0016] Step 4: Receive the data on each running stage and running result of the virtual machine in Step 3 according to the control instructions, and analyze the consistency of the running stage and running result data.

[0017] Furthermore, in step 1, when monitoring the network security of the connection application between the two systems, the network security is evaluated using the following formula:

[0018]

[0019] In the formula: δ is the network security coefficient; Where, ω j p represents the weight of a single-point network attack. j A represents the number of nodes associated with a single point of attack on a network. j As a security evaluation index, it is set to 1 when a network attack occurs and 0 when no network attack occurs. 1≤i≤N is the network security evaluation range, N is the extreme value of the network security evaluation range, 1≤j≤k is the network transmission link node selection range, and k is the extreme value of the network transmission link node selection target. Among them, D i As a single-point network attack threat assessment factor;

[0020] Among them, δ is directly proportional to network security. The judgment threshold is manually set by the user, and the network security is determined based on the value of δ.

[0021] Furthermore, when step 1 is executed, a web crawler is simultaneously deployed in the application network connecting the two systems. Based on the web crawler deployed in the network, the network security monitoring location is selected. The selected network security monitoring location is simultaneously applied to the reception of control commands that occur in real time between the two systems.

[0022] When deploying a web crawler in the network, real-time coordination is performed between the web crawler and the nodes deployed in the network. This coordination process is represented as follows:

[0023]

[0024] In the formula: C represents the current number of web crawler tasks; u i Let F be the number of URLs to be crawled for the i-th web crawler task; n is the number of web crawler nodes currently running; F max and F min The threshold values ​​are: P = 1, which means that the current number of web crawler nodes cannot meet the needs of the web crawler task and more web crawler nodes need to be added; P = -1, which means that the current number of web crawler nodes is higher than the actual web crawler task needs and the number of web crawler nodes needs to be reduced.

[0025] Furthermore, in step 2, while performing the security verification operation on the control command, the formal design of the verification logic is completed simultaneously through steps 21 and 22.

[0026] In step 21, when the virtual machine is built according to the operating logic of each functional module in the system, both systems execute the design of the corresponding virtual machine. In step 22, when capturing the direction of control command transmission, the direction of control command transmission is determined according to the continuous running status of the web crawler deployed in the network.

[0027] Furthermore, the virtual machine model constructed in step 21 includes a virtual CPU, a virtual storage device, and a virtual adapter. The virtual machine executes the output of virtual running data through the virtual CPU, virtual storage device, and virtual adapter.

[0028] In this dual-system system, the operational logic of each functional module is written to virtual memory, and the virtual CPU executes the writing operation of the operational logic. The written operational logic synchronously executes the output of the instruction opcode field length, represented as:

[0029]

[0030] In the formula: Lenght op The length of the instruction opcode field, in bits; N is the number of execution logic lines written; Length byte The length is one byte for the virtual machine.

[0031] Furthermore, when the control commands generated in the dual systems are transmitted between the dual systems via the network, the communication interface for transmitting the control commands in the network is simultaneously optimized, including the following steps:

[0032] I: Detect whether there is a loop in the communication interface, confirm the loop limit of the communication interface, and manually set the data throughput rate of the communication interface according to the loop limit attribute of the communication interface. The loop limit attribute of the communication interface is a quantitative or controllable variable.

[0033] II: For interfaces that need to be configured to set throughput, first analyze the loop logic to determine whether it can be extracted into a single logic function. If the result is yes, the logic will be merged into a single external interface of the system. That is, the original interface will be decomposed into two interfaces called by the upper layer. The calling method will be changed to use the condition of the loop upper limit as a parameter for function call. Otherwise, the process will end.

[0034] III: When the communication interface is not unique, first handle the processing logic outside the calling interface separately, and determine whether it can be implemented by a function. If the result is yes, implement this part of the logic as an interface, and complete it in the user layer by calling two functions in parallel. The function parameters are provided by the user space. Otherwise, the process ends.

[0035] Furthermore, when step 3 is executed, the database construction operation is performed synchronously, and the constructed database is used to store the data of each running stage and running result when the virtual machine runs according to the control instructions.

[0036] In this process, the virtual machine running according to the control instructions executes the threshold control instructions at each web crawler deployment node. The running stage and running result data of each execution are stored separately from the database. After the virtual machine completes the operation of executing and storing a control instruction at the web crawler deployment node, the running stage and running result data of the virtual machine stored in the database are packaged and fed back to step 4.

[0037] Furthermore, the data consistency in step 4 is calculated using the following formula:

[0038]

[0039] In the formula: The distribution vector of the feature data present in the pooling result i of data s; Let j be the distribution vector of the feature data present in the pooling result j of data e;

[0040] In step 4, the user terminal simultaneously sets the consistency judgment threshold. After calculating the consistency of the data in each running stage and the running result data, step 4 uses the consistency judgment threshold to determine whether the data is consistent.

[0041]

[0042] In the formula: w i w is the feature parameter matrix corresponding to pooling result i; j r is the feature parameter matrix corresponding to the pooling result j; jk and r jk The convolution operation is performed based on the pooling results i and j; n is the set of data pooling results; The dimension of the feature parameters.

[0043] Furthermore, if the result of step 5 is yes, the control command and the control command between the two systems will be further transmitted; otherwise, the transmission of the control command between the two systems will end.

[0044] Beneficial effects

[0045] Compared with known public technologies, the technical solution provided by this invention has the following advantages:

[0046] Beneficial effects:

[0047] 1. This invention provides a formal design and verification method for dual-system communication. This method mainly uses a virtual machine to build a verification method for the control commands transmitted between the systems. Based on this virtual machine setting, the immediacy of the verification process of the control command transmission is satisfied, making the verification effect of the control commands more reliable and accurate. In addition, during the control command transmission stage between the systems, the transmission environment can be monitored for security, effectively avoiding the influence of unstable factors when the control commands are transmitted from the network to the system.

[0048] 2. In the process of executing its steps, the method of this invention adopts a limited interface design to avoid unnecessary loops as much as possible, and uses a method to prevent necessary loop statements from being placed in the upper-level architecture. In the lower level, an explicit resource scheduling method is used, which reduces the complexity of the verification process and meets the requirements of the verification framework.

[0049] 3. In the method of the present invention, when its steps are executed, the consistency of multiple running data is further calculated by executing control instructions in a virtual machine to obtain running stage and running result data, and the results are output digitally. This digital output helps the user end to read the data, so that the output results of the method can be known by the user end more quickly. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.

[0051] Figure 1 This is a flowchart illustrating a formal design and verification method for dual-system communication.

[0052] Figure 2 This is a schematic diagram of the dual-system communication verification logic in this invention;

[0053] Figure 3 This is a schematic diagram of the virtual machine image building structure in this invention;

[0054] Figure 4 This is a schematic diagram illustrating the virtual CPU operation logic in the virtual machine of this invention;

[0055] Figure 5 This is a schematic diagram demonstrating the formal verification process of dual-system communication IPC in this invention. Detailed Implementation

[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0057] The present invention will be further described below with reference to embodiments.

[0058] Example 1

[0059] This embodiment presents a formal design and verification method for dual-system communication, such as... Figure 1 As shown, it includes the following steps:

[0060] Step 1: Receive control commands transmitted in real time between the two systems and monitor the security of the application network connecting the two systems;

[0061] Step 2: If the network security monitoring result for the connection between the two systems in Step 1 is negative, disconnect the network connection between the two systems. If the monitoring result is positive, perform a security verification operation on the control command received in Step 1.

[0062] Step 21: Obtain the operating logic of each functional module in the dual system, and execute virtual machine construction according to the operating logic of each functional module in the system;

[0063] Step 22: Capture the direction of control command transmission, use the direction of control command transmission as a trigger signal, and execute the corresponding configuration of the virtual machine and the trigger signal;

[0064] Step 3: Trigger the specified virtual machine to run according to the direction of control command transmission. The virtual machine will feed back the received control commands to itself, driving the virtual machine to run according to the control commands.

[0065] Step 4: Receive the data on each running stage and running result of the virtual machine in Step 3 according to the control instructions, and analyze the consistency of the running stage and running result data.

[0066] Step 2: While performing the security verification operation on the control command, the formal design of the verification logic is completed simultaneously through steps 21 and 22.

[0067] In step 21, when the virtual machine is built according to the running logic of each functional module in the system, both systems execute the design of the corresponding virtual machine. In step 22, when the direction of control command transmission is captured, the direction of control command transmission is determined according to the continuous running status of the web crawler deployed in the network.

[0068] In step 4, data consistency is determined using the following formula:

[0069]

[0070] In the formula: The distribution vector of the feature data present in the pooling result i of data s; Let j be the distribution vector of the feature data present in the pooling result j of data e;

[0071] In step 4, the user terminal simultaneously sets the consistency judgment threshold. After calculating the consistency of the data in each running stage and the running result data, step 4 uses the consistency judgment threshold to determine whether the data is consistent.

[0072]

[0073] In the formula: w i w is the feature parameter matrix corresponding to pooling result i; j r is the feature parameter matrix corresponding to the pooling result j; jk and r jk The convolution operation is performed based on the pooling results i and j; n is the set of data pooling results; The dimension of the feature parameters.

[0074] In this embodiment, the execution of steps 1 to 5 provides effective formal verification for the transmission of control commands in the dual-system communication, ensuring the accuracy of the transmission of control commands and maintaining the stability of the mutual operation and cooperation of the corresponding devices in the dual systems.

[0075] Furthermore, based on the calculations obtained from the above formulas, the control commands transmitted during the dual-system communication process can be output in digital form, so as to help the user end to know more quickly whether there are any errors or abnormalities in the transmission of control commands.

[0076] Specifically, at the implementation level, in order to ensure that the code is designed and implemented in accordance with the specification requirements, it is necessary to verify the refinement relationship between the implementation code and the specification. This invention utilizes a collaborative design method and employs a single-layer refinement approach to verify the equivalence between the implementation code and the code specification, that is, to verify that the implementation code is a refinement of the specification.

[0077] This refinement method verifies the refinement relationship between the code and the specification by deriving the equivalence between the state-space expression of the state transition function in the specification and the state-space expression of the implementation code.

[0078] The single-layer refinement method is represented as:

[0079] (1) To describe the behavior of IPC system communication, developers first write two specifications. The first specification describes the security policy of the system's security attributes, and the second specification describes the state changes that occur when an interface call occurs. The rapid formal verification framework provides data structures such as Map to guide developers in creating state machine specifications.

[0080] (2) Developers must ensure the correctness of the specifications. Based on this, developers can manually or use the code generator in the framework to write or generate the implementation code. Currently, the framework supports automatic generation of C code. For automatically generated code, developers need to make appropriate modifications according to the actual situation to lay the foundation for future verification.

[0081] (3) To ensure the refinement relationship between the code and the specification, the developers write a peer function. This peer function describes the one-to-one relationship between the system code and the specification state using a first-order logical expression.

[0082] (4) Symbolic execution technology is used to collect state data from the implementation code and the reduction interface. The implementation code is first converted to LLVM IR using LLVM, then encapsulated using the system's built-in tools. Finally, the symbolic execution engine is used to collect constraints and state attributes from the interface. For the reduction interface, symbolic execution is performed directly to collect constraints and state attributes. The constraint and state attribute sets of both, along with the equivalent functions, are solved using the Z3 solver to determine if the states are equivalent. If they are equivalent, the refinement relation is satisfied; otherwise, the verification fails.

[0083] On the other hand, the following verification method is implemented through two definitions:

[0084] Definition 1: Verify that the TIPC implementation interface function is a refinement of the state transition specification:

[0085]

[0086] Definition 2: The state transition specification satisfies the requirements of the upper-layer security attributes:

[0087]

[0088] Example 2

[0089] At the implementation level, based on Example 1, this example refers to... Figure 1 The formal design and verification method for dual-system communication in Example 1 will be further described in detail below:

[0090] Step 1: When monitoring network security for applications connecting the two systems, network security is assessed using the following formula:

[0091]

[0092] In the formula: δ is the network security coefficient; Where, ω j p represents the weight of a single-point network attack. j A represents the number of nodes associated with a single point of attack on a network. j As a security evaluation index, it is set to 1 when a network attack occurs and 0 when no network attack occurs. 1≤i≤N is the network security evaluation range, N is the extreme value of the network security evaluation range, 1≤j≤k is the network transmission link node selection range, and k is the extreme value of the network transmission link node selection target. Among them, D i As a single-point network attack threat assessment factor;

[0093] Among them, δ is directly proportional to network security. The judgment threshold is manually set by the user, and the network security is determined based on the value of δ.

[0094] The above formula can be used to perform security monitoring on dual-system communication application networks, ensuring that the steps of this method are executed under the condition that the network is completely secure.

[0095] like Figure 1 As shown, during step 1, a web crawler is deployed synchronously in the application network connecting the two systems. Based on the web crawler deployed in the network, the network security monitoring location is selected. The selected network security monitoring location is synchronously applied to the reception of control commands that occur in real time between the two systems.

[0096] When deploying a web crawler in the network, real-time coordination is performed between the web crawler and the nodes deployed in the network. This coordination process is represented as follows:

[0097]

[0098] In the formula: C represents the current number of web crawler tasks; u i Let F be the number of URLs to be crawled for the i-th web crawler task; n is the number of web crawler nodes currently running; F max and F min The threshold values ​​are: P = 1, which means that the current number of web crawler nodes cannot meet the needs of the web crawler task and more web crawler nodes need to be added; P = -1, which means that the current number of web crawler nodes is higher than the actual web crawler task needs and the number of web crawler nodes needs to be reduced.

[0099] The above settings provide the necessary control logic for the case crawler deployed in the dual-system communication network in this method.

[0100] Example 3

[0101] At the implementation level, based on Example 1, this example refers to... Figure 1 The formal design and verification method for dual-system communication in Example 1 will be further described in detail below:

[0102] The virtual machine model constructed in step 21 includes a virtual CPU, virtual storage, and a virtual adapter. The virtual machine executes the output of virtual running data through the virtual CPU, virtual storage, and virtual adapter.

[0103] In this dual-system system, the operational logic of each functional module is written to virtual memory, and the virtual CPU executes the writing operation of the operational logic. The written operational logic synchronously executes the output of the instruction opcode field length, represented as:

[0104]

[0105] In the formula: Lenght op The length of the instruction opcode field, in bits; N is the number of execution logic lines written; Length byte The length is one byte for the virtual machine.

[0106] The above formula can be used to further convert instruction opcodes into the operating logic of each functional module in the system written to virtual memory.

[0107] like Figure 1 As shown, when control commands generated in the dual systems are transmitted between the two systems via the network, the communication interface for transmitting control commands in the network is optimized synchronously, including the following steps:

[0108] I: Detect whether there is a loop in the communication interface, confirm the loop limit of the communication interface, and manually set the data throughput rate of the communication interface according to the loop limit attribute of the communication interface. The loop limit attribute of the communication interface is a quantitative or controllable variable.

[0109] II: For interfaces that need to be configured to set throughput, first analyze the loop logic to determine whether it can be extracted into a single logic function. If the result is yes, the logic will be merged into a single external interface of the system. That is, the original interface will be decomposed into two interfaces called by the upper layer. The calling method will be changed to use the condition of the loop upper limit as a parameter for function call. Otherwise, the process will end.

[0110] III: When the communication interface is not unique, first handle the processing logic outside the calling interface separately, and determine whether it can be implemented by a function. If the result is yes, implement this part of the logic as an interface, and complete it in the user layer by calling two functions in parallel. The function parameters are provided by the user space. Otherwise, the process ends.

[0111] By performing the above steps, better optimization results can be achieved for the network communication interface during dual-system communication.

[0112] like Figure 1 As shown, during step 3, the database construction operation is performed synchronously, and the constructed database is used to store the data of each running stage and running result of the virtual machine when it runs according to the control instructions.

[0113] In this process, the virtual machine running according to the control instructions executes the threshold control instructions at each web crawler deployment node. The running stage and running result data of each execution are stored separately from the database. After the virtual machine completes the operation of executing and storing a control instruction at the web crawler deployment node, the running stage and running result data of the virtual machine stored in the database are packaged and fed back to step 4.

[0114] like Figure 1 As shown, if the result of step 5 is yes, the control command and the control command between the two systems will be further transmitted; otherwise, the transmission of the control command between the two systems will end.

[0115] In summary, the methods described in the above embodiments primarily employ virtual machines to verify control commands transmitted between systems. This virtual machine setup ensures the immediacy of control command transmission verification, making the verification more reliable and accurate. Furthermore, during the control command transmission phase, the transmission environment can be securely monitored, effectively mitigating instability factors affecting control commands transmitted over the network to the system. Additionally, the method utilizes a limited interface design to minimize unnecessary loops, relegating necessary loop statements to the upper-level architecture and employing explicit resource scheduling at the lower level, thus reducing the complexity of the verification process and meeting the requirements of the verification framework. Simultaneously, during execution, the method uses control commands executed within the virtual machine to obtain runtime and result data, further calculating the consistency of multiple runtime data and outputting digital results. This digital output assists the user in reading the results, allowing for faster access to the output.

[0116] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions will not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A formal design and verification method for dual-system communication, characterized in that, Includes the following steps: Step 1: Receive control commands transmitted in real time between the two systems and monitor the security of the application network connecting the two systems; In step 1, when monitoring the network security of the connection application between the two systems, the network security is evaluated using the following formula: In the formula: δ is the network security coefficient; Where, ω j p represents the weight of a single-point network attack. j A represents the number of nodes associated with a single point of attack on a network. j As a security evaluation index, it is set to 1 when a network attack occurs and 0 when no network attack occurs. 1≤i≤N is the network security assessment range, N is the extreme value of the network security assessment range, 1≤j≤k is the network transmission link node selection range, and k is the extreme value of the network transmission link node selection target. Among them, D i As a single-point network attack threat assessment factor; Among them, δ is directly proportional to network security. The judgment threshold is manually set by the user, and the network security is determined based on the value of δ. Step 2: If the network security monitoring result for the connection between the two systems in Step 1 is negative, disconnect the network connection between the two systems. If the monitoring result is positive, perform a security verification operation on the control command received in Step 1. Step 21: Obtain the operating logic of each functional module in the dual system, and execute virtual machine construction according to the operating logic of each functional module in the system; Step 22: Capture the direction of control command transmission, use the direction of control command transmission as a trigger signal, and execute the corresponding configuration of the virtual machine and the trigger signal; Step 3: Trigger the specified virtual machine to run according to the direction of control command transmission. The virtual machine will feed back the received control commands to the virtual machine, driving the virtual machine to run according to the control commands; Step 4: Receive the data on each running stage and running result of the virtual machine in Step 3 according to the control instructions, and analyze the consistency of the running stage and running result data.

2. The formal design and verification method for dual-system communication according to claim 1, characterized in that, When step 1 is executed, a web crawler is simultaneously deployed in the application network connecting the two systems. Based on the web crawler deployed in the network, the network security monitoring location is selected. The selected network security monitoring location is simultaneously applied to the reception of control commands that occur in real time between the two systems. When deploying a web crawler in the network, real-time coordination is performed between the web crawler and the nodes deployed in the network. This coordination process is represented as follows: In the formula: C represents the current number of web crawler tasks; u i Let F be the number of URLs to be crawled for the i-th web crawler task; n is the number of web crawler nodes currently running; F max and F min The threshold values ​​are: P = 1, which means that the current number of web crawler nodes cannot meet the needs of the web crawler task and more web crawler nodes need to be added; P = -1, which means that the current number of web crawler nodes is higher than the actual web crawler task needs and the number of web crawler nodes needs to be reduced.

3. The formal design and verification method for dual-system communication according to claim 1, characterized in that, In step 2, while performing the security verification operation on the control command, the formal design of the verification logic is completed simultaneously through steps 21 and 22. In step 21, when the virtual machine is built according to the operating logic of each functional module in the system, both systems execute the design of the corresponding virtual machine. In step 22, when capturing the direction of control command transmission, the direction of control command transmission is determined according to the continuous running status of the web crawler deployed in the network.

4. A formal design and verification method for dual-system communication according to claim 1 or 3, characterized in that, The virtual machine model constructed in step 21 includes a virtual CPU, a virtual storage device, and a virtual adapter. The virtual machine executes the output of virtual running data through the virtual CPU, virtual storage device, and virtual adapter. In this dual-system system, the operational logic of each functional module is written to virtual memory, and the virtual CPU executes the writing operation of the operational logic. The written operational logic synchronously executes the output of the instruction opcode field length, represented as: In the formula: Lenght op The length of the instruction opcode field, in bits; N is the number of execution logic lines written; Length byte The length is one byte for the virtual machine.

5. The formal design and verification method for dual-system communication according to claim 1, characterized in that, When the control commands generated in the dual systems are transmitted between the dual systems via the network, the communication interface for transmitting the control commands in the network is simultaneously optimized, including the following steps: I: Detect whether there is a loop in the communication interface, confirm the loop limit of the communication interface, and manually set the data throughput rate of the communication interface according to the loop limit attribute of the communication interface. The loop limit attribute of the communication interface is a quantitative or controllable variable. II: For interfaces that require throughput rate settings, first analyze the loop logic to determine whether it can be fully extracted into a single logic function. If the result is yes, the loop logic will be merged into a single external system interface. The original interface will be decomposed into two interfaces called by the upper layer. The calling method will be changed to use the loop upper limit condition as a parameter for function calling. Otherwise, the process will end. III: When the communication interface is not unique, first handle the processing logic outside the calling interface separately, and determine whether it can be implemented by a function. If the result is yes, implement the preceding processing logic as an interface, and complete it in the user layer by calling two functions in parallel. The function parameters are provided by the user space. Otherwise, the process ends.

6. The formal design and verification method for dual-system communication according to claim 1, characterized in that, When step 3 is executed, the database construction operation is performed synchronously, and the constructed database is used to store the data of each running stage and running result of the virtual machine when it runs according to the control instructions. In this process, the virtual machine running according to the control instructions executes the threshold control instructions at each web crawler deployment node. The running stage and running result data of each execution are stored separately from the database. After the virtual machine completes the operation of executing and storing a control instruction at the web crawler deployment node, the running stage and running result data of the virtual machine stored in the database are packaged and fed back to step 4.

7. The formal design and verification method for dual-system communication according to claim 1, characterized in that, In step 4, data consistency is determined using the following formula: In the formula: The distribution vector of the feature data present in the pooling result i of data s; Let j be the distribution vector of the feature data present in the pooling result j of data e; In step 4, the user terminal simultaneously sets the consistency judgment threshold. After calculating the consistency of the data in each running stage and the running result data, step 4 uses the consistency judgment threshold to determine whether the data is consistent.

8. The formal design and verification method for dual-system communication according to claim 7, characterized in that, In the formula: w i The feature parameter matrix corresponding to pooling result i; w j The feature parameter matrix corresponding to the pooling result j; r jk The convolution operation is based on the pooling results i and j; n is the set of data pooling results; θ is the dimension of the feature parameters.

9. The formal design and verification method for dual-system communication according to claim 1, characterized in that, If the result of step 4 is yes, the control command and the control command between the two systems will be further transmitted; otherwise, the transmission of the control command between the two systems will end.

Citation Information

Patent Citations

  • Formalization method for verification and performance analysis of high reliable communication system

    CN103036739B

  • Concurrent real-time program verification ptimized processing system and method based on rewrite logic

    CN102231133A