A method for resource configuration and security optimization of integrated electronic system considering resource sharing and isolation

CN117786698BActive Publication Date: 2026-09-25NORTHWESTERN POLYTECHNICAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311814771.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2026-09-25
Estimated Expiration
2043-12-26

AI Technical Summary

Technical Problem

[0004]一方面,若将所有的共享资源都隔离,这样限制了资源的共享程度,也就失去了资源共享的意义和价值,即隔离的资源多,故障关联传播危险的可能性减少,但是降低了系统的效率;另一方面,若隔离的资源少,故障关联传播危险的可能性增加,但是提高了系统的效率

Benefits of technology

[0065]1.本发明为IMA的共享与隔离配置提供了理论与技术指导,在降低系统效率和提升资源利用效率之间寻找最优的共享资源配置方案,在保证飞机失效的定量指标要求的情况下,使得系统闲置资源的分配得到优化,提高了资源的利用效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117786698B_ABST
    Figure CN117786698B_ABST
Patent Text Reader

Abstract

The application provides a comprehensive electronic system resource configuration and security optimization method considering resource sharing and isolation, provides theoretical and technical guidance for shared and isolated configuration of an integrated modular avionics system, finds an optimal shared resource configuration scheme between reducing system efficiency and improving resource utilization efficiency, optimizes allocation of idle resources of the system under the condition of guaranteeing quantitative index requirements of airplane failure, and improves resource utilization efficiency.The application establishes a multi-objective shared resource configuration optimization model, efficiently configures resource sharing and isolation, guarantees security of the configuration, and improves the optimization design capability of the comprehensive electronic system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of systems engineering, and specifically relates to a comprehensive method for optimizing the resource allocation and security of electronic systems that considers resource sharing and isolation. Background Technology

[0002] like Figure 1 As shown, Integrated Modular Avionics (IMA) is a new and popular avionics architecture. IMA can be considered a service-providing virtual system platform formed by a series of flexible, reusable, and interoperable hardware and software resources, used to support applications performing aircraft functions. The IMA architecture places multiple applications on a single platform, thereby saving space, reducing the overall system weight, and decreasing energy consumption.

[0003] The need to improve IMA efficiency necessitates the sharing of many underlying resources within the IMA. However, various forms of resource sharing also introduce the risk of fault association and propagation; different forms of sharing may result in different coupled faults and different propagation paths. To reduce the risk of fault association and propagation caused by resource sharing, it is necessary to adopt an isolation design approach for underlying resources to improve their security.

[0004] On the one hand, isolating all shared resources limits the degree of resource sharing, thus losing the meaning and value of resource sharing. That is, the more resources are isolated, the less likely the risk of fault propagation is, but the lower the efficiency of the system. On the other hand, if fewer resources are isolated, the more likely the risk of fault propagation is, but the higher the efficiency of the system. Summary of the Invention

[0005] To address the issues raised in the background section, a comprehensive analysis balancing resource sharing and isolation in IMA (Integrated Resource Allocation) is needed. While meeting system security requirements, predefined tasks / functions are effectively allocated to various resources, and the isolation and sharing of system resources are designed. In other words, given system security requirements, based on a multi-layered resource allocation framework, the sharing and isolation of system resources are designed to ensure efficient resource utilization and achieve optimal system efficiency.

[0006] In the design of an IMA system, the resource allocation problem is addressed first. However, the coupling relationship between shared resources has a significant impact on system failure, and different configuration schemes bring different performance characteristics to the IMA system, including efficiency and security. Therefore, it is necessary to select an optimal shared resource configuration scheme that considers the failure logic of shared resources, model the underlying resource sharing and isolation configuration, and further optimize it according to requirements to obtain the optimal solution. However, traditional methods based on fault tree analysis are difficult to describe the coupling relationship of shared resources and cannot express the degree of correlation impact. Based on this, this invention proposes a multi-objective IMA resource sharing and isolation security configuration optimization method.

[0007] Specifically, the following steps are included:

[0008] Step 1: Establish a hierarchical model of the IMA system based on task-function-resource and a multi-layered resource allocation framework for the IMA system;

[0009] Step 2: Based on the IMA system hierarchical model and multi-layer resource allocation framework established in Step 1, establish a security quantification model;

[0010] Step 3: Based on the IMA system hierarchical model and multi-layer resource allocation framework established in Step 1, establish a resource utilization efficiency model;

[0011] Step 4: Based on the security quantification model and resource utilization efficiency model, as well as the constraints in the shared resource allocation process, establish a multi-objective shared resource allocation optimization model;

[0012] Step 5: Solve the multi-objective shared resource allocation optimization model using optimization algorithms to obtain the Pareto optimal set of shared resource allocation optimization design schemes;

[0013] Step 6: Calculate the security index and resource utilization efficiency of each shared resource configuration optimization design scheme in the scheme set obtained in Step 5, and select the optimal configuration scheme.

[0014] Furthermore, step 1 establishes a hierarchical model of the IMA system based on task-function-resource and a multi-layered resource allocation framework for the IMA system, including the following sub-steps:

[0015] Step 1.1: Define the IMA system S C The three levels of task, function, and resource:

[0016] S C ={S T S F S R}

[0017] S T ={t1,t2,…,tk}

[0018] S F ={f1,f2,…,f m}

[0019] S R ={r1,r2,…,r n}

[0020] C C ={C T,F C F,R}

[0021] Among them, task layer S T For several task elements t k The set of functions; functional layer S F For several functional elements f m The set of resources; resource layer S R For several resource elements r n A set;

[0022] C C This indicates the relationship between two layers, including the relationship between the task layer and the functional layer. (C) T,F The relationship between the functional layer and the resource layer (C) F,R A single resource can support multiple functions, and these resources are also interconnected. This can be achieved using C++. Ri,Rj This represents the relationship between resources, which is determined by functional requirements.

[0023] Step 1.2: Sort the resource layer element set S according to resource type R Further categorization:

[0024]

[0025] Where x represents the x-th type of shared resource, x = (1, 2, ..., N), N y Indicates the quantity of this type of resource configuration; Represents the Nth resource allocated from the xth type of resource. y One resource object, N y ∈(1,2,…,N);

[0026] Step 1.3: Use an adjacency matrix to describe the multi-layered resource allocation form and specific allocation scheme of shared resources within the resource layer, and represent the mapping association configuration matrix M representing this coupling relationship. rf for:

[0027]

[0028] Where, r n For resource elements, fm For upper-level resources;

[0029]

[0030] HF l This represents the l-th type of functionality; this type of functionality is implemented by multiple sub-functions. To complete together, that is k is the number of sub-functions, k = (1, 2, ..., N).

[0031] Furthermore, step 2 establishes a security quantification model, including the following sub-steps:

[0032] Step 2.1: Define the association matrix within the same resource layer

[0033]

[0034] in, The correlation coefficient,

[0035]

[0036] Step 2.2: Define the failure probability of shared resources

[0037]

[0038] in, The inherent probability of failure for shared resources;

[0039] The probability matrix C represents the probability of failure propagation at the same resource level. xP for;

[0040]

[0041] Step 2.3: Define the IMA failure probability P(F) ij The measurement formula is:

[0042]

[0043] in, This represents the failure probability of the IMA when the upper-layer resource of the resource layer fails. This represents the failure probability of the IMA when the upper-layer resources of the resource layer are not invalid.

[0044] Step 2.4: Calculate the failure probability of the shared resource. The calculation formula is:

[0045]

[0046] Furthermore, step 3 establishes a resource utilization efficiency model, including the following sub-steps:

[0047] Step 3.1: Define the IMA resource utilization efficiency UE(x,k), and calculate it using the following formula:

[0048]

[0049] Among them, K r(k) This represents the utilization efficiency impact factor of the k-th type of resource. The higher the level of the shared resource, the higher the utilization efficiency impact factor K. r(k) The larger the value, the more k∈[1,2,…,x];

[0050] Step 3.2: Define n used(k) This represents the number of k-th type resources actually used, calculated using the following formula:

[0051]

[0052] Count x,y Represents the y-th resource object r y Usage across all types of resources;

[0053] Count x,y ∈[1,m] and n used(k) =1,2,…,N,N≥N y .

[0054] Furthermore, step 4 establishes a multi-objective shared resource allocation optimization model, including the following sub-steps:

[0055] Step 4.1: Initialize the model and establish a multi-objective optimal allocation model for shared resources that meets the constraints. The constraints include: minimum configuration quantity constraint, dedicated resource quantity constraint, conflict resource isolation constraint, safety-critical resource isolation constraint, and actual configured shared resource quantity constraint.

[0056] The minimum configuration quantity constraint means that all the lowest-level shared resources are used, and the configuration quantity of each resource cannot exceed the total number of resources in the upper layers.

[0057] The constraint on the number of dedicated resources means that there are dedicated resources in the shared resources that cannot be shared, and the dedicated resource can only support one upper-level resource or sub-function.

[0058] The conflict resource isolation constraint means that in the actual allocation process, multiple sets of shared resources cannot be allocated to the same upper-level resource at the same time;

[0059] The constraint of isolation of safety-critical resources means that some safety-critical resources and functions must be designed with isolation and cannot be allocated to the same resource as other resources.

[0060] The actual number of shared resources configured is constrained to the actual number of shared resources n configured in step 3.2. used(k) Usage count of the y-th shared resource object x,y Relevant constraints;

[0061] Step 4.2: Based on the constraints determined in Step 4.1, establish a multi-objective shared resource allocation optimization model.

[0062] Furthermore, in step 5, the NSGA-II optimization algorithm multi-objective shared resource allocation optimization model is used to obtain the Pareto optimal shared resource allocation optimization design scheme set.

[0063] Furthermore, in step 6, the failure probability of each scheme in the scheme set is calculated. and resource utilization efficiency UE (IDCS) And select the optimal configuration scheme.

[0064] The advantages of this invention are:

[0065] 1. This invention provides theoretical and technical guidance for the shared and isolated configuration of IMA, seeking the optimal shared resource configuration scheme between reducing system efficiency and improving resource utilization efficiency. While ensuring the quantitative requirements of aircraft failure, it optimizes the allocation of idle system resources and improves resource utilization efficiency.

[0066] 2. This invention establishes a multi-objective shared resource configuration optimization model, which efficiently configures resource sharing and isolation while ensuring configuration security, thereby improving the optimization design capability of integrated electronic systems. Attached Figure Description

[0067] Figure 1 : IMA (Integrated Machine Assembly) diagram;

[0068] Figure 2 : A schematic diagram of the functional-resource relationship structure of the integrated display control system;

[0069] Figure 3 : Schematic diagram of inherent failure logic relationships within the resource layer of the integrated display control system;

[0070] Figure 4 : Schematic diagram of the crossover genetics operator operation;

[0071] Figure 5 : Schematic diagram of the operation mode of the mutation genetic operator;

[0072] Figure 6 Pareto bound solution space for optimizing system resource allocation in integrated display control systems;

[0073] Figure 7 : Schematic diagram of the optimal configuration scheme for the integrated display control system;

[0074] Figure 8 Schematic diagram of the configuration scheme for the integrated display control system sharing design; Detailed Implementation

[0075] This invention first proposes a hierarchical model of the IMA system based on task-function-resource, and then establishes a multi-layered resource allocation framework for the IMA system. Next, it establishes a security quantification model and a resource utilization efficiency model, constructing a multi-objective shared resource allocation optimization model using failure probability (a security indicator) and resource utilization efficiency (an economic indicator). This model considers the different constraints imposed on shared resource allocation to meet system security requirements. Finally, it uses the multi-objective optimization algorithm NSGA-II as the model solver to perform a trade-off analysis between IMA resource sharing and isolation, selecting an optimal shared resource allocation scheme.

[0076] Step 1: Establish a hierarchical model of the IMA system based on task-function-resource and a multi-level resource allocation framework for the IMA system.

[0077] The construction of an IMA (Integrated Management and Automation) system is based on specific task requirements. This involves pre-planning use case scenarios through requirements analysis. For example, the basic task of a civil aircraft is to ensure the safe and efficient transport of passengers, while the task of a communication network is to ensure the efficient transmission of data. These planned use case scenarios can be defined as the system's task view or task layer. Secondly, all functions support the smooth completion of system tasks based on system management. This means that to achieve a specific task, the required basic functions are decomposed. For example, when an aircraft performs takeoff tasks, it needs flight control management functions, navigation functions, and communication functions. This decomposition / allocation is the decomposition from the system level to the functional level; in the field of systems engineering, this decomposition can also be seen as the decomposition from the system level to the subsystem level. However, the design of tasks and functions belongs to the design of the system logic layer. Its final implementation requires the support of physical resources. That is, each function is implemented by several resources working together, thus realizing the allocation mapping from the system logic layer to the physical resource layer.

[0078] Therefore, an IMA system can be decomposed into three layers: Task, Function, and Resource. For example, when an IMA system implements a specific task, it is mainly supported by the corresponding resident functions and the underlying resources required (such as typical computing resources, storage resources, communication resources, and execution resources). Based on this, a TFR system hierarchical model can be established.

[0079] Step 1.1: IMA System S C It consists of three levels: task, function, and resource. C The formal representation of the relationship between them is as follows:

[0080] S C ={S T S F S R}

[0081] C C ={C T,F C F,R}

[0082] Task layer element set S T A task unit is established based on system requirements analysis. It can be decomposed layer by layer into several sub-tasks, and each sub-task is supported by several basic functions. Task set S T It can be represented as a set of several task elements:

[0083] S T ={t1,t2,…,t k}

[0084] There are relationships between subtasks and between tasks and functions, expressed in C++. T,F This represents the relationship between tasks and functions, determined by system-level requirements.

[0085] Functional layer element set S F A function is a functional unit in the system that supports task implementation; one function is implemented by several resources. Function set S F It can be represented as a set of several functional elements:

[0086] S F ={f1,f2,…,f m}

[0087] There are relationships between various functions and between functions and resources, using C++. F,R This represents the relationship between functions and underlying resources, determined by system task requirements.

[0088] Resource layer element set SR It is the physical or logical unit that implements functions in the system, the underlying unit of the system, and the set of system resource elements S. R It can be represented as a set of several resource elements:

[0089] S R ={r1,r2,…,r n}

[0090] A single resource can support multiple functions, and these resources are also interconnected. This can be achieved using C++. Ri,Rj This represents the relationship between resources, which is determined by functional requirements.

[0091] Step 1.2: Sort the resource layer element set S according to resource type R Further categorization:

[0092]

[0093] Where x represents the xth type of shared resource, N y Indicates the quantity of this type of resource configuration (e.g.) (This indicates that the number of shared resource configurations of the first type is N1). Represents the Nth resource allocated from the xth type of resource. y A resource object, that is, a resource of the same type is composed of multiple resource objects (e.g., (This refers to the second resource object allocated in the third type of resource).

[0094] Step 1.3: Given the number of shared resources, when all shared resources are allocated, the multi-level resource allocation form and specific allocation scheme are also formed, thus obtaining the coupling relationship within the resource layer. To describe the specific relationship information, an adjacency matrix is ​​used to describe the multi-level resource allocation form and specific allocation scheme of shared resources within the resource layer. The mapping association configuration matrix M representing this coupling relationship is then used. rf for:

[0095]

[0096] Where, r n For resource elements, f m For upper-level resources;

[0097]

[0098] Because the IMA system's underlying resources support the implementation of upper-layer functions, resource allocation must be based on functional requirements. HF l This represents the l-th type of function. A function type is implemented by multiple sub-functions. To complete together, that is k is the number of sub-functions, k = (1, 2, ..., N).

[0099] Step 2: Establish a security quantification model by defining multiple security indicators;

[0100] The failure probability of a system is derived by reasoning through the failure probabilities of all logical relationships related to the system (mainly referring to resource elements at various levels of the system and their associated conditional elements) based on the system's functional structure, thereby identifying the frequency of various incidents. This invention uses failure probability as a quantitative indicator of the security model to measure the security level of shared resource configuration in an IMA system.

[0101] Based on the coupling and failure logic relationships between various resources in the IMA system, the failure probability can be calculated. The coupling relationships at the resource layer characterize the relationships between various resource elements arising from the need for resource sharing. This relationship manifests in two ways: firstly, it originates from the inherent failure logic relationships within the resource layer; secondly, after the shared resource configuration is completed, the relationships between various resource elements arise because they serve the same upper-level resource / function. Through analysis, whether it's the inherent logical relationship or the relationship arising from different resource configurations, a failure logic relationship can be formed for each configuration scheme after resource configuration. To quantitatively describe the coupling relationships within the resource layer, this relationship is defined as follows:

[0102] Step 2.1: The association information within the same resource layer can be obtained from the association matrix C of the shared resources at each layer. x express:

[0103]

[0104] in, The correlation coefficient is the correlation coefficient. Used to characterize the relationships between various resource elements, representing the information interaction, material exchange, or possession by the same other layer element among resource elements after different resource configurations.

[0105]

[0106] Step 2.2: Failure probability of each shared resource In addition to the inherent inefficiency of shared resources themselves It is related to, and because of the correlation, is affected by fault propagation, that is, by the probability of failure propagation. Therefore, the failure probability of shared resources is defined. As a safety indicator:

[0107]

[0108] in, The inherent failure probability of a shared resource is the inherent failure probability of the nth shared resource in the xth resource category.

[0109] This refers to the failure propagation probability, which is the probability that shared resources configured in the same resource level will fail due to the propagation of failures.

[0110] Then the formula for the failure propagation probability matrix at the same resource level is C. xP for;

[0111]

[0112] Moreover, they are configured in the same resource The next level of shared resource collection If this upper-level resource If a failure occurs, all its subordinate shared resources will be affected by the failure propagation and become invalid as well.

[0113]

[0114] Failure probability of each shared resource In addition to the inherent inefficiency of shared resources themselves It is related to, and because of the correlation, is affected by fault propagation, that is, by the probability of failure propagation. That's relevant. Specifically, there are two situations:

[0115] If these resources are related in their inherent failure logic, they will be affected by each other's failure propagation regardless of whether they are configured in the same process; if they are shared resources configured in the same upper-level resource, they will all be related and affected by each other's failure propagation.

[0116] Step 2.3: Define the failure probability P(F) of the IMA system. ij ), which is the probability of the top event occurring in the IMA failure logic relationship, is measured by the following formula:

[0117]

[0118] in, This represents the failure probability of the IMA when the upper-level resource of the resource layer fails (x≠1). This represents the failure probability of the IMA when the upper-layer resources of the resource layer are not invalid.

[0119] Step 2.4: Calculate the failure probability of the shared resource. The calculation formula is:

[0120]

[0121] The above formula describes the calculation process for the failure probability of each shared resource with a coupled relationship. This formula can also be used to explicitly describe the relationships between shared resources within a layer.

[0122] The structure of the probability of failure for each shared resource includes:

[0123] (1) AND gate structure

[0124]

[0125] (2) OR gate structure

[0126]

[0127] Step 3: Establish a resource utilization efficiency model by defining economic indicators.

[0128] The shared resource characteristics of IMA systems optimize the allocation of idle resources and improve resource utilization efficiency. This invention quantifies resource utilization efficiency from the perspective of resource sharing and isolation design. Resource utilization efficiency is defined as the degree (quantity) of shared resource occupation and consumption in order to ensure the safe and correct operation of system tasks / functions when the system is configured for resource sharing and isolation. It reflects the resource configuration form: "shared" or "isolated," and is one of the important indicators for measuring the degree of resource utilization.

[0129] Define the IMA resource utilization efficiency UE(x,k) as follows:

[0130]

[0131] Among them, K r(k) This represents the utilization efficiency impact factor of the k-th type of resource. The higher the level of the shared resource, the higher the utilization efficiency impact factor K. r(k) The larger the value, the more k∈[1,2,…,x];

[0132] n used(k) This represents the number of the k-th type of resource actually used. Every shared resource will be used, meaning there will not be an n-th resource. used(k) =0. Resource utilization efficiency is related to the amount of shared resources used. The higher the degree of sharing and the lower the degree of isolation, the less shared resources are used, and the greater the resource utilization efficiency. Conversely, the lower the degree of sharing and the higher the degree of isolation, the more shared resources are used, and the lower the resource utilization efficiency.

[0133] Define Countx,y To count the usage of the y-th shared resource object, y∈[1,N] y Each configuration scheme can yield a mapping correlation matrix, then, through formula M... rf Count can be obtained by calculating the element in the nth row. x,y :

[0134]

[0135] Where: Count x,y ∈[1,m], then

[0136]

[0137] Step 4: Establish a multi-objective shared resource allocation optimization model and construct a safe optimization design and configuration scheme under the constraints of the shared resource allocation process.

[0138] Multi-objective shared resource optimization is essentially a decision problem oriented towards system security design. The objective is to optimize based on multiple objectives. By weighing and comparing the security objective of system failure probability and the economic objective of maximizing resource utilization efficiency, a Pareto-optimal set for the comprehensive analysis and optimization of shared resource allocation in an IMA system is obtained.

[0139] This invention establishes a multi-objective optimization model based on the failure probability (a safety indicator) and resource utilization efficiency (an economic indicator). The system failure probability of each shared resource allocation scheme must meet the system design requirements. That is, given a system design requirement, the failure probability P(F) is... Req ), then P(F) ij )≤P(F Req ).

[0140] In addition, to ensure that system security requirements are met, the allocation of shared resources will be subject to different constraints, including: minimum configuration quantity constraints, dedicated resource quantity constraints, conflict resource isolation constraints, security-critical resource isolation constraints, and actual configured shared resource quantity constraints.

[0141] 1) Minimum configuration quantity constraint: All shared resources at the lowest level are used, and the configuration quantity of each resource cannot exceed the total number of resources at the upper level.

[0142] According to the system's TFR model, to ensure the system's tasks / functions are implemented, all bottom-level resources must be allocated to their corresponding upper-level resources, but the allocation cannot exceed the sum of their quantities. This constraint indicates that for each bottom-level resource, there exists a condition where... In the process of allocation There must be at least one 1, but it must be less than or equal to the sum of the number of upper-layer resources configured. This constraint can be described using a system of inequalities:

[0143] b1≤M 12 A1≤b m

[0144] Where A1 = [1,1,…,1] T b1 = [1,1,…,1] T b m =[m,m,…,m] T By analyzing the associated configuration matrix Multiplying them together, we can see that M 12 The sum of the values ​​of each row of elements is between 1 and m, thus satisfying the constraint that every shared resource is used.

[0145] It should be noted that: when M 12 When A1 = b1, the configuration quantity of each resource is 1; if M 12 A1→b1 indicates a higher degree of resource sharing in the system; if M 12 A1→b m This indicates a lower degree of resource sharing and a higher degree of isolation design in the system. When M 12 A1=b m Each resource employs an isolated security design, meaning that all resources are not shared.

[0146] 2) Constraints on the quantity of dedicated resources:

[0147] Among shared resources, there are dedicated resources (DRs), which only support one upper-level resource / sub-function. Therefore, these resources cannot be shared. That is, the actual number of dedicated resources used for h upper-level resources / sub-functions can only be h, and h ≤ m, where m is the upper-level resource / sub-function. This constraint applies to dedicated resources. The configured quantity must be 1, that is The value can only be 1, that is This constraint can be described using an equation:

[0148]

[0149] Among them, A DR(rf) =[1,1,…,1] T b DR(rf) =[1,1,…,1] T Association configuration matrix This indicates the configuration relationship between dedicated resources and upper-level resources. Analysis of the multiplication of the configuration matrix reveals that for dedicated resources... The nth row contains only one 1 element, and the sum of its values ​​can only be 1.

[0150] Furthermore, dedicated resources can be configured together with other shared resources within the same upper-level resource / sub-function. Therefore, the number of shared resources configured within the upper-level resource for a dedicated resource is ≥1, i.e. This constraint can be expressed as an inequality:

[0151]

[0152] Among them, A DR(fr) =[1,1,…,1],b DR(fr) =[1,1,…,1]. For dedicated resources The m-th column contains at least one 1, and the sum of its values ​​is greater than or equal to 1.

[0153] 3) Conflicting resource isolation constraint: Conflicting resources cannot be configured in the same upper-level resource and must meet the isolation constraint condition.

[0154] In the resource allocation process of the IMA system, some resources cannot be simultaneously allocated to the same upper-level resource; these resources are called conflicting resources. This means that the conflicting resource isolation constraint must be satisfied. This constraint requires determining which resources are conflicting resources and cannot be allocated to the same upper-level resource based on the specific circumstances of the actual allocation process. Furthermore, shared resources are also conflicting resources when they are designed with isolation in mind, and therefore cannot be configured in the same upper-level resource. For example, suppose the c-th resource object in resource type x... and the d-th resource object Different at the same time assigned to the first Among the upper-level resources, namely In practice, multiple sets of resources may need to meet the isolation condition. This constraint is described here using an inequality:

[0155] A SEG M rf ≤b SEG

[0156] Where, matrix A SEG Each row in the code assigns a value of 1 to a resource that may conflict. SEG The number of rows represents the number of resource groups that need to meet the isolation conditions in the actual process, and the number of columns represents the number of shared resources used in the actual process, i.e., the value of n mentioned above. The row number e of this matrix corresponds to A SEG The number of rows and columns f corresponds to the number of upper-level resource configurations, i.e., the value of m mentioned above.

[0157] 4) Separate isolation constraints for safety-critical resources

[0158] This invention uses the term "Safety Critical Resource (SCR)" to describe a resource / function that directly impacts safety. Safety critical resources / functions must be designed with separate, isolated security features to ensure normal system operation. For example, the flight control management function in an aircraft's avionics system cannot be shared; it must be configured separately and isolated. Safety critical resources / functions must be designed with separate, isolated security features and cannot be allocated to the same resource as other resources (except dedicated resources) to improve system security. This constraint indicates that safety critical resources... The allocated upper-level resources consist of only one resource and one dedicated resource, namely... The value contains exactly two 1s, that is This constraint can be described using an equation:

[0159]

[0160] Among them, A SCR =[1,1,…,1],b SCR =[2,2,…,2]. This represents the configuration relationship between Safety Critical Resources (SCRs) and higher-level resources. Analysis of the multiplication of the configuration matrix reveals the relationship between safety critical resources... The m-th column contains two 1s, and the sum of their values ​​can only be 2.

[0161] 5) Constraints on the actual number of shared resources configured

[0162] The actual number of shared resources configured, n used(k) Usage count of the y-th shared resource object x,y Related, that is Suppose there are n resources that need to be configured into m upper-level resources, where there are t types of shared resource objects that can be configured. used(k) The minimum value is n, and the maximum value is (n + t·m) shared resource objects. This constraint is described here using an inequality:

[0163]

[0164] Among them, A u =[1,1,…,1],A v =[1,1,…,1] T .

[0165]

[0166] In summary, by combining the objective function and constraints, we obtain the standard multi-objective shared resource optimization model as follows:

[0167] P(F ij ):

[0168] P(F ij )≤P(F Req )

[0169]

[0170] st1≤k≤x

[0171] b1≤M 12 A1≤b m

[0172]

[0173]

[0174] A SEG M rf ≤b SEG

[0175]

[0176]

[0177] 1≤t, 1≤n, 1≤m, n≤m

[0178] By solving the above optimization model, a Pareto optimal set of shared resource allocation optimization design schemes can be obtained.

[0179] Step 5: Use the NSGA-II optimization algorithm to solve the above shared resource allocation optimization model and obtain the Pareto optimal shared resource allocation optimization design scheme.

[0180] The NSGA-II optimization algorithm is a common multi-objective genetic algorithm. Due to its unique sorting mechanism, elitism, and the fact that it does not require the selection of shared parameters, it is widely regarded as the most efficient method for solving multi-objective problems.

[0181] Next, the content of this invention will be further described in detail using the IMA integrated display control system as an example:

[0182] The Integrated Display and Control System (IDCS) is a typical modern IMA system, its main characteristic being resource sharing. IDCS is used to visually display information data from airborne sensors and systems to the pilots and crew, enabling pilots to safely fly the aircraft and complete missions. IDCS is a modular structure composed of standardized hardware modules, with the AFDX network centralizing data from each module into a shared system module for processing. IDCS resource modules can be dynamically configured, and their allocation is based on the mission's security level, ensuring sufficient processing time, storage capacity, network I / O communication, and other types of bus-connected interface resources during mission execution. The IDCS model constructed in this embodiment is as follows: Figure 2 As shown.

[0183] In the image: r 3 Represents node resources. 2 Represents module resources, r 1 This represents a partition of resources. A partition is the smallest unit for resource configuration and allocation in a system; a module can be configured with several partitions. Display function HF 1 and control functions HF 2 Each consists of two sub-functions, and these sub-functions are mutually redundant.

[0184] In addition to its own failure, each shared resource is also affected by the failure propagation of its subordinate resources. Therefore, the inherent relationship between the loss of IDCS functionality and resource failure can be divided into the following situations:

[0185] ①Third type of resource r 3 When a failure occurs, the failure relationship between IDCS functionality loss and resource failure is as follows:

[0186]

[0187]

[0188] ②Third type of resource r 3 No failure occurred, and the second type of resource r 2 When a failure occurs, the failure relationship between IDCS functionality loss and resource failure is as follows:

[0189]

[0190]

[0191]

[0192] ③Third type of resource r 3Second type of resource r 2 When no failures occur, the failure relationship between IDCS function loss and resource failure is as follows:

[0193]

[0194]

[0195]

[0196]

[0197] In summary, there are definite failure logic relationships within the IDCS resource layer, and these inherent failure logic relationships remain unchanged regardless of the quantity and form of resource configurations. The r involved in this IDCS case... 3 r 2 Both types of shared resources are designed with sharing and isolation in mind, with the configuration quantities set at 2 and 3 respectively.

[0198] Therefore, the failure logic expression of this IDCS model is:

[0199]

[0200]

[0201]

[0202]

[0203]

[0204] For the IDCS security quantification model in this embodiment, the basic number of resources required to implement the functions in this model is: N1 = 6, N2 = 3, N3 = 2. Table 1 shows the resource objects of various resources in the IDCS system and their inherent failure probabilities, as well as the failure propagation impact probability. for:

[0205] Table 1 Inherent Failure Probabilities of Various Resource Objects in IDCS

[0206]

[0207] The probability of failure propagation in this embodiment is given as follows:

[0208] The shared resources involved in this embodiment are of three types, including r. 3 r 2 , in, A shared and isolated design was implemented; Designed for a shared architecture, without any isolation features, and and It is a conflicting resource; a shared resource. When using an isolated design, the configuration quantity is 1 to 2. When using a shared design, the configuration quantity is 1, and when using an isolated design, the configuration quantity is 2. In this case, the sub-function... use At this time, sub-function use Shared resources This is a dedicated resource, therefore the quantity of this type of resource is configured as 4, i.e., the second type of resource r 2 Each type of shared resource corresponds to one dedicated resource. At this time, sub-function use At this time, sub-function use Sub-function use Shared resources It is a critical resource for safety.

[0209] Furthermore, this embodiment has already provided a second type of shared resource. Configured in The allocation result, i.e. Configured in middle, Configured in Thus, the correlation matrix of the second type of resource and the probability of failure propagation are determined.

[0210] In summary, based on the inherent failure logic of the IDCS system, the failure probability of the IMA integrated display control system is calculated as follows:

[0211]

[0212] For the resource utilization efficiency model in this embodiment, the resource utilization efficiency of the IDCS model in this embodiment is:

[0213]

[0214] In this IDCS model, the resource utilization efficiency influencing factor is given as: K r(1) =1 / 125, K r(2) =1 / 5, K r(3) =1 / 2. It has been designed with both sharing and isolation features, and its configuration quantity is already given; These shared resources were configured as shared resources without any isolation design.

[0215] Therefore, when sharing resources When using a shared design, the configuration quantity is 1; when sharing resources When using an isolation design, the configuration quantity is 2. The actual usage quantity of various IDCS resource objects is shown in Table 2:

[0216] Table 2 Actual Usage Quantity of Various IDCS Resource Objects

[0217]

[0218] The specific security constraints in this embodiment include minimum configuration quantity constraints, dedicated resource quantity constraints, conflict resource isolation constraints, safety-critical resource isolation constraints, and actual configuration shared resource quantity constraints. In particular, this embodiment also includes quantitative safety index constraints for aircraft failure, in accordance with civil aircraft airworthiness regulations.

[0219] (1) Minimum configuration quantity constraint: All shared resources at the lowest level are used.

[0220] In this embodiment, there are six types of shared resources at the lowest level. They are all configured to satisfy this security constraint in the following mathematical description:

[0221] b 1(IDCS) ≤M 12 A (IDCS) ≤b 3(IDCS)

[0222] Among them, A (IDCS) =[1,1,1,1,1,1] T b 1(IDCS) =[1,1,1] T b 3(IDCS) =[3,3,3] T .

[0223] (2) Dedicated resource quantity constraint: This means that there are dedicated resources (DR) in the shared resources that cannot be shared. The dedicated resource can only support 1 upper-level resource or sub-function.

[0224] In this embodiment, shared resources It is a dedicated resource and cannot be shared; it only supports one upper-level resource r. 2 That is, each upper-level resource r 2 Corresponding to 1 dedicated resource Therefore, there are 3 dedicated resources: Configured in upper-layer resources respectively In, that is Describe this security constraint using a mathematical formula.

[0225]

[0226] In this embodiment, A DR(IDCS) =[1,1,1] T b DR(IDCS) =[1,1,1] T .

[0227] In addition, the three dedicated resources are configured in the same way as other underlying shared resources in the upper-layer resource r. 2 Therefore, the number of resources in the upper-level resources where the dedicated resources are allocated is ≥1, i.e. This constraint can be expressed as an inequality:

[0228]

[0229] Among them, A DR(fr) =[1,1,…,1],b DR(fr) =[1,1,…,1]. This is the current association configuration matrix. and Unlike other resources, it is equivalent to three dedicated resources. Shared resources with 5 other resources Simultaneously configure the associated configuration matrix.

[0230] (3) Conflicting resource isolation constraint: Conflicting resources cannot be configured in the same upper-level resource.

[0231] In this embodiment, shared resources These are conflicting resources, therefore they cannot be configured with the same upper-level resource. Therefore, the associated configuration matrix is: This constraint is described here using an inequality:

[0232] A SEG(IDCS1) M rf ≤b SEG(IDCS1)

[0233] In the above formula, the matrix

[0234] In addition, when sharing resources When using an isolation design, the configuration quantity is 2, that is... and At this time, these two shared resources and These are conflicting resources, therefore they cannot be configured on the same upper-level resource. In, that is This constraint is described here using an inequality:

[0235]

[0236] in The associated configuration matrix at this time With M rf Different, it is equivalent to The associated configuration matrix when these 9 resources are configured simultaneously.

[0237] (4) Separate isolation constraint for safety-critical resources:

[0238] In this embodiment, shared resources These are security-critical resources and must be designed with isolation in place, meaning that the upper-level resources allocated to them must be isolated separately. There is only 1 shared resource. and 1 dedicated resource Therefore, the associated configuration matrix M rf for: The value of has exactly two 1s, that is This constraint can be described using an equation:

[0239]

[0240] Among them, A SCR(IDCS) =[1,1,…,1],b SCR(IDCS) =[2,2,2].

[0241] (5) Constraints on the actual number of shared resources configured:

[0242] This embodiment contains t=8 types of shared resource objects, but it includes one security-critical resource and two conflicting resources, reducing the number of shared resources used. The actual configuration quantity of these three types of shared resources is designed to be 1. In addition, there is one dedicated resource. Therefore, the actual shared resource constraints configured in this embodiment are:

[0243] 14≤n used(IDCS) ≤22

[0244] To better illustrate the proposed method, this embodiment only analyzes shared resources. The sharing and isolation design is implemented, with other shared resources designed in a defined sharing and isolation manner. The specific number of shared resources used is shown in Table 2.

[0245] (6) Quantitative safety indicator constraints:

[0246] An IMA failure can cause varying degrees of loss of life and property. According to Civil Aircraft Airworthiness Regulations CCAR 25.1309, the quantitative indicator for aircraft failure is less than 10. -9 In this embodiment, the failure probability P(IDCS) The requirements are:

[0247] P (IDCS) (F ij ≤10 -9 .

[0248] Finally, the optimized model for shared resource configuration of the integrated display control system of the IDCS instance is obtained as follows:

[0249]

[0250]

[0251] P (IDCS) (F ij ≤10 -9

[0252] st1≤k≤3

[0253] b 1(IDCS) ≤M 12 A (IDCS) ≤b 3(IDCS)

[0254] A (IDCS) =[1,1,1,1,1,1] T b 1(IDCS) =[1,1,1] T b 3(IDCS) =[3,3,3] T

[0255]

[0256] A DR(IDCS) =[1,1,1] T b DR(IDCS) =[1,1,1] T

[0257]

[0258] A DR(fr) =[1,1,…,1],b DR(fr) =[1,1,…,1]

[0259] A SEG(IDCS1) M rf ≤b SEG(IDCS1)

[0260]

[0261]

[0262]

[0263]

[0264] A SCR(IDCS) =[1,1,…,1],b SCR(IDCS) =[2,2,2]

[0265] 14≤n used(IDCS) ≤22

[0266] The NSGA-II optimization algorithm is used to solve the shared resource allocation optimization model of the integrated display control system, and the final Pareto solution set is obtained through iterative evolution. The specific process is as follows:

[0267] Step 5.1: Set the optimization algorithm parameters; set the number of iterations;

[0268] Step 5.2: Population initialization. The initialization parameters include the maximum number of generations, population size, genetic crossover ratio, genetic mutation ratio, and mutation probability; and the initial population is randomly generated according to the constraint domain.

[0269] Step 5.3: Calculate the fitness value of the new individual under the objective function;

[0270] Step 5.4: Merge offspring and parent individuals according to population size;

[0271] Step 5.5: Select superior individuals from the population through non-dominated sorting; this is used to evaluate the relative merits of individuals.

[0272] Let the population be Let one of the individuals be i, and after sorting, we obtain r non-dominated fronts: And it satisfies the following properties:

[0273]

[0274] And i≠j,

[0275]

[0276] Each individual corresponds to two parameters: n i S represents the number of individuals dominated by i; i The number of individuals dominating i is represented as:

[0277]

[0278]

[0279] First, let n iIndividuals with a rank of 0 are labeled as F1, where F1 represents the first-level non-dominated interface and its rank value is 1. Next, the rank of an individual in F1 is determined... k The value decreases by 1 when encountering n. k If -1 = 0, then the individual k is placed in set H as the second-level non-dominated interface, and its rank value is recorded as 2. Then, each individual in the second-level solution set is traversed, and the n of all individuals is... k The value is reduced by 1 when encountering n. k If -1 = 0, then this individual is marked as a level 3 non-dominated interface. Repeat the above steps in this manner until the entire population is stratified.

[0280] Step 5.6: Crowded Distance Allocation;

[0281] Calculate the Euclidean distance between individuals within the same interface based on the m-th objective function.

[0282]

[0283] in, represent The value of the i-th chromosome relative to the m-th objective function. and These are the maximum and minimum values ​​of the m-th objective function, respectively;

[0284] Step 5.7: Perform optimal selection on individuals within the population;

[0285] Elite ranking among individuals is achieved through the crowding comparison operator;

[0286] Randomly select 2 individuals, when or and In this case, individual a is superior to individual b. That is, individuals in a lower (superior) dominance ranking, or those with the same ranking but a larger crowding distance (more superior), will be selected first.

[0287] Step 5.8: As Figure 4 , Figure 5 As shown, the optimized individuals are selected as parent individuals, and new offspring individuals are generated through crossover and mutation of genetic operators. The purpose of adding genetic operators is to avoid obtaining local optima and improve the convergence speed of optimization.

[0288] Based on the genetic crossover ratio, select parent individuals for genetic crossover from all parent individuals, then select two parent individuals in turn, and randomly select a portion of the two parent individuals for crossover recombination to obtain the corresponding offspring individuals.

[0289] Based on the genetic mutation ratio, select parent individuals for genetic crossover from all parent individuals, and mutate a portion of the parent individuals according to the mutation probability to obtain the corresponding offspring individuals;

[0290] Step 5.9: Recombination and selection of populations;

[0291] The parent and offspring populations are recombined, and a new generation of populations is selected and generated based on the population size.

[0292] Step 5.10: Determine whether the preset number of iterations has been reached;

[0293] If the required number of iterations is reached, proceed to step 5.11;

[0294] Otherwise, proceed to step 5.3;

[0295] Step 5.11: Output the optimal solution set;

[0296] This embodiment, through iterative evolution, yields the final 13 Pareto solution sets, whose corresponding state positions are as follows: Figure 6 As shown.

[0297] Step 6: Substitute the Pareto optimal shared resource configuration optimization design into Step 3.1 to calculate the resource utilization efficiency (UE). (IDCS) Substitute into step 2.2 to calculate the failure probability. Select the optimal configuration scheme from all Pareto-optimal shared resource configuration optimization schemes.

[0298] This embodiment yields 13 Pareto solutions that meet the requirements. The optimization objective of this embodiment is to achieve optimal efficiency while satisfying system safety requirements. Therefore, all solutions satisfy the quantitative safety index constraints and have the same optimal resource utilization efficiency (UE). (IDCS) (x,k)=0.31767; Here we select the solution with the lowest failure probability as the optimal solution. The optimal configuration scheme of the IDCS model in this embodiment is as follows: Figure 7 As shown.

[0299] Figure 7 The configuration scheme is shared resources. When using an isolation design, the configuration quantity is 1. To better illustrate the difference between shared and isolated configurations, we select one from the obtained Pareto solution set. Adopting a shared configuration scheme during design, such as Figure 8 The configuration scheme shown is the same as... Figure 7 The optimal solutions were compared and analyzed, and their optimization target values ​​are shown in Table 3.

[0300] From the configuration schemes of the two, it can be seen that, although Figure 8 China Shared Resources Resource utilization efficiency of shared design UE (IDCS) The failure probability P is relatively high, but the failure probability P is relatively high. (IDCS) Exceeded the quantitative safety index constraint (P) (IDCS) (F ij ≤10 -9 In other words, resource sharing exacerbates the risk of fault propagation and cannot meet the security requirements of the IDCS system.

[0301] Therefore, it has been demonstrated that shared design can improve system efficiency, but increases risk, while isolated design can improve system security and reduce the possibility of fault propagation.

[0302] Table 3 Comparison with the optimal configuration scheme

[0303]

[0304] Therefore, the resource configurations of the optimal configuration scheme for this IDCS model are shown in Table 4:

[0305] Table 4 Resource Allocation of Sub-functions

[0306]

[0307] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the scope of the technology disclosed in the present invention, and such modifications or substitutions should all be covered within the scope of protection of the present invention.

Claims

1. A comprehensive method for optimizing resource allocation and security in electronic systems, considering resource sharing and isolation, characterized in that, Includes the following steps: Step 1: Establish a hierarchical model of the IMA system based on task-function-resource and a multi-layered resource allocation framework for the IMA system; Step 2: Based on the IMA system hierarchical model and multi-layer resource allocation framework established in Step 1, establish a security quantification model; Step 3: Based on the IMA system hierarchical model and multi-layer resource allocation framework established in Step 1, establish a resource utilization efficiency model; Includes the following sub-steps: Step 3.1: Define IMA resource utilization efficiency The calculation formula is: in, Indicates the first The utilization efficiency influencing factor of shared resources is as follows: the higher the level of the shared resource, the higher the utilization efficiency influencing factor. The larger, ; This represents the xth type of shared resource; Step 3.2: Definition Indicates the number actually used The number of resource types is calculated using the following formula: Indicates the first Individual resource objects Usage across all types of resources; Configure the mapping association matrix Elements in; and , Indicates the quantity of this type of resource configuration; Step 4: Based on the security quantification model and resource utilization efficiency model, as well as the constraints in the shared resource allocation process, establish a multi-objective shared resource allocation optimization model, including the following sub-steps: Step 4.1: Initialize the model and establish a multi-objective optimal allocation model for shared resources that meets the constraints, including: minimum configuration quantity constraint, dedicated resource quantity constraint, conflict resource isolation constraint, safety-critical resource isolation constraint, and actual configured shared resource quantity constraint. The minimum configuration quantity constraint means that all the lowest-level shared resources are used, and the configuration quantity of each resource cannot exceed the total number of resources in the upper layers. The constraint on the number of dedicated resources means that there are dedicated resources in the shared resources that cannot be shared, and the dedicated resource can only support one upper-level resource or sub-function. The conflict resource isolation constraint means that in the actual allocation process, multiple sets of shared resources cannot be allocated to the same upper-level resource at the same time; The constraint of isolation of safety-critical resources means that some safety-critical resources and functions must be designed with isolation and cannot be allocated to the same resource as other resources. The actual number of shared resources configured is constrained to the actual number of shared resources configured in step 3.

2. Usage information with the y-th shared resource object Relevant constraints; Step 4.2: Based on the constraints determined in Step 4.1, establish a multi-objective shared resource allocation optimization model; Step 5: Solve the multi-objective shared resource allocation optimization model using optimization algorithms to obtain the Pareto optimal set of shared resource allocation optimization design schemes; Step 6: Calculate the security index and resource utilization efficiency of each shared resource configuration optimization design scheme in the scheme set obtained in Step 5, and select the optimal configuration scheme.

2. The integrated electronic system resource allocation and security optimization method considering resource sharing and isolation according to claim 1, characterized in that, Step 1 establishes a hierarchical model of the IMA system based on task-function-resource and a multi-layered resource allocation framework for the IMA system, including the following sub-steps: Step 1.1: Define the IMA system The three levels of task, function, and resource: Among them, the task layer For several task elements A collection; functional layer For several functional elements The collection; resource layer For several resource elements A set; This indicates the relationship between two layers, including the relationship between the task layer and the functional layer. The relationship between the functional layer and the resource layer A single resource can support multiple functions, and these resources are also interconnected. This represents the relationships between resources, which are determined by functional requirements. Step 1.2: Organize the resource layer element set according to resource type Further categorization: Where x represents the xth type of shared resource, , Indicates the quantity of this type of resource configuration; Indicates the first The first type of resource allocated One resource object, ; Step 1.3: Use an adjacency matrix to describe the multi-layered resource allocation form and specific allocation scheme of shared resources within the resource layer, and represent the mapping association configuration matrix of this coupling relationship. for: in, As resource elements, For upper-level resources; Indicates the first Class functionality; this class functionality is implemented by multiple sub-functionalities. To complete together, that is , The number of sub-functions .

3. The integrated electronic system resource allocation and security optimization method considering resource sharing and isolation according to claim 2, characterized in that, Step 2 involves establishing a security quantification model, which includes the following sub-steps: Step 2.1: Define the association matrix within the same resource layer : in, The correlation coefficient, ; Step 2.2: Define the failure probability of shared resources : in, The inherent probability of failure for shared resources; The formula for the failure propagation probability matrix at the same resource level is: [Formula for failure propagation probability matrix]. for; Step 2.3: Define the IMA failure probability The measurement formula is: in, This represents the failure probability of the IMA when the upper-layer resource of the resource layer fails. This represents the failure probability of the IMA when the upper-layer resources of the resource layer are not invalid. Step 2.4: Calculate the failure probability of the shared resource. The calculation formula is: 。 4. The integrated electronic system resource allocation and security optimization method considering resource sharing and isolation according to claim 1, characterized in that, In step 5, the NSGA-II optimization algorithm multi-objective shared resource allocation optimization model is used to obtain the Pareto optimal shared resource allocation optimization design scheme set.

5. The method for optimizing resource allocation and security of an integrated electronic system considering resource sharing and isolation as described in claim 1, characterized in that, In step 6, the failure probability of each scheme in the scheme set is calculated. and resource utilization efficiency And select the optimal configuration scheme.

Citation Information

Patent Citations

  • A system and method for protecting Linux operating system security base on IMA

    CN109543413A

  • Shared resource allocation method for cloud load testing

    CN111082971A