An Abstract Modeling and Verification Method for the Code Implementation of the Core Transaction System Architecture
Through UML and CSP modeling technology combined with PAT verifier, the problems of process communication and cluster node state change in the trading system architecture design are solved, early error detection and system security are achieved, and the stability and consistency of the trading system in abnormal scenarios are ensured.
Patent Information
- Application Number
- CN202510285990.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-03-12
AI Technical Summary
The existing technology is difficult to detect potential design errors in the early stage of trading system architecture design, especially in inter-process communication and cluster node state changes. The existing master-slave arbitration mechanism lacks comprehensive formal verification, making it difficult to ensure the security and consistency of the system in abnormal scenarios.
UML modeling technology is used to build a process communication model of the transaction system architecture, and convert it into a formal CSP model, combined with PAT verifier for verification, state machine modeling and CSP model optimization are carried out for cluster selection modules, and nature specifications are defined using assertions to ensure that the system's behavior in different exception scenarios meets expectations.
Discover potential errors in the early stage of system development, improve the accuracy and security of the architectural model, ensure the correct behavior of the system in abnormal scenarios, reduce development costs and improve system security.
Smart Images

Figure CN119782125B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of abstract modeling and verification, and more specifically, to an abstract modeling and verification method for the code implementation of a core transaction system architecture. Background Art
[0002] UML Modeling Technology: The Unified Modeling Language (UML) is a standardized graphical modeling language widely used in software engineering, system design, and business process modeling. It provides a series of graphical modeling elements to describe the structure, behavior, and interaction process of a system. The purpose of UML is to help developers, designers, and other relevant personnel clearly and accurately model a system during the development process, thereby reducing misunderstandings and errors in development, helping designers build platform-independent models, and improving software development efficiency and quality. UML includes multiple models, such as class diagrams, use case diagrams, state machine diagrams, activity diagrams, sequence diagrams, etc. Each model diagram has a specific application scenario to model the static structure and dynamic behavior of a system from different perspectives.
[0003] Among them, there are two key models in UML modeling technology: sequence diagrams and state machine diagrams.
[0004] A sequence diagram is a dynamic model used to describe the interaction between objects or components in a system, especially to show the temporal relationship of message passing. In a sequence diagram, the vertical "lifeline" represents the life cycle of an object or component, and the horizontal arrow represents the message passing, thus showing how objects interact and communicate with messages in chronological order. It can accurately display the participation process of each object in the system and the order of message passing, and is especially suitable for complex business logics, distributed systems, or scenarios where multiple components collaborate. The main role of a sequence diagram is to help designers clearly understand and analyze the dynamic interaction process in a system. Through a sequence diagram, developers can clarify the behavior of each object at a specific time point, accurately grasp the order and dependency relationship of message passing in the system. During the system modeling process, a sequence diagram can help identify potential performance bottlenecks or design flaws, thereby optimizing the system architecture and process. It is particularly effective in showing the collaboration process among components in a complex system. Therefore, during the architecture design stage, sequence diagrams are usually used to model the interaction behavior among components.
[0005] A State Machine Diagram is a model used to describe the behavior of a system or component in different states and the transitions between those states. It represents how a dynamic system responds in different situations by defining a set of states, the transition rules between states, and the behavior of the system in each state. State machines are widely used in fields such as control systems, embedded systems, protocol design, software engineering, etc. Especially when it is necessary to describe the internal state changes and external event responses of a system, state machines provide an effective modeling method. In the state machine model, the behavior of the system consists of a finite number of states, and each state represents a possible working mode or situation of the system. The transitions between states are driven by specific trigger events or conditions, that is, when certain conditions are met, the system will transition from one state to another. The state machine model usually consists of three basic elements: states, transitions, and events. States describe the current situation of the system, transitions describe the transition from one state to another, and events trigger the occurrence of these state transitions. The role of state machines in system modeling is particularly important, especially when describing complex control logics, protocol flows, or the life cycle of a system. By using state machines, designers can intuitively express the various states of the system and their transition rules, thus simplifying system design and analysis. Therefore, in the architecture design phase, using state machines to model the complex state transition processes of key components, subsystems, and modules is crucial for modeling the complex behavior of the system.
[0006] CSP Formal Modeling Technique: Communicating Sequential Processes (CSP) is a formal modeling technique used to describe the behavior of concurrent systems, proposed by British computer scientist Tony Hoare in 1978. CSP is mainly used to describe the interaction and communication between multiple processes, and is particularly suitable for modeling the cooperation between processes in concurrent systems, distributed systems, and multi-tasking environments. CSP uses the method of process algebra to express the behavior and interaction of the system by defining formal rules for processes, communication, and synchronization. The core concepts of CSP are "processes" and "communication". In CSP, a process is an independent computational entity that can communicate through message passing. The communication between processes is usually synchronous, that is, the execution of one process will wait for the response or data transfer of another process. CSP uses events and channels to represent the interaction between processes. Events are the basic operations of processes, and channels are the media for transferring data between processes. By defining how processes interact through these events and channels, CSP can accurately describe the cooperation and synchronization of each process in a concurrent system.
[0007] In system modeling, CSP is particularly suitable for describing complex concurrent systems. Traditional program models are usually executed sequentially, while the coordinated work of multiple processes in a concurrent system makes the problem more complex. CSP provides a concise and powerful way to model these concurrent interactions. Through CSP, designers can clearly define the behaviors of individual processes and their synchronization and communication, thus ensuring the correctness and consistency of the system. For example, in the fields of distributed computing, operating system process management, and real-time systems, CSP is widely used to model the coordination and resource sharing between concurrent tasks. One of the advantages of CSP is its ability to formally express concurrent behaviors, enabling system designers to verify the correctness of the system in a mathematical way. Through CSP modeling, developers can apply various formal verification techniques, such as model checking and formal reasoning, to ensure that the system does not deadlock or exhibit other inconsistent behaviors during concurrent execution. The precision of CSP has led to its wide application in fields with high security requirements, such as aerospace, financial systems, and embedded systems.
[0008] In addition, compared with other formal modeling languages, the biggest feature of CSP is that it particularly emphasizes communication and synchronization, and its modeling process can flexibly express the interaction and cooperation of processes, making it suitable for complex concurrent or distributed environments. Through abstraction, CSP can effectively describe the communication and cooperation of the system, thus providing a theoretical basis and practical guidance for the design, verification, and optimization of concurrent systems. Therefore, CSP can be used as a formal modeling language to accurately model the message communication process between various processes, components, and subsystems in a complex system and the state transitions of core functional modules, laying a foundation for verification and analysis using formal verification techniques.
[0009] PAT Verifier: The PAT (Process Analysis Toolkit) verifier is a tool for formally verifying the behavior of concurrent systems. It is widely used in the verification of systems based on CSP or other formal modeling languages. The PAT verifier provides an automated way to analyze and verify the behaviors of individual processes and their interactions in a concurrent system to ensure that the system meets the specified specifications and requirements. By using the PAT verifier, developers can effectively discover potential errors, deadlocks, data inconsistencies, etc. in the system. Especially in complex concurrent and distributed systems, verification tools play a crucial role.
[0010] The working principle of the PAT validator is based on model checking technology. By automatically exploring the system model, it checks whether the system satisfies the given properties or constraints on all possible execution paths. By inputting a system modeled in languages such as CSP, the PAT validator can traverse the state space of the system, checking the safety, liveness, deadlock-freedom, and divergence-freedom of the system. The PAT validator provides a visual verification tool interface, which can implement the verification and analysis of CSP models and generate counterexamples when errors are found. Through model simulation, designers can carefully analyze the message communication process between processes, simulate each step of the message communication, and also simulate the state transition process of the system in the implementation of the core algorithm module, thus facilitating error location.
[0011] In the prior art, the design scheme of the system cluster leader election module mainly relies on hardware devices, that is, the anomaly detection and recovery technology for redundant designs such as master-slave arbitration. In the prior art, only partial formal verification is included for the master-slave arbitration mechanism, that is, only module-level verification is provided.
[0012] Therefore, there is an urgent need to design an abstract modeling and verification method for the code implementation of the core transaction system architecture, so as to integrate formal modeling and verification technologies in the early stage of architecture design, discover potential errors in the design, improve the accuracy and security of the architecture model, ensure that the behavior of the system meets expectations in different abnormal scenarios, and solve the modeling problems of communication between processes and state transitions of cluster nodes in the transaction system. Summary of the Invention
[0013] The purpose of the present invention is to overcome the deficiencies of the prior art and provide an abstract modeling and verification method for the code implementation of the core transaction system architecture, so as to integrate formal modeling and verification technologies in the early stage of architecture design, discover potential errors in the design, improve the accuracy and security of the architecture model, ensure that the behavior of the system meets expectations in different abnormal scenarios, and solve the modeling problems of communication between processes and state transitions of cluster nodes in the transaction system.
[0014] To achieve the above object, an abstract modeling and verification method for the code implementation of the core transaction system architecture is designed. The method includes: A. Modeling and verifying the architecture of the transaction system: By extracting relevant information from the code implementation and development design documents of the architecture framework, using abstract modeling techniques to construct the behavior model of the existing system, using UML sequence diagrams to model the process communication process of the system, converting the UML sequence diagrams into formal CSP models to describe the communication mechanism and synchronization behavior of the system, and using the PAT verifier to perform verification and analysis of security properties; B. Modeling and verifying the cluster leader election module in the transaction system: Constructing the state machine models of each node during the cluster leader election process to describe the state transition process of the cluster leader election, constructing the system dynamic model, and using the PAT verifier to verify and analyze the correctness of the leader election process.
[0015] Preferably, the present invention further includes: The method for modeling and verifying the architecture of the transaction system is specifically as follows: S1. Modeling the process communication process of the core transaction system architecture based on UML sequence diagrams, including: S11. Identifying different functional modules in the transaction system architecture; S12. Modeling the message passing sequence, synchronous and asynchronous communication methods, and trigger conditions of transaction operations among each module through sequence diagrams; S13. By comparing the design documents and actual code implementation, ensuring that the communication model described by the sequence diagrams is consistent with the actual architecture of the system; S2. Constructing a formal model of the process communication process of the core transaction system architecture based on CSP, including S21. It is necessary to convert the message passing in the sequence diagrams into events in CSP to ensure the accuracy and consistency of communication behavior; S22. Through the concurrent control mechanism of CSP, modeling the synchronization and mutual exclusion relationships among multiple transaction processes in the system to ensure that the system can efficiently and correctly process concurrent transaction requests; S23. Defining property specifications in the form of assertions, aiming at the property specifications of the sequence diagram model, no deadlock and no divergence; S3. Based on the PAT verifier for model verification, after constructing the formal CSP model, using the PAT model verifier to verify the constructed CSP model to ensure that the model meets the predefined property specifications, and the property specifications include no deadlock and no divergence. By using the #assert assertion statement in the PAT verifier to formally define the above specifications, the dynamic behavior of the system can be comprehensively verified.
[0016] Preferably, the present invention further includes: The method for modeling and verifying the architecture of the transaction system further includes step S4. Optimization and feedback iteration of the CSP formal model. According to the feedback results of the PAT verification, optimization and feedback are carried out to ensure that the system design can be improved in each iteration.
[0017] Preferably, the present invention further includes: The method for modeling and verifying the cluster master election module in the trading system is specifically as follows: S1. Model the cluster master election module of the core trading system based on the UML state machine diagram, including: S11. Analyze the code implementation logic of the cluster master election module, and abstract different working states that may occur in the master election process of cluster nodes; S12. Deeply study the state transition logic of the nodes, and clearly define the transition conditions between different states of each node and their corresponding trigger events or operations through the UML state machine model; S13. Combine the design document and actual code implementation of the cluster master election module to compare and verify the state machine diagram, ensuring that the state machine diagram accurately reflects the actual situation of node behavior, thereby avoiding potential logical errors or inconsistencies; S2. The CSP model of the cluster master election module, including: S21. Map the state transitions and operations in the state machine diagram to the event sequence in the CSP model, and different transition conditions are combined through concurrent operators; S22. Considering that nodes in the cluster may fail, a failure state is added to the CSP model; S23. Define property specifications in the form of assertions. The property specifications for the state machine diagram include liveness, safety, and stability; S3. Use the PAT model verifier for verification. After constructing the CSP formal model, use the PAT model verifier to verify the CSP model to ensure that the system meets the predefined property requirements. The properties include liveness, safety, and stability. The above specifications are formally defined through the #assert assertion statement in the PAT verifier to comprehensively verify the key behaviors of the model.
[0018] Preferably, the present invention further includes: The method for modeling and verifying the cluster master election module in the trading system further includes step S4. Optimization and feedback iteration of the CSP formal model. According to the feedback results of the PAT verification, perform optimization and feedback to ensure that the system design can be improved in each iteration.
[0019] Compared with the prior art, the advantages of the present invention are as follows:
[0020] It realizes the integration of trusted modeling and verification technology in the architecture design process of the trading system, ensures the correctness and security of the system architecture model, so as to be able to discover errors in the early stage of system development, reduce development costs, and improve system security. It solves the problem of modeling the state transitions of each node in the communication process between processes and the cluster master election process in the trading system architecture.
[0021] Using a PAT validator to perform formal verification and analysis on the message communication model of the trading system architecture framework and the state transition model of the cluster leader election module can identify potential errors in the trading system architecture design for different abnormal scenarios, and analyze the counterexamples obtained after verifying the abnormal scenarios, thereby helping to optimize the model design to ensure system security. This method has good generality and can be extended and applied to the modeling and security verification analysis of other design modules of the trading system. Description of the Drawings
[0022] Figure 1 Flowchart for modeling and validating the architecture of the trading system in the present invention;
[0023] Figure 2 Flowchart for modeling and validating the cluster leader election module in the trading system in the present invention;
[0024] Figure 3 Schematic diagram of the sequence diagram model of thread communication in the trading system in the first embodiment of the present invention;
[0025] Figure 4 Schematic diagram of the CSP model of the sequence diagram in the first embodiment of the present invention;
[0026] Figure 5 Schematic diagram of the verification results of deadlock-free and divergence-free in the first embodiment of the present invention;
[0027] Figure 6 Schematic diagram of the state machine model constructed using the Modelio tool in the second embodiment of the present invention;
[0028] Figure 7 Schematic diagram of the variable definition of the CSP model of the cluster leader election module in the second embodiment of the present invention;
[0029] Figure 8 Schematic diagram of the node definition of the CSP model of the cluster leader election module in the second embodiment of the present invention;
[0030] Figure 9 Schematic diagram of the specification definition of the properties of the cluster leader election module in the second embodiment of the present invention;
[0031] Figure 10 Schematic diagram of the specification verification results of the properties of the cluster leader election module in the second embodiment of the present invention. Detailed Embodiments
[0032] To make the purpose, principle, and structure of the present invention clearer and more understandable, the following further elaborates with reference to the accompanying drawings and specific embodiments.
[0033] The existing system availability guarantee solutions mainly rely on hardware devices, that is, the anomaly detection and recovery technologies for redundant designs such as master-slave arbitration. They do not have the ability to construct an abstract model of a complex transaction system and use formal verification tools to conduct rigorous verification and analysis on the abstract model, making it difficult to discover potential risks. The existing master-slave arbitration mechanism only includes partial formal verification, that is, it provides module-level security and cannot generalize this empirical technology to distributed application scenarios, that is, it does not model and verify the arbitration model and business workflow based on the business framework. It is difficult for existing formal technologies to efficiently model both the business workflow and the master election algorithm of a transaction system through one model.
[0034] The present invention provides an abstract modeling and verification method for the code implementation of the core transaction system architecture, which abstractly models the dynamic behavior in the architecture for the existing code of the transaction system, aiming to use formal modeling and verification technologies to analyze potential security hazards in the design and implementation of the transaction system architecture, thereby improving the security of the system.
[0035] The present invention conducts research from both macro and micro perspectives. At the macro level, it models and verifies the architecture of the transaction system. By extracting relevant information from the code implementation and development design documents of the architecture framework, it uses abstract modeling technology to construct the behavior model of the existing system, that is, uses UML sequence diagrams to model the process communication process of the system. Subsequently, it converts the UML sequence diagrams into a formal model of CSP to describe the communication mechanism and synchronization behavior of the system, and uses the PAT validator to conduct verification and analysis of security properties. At the micro level, it models and verifies and analyzes the core module in the transaction system - the cluster master election module, constructs the state machine model of each node during the cluster master election process to describe the state transition process of the cluster master election, constructs the system dynamic model, and uses the PAT validator to conduct verification and analysis of the correctness of the master election process.
[0036] 1. Refer to Figure 1 , the modeling and verification of the transaction system architecture framework are specifically as follows:
[0037] (1) Model the process communication process of the core transaction system architecture based on UML sequence diagrams.
[0038] In the present invention, we have conducted a detailed analysis of the code (C++ implementation) of the core trading system architecture and abstractly modeled the communication process between different processes in the architecture using sequence diagrams in the Unified Modeling Language (UML). Particular attention has been paid to the message communication process in which business messages in the architecture pass through the trading system architecture framework and are sequentially subjected to specific business logic processing in each thread. The core of the present invention is to use abstract modeling techniques to construct static structure and dynamic behavior models of the core trading system, with particular attention to the process communication process in the trading system architecture. During the modeling process, abstract modeling is carried out based on the existing code implementation of the system, accurately reflecting the message communication process in the actual code.
[0039] Specifically, first, it is necessary to identify different functional modules in the trading system architecture. Secondly, the message passing sequence, synchronous and asynchronous communication methods, and trigger conditions for trading operations between each module are modeled through sequence diagrams. Finally, by comparing the design documents and actual code implementation, it is ensured that the communication model described by the sequence diagram is consistent with the actual architecture of the system.
[0040] By modeling the sequence diagram of message interaction in the core trading system architecture framework, the present invention can design an abstract model consistent with the actual code in the core trading system architecture design stage. Its expressive ability is stronger, and it can effectively improve the reusability of the system model.
[0041] (2) Construct a formal model of the process communication process of the core trading system architecture based on CSP.
[0042] Based on the communication behavior described in the UML sequence diagram, a corresponding CSP formal model is established to ensure that the communication process of the system meets the required concurrency control and synchronization mechanisms. First, it is necessary to convert the message passing in the sequence diagram into events in CSP to ensure the accuracy and consistency of the communication behavior. Secondly, through the concurrency control mechanism of CSP, the synchronization and mutual exclusion relationships between multiple trading processes in the system are modeled to ensure that the system can efficiently and correctly process concurrent trading requests. Finally, property specifications are defined in the form of assertions, targeting the property specifications of the sequence diagram model, namely deadlock-freedom and non-divergence.
[0043] (3) Conduct model verification based on the PAT validator.
[0044] After constructing the CSP formal model, the present invention further uses the PAT model validator to verify the constructed CSP model to ensure that the model meets the predefined property specifications, which include deadlock-freedom and non-divergence. By formally defining the above specifications in the form of #assert assertion statements in the PAT validator, the dynamic behavior of the system can be comprehensively verified.
[0045] (4) Optimization and feedback iteration of the CSP formal model.
[0046] According to the feedback results of PAT verification, the present invention also introduces an optimization and feedback mechanism to ensure that the system design can be improved in each iteration.
[0047] 2. Refer to Figure 2 , the modeling and verification of the master selection module of the trading system cluster are as follows.
[0048] (1) Model the master selection module of the core trading system based on the UML state machine diagram.
[0049] In the present invention, a detailed analysis is carried out on the code implementation of the master selection module of the key components in the core trading system, and the process of the algorithm is formally modeled by using the state machine diagram in the Unified Modeling Language (UML). The focus is on the state transitions of the cluster nodes during the master selection process, and the state transitions of the nodes under different trigger events are deeply explored to discover potential unsafe behaviors or design defects in the master selection module. The core method of the present invention is to construct an arbitration logic model of the master selection module through abstract modeling technology. This method has extremely high expressive power, can accurately model the state changes of each node during the master selection process, comprehensively reflect the interactions and state transitions among the nodes in the cluster, and provide a solid theoretical basis for the subsequent model verification work.
[0050] In the specific implementation process, first, analyze the code implementation logic of the master selection module, and abstract different working states that may occur to the cluster nodes during the master selection process, such as: waiting for master selection state, master node state, slave node state, etc. Secondly, deeply study the state transition logic of the nodes, and clearly define the transition conditions between different states of each node and their corresponding trigger events or operations through the UML state machine model. Finally, compare and verify the state machine diagram in combination with the design document and actual code implementation of the master selection module to ensure that the state machine diagram accurately reflects the actual situation of the node behavior, thereby avoiding potential logical errors or inconsistencies.
[0051] Through the state diagram modeling method, the present invention can abstractly model the state transition process of the cluster nodes in the design stage of the master selection module, providing a strong guarantee for the high availability and security of the system.
[0052] (2) The CSP model of the master selection module.
[0053] Based on the UML state machine diagram, a CSP model for node state transitions is established to formally describe the state transitions and corresponding operations of each node in the cluster leader election module. First, the state transitions and operations in the state machine diagram need to be mapped to event sequences in the CSP model, and different transition conditions are combined through concurrent operators. Second, considering that nodes in the cluster may fail, a failure state is added to the CSP model. Finally, property specifications are defined in the form of assertions. The property specifications for the state machine diagram include liveness, safety, and stability.
[0054] (3) Use the PAT model checker for verification.
[0055] After constructing the CSP formal model, the present invention further uses the PAT model checker to verify the CSP model to ensure that the system meets the predefined property requirements, and the properties include liveness, safety, and stability. By using the #assert assertion statement in the PAT checker to formally define the above specifications, the key behaviors of the model are comprehensively verified.
[0056] (4) Optimization and feedback iteration of the CSP formal model.
[0057] According to the feedback results of the PAT verification, the present invention also introduces an optimization and feedback mechanism to ensure that the system design can be improved in each iteration.
[0058] The present invention conducts targeted research on the defects of the prior art:
[0059] 1. The existing system cluster leader election module design solutions mainly rely on hardware devices, that is, the anomaly detection and recovery technologies for redundant designs such as master-slave arbitration.
[0060] The background of the election security of the core trading system mainly stems from the rapid development of the financial market and the improvement of regulatory requirements. With the surging trading volume and the continuous refresh of trading peaks, the existing system faces huge challenges in stability and processing power. Such highly available distributed systems usually implement a fault detection mechanism to timely identify and handle the failures of nodes or components, and complete fault recovery through service reconstruction or hot start, etc.
[0061] In the fault recovery mechanism of the core trading system, multiple key components work together to ensure the high availability of the system. Fault detection components (such as heartbeat detection and log analysis) continuously monitor the system status. When an anomaly is detected, an alarm is immediately triggered and, through the event processing framework, the recovery process is initiated across the cluster. The detection mechanism is tightly integrated with the redundant design, which, through primary-backup switching and load balancing technologies, ensures that when the primary node fails, the standby node can quickly take over the work and maintain the continuity of the service. The data backup and synchronization mechanism ensures the consistency and integrity of data during the failover process, preventing data loss.
[0062] Within the scope of the security guarantee of the current system, the implementation of the above-mentioned fault recovery mechanism only fulfills the maintenance function of the core trading system. Within the scope of intellectual property retrieval, there is no relevant literature equivalent to the content protected by this patent (i.e., the modeling and verification of the core trading system cluster election mechanism).
[0063] The present invention adopts a method completely different from maintenance. Generally, these anomaly detection and recovery methods have not been formally verified and analyzed, and there may be some potential risks. As a complex state system in the context of a highly available service cluster, the fault detection of traditional cluster elections highly depends on technologies such as data mining or fault identification, and it is difficult to cover all fault modes. Secondly, if the input data has quality problems or is incomplete, it may affect the accuracy and efficiency of anomaly detection. Its recovery technology is usually an emergency measure when the system is unavailable, involving the restart of software, hardware, or services, which may only be a temporary solution rather than fundamentally improving the system security.
[0064] Strictly speaking, these traditional solutions lack the ability to strictly verify and prove the system security from the abstract model level. This also means that although they can partially handle and recover known fault modes, they may not be able to comprehensively predict and prevent unknown system faults, thus limiting the long-term guarantee of system availability.
[0065] 2. The existing master-slave arbitration mechanism only includes partial formal verification, that is, only module-level verification is provided.
[0066] There is an improved Raft leader election algorithm among ETCD, the arbitrator, and cluster nodes, which can achieve consistency and fault recovery in a distributed system and reach an agreement in each stage to achieve fault recovery. After searching for intellectual property and academic literature, there are three related technical solutions for verifying the consistency of the native Raft leader election algorithm, namely, logical analysis based on TLA+, analysis of the Raft leader election protocol using the TLC model checker, and verification of the Raft algorithm using the Stateright model checker. These three methods mainly analyze the formalization of the Raft algorithm itself. However, they do not provide security guarantees closely related to the actual business of the core system transactions, and their effects are similar, so they will not be elaborated in detail. The following briefly lists the core content of these three methods:
[0067] The first solution: logical analysis based on TLA+ (Temporal Logic of Actions). This solution conducts formal modeling through TLA+. By using TLA+, each component and state transition of the Raft algorithm can be modeled and its correctness can be verified.
[0068] The second solution: an analysis method for the Raft leader election protocol based on TLC. TLC is a model checker for the TLA+ (Temporal Logic of Actions) formal language. This solution provides a formal specification of the Raft protocol and uses the TLC model checker to verify the case with a small number of protocol participants. This work not only provides a formal description of Raft but also verifies its correctness.
[0069] The third solution: Stateright model verification. Stateright is widely used in the verification of distributed consistency algorithms such as the Raft protocol and the Paxos protocol, especially in the research and academic fields. It is used to check the behavior of the protocol under various fault conditions such as fault recovery, node failure, and network partitioning. This solution uses the Stateright model checker to verify the Raft Lite algorithm. By implementing a CheckerRunner, the Raft Lite algorithm is wrapped into the model checker. The key part is the step function, which processes any event and returns the actions that the node should take, making the behavior of the algorithm similar to a state machine.
[0070] The present invention discovers the defects of the prior art:
[0071] 1. The existing system availability guarantee solutions mainly rely on hardware devices, that is, the anomaly detection and recovery technologies for redundant designs such as master-slave arbitration, which do not have the ability to construct an abstract model of a complex transaction system and use formal verification tools to conduct rigorous verification and analysis on the abstract model, making it difficult to discover potential risks.
[0072] 2. The existing master-slave arbitration mechanism only includes partial formal verification, that is, it provides module-level security and cannot generalize this empirical technology to distributed application scenarios, that is, it does not model and verify the arbitration model and business workflow based on the business framework.
[0073] 3. It is difficult for existing formalization technologies to efficiently model the business workflow and master election algorithm of a transaction system through one model.
[0074] The key improvements in the technical means of the present invention can be summarized as follows:
[0075] 1. An architecture modeling and verification method adapted to the business scenario of a transaction system. The present invention proposes a core transaction system architecture modeling and verification method specifically designed for transaction business scenarios. Its advantage is to integrate formal modeling and verification technologies in the early stage of architecture design to discover potential errors in the design in a rigorous proof manner. Integrating trusted modeling and verification technologies in the system architecture design stage can ensure the accuracy and security of the architecture model. Through this method, developers can identify potential problems in the early stage, make timely adjustments, thereby reducing the development cycle, lowering costs, and improving the security of the system.
[0076] 2. UML dynamic model abstraction for the core transaction system and modeling of process communication and state transition. The present invention proposes a method for abstracting a dynamic system model (such as sequence diagrams and state machine diagrams) from design documents and code, aiming to solve the modeling problems of communication between processes and state transitions of cluster nodes in a transaction system. Through this method, the message passing sequence, synchronous / asynchronous communication methods between internal modules of the transaction system, and the state changes of nodes in the master election algorithm can be clarified, thereby ensuring the operability and logical consistency of the system architecture. This method can discover potential risks that cannot be found in testing and is an important technology to ensure the high availability and high security of the system.
[0077] 3. Formal Verification and Exception Analysis of the CSP Model. The present invention proposes a method for formalizing the modeling and verification of the trading system architecture based on the process algebra CSP. This method can perform strict formal verification on the architecture model of the trading system to ensure that the behavior of the system under different abnormal scenarios meets expectations. Through this method, potential defects in the architecture design can be systematically identified, and counterexamples can be automatically generated during the verification process. The detailed analysis of the counterexamples helps to accurately locate errors or vulnerabilities in the system design, providing an important basis for subsequent design optimization. This verification mechanism not only improves the security of the system architecture but also ensures that the system can always maintain stability in a complex abnormal environment, avoiding potential risks caused by architecture defects, thus providing strong protection for the security of the trading system.
[0078] It certainly has better technical effects compared with the prior art:
[0079] 1. Realize the integration of trusted modeling and verification technologies in the architecture design process to ensure the correctness and security of the system architecture model, so as to be able to detect errors in the early stage of system development, reduce development costs, and improve system security.
[0080] 2. Solve the problem of modeling the state transitions of each node during the communication process between processes and the master election process of the cluster in the trading system architecture.
[0081] 3. Support the use of the PAT validator to perform formal verification and analysis on the message communication model of the trading system architecture framework and the state transition model of the cluster master election module, be able to discover potential errors in the trading system architecture design for different abnormal scenarios, and analyze the counterexamples obtained after verifying the abnormal scenarios, thereby helping to optimize the model design to ensure system security. It has good versatility and can be extended and applied to the modeling and security verification analysis of other design modules of the trading system.
[0082] Example 1: Modeling and Verification of Thread Communication in the Core Trading System Architecture Framework
[0083] See Figures 3 to 5 .
[0084] The sequence diagram model constructed by the Modelio tool is as follows: The sequence diagram model constructed by the Modelio tool is as Figure 3As shown in the figure, the model defines eight thread entities, specifically including Event_Assembler, Pre_processor, Biz_Processor, Event_Main, Transaction_Main, Query_Processor, Transaction_Processor, and RC. The information indicated by the arrows in the figure is derived from the system code implementation and has been abstracted. Among them, the get_xx series of messages belong to the transaction collection queue request message set in the event processing framework, while the event_xx series of messages belong to the event submission message set in the main process workflow.
[0085] The construction of the CSP model is as follows: The conversion process from the sequence diagram model to the CSP model is as Figure 4 shown. During the conversion process, we defined three types of enumeration variables using the enum keyword: the request message REQ set, the event EVENT set, and the content PROTOCAL_SEND set transmitted through the UDP protocol. Then, we defined five message channels using the channel keyword, and the variable values of these channels were set to 0, indicating synchronous communication. The five message channels are Event_Assemble_Que, Call_Function, RC_Channel, Biz_Query_Que, and Self_Channel. To simulate the communication process between entities in the core trading system, we split the event processing framework into four thread entities: the event framework main thread, the event collector, the event pre-processor, and the business processor. Through the process algebra CSP, we abstracted these four thread entities into the Event_Main process, the Event_Assembler process, the Pre_Processor process, and the Biz_Processor process respectively. At the same time, the business processing framework was split into three thread entities: the transaction thread, the query thread, and the business processing thread, which were abstracted into Event_Main, Event_Assembler, Pre_Processor, and Biz_Processor respectively. In addition, the risk control cluster was abstracted into the RC process. Finally, we combined the above eight processes into the System() process using the concurrent operator ||, and ensured that the system has divergence-free and deadlock-free properties through the #assert assertion.
[0086] The analysis of the verification results is as follows: The verification results are as Figure 5 shown, and the system successfully passed the verification. According to the verification results, the time complexity of the core trading system thread communication verification process is at the millisecond level, and the space complexity is at the MB level. Specifically, as Figure 5The deadlock - free and divergence - free verification process shown above took approximately 5.2 milliseconds and occupied approximately 8.7 MB of space. Since synchronous communication is adopted between threads and the form of message content is single, the time complexity and space complexity of the verification process are relatively low.
[0087] Embodiment 2: Modeling and verification of the cluster leader - election module state machine.
[0088] Overview of the system implementation of the cluster leader - election module: According to the implementation logic of the code, we know that the implementation of the cluster leader - election module system covers two initial states: the init state and the join state. For the convenience of elaboration and analysis, this article has made necessary simplifications and abstractions, only focusing on the transition process of the init state and temporarily not considering the join state. At the same time, relevant variables such as TierStatus and the participation details of etcd have also been simplified. The state machine model constructed by the Modelio tool for the simplified system is as Figure 6 shown.
[0089] Construction of the state machine transition model and the CSP model: Through the abstraction of the specific code implementation, we extracted the state machine transition model of the cluster leader - election module. Subsequently, based on the UML state machine transition model, a CSP model was further constructed. Figure 7 shows the variable definitions in the CSP model of the leader - election algorithm. Among them, #define N 4 defines the total number of nodes in the system as 4, and #define STATENUMBER 5 defines the five possible states of each node in the system. The var statement is used to define the variables involved in the state transition logic. For example, when is_etcd_avail is true, it means that etcd is ready, and when is_masterNode_crash is false, it means that the master node has not crashed. The IfIsLeader() function is used to determine whether a certain node is a leader node. Figure 8 further details the transition conditions between each node in the leader - election algorithm.
[0090] Property specification of the cluster leader - election module: The property specification of the cluster leader - election module is as Figure 9 shown. Among them, the Initialization() function is responsible for setting all nodes to the init state, and the LeaderElection() function defines the entire process of the leader - election algorithm. The #assert assertion defines property specifications including oneLeader and stable. The oneLeader assertion is used to verify the liveness and safety of the system, ensuring that finally there is exactly one master node elected; the stable assertion is used to verify whether the system reaches a stable state, that is, whether the weight of the selected node is the maximum weight set initially (i.e., the leader - election is successful).
[0091] Analysis of verification results: The verification results are as follows Figure 10 shown, and the system successfully passes the verification. According to the verification results, the time complexity of the verification process of the cluster master selection module is at the second level, and the space complexity is at the MB level. Specifically, the active and security verification processes take about 0.5 seconds, and the space consumed is about 47.8 MB.
[0092] As mentioned above, it is only the specific implementation manner of this invention, but the protection scope of this invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by this invention, according to the technical solution and novel concept of this invention, makes equivalent replacements or changes, and should be covered within the protection scope of this invention.
Claims
1. An abstract modeling and verification method for the code implementation of a core transaction system architecture, characterized in that The method includes: A. Modeling and validating the architecture of the trading system: By extracting relevant information from the code implementation and development design documents of the architecture framework, using abstract modeling techniques to construct the behavior model of the existing system, using UML sequence diagrams to model the process communication process of the system, converting the UML sequence diagrams into a formal model of CSP to describe the communication mechanism and synchronization behavior of the system, and using the PAT validator to conduct verification and analysis of security properties; B. Modeling and validating the cluster master selection module in the trading system: Construct a state machine model for each node during the cluster master selection process to describe the state transition process of cluster master selection, construct a system dynamic model, and use the PAT validator to conduct verification and analysis of the correctness of the master selection process; The method for modeling and validating the cluster master selection module in the trading system is specifically as follows: S1. Model the cluster master selection module of the core trading system based on the UML state machine diagram, including: S11. Analyze the code implementation logic of the cluster master selection module, and abstract different working states that may occur for cluster nodes during the master selection process; S12. Deeply study the state transition logic of the nodes, and clearly define the transition conditions between different states of each node and their corresponding trigger events or operations through the UML state machine model; S13. Combine the design document and actual code implementation of the cluster master selection module, compare and verify the state machine diagram to ensure that the state machine diagram accurately reflects the actual situation of node behavior, thereby avoiding potential logical errors or inconsistencies; S2. CSP model of the cluster master selection module, including: S21. Map the state transitions and operations in the state machine diagram to event sequences in the CSP model, and combine different transition conditions through concurrent operators; S22. Considering that nodes in the cluster may fail, add a failure state to the CSP model; S23. Define property specifications in the form of assertions. The property specifications for the state machine diagram include liveness, safety, and stability; S3. Use the PAT model validator for verification. After constructing the formal CSP model, use the PAT model validator to verify the CSP model to ensure that the system meets the predefined property requirements. The properties include liveness, safety, and stability. Define the above specifications formally through the #assert assertion statement in the PAT validator to comprehensively verify the key behaviors of the model; The method for modeling and validating the cluster master selection module in the trading system further includes step S4. Optimization and feedback iteration of the CSP formal model. According to the feedback results of the PAT verification, conduct optimization and feedback to ensure that the system design can be improved in each iteration.
2. The abstract modeling and verification method for the code implementation of the core transaction system architecture according to claim 1, characterized in that, The method for modeling and validating the architecture of the trading system is specifically as follows: S1. Model the process communication process of the core trading system architecture based on the UML sequence diagram, including: S11. Identify different functional modules in the trading system architecture; S12. Model the message passing sequence, synchronous and asynchronous communication methods, and trigger conditions of trading operations between each module through the sequence diagram; S13. Ensure that the communication model described in the sequence diagram is consistent with the actual architecture of the system by comparing the design document and the actual code implementation; S2. Build a formal model of the process communication in the core trading system architecture based on CSP, including: S21. It is necessary to convert the message passing in the sequence diagram into events in CSP to ensure the accuracy and consistency of communication behavior; S22. Through the concurrent control mechanism of CSP, model the synchronization and mutual exclusion relationships among multiple trading processes in the system to ensure that the system can efficiently and correctly handle concurrent trading requests; S23. Define property specifications in the form of assertions, aiming at the property specifications of the sequence diagram model, which are deadlock - free and divergence - free; S3. Conduct model verification based on the PAT validator. After building the CSP formal model, use the PAT model validator to verify the constructed CSP model to ensure that the model meets the predefined property specifications, which include deadlock - free and divergence - free. Formalize the above - mentioned specifications by using the #assert assertion statement in the PAT validator, so as to comprehensively verify the dynamic behavior of the system.
3. The abstract modeling and verification method for the core trading system architecture code implementation according to claim 2, characterized in that The method for modeling and verifying the architecture of the trading system further includes step S4. Optimization and feedback iteration of the CSP formal model. According to the feedback results of the PAT verification, conduct optimization and feedback to ensure that the system design can be improved in each iteration.
Citation Information
Patent Citations
Extension UML-based Web application formalization modeling and verification method
CN108830085A
MBSE-based command and control system distributed simulation method
CN117193939A