An airborne equipment software reliability evaluation method
By constructing an airborne equipment software reliability evaluation index system, the difficult problem of airborne equipment software reliability evaluation has been solved, comprehensive evaluation and safety hazard investigation have been achieved, and the software operation quality and safety have been improved.
Patent Information
- Application Number
- CN202411810127.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-10
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-12-10
AI Technical Summary
Existing technologies lack effective methods for reliability assessment of airborne equipment software, which makes it difficult to discover software security risks and leads to low operational reliability.
Construct an airborne equipment software reliability evaluation index system, including first-level, second-level and third-level evaluation indicators. Through data acquisition, analysis and integration, form a reliability requirement set for the purpose of troubleshooting safety hazards.
It provides a set of effective methods to comprehensively evaluate software reliability, identify security issues and risk defects, and improve software operation quality and security.
Smart Images

Figure CN119829401B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of aviation software reliability assessment, and in particular to a method for assessing the reliability of airborne equipment software. Background Art
[0002] The vast majority of airborne equipment software is embedded. Due to its unique nature within the aviation sector, it not only requires robustness against hazards and interference during operation, but also places complex design requirements on its design framework, code structure, communication module design, numerical conversion accuracy, mode transitions, and operational boundaries. Therefore, an effective and systematic evaluation method is needed to assess airborne equipment reliability. This method can then analyze failure modes and effects, provide guidance and explanation for software reliability requirements, promptly identify reliability risks, improve software operational quality, and narrow the gap between airborne equipment software design and standardization. Furthermore, this method should enhance the density of airborne equipment software reliability requirements, refine requirements capture and iteration, generate high-quality export documentation, and establish software failure and reliability data assets. However, a universal and effective method for airborne equipment software reliability evaluation currently exists. Summary of the Invention
[0003] In view of this, an embodiment of the present application provides a method for evaluating the reliability of airborne equipment software. By analyzing the reliability of airborne equipment software, it can provide instructions and guidance for obtaining software reliability requirements, so as to solve the problems of difficulty in troubleshooting safety risks of airborne equipment software and low software operation reliability.
[0004] The present invention provides a method for evaluating the reliability of airborne equipment software. The method includes:
[0005] Determine the evaluation boundaries and evaluation criteria for airborne software reliability;
[0006] Based on the evaluation boundary and the evaluation standard criteria, an airborne software reliability evaluation index system is constructed, wherein the reliability evaluation index system includes airborne equipment software reliability as a first-level evaluation index, the airborne equipment software reliability includes a plurality of second-level evaluation indicators, and each second-level evaluation indicator includes a plurality of third-level evaluation indicators;
[0007] Acquiring data of the third-level evaluation indicators for the airborne software, and analyzing the second-level evaluation indicators based on the acquired data to obtain analysis results for each second-level evaluation indicator;
[0008] Based on preset evaluation rules, integrating the analysis results of each secondary evaluation indicator to obtain an evaluation result of the reliability of the airborne equipment software;
[0009] Based on the evaluation results of the airborne equipment software reliability, an airborne software reliability requirement set is constructed, and the airborne software reliability requirement set is used to identify safety hazards of airborne software.
[0010] According to a specific implementation of an embodiment of the present application, the evaluation boundary includes a demand analysis stage, a demand iteration stage, and an export document stage.
[0011] According to a specific implementation of the embodiment of the present application, the evaluation criteria include reliance on documents, clear interfaces, independent indicators, and comprehensive reliability.
[0012] According to a specific implementation method of an embodiment of the present application, the second-level evaluation indicators include fault frequency, fault type, fault level and fault impact range. The third-level evaluation indicators in the fault frequency include mean time between failures and mean time to recovery. The third-level evaluation indicators in the fault type include data type definition error, data value abnormality, timing constraint violation, functional logic error, associated equipment failure, software and hardware coupling conflict and non-reproducible failure. The third-level evaluation indicators in the fault level include multiple severity levels. The third-level evaluation indicators in the fault impact range include the whole system range of the whole machine, the subsystem cross-linking range, the internal range of the equipment and the software itself.
[0013] According to a specific implementation of the embodiment of the present application, the data acquisition of the three-level evaluation indicators for the airborne software includes:
[0014] The three-level evaluation index data is obtained through troubleshooting means for airborne software, and the troubleshooting means include:
[0015] Check the external interfaces of the carrier on which the onboard device software runs, and describe the interface data, timing, communication, combination, and source / destination device information in a graphical or tabular manner; the external interfaces of the carrier include discrete input interfaces, analog input interfaces, discrete output interfaces, and bus input / output interfaces;
[0016] Check the execution of software functions and describe the control solution, logical conditions, task execution sequence, and software and hardware coupling relationship for software function items; the software function items include logic execution, constraints, conditions, sequence, execution of operation information, and actual processing;
[0017] Check the functional combination relationship, for the combination relationship between software functions, describe the information of concurrent execution and sequential execution between functions; the functional combination relationship is the combination and interaction relationship between specific software function implementations, including the relationship between timing, constraints, concurrency, combination and priority processing;
[0018] Check the software working mode migration situation, and describe the working status, state transition conditions, state transition path, and related functions for the software working status and mode; the software working mode migration situation refers to the various links that the airborne equipment software goes through during operation, including power-on, self-test, periodic task operation, maintenance, and power-off working mode conversion.
[0019] According to a specific implementation of the embodiment of the present application, analyzing the secondary evaluation indicators based on the acquired data to obtain analysis results for each secondary evaluation indicator includes:
[0020] Based on the acquired data, for each of the second-level evaluation indicators, the data of the third-level evaluation indicators corresponding to the second-level evaluation indicator are scored, and based on the scores, a score for each second-level evaluation indicator is obtained;
[0021] The score of each secondary evaluation indicator is used as the analysis result of each secondary evaluation indicator.
[0022] According to a specific implementation of the embodiment of the present application, scoring the data of the third-level evaluation indicator corresponding to the second-level evaluation indicator, and obtaining a score for each second-level evaluation indicator based on the score, includes:
[0023] Assigning different weights to the mean time between failures and the mean time to recovery corresponding to the failure frequency, respectively, performing weighted summation based on the acquired data to obtain a first score, and using the first score as the score of the failure frequency;
[0024] Assigning different weights to the data type definition error, the data value anomaly, the timing constraint violation, the functional logic error, the associated device failure, the software-hardware coupling conflict, and the non-reproducible failure corresponding to the fault type, respectively, and performing weighted summation based on the acquired data to obtain a second score, and using the second score as the score of the fault type;
[0025] Assigning different scores to each severity level corresponding to the fault level, analyzing the severity level corresponding to the acquired data, and using the score corresponding to the severity level as a score for the fault level;
[0026] Different scores are assigned to the entire system scope, subsystem cross-linking scope, internal scope of the equipment and software scope corresponding to the fault impact scope, and the corresponding scope in the acquired data is analyzed, and the score corresponding to the scope is used as the score of the fault impact scope.
[0027] According to a specific implementation of the embodiment of the present application, the analysis results of each secondary evaluation indicator are integrated based on the preset evaluation rules to obtain the evaluation result of the airborne device software reliability, including:
[0028] Assigning different weights to each of the secondary evaluation indicators, performing weighted summation on the analysis results of each of the secondary evaluation indicators based on the weights to obtain a total score;
[0029] The total score is used as the evaluation result of the reliability of the airborne equipment software.
[0030] According to a specific implementation of the embodiment of the present application, constructing an airborne software reliability requirement set based on the evaluation result of the airborne device software reliability includes:
[0031] Based on the evaluation results of the airborne equipment software reliability, data integration is performed according to failure modes, failure causes, failure impacts, control measures, and software reliability requirements. According to the data format requirements, each item is recorded one by one to form a complete software failure risk analysis data record, thereby forming the airborne software reliability requirement set.
[0032] Beneficial effects:
[0033] The airborne equipment software reliability assessment method in the embodiments of this application constructs a reliability index system and employs a distributed data analysis method to analyze multiple reliability aspects of airborne equipment software. This method comprehensively and comprehensively assesses software reliability, provides data support for troubleshooting software security risks, and offers an effective method for software reliability testing. This effective reliability and risk analysis method can identify most software security issues and risk defects. On this basis, combined with targeted software reliability testing, airborne equipment simulation verification, and airborne system joint testing and verification, a more comprehensive solution can be found for the security risks inherent in airborne equipment software. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0035] Figure 1 An evaluation boundary graph in an airborne device software reliability evaluation method according to an embodiment of the present invention;
[0036] Figure 2 4 is a framework diagram of an airborne software reliability evaluation index system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0037] The embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0038] The following describes the embodiments of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, in the absence of conflict, the features in the following embodiments and embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative work are within the scope of protection of this application.
[0039] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this application, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement an apparatus and / or practice a method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this apparatus and / or practice this method.
[0040] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present application. The illustrations only show components related to the present application and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.
[0041] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples. However, one skilled in the art will appreciate that the aspects described can be practiced without these specific details.
[0042] The present invention provides a method for evaluating the reliability of airborne equipment software. Figure 1 and Figure 2 The method comprises:
[0043] Step S1: Determine the assessment boundary and assessment criteria of the airborne software reliability;
[0044] Step S2: constructing an airborne software reliability evaluation index system based on the evaluation boundary and the evaluation standard criteria, wherein the reliability evaluation index system includes airborne equipment software reliability as a first-level evaluation index, the airborne equipment software reliability includes multiple second-level evaluation indicators, and each second-level evaluation indicator includes multiple third-level evaluation indicators;
[0045] Step S3: acquiring data of the third-level evaluation indicators for the airborne software, and analyzing the second-level evaluation indicators based on the acquired data to obtain analysis results for each second-level evaluation indicator;
[0046] Step S4: Based on preset evaluation rules, the analysis results of each secondary evaluation indicator are integrated to obtain an evaluation result of the airborne equipment software reliability;
[0047] Step S5: Based on the evaluation result of the airborne device software reliability, construct an airborne software reliability requirement set, and use the airborne software reliability requirement set for airborne software security risk investigation.
[0048] In this embodiment, a hierarchical evaluation index system is established for airborne equipment software reliability evaluation, with the indicators divided into primary, secondary, and tertiary evaluation indicators. Primary evaluation indicators are the evaluation targets and directly reflect the evaluation results. Secondary evaluation indicators evaluate primary evaluation indicators from various dimensions. Tertiary evaluation indicators are calculable and obtainable indicators that directly reflect the quality of secondary evaluation indicators.
[0049] This embodiment constructs a reliability index system and employs a distributed data analysis approach to analyze multiple reliability aspects of airborne equipment software. This results in a comprehensive assessment of software reliability, providing data support for troubleshooting software security risks and an effective approach for software reliability testing. This proven reliability and risk analysis method can uncover the majority of software security issues and risk defects. This approach, combined with targeted software reliability testing, airborne equipment simulation verification, and airborne system joint testing, allows for a more comprehensive solution to the inherent security risks inherent in airborne equipment software.
[0050] In one embodiment, the evaluation boundaries include the demand analysis stage, the demand iteration stage, and the export document stage; the evaluation criteria include reliance on documents, clear interfaces, indicator independence, and comprehensive reliability.
[0051] Specifically, refer to Figure 1In step S1, during airborne product software design, the most suitable stages for software reliability analysis are requirements analysis, requirements iteration, and export documentation. Conducting reliability assessments during these stages can fully account for design flaws, effectively minimizing the probability of design issues arising during subsequent testing and experimentation, and reducing maintenance costs. Given the large scale, complex logic, large number of components, and strong coupling of airborne equipment software, reliability assessments should be conducted based on the principles of "relying on documentation," "clear interfaces," "independent indicators," and "comprehensive reliability."
[0052] In one embodiment, the second-level evaluation indicators include fault frequency, fault type, fault level and fault impact range. The third-level evaluation indicators in the fault frequency include mean time between failures and mean time to recovery. The third-level evaluation indicators in the fault type include data type definition error, data value abnormality, timing constraint violation, functional logic error, associated equipment failure, software and hardware coupling conflict and non-reproducible failure. The third-level evaluation indicators in the fault level include multiple severity levels. The third-level evaluation indicators in the fault impact range include the whole system range, subsystem cross-linking range, equipment internal range and software itself range.
[0053] In this embodiment, guided by the evaluation boundaries and evaluation criteria, an airborne equipment software reliability analysis index system is constructed based on the characteristics of the airborne software itself, the defect classification method, the key requirement elements and the failure type statistics. The distributed design concept is adopted to make the evaluation indicators independent of each other. Each sub-indicator can evaluate a dimension of software reliability separately. The sub-indicators are: fault frequency, fault type, fault level and fault impact range, such as Figure 2 . According to the evaluation comparison, the reliability of airborne equipment software is a first-level indicator. Since software reliability is strongly correlated with the equipment's failure frequency, failure type, failure size, and failure impact range, and the coupling between indicators is relatively small, the failure frequency, failure type, failure level, and failure impact range are selected as second-level evaluation indicators. Specifically, the failure frequency indicator refers to the interval frequency of airborne software failures; the failure type indicator refers to the type of airborne software failures, reflecting the difficulty of troubleshooting software failures; the failure level indicator refers to the severity of airborne software failures, which is divided into major, serious, mild, and minor levels; the failure range indicator refers to the impact range of airborne software failures, which is divided into the entire system range, the subsystem cross-linking range, the equipment internal range, and the software itself range.
[0054] Regarding the selection of three-level evaluation indicators, the mean time between failures is determined by the weighted sum of the mean time between failures and the mean time to recover from failures. These two indicators can be directly obtained, so they are the three-level evaluation indicators. Similarly, the types of fault phenomena that can be directly determined, such as data type definition errors, abnormal data values, timing constraint violations, functional logic errors, key equipment failures, software-hardware coupling conflicts, and non-reproducible failures, are defined as three-level evaluation indicators, which can intuitively reflect the type of failure. In terms of the fault level, it can be divided into major, severe, mild, and minor levels as three-level evaluation indicators. These indicators can effectively reflect the severity of the fault. Finally, the entire system scope, subsystem interconnection scope, equipment internal scope, and software internal scope are selected as three-level evaluation indicators to reflect the impact range of the fault.
[0055] In one embodiment, the data acquisition of the three-level evaluation indicators for the onboard software includes:
[0056] The three-level evaluation index data is obtained through troubleshooting means for airborne software, and the troubleshooting means include:
[0057] Check the external interfaces of the carrier on which the onboard device software runs, and describe the interface data, timing, communication, combination, and source / destination device information in a graphical or tabular manner; the external interfaces of the carrier include discrete input interfaces, analog input interfaces, discrete output interfaces, and bus input / output interfaces;
[0058] Check the execution of software functions and describe the control solution, logical conditions, task execution sequence, and software and hardware coupling relationship for software function items; the software function items include logic execution, constraints, conditions, sequence, execution of operation information, and actual processing;
[0059] Check the functional combination relationship, for the combination relationship between software functions, describe the information of concurrent execution and sequential execution between functions; the functional combination relationship is the combination and interaction relationship between specific software function implementations, including the relationship between timing, constraints, concurrency, combination and priority processing;
[0060] Check the software working mode migration situation, and describe the working status, state transition conditions, state transition path, and related functions for the software working status and mode; the software working mode migration situation refers to the various links that the airborne equipment software goes through during operation, including power-on, self-test, periodic task operation, maintenance, and power-off working mode conversion.
[0061] In one embodiment, analyzing the secondary evaluation indicators based on the acquired data to obtain analysis results for each secondary evaluation indicator includes:
[0062] Based on the acquired data, for each of the second-level evaluation indicators, the data of the third-level evaluation indicators corresponding to the second-level evaluation indicator are scored, and based on the scores, a score for each second-level evaluation indicator is obtained;
[0063] The score of each secondary evaluation indicator is used as the analysis result of each secondary evaluation indicator.
[0064] In one embodiment, scoring the data of the third-level evaluation indicator corresponding to the second-level evaluation indicator and obtaining a score for each second-level evaluation indicator based on the score includes:
[0065] Assigning different weights to the mean time between failures and the mean time to recovery corresponding to the failure frequency, respectively, performing weighted summation based on the acquired data to obtain a first score, and using the first score as the score of the failure frequency;
[0066] Assigning different weights to the data type definition error, the data value anomaly, the timing constraint violation, the functional logic error, the associated device failure, the software-hardware coupling conflict, and the non-reproducible failure corresponding to the fault type, respectively, and performing weighted summation based on the acquired data to obtain a second score, and using the second score as the score of the fault type;
[0067] Assigning different scores to each severity level corresponding to the fault level, analyzing the severity level corresponding to the acquired data, and using the score corresponding to the severity level as a score for the fault level;
[0068] Different scores are assigned to the entire system scope, subsystem cross-linking scope, internal scope of the equipment and software scope corresponding to the fault impact scope, and the corresponding scope in the acquired data is analyzed, and the score corresponding to the scope is used as the score of the fault impact scope.
[0069] The following is a detailed explanation of the scoring of each secondary evaluation indicator using specific examples:
[0070] Failure frequency index D1 data analysis: The failure frequency index refers to the interval frequency of failures in the airborne software, which is obtained by the weighted sum of the mean time between failures and the mean time to recover from failures. The smaller the value, the higher the reliability.
[0071] Fault type indicator D2 data analysis: The fault type indicator refers to the type of fault that occurs in the airborne software and reflects the difficulty of troubleshooting the software. Based on the software requirement elements and software failure mode analysis criteria, the software failure mode analysis criteria and common failure data are used to analyze the possible causes of software failures for the software requirement elements. These include data type definition errors, abnormal data values, timing constraint violations, functional logic errors, hardware and software coupling conflicts, and related equipment failures. These are then quantified and assigned values. The smaller the value, the higher the reliability.
[0072] After the specific fault is found, quantitative values are assigned according to the fault type, specifically:
[0073] D2{Data type definition error}=0.15;D2{Data value abnormality}=0.3;
[0074] D2{time constraint violation}=0.15;D2{functional logic error}=0.2;
[0075] D2{software and hardware coupling conflict}=0.1; D2{associated equipment failure}=0.05;
[0076] D2{non-reproducible fault}=0.05;
[0077] Fault Level Indicator D3 Data Analysis: The fault level indicator refers to the severity of airborne software faults and is categorized as major, severe, minor, and mild. It is quantified and assigned a value, with lower values indicating higher reliability. Table 1 shows the fault level determination and quantification.
[0078] Table 1 Fault level quantification table
[0079]
[0080] Fault scope indicator D4 data analysis: The fault scope indicator value represents the impact range of an onboard software fault, divided into the entire system, the subsystem cross-linking range, the internal range of the device, and the software itself. It is quantified and assigned a value. The smaller the value, the higher the reliability. The determination and quantification of the fault impact range are shown in Table 2.
[0081] Table 2 Fault range quantification table
[0082]
[0083] In one embodiment, the analysis results of each secondary evaluation indicator are integrated based on preset evaluation rules to obtain the evaluation result of the airborne device software reliability, including:
[0084] Assigning different weights to each of the secondary evaluation indicators, performing weighted summation on the analysis results of each of the secondary evaluation indicators based on the weights to obtain a total score;
[0085] The total score is used as the evaluation result of the reliability of the airborne equipment software.
[0086] In specific implementation, for this scenario, the influence weight of the secondary evaluation indicators is set as failure frequency: failure type: failure level: failure impact range = 0.3: 0.3: 0.2: 0.2. The analysis results of the secondary evaluation indicators are weighted and summed to obtain the total reliability score of the airborne equipment, as shown in the following formula:
[0087] P=0.3·D1+0.3·D2+0.2·D3+0.2·D4,
[0088] Among them, P is the total score. According to this formula and the analysis results of the secondary evaluation indicators, a comprehensive evaluation result can be obtained.
[0089] It should be noted that the assignment of each weight and the score of each setting in the embodiment of the present application are obtained by comprehensive evaluation and calculation based on experience and actual needs.
[0090] In one embodiment, constructing an airborne software reliability requirement set based on the airborne device software reliability evaluation result includes:
[0091] Based on the evaluation results of the airborne equipment software reliability, data integration is performed according to failure modes, failure causes, failure impacts, control measures, and software reliability requirements. According to the data format requirements, each item is recorded one by one to form a complete software failure risk analysis data record, thereby forming the airborne software reliability requirement set.
[0092] Specifically, based on the evaluation results of the reliability of the airborne equipment software, the safety and failure risk of the airborne equipment software are analyzed, and according to the established airborne equipment software failure impact level, the safety and failure risk analysis results are integrated to form the airborne software reliability requirement set.
[0093] The analysis results of failure modes, failure causes, failure impacts, software failure impact levels, control measures, software safety requirements, etc. shall be recorded one by one in accordance with the failure risk analysis data format requirements to form a complete software failure risk analysis data record. The safety requirements of the airborne equipment software can be supported by analyzing the data.
[0094] The embodiment provided by the present invention comprehensively evaluates the software reliability by analyzing the failure frequency, failure type, failure level and failure range of the airborne equipment software, provides data support for troubleshooting software safety risks, and provides a set of effective methods for software reliability testing.
[0095] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for evaluating the reliability of airborne equipment software, characterized in that: The method comprises: Determine the evaluation boundaries and evaluation criteria for airborne software reliability; Based on the evaluation boundary and the evaluation standard criteria, an airborne software reliability evaluation index system is constructed, wherein the reliability evaluation index system includes airborne equipment software reliability as a first-level evaluation index, the airborne equipment software reliability includes multiple second-level evaluation indicators, each second-level evaluation indicator includes multiple third-level evaluation indicators, and the second-level evaluation indicators include fault frequency, fault type, fault level, and fault impact range; Acquiring data of the third-level evaluation indicators for the airborne software, and analyzing the second-level evaluation indicators based on the acquired data to obtain analysis results for each second-level evaluation indicator; Based on preset evaluation rules, integrating the analysis results of each secondary evaluation indicator to obtain an evaluation result of the reliability of the airborne equipment software; Based on the evaluation results of the airborne equipment software reliability, an airborne software reliability requirement set is constructed, and the airborne software reliability requirement set is used to identify safety hazards of airborne software.
2. The method for evaluating the reliability of airborne equipment software according to claim 1, wherein: The evaluation boundaries include the requirements analysis stage, the requirements iteration stage and the export document stage.
3. The method for evaluating the reliability of airborne equipment software according to claim 1, wherein: The evaluation criteria include reliance on documentation, clear interfaces, indicator independence, and comprehensive reliability.
4. The method for evaluating the reliability of airborne equipment software according to claim 1, wherein: The three-level evaluation indicators in the fault frequency include the average failure interval and the average failure recovery time; the three-level evaluation indicators in the fault type include data type definition error, data value abnormality, timing constraint violation, functional logic error, associated equipment failure, software and hardware coupling conflict and non-reproducible failure; the three-level evaluation indicators in the fault level include multiple severity levels; the three-level evaluation indicators in the fault impact scope include the entire system scope of the whole machine, the subsystem cross-linking scope, the internal scope of the equipment and the scope of the software itself.
5. The method for evaluating the reliability of airborne equipment software according to claim 1, wherein: The data acquisition of the three-level evaluation indicators for the airborne software includes: The three-level evaluation index data is obtained through troubleshooting means for airborne software, and the troubleshooting means include: Check the external interfaces of the carrier on which the onboard device software runs, and describe the interface data, timing, communication, combination, and source / destination device information in a graphical or tabular manner; the external interfaces of the carrier include discrete input interfaces, analog input interfaces, discrete output interfaces, and bus input / output interfaces; Check the execution of software functions and describe the control solution, logical conditions, task execution sequence, and software and hardware coupling relationship for software function items; the software function items include logic execution, constraints, conditions, sequence, execution of operation information, and actual processing; Check the functional combination relationship, for the combination relationship between software functions, describe the information of concurrent execution and sequential execution between functions; the functional combination relationship is the combination and interaction relationship between specific software function implementations, including the relationship between timing, constraints, concurrency, combination and priority processing; Check the software working mode migration situation, and describe the working status, state transition conditions, state transition path, and related functions for the software working status and mode; the software working mode migration situation refers to the various links that the airborne equipment software goes through during operation, including power-on, self-test, periodic task operation, maintenance, and power-off working mode conversion.
6. The method for evaluating the reliability of airborne equipment software according to claim 4, wherein: The analyzing the secondary evaluation indicators based on the acquired data to obtain analysis results for each secondary evaluation indicator includes: Based on the acquired data, for each of the second-level evaluation indicators, the data of the third-level evaluation indicators corresponding to the second-level evaluation indicator are scored, and based on the scores, a score for each second-level evaluation indicator is obtained; The score of each secondary evaluation indicator is used as the analysis result of each secondary evaluation indicator.
7. The method for evaluating the reliability of airborne equipment software according to claim 6, wherein: Scoring the data of the third-level evaluation indicator corresponding to the second-level evaluation indicator, and obtaining a score for each second-level evaluation indicator based on the score, includes: Assigning different weights to the mean time between failures and the mean time to recovery corresponding to the failure frequency, respectively, performing weighted summation based on the acquired data to obtain a first score, and using the first score as the score of the failure frequency; Assigning different weights to the data type definition error, the data value anomaly, the timing constraint violation, the functional logic error, the associated device failure, the software-hardware coupling conflict, and the non-reproducible failure corresponding to the fault type, respectively, and performing weighted summation based on the acquired data to obtain a second score, and using the second score as the score of the fault type; Assigning different scores to each severity level corresponding to the fault level, analyzing the severity level corresponding to the acquired data, and using the score corresponding to the severity level as a score for the fault level; Different scores are assigned to the entire system scope, subsystem cross-linking scope, internal scope of the equipment and software scope corresponding to the fault impact scope, and the corresponding scope in the acquired data is analyzed, and the score corresponding to the scope is used as the score of the fault impact scope.
8. The method for evaluating the reliability of airborne equipment software according to claim 1, wherein: The analysis results of each secondary evaluation indicator are integrated based on the preset evaluation rules to obtain the evaluation results of the airborne equipment software reliability, including: Assigning different weights to each of the secondary evaluation indicators, performing weighted summation on the analysis results of each of the secondary evaluation indicators based on the weights to obtain a total score; The total score is used as the evaluation result of the reliability of the airborne equipment software.
9. The method for evaluating airborne equipment software reliability according to claim 1, wherein: The step of constructing an airborne software reliability requirement set based on the airborne equipment software reliability evaluation result includes: Based on the evaluation results of the airborne equipment software reliability, data integration is performed according to failure modes, failure causes, failure impacts, control measures, and software reliability requirements. According to the data format requirements, each item is recorded one by one to form a complete software failure risk analysis data record, thereby forming the airborne software reliability requirement set.
Citation Information
Patent Citations
Reliability evaluation method, system and equipment of software system and storage medium
CN115098370A
Aviation airborne software quality evaluation method based on software full life cycle
CN115619264A