System security analysis method based on complex state network

Through the method based on complex state networks, the attraction theory of finite state machine network and dissipation system is used to analyze the safety of the aircraft system, and the problem of difficulty in identifying the unsafe interactive behavior of complex systems is solved in the existing technology, and accurate analysis and early warning of system risks are achieved.

CN120030671APending Publication Date: 2025-05-23BEIHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510057420.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Existing security analysis methods are difficult to identify unsafe interaction behaviors in complex systems, and cannot guarantee the accuracy and completeness of security analysis results, especially when the interaction between multiple components is insufficiently considered during system design.

Method used

The system security analysis method based on complex state networks is adopted to characterize the state and state transfer relationship of the aircraft system through a finite state machine network, and analyze the safety boundaries of the system based on the attraction theory of the dissipation system to determine potential safety risks.

Benefits of technology

It realizes a clear analysis of the risk propagation trend of complex systems, reveals potential risks, and provides automated security analysis ideas and methods from the perspective of functional logic to avoid safety hazards from the source.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030671A_ABST
    Figure CN120030671A_ABST
Patent Text Reader

Abstract

The invention relates to a system security analysis method based on a complex state network, and belongs to the technical field of system security. The system refers to an aircraft overall system or an aircraft component system. The method comprises the following steps: constructing a finite-state machine network containing a state transition relationship based on key components of the system and a function influence relationship between the key components; forming a state vector representing the overall state of the system at a moment based on the state of each key component at the moment, determining an evolution rule of all the state vectors based on a finite state machine network, and constructing a state evolution network of the system based on the evolution rule; determining a plurality of final vectors of the overall state of the system based on the state evolution network; and determining a risk level of each final vector, and obtaining a security analysis result of the system based on the risk level and the propagation path corresponding to the final vector. According to the method, the security boundary of system state evolution is determined based on the attractor theory of the dissipation system, potential security risks of the system are obtained through analysis, and early warning and avoidance of the risks are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of system security, and in particular relates to a system security analysis method based on a complex state network. Background Art

[0002] The safety research of complex engineering systems, especially manned spacecraft, aircraft and other transportation equipment is a major and urgent topic related to personal safety.

[0003] Safety analysis and evaluation is an indispensable part of the development of aircraft systems. After a period of rapid decline in the accident rate, the safety of aircraft systems has been improved to a certain extent. However, the rapid growth of air traffic has led to a substantial increase in the number of aviation accidents. In addition, as aircraft designs become more and more complex, the difficulty of accident handling is also increasing. Therefore, it is urgent to improve the technical level of safety analysis and evaluation of flight systems.

[0004] Existing safety analysis methods, such as fault tree analysis (FTA) and failure mode and effects analysis (FMEA), mainly rely on manual experience, and the evaluation process lags behind the design. It is difficult to identify unsafe interactive behaviors in complex systems, and the accuracy and completeness of safety analysis results cannot be guaranteed. In particular, when a safety accident is not caused by the failure of a single component, but an interaction failure caused by insufficient consideration of the interaction between two or more components during system design, the existing safety analysis methods may not be able to find the cause of the accident. On the other hand, existing safety analysis methods focus more on failure modes at the physical level rather than at the functional level. Therefore, they cannot identify failures caused by unsafe interactions between functions rather than physical components. It is difficult to estimate unknown risks at the system level based on safety analysis results, and it is impossible to avoid aircraft system risks as much as possible from the source. Summary of the invention

[0005] In view of the above analysis, the present invention aims to provide a system safety analysis method based on a complex state network. Based on a finite state machine, the state evolution network of the aircraft system is deduced using the states and state transition relationships of each key component of the aircraft. Based on the attractor theory of dissipative systems, the state evolution network is used to analyze the safety boundary of the system and determine the potential safety risks of the aircraft system.

[0006] The present invention provides a system safety analysis method based on a complex state network, wherein the aircraft system is an aircraft complete system or an aircraft component system, and the aircraft component system includes an aircraft power system, an aircraft flight control system, etc.

[0007] The method of the present invention specifically comprises the following steps:

[0008] Construct a finite state machine network including state transfer relationships based on the key components of the system and the functional impact relationships between the key components;

[0009] Based on the state of each key component at a certain moment, a state vector representing the overall state of the system at that moment is formed, based on the finite state machine network, an evolution rule of all state vectors is determined, and based on the evolution rule, a state evolution network of the system is constructed;

[0010] Determine multiple final vectors of the overall state of the system based on the state evolution network; wherein the final vector refers to a vector where the state no longer transfers;

[0011] The risk level of each of the final vectors is determined, and a security analysis result of the system is obtained based on the risk level and a propagation path corresponding to the final vector.

[0012] Furthermore, the construction of a finite state machine network including a state transition relationship based on the key components of the system and the functional impact relationship between the key components includes:

[0013] Modeling each key component as a finite state machine; wherein the state of the finite state machine includes an input function state, an internal state, and an output function state;

[0014] Determine the state transfer relationship between each finite state machine based on the functional impact relationship between each key component;

[0015] Based on the state transfer relationship between the finite state machines, a directed edge connecting the finite state machines is determined, the directed edge points from the upper finite state machine to the lower finite state machine, and the output functional state of the upper finite state machine serves as the input functional state of the lower finite state machine;

[0016] The finite state machine network is constructed based on all finite state machines and directed edges.

[0017] Furthermore, the determining of the state transition relationship between the finite state machines based on the functional impact relationship between the key components includes:

[0018] Each finite state machine receives the output function state from the upper finite state machine as its own input function state, and determines whether its internal state changes with the change of the input according to the type of the input function state, where:

[0019] When the input function states are all data streams, the internal state of the finite state machine does not change with the input;

[0020] When the input function states are all physical flows, the internal state of the finite state machine changes as the input changes;

[0021] When the input functional state includes data flow and physical flow, the internal state of the finite state machine changes with the change of the physical flow input; wherein the power transfer relationship between components is defined as the physical flow; and the information or data transfer relationship between components is defined as the data flow.

[0022] Furthermore, the state vector representing the overall state of the system at a certain moment is formed based on the state of each key component at that moment, the evolution rules of all state vectors are determined based on the finite state machine network, and the state evolution network of the system is constructed based on the evolution rules, including:

[0023] Based on the internal state of each key component at a certain moment, a state vector representing the overall state of the system at that moment is formed;

[0024] Determine all possible state vectors and state transition relationships of the state vectors based on the finite state machine network;

[0025] The state evolution network of the aircraft is constructed by taking each state vector as a node and connecting each node using the state transfer relationship between each state vector.

[0026] Furthermore, the security analysis result of the system based on the risk level and the propagation path corresponding to the final vector includes forward analysis and reverse analysis, wherein:

[0027] The reverse analysis includes: determining the initial vector corresponding to each final vector based on the final vector and the corresponding propagation path, and obtaining the safety analysis result of the system based on the corresponding risk level and the state analysis of each key component in the initial vector; wherein the initial vector is the starting point vector of the state transition relationship in the state evolution network;

[0028] The forward analysis includes: determining the corresponding final vector according to the propagation path based on each initial vector of the state evolution network, and obtaining the security analysis result of the system based on the corresponding risk level and the state of each security component in the initial vector.

[0029] Further, determining the risk level of each of the final vectors includes:

[0030] Determining the risk level of the final vector based on the sum of the internal state values ​​of each key component in each final vector;

[0031] or,

[0032] The risk level corresponding to each final vector is determined based on the status of a specified key component in the final vector.

[0033] Furthermore, the internal state and output function state of the finite state machine include three states {0, 1, 2}, respectively represented as internal state S0 ={0,1,2} and output function status Y={0,1,2}; where 0 represents a fault state, 2 represents a normal working state, and 1 represents an intermediate state between normal working and fault but still able to work.

[0034] Further, the determining the risk level corresponding to the final vector based on the state of the specified key component in each final vector includes:

[0035] If the status of the specified critical component is 0, the final vector is high risk;

[0036] If the status of the specified critical component is 1, the final vector is medium risk;

[0037] If the status of the specified key component is 2, and the status of other key components are not all 2, then the final vector is low risk;

[0038] If the states of the specified key component and other key components are both 2, the final vector is safe.

[0039] Furthermore, it is characterized in that the overall aircraft system is a wing-body fusion aircraft;

[0040] The key components include an engine controller, a turboshaft engine, a generator, an inverter, a superconducting motor, a fan, a tail nozzle, an air inlet, a flight controller, a servo, an elevator and an airframe.

[0041] Furthermore, the state transition relationship between the finite state machines includes:

[0042] The input function state of the flight controller finite state machine is the output function state of the body, and its internal state does not change with the input function state;

[0043] The input function state of the servo finite state machine is the output function state of the flight controller, and its internal state changes with the input function state;

[0044] The input function state of the elevator finite state machine is the output function state of the servo and tail nozzle, and its internal state changes with the input function state;

[0045] The input function state of the airframe finite state machine is the output function state of the elevator and tail nozzle, and its internal state changes with the input function state;

[0046] The input functional state of the tail nozzle finite state machine is the output functional state of the fan, and its internal state changes with the input functional state;

[0047] The input functional state of the air intake finite state machine is the output functional state of the body, and its internal state changes with the input functional state;

[0048] The input functional state of the fan finite state machine is the output functional state of the air inlet and the superconducting motor, and its internal state changes with the input functional state;

[0049] The input functional state of the superconducting motor finite state machine is the output functional state of the inverter and the engine controller, and its internal state changes with the output functional state of the inverter;

[0050] The input functional state of the inverter finite state machine is the output functional state of the generator, and its internal state changes with the input functional state;

[0051] The input functional state of the generator finite state machine is the output functional state of the turboshaft engine, and its internal state changes with the input functional state;

[0052] The input functional state of the turboshaft engine finite state machine is the output functional state of the engine controller, and its internal state changes with the input functional state;

[0053] The input functional state of the engine controller finite state machine is the output functional state of the airframe and the turboshaft engine, and its internal state does not change with the input functional state.

[0054] The present invention can achieve at least one of the following beneficial effects:

[0055] By conducting a logical analysis of the system, determining the key components of the system and the functional impact relationships between components, using a finite state machine to represent the state of each key component and using state transition relationships to represent the functional impact relationships between components, the problem of system safety analysis caused by the large number of feedback links in complex engineering systems and the complex interaction relationships between system components is solved, and an idea and method for automated analysis from a functional logic perspective is provided.

[0056] By characterizing the working status of the entire system based on the state vectors of all key components and deducing the state evolution network of the entire system based on the finite state machine network, we can clearly analyze the risk propagation trend of the system, reveal the potential risks of complex systems, and obtain safety analysis results.

[0057] Finite state machines and state transition relationships are used to characterize the key components of a wing-body aircraft and the functional influence relationships between the components. State vectors are used to characterize the overall state of the wing-body aircraft, simplifying the complex system analysis of the wing-body aircraft into an analysis of the state evolution network. The causes of various possible accidents / safety hazards can be analyzed based on the state evolution network, and possible unknown risks can be analyzed through the propagation path of state evolution, thereby avoiding safety hazards as much as possible from the source.

[0058] Other features and advantages of the present invention will be described in the following description, and some advantages may become apparent from the description, or may be understood by practicing the present invention. The purpose and other advantages of the present invention may be realized and obtained through the contents particularly pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] The accompanying drawings are only used for the purpose of illustrating specific embodiments and are not to be considered as limiting the present invention. In the entire drawings, the same reference symbols represent the same components;

[0060] Figure 1 This is a flow chart of a method according to an embodiment of the present invention;

[0061] Figure 2 is a schematic diagram of a finite state machine according to a first embodiment of the present invention;

[0062] Figure 3 This is an example of a finite state machine network in accordance with the first embodiment of the present invention;

[0063] Figure 4 This is an example of a state evolution network according to the first embodiment of the present invention;

[0064] Figure 5 This is a method framework diagram of Embodiment 2 of the present invention;

[0065] Figure 6 This is the functional logic model of the flight control system in Embodiment 2 of the present invention;

[0066] Figure 7 This is the functional logic model of the propulsion system in the second embodiment of the present invention;

[0067] Figure 8 This is a finite state machine network of a wing-body fusion aircraft according to Embodiment 2 of the present invention;

[0068] Fig. 9 This is a state evolution network of a wing-body fusion aircraft according to the second embodiment of the present invention;

[0069] Fig.10 The second embodiment of the present invention is the state evolution network security area division;

[0070] Fig.11 This is a schematic diagram of a certain safety area in Embodiment 2 of the present invention;

[0071] Fig.12 This is the evolution process of the fan complete failure case in the second embodiment of the present invention;

[0072] Fig.13 This is the evolution process of the fan elevator jam case according to the third embodiment of the present invention. DETAILED DESCRIPTION

[0073] The preferred embodiments of the present invention are described in detail below in conjunction with the accompanying drawings, wherein the accompanying drawings constitute a part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not used to limit the scope of the present invention.

[0074] Embodiment 1

[0075] A specific embodiment of the present invention discloses a system security analysis method based on a complex state network, which specifically includes the following steps (such as Figure 1 shown):

[0076] Step S1, constructing a finite state machine network including state transfer relationships based on key components of the system and the functional impact relationships between the key components;

[0077] Step S2: based on the states of the key components at a certain moment, a state vector representing the overall state of the system at that moment is formed; based on the finite state machine network, an evolution rule of all state vectors is determined; and based on the evolution rule, a state evolution network of the system is constructed;

[0078] Step S3, determining multiple final vectors of the overall state of the system based on the state evolution network; wherein the final vector refers to a vector whose state no longer transfers;

[0079] Step S4: determine the risk level of each of the final vectors, and obtain a security analysis result of the system based on the risk level and the propagation path corresponding to the final vector.

[0080] The aircraft system described in this embodiment is an aircraft complete system or an aircraft component system, and the aircraft component system includes an aircraft power system, an aircraft flight control system, etc.

[0081] In this embodiment, a finite state machine network is used as a basis, and the state and state transition relationship of each key component of the system is used to deduce the state evolution network of the system. The final vector of the overall state is determined based on the state evolution network. According to the propagation path corresponding to the final vector, other vectors that may evolve to the final vector can be determined. The overall state of the system represented by it, that is, other vectors that may evolve to the final vector are also at the same risk level as the final vector, thereby effectively discovering potential security risks of the system.

[0082] Specifically, due to the different structural and functional characteristics of various types of aircraft, step S0 is further included before step S1:

[0083] Step S0: Determine the key components of the system and the functional impact relationships between the components based on the system design documents of the aircraft and expert experience.

[0084] During implementation, a functional logic model of the aircraft can be constructed from the perspectives of power propulsion and flight control based on the aircraft's system design documents, and multiple key components of the system and their functional impact relationships can be determined based on the functional logic model.

[0085] Specifically, in step S1, constructing a finite state machine network including a state transition relationship based on the key components of the system and the functional impact relationship between the key components includes:

[0086] Modeling each key component as a finite state machine; wherein the state of the finite state machine includes an input function state, an internal state, and an output function state;

[0087] Determine the state transfer relationship between each finite state machine based on the functional impact relationship between each key component;

[0088] Based on the state transfer relationship between the finite state machines, a directed edge connecting the finite state machines is determined, the directed edge points from the upper finite state machine to the lower finite state machine, and the output functional state of the upper finite state machine serves as the input functional state of the lower finite state machine;

[0089] The finite state machine network is constructed based on all finite state machines and directed edges.

[0090] Furthermore, determining the state transition relationship between the finite state machines based on the functional impact relationship between the key components includes:

[0091] Each finite state machine receives the output function state from the upper finite state machine as its own input function state, and determines whether its internal state changes with the change of the input according to the type of the input function state, where:

[0092] When the input function states are all data streams, the internal state of the finite state machine does not change with the change of the input; accordingly, the finite state machine is called a data stream finite state machine;

[0093] When the input function states are all physical flows, the internal state of the finite state machine changes with the change of the input; accordingly, the finite state machine is called a physical flow finite state machine;

[0094] When the input functional state includes data flow and physical flow, the internal state of the finite state machine changes with the change of the physical flow input; accordingly, the finite state machine is called a physical flow finite state machine;

[0095] Among them, the power transfer relationship between components is defined as physical flow; the information or data transfer relationship between components is defined as data flow.

[0096] Furthermore, since the present invention mainly focuses on the state of the key components themselves and the state of their inputs, and does not consider the time delay factor, a simplified Mealy state machine is used to establish a finite state machine. A 4-tuple is used to describe the finite state machine of the present invention:

[0097] M=<x t ,s t ,y t ,δ>;

[0098] Where M represents a finite state machine, and δ is a set of state transition relations, including: y t =f(s t , x t ), s t+1 =g(s t , x t ).

[0099] s t represents the internal state of the finite state machine at time t, x t is a finite set of input functional states, representing the external influences on the finite state machine, and the output functional state y t represents the response of the finite state machine at time t based on the internal state and the input function state. The transition functions f(·) and g(·) represent the state transition relationship functions. Figure 2 Schematic diagram of the finite state machine of the present invention.

[0100] Furthermore, the state transition relationship of the physical flow finite state machine is described by the following settings:

[0101]

[0102] in Represents a finite state machine M i The internal state at time t+1 is Finite State Machine M i The output function status at time t, and Represent the finite state machine M i Output function state and internal state at the initial time.

[0103] Then the set of state transition relations of the physical flow finite state machine is expressed as:

[0104]

[0105] in, It means that at time t, M i The output function state of the upper finite state machine accepted, Represents the sum of the states of these output functions.

[0106] Furthermore, the state transition relationship of the data flow finite state machine is described by the following settings:

[0107]

[0108] Then the set of state transition relations of the data flow finite state machine is expressed as:

[0109]

[0110] For example, Figure 3 The figure shows a simple finite state machine network, where M 1 、M 2 、M 3 They are key components C 1 , C 2 , C 3 The corresponding finite state machine.

[0111] When constructing the finite state machine network, the three finite state machines / key components are used as nodes, and the finite state machines are connected by edges according to the functional impact relationship. i To M j The edge of the ij It means that if e ij is a data stream, then it is recorded as If e ij is a physical flow, then Assume M 1 , M 2 , M 3 At time t, the input function state, output function state and internal state are and According to the network connection relationship, there are:

[0112]

[0113] The sets of state transition relations of the three finite state machines are expressed as follows:

[0114]

[0115] Among them, f 1 (·),f 2 (·),f 3 (·) are the state transition relationship functions of the three finite state machines respectively.

[0116] Furthermore, the finite state machine network can be expressed as:

[0117] G sys =<M(G),E(G)> ;

[0118] Among them G sys represents a finite state machine network, M(G)={M 1 , M 2 , …, M n} is the network vertex set, each vertex is a finite state machine, vertex is the corresponding finite state machine of component i, E(G)={e ij :e ji , e ij ≠e ji} is the set of directed edges in the network, e ij It is from M i To M j The directed edge of .

[0119] Specifically, step S2 includes:

[0120] Based on the internal state of each key component at a certain moment, a state vector representing the overall state of the system at that moment is formed;

[0121] Determine all possible state vectors and state transition relationships of the state vectors based on the finite state machine network;

[0122] The state evolution network of the aircraft is constructed by taking each state vector as a node and connecting each node using the state transfer relationship between each state vector.

[0123] Furthermore, using V t The state vector represents the overall state of the system at time t, Based on the state transition relationship function of each finite state machine, all possible system states are traversed to obtain all state vectors. Each state vector is regarded as a network node. The vector V t To V t+1 A directed edge is formed between them. All nodes are connected by directed edges to form the state evolution network of the aircraft, such as Figure 4 Shown is an example of a state evolution network.

[0124] Specifically, in step S3, if Figure 4 As shown, the state evolution network presents a tree-like feature, and all nodes eventually converge into multiple attractors, that is, multiple final vectors representing the overall state of the system, and the state of the final vector no longer changes. For example, Figure 4 V a is an attractor, i.e., a final vector. It should be noted that without considering component maintenance, the state evolution network of the system is a directed acyclic graph.

[0125] Specifically, in step S4, the risk level of each final vector is determined, and a security analysis result of the system is obtained based on the risk level and the propagation path corresponding to the final vector.

[0126] The principle of step S4 is described below:

[0127] like Figure 4 As shown, the model of the present invention is similar to a dissipative system. Under the action of the state transition relationship, the state evolution network of the system evolves to the final vector and no longer changes. This final vector node that no longer changes is called an attractor in the field of dynamic systems. At the same time, the network weakly connected subgroup formed by all nodes that can reach this attractor is called an attraction domain. Figure 4 Midpoint V a It is a typical attractor in the state evolution network.

[0128] Furthermore, the present invention uses whether the state of the attractor itself is safe as the criterion for dividing the safe domain and the unsafe domain. This is because the attractor first represents the final reachable node of the weakly connected sub-cluster in which it is located, that is, all nodes in the weakly connected sub-cluster will evolve to the safe state represented by the attractor. Therefore, the safe state of the attractor represents the safe state of the entire weakly connected sub-cluster. In the state evolution network, the weakly connected component represented by the attractor judged to be unsafe is regarded as the unsafe area, and the weakly connected component represented by the attractor judged to be safe is regarded as the safe area.

[0129] Therefore, the method of the present invention determines the risk level of each final vector, and then determines the security analysis result of the system based on the risk level and the propagation path corresponding to the final vector.

[0130] Further, determining the risk level of each of the final vectors includes:

[0131] The risk level of the final vector is determined based on the sum of the internal state values ​​of each key component in each final vector; that is, for an n-dimensional vector calculate a value of , based on which the risk level of the final vector is determined;

[0132] or,

[0133] Based on the state of the specified key components in each of the final vectors Determine the risk level corresponding to the final vector.

[0134] Furthermore, the safety analysis results of the aircraft are obtained based on the risk level and the propagation path corresponding to the final vector, including forward analysis and reverse analysis, where:

[0135] The reverse analysis includes: based on each of the final vectors and the corresponding propagation path, backtracking to determine each of the final vectors VEND The corresponding initial vector V 0 , based on the corresponding risk level and the initial vector V 0 The state analysis of each key component in the system obtains the safety analysis result of the system; wherein the initial vector V 0 is the starting point vector of the state transition relationship in the state evolution network;

[0136] Forward analysis includes: initial vectors V based on the state evolution network 0 Determine the corresponding final vector V according to the propagation path END , based on the final vector V END The corresponding risk level and the status of each security component in the initial vector obtain the security analysis result of the system.

[0137] This embodiment discloses a system safety analysis method based on a complex state network, which performs a logical analysis on the system, determines the key components of the system and the functional impact relationships between the components, uses a finite state machine to represent the state of each key component, and uses a state transition relationship to represent the functional impact relationship between the components. This solves the problem of system safety analysis caused by the large number of feedback links in complex engineering systems and the complex functional relationships between system components, and provides an idea and method for automated analysis from a functional logic perspective.

[0138] By characterizing the working status of the entire system based on the state vectors of all key components and deducing the state evolution network of the entire system based on the finite state machine network, we can clearly analyze the risk propagation trend of the system, reveal the potential risks of complex systems, and obtain safety analysis results.

[0139] Embodiment 2

[0140] Another specific embodiment of the present invention discloses a system safety analysis method based on a complex state network. The research object is a wing-body fusion aircraft. The method of this embodiment includes steps S20-S24 (such as Figure 5 shown).

[0141] Step S20: Determine the key components of the system and the functional impact relationships between the components based on the aircraft system design documents and expert experience.

[0142] Specifically, functional logic modeling is performed on the wing-body fusion aircraft, and logical analysis is conducted from two perspectives: the power propulsion system and the flight control system.

[0143] Specifically, for the flight control system, the function of "maintaining a level flight attitude" is taken as the analysis object. According to the operating principle of the aircraft stall, the control process of the angle of attack is a closed-loop control system. The process of controlling the angle of attack through the flight control system is mainly: command process - execution process - information feedback process, such as Figure 6 As shown. The implementation of each process depends not only on the completion of the previous process, but also on the completion of the given function of the specific component. Among them, the execution process requires the servo and the control surface (including the elevator) to work together to adjust the pitch attitude. The information feedback process reflects the process of the body collecting the current angle of attack information and returning it to the flight controller. The key components of the flight control system include the flight controller, servo, elevator and body (angle of attack part).

[0144] Specifically, Figure 7 As mentioned above, for the power propulsion system, the function of "the aircraft generates the required thrust" is taken as the analysis object. According to the thrust generation principle of the power system of the distributed wing-body fusion aircraft, the main process of the power system controlling the speed and acceleration of the aircraft is: control process-energy conversion process-external work process-feedback process. It is worth noting that there are three feedback processes in the propulsion system. The first feedback process occurs in the control process and the energy conversion process. In this process, the state data of the turboshaft engine is fed back to the engine controller to realize the work control of the turboshaft engine. The second and third feedbacks both occur in the external work link and the feedback link. Among them, the second feedback is the feedback of the speed / acceleration data and angle of attack attitude data collected by the fuselage on the intake quality of the air intake, that is, the aircraft can only ensure the stability of the airflow in the air intake at a certain speed and angle of attack. The third feedback is the information feedback collected by the fuselage. The key components of the power propulsion system include the engine controller, turboshaft engine, generator, inverter, superconducting motor, fan, tail nozzle, air intake, and fuselage (speed part).

[0145] Based on the above functional logic model, 12 key components that affect the safe flight of the wing-body fusion aircraft are summarized, including: flight controller, servo, elevator, fuselage, engine controller, turboshaft engine, generator, inverter, superconducting motor, fan, tail nozzle and air inlet.

[0146] Step S21: construct a finite state machine network including state transfer relationships based on the key components of the system and the functional impact relationships between the key components.

[0147] Specifically, 12 finite state machines are constructed based on 12 key components. The internal state and output function state of the finite state machine include three states {0, 1, 2}, which are represented as internal state S 0 ={0, 1, 2} and output function status Y={0, 1, 2}; where 0 represents a fault state, 2 represents a normal working state, and 1 represents an intermediate state between normal working and fault but still able to work.

[0148] Furthermore, in the process of constructing the finite state machine network model, the influence relationship between key components can be divided into two loops, one is the aircraft angle of attack control loop, and the other is the aircraft speed control loop.

[0149] Specifically, Figure 8 As shown in the figure, it is the finite state machine network of the wing-body fusion aircraft. It should be noted that due to the "fly-thrust coupling" characteristics of the wing-body fusion aircraft, the wake output by the tail nozzle will affect the control surface efficiency of the elevator. Figure 6 and Figure 7 The physical flow influence of the tail nozzle on the elevator is added in the integration process of the functional logic model shown.

[0150] Specifically, the state transfer relationship between the finite state machines includes:

[0151] The input function state of the flight controller finite state machine is the output function state of the body, and its internal state does not change with the input function state;

[0152] The input function state of the servo finite state machine is the output function state of the flight controller, and its internal state changes with the input function state;

[0153] The input function state of the elevator finite state machine is the output function state of the servo and tail nozzle, and its internal state changes with the input function state;

[0154] The input function state of the airframe finite state machine is the output function state of the elevator and tail nozzle, and its internal state changes with the input function state;

[0155] The input functional state of the tail nozzle finite state machine is the output functional state of the fan, and its internal state changes with the input functional state;

[0156] The input functional state of the air intake finite state machine is the output functional state of the body, and its internal state changes with the input functional state;

[0157] The input functional state of the fan finite state machine is the output functional state of the air inlet and the superconducting motor, and its internal state changes with the input functional state;

[0158] The input functional state of the superconducting motor finite state machine is the output functional state of the inverter and the engine controller, and its internal state changes with the output functional state of the inverter;

[0159] The input functional state of the inverter finite state machine is the output functional state of the generator, and its internal state changes with the input functional state;

[0160] The input functional state of the generator finite state machine is the output functional state of the turboshaft engine, and its internal state changes with the input functional state;

[0161] The input functional state of the turboshaft engine finite state machine is the output functional state of the engine controller, and its internal state changes with the input functional state;

[0162] The input functional state of the engine controller finite state machine is the output functional state of the airframe and the turboshaft engine, and its internal state does not change with the input functional state.

[0163] Furthermore, the state transition relationship of the finite state machine corresponding to the turboshaft engine, generator, inverter, steering gear, tail nozzle and air inlet is expressed as:

[0164]

[0165] Among them, G 1 (t) represents the internal state of the finite state machine at time t, G 1 (t+1) represents the internal state and output function state at the next moment, G s (t) represents the input functional state at time t, that is, the output functional state of the upper-level finite state machine.

[0166] The state transition relationship of the finite state machine corresponding to the elevator and the fuselage is expressed as:

[0167]

[0168] Among them, G 2 (t) represents the internal state of the finite state machine at time t, G 2 (t+1) represents the internal state and output function state at the next moment, G s (t) and G W (t) represent the two input functional states at time t, that is, the input functional states of the two upper-level finite state machines.

[0169] It should be noted that, according to the analysis of the functional influence relationship between the key components of the wing-body fusion aircraft, in the input functional state of the elevator finite state machine, the output functional state of the servo has a strong physical flow influence on the elevator, and the output functional state of the tail nozzle has a weak physical flow influence on the elevator. This is because according to the characteristics of the wing-body fusion aircraft, considering the functional influence of the tail nozzle on the elevator, when the tail nozzle airflow decreases, the same attitude adjustment can be achieved by increasing the angle of the elevator; strong physical flow influence and weak physical flow influence are as follows Figure 8As shown by the thick solid line and the thin solid line. Furthermore, the strong physical flow influence and the weak physical flow influence are reflected as different weight coefficients in the state transfer relationship. Similarly, the input functional state of the aircraft is also subject to strong physical flow influence and weak physical flow influence. Under the risk state, the influence of elevator failure on the adjustment of the aircraft angle of attack can be supplemented by the functions of other control surfaces, while the failure of the tail nozzle to output thrust will cause the aircraft to stall severely, and ultimately fail to provide sufficient lift and cause a major accident. Therefore, the functional influence of the elevator on the aircraft is defined as a weak physical flow influence, and the functional influence of the tail nozzle on the aircraft is defined as a strong physical flow influence.

[0170] The state transition relationship of the finite state machine corresponding to the fan is expressed as:

[0171]

[0172] Among them, G 3 (t) represents the internal state of the finite state machine at time t, G 3 (t+1) represents the internal state and output function state at the next moment, G S1 (t) and G S2 (t) represents the two input functional states at time t, that is, the input functional states of the two upper-level finite state machines.

[0173] like Figure 8 As shown, the two input function states of the fan finite state machine are both strong physical flows, so their weight coefficients in the state transfer relationship are the same.

[0174] The state transition relationship of all finite state machines of superconducting motors is expressed as:

[0175]

[0176] Among them, G m (t) represents the internal state of the finite state machine at time t, G m (t+1) represents the internal state and output function state at the next moment, G s (t) represents the input function state at time t, that is, the input function state of the upper finite state machine.

[0177] The state transition relationship of the flight controller finite state machine is expressed as:

[0178]

[0179] G d (t+1)=G d (t)

[0180] Among them, G d (t) represents the internal state of the finite state machine at time t, G d(t+1) represents the internal state at the next moment, y d (t+1) represents the output function state at the next moment, G I (t) represents the input function state at time t; Figure 8 As shown, the input functional state of the flight controller finite state machine includes a physical flow (solid line) and a data flow (dashed line).

[0181] The state transition relationship of the engine controller finite state machine is expressed as:

[0182]

[0183] G f (t+1)=G f (t)

[0184] Among them, G f (t) represents the internal state of the finite state machine at time t, G f (t+1) represents the internal state at the next moment, y f1 (t+1) and y f2 (t+1) represents the output function state at the next moment, G I2 (t) and G I1 (t) represents the input function status at time t; Figure 8 As shown, the input functional state of the engine controller finite state machine is two data streams.

[0185] Step S22: Based on the states of the key components at a certain moment, a state vector representing the overall state of the system at that moment is formed; based on the finite state machine network, an evolution rule of all state vectors is determined; and based on the evolution rule, a state evolution network of the system is constructed.

[0186] Specifically, the twelve key components are numbered, 1-12 respectively: engine controller, turboshaft engine, generator, inverter, superconducting motor, fan, tail nozzle, air intake, flight controller, steering gear, elevator, fuselage. The initial system state and the state at time t are represented by 12-dimensional vectors express.

[0187] Iterate all possible initial state vectors of the system, and the initial state vector is transferred according to the state transfer rule. All state vectors and state transfer paths constitute the state evolution network of the wing-body fusion aircraft, such as Fig. 9 The state transition network of the system consists of 3 12 =531441 nodes, where each node in the network represents a state vector and the directed edges between nodes are state transition paths.

[0188] Step S23: determining multiple final vectors of the overall state of the system based on the state evolution network; wherein the final vector refers to a vector whose state no longer transitions.

[0189] Specifically, Fig. 9 As shown, the areas of different colors in the state evolution network of the wing-body blended aircraft are attraction domains formed by different attractors. The entire network generates a total of 168 attractors, that is, 168 final vectors.

[0190] Step S24: determine the risk level of each of the final vectors, and obtain a security analysis result of the system based on the risk level and the propagation path corresponding to the final vector.

[0191] This embodiment determines the risk level corresponding to each final vector based on the state of a specified key component in the final vector.

[0192] Specifically, since the wing-body fusion aircraft is logically analyzed from the two perspectives of the power propulsion system and the flight control system, the output is finally concentrated on the fuselage. The fuselage is used as the designated key component, and the risk level corresponding to the final vector is determined by the state of the fuselage finite state machine.

[0193] Specifically, the risk levels of the 168 attractors, i.e., the final vectors, in the network are divided into four levels: high risk (body state is 0), medium risk (body state is 1), low risk (body state is 2, and there is a key component with state 1 among other key components), and safe (body state is 2 and the states of other key components are all 2), such as Fig.10 shown.

[0194] It should be noted that this risk classification method is not limited to wing-body blended aircraft, but is also applicable to other types of aircraft. Fig.10 As shown, for the wing-body fusion aircraft, it can be seen that the number of cases where the designated key component (airframe) is in state 2 (i.e., the corresponding attractors) is only four, indicating that when most other key components are in normal working state and only a few key components are out of normal working state, the designated key component can be guaranteed to be in normal working state 2. Therefore, the risk level classification method is not limited to this embodiment, and can be applied to the system safety analysis of other types of aircraft overall systems or aircraft component systems described in the present invention.

[0195] The classification of risk levels is shown in Table 1:

[0196] Table 1 Risk level classification

[0197]

[0198]

[0199] Exemplarily, this embodiment performs reverse analysis on the medium risk attractor:

[0200] Specifically, flight-engine coupling is the most obvious feature of wing-body fusion aircraft compared to traditional civil airliners. Therefore, in view of this feature, starting from the medium-risk attractors, the initial states of these attractors were traced back, and the results of simultaneous degradation of key components of the power system and key components of the flight control system were obtained. The results are shown in Table 2.

[0201] The following two security analysis results were found:

[0202] (1) The attraction domain where the degradation of a single key component of the flight control system (numbered 9-12) is coupled with the degradation of a single key component of the power system (numbered 1-8) is a medium-risk area, as shown in Table 2. In Table 2, x indicates that the state can be any of 0, 1, and 2.

[0203] Table 2 Coupling degradation results of propulsion system components and flight control system components

[0204] Initial state Attractor Initial state Attractor Initial state Attractor 1xxxxxxx1xxx 111111111111 221xxxxx21xx 221111112111 2221xxxx221x 222111112211 21xxxxxx1xxx 211111111111 2221xxxx21xx 222111112111 22221xxx221x 222211112211 221xxxxx1xxx 222111111111 22221xxx21xx 222211112111 222221xx221x 222221112211 2221xxxx1xxx 222211111111 222221xx21xx 222221112111 1xxxxxxx2221 111111112221 22221xxx1xxx 222221111111 1xxxxxxx221x 111111112211 21xxxxxx2221 211111112221 1xxxxxxx21xx 111111112111 21xxxxxx221x 211111112211 221xxxxx2221 221111112221 21xxxxxx21xx 211111112111 221xxxxx221x 221111112211 2221xxxx2221 222111112221 Initial state Attractor 22221xxx2221 222211112221 222221xx2221 222221112221

[0205] Tracing back to the initial state of the attractor (1111111111111), it is found that if the whole aircraft is in a state of functional degradation, the reason is that the flight controller and the engine controller are in a state of functional degradation at the same time. Therefore, during the design phase, the control logic of the flight controller and the engine controller must be strictly verified and designed, otherwise the aircraft may face major risks.

[0206] (2) When the critical components of the flight control system (numbers 9 to 11) degrade, the system remains in a safe state. Fig.11 As shown, there are three initial events (222222221122), (2222222221222) and (2222222221212), representing the degradation of the flight controller and servo, the degradation of the flight controller, and the degradation of the flight controller and elevator. The attractor shows that although the performance of the entire flight control system has degraded, the flight state remains stable (the aircraft is in state 2).

[0207] For example, in this embodiment, a positive analysis is performed on a fan complete failure case (windmill mode):

[0208] The corresponding initial state node is (222220222222). In the state evolution network, the attractor of the final evolution of this node, that is, the final vector, is (222210002210), which is a high-risk attractor. The evolution path is as follows Fig.12 shown.

[0209] It can be seen that when the fan fails, that is, when the component state is 0, its functional output first affects the state of the tail nozzle itself. Furthermore, the tail nozzle gradually loses its functional output, that is, the thrust gradually decreases. At this time, it can be seen that the state of the fuselage gradually changes from 2 to 0. It can be considered that the reduction in thrust output causes the aircraft's flight state to change from unstable to out of control. It can be seen here that since the fuselage will affect the input of the air inlet, as the speed of the fuselage is lost, the probability of turbulence in front of the air inlet gradually increases, and eventually causes its state to gradually change from 2 to 0. Due to the influence of the reduction in wake flow, the efficiency of the elevator will also decrease accordingly, and finally appear as state 1 in the model.

[0210] From the above analysis, we can see that the safety analysis model of wing-body fusion aircraft constructed based on complex state network accurately reflects the fault propagation process caused by the complete failure of the fan of the wing-body fusion aircraft. The safety analysis result is that the wing-body fusion aircraft cannot maintain stable cruising in the windmill mode, and this event eventually evolves into a high risk.

[0211] In practical applications, it is necessary to issue warnings in daily maintenance and flight preparation work based on the results of this safety analysis, and this event can be included as a mandatory event in the airworthiness regulations.

[0212] The present embodiment discloses a system safety analysis method based on a complex state network. It uses a finite state machine and a state transition relationship to characterize the key components of a wing-body fusion aircraft and the functional influence relationship between the components, and uses a state vector to characterize the overall state of the wing-body fusion aircraft. It simplifies the complex system analysis of the wing-body fusion aircraft into an analysis of a state evolution network, and can analyze the causes of various possible accidents / safety hazards based on the state evolution network. It can analyze the possible unknown risks through the propagation path of the state evolution, so as to avoid safety hazards as much as possible from the source.

[0213] Embodiment 3

[0214] A specific embodiment of the present invention discloses a system safety analysis method based on a complex state network. Based on the second embodiment, this embodiment performs a system safety analysis on a wing-body fusion aircraft that is undergoing a pre-flight inspection, specifically comprising the following steps:

[0215] Step S31, when performing a pre-flight inspection on the aircraft, determine the working status of all the limit state machines of each key component of the aircraft based on the inspection results; the working status includes: normal working status, fault status, and an intermediate state between normal working and fault but still able to work, represented by 2, 0, and 1 respectively.

[0216] Step S32: construct a state vector V representing the overall state of the aircraft based on the working states of all finite state machinesP .

[0217] Step S33: In the state evolution network, based on V P The corresponding final vector, i.e., the attractor, is determined, and the safety analysis result of the aircraft is obtained based on the risk level of the attractor.

[0218] Specifically, during a pre-flight inspection, it was found that the elevator was stuck, and the initial state of the elevator finite state machine was determined to be 0. At the same time, it was found that some fans of the aircraft did not rotate, and the initial state of the fan finite state machine was determined to be 1. Since the stuck elevator would affect the flight posture, the initial state of the body finite state machine was 1.

[0219] according to Fig.13 It can be seen that as the elevator stuck and the angle of attack further increased, the flight state gradually lost control, and at the same time, initial turbulence appeared in the air intake. Finally, under the influence of the large angle of attack, the aircraft's fan, tail nozzle and other propulsion system components eventually failed. This evolution process was caused by a failure in the flight control system, which eventually led to the failure of the propulsion system components. It fully reflects the characteristics of the flight-engine coupling of wing-body fusion aircraft, that is, some failures in the flight control system will eventually lead to the failure of the propulsion system. That is, the system goes from the initial state V P =(222211222202) evolves to the final vector V in the state evolution network END =(222210002200), which is a high-risk attractor.

[0220] The result of the flight inspection was that the aircraft was at high risk. Obviously, the flight mission could not be carried out before the corresponding key components were repaired or replaced.

[0221] The present embodiment discloses a system safety analysis method based on a complex state network. The working status of each key component of the aircraft is obtained through a pre-flight inspection, and a state vector representing the overall state of the aircraft is determined based on the working status. The state evolution network and the state vector are used to perform a safety analysis on the aircraft to obtain a safety analysis result. This method can effectively provide early warnings for possible risks, avoid potential flight safety hazards, and reduce flight accidents.

[0222] It should be noted that the above embodiments are based on the same inventive concept and parts not described repeatedly can be used as reference for each other.

[0223] The above description is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by any technician familiar with the technical field within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. A system safety analysis method based on a complex state network, wherein the system is an aircraft overall system or an aircraft component system, characterized in that: The steps include: Construct a finite state machine network including state transfer relationships based on the key components of the system and the functional impact relationships between the key components; Based on the state of each key component at a certain moment, a state vector representing the overall state of the system at that moment is formed, based on the finite state machine network, an evolution rule of all state vectors is determined, and based on the evolution rule, a state evolution network of the system is constructed; Determine multiple final vectors of the overall state of the system based on the state evolution network; wherein the final vector refers to a vector where the state no longer transfers; The risk level of each of the final vectors is determined, and a security analysis result of the system is obtained based on the risk level and a propagation path corresponding to the final vector.

2. The system security analysis method according to claim 1, characterized in that: The method of constructing a finite state machine network including a state transition relationship based on the key components of the system and the functional impact relationship between the key components includes: Modeling each key component as a finite state machine; wherein the state of the finite state machine includes an input function state, an internal state, and an output function state; Determine the state transfer relationship between each finite state machine based on the functional impact relationship between each key component; Based on the state transfer relationship between the finite state machines, a directed edge connecting the finite state machines is determined, the directed edge points from the upper finite state machine to the lower finite state machine, and the output functional state of the upper finite state machine serves as the input functional state of the lower finite state machine; The finite state machine network is constructed based on all finite state machines and directed edges.

3. The system security analysis method according to claim 2, characterized in that: Determining the state transfer relationship between the finite state machines based on the functional impact relationship between the key components includes: Each finite state machine receives the output function state from the upper finite state machine as its own input function state, and determines whether its internal state changes with the change of the input according to the type of the input function state, where: When the input function states are all data streams, the internal state of the finite state machine does not change with the input; When the input function states are all physical flows, the internal state of the finite state machine changes as the input changes; When the input functional state includes data flow and physical flow, the internal state of the finite state machine changes with the change of the physical flow input; wherein the power transfer relationship between components is defined as the physical flow; and the information or data transfer relationship between components is defined as the data flow.

4. The system security analysis method according to any one of claims 1 to 3, characterized in that: The state vector representing the overall state of the system at a certain moment is formed based on the state of each key component at that moment, the evolution rules of all state vectors are determined based on the finite state machine network, and the state evolution network of the system is constructed based on the evolution rules, including: Based on the internal state of each key component at a certain moment, a state vector representing the overall state of the system at that moment is formed; Determine all possible state vectors and state transition relationships of the state vectors based on the finite state machine network; The state evolution network of the aircraft is constructed by taking each state vector as a node and connecting each node using the state transfer relationship between each state vector.

5. The system security analysis method according to claim 4, characterized in that: The security analysis result of the system based on the risk level and the propagation path corresponding to the final vector includes forward analysis and reverse analysis, wherein: The reverse analysis includes: determining the initial vector corresponding to each final vector based on the final vector and the corresponding propagation path, and obtaining the safety analysis result of the system based on the corresponding risk level and the state analysis of each key component in the initial vector; wherein the initial vector is the starting point vector of the state transition relationship in the state evolution network; The forward analysis includes: determining the corresponding final vector according to the propagation path based on each initial vector of the state evolution network, and obtaining the security analysis result of the system based on the corresponding risk level and the state of each security component in the initial vector.

6. The system security analysis method according to any one of claim 5, characterized in that: Determining the risk level of each final vector includes: Determining the risk level of the final vector based on the sum of the internal state values ​​of each key component in each final vector; or, The risk level corresponding to each final vector is determined based on the status of a specified key component in the final vector.

7. The system security analysis method according to claim 6, characterized in that: The internal state and output function state of the finite state machine include three states {0, 1, 2}, respectively represented by internal state S0 = {0, 1, 2} and output function state Y = {0, 1, 2}; wherein 0 represents a fault state, 2 represents a normal working state, and 1 represents an intermediate state between normal working and fault but still able to work.

8. The system security analysis method according to claim 7, characterized in that: Determining the risk level corresponding to each final vector based on the state of a specified key component in each final vector includes: If the status of the specified critical component is 0, the final vector is high risk; If the status of the specified critical component is 1, the final vector is medium risk; If the status of the specified key component is 2, and the status of other key components are not all 2, then the final vector is low risk; If the states of the specified key component and other key components are both 2, the final vector is safe.

9. The system security analysis method according to any one of claims 1-3 and 5-8, characterized in that: The overall aircraft system is a wing-body fusion aircraft; The key components include an engine controller, a turboshaft engine, a generator, an inverter, a superconducting motor, a fan, a tail nozzle, an air inlet, a flight controller, a servo, an elevator and an airframe.

10. The system security analysis method according to claim 9, characterized in that: The state transfer relationship between the finite state machines includes: The input function state of the flight controller finite state machine is the output function state of the body, and its internal state does not change with the input function state; The input function state of the servo finite state machine is the output function state of the flight controller, and its internal state changes with the input function state; The input function state of the elevator finite state machine is the output function state of the servo and tail nozzle, and its internal state changes with the input function state; The input function state of the airframe finite state machine is the output function state of the elevator and tail nozzle, and its internal state changes with the input function state; The input functional state of the tail nozzle finite state machine is the output functional state of the fan, and its internal state changes with the input functional state; The input functional state of the air intake finite state machine is the output functional state of the body, and its internal state changes with the input functional state; The input functional state of the fan finite state machine is the output functional state of the air inlet and the superconducting motor, and its internal state changes with the input functional state; The input functional state of the superconducting motor finite state machine is the output functional state of the inverter and the engine controller, and its internal state changes with the output functional state of the inverter; The input functional state of the inverter finite state machine is the output functional state of the generator, and its internal state changes with the input functional state; The input functional state of the generator finite state machine is the output functional state of the turboshaft engine, and its internal state changes with the input functional state; The input functional state of the turboshaft engine finite state machine is the output functional state of the engine controller, and its internal state changes with the input functional state; The input functional state of the engine controller finite state machine is the output functional state of the airframe and the turboshaft engine, and its internal state does not change with the input functional state.