Simulation verification method and system for complex equipment system state machine diagram model

By using the KARMA language and GOPPRR-E element modeling method in complex equipment systems, a unified state machine element model is established and converted into a hybrid automata model for simulation verification, the unified description and simulation verification of state machine graph models of complex systems is solved, and efficient simulation verification and design verification are achieved.

CN120065778APending Publication Date: 2025-05-30BEIJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510248155.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The prior art is difficult to implement unified description and simulation verification of state machine graph models of complex systems, especially in cross-platform simulation verification between multiple modeling languages ​​and tools.

Method used

Through a complex equipment system state machine element model based on the KARMA language, combined with the GOPPRR-E element model, a unified state machine element model is established, and simulation semantics are extended to support continuous behavior and trigger events. The state machine graph model is then converted to a hybrid automaton model and simulated validation is performed using an integrated hybrid automaton simulation solver.

Benefits of technology

It realizes multi-language unified construction and simulation verification of complex system state machine graph models, supports the simulation of discrete events, timing systems and hybrid system behaviors, improves the correctness and rationality of the design, simplifies the simulation process and reduces the complexity between tools.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120065778A_ABST
    Figure CN120065778A_ABST
Patent Text Reader

Abstract

The invention discloses a simulation verification method and system for a state machine graph model of a complex equipment system, and belongs to the technical field of complex equipment system engineering.The simulation verification method comprises the steps that a state machine graph element model of the complex equipment system is established, and continuous behaviors in a simulation semantic description state and trigger events, condition guards and effect execution in state conversion are expanded; analyzing logic and behaviors of state conversion of the complex equipment in a certain scene, and establishing a corresponding state machine graph model according to the established state machine graph element model; checking the constructed state machine diagram model before simulation, and converting the state machine diagram model into a hybrid automaton model according to a conversion rule; and performing simulation solution on the generated hybrid automaton model through an integrated hybrid automaton simulation solver. By the adoption of the method, the technical problem that unified description and modeling to simulation verification automation of the complex system state machine diagram model are difficult to achieve can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of complex equipment system engineering, and in particular to a method and system for simulating and verifying a state machine diagram model of a complex equipment system. Background Art

[0002] Model-Based System Engineering (MBSE) is a standardized modeling method that continuously runs through the entire research and development life cycle of a system. It uses computer models to support requirements, design, analysis, verification, and validation activities of complex systems throughout the entire life cycle from conceptual design to development and subsequent maintenance. The State Machine Diagram is a model often used in the MBSE design of complex systems. It shows the logic of system operation by defining the states of the system and the transitions between states, and describes the dynamic behavior of the system through events triggered under specific conditions and changes in variables, thereby ensuring the stability and correctness of complex systems in a changing environment. Therefore, the accurate expression of the state machine diagram and the verification of its logic layer and behavior layer are crucial in the design of complex systems. Simulation Verification is a process of ensuring that the system meets performance and functional requirements during the design phase by continuously reducing errors and iteratively improving.

[0003] During the design process of complex equipment systems, by simulating and verifying the state machine diagram, designers can: 1) ensure that the system meets the established functions and performance, thereby avoiding designs that do not meet the objectives; 2) help developers, deployers, and operators understand the design requirements and grasp various information changes during the design process; 3) to a certain extent, ensure logical correctness and detect problems such as logical conflicts, deadlocks, and abnormal changes during parameter simulation.

[0004] A complex system refers to a system that exhibits complex logic and behavior in the interaction of discrete events and the continuous change of variables. They usually appear in fields such as aerospace, aviation, and automotive. With the gradual development of complex systems, the system logic becomes more complex, the interactions of various subsystems are intricate, and the system performance and functional parameters change dynamically and repeatedly. Currently, the full-life cycle design process of complex systems is often a multi-disciplinary cross-development process, usually requiring the use of multiple different types of modeling languages (such as UML, SysML, UPDM, BPMN, etc.) to build models, and for models built with different languages, the simulation tools used are often inconsistent. On the one hand, there is a lack of a language to uniformly describe the state machine diagram models of these modeling languages for subsequent simulation verification of state machine diagrams; on the other hand, the state machine diagram models designed by MBSE cannot be directly used for simulation verification and need to integrate and transform the system design model and the system simulation model (Modelica or Simulink model, etc.) across platforms for simulation verification. The accurate expression of system state transitions and the verification of state machine diagram models play a crucial role in the design of complex systems.

[0005] To address the above problems, existing technologies cover the construction of state machine diagrams of multiple modeling languages by supporting as many general modeling languages as possible, and automatically convert semi-formal state machine diagram models into executable simulation models through the establishment of corresponding mapping rules for direct simulation verification on modeling tools. Johnson et al. established model elements equivalent to Modelica based on the SysML extension mechanism and used a transformation method based on TGG (Triple Graph Grammars) to establish the mapping relationship between the meta-models of the two languages for automatic transformation. Schamai et al. extended SysML and defined new equation diagrams and simulation diagrams to construct an executable system simulation model. W. Schamai proposed a formal method for Modelica transformation of UML state machine diagrams, using the state machine diagram as a carrier for hybrid modeling of discrete and continuous behaviors and combining with continuous behaviors by adding annotations in state transitions. Takahiro Ando established a set of rules for converting SysML state machine diagrams into CSP#, and to better verify through the model checking tool PAT, added transition rules for pseudo states, thus improving the verification accuracy of SysML state machine diagrams.

[0006] Although these methods can support the simulation verification of state machine diagram models of complex systems built with specific modeling languages, for the currently increasingly large and complex systems, multiple modeling languages are needed to describe system state transitions and simulation verification needs to be carried out under the same tool. In these aspects, the above methods are difficult to meet the requirements of unified description of complex system state transition logic and simulation verification on the same platform. Currently, the following problems exist in MBSE modeling tools: 1. Modeling tools are difficult to support the unified construction of complex system state machine diagram models Currently, existing modeling tools (such as MagicDraw, Rhapsody, etc.) support multiple modeling languages (UML, SysML, UPDM, etc.), but these tools are usually limited to a certain language or model type. Different modeling languages are suitable for different system characteristics and requirements, and there are often differences in the ways, syntax, and semantics of representing state machines.

[0007] 2. Modeling tools are difficult to support the automatic conversion of state machine diagram models into simulation models Most modeling tools such as MagicDraw and Rhapsody have started to explore the automation of model conversion. However, due to the complexity of automatic conversion and the loss and misunderstanding of semantic mapping information, most cases still rely on manual conversion at present. State machine diagram models usually focus on the structure, states, and their transition relationships of the system, while simulation models emphasize dynamic behavior and time evolution. This difference makes the implementation of automatic conversion complex. Moreover, the elements in the state machine diagram model may not directly correspond to the elements in the simulation model in terms of meaning and manifestation form, resulting in the loss or misunderstanding of information during the conversion process.

[0008] 3. Modeling tools are difficult to support the direct simulation verification of state machine diagram models Most modeling tools such as MagicDraw and Rhapsody are often used in combination with simulation tools such as Matlab / Simulink or Dymola and AMESim that support Modelica for simulation analysis at the system logic level. However, this process often involves converting the state machine diagram model into a format that the simulation tool can handle. This simulation verification method not only has a strong dependence on the simulation platform but also requires high simulation professionalism, making it difficult to achieve direct simulation verification on the modeling tool.

[0009] 4. Modeling tools are difficult to support the simulation verification of most elements of state machine diagram models.

[0010] Currently, the conversion methods of most state machine diagram to simulation verification tools such as Matlab / Simulink or Dymola and AMESim that support Modelica only cover a limited subset of the state machine diagram metamodel. Few conversion methods cover most of the syntactic features of the state machine diagram, and most work covers less than 50% of the syntactic features. Summary of the Invention

[0011] The objective of the present invention is to provide a simulation verification method and system for a complex equipment system state machine diagram model, which can solve the technical problems of difficult unified description of complex system state machine diagram models and automation from modeling to simulation verification.

[0012] To achieve the above object, the present invention provides a simulation verification method for the state machine diagram model of a complex equipment system, and the steps include: S1. Based on the state changes of the complex equipment system, sort out the meta-models of various language state machine diagrams, establish a state machine diagram meta-model of the complex equipment system to uniformly describe the state transitions of the complex equipment, and extend the simulation semantics to describe the continuous behavior in the state and the trigger events, condition guards, and effect executions in the state transitions; S2. Analyze the logic and behavior of the state transitions in a certain scenario of the complex equipment, and establish a corresponding state machine diagram model according to the constructed state machine diagram meta-model; S3. Before simulation, check the constructed state machine diagram model to ensure that various models of the state machine diagram meet the design standards, and convert the state machine diagram model into a hybrid automaton model according to the conversion rules; S4. Through the integrated hybrid automaton simulation solver, perform simulation and solution on the generated hybrid automaton model to realize the simulation of discrete events, timed systems, and hybrid system behaviors.

[0013] Preferably, in step S1, based on the GOPPRR-E meta-modeling method, sort out the meta-models of various language state machine diagrams, and establish a state machine diagram meta-model of the complex equipment system based on the KARMA language. The GOPPRR-E meta-modeling includes a graph meta-model, an object meta-model, a relationship meta-model, an endpoint meta-model, a role meta-model, and an attribute meta-model. Among them, the graph meta-model is the state machine diagram, and the object meta-model includes: simple state, composite state, submachine state, initial pseudo-state, branch pseudo-state, merge pseudo-state, select pseudo-state, connection pseudo-state, and end pseudo-state; the relationship meta-model includes a transition relationship; the endpoint meta-model includes an entry point pseudo-state and an entry / exit point pseudo-state; the role meta-model includes a transition start end and a transition end; the attribute meta-model includes a name, an entry action, an execution action, and an exit action.

[0014] Preferably, the state machine diagram meta-model is used to construct the state machine diagram of the complex equipment, describe the states that the complex equipment can appear, the transitions between states, and the behaviors existing in the states; the object meta-model simple state is used to construct the basic state of the system, the object meta-model composite state is used to construct a complex state composed of multiple sub-states to help construct a hierarchical state structure, the object meta-model submachine state is used to construct a nested state machine, allowing an independent state machine to be defined in the submachine state, and the object meta-model initial pseudo-state, branch pseudo-state, merge pseudo-state, select pseudo-state, connection pseudo-state, and end pseudo-state are used to control the flow and decision-making logic of the state machine; the relationship meta-model is used to construct the transitions between states; the endpoint meta-model entry point pseudo-state and entry / exit point pseudo-state are used to construct the initial and end operations when entering and exiting a composite state or a sub-state machine.

[0015] Preferably, in step S1, semantic extension of simulation is performed on the object meta-model and relationship meta-model in the state machine diagram meta-model, and discrete and continuous changes are placed in each element of the model. Among them, a variable assignment mechanism is added to all state object meta-models to represent continuous changes within the state, and the type of the state is clarified to represent various types of states. For the relationship meta-model, semantics of trigger events, variable guard conditions, and instantaneous variable changes are added to represent trigger events, jump guard conditions, and execution effects respectively.

[0016] Preferably, in step S2, establishing a corresponding state machine diagram model according to the established state machine diagram meta-model includes: Identifying and defining the possible states that may occur during the operation of the complex equipment system and instantiating them into simple states; Combining related states into composite states to simplify the multi-level state structure; Using pseudo-states to optimize the description of the logic of state transitions; Determining the state transitions of the complex equipment system from one state to another.

[0017] Preferably, in step S3, converting the state machine diagram model into a hybrid automaton model according to the conversion rules includes: Sorting out the conversion relationships between the elements of the state machine diagram model and the hybrid automaton model, and combining the simulation meaning of the state machine diagram model to establish the semantic conversion rules between the two; Inputting the established state machine diagram, and based on the state machine diagram modeling specification, performing model checking on various states and transitions of the state machine diagram; Converting various elements of the established state machine diagram model of the complex equipment system containing discrete and continuous changes into the elements of the corresponding hybrid automaton simulation model according to the semantic conversion rules.

[0018] The present invention also provides a simulation verification system for a state machine diagram model of a complex equipment system, including a data layer, a function layer, and an application layer; the data layer is used to encapsulate and store multi-architecture modeling language KARMA data and hybrid automaton simulation model data; the function layer obtains the data encapsulated by the data layer, including a state machine diagram model construction module, a hybrid automaton model conversion module, and a hybrid automaton solver module, and the application layer interacts with the user, including a state machine diagram model selection module and a simulation solution and simulation information display module.

[0019] Preferably, the function layer specifically includes: The state machine diagram model construction module includes a model instantiation sub-module and a simulation semantics input sub-module; the instantiation sub-module instantiates the simple states, composite states, sub-machine states, initial pseudo-states, branch pseudo-states, merge pseudo-states, choice pseudo-states, junction pseudo-states, final pseudo-states and transition metamodels of the state machine diagram; the simulation semantics input sub-module is used to input simulation semantics information describing the continuously changing behavior of complex equipment into the instantiated object metamodel and input simulation semantics information describing the discrete instantaneous changing behavior of complex equipment into the relationship metamodel; The hybrid automaton model conversion module includes a construction model detection sub-module and an automatic conversion sub-module; the construction model detection sub-module checks the model before simulation; the automatic conversion sub-module reads the semantic information in the state machine diagram model, on the one hand maps the conversion rules between various instantiated metamodels in the state machine diagram and related elements of the hybrid automaton simulation model, and on the other hand maps according to the simulation semantics input in the state machine diagram model and the conversion rules of related elements of the hybrid automaton simulation model, and finally generates the corresponding hybrid automaton simulation model; The hybrid automaton solving module calls the integrated hybrid automaton simulation solver, configures the parameters related to the simulation according to the settings, and performs the simulation solving of the hybrid automaton model.

[0020] Preferably, the application layer specifically includes: The state machine diagram model selection module calls the hybrid automaton model conversion module according to the selected state machine diagram model to be compiled, and generates the corresponding hybrid automaton model; The simulation solving performs relevant simulation configurations on the hybrid automaton model generated by the state machine diagram model selection module, calls the hybrid automaton solver module for simulation, and solves the data of the hybrid automaton model in real time; The simulation information display module visually displays the current state of the model and the corresponding changes of the set variables to the user.

[0021] Therefore, the present invention adopts the above-mentioned simulation verification method and system for the state machine diagram model of a complex equipment system, and has the following beneficial effects: (1) Based on the state machine diagram metamodel of the complex equipment system in the KARMA language, the present invention can customize the modeling language in combination with the logical architecture of the complex system, support the unified construction of multiple languages for the logical architecture model of the complex system, and thus solve the semantic heterogeneity problem of the state machine diagram model of the complex system; (2) By establishing the conversion rules between each meta-model in the complex equipment state machine diagram model and the elements of the hybrid automata simulation model, the present invention supports the automatic conversion of the state machine diagram model into a simulation model, thereby realizing the inspection of the system state transition logic design and behavior design, and to a certain extent, avoiding the deadlock and contradictory design problems in the logic design, thus improving the correctness and rationality of the design; (3) The simulation verification of the state machine diagram model of the present invention does not require starting other simulation verification tools, simplifies the simulation process, reduces the complexity of tool switching and data transfer. By integrating the hybrid automata simulation solver, the system can quickly run the generated simulation model and present the dynamic behavior of the model in real time. Users can intuitively view key information such as the running mode, state transition, and event trigger to ensure that every detail of the design is fully verified.

[0022] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Description of the Drawings

[0023] Figure 1 It is a schematic flow diagram of a method for supporting the simulation verification of the state machine diagram of the complex equipment system MBSE according to an embodiment of the present invention; Figure 2 It is a schematic working principle diagram of the state machine diagram model construction based on GOPPRR-E according to an embodiment of the present invention; Figure 3 It is a schematic diagram of the KARMA discrete and continuous change simulation semantic extension according to an embodiment of the present invention; Figure 4 It is a schematic flow diagram of the complex system logic architecture modeling and simulation verification according to an embodiment of the present invention; Figure 5 It is a schematic working principle diagram of the semantic conversion from the state machine diagram model to the hybrid automata model according to an embodiment of the present invention; Figure 6 It is a system architecture diagram according to an embodiment of the present invention; Figure 7 It is a diagram showing the simulation verification result of the logic architecture model according to an embodiment of the present invention. Specific Embodiments

[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. The components of the embodiments of the present invention generally described and illustrated in the drawings herein can be arranged and designed in a variety of different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0025] Embodiment Refer to Figure 1 , the present invention provides a simulation verification method for the state machine diagram model of a complex equipment system, and the steps include: S1. Based on the state changes of the complex equipment system, sort out the relevant fields of state machine diagrams in various languages (such as SysML, UML, UPDM), summarize and analyze the description of the system state machine diagram model, and aggregate the basic elements of state machine diagram knowledge in different languages. Combine the GOPPRR-E meta-modeling method to establish a state machine diagram meta-model of the complex equipment system based on the KARMA language to uniformly describe the state transition of the complex equipment, and extend the simulation semantics to describe the continuous behavior in the state and the trigger events, condition guards, and effect executions in the state transition. Specifically: Refer to Figure 2 , according to the GOPPRR-E meta-modeling method (including the graphic meta-model, object meta-model, relationship meta-model, endpoint meta-model, role meta-model, and attribute meta-model), summarize and analyze the model specifications of state machine diagrams in multiple modeling languages, and then construct a unified meta-model related to state machine diagrams based on multiple modeling languages.

[0026] The graphic element model is a state machine diagram, which is used to construct the state machine diagram of complex equipment, and describe the possible states of complex equipment, the transitions between states, and the behaviors existing in the states. The object meta-model includes: simple state, composite state, submachine state, initial pseudo-state, branch pseudo-state, join pseudo-state, choice pseudo-state, connection pseudo-state, and end pseudo-state, which are used to construct the basic states of the system. The composite state of the object meta-model is used to construct complex states composed of multiple sub-states, and helps to construct a hierarchical state structure. A composite state is a state that contains at least one region, which can be divided into a simple composite state and an orthogonal composite state. The region, as a container for states and transitions, organizes a group of states together to form a new state machine. The submachine state is used to construct nested state machines, allowing an independent state machine to be defined within the submachine state. In this architecture, the simple composite state and the orthogonal composite state represent the visible nested state machine diagram through "section" expansion, while the submachine state represents the invisible nested state machine diagram through "decomposition" expansion. The initial pseudo-state, branch pseudo-state, join pseudo-state, choice pseudo-state, connection pseudo-state, and end pseudo-state are used to control the flow and decision-making logic of the state machine. The relationship meta-model includes transition relationships, which are used to construct the transitions between states. The endpoint meta-model includes entry point pseudo-states and entry / exit point pseudo-states, which are used to construct the initial and end operations when entering and exiting a composite state or a sub-state machine. The role meta-model includes transition start and transition end. The attribute meta-model includes name, entry action, execution action, and exit action.

[0027] Refer to Figure 3 , in order to more accurately express the dynamic behaviors in the state machine diagram, various object meta-models and relationship meta-models in the state machine diagram are extended, and the description of simulation semantics is introduced, placing discrete and continuous changes in each element of the model. These extensions include the definition of continuous changes within the state, trigger events during the transition process, jump guard conditions, and execution effects. The state machine diagram meta-model is enriched by adding the semantics of event declaration and variable declaration, adding a variable assignment mechanism to all state object meta-models to represent continuous changes within the state, and clarifying the types of states to characterize various states. For the relationship meta-model, the semantics of trigger events, variable guard conditions, and variable instantaneous changes are further extended to represent trigger events, jump guard conditions, and execution effects respectively.

[0028] S2. Analyze the logic and behaviors of state transitions in a certain scenario of complex equipment, and establish a corresponding state machine diagram model according to the constructed state machine diagram meta-model. Specifically, it includes: Identify and define the possible states that may occur during the operation of the complex equipment system, and instantiate them as simple states; Combine relevant states into composite states, simplify the multi-level state structure, and ensure that each state can reflect the true behaviors and functions of the equipment at this stage; Use pseudo-states to optimize the logic for describing state transitions; Determine the state transitions of a complex equipment system from one state to another, i.e., the triggering events or conditions for transitioning from one state to another, and describe them using triggering events or variable guards.

[0029] S3. Before simulation, check the constructed state machine diagram model to ensure that various models of the state machine diagram meet the design standards. According to the conversion rules, convert the state machine diagram model into a hybrid automaton model. Specifically: Refer to Figure 4 and Figure 5 to sort out the conversion relationships between the elements of the state machine diagram model and the hybrid automaton model. Combining the simulation significance of the state machine diagram model, establish the semantic conversion rules between the two. Input the established state machine diagram. Based on the state machine diagram modeling specifications, conduct model checks on various states and transitions of the state machine diagram; convert the various elements of the constructed state machine diagram model of a complex equipment system with discrete and continuous changes into the corresponding elements of a hybrid automaton simulation model (Hybrid Automaton, HA) according to the semantic conversion rules. The hybrid automaton is mainly composed of eight meta-models, namely Location, Edge, X, Init, Inv, Flow, Jump, and Event. The state machine diagram consists of one or more state machines StateMachine, and each state machine StateMachine corresponds to a hybrid automaton Hybrid Automaton; all states in the state machine diagram, including ordinary states and pseudo-states State or Pseudo State, are represented by location. In addition, the transitions Transition in the state machine diagram include intra-layer transitions and cross-layer transitions: Intra-layer transitions are the connections of transition relationships within the same state machine and are directly represented by edge in the hybrid automaton; Cross-layer transitions are the connections of transition relationships across state machines and need to trace back to the state machines to which these cross-layer states belong and the state machines to which the state machines belong. The triggering event EventDeclare in the state machine diagram corresponds to Event in the hybrid automaton, and the variable VariableDeclare corresponds to X or Inv in the hybrid automaton; the continuous change EquationClause of the variable in the state corresponds to Flow in the hybrid automaton, and the initial identifier InitialClause corresponds to Init in the hybrid automaton; the triggering TriggerClause of the event in the transition corresponds to Event in Jump in the hybrid automaton, the guard condition GuardClause of the variable corresponds to When in Jump in the hybrid automaton, and the discrete change EffectClause of the variable corresponds to do in Jump in the hybrid automaton.

[0030] S4. Use the integrated hybrid automaton simulation solver to perform simulation and solution on the generated hybrid automaton model, realizing the simulation of discrete events, timed systems, and the behavior of hybrid systems. During the simulation process, it can display the changes of each state in the state machine diagram in real time, track the changes of the set variables, and dynamically generate variable change curves. Among them, the hybrid automaton simulation solver is a hybrid automaton model with the theory of algebraic differential equations, which is used to simulate the computational and physical behavior of the system.

[0031] Referring to Figure 6 , the present invention also provides a simulation and verification system for the state machine diagram model of a complex equipment system, including a data layer, a function layer, and an application layer.

[0032] The data layer is used to encapsulate and store multi-architecture modeling language KARMA data and hybrid automaton simulation model data. The KARMA data provides support for the model construction module in the function layer. When constructing the state machine diagram model, it is responsible for storing model data and simulation semantic information; the hybrid automaton simulation model data provides support for the function layer, which is used to visually display the solution results of the hybrid automaton simulation solver and receive the current execution state and dynamic changes of the model in real time during the simulation.

[0033] The function layer obtains the encapsulated data of the data layer, constructs the state machine diagram model of the complex equipment system, and converts the hybrid automaton simulation model corresponding to the state machine diagram model. Finally, it performs simulation verification on the converted hybrid automaton simulation model through the integrated hybrid automaton simulation solver, including a state machine diagram model construction module, a hybrid automaton model conversion module, and a hybrid automaton solver module.

[0034] The state machine diagram model construction module is used to describe information such as the operation mode, state transition, and event trigger of the system, show the behavior process of the complex equipment system and the changes between states. Combining the actual usage scenarios, for each operating condition and event, define the possible trigger conditions for the state transition of the complex system, the corresponding state changes, and the execution behavior. The state machine diagram model construction module includes a model instantiation sub-module and a simulation semantic input sub-module. The instantiation sub-module creates, edits, and constructs the state machine diagram model of the complex equipment system through the user interface, and can instantiate meta-models such as simple states, composite states, sub-machine states, initial pseudo-states, branch pseudo-states, convergence pseudo-states, selection pseudo-states, connection pseudo-states, end pseudo-states, and transitions of the state machine diagram. The simulation semantic input sub-module is used to input simulation semantic information describing the continuously changing behavior of the complex equipment in the instantiated object meta-models such as simple states, sub-machine states, and composite states, including continuous variable changes, and input simulation semantic information describing the discrete instantaneous change behavior of the complex equipment in the relational meta-relationship model, including trigger events, variable conditions, and instantaneous discrete changes of variables required for state jumps.

[0035] The hybrid automaton model conversion module is used to identify the model and simulation semantics in the state machine diagram model, and convert them one by one into elements such as states, variables, and transition conditions corresponding to the hybrid automaton.

[0036] The hybrid automaton model conversion module includes a model detection sub-module and an automatic conversion sub-module. The model detection sub-module is used to perform model checks before simulation to timely discover and eliminate non-standard modeling problems in the state machine diagram model, avoiding the inability to convert to a correct simulation model due to non-standard models. The automatic conversion sub-module reads the semantic information in the state machine diagram model. On the one hand, it maps the conversion rules of various instantiated meta-models in the state machine diagram, including simple states, composite states, sub-machine states, initial pseudo-states, branch pseudo-states, merge pseudo-states, choice pseudo-states, junction pseudo-states, end pseudo-states, and transitions, to the relevant elements of the hybrid automaton simulation model. On the other hand, it maps according to the simulation semantics input by the state machine diagram model and the conversion rules of the relevant elements of the hybrid automaton simulation model, and finally generates the corresponding hybrid automaton simulation model.

[0037] The hybrid automaton solving module calls the integrated hybrid automaton simulation solver, configures the parameters related to the simulation according to the settings, and performs the simulation and solution of the hybrid automaton model. This module ensures the accuracy and efficiency of the simulation process, can dynamically adjust the simulation settings according to the needs of the model, and guarantees the accurate simulation and analysis of complex systems.

[0038] The application layer interacts with the user, including the state machine diagram model selection module and the simulation solution and simulation information display module.

[0039] The state machine diagram model selection module includes an automatic conversion button for the simulation model and a front-end for selecting the state machine diagram model. By clicking the button, according to the selected state machine diagram model to be compiled, it calls the hybrid automaton model conversion module to generate the corresponding hybrid automaton model.

[0040] The simulation solution includes a simulation solution button and a front-end for selecting the simulation model. By clicking the button, it performs relevant simulation configurations on the hybrid automaton model generated by the state machine diagram model selection module, calls the hybrid automaton solver module for simulation, and obtains the data of the real-time solution of the hybrid automaton model.

[0041] The simulation information display module receives the data of the real-time solution of the hybrid automaton model and visually displays the current state of the model and the corresponding changes in the set variables to the user.

[0042] To verify the effectiveness of the method of the present invention, the star-rocket separation process is used as the modeling object for illustration.

[0043] S1. Based on the state changes of complex equipment systems, sort out the meta-models of various language state machine diagrams, and establish a unified description of the state machine diagram meta-model of complex equipment systems based on the KARMA language in combination with the GOPPRR-E meta-modeling method to describe the state transitions of complex equipment, and expand the simulation semantics to describe the continuous behavior in the state and the trigger events, condition guards, and effect executions in the state transitions.

[0044] S2. Refer to Figure 7 , analyze the state process of the satellite-rocket separation process, which occurs after the rocket sends the satellite into the predetermined orbit, the upper stage propulsion phase of the rocket completes the task, and the satellite is released from the payload bay of the rocket and enters the independent operation state. Satellite-rocket separation usually relies on precise mechanical devices and strict time control to ensure that the satellite safely and stably detaches from the rocket and avoid any accidental failures. The inputs include the states such as payload installation of the satellite, verticality adjustment, azimuth adjustment, parameter binding, ignition flight, control breakpoint, termination of flight, vertical flight, turning, turning judgment, whether the time exceeds the set value, safety control, safety self-destruction, etc., and the state transitions such as whether the ignition condition is met, whether a failure occurs, and whether the time exceeds the set value. Based on the state machine diagram related meta-model constructed in step S1, construct the state machine diagram model of satellite-rocket separation, and input the above conditions (such as ignition condition, fault detection, time overrun, etc.) as discrete events in the simulation semantics into the model. Specifically, it includes: Analyze the various states existing in the satellite-rocket separation process, and construct the state machine diagram model of the satellite-rocket separation process based on the model construction module in the system. Open the model canvas and instantiate the objects in the state machine diagram meta-model, such as "initial pseudo-state" and "state", "composite state", etc. through the way of dragging and dropping. Analyze the satellite-rocket separation process to obtain various states, including the initial pseudo-state, payload installation state, verticality adjustment state, azimuth adjustment state, parameter binding state, allow ignition selection pseudo-state, ignition flight state, control breakpoint state, termination pseudo-state, vertical flight combined state, safety control state, safety self-destruction state, detect fault flight combined state, separation state, final pseudo-state. There is a new sub-state machine inside the vertical flight combined state, which includes an initial pseudo-state, a vertical flight state, a turning state, a whether to turn selection pseudo-state, and an event meets 32s selection pseudo-state; the detect fault flight combined state contains two new sub-state machines, the detect fault sub-state machine includes an initial pseudo-state and a fault detection state, and the flight sub-state machine includes an initial pseudo-state and a flight state. Each state is connected through the relationship of transition. The transitions output by each selection pseudo-state connect two states, and the states in some sub-state machines are connected across layers. Finally, complete the construction of the model, and the output is the preliminary model of the state machine diagram of the satellite-rocket separation process.

[0045] Based on the preliminary architecture model of the state machine diagram for the satellite-rocket separation process, analyze various behaviors in the states and transitions of the satellite-rocket separation process. Build modules based on the state machine diagram model in the system and expand the behavior information on the preliminary model of the state machine diagram for the satellite-rocket separation process. Open the model and add trigger events and execution effects in the transition relationships. Specifically: In the transition with the pseudo-state of allowing ignition selection as the input and the ignition flight state as the output, set the trigger event as "satisfy ignition" and the execution effect as the boolean variable "satisfy ignition condition" being true, with the default being false; In the transition with the pseudo-state of allowing ignition selection as the input and the control breakpoint state as the output, set the trigger event as "do not satisfy ignition" and the execution effect as the boolean variable "satisfy ignition condition" being false; In the transition with the pseudo-state of whether to turn as the input and the detected fault flight combination state as the output, set the trigger event as "turn occurs" and the execution effect as the boolean variable "turn occurs" being true, with the default being false; In the transition with the pseudo-state of whether to turn as the input and the event satisfy 32s selection pseudo-state as the output, set the trigger event as "no turn occurs" and the execution effect as the boolean variable "turn occurs" being false; In the transition with the pseudo-state of whether to turn as the input and the turn state as the output, set the trigger event as "time is less than 32s", and the guard condition as the boolean variable "turn occurs" being equal to false; In the transition with the pseudo-state of whether to turn as the input and the safety control state as the output, set the trigger event as "time is greater than 32s"; In the transition with the pseudo-state of whether to turn as the input and the safety control state as the output, set the trigger event as "time is greater than 42s"; In the transition with the fault detection state as the input and the safety self-destruction state as the output, set the trigger event as "fault occurs"; In the transition with the detected fault flight combination state as the input and the separation state as the output, set the trigger event as "reach the specified time". The final output is the state machine diagram model of the satellite-rocket separation process with simulation semantics.

[0046] S3. Traverse each model in the state machine diagram of the satellite-rocket separation process, check according to the simulation meaning and modeling rules, and promptly display the errors and non-standard warnings in the model to ensure that the use of all models complies with the modeling specifications. Through the meta-model of the state machine diagram, the simulation semantics, and the conversion rules of each element of the hybrid automaton, the state machine diagram model of the satellite-rocket separation process is converted into an executable hybrid automaton model. In the state machine diagram of the satellite-rocket separation process, there are simple states such as payload installation state, verticality adjustment state, azimuth angle adjustment state, parameter binding state, ignition flight state, control break point state, etc., as well as composite states such as vertical flight combination state, fault detection flight combination state, etc. At the same time, there are also pseudo-states such as initial pseudo-state, final pseudo-state, selection pseudo-state, and termination pseudo-state. Each state corresponds to a Location in the hybrid automaton, where the initial pseudo-state also needs to correspond to the Init of the hybrid automaton, and no Edge can be added to the Location corresponding to the final pseudo-state and the termination pseudo-state. Multiple transitions of the selection pseudo-state correspond to multiple Edges in the hybrid automaton. For state transitions across layers, special processing is required: first, determine the composite states to which the start and end states of the transition belong, and then generate the corresponding transitions in the main state machine diagram and the sub-state machine diagram respectively, so as to realize the mapping of pseudo-states and multi-layer nested complex logic to the hybrid automaton model. Among them, the simulation semantics added as trigger events include: "ignition satisfied", "ignition not satisfied", "turn occurred", "turn not occurred", "time greater than 32s", "time less than 32s", corresponding to the Event in the hybrid automaton; the simulation semantics added as guard conditions include: judge whether the boolean variable "turn occurred is satisfied" is false before entering the turning state, corresponding to When in the Jump of the hybrid automaton; the simulation semantics added as execution effects include: the boolean variable "ignition condition satisfied" is true when entering the ignition flight state, the boolean variable "ignition condition satisfied" is false, "turn occurred", and the boolean variable "turn occurred" is true when entering the fault detection flight combination state, corresponding to Do in the Jump of the hybrid automaton. Through the hybrid automaton model conversion module, the state machine diagram model of the satellite-rocket separation process is finally automatically converted into an executable hybrid automaton model.

[0047] Step S4: By invoking the integrated hybrid automaton simulation solver, directly run the simulation on the hybrid automaton model of the automatically converted satellite-rocket separation process in the modeling tool. During the simulation process, map the simulation data to the state machine diagram model of the satellite-rocket separation process in real time, and display the changes of each state in the state machine diagram in real time. When in the pseudo-state allowing ignition selection, if the triggering event is "ignition satisfied", enter the ignition flight state; if the triggering event is "ignition not satisfied", enter the control break point state, and finally enter the termination pseudo-state, indicating the failure of satellite-rocket separation. When in the pseudo-state of whether to turn selection, if the triggering event is "no turn occurred", enter the pseudo-state of event satisfaction 32s selection to continue the judgment; if the triggering event is "turn occurred", enter the fault flight combination state. When in the pseudo-state of time satisfaction 32s selection, if the triggering event is "time less than 32s" and the guard condition boolean variable "turn occurred" is false, return to the turn state to re-judge; if the triggering event is "time greater than 32s" and "turn occurred" is false, enter the safety control state, and finally enter the termination pseudo-state, indicating the failure of satellite-rocket separation. When in the fault flight combination state, if the triggering event is "fault occurred", enter the safety control state, and finally enter the termination pseudo-state, indicating the failure of satellite-rocket separation; if the triggering event is "specified time reached", enter the separation state, and finally enter the final state to complete the simulation of the entire permission process.

[0048] Therefore, the present invention adopts the above-mentioned simulation verification method and system for the state machine diagram model of a complex equipment system, which can support the automatic conversion of the state machine diagram model of a complex equipment system described in multiple modeling languages to a hybrid automaton simulation model, as well as the modeling standardization check and simulation verification of the state machine diagram model.

[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that they can still modify or equivalently replace the technical solutions of the present invention, and these modifications or equivalent replacements cannot make the modified technical solutions deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A simulation verification method for a complex equipment system state machine diagram model, characterized in that the steps include: S1. Based on the state changes of complex equipment systems, the metamodels of state machine diagrams in various languages ​​are sorted out, and the state machine diagram metamodel of complex equipment systems is established to uniformly describe the state transitions of complex equipment, and the simulation semantics is extended to describe the continuous behavior in the state and the trigger events, condition guards, and effect execution in the state transitions; S2. Analyze the logic and behavior of state transition in a certain scenario of complex equipment, and establish a corresponding state machine graph model based on the constructed state machine graph metamodel; S3. Check the constructed state machine diagram model before simulation to ensure that various models of the state machine diagram meet the design standards, and convert the state machine diagram model into a hybrid automaton model according to the conversion rules; S4. Through the integrated hybrid automaton simulation solver, the generated hybrid automaton model is simulated and solved to realize the simulation of discrete events, timing systems and hybrid system behaviors.

2. The simulation verification method of a complex equipment system state machine diagram model according to claim 1, characterized in that: In step S1, based on the GOPPRR-E metamodeling method, the metamodels of state machine diagrams in various languages ​​are sorted out, and a state machine diagram metamodel of a complex equipment system based on the KARMA language is established. The GOPPRR-E metamodeling includes a diagram metamodel, an object metamodel, a relationship metamodel, an endpoint metamodel, a role metamodel and an attribute metamodel, wherein the diagram metamodel is a state machine diagram, the object metamodel includes: simple state, composite state, sub-machine state, initial pseudo state, branch pseudo state, confluence pseudo state, selection pseudo state, connection pseudo state and end pseudo state; the relationship metamodel includes a conversion relationship; the endpoint metamodel includes an entry point pseudo state and an entry and exit point pseudo state; the role metamodel includes a conversion start and a conversion end; the attribute metamodel includes a name, an entry action, an execution action and an exit action.

3. The simulation verification method of a complex equipment system state machine diagram model according to claim 2, characterized in that: The state machine diagram metamodel is used to construct state machine diagrams of complex equipment, describing the states of complex equipment, transitions between states, and behaviors within states; the object metamodel simple states are used to construct the basic states of the system; the object metamodel composite states are used to construct complex states composed of multiple sub-states, helping to build a hierarchical state structure; the object metamodel sub-machine states are used to build nested state machines, allowing independent state machines to be defined in sub-machine states; the object metamodel initial pseudo-states, branch pseudo-states, convergence pseudo-states, selection pseudo-states, connection pseudo-states, and end pseudo-states are used to control the flow and decision logic of the state machine; the relational metamodel is used to construct transitions between states; the endpoint metamodel entry point pseudo-states and entry and exit point pseudo-states are used to construct the initial and end operations when entering and exiting a composite state or sub-state machine.

4. The simulation verification method of a complex equipment system state machine diagram model according to claim 3 is characterized in that: In step S1, the object metamodel and the relational metamodel in the state machine diagram metamodel are simulated and semantically extended, and discrete and continuous changes are placed in each element of the model. A variable assignment mechanism is added to all state object metamodels to express continuous changes within the state, and the state type is clarified to characterize various states. The semantics of trigger events, variable guard conditions, and instantaneous changes of variables are added to the relational metamodel, which are used to characterize trigger events, jump guard conditions, and execution effects, respectively.

5. The simulation verification method of a complex equipment system state machine diagram model according to claim 4 is characterized in that: In step S2, establishing a corresponding state machine diagram model according to the constructed state machine diagram metamodel includes: Identify and define the states that may occur in a complex equipment system during operation, and instantiate them into simple states; Combine related states into composite states to simplify multi-level state structures; Use pseudo-states to optimize the logic describing state transitions; Determine the state transitions of complex equipment systems from one state to another.

6. A simulation verification method and system for a complex equipment system state machine diagram model according to claim 5, characterized in that: Step S3 specifically includes: Sort out the conversion relationship between the elements of the state machine diagram model and the hybrid automaton model, and establish the semantic conversion rules between the two in combination with the simulation significance of the state machine diagram model; Input the established state machine diagram, and perform model checking on various states and transitions of the state machine diagram based on the state machine diagram modeling specification; The various elements of the constructed state machine diagram model of the complex equipment system containing discrete and continuous changes are converted into the elements of the corresponding hybrid automaton simulation model according to the semantic conversion rules.

7. A simulation verification system for a state machine diagram model of a complex equipment system, applying a simulation verification method for a state machine diagram model of a complex equipment system according to any one of claims 1 to 6, characterized in that: It includes a data layer, a function layer and an application layer; the data layer is used to encapsulate and store multi-architecture modeling language KARMA data and hybrid automaton simulation model data; the function layer obtains the encapsulated data of the data layer, including a state machine diagram model construction module, a hybrid automaton model conversion module and a hybrid automaton solver module; the application layer interacts with the user, including a state machine diagram model selection module and a simulation solution and simulation information display module.

8. The simulation verification system of a complex equipment system state machine diagram model according to claim 7, characterized in that: The functional layer specifically includes: The state machine diagram model construction module includes a model instantiation submodule and a simulation semantic input submodule; the instantiation submodule instantiates the simple state, composite state, submachine state, initial pseudo state, branch pseudo state, convergence pseudo state, selection pseudo state, connection pseudo state, end pseudo state and transition metamodel of the state machine diagram; the simulation semantic input submodule is used to input simulation semantic information describing the continuous change behavior of complex equipment in the instantiated object metamodel and input simulation semantic information describing the discrete instantaneous change behavior of complex equipment in the relational metamodel; The hybrid automaton model conversion module includes a model construction detection submodule and an automatic conversion submodule; the model construction detection submodule checks the model before simulation; the automatic conversion submodule reads the semantic information in the state machine diagram model, on the one hand, maps the conversion rules of various instantiated metamodels in the state machine diagram with the related elements of the hybrid automaton simulation model, and on the other hand, maps the simulation semantics input according to the state machine diagram model with the conversion rules of the related elements of the hybrid automaton simulation model, and finally generates the corresponding hybrid automaton simulation model; The hybrid automaton solving module calls the integrated hybrid automaton simulation solver, configures simulation-related parameters and settings, and executes simulation solving of the hybrid automaton model.

9. The simulation verification system of a complex equipment system state machine diagram model according to claim 7, characterized in that: The application layer specifically includes: The state machine diagram model selection module calls the hybrid automatic model conversion module according to the selected state machine diagram model to be compiled to generate a corresponding hybrid automatic machine model; The simulation solution performs relevant simulation configuration on the hybrid automaton model generated by the state machine diagram model selection module, calls the hybrid automaton solver module to perform simulation, and obtains data of the hybrid automaton model in real time; The simulation information display module visualizes the current state of the model and the corresponding changes of the set variables to the user.