Formalized modeling method and device, electronic equipment and storage medium

Through formal modeling methods, including identifying modeling objects, defining states and migrations, and converting the model into a random hybrid automaton network supported by UPPAAL, the problems of poor accessibility of model inspection technology in the prior art are solved, and effective verification of the ATS architecture and accurate acquisition of the system state space are achieved.

CN120068407AActive Publication Date: 2025-05-30SUN YAT SEN UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510105728.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-30
Estimated Expiration
2045-01-23

AI Technical Summary

Technical Problem

The prior art determines that the accessibility of the properties in the state space is poor through model inspection technology, and the ATS architecture cannot be effectively verified, and the system state space and execution traces cannot be accurately obtained.

Method used

A formal modeling method is proposed, by obtaining scene architecture data, identifying modeling objects, analyzing the physical interaction mechanism between objects, defining parameter variables of the state and state switching process, constructing ports and executing functions, determining states and migrations, and converting the ML4TSA model into a random hybrid automaton network supported by UPPAAL through a model conversion algorithm.

Benefits of technology

The accessibility of the properties in the state space is improved through model inspection technology, the accuracy and accuracy of obtaining the system state space and execution traces is enhanced, and effective verification of the ATS architecture is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068407A_ABST
    Figure CN120068407A_ABST
Patent Text Reader

Abstract

The invention discloses a formalized modeling method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining scene architecture data which is used for describing physical entities in a scene and an information interaction relationship between the entities; and completing a formalized modeling process according to the scene architecture data, and finally obtaining a verifiable formalized model for describing the scene and the architecture. The embodiment of the invention can improve the reachability of judging the property in the state space through a model inspection technology, improves the precision and accuracy of obtaining the state space and the execution trace of the system, and can be widely applied to the technical field of computers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and particularly to a formal modeling method, apparatus, electronic device, and storage medium. Background Art

[0002] Modeling a system is a technical method of presenting the composition of the system and the relationships between its components to people in a tabular, graphical, or formulaic manner, that is, a process of abstracting the system. The abstraction of the system can be carried out from multiple levels, that is, modeling can be performed from multiple dimensions. During the modeling process, the system gradually becomes unambiguous.

[0003] The formal method is an application method of analytical techniques based on a mathematical foundation and proven through strict mathematical proofs, and is commonly used in the description, development, and verification processes of software and hardware systems. Formal modeling applies the formal method to the modeling process. It is based on an unambiguous formal specification language, uses a precisely defined formal language to describe the functions of the system, and constructs models for the state characteristics and behavior characteristics of the target software system using some mathematically abstracted known characteristics, thereby completing the formal modeling process. The formal model should be between the programming language and the high-level requirements, and has the characteristics of precision and unambiguity, but does not present too many details.

[0004] Some classic formal languages, such as the Z language, B language, Event-B language, VDM, etc., all have their respective formal semantics. The formal models obtained by using the formal language in accordance with the modeling specifications can accurately describe the system, facilitating subsequent formal analysis and verification.

[0005] However, the formal modeling methods mentioned in the current related technologies have the following problems: 1. The reachability of the determined properties in the state space through the model checking technology is poor, and the ATS architecture cannot be verified; 2. The system state space and execution trace cannot be accurately obtained, which is not conducive to the application of subsequent model checking technology. Summary of the Invention

[0006] The main purpose of the embodiments of the present invention is to propose a formal modeling method, apparatus, electronic device, and storage medium, which can improve the reachability of the determined properties in the state space through the model checking technology, and improve the accuracy and precision of obtaining the system state space and execution trace.

[0007] To achieve the above object, on the one hand, an embodiment of the present invention proposes a formal modeling method, including the following steps:

[0008] Obtain scenario architecture data, where the scenario architecture data is used to describe the physical entities in the scenario and the information interaction relationships between the entities;

[0009] Complete the formal modeling process based on the described scenario architecture data, and this process includes the following steps:

[0010] Identify the modeling objects based on the scenario architecture, analyze the physical interaction mechanism between the objects, and identify the modeling subjects;

[0011] For each modeling object, define parameter variables that can describe its state and the state transition process to complete the parameter definition;

[0012] Determine the input and output information flows of each object according to the information interaction relationship described by the scenario architecture to construct the ports of each modeling object; and determine the execution function according to the triggering relationship of the information flows;

[0013] Based on the cyber-physical interaction mechanism of the objects, determine the state and state transition process of the objects; use variables to describe the state, define relevant invariants and variable evolution rules, and determine the state boundaries by setting variable constraints; consider the state transition process during information transmission and physical movement, describe this process through migrations, and set the trigger signals, guard conditions, and migration actions corresponding to each migration; in this process, apply the port values to the guard conditions and migration actions to achieve the cyber-physical integrated modeling;

[0014] Based on the modeling tool, complete the visual expression of the model, and use the model transformation algorithm to convert the ML4TSA model instance into a stochastic hybrid automaton network supported by UPPAAL;

[0015] Finally, obtain a verifiable formal model that describes the scenario and architecture.

[0016] In some embodiments, in the step of completing the formal modeling process according to the scenario architecture data, the autonomous transportation architecture modeling language ML4TSA is used as the formal modeling language, and the requirements of the autonomous transportation architecture modeling language include: visually expressing the system state, integrating the architecture and scenario characteristics, and providing formal semantic support;

[0017] Among them, ML4TSA is extended based on the UML state diagram to visually express the system state space, and describes the system operation process through variable evolution and state transition;

[0018] According to the characteristics of the ATS architecture and traffic scenarios, add modeling elements to enrich the description ability of the language, and support subsequent formal verification research by defining the formal grammar and semantics of the language;

[0019] The ML4TSA uses state and migration description objects. ML4TSA extends the description ability of states through state constraints (constrain) and evolution rules (evolution). Among them, constrain is used to specify the value range of state-related variables. It formally describes the set of expressions that variables must maintain correctly in this state, defining the boundaries of the state. Evolution describes the time-related change rules of variables within the scope of state constraints, reflecting the adaptability of ML4TSA to continuous system processes.

[0020] At the same time, ML4TSA extends the migrations in the state diagram through guard conditions (guard), migration actions (action), and trigger signals (signal). The migration is triggered by the signal event represented by signal and restricted by the guard condition specified by guard. The re-assignment of discrete variables and the generation of signals are specified by the action corresponding to the migration.

[0021] To reflect the cyber-physical fusion characteristics in the ATS model, ML4TSA defines the ports (port) and execution functions of objects, and represents the information processing process of objects through the change process of interface information values.

[0022] In some embodiments, the ML4TSA model describes the state change process within several components and the synchronous interaction process between components. Among them, for an ML4TSA object, there is:

[0023] ML4TSA = (S, Var, →, Init, P, F, Cons, Evo)

[0024] Where, S = {s c , s p} is the set of state names, where s c is the information interaction state name, and s p is the physical motion state name. For any component, its state can be expressed as: s = s c |s p |(s c , s p ), s c ∈ S c , s p ∈ S p , and it is determined whether to use composite states for description according to its participation in the information space and physical space. At the same time, the state s is jointly described by the invariant constraint (constrain) and the evolution rule (evolution).

[0025] Var is a set of variables used to describe states, including five types: discrete variable set DiscreteVar, continuous variable ContinuousVar, clock variable ClockVar, probability variable ProbabilityVar, and signal variable SignalVar;

[0026] → is a set of transitions connecting states. It is composed of triples and is represented as →: {(s, t, s′)|s, s′ ∈ S, t ∈ T}, that is, a source state is transformed into a target state through a transition. Here, s is the source state, s′ is the target state, and t = (signal, guard, action) is the transition label, which is described by three attributes: signal is the triggering signal used to indicate the start time of the transition; guard is the guard condition used to determine whether the transition can occur; action is the transition action, indicating the discrete state changes that occur inside the component after the transition;

[0027] Init is the set of initial states, which stipulates the initial states of the component and also determines the initial distribution of variables within the component;

[0028] P = {p in , p out} is the set of ports of the component, where p in and p out are the input and output ports respectively, used to store the information flows received and generated by the component;

[0029] F is the information processing function of the component, used to describe the functions executed by the component; Evo is the set of evolution rules; Cons is the set of state constraints.

[0030] In some embodiments, the ML4TSA model organizes type variables through expressions and constructs modeling elements to formally describe the system state and the state transition process. Among them, boolean expressions are used to describe guard conditions, triggering signals, state constraints, and interface values; action expressions are used to describe transition actions and evolution rules; clock expressions are used to define time-related limiting conditions; differential expressions are used to describe the reaction of continuous variables to time; function expressions are encapsulations of multiple sets of predicates, used to represent complex expression logical relationships;

[0031] Let c be a clock variable, x d , x c be discrete and continuous variables respectively, p be a probability variable, η be a signal variable, and the semantic definitions of boolean expressions, action expressions, and time expressions are as follows:

[0032] Boolean expressions: Among them, η is a boolean value. When a signal is generated in the system, the corresponding variable value is True, and at this time the expression is satisfied; A(xd ) AND IF(c) is an algebraic inequality or algebraic equation for discrete variables and clock variables. When the values of each variable make the expression hold, the corresponding A(x d ) AND IF(c) take the value True; for the discrete variable values r(x d ), it is expressed as:

[0033] is a differential inequality or differential equation for continuous variables, which describes a time-dependent continuous variable x c = w(t); within a specific time range r(c), if there exists w(t) as the solution of the differential equation , then it is considered that x c = w(t) makes the expression hold; this process can be expressed as: F(x d ,x c ,c) is a function expression;

[0034] Action expression:

[0035] Among them, Gen(η) is a generate signal operation, which modifies the Boolean value of the signal variable to True to achieve communication or process synchronization between multiple objects; A(x d ) and Reset(c) are algebraic equations for discrete variables and clock variables respectively, both of which represent reassigning values to variables. Among them, the role of Reset(·) in the modeling process is to set the local clock to zero; AND F(x d ,x c ,c) are defined in the same way as in the Boolean expression;

[0036] Clock expression: Among them, IF and Reset are an algebraic inequality and a clock assignment operation respectively. The former judges whether a time-related inequality holds and returns a Boolean value; the latter modifies the clock value or definition and is a branch of the action expression; to ensure real-time synchronization between different objects, ML4TSA realizes the synchronization of multiple types of clocks among multiple objects through a global clock c global ; to ensure the accuracy of the mapping with the global clock, ML4TSA adopts a mapping time accumulation mechanism to record the changes caused by the reset operation to the clock c.

[0037] In some embodiments, the method further includes: defining the operational semantics of the system through the Label Transition System (LTS) definition language, representing the semantics of the system as state transition rules, and describing the dynamic process of the system through state transitions. The definitions of states, valid and invalid transitions are given below:

[0038] Valid state: In ML4TSA, a model instance usually consists of multiple components and the interactions between them; a component state is defined as a quadruple (s, v, c, p), where s ∈ S is the state name, representing the discrete state of the component; v: Var → Value shows the function values associated with state s; c ∈ Clock represents the clock variable, which is shown independently as a special variable due to the real-time characteristics of the system; p = {port.value | port ∈ P} is the real-time information flow situation of each port of the component. According to the definition of the component state, LTS describes the reasonable states of the component. A component Obj state (s, v, c, p) is a reasonable state if and only if it satisfies the following conditions: 1) The variable values, clock, and port values satisfy the constraint expressions of the state: 2) When the state is the initial state, the variable values, clock, and port values satisfy the initial conditions:

[0039] Valid transition: LTS describes the dynamic process of the system as state changes, including two types: state transitions and variable evolutions. A state change process is represented as Its validity needs to satisfy the following conditions: 1) The states before and after the change are both valid states: (s, v, c, p) ∈ Obj.State ∧ (s′, v′, c′, p′) ∈ Obj.State; 2) If the state names before and after the change are different, there is a corresponding transition between the states, and the transition conditions are satisfied: 3) If the state names before and after the change are the same, there are corresponding evolution rules for the variables within the state:

[0040] System failure: A state change process fails if and only if any of the following situations occur: Failure: 1) The states before and after the change are invalid: 2) The state before the change is about to fail, but the transition conditions are not satisfied: where ε →0 represents a positive number approaching 0.

[0041] In some embodiments, the state change process of the system includes two types: state transition and variable evolution. These two processes are respectively determined by five factors: state constraint, evolution rule, guard condition, trigger signal, and transition action. Among them, for a component state (s, v, c, p), if there is no transition (s, t, s′) in the model, then its state change process is only constrained by the constraint. The following respectively give the definitions of 2 state transitions and 3 variable evolution rules to describe the operational semantics of ML4TSA:

[0042] (1) State transition caused by a trigger signal:

[0043]

[0044] Rule1.1 means that when the component is in the state (s, v, c, p), there exists a transition t such that the component can transfer to the state s′. Both the states before and after the state change are valid states, and the constraint condition can be satisfied, and the signal signal(t) is triggered. At this time, the component changes from the state s to the state s′ through the transition t. At the same time, the action corresponding to the transition t reassigns (v, c, p) to (v′, c′, p′). The entire state change process is represented as T, indicating a discrete change in the component state. The prob in Rule1.1 is a probability variable, representing the possible random switching during the state change process. Finally, the component switches from the state (s, v, c, p) to the state (s′, v′, c′, p′);

[0045] (2) State transition caused by a violated state constraint:

[0046]

[0047] Rule1.2 means that when the component is in the state (s, v, c, p), there exists a transition t such that the component can transfer to the state s′. At the same time, there exists a time interval ε greater than 0 and approaching 0, such that the component will enter the failure state after ε time. At this time, if the changed state (s′, v′, c′, p′) is a valid state, the constraint condition can be satisfied, and the signal signal(t) is triggered, then the component changes from the state s to the state s′ through the transition t. At the same time, the action corresponding to the transition t reassigns (v, c, p) to (v′, c′, p′). The meanings of T and prob are the same as those in Rule1.1. Finally, the component switches from the state (s, v, c, p) to the state (s′, v′, c′, p′);

[0048] (3) Variable evolution without a trigger signal:

[0049]

[0050] Rule 2.1 means that when the component is in the state (s, v, c, p), there exists a transition t such that the component can transfer to the state s′, and the states before and after the change are both valid states. However, at this time, the constraint condition cannot be satisfied. Therefore, the component cannot be converted from the state s to the state s′ through the transition t. If there is an evolution rule in the state s, then (v, c, p) will evolve over time, and finally the component will switch from the state (s, v, c, p) to the state (s, v′, c′, p′);

[0051] Among them, the action process of the evolution rule is described as follows: The evolution rule consists of a set of differential expressions, that is, a set of differentiable functions of continuous variables related to time f: t → x d , and its first derivative is expressed as For a period of time there is τ(c) = γ 1 、τ(c′) = γ 2 , and at the same time there is f(γ 1 ) = v, f(γ 2 ) = v′. For there is and it satisfies the valid state constraint;

[0052] (4) Variable evolution caused by non-compliance with migration conditions:

[0053]

[0054] Rule 2.2 means that when the component is in the state (s, v, c, p), there exists a transition t such that the component can transfer to the state s′, and the states before and after the change are both valid states. However, at this time, the signal signal(t) cannot be triggered. Therefore, the component cannot be converted from the state s to the state s′ through the transition t; If there is an evolution rule in the state s, then (v, c, p) will evolve over time, and finally the component will switch from the state (s, v, c, p) to the state (s, v′, c′, p′);

[0055] (5) Variable evolution caused by no migration:

[0056]

[0057] Rule 2.3 means that when the component is in the state (s, v, c, p), there does not exist a transition t such that the component can transfer to the state s′, but there is an evolution rule in the state s, and the states before and after the change are both valid states. Then (v, c, p) will evolve over time, and finally the component will switch from the state (s, v, c, p) to the state (s, v′, c′, p′);

[0058] The operational semantics of ML4TSA are defined by the above 5 state change rules to ensure the normal operation of the model; meanwhile, ML4TSA provides two means to model the cyber-physical fusion process of the ATS architecture and scenarios, specifically:

[0059] (1) Modeling elements containing port values: In the specific ATS architecture and scenario models, the expressions composed of the port value port.value participate in the construction of elements such as state constraints, trigger signals, guard conditions, and transition actions, which are used to represent the mutual influence between the architecture information and the physical world;

[0060] (2) Strict cyber-physical clock mapping: During the ML4TSA modeling process, the information processing process and the physical motion process respectively describe the system operation processes on the information side and the physical side. During this process, the information process and the physical process adopt strict clock mapping to ensure the smooth interaction between the two.

[0061] In some embodiments, the method further includes:

[0062] Construct a graphical modeling platform according to the ML4TSA modeling language, and implement the conversion between the ML4TSA model and the network of stochastic hybrid automata to obtain the support of the UPPAAL verification engine;

[0063] Among them, the graphical modeling platform includes a main modeling interface, a tool panel for modeling elements, and a detailed property editing interface. On the main interface, elements such as states, transitions, and ports defined by ML4TSA are represented as graphics, and the relationships between elements are reflected by line segments; the tool panel provides functions for creating, deleting, and modifying modeling elements; the property editing interface supports the editing of the names and expressions of modeling elements;

[0064] During the model conversion process, based on the meta-model analysis of ML4TSA and the network of stochastic hybrid automata NSHA, mapping rules including global variables, states, transitions, and ports are designed; the ports and execution functions in ML4TSA exist in the form of variables in NSHA, and by maintaining a global matrix variable, the port values of each physical object are stored.

[0065] Another aspect of the embodiments of the present invention also provides a formal modeling device, including:

[0066] A first module for obtaining scenario architecture data, where the scenario architecture data is used to describe the physical entities in the scenario and the information interaction relationships between the entities;

[0067] A second module for completing the formal modeling process according to the scenario architecture data, and this process includes the following steps:

[0068] Identify the modeled objects based on the scenario architecture, analyze the physical interaction mechanism between the objects, and identify the modeling subject;

[0069] For each modeled object, define parameter variables that can describe its state and the state transition process, and complete the parameter definition;

[0070] According to the information interaction relationship described by the scenario architecture, determine the input and output information flows of each object to construct the ports of each modeled object; and determine the execution function according to the triggering relationship of the information flows;

[0071] Based on the cyber-physical interaction mechanism of the object, determine the state and the state transition process of the object; describe the state using variables, define relevant invariants and variable evolution rules, and determine the state boundary by setting variable constraints; consider the state transition process during information transmission and physical movement, describe this process through transitions, and set the trigger signal, guard condition, and transition action corresponding to each transition; in this process, apply the port values to the guard conditions and transition actions to achieve cyber-physical integrated modeling;

[0072] Based on the modeling tool, complete the visual expression of the model, and use the model conversion algorithm to convert the ML4TSA model instance into a stochastic hybrid automaton network supported by UPPAAL;

[0073] The third module is used to finally obtain a verifiable formal model describing the scenario and the architecture.

[0074] To achieve the above object, another aspect of the embodiments of the present invention provides an electronic device, the electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the method described above is implemented.

[0075] To achieve the above object, another aspect of the embodiments of the present invention provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described above is implemented.

[0076] The embodiments of the present invention also disclose a computer program product or a computer program, the computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device can read the computer instructions from the computer-readable storage medium, and when the processor executes the computer instructions, the computer device executes the method described above.

[0077] The embodiments of the present invention at least include the following beneficial effects: The present invention provides a formal modeling method, apparatus, electronic device, and storage medium. The solution obtains scenario architecture data, which is used to describe the physical entities in the scenario and the information interaction relationships between the entities; completes the formal modeling process according to the scenario architecture data, and finally obtains a verifiable formal model describing the scenario and the architecture. The embodiments of the present invention can improve the reachability of properties in the state space determined by model checking technology and improve the accuracy and precision of obtaining the system state space and execution traces. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] Figure 1 is a schematic diagram of an implementation environment provided by an embodiment of the present invention;

[0079] Figure 2 is a flowchart of the overall steps provided by an embodiment of the present invention;

[0080] Figure 3 is a schematic diagram of the relationship between modeling elements and expressions in ML4TSA provided by an embodiment of the present invention;

[0081] Figure 4 is a schematic diagram of a cyber-physical fusion modeling case provided by an embodiment of the present invention;

[0082] Figure 5 is a schematic diagram of the ML4TSA meta-model provided by an embodiment of the present invention;

[0083] Figure 6 is a schematic diagram of the graphical modeling environment of ML4TSA provided by an embodiment of the present invention;

[0084] Figure 7 is a schematic diagram of the graphical representation of modeling elements and tools provided by an embodiment of the present invention;

[0085] Figure 8 is a schematic diagram of a timed automata network within the UPPAAL interface provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0086] In order to make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present invention. They are only examples of devices and methods that are consistent with some aspects of the embodiments of the present invention as detailed in the appended claims.

[0087] It is understood that in the description of the present invention and the above-mentioned drawings, terms such as "first", "second", "third", "fourth", etc. (if any) are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that comprises a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0088] It should be understood that in the present invention, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that three relationships can exist. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expression means any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0089] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.

[0090] Before elaborating on the embodiments of the present invention in detail, the meanings of relevant variables involved in the embodiments of the present invention are described as follows:

[0091] S = {s c , s p}: The set of state names, where s c is the name of the information interaction state, and s p is the name of the physical motion state;

[0092] Var: The set of variables;

[0093] →: A set of migrations connecting states;

[0094] signal: The trigger signal, which is used to indicate the start time of the migration;

[0095] guard: The guard condition, which is used to determine whether a transition can occur;

[0096] action: The transition action, which indicates the discrete state changes that occur within the component after the transition;

[0097] Init: The set of initial states;

[0098] P = {p in , p out}: The set of ports of the component;

[0099] F: The information processing function of the component;

[0100] Evo: The set of evolution rules, which is composed of the evolution rules evolution mentioned above;

[0101] Cons: The set of state constraints, which is composed of the invariant constraints constrain mentioned above;

[0102] A(x d ), IF(c): The algebraic inequality or algebraic equation for discrete variables and clock variables, where x d is the discrete variable and c is the clock variable;

[0103] The differential inequality or differential equation for continuous variables, where x c is the continuous variable;

[0104] F(x d , x c , c): The function expression, which is the encapsulation of the above algebraic expression and differential expression;

[0105] Gen(η): The generate signal operation, where η is the signal variable and is a boolean value;

[0106] Reset(·): The local clock reset operation;

[0107] τ(c) ∈ R: The current reading of the clock;

[0108] I(c): The definition function of the clock;

[0109] A dense sequence of moments;

[0110] A dense sequence of moments constructed based on the global clock;

[0111] The clock mapping function;

[0112] Network of Stochastic Hybrid Automata (NSHA).

[0113] The formal modeling method, device, electronic device, and storage medium provided by the embodiments of the present invention relate to the field of computer technology. The formal modeling method provided by the embodiments of the present invention can be applied to a terminal, a server, or software running on a terminal or a server. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, etc., but is not limited thereto; the server side can be configured as an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server can also be a node server in a blockchain network; the software can be an application implementing the formal modeling method, etc., but is not limited to the above forms.

[0114] The present invention can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0115] As Figure 1 shown, it is a schematic diagram of an implementation environment provided by the embodiments of the present invention. Referring to Figure 1 , this implementation environment includes at least one terminal 102 and a server 101. The terminal 102 and the server 101 can be network-connected through wireless or wired means to complete data transmission and exchange.

[0116] The server 101 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0117] In addition, the server 101 can also be a node server in a blockchain network. Among them, the blockchain is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithms.

[0118] The terminal 102 can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart speaker, a smart watch, etc. Among them, the terminal 102 can also be an in-vehicle terminal of various device types exemplified above, but is not limited thereto. The terminal 102 and the server 101 can be directly or indirectly connected through wired or wireless communication methods, and the embodiments of the present invention do not limit this here.

[0119] Exemplarily based on Figure 1 the shown implementation environment, the embodiments of the present invention provide a formal modeling method. Taking the application of this formal modeling method to the server 101 as an example for illustration, it can be understood that this method can also be applied to the terminal 102.

[0120] Referring to Figure 2 , Figure 2 is a flowchart of the formal modeling method applied to the server provided by the embodiments of the present invention. The execution subject of this method can be any of the foregoing computer devices (including servers or terminals). Referring to Figure 2 , this method may include the following steps:

[0121] Obtain scenario architecture data, where the scenario architecture data is used to describe the physical entities in the scenario and the information interaction relationships between the entities;

[0122] Complete the formal modeling process according to the scenario architecture data, and this process includes the following steps:

[0123] Based on the scenario architecture, identify the objects to be modeled, analyze the physical interaction mechanism between the objects, and identify the modeling subjects;

[0124] For each modeling object, define parameter variables that can describe its state and the state transition process, and complete the parameter definition;

[0125] Determine the input and output information flows of each object according to the information interaction relationship described by the scenario architecture, so as to construct the ports of each modeling object; and determine the execution function according to the triggering relationship of the information flows.

[0126] Based on the cyber-physical interaction mechanism of the object, determine the state and state transition process of the object; describe the state using variables, define relevant invariants and variable evolution rules, and determine the state boundary by setting variable constraints; consider the state transition process during information transmission and physical movement, describe this process through transitions, and set the trigger signal, guard condition, and transition action corresponding to each transition; apply the port values to the guard conditions and transition actions during this process to achieve cyber-physical integrated modeling.

[0127] Based on the modeling tool, complete the visual expression of the model, and use the model conversion algorithm to convert the ML4TSA model instance into a stochastic hybrid automaton network supported by UPPAAL.

[0128] Finally, obtain a verifiable formal model describing the scenario and architecture.

[0129] The following details the implementation process of the present invention in a specific application scenario:

[0130] In view of the problems existing in the prior art, the overall process of modeling provided by the embodiments of the present invention includes:

[0131] 1. Data input:

[0132] Scenario architecture data, used to describe the physical entities in the scenario and the information interaction relationship between the entities.

[0133] 2. Modeling process:

[0134] (1) Identify the modeling subject. Based on the scenario architecture, identify the objects to be modeled and analyze the cyber-physical interaction mechanism between the objects.

[0135] (2) Define parameters. For each modeling object, define parameter variables that can describe its state and state transition process. ML4TSA supports discrete variables, continuous variables, clock variables, probability variables, signal variables, etc. A suitable data structure can be defined for each modeling object to organize variables.

[0136] (3) Construct ports and execution functions. Determine the input and output information flows of each object according to the information interaction relationship described by the scenario architecture, so as to construct the ports of each modeling object; determine the execution function according to the triggering relationship of the information flows.

[0137] (3) Determine states and transitions. Based on the cyber-physical interaction mechanism of the object, determine the states of the object and the state transition process. Use variables to describe the states, and define relevant invariants and variable evolution rules. Determine the state boundaries by setting variable constraints; consider the state transition process during information transmission and physical movement, describe this process through transitions, and set the trigger signals, guard conditions, and transition actions corresponding to each transition. Apply the port values to the guard conditions and transition actions during this process to achieve cyber-physical integrated modeling.

[0138] (4) Transform the model. Based on the modeling tool, complete the visual expression of the model, and use the model transformation algorithm to transform the ML4TSA model instance into a stochastic hybrid automaton network supported by UPPAAL.

[0139] 3. Output data results: Describe the verifiable formal model of the scenario and architecture.

[0140] Specifically, in order to formally describe the autonomous transportation system architecture and the scenario operation process, the embodiments of the present invention propose a domain-specific formal modeling language: Autonomous Transportation System Architecture Modeling Language (ML4TSA), which can be used to depict the information flow within the architecture and the physical movement process within the scenario. To verify the properties of the ATS architecture, the requirements for the modeling language are summarized as follows:

[0141] (1) Display and express the system state. The ATS domain-specific modeling language should be able to explicitly describe the system state and its change process, so as to determine the reachability of the properties in the state space through model checking techniques, and then verify the ATS architecture;

[0142] (2) Incorporate architecture and scenario characteristics. The ATS domain-specific modeling language should be able to reflect the ATS architecture and scenario characteristics, including: ① Characterize random events, that is, require the model to be able to simulate probability events in the traffic system and information transmission process; ② Describe hybrid phenomena, that is, require the model to be able to represent discrete events and continuous changes in the system; ③ Real-time response, that is, require the model to be able to depict the system state path evolving over time; ④ Abstractly represent the system, that is, require the model to model at the architecture level, and reduce the model complexity by reducing the attention to specific control algorithms; ⑤ Integrate cyber-physical processes, that is, require the model to describe the interaction process between information interaction within the system architecture and physical movement within the scenario.

[0143] (3) Provide formal semantic support. The ATS domain-specific modeling language should describe its operational semantics through a formal language, so as to obtain an accurate system state space and execution trace, which is convenient for the subsequent application of model checking techniques.

[0144] Based on the above requirements, ML4TSA extends the UML state diagram to display and represent the system state space, and describes the system operation process through variable evolution and state transition. Meanwhile, according to the characteristics of the ATS architecture and traffic scenarios, modeling elements are added to enrich the description ability of the language. And by defining the formal grammar and semantics of the language, it supports subsequent formal verification research. Similar to the UML state diagram, ML4TSA uses states and transitions to describe objects. On this basis, ML4TSA extends the description ability of states through constrain (state constraint) and evolution (evolution rule). Among them, constrain is used to specify the value range of variables related to the state, which formally describes the set of expressions that variables must maintain correctly in this state, that is, it defines the boundary of the state; evolution describes the time-related change rules of variables within the state constraint range, reflecting ML4TSA's adaptability to continuous system processes. At the same time, ML4TSA extends the transitions in the state diagram through guard (guard condition), action (transition action) and signal (trigger signal). The transition can be triggered by a signal event represented by signal and restricted by the guard condition specified by guard. The re-assignment of discrete variables and the generation of signals are specified by the action corresponding to the transition. At the same time, to reflect the cyber-physical fusion characteristics in the ATS model, ML4TSA defines the port (port) and execution function of the object, and represents the information processing process of the object through the change process of the interface information value. The following will introduce from aspects such as the syntax, semantics, rationality, tool development and model conversion algorithm of the modeling language respectively.

[0145] (1) Syntax declaration:

[0146] The ML4TSA model describes the state change process within several components and the synchronous interaction process between components. For an ML4TSA object, there is:

[0147] ML4TSA = (S, Var, →, Init, P, F, Cons, Evo)

[0148] 1), S = {s c , s p} is the set of state names, where s c is the information interaction state name, s p is the physical motion state name. For any component, its state can be expressed as: s = s c |s p |(s c , s p ), s c ∈ S c , s p ∈ S p, determine whether to use a composite state for description according to its participation in the information space and the physical space. At the same time, the state s is jointly described by the invariant constraint constrain and the evolution rule evolution.

[0149] 2) Var is a set of variables used to describe the state, including five types: the discrete variable set DiscreteVar, the continuous variable ContinuousVar, the clock variable ClockVar, the probability variable ProbabilityVar, and the signal variable SighalVar. Organized by expressions, it can represent modeling elements such as the constraint condition cons and the evolution rule evo.

[0150] 3) → is a set of transitions connecting states, which is composed of triples and is represented as →: {(s, t, s′)|s, s′ ∈ S, t ∈ T}, that is, a source state is transformed into a target state through a transition. Among them, s is the source state, s′ is the target state, and t = (signal, guard, action) is the transition label, which is described by three attributes. signal is the trigger signal used to indicate the start time of the transition. The ML4TSA model realizes communication and state synchronization between different objects through it. For example, the information flow transmission signal received during vehicle driving; guard is the guard condition used to determine whether the transition can occur. Essentially, it is a constraint on the transition. For example, the minimum safe distance constraint between vehicles during the driving of autonomous vehicles; action is the transition action, which indicates the discrete state changes that occur inside the component after the transition, including reassigning discrete variables, generating signals, etc. In a transition, it is not always necessary to describe it with three attributes, that is, the transition may be described by any combination of these attributes.

[0151] 4) Init is the set of initial states, which stipulates the initial state of the component and also determines the initial distribution of the variables in the component.

[0152] 5) P = {p in , p out} is the set of ports of the component, where p in and p out are the input and output ports respectively, used to store the information flows received and generated by the component. Each port corresponds to an information flow, and p = (id, type, content, value). When p.value = False, there is no information flow corresponding to port p in the component. Usually, the port set of a component is composed of an input port set P in and an output port set P out . Through the change of port values, the model can describe the information interaction process of the component.

[0153] 6) F is the information processing function of the component, which is used to describe the functions performed by the component (the generation process of information flow is regarded as the instantiation presentation of the function). is an abstract mapping function, where t x′ is the execution time of generating information flow. In the modeling process, the information processing function is usually determined based on the knowledge graph obtained previously.

[0154] 7) Evo is a set of evolution rules, which is composed of the evolution rules mentioned above. The evolution rules are expressed as a set of differential expressions, which are used to describe the internal mechanism of the component state, that is, the change of continuous / clock variables in this state with respect to time. When the migration of the component cannot be triggered, the state change process of the component is mainly specified by the evolution rules;

[0155] 8) Cons is a set of state constraints, which consists of the invariant constraints mentioned above. Invariants are expressed as a set of Boolean expressions that describe the value range of variables in the component state. They define the state boundaries of the component. All variables in the state must satisfy the constraints, otherwise the component will be out of the state. Usually,

[0156] Similar to other UML extension languages, ML4TSA uses type variables for modeling, including probability variables, discrete variables, continuous variables, signal variables, and clock variables, in order to support the model's description of random, hybrid, and real-time systems. Based on the above variable types, modeling elements such as constraint and evolution can be constructed through expression sets, and each expression can be regarded as a predicate of a specific type of variable. ML4TSA allows five types of expressions, namely Boolean expressions, clock expressions, differential expressions, action expressions, and function expressions.

[0157] Figure 3 The relationship between type variables, modeling elements and expressions is shown. ML4TSA organizes type variables and constructs modeling elements through expressions, thereby formally describing the system state and state transition process. Boolean expressions are used to describe guard conditions, trigger signals, state constraints and interface values; action expressions are used to describe migration actions and evolution rules; clock expressions are used to define time-related constraints; differential expressions describe the reaction of continuous variables to time; function expressions are encapsulations of multiple groups of predicates, which can represent more complex expression logical relationships. At the same time, there is also a hierarchical relationship between expressions. For example, a time expression or a set of differential expressions can constitute a Boolean expression, and an action expression can also include differential expressions and function expressions.

[0158] Let c be the clock variable, x d 、x cThey are discrete variables and continuous variables respectively. p is a probability variable, η is a signal variable, and the semantic definitions of boolean expressions, action expressions, and time expressions are as follows.

[0159] Definition 1: Boolean expression:

[0160]

[0161] where η is a boolean value. When a signal is generated in the system, the corresponding variable value is True, and the expression is satisfied at this time.

[0162] A(x d ) and IF(c) are algebraic inequalities or algebraic equations for discrete variables and clock variables. When the value of each variable makes the expression hold, the corresponding A(x d ) and IF(c) take the value True. For the discrete variable value r(x d ) that satisfies the algebraic expression, it can be expressed as: The definition of the clock variable value r(c) is the same.

[0163] is a differential inequality or differential equation for continuous variables, which describes a time-related continuous variable x c = w(t). Within a specific time range r(c), if there exists w(t) as the solution of the differential equation , then it is considered that x c = w(t) makes the expression hold. This process can be expressed as:

[0164] F(x d ,x c ,c) is a function expression, which is the encapsulation of the above algebraic expressions and differential expressions. It returns a boolean value and supports more complex variable judgments in the model. In addition, ML4TSA supports ∨,∧, and other operators defined by first-order predicate logic, as shown below.

[0165]

[0166] Definition 2: Action expression:

[0167]

[0168] where Gen(η) is an operation to generate a signal, which modifies the boolean value of the signal variable to True to achieve communication or process synchronization between multiple objects.

[0169] A(x d) and Reset(c) are algebraic equations for discrete variables and clock variables respectively, both representing the reassignment of variables. During the modeling process, the role of Reset(·) is to reset the local clock to zero.

[0170] is defined in the same way as in the Boolean expression. In addition, some action expressions are described by probability variables to represent random events in the model. d ,x c ,c) is defined in the same way as in the Boolean expression. In addition, some action expressions are described by probability variables to represent random events in the model.

[0171] Definition 3: Clock Expression:

[0172]

[0173] Among them, IF and Reset are algebraic inequalities and clock assignment operations respectively. The former judges whether the time-related inequality holds and returns a Boolean value; the latter modifies the clock value or definition and is a branch of the action expression.

[0174] Clock variables are a special type of variable used to describe time-dependent events. It is specified by two parts: c ∷=(τ(c), I(c)). Where τ(c) ∈ R represents the current reading of the clock, and its reading set constitutes a dense sequence of moments. I(c) represents the definition function of the clock, through which ML4TSA provides a means to modify the physical definition of the clock. In the default clock c, there is I(c): τ(c)′ = 1, which means that the clock rate is consistent with the actual time. However, during the actual modeling process, I(c) can define various types of clock types, such as clocks representing different rates like ms and us, and clocks representing different physical meanings like speed and distance. In addition, thanks to the isomorphism of the definition function on its domain, multiple types of clocks can be compared within the same framework.

[0175] To ensure real-time synchronization between different objects, ML4TSA realizes the synchronization of multiple types of clocks among multiple objects through a global clock c global For c global , there is I(c global ): c g ′ lobal = 1. Obviously, for any clock c in ML4TSA, there is That is, any clock can be mapped to the global clock: Therefore, different clock variables in the model can be synchronized and compared through the global clock. During the modeling process, the clock may be modified through clock assignment operations to avoid cumulative errors during system operation. It should be noted that the clock operation Reset does not affect the synchronization between variables. Take the clock reset operation Reset 0 (c): τ(c) = 0 as an example. If the clock readings before and after this operation are τ(c) old and τ(c) new respectively, the clock reading sequence after the operation is Obviously, there exists τ(c) old ≠ τ(c) new . However, as shown below, in order to ensure the accuracy of the mapping to the global clock, ML4TSA adopts a mapping time accumulation mechanism to record the changes caused by the reset operation to clock c.

[0176] f c (τ(c) new ) = f c (τ(c) old )

[0177]

[0178] Obviously, through the accumulation mechanism, the segments of the local clock c mapped to the global clock before and after reset are non-repetitive and adjacent, effectively ensuring the synchronization of clocks in different components.

[0179] Definition 4: Port:

[0180] The port set of a component consists of input ports and output ports, as shown below.

[0181] P = {p | p ∈ (P in ∪ P out )}

[0182] p ∷= {id, type, content, value}

[0183] where id is the unique identifier of the port, type indicates whether the port is an input port or an output port, content is the specific content of the information flow corresponding to the port, and value is a boolean value indicating the existence state of the information flow in the port.

[0184] It should be noted that to simplify the modeling process of information transmission, ML4TSA does not provide the definition of channels between different components, but sets up a synchronization mechanism for input and output port values to ensure information transfer between components. Simply put, if there is an information interaction relationship between two components, it means that there is the same port content between component A and component B, that is p.content = p'.content. At this time, through global variable synchronization, the port values of p and p' will remain consistent, that is

[0185] (2). Semantic definition:

[0186] The formal grammar defines the constituent elements of the model, while the formal semantics defines the dynamic operation rules of the model. In this embodiment, the Labeled Transition System (LTS) is used to define the operational semantics of the language. LTS represents the semantics of the system as the transition rules of states, and describes the dynamic process of the system through state transitions. The definitions of states, valid and invalid transitions are given first below.

[0187] Definition 5 Valid state:

[0188] In ML4TSA, a model instance is usually composed of multiple components and the interactions between components. A component state is defined as a quadruple (s, v, c, p), where s ∈ S is the state name, representing the discrete state of the component; v: Var → value shows the function values associated with state s; c ∈ Clock represents the clock variable, which is shown independently as a special variable due to the real-time characteristics of the system; p = {port.value | port ∈ P} is the real-time information flow situation of each port of the component. According to the above definition of component state, LTS describes the reasonable states of the component. A component Obj state (s, v, c, p) is a reasonable state if and only if it satisfies the following conditions:

[0189] 1). The variable values, clock, and port values satisfy the constraint expressions of the state:

[0190] 2). When the state is the initial state, the variable values, clock, and port values satisfy the initial conditions:

[0191] Definition 6 Valid transition:

[0192] LTS describes the dynamic process of the system as state changes. It includes two categories: state transitions and variable evolutions. A state change process is represented as Similarly, its validity needs to satisfy the following conditions:

[0193] 1). The states before and after the change are both valid states: (s, v, c, p) ∈ Obj.State ∧ (s', v', c', p') ∈ Obj.State;

[0194] 2), if the state names before and after the change are different, there is a corresponding transition between the states, and the transition conditions are satisfied:

[0195] 3), if the state names before and after the change are the same, there is a corresponding evolution rule for the variables within the state:

[0196] Definition 7 System failure:

[0197] When and only when the following situation occurs, a state change process fails:

[0198] 1), the states before and after the change fail:

[0199] 2), the state before the change is about to fail, but the transition condition is not satisfied: where ε →0 represents a positive number approaching 0.

[0200] The state change process of the system includes two types: state transition and variable evolution. These two types of processes are respectively determined by the five factors of the aforementioned state constraint constrain, evolution rule evolution, guard condition guard, trigger signal signal, and transition action action. For a component state (s, v, c, p), if there is no transition (s, t, s′) in the model, its state change process is only constrained by constrain. Based on this, 2 state transition and 3 variable evolution rules are proposed to describe the operational semantics of ML4TSA. The definitions of each semantic rule are given below.

[0201] (1) State transition caused by the trigger signal:

[0202]

[0203] Rule1.1 means that when the component is in the state (s, v, c, p), there is a transition t that enables the component to transfer to the state s′. Both before and after the state change are valid states, and the constraint condition can be satisfied, and the signal signal(t) is triggered. At this time, the component changes from the state s to the state s′ through the transition t. At the same time, the action corresponding to the transition t reassigns (v, c, p) to (v′, c′, p′). The entire state change process is represented as T, indicating a discrete change in the component state. The prob in Rule1.1 is a probability variable, representing the possible random switching during the state change process. Finally, the component switches from the state (s, v, c, p) to the state (s′, v′, c′, p′).

[0204] (2) State transition caused by state constraint violation:

[0205]

[0206] Rule1.2 means that when the component is in the state (s, v, c, p), there exists a transition t such that the component can transfer to the state s′. At the same time, there exists a time interval ε greater than 0 and approaching 0, such that the component will enter the failure state after ε time. At this time, if the changed state (s′, v′, c′, p′) is a valid state and the constraint conditions can be satisfied and the signal signal(t) is triggered, then the component converts from the state s to the state s′ through the transition t. At the same time, the actions corresponding to the transition t reassign (v, c, p) to (v′, c′, p′). The meanings of T and prob are the same as those in Rule1.1. Finally, the component switches from the state (s, v, c, p) to the state (s′, v′, c′, p′).

[0207] (3) Variable evolution caused by the absence of a trigger signal:

[0208]

[0209] Rule2.1 means that when the component is in the state (s, v, c, p), there exists a transition t such that the component can transfer to the state s′. Both the pre-change and post-change states are valid states, but at this time the constraint conditions cannot be satisfied. Therefore, the component cannot convert from the state s to the state s′ through the transition t. However, if there is an evolution rule in the state s, then (v, c, p) will evolve over time. Finally, the component switches from the state (s, v, c, p) to the state (s, v′, c′, p′).

[0210] The process of the evolution rule is described as follows: The evolution rule consists of a set of differential expressions, that is, a set of differentiable functions of continuous variables related to time f: t → x d , and its first derivative is expressed as For a period of time there is τ(c) = γ 1 and τ(c′) = γ 2 , and at the same time there is f(γ 1 ) = v and f(γ 2 ) = v′. For there is and it satisfies the valid state constraint.

[0211] (4) Variable evolution caused by non-compliance with transition conditions:

[0212]

[0213] Rule 2.2 means that when the component is in the state (s, v, c, p), there exists a transition t that enables the component to transfer to the state s′, and the states before and after the change are both valid states. However, at this time, the signal signal(t) cannot be triggered, so the component cannot be converted from the state s to the state s′ through the transition t. However, if there is an evolution rule in the state s, then (v, c, p) will evolve over time, and finally the component will switch from the state (s, v, c, p) to the state (s, v′, c′, p′).

[0214] (5) Variable evolution caused by no migration:

[0215]

[0216] Rule 2.3 means that when the component is in the state (s, v, c, p), there does not exist a transition t that enables the component to transfer to the state s′, but there is an evolution rule in the state s, and the states before and after the change are both valid states, then (v, c, p) will evolve over time, and finally the component will switch from the state (s, v, c, p) to the state (s, v′, c′, p′).

[0217] The operational semantics of ML4TSA are defined by the above five state change rules to ensure the normal operation of the model. In actual modeling, ML4TSA provides two means to model the cyber-physical fusion process of the ATS architecture and scenarios.

[0218] (1) Modeling elements containing port values:

[0219] ML4TSA provides the modeling element of ports, which expands the description ability of traditional UML activity diagrams, enabling it to model the information interaction in the ATS architecture. In the specific ATS architecture and scenario model, the expressions composed of the port value port.value participate in the construction of elements such as state constraints, trigger signals, guard conditions, and migration actions, which can represent the mutual influence between the architecture information and the physical world.

[0220] Figure 4Describes a simple case of vehicle-pedestrian interaction. The lower left figure shows the impact of information transfer in the architecture on the scene state transition. It can be seen that the vehicle can switch from the uniform motion (No_acc) state to the decelerated motion (Neg_acc) state. The guard condition corresponding to this state transition is that the port value of the information flow with the port content of "vehicle braking control scheme" in vehicle Obj is not empty, that is, vehicle Obj generates the corresponding braking decision. Similarly, the lower right figure shows the impact of the physical scene on the generation and transfer of information flow. The generation of the information flow with the port content of "surrounding pedestrian information" in vehicle Obj needs to be triggered by a signal, that is, a pedestrian appears within the detection range of vehicle Obj in the physical world. Through this setting, the information space and the physical space can be connected to achieve the integration of information processes and physical processes.

[0221] (2) Strict cyber-physical clock mapping:

[0222] In the ML4TSA modeling process, the information processing process and the physical motion process respectively describe the system operation processes on the information side and the physical side. During this process, the information process and the physical process adopt strict clock mapping to ensure the smooth interaction between the two.

[0223] As mentioned above, the clock of ML4TSA consists of clock readings and clock definitions. Different clock definitions can be used on the information side and the physical side, and different clock rates can be set to meet specific modeling requirements. At the same time, ML4TSA provides a clock mapping function that can map the local clocks of each process to the global clock for clock comparison. Therefore, the information-side process and the physical-side process will be able to achieve real-time synchronization and strict mapping to ensure the effectiveness of cyber-physical process interaction.

[0224] (III). Modeling tool development and model conversion:

[0225] In the embodiment of the present invention, for the proposed ML4TSA modeling language, a graphical modeling platform is constructed, and the conversion between the ML4TSA model and the stochastic hybrid automaton network is realized to obtain the support of the UPPAAL verification engine.

[0226] As Figure 5 shown, the ML4TSA metamodel covers the elements in the modeling language and clearly considers the syntactic relationships of inclusion, reference, and inheritance between elements. Since the modeling process is essentially the instantiation of elements and relationships in the language, by providing model instance constraints through the metamodel, the generation of unreasonable models can be avoided. Therefore, based on the metamodel in this section, Sirius is used to develop a graphical interface, providing an instantiated editing tool as a means to implement the modeling language in the ATS architecture field. Figure 6It shows its main modules, including a main modeling interface, a tool panel for modeling elements, and a detailed property editing interface. In the main interface, elements such as states, transitions, and ports defined by ML4TSA are represented as graphics, and the relationships between elements are reflected by line segments; the tool panel provides functions such as creating, deleting, and modifying modeling elements, and such functions are restricted by the meta-model to avoid unreasonable operations. The relevant graphical interfaces and tools are shown as Figure 7 shown; the property editing interface supports the editing of the names, expressions, etc. of modeling elements.

[0227] Model files can be exported through EMF (Eclipse Modeling Framework). During the model transformation process, based on the meta-model analysis of ML4TSA and NSHA, mapping rules including global variables, states, transitions, and ports are designed. The transformation process is shown in Table 1. It should be noted that during the information interaction process, the functional execution of each physical object is highly correlated with the values of its input ports, and its inputs come from the output ports of other physical objects. To avoid port value access errors caused by request delays, ports and execution functions in ML4TSA exist as variables in NSHA. By maintaining a global matrix variable, the port values of each physical object are stored. During the interaction process, physical objects can directly access and also directly modify the port value matrix. Efficient matrix query and calculation reduce the model verification cost, and this integration also ensures a high degree of unity between the information interaction clock and the physical operation clock.

[0228] Table 1 Transformation process between the ATS architecture domain model and the network of stochastic hybrid automata

[0229]

[0230]

[0231] During the transformation process, five operational semantics are verified, as shown in Table 2. The verification results show that there are rules corresponding to the operational semantics in NSHA, which ensures the semantic consistency before and after model mapping.

[0232] Table 2 Semantic mapping between MLTSA and NSHA

[0233]

[0234] The instantiated model is transformed into a network of stochastic hybrid automata supported by UPPAAL through the transformation algorithm, as Figure 8 shown. Multiple instantiated models can change their states over time and communicate with each other. In this section, the properties of ATS will be verified based on this.

[0235] Another aspect of the embodiments of the present invention further provides a formal modeling device, including:

[0236] A first module, configured to obtain scenario architecture data, where the scenario architecture data is used to describe physical entities in a scenario and the information interaction relationships between the entities;

[0237] A second module, configured to complete a formal modeling process according to the scenario architecture data, and the process includes the following steps:

[0238] Identify modeling objects based on the scenario architecture, analyze the physical interaction mechanism between the objects, and identify the modeling subjects;

[0239] For each modeling object, define parameter variables that can describe its state and state transition process, and complete parameter definition;

[0240] According to the information interaction relationships described by the scenario architecture, determine the input and output information flows of each object to construct ports for each modeling object; and determine execution functions according to the triggering relationships of the information flows;

[0241] Based on the cyber-physical interaction mechanism of the objects, determine the state and state transition process of the objects; use variables to describe the state, define relevant invariants and variable evolution rules, and determine state boundaries by setting variable constraints; consider the state transition process in the information transmission and physical movement processes, describe this process through migrations, and set the triggering signals, guard conditions, and migration actions corresponding to each migration; in this process, apply port values to the guard conditions and migration actions to achieve cyber-physical integrated modeling;

[0242] Based on a modeling tool, complete the visual expression of the model, and use a model conversion algorithm to convert the ML4TSA model instance into a stochastic hybrid automaton network supported by UPPAAL;

[0243] A third module, configured to finally obtain a verifiable formal model describing the scenario and architecture.

[0244] It can be understood that the contents in the above method embodiments are all applicable to the device embodiments of the present invention. The functions specifically implemented by the device embodiments of the present invention are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0245] The embodiments of the present invention further provide an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the above formal modeling method. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.

[0246] It can be understood that the content in the above method embodiments is applicable to the device embodiments of the present invention. The functions specifically implemented in the device embodiments of the present invention are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0247] The embodiments of the present invention also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above formal modeling method is implemented.

[0248] It can be understood that the content in the above method embodiments is applicable to the storage medium embodiments of the present invention. The functions specifically implemented in the storage medium embodiments of the present invention are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0249] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0250] The embodiments described in the embodiments of the present invention are for more clearly illustrating the technical solutions of the embodiments of the present invention, and do not constitute a limitation on the technical solutions provided by the embodiments of the present invention. Those skilled in the art know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present invention are also applicable to similar technical problems.

[0251] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present invention, and may include more or fewer steps than those shown, or combine certain steps, or different steps.

[0252] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0253] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and appropriate combinations thereof.

[0254] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.

[0255] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0256] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0257] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. And the aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks or optical discs and other various media that can store programs.

[0258] The preferred embodiments of the embodiments of the present invention have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of the present invention. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present invention shall fall within the scope of the rights of the embodiments of the present invention.

Claims

1. A formal modeling method, characterized in that: The following steps are involved: Acquire scene architecture data, where the scene architecture data is used to describe physical entities in the scene and information interaction relationships between entities; The formal modeling process is completed according to the scenario architecture data, and the process includes the following steps: Identify the modeling objects based on the scene architecture, analyze the physical interaction mechanism between objects, and identify the modeling subject; For each modeling object, define parameter variables that can describe its state and state switching process to complete parameter definition; According to the information interaction relationship described by the scenario architecture, the input and output information flows of each object are determined to construct the ports of each modeling object; and the execution function is determined according to the triggering relationship of the information flow; Based on the cyber-physical interaction mechanism of the object, determine the state and state switching process of the object; use variables to describe the state, define relevant invariants and variable evolution rules, and determine the state boundary by setting variable constraints; consider the state switching process during information transmission and physical movement, describe the process through migration, and set the trigger signal, guard condition, and migration action corresponding to each migration; in this process, apply the port value to the guard condition and migration action to realize the fusion modeling of cyber-physics; The model is visualized based on the modeling tool, and the ML4TSA model instance is converted into a random hybrid automaton network supported by UPPAAL using the model conversion algorithm. Finally, a verifiable formal model describing the scenario and architecture is obtained.

2. A formal modeling method according to claim 1, characterized in that: In the step of completing the formal modeling process according to the scenario architecture data, the autonomous traffic architecture modeling language ML4TSA is used as the formal modeling language. The requirements of the autonomous traffic architecture modeling language include: displaying and expressing system status, integrating architecture and scenario characteristics, and providing formal semantic support; Among them, ML4TSA is extended based on UML state diagram to display and express the system state space, and describe the system operation process through variable evolution and state transition; According to the characteristics of ATS architecture and traffic scenarios, modeling elements are added to enrich the descriptive ability of the language, and the formal syntax and semantics of the language are defined to support subsequent formal verification research; ML4TSA uses state and transition description objects. ML4TSA expands the description capability of the state through state constraints and evolution rules. Constraint is used to specify the value range of state-related variables. It formally describes the set of expressions that the variables must maintain in the state and defines the boundaries of the state. Evolution describes the time-related change rules of variables within the state constraint range, reflecting the adaptability of ML4TSA to continuous system processes. At the same time, ML4TSA extends the migration in the state diagram through guard conditions, migration actions and trigger signals. The migration is triggered by the signal event represented by signal and is subject to the guard conditions specified by guard. The reassignment of discrete variables and the generation of signals are specified by the action corresponding to the migration. In order to reflect the information-physical fusion characteristics in the ATS model, ML4TSA defines the port and execution function of the object, and represents the information processing process of the object through the change process of the interface information value.

3. A formal modeling method according to claim 2, characterized in that: The ML4TSA model describes the state change process within several components and the synchronous interaction process between components. For an ML4TSA object, there are: ML4TSA=(S,Var,→,Init,P,F,Cons,Evo) Where S = {s c ,s p } is a set of state names, where s c is the name of the information interaction state, s p is the name of the physical motion state. For any component, its state can be expressed as: s = s c |s p |(s c ,s p ),s c ∈S c ,s p ∈S p , according to its participation in the information space and the physical space, determine whether to use a composite state to describe it; at the same time, the state s is described by the invariant constraint and the evolution rule evolution; Var is a variable set used to describe the state, including five types: discrete variable set DiscreteVar, continuous variable ContinuousVar, clock variable ClockVar, probability variable ProbabilityVar, and signal variable SignalVar; → is a set of migrations of connection states, which consists of a triple, expressed as →:{(s,t,s′)|s,s′∈S,t∈T}, that is, a source state is transformed to a target state through migration, where s is the source state, s′ is the target state, and t=(signal,guard,action) is the migration label, which is described by three attributes: signal is the trigger signal, which is used to indicate the start time of the migration; guard is the guard condition, which is used to determine whether the migration can occur; action is the migration action, which indicates the discrete state change that occurs inside the component after the migration occurs; Init is the initial state set, which specifies the initial state of the component and also determines the initial distribution of variables within the component; P = {p in ,p out } is the port set of the component, where p in and p out They are input and output ports, respectively, used to store the information flows received and generated by the component; F is the information processing function of the component, which is used to describe the functions performed by the component; Evo is the evolution rule set; Cons is the state constraint set.

4. A formal modeling method according to claim 1, characterized in that: The ML4TSA model organizes type variables through expressions and constructs modeling elements, thereby formally describing the system state and state transition process, wherein Boolean expressions are used to describe guard conditions, trigger signals, state constraints, and interface values; Action expressions are used to describe migration actions and evolution rules; clock expressions are used to define time-related constraints; Differentiated expressions are used to describe the response of continuous variables to time; Function expressions are encapsulations of multiple groups of predicates, used to express complex expression logical relationships; Let c be the clock variable, x d 、x c are discrete variables and continuous variables respectively, p is a probability variable, η is a signal variable, and the semantic definitions of Boolean expressions, action expressions, and time expressions are as follows: Boolean expressions: Where η is a Boolean value. When a signal is generated in the system, the corresponding variable value is True, and the expression is satisfied; A(x d ) and IF(c) are algebraic inequalities or algebraic equations for discrete variables and clock variables. When the value of each variable makes the expression valid, the corresponding a(x d ) and IF(c) evaluate to True; for discrete variables that satisfy the algebraic expression, the value r(x d ), expressed as: is a differential inequality or differential equation for a continuous variable, describing a time-dependent continuous variable x c =w(t); within a specific time range r(c), if there exists w(t) which is a differential equation The solution of x c =w(t) makes the expression valid; the process can be expressed as: F(x d ,x c ,c) is a function expression; Action Expression: Among them, Gen(η) is a signal generation operation, which will modify the Boolean value of the signal variable to True to achieve communication or process synchronization between multiple objects; A(x d ) and Reset(c) are algebraic equations of discrete variables and clock variables, respectively. Both represent the reassignment of variables. In the modeling process, the role of Reset(·) is to reset the local clock to zero. and F(x d ,x c ,c) The definition is consistent with that in Boolean expression; Clock expression: Among them, IF and Reset are algebraic inequality and clock assignment operations respectively. The former determines whether the time-related inequality is true and returns a Boolean value; the latter modifies the clock value or definition and is a branch of the action expression. In order to ensure real-time synchronization between different objects, ML4TSA uses a global clock c global Realize the synchronization of multiple types of clocks between multiple objects; in order to ensure the accuracy of mapping with the global clock, ML4TSA adopts a mapping time accumulation mechanism to record the changes caused by the zeroing operation to the clock c.

5. A formal modeling method according to claim 1, characterized in that: The method further includes: defining the operational semantics of the language through the label migration system LTS, expressing the semantics of the system as a state migration rule, and describing the dynamic process of the system through state migration. The definition of state, migration validity and failure is given below: Valid state: In ML4TSA, a model instance is usually composed of multiple components and the interactions between components; a component state is defined as a four-tuple (s, v, c, p), where s∈S is the state name, indicating the discrete state of the component; v: Var→Value shows the function value associated with the state s; c∈Clock represents the clock variable, which is displayed independently as a special variable due to the real-time characteristics of the system; p={port.value|port∈P} is the real-time information flow of each port of the component; According to the definition of component state, LTS describes the reasonable state of the component; A component Obj state (s, v, c, p) is a reasonable state if and only if it satisfies the following conditions: 1) The variable value, clock, and port value satisfy the state constraint expression: (s, v, c, p)∈Obj.Stateiff 2) When the state is the initial state, the variable values, clock, and port values ​​meet the initial conditions: Effective migration: LTS describes the dynamic process of the system as state change, including state migration and variable evolution. A state change process is expressed as Its validity must meet the following conditions: 1) The status before and after the change is valid: 2) If the state names before and after the change are different, there is a corresponding migration between the states and the migration conditions are met: 3) If the state names before and after the change are the same, then there are corresponding evolution rules for the variables in the state: System failure: A state change process occurs if and only if Invalidation: 1) Invalidation of the state before and after the change: 2) The state before the change is about to become invalid, but the migration conditions are not met: where ε →0 Represents a positive number approaching 0.

6. A formal modeling method according to claim 1, characterized in that: The state change process of the system includes state migration and variable evolution. These two processes are determined by five factors: state constraint, evolution rule, guard condition, trigger signal and migration action. For a component state (s, v, c, p), if there is no migration (s, t, s′) in the model, its state change process is only subject to the constraint. The following are the definitions of 2 state migrations and 3 variable evolution rules, which are used to describe the operational semantics of ML4TSA: (1) State transition caused by trigger signal: Rule 1.1 indicates that when a component is in state (s, v, c, p), there is a transition t that enables the component to move to state s′. Both the state before and after the state change are valid. The constraint condition can be satisfied, and the signal signal(t) is triggered. At this time, the component changes from state s to state s′ through migration t. At the same time, the action corresponding to migration t reassigns (v,c,p) to (v′,c′,p′). The entire state change process is represented by T, which represents a discrete change of the component state. The prob in Rule 1.1 is a probability variable, which represents the random switching that may occur during the state change process. Finally, the component switches from state (s,v,c,p) to state (s′,v′,c′,p′). (2) State transition caused by state constraint violation: Rule 1.2 indicates that when a component is in state (s, v, c, p), there is a transition t that enables the component to transfer to state s′. At the same time, there is a time interval ε that is greater than 0 and close to 0, so that the component will enter a failed state after ε time. At this time, if the changed state (s′, v′, c′, p′) is a valid state and the constraint condition can be satisfied and the signal signal(t) is triggered, then the component changes from state s to state s′ through transition t; at the same time, the action corresponding to transition t reassigns (v,c,p) to (v′,c′,p′); the meanings of T and prob are consistent with Rule 1.1, and finally the component switches from state (s,v,c,p) to state (s′,v′,c′,p′); (3) Variable evolution caused by no trigger signal: Rule 2.1 indicates that when a component is in state (s, v, c, p), there is a transition t that enables the component to move to state s′. Both the states before and after the change are valid states. However, the constraint cannot be satisfied, so the component cannot be transformed from state s to state s′ through migration t. If there is an evolution rule in state s, (v, c, p) will evolve over time, and eventually the component will switch from state (s, v, c, p) to state (s, v′, c′, p′); The action process of the evolution rules is described as follows: The evolution rules are composed of a set of differential expressions, that is, a set of time-dependent continuous variable differentiable functions f:t→x d , whose first-order derivative is expressed as ; for a period of time We have τ(c) = γ1, τ(c′) = γ2, and at the same time, we have f(γ1) = v, f(γ2) = v′. Both And satisfy the valid state constraints; (4) Variable evolution caused by failure to meet migration conditions: Rule2.2 indicates that when a component is in state (s, v, c, p), there is a transition t that enables the component to transfer to state s′. The states before and after the change are both valid states, but the signal signal(t) cannot be triggered at this time, so the component cannot be converted from state s to state s′ through transition t. If there is an evolution rule in state s, (v, c, p) will evolve over time, and eventually the component will switch from state (s, v, c, p) to state (s, v′, c′, p′). (5) Variable evolution without migration: Rule 2.3 means that when a component is in state (s, v, c, p), there is no transition t that enables the component to move to state s′, but there is an evolution rule in state s, and the states before and after the change are both valid states, then (v, c, p) will evolve over time, and eventually the component will switch from state (s, v, c, p) to state (s, v′, c′, p′); The above five state change rules define the operational semantics of ML4TSA to ensure the normal operation of the model. At the same time, ML4TSA provides two means to model the cyber-physical integration process of the ATS architecture and the scenario, specifically: (1) Modeling elements containing port values: In the specific ATS architecture and scenario model, the expression composed of the port value port.value participates in the construction of state constraints, trigger signals, guard conditions, and migration action elements, and is used to express the mutual influence between architecture information and the physical world; (2) Strict information-physical clock mapping: In the ML4TSA modeling process, the information processing process and the physical movement process describe the system operation process on the information side and the physical side respectively. In this process, the information process and the physical process adopt strict clock mapping to ensure the smooth interaction between the two.

7. A formal modeling method according to claim 1, characterized in that: The method further comprises: Based on the ML4TSA modeling language, a graphical modeling platform is built, and the conversion between the ML4TSA model and the random hybrid automaton network is realized to obtain the support of the UPPAAL verification engine; The graphical modeling platform includes a main modeling interface, a tool panel for modeling elements, and a detailed property editing interface. In the main interface, the state, transition, port and other elements defined by ML4TSA are represented as graphics, and the relationship between elements is reflected by lines; the tool panel provides the functions of creating, deleting and modifying modeling elements; the property editing interface supports the editing of the name and expression of modeling elements; During the model conversion process, mapping rules including global variables, states, transitions, and ports are designed based on the metamodel analysis of ML4TSA and random hybrid automaton network NSHA; the ports and execution functions in ML4TSA exist in the form of variables in NSHA, and the port values ​​of each physical object are stored by maintaining a global matrix variable.

8. A formal modeling device, characterized in that: include: The first module is used to obtain scene architecture data, where the scene architecture data is used to describe the physical entities in the scene and the information interaction relationship between the entities; The second module is used to complete a formal modeling process according to the scenario architecture data, the process comprising the following steps: Identify the modeling objects based on the scene architecture, analyze the physical interaction mechanism between objects, and identify the modeling subject; For each modeling object, define parameter variables that can describe its state and state switching process to complete parameter definition; According to the information interaction relationship described by the scenario architecture, the input and output information flows of each object are determined to construct the ports of each modeling object; and the execution function is determined according to the triggering relationship of the information flow; Based on the cyber-physical interaction mechanism of the object, determine the state and state switching process of the object; use variables to describe the state, define relevant invariants and variable evolution rules, and determine the state boundary by setting variable constraints; consider the state switching process during information transmission and physical movement, describe the process through migration, and set the trigger signal, guard condition, and migration action corresponding to each migration; in this process, apply the port value to the guard condition and migration action to realize the fusion modeling of cyber-physics; The model is visualized based on the modeling tool, and the ML4TSA model instance is converted into a random hybrid automaton network supported by UPPAAL using the model conversion algorithm. The third module is used to finally obtain a verifiable formal model that describes the scenario and architecture.

9. An electronic device, characterized in that: including a processor and a memory; The memory is used to store programs; The processor executes the program to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The storage medium stores a program, and the program is executed by a processor to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Scene analysis-based system formal model generating method

    CN108009374A

  • A man-machine interaction risk scene recognition method based on formal verification

    CN109783870A

  • Formalized verification method for network physical system requirements based on UPPAAL-SMC

    CN109976712A