Method and system for converting RSML-e model into Luter synchronous data stream language
By converting the RSML-e model into the basic unit of the Luster synchronous data stream language and performing corresponding conversions, the problem of inability to effectively detect system security attributes in the prior art is solved, and effective verification of system security attributes and mitigation of state explosion problems are achieved.
Patent Information
- Application Number
- CN202510208817.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-02-25
AI Technical Summary
The prior art is difficult to convert the RSML-e model into a verifiable Luster synchronous data flow language model, resulting in the inability to effectively detect the security attributes of the system.
By analyzing the RSML-e model, it is converted into the basic units of the Luster synchronous data stream language, including types, boolean expressions, and-or tables, variables, macros and functions, and perform corresponding type conversions, Boolean expression conversions, and-or table conversions, variable conversions, macros and function conversions.
The transformation from the RSML-e model to the Luster synchronous data stream language is realized, so that the security attributes of the system can be verified using model detection tools, alleviating the state explosion problem and improving the security of the system.
Smart Images

Figure CN120144649A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of system security and reliability, and particularly relates to a method and system for converting an RSML -e model into a Luster synchronous data flow language. Background Art
[0002] Model checking is a formal verification technique that allows the detection of properties of a model, such as security, liveness, functionality, etc., by exhaustively exploring the state space, which makes the detection of properties highly automated and simple.
[0003] The starting point of formal analysis is a formal specification language. RSML (Requirements State Machine Language) is a state-based specification language commonly used in fields such as software development, systems engineering, and automation control. It is based on state machine theory and precisely describes the functional and performance requirements of a system by defining various states of the system, the transition conditions between states, and the behavior and output in each state. RSML -e is developed based on the RSML language, and its main difference from the RSML language is that RSML -e supports strict specifications for the interaction between the environment and control software, and it is used by NASA to describe the requirements model for the mode transition of an automatic flight system. The automatic flight system is the core system of modern large aircraft flight control, and the flight mode transition determines the flight control process. The safety verification of mode transition requirements is an important challenge in the development of the automatic flight system. Therefore, it is very important to verify the safety properties of the RSML -e model.
[0004] Although RSML -e has good readability and understandability and is a good communication tool between non-professionals and professionals, RSML -e is not executable, and the model established with RSML -e cannot be model-checked. In addition, the emergence of the state space explosion problem also limits the scale of analyzable models. Therefore, in order to actually detect the security properties of a system, it is necessary to convert it into a suitable verifiable model.
[0005] The model established with the Luster synchronous data flow language is a verifiable model, and when verifying the model established with the Luster synchronous data flow language, methods such as bounded model checking (BMC) and property-directed reachability (PDR) can be applied to alleviate the state explosion problem that may occur during property verification to a certain extent.
[0006] The JKind Model Checker is a model checking tool for the Luster synchronous data flow language and is an open-source industrial-grade model checker. JKind uses multiple parallel engines applied to models with an infinite number of states to prove properties or give counterexamples. The structure of JKind is several parallel engines that coordinate to prove properties, mimicking the designs of PKind and Kind 2. Some engines are directly responsible for proving properties, some assist in this work by generating invariants, and some are reserved for post-processing proof or counterexample results. Each engine can be individually enabled or disabled according to user needs. Refer to Figure 1 , where the bounded model checking (BMC) engine performs standard iterative unfolding of the transition relation to find counterexamples and serves as the base case for k-induction. The BMC engine guarantees that the length of any counterexample it finds is minimal; the k-Induction engine performs the inductive step of k-induction, possibly using invariants generated by other engines; the invariant generation (Inv Gen) engine uses template-based invariant generation techniques and uses its own k-induction loop; the property-directed reachability (PDR) engine performs property-directed reachability using implicit abstraction techniques. Different from BMC and k-induction, each property is handled separately by a different PDR sub-engine. Finally, the Advice engine generates invariants based on previous runs of JKind.
[0007] Therefore, in order to be able to actually detect the security properties of the system, it is necessary to study the transformation from the RSML -e model to the Luster synchronous data flow language. Summary of the Invention
[0008] Object of the Invention: In view of the defects and deficiencies of the above prior art, the object of the present invention is to provide a method and system for transforming from an RSML -e model to the Luster synchronous data flow language.
[0009] Technical Solution: In order to achieve the above object of the invention, the present invention adopts the following technical solutions:
[0010] In a first aspect, a method for transforming from an RSML -e model to the Luster synchronous data flow language includes the following steps:
[0011] Analyze the RSML -e model, and determine the basic units for converting the RSML -e model into the Luster synchronous data flow language as types, boolean expressions, and-or tables, variables, macros, and functions;
[0012] Perform type conversion. For boolean and enumeration types, create a new enumeration type that includes the original values in RSML -e and a specific enumeration value representing undefined; for integer and real types, create a struct type with two elements, one element being an enumeration type indicating whether the value is defined and the other element storing the actual numerical value;
[0013] Perform boolean expression conversion. The boolean variables in RSML -e are directly converted to truth value judgments in Luster; convert the logical NOT in RSML -e to a false value judgment in Luster; convert the PREVIOUS STEP in RSML -e to a call to the pre() function in Luster to reference the state of the previous step; convert the variable comparison in RSML -e to an equality judgment in Luster, and the When conditional judgment in RSML -e is also represented as an equality judgment in Luster;
[0014] Perform and-or table conversion. Convert the boolean variables or expressions in RSML -e to boolean expressions in Luster. Traverse the and-or table column by column and construct a sub-expression for each column. This sub-expression is formed by logically ANDing the boolean expressions in the corresponding rows or their logical NOTs; connect the sub-expressions of all columns with logical OR to form the final Luster boolean expression;
[0015] Perform variable conversion. For ordinary variables, convert them to Luster nodes with input parameters, and use the -> symbol and if-else statements for initial value and conditional assignment. If state conversion is involved, include the value of the previous state as a condition; for input variables, create Luster nodes for them and use the input parameters of the main node as the input parameters of these nodes;
[0016] Perform macro and function conversion. Define Luster nodes for the macros and functions in RSML -e including input parameters and return values. Convert the and-or table logic inside the macros and functions to Luster boolean expressions and assign the results of the boolean expressions to the return values of the nodes.
[0017] Furthermore, when performing type conversion, for boolean types, use True and False with the first letter capitalized in the new enumeration type; for enumeration types, swap the capitalization of the first letter of the enumeration values in the original enumeration type and add them to the new enumeration type; for undefined types, add different suffixes after Undefined as specific enumeration values for undefined and add them to the new enumeration type.
[0018] Further, when performing the and-or table conversion, traverse the and-or table column by column and construct a sub-expression for each column, including:
[0019] Traverse the and-or table column by column and form a sub-expression of the form expr according to the Boolean expression corresponding to the first column for each True or False in each column 1= A 1 and not A 2 and A 3 ......and not A n , expr 2= not A 1 and A 2 and notA 3 ......and A n sub-expressions of the form.
[0020] Further, connect the sub-expressions of all columns by logical OR, including:
[0021] Connect all sub-expressions with or to form a Boolean expression of the form expr 1 or expr 2 ......or expr n Boolean expression of.
[0022] Further, variable conversion also includes: instantiating nodes of the converted ordinary variables and input variables in the main node of Luster.
[0023] Further, macro and function conversion also includes: referencing and instantiating nodes of the converted macros and functions in the main node of Luster.
[0024] Further, the method also includes: in the if-else conditional structure of Luster, taking the condition of the parent variable as the primary judgment condition, and calculating or assigning the value of the child variable or macro only according to subsequent conditions when the condition of the parent variable is satisfied. When the condition of the parent variable is not satisfied, set the default value Undefined for the child variable or macro.
[0025] In a second aspect, a conversion system from an RSML -e model to a Luster synchronous data flow language includes:
[0026] A conversion unit determination module for analyzing the RSML -e model, and determining the basic units of converting the RSML -e model into a Luster synchronous data flow language as types, Boolean expressions, and-or tables, variables, macros, and functions;
[0027] A type conversion module for performing type conversion. For boolean and enumeration types, a new enumeration type is created, including the original value in RSML and a specific enumeration value representing undefined; for integer and real types, a structure type containing two elements is created, one element is an enumeration type indicating whether the value is defined, and the other element stores the actual numerical value; -e In RSML, for integer and real types, a structure type with two elements is created. One element is an enumeration type indicating whether the value is defined, and the other element stores the actual numerical value;
[0028] A boolean expression conversion module for performing boolean expression conversion. In RSML, -e boolean variables are directly converted to truth value judgments in Luster; the logical NOT in RSML -e is converted to a false value judgment in Luster; the PREVIOUS STEP in RSML -e is converted to a call to the pre() function in Luster to reference the state of the previous step; variable comparisons in RSML -e are converted to equality judgments in Luster; the When conditional judgment in RSML -e is also represented as an equality judgment in Luster;
[0029] An and - or table conversion module for performing and - or table conversion. In RSML, -e boolean variables or expressions are converted to boolean expressions in Luster. Traverse the and - or table column by column, and construct a sub - expression for each column. The sub - expression is formed by logically ANDing the boolean expressions in the corresponding rows or their logical NOTs; the sub - expressions of all columns are logically ORed to form the final Luster boolean expression;
[0030] A variable conversion module for performing variable conversion. For ordinary variables, they are converted to Luster nodes with input parameters, and the -> symbol and if - else statements are used for initial value and conditional assignment. If state conversion is involved, the value of the previous state is included as a condition; for input variables, a Luster node is created for them, and the input parameters of the main node are used as the input parameters of this node;
[0031] A macro and function conversion module for performing macro and function conversion. Define Luster nodes for the macros and functions in RSML -e , including input parameters and return values. Convert the and - or table logic within the macros and functions to Luster boolean expressions, and assign the results of the boolean expressions to the return values of the nodes.
[0032] In a third aspect, a computer device includes: one or more processors; a memory; and one or more programs, where the one or more programs are stored in the memory and configured to be executed by the one or more processors, and when the programs are executed by the processors, the steps of the conversion method from the RSML -e model to the Luster synchronous data flow language as described in the first aspect of the present invention are implemented.
[0033] In a fourth aspect, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the conversion method from the RSML -e model to the Luster synchronous data flow language as described above are implemented.
[0034] Beneficial effects: The present invention provides a conversion method from the RSML -e model to the Luster synchronous data flow language. According to the respective syntax characteristics of the RSML -e model and the Luster synchronous data flow language, types, conditions, variables, macros, functions, etc. defined in the RSML -e model are converted into the Luster synchronous data flow language format, that is, the RSML -e model is converted into the Luster synchronous data flow language, so that the security properties of the system can be verified using a model checker (such as The JKIND Model Checker) tool, and the state explosion problem can be alleviated to a certain extent by using the built-in BMC engine, PDR engine, etc. of The JKIND Model Checker, and incorrect or ambiguous requirements in the requirements can be found, improving the security of the system. Description of the Drawings
[0035] Figure 1 It is a structural diagram of the JKind engine;
[0036] Figure 2 It is a flowchart of the conversion method of the present invention;
[0037] Figure 3 It is the RSML -e model corresponding to the type Base_State in the embodiment of the present invention;
[0038] Figure 4 It is the RSML -e model corresponding to the macro When_Turn_FD_On in the embodiment of the present invention;
[0039] Figure 5 It is the RSML -e model corresponding to the state variable NAV in the embodiment of the present invention;
[0040] Figure 6 The RSML corresponding to the input variable Offside_FGS_Active in the embodiments of the present invention -e model;
[0041] Figure 7 The Jkind verification result in the embodiments of the present invention. Detailed implementation manners
[0042] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0043] Refer to Figure 2 , a conversion method from an RSML -e model to the Luster synchronous data flow language is provided in the embodiments of the present invention, including the following steps:
[0044] Step 1: Analyze the RSML -e model to determine the basic units for converting the RSML -e model into the Luster synchronous data flow language, so as to facilitate subsequent conversion of different units.
[0045] Specifically, the RSML -e language supported by the RSML -e model is a synchronous data flow language, and its language specifications include variables, functions, macros, etc. Input variables are used to record the values observed in the environment; state variables are defined in a hierarchical form and are used to simulate various states of the control model; the encapsulation of functions and macros provides readability and usability for users.
[0046] RSML -e language and the Luster synchronous data flow language both support basic variable types. The RSML -e language uses the undefined value to support uncertainty modeling. In the definition of the initial value of a state variable, if the user cannot know the initial state of the environment or the initial state of the environment is uncertain, resulting in the value of the state variable being unknown, then the user can define the initial value of the state variable as undefined to support subsequent state changes. The Luster synchronous data flow language does not have such a built-in mechanism. Therefore, for the clarity of conversion, the present invention converts the type as a separate unit.
[0047] RSML -eThe variables, functions, and macros of the model contain a large number of judgment conditions. These judgment conditions appear in the form of Boolean expressions or in the form of and-or tables. Since there are various types of Boolean expressions and the conversion of and-or tables is relatively complex, for the sake of clear conversion, the present invention separately converts both Boolean expressions and and-or tables as a single unit.
[0048] After the above analysis, in the present invention, RSML -e The basic units for converting the model to the Luster synchronous data flow language are determined to be types, Boolean expressions, and-or tables, variables, macros, and functions.
[0049] Step 2: According to the proposed conversion method, convert each basic unit of the RSML -e model into the Luster synchronous data flow language. According to the embodiments of the present invention, converting the RSML -e model into the Luster synchronous data flow language includes the conversion of types, the conversion of Boolean expressions, the conversion of and-or tables, the conversion of variables, the conversion of macros and functions, and the handling of flattening problems.
[0050] (1) For types, RSML -e supports the use of undefined values, while the Luster synchronous data flow language does not support the use of undefined values. Therefore, the conversion of the types includes the following: converting the data types supported by the RSML -e model into the basic data types supported by the Luster synchronous data flow language.
[0051] According to the embodiments of the present invention, converting the data types supported by the RSML -e model into the basic data types supported by the Luster synchronous data flow language includes: for Boolean and enumeration types, creating a new enumeration type that includes the original values in RSML -e and a specific enumeration value representing undefined. For integer and real types, creating a structure type containing two elements, one element being an enumeration type indicating whether the value is defined, and the other element storing the actual numerical value.
[0052] Specifically, for Boolean and enumeration types, we retain the original Boolean and enumeration types and create a new enumeration type. We put undefined as an enumeration value together with true, false, or the original enumeration values into the newly created enumeration type to represent the same as in RSML -eThe case of uncertain semantics corresponding thereto. It should be noted that the enumerated values of different enumerated types in Luster are not allowed to be repeated, and the present invention needs to retain the original enumerated type as the main node input parameter. Therefore, true, false, and the enumerated values in the original enumerated type cannot be used in the newly created enumerated type, and undefined cannot appear in different enumerated types either. So here, True and False with the first letter capitalized are used in the new enumerated type; for the enumerated values in the original enumerated type, the case of the first letter is swapped and added to the new enumerated type; for undefined, different suffixes are added after it to form Undefined_bool, Undefined_enum1, Undefined_enum2 and added to the new enumerated type. For example, the converted boolean type is type bool2 = enum{True,False,Undefined_bool}.
[0053] For integer or real types, a structure type containing two elements is newly created. One element is an enumerated type {Undefined_int, Defined_int} or {Undefined_real, Defined_real} to store whether it is defined, and the other element is an integer or real type to store the original integer or real type.
[0054] (2) For boolean expressions, in RSML -e contains different forms of boolean expressions. Therefore, the following contents are included in the conversion of boolean expressions: converting the boolean expressions of the RSML -e model into boolean expressions of the Luster synchronous data flow language.
[0055] According to the embodiments of the present invention, converting the boolean expressions of the RSML -e model into boolean expressions of the Luster synchronous data flow language includes: directly converting the boolean variables in RSML -e into truth value judgments in Luster; converting the logical NOT in RSML -e into false value judgments in Luster; converting the PREVIOUS STEP in RSML -e into a call to the pre() function in Luster to reference the state of the previous step; converting the variable comparison in RSML -e into an equality judgment in Luster, and the When conditional judgment in RSML -e is also represented as an equality judgment in Luster.
[0056] Specifically, assume that there is a boolean variable a, and the variable A after type conversion; other type variables b, c, and the variables B, C after type conversion. RSML-e The judgment conditions in the form of: a, not a, PREVIOUS STEP (a), b = c, PREVIOUS STEP (b) = c, When (b = c). For a, the converted Boolean expression is A = True; for not a, the converted Boolean expression is A = False; for PREVIOUS STEP (a), the converted Boolean expression is pre (A) = True; for b = c, the converted Boolean expression is B = C; for PREVIOUS STEP (b) = c, the converted Boolean expression is pre (B) = C; for When (b = c), the converted Boolean expression is B = C.
[0057] (3) For and-or tables, RSML -e The and-or table is often used to express conditions. The rows of the and-or table represent the and (and) relationship, and the columns represent the or (or) relationship. In addition, there is a column of Boolean variables or Boolean expressions in front of the and-or table. Each cell in the and-or table indicates whether the related Boolean variable or Boolean expression is true or not. T represents true (True) and F represents false (False). Therefore, the conversion of the and-or table includes the following: Convert RSML -e The and-or tables in the model are converted to Boolean expressions in Luster's synchronous dataflow language.
[0058] According to an embodiment of the present invention, RSML -e The and-or table in the model is converted to a Boolean expression in Luster Synchronous Data Flow Language, including: -e Convert the Boolean variables or expressions in to Boolean expressions in Luster, traverse the and-or table by column, and build a sub-expression for each column. The sub-expression is formed by connecting the Boolean expressions of the corresponding row or their logical negation through logical AND; connect the sub-expressions of all columns through logical OR to form the final Luster Boolean expression.
[0059] Specifically, suppose the Boolean expression before the table is a 1 , a 2 , a 3 ......a n , the Boolean expression converted by the above Boolean expression conversion method is A 1 , A 2 , A 3 ......A n , the transformations in the and-or table include:
[0060] (3-1) Traverse the and-or table column by column, and form sub-expressions in the form of expr according to the Boolean expressions in the first column corresponding to T or F in each column 1= A 1 and not A 2 and A 3 ......and not A n ,expr 2= not A 1 and A 2 and notA 3 ......and A n ;
[0061] (3-2) Connect all sub-expressions with or to form a Boolean expression in the form of expr 1 or expr 2 ......or expr n .
[0062] (4) For variables, variables are divided into two types, one is ordinary variables and the other is input variables. The value of an ordinary variable depends on the values of other variables in the current state or itself or other variables in the previous state; the value of an input variable does not depend on other variables and is not subject to other constraints except for the initial value. Therefore, the following content is included in the conversion of variables: Convert the variables of the RSML -e model into nodes of the Luster synchronous data flow language.
[0063] According to the embodiments of the present invention, converting the variables of the RSML -e model into nodes of the Luster synchronous data flow language includes: for ordinary variables, convert them into Luster nodes with input parameters, use the -> symbol and if-else statements for initial value and conditional assignment, and if state transition is involved, include the value of the previous state as a condition; for input variables, create Luster nodes for them and use the input parameters of the main node as the input parameters of these nodes.
[0064] Specifically, for ordinary variables, convert it into a node in Luster, and use the other variables it depends on as the input parameters of this node. After converting the Boolean expressions and and-or tables in it into Boolean expressions of Luster synchronous data flow language using the above method, specify the initial value with the -> symbol in Luster, and assign values to the variables using if-else statements. For example, if the initial value of variable a is b, its value is d when the condition (Boolean expression or and-or table) c is satisfied, its value is f when the condition e is satisfied, and g otherwise. After conversion, a, b, c, d, e, f, g become A, B, C, D, E, F, G. Then the converted variable A is:
[0065] node A(other variables that a depends on are used as the input parameters of this node) returns (result: type(A));
[0066] let
[0067] result = B -> if C then D else if E then F else G;
[0068] tel;
[0069] It should be noted that the conversion between states is sometimes involved in ordinary variables. In this case, the value of the previous state is added as a condition to the relevant Boolean expression. For example, d -> b if h is added to the above variable a. After conversion, h becomes H. Then the converted variable A is:
[0070] node A(other variables that a depends on are used as the input parameters of this node) returns (result: type(A));
[0071] let
[0072] result = B -> if C then D else if E then F else if pre(result) = D and H then B else G;
[0073] tel;
[0074] For input variables, declare them in the input parameters of the main node. However, since the input parameters of the main node in Luster are randomly assigned, while the input variables in RSML -e have initial values, the present invention also creates a node for the input variables and uses the input parameters of the main node as the input parameters of this node to achieve the effect of assigning initial values. For example, if the input variable a is a Boolean value and its initial value is true, then the converted variable A is:
[0075] node A(iv_A:bool) returns (result:bool2);
[0076] let
[0077] result = True -> if iv_A = true then True then False;
[0078] tel;
[0079] iv_A is declared among the input parameters of the main node:
[0080] node main(iv_A:bool) returns (result:bool)
[0081] It should be noted that the nodes of the above-mentioned ordinary variables and input variables need to be instantiated in the main node.
[0082] The main node is the core of the Luster synchronous data flow language. JKIND only analyzes the attributes of the main node. Therefore, all other nodes must be instantiated in the main node to be called or used for attribute analysis. The input parameters of the main node do not depend on other nodes. In other words, their values can be freely changed. Therefore, they are used as the input parameters of the input variable nodes.
[0083] (5) For macros and functions, RSML -e The macros and functions in the model are used to represent combinations of conditional events. This definition method can avoid the situation where the conditional table under a certain event is too long. Therefore, the conversion of macros and functions includes the following: converting the macros and functions of the RSML -e model into nodes of the Luster synchronous data flow language.
[0084] According to the embodiments of the present invention, converting the macros and functions of the RSML -e model into nodes of the Luster synchronous data flow language includes: defining Luster nodes for the macros and functions of the RSML -e , including input parameters and return values, converting the and-or table logic in the macros and functions into Luster boolean expressions, and assigning the result of the boolean expression to the return value of the node.
[0085] Specifically, create a node with a return value of result for the macro and function, use the other variables it depends on as the input parameters of this node, convert the and-or table in the macro and function into a boolean expression of the Luster synchronous data flow language using the above and-or table conversion method, assign this boolean expression to result, and instantiate this node in the main node.
[0086] (6) Flattening problem
[0087] RSML -e The model is a hierarchical model that supports the definition of parent variables or macros and child variables or macros in the following way: in a child variable or macro, the parent variable or macro is defined with the Parent keyword and the conditional constraints of the parent variable or macro on the child variable or macro. However, the Luster synchronous data flow language does not support hierarchy, so flattening is required.
[0088] The processing of the present invention for the flattening problem includes the following: placing the parent variable conditions of the RSML -e model at the head of the if-else condition of the Luster synchronous data flow language. Only when the parent variable conditions are met can the next conditional judgment be made; otherwise, the variable will be in the initial value Undefined.
[0089] The above describes the process of the conversion method from the RSML -e model to the Luster synchronous data flow language proposed by the present invention. To have a clearer understanding of the implementation method and advantages of the above technical solution, next, taking the RSML -e model of the flight guidance system proposed in the literature "Steven P. Miller, Alan C. Tribble, Timothy M. Carlson, and Eric J. Danielson Rockwell Collins, Cedar Rapids, Iowa. Flight Guidance System Requirements Specification [M]. 2003.]" as an example, the conversion method described in the content of the present invention is used to convert this model into the Luster synchronous data flow language.
[0090] Since this RSML -e model is too large, a part of the model is intercepted to illustrate the above invention content. Converting the RSML -e model into the Luster synchronous data flow language includes the following:
[0091] The first part: Conversion of types. Taking the type Base_State in the RSML -e model as an example to illustrate the conversion of types. The details of the RSML -e model are shown in Figure 3 . From Figure 3It can be known that this type is an enumeration type with two optional values, namely "Cleared" and "Selected", which are used to represent whether a specific flight mode is selected in the requirement model of the automatic flight system mode conversion. The steps to convert it into the Luster synchronous data flow language type are as follows:
[0092] 1. Retain the original enumeration type type Base_State = enum{Cleared,Selected} as the type of the main node input parameter;
[0093] 2. Create a new enumeration type type Base_State2 = enum{cleared,selected,Undifined_Base_State} to represent the uncertain situation of the semantics existing in RSML -e in.
[0094] 3. Finally, this type is converted into two types in the Luster synchronous data flow language, and the manifestation is as follows:
[0095] type Base_State = enum{Cleared,Selected};
[0096] type Base_State2 = enum{cleared,selected,Undifined_Base_State}.
[0097] The second part: The conversion of boolean expressions. Take the boolean expressions involved in the macro When_Turn_FD_On and the state variable NAV in the RSML -e model to illustrate the conversion of boolean expressions. The RSML -e model details can be seen in Figure 4 and Appendix 5. Among them, When_Turn_FD_On is used to represent whether the flight director is turned on, and NAV represents whether the navigation mode (NAV) is selected. The conversion methods include:
[0098] 1. The boolean expression When_FD_Switch_Pressed_Seen in the macro When_Turn_FD_On is converted to When_FD_Switch_Pressed_Seen = True;
[0099] 2. The boolean expression When(AP = Engaged) in the macro When_Turn_FD_On is converted to AP = engaged;
[0100] 3. The Boolean expression Pilot_Flying = LEFT in the macro When_Turn_FD_On is converted to Pilot_Flying = lEFT;
[0101] 4. The Boolean expression PREVIOU STEP(Mode_Annunciations_On) in the macro When_Turn_FD_On is converted to pre(Mode_Annunciations_On) = True;
[0102] 5. The Boolean expression not Is_This_Side_Active in the state variable NAV is converted to Is_This_Side_Active = False;
[0103] 6. The Boolean expression PREVIOU STEP(NAV_Selected) = Armed in the state variable NAV is converted to pre(NAV_Selected) = armed.
[0104] Part Three: Conversion of the and - or table, taking the and - or table in the macro When_Turn_FD_On in the RSML -e model as an example to illustrate the conversion of the and - or table. The RSML -e model details can be seen Figure 4 , and the steps to convert it to the Luster synchronous data - flow language type are as follows:
[0105] 1. Traverse the and - or table column - by - column, and form expr according to the Boolean expression corresponding to the first column for each column T or F 1 = When_FD_Switch_Pressed_Seen = True, expr 2 = AP = engaged, expr 3 = Overspeed_Condition = True, expr 4 = When_Lateral_Mode_Manually_Selected = True, expr 5 = When_Vertical_Mode_Manually_Selected = True, expr 6 = the sub - expression of (When_Pilot_Flying_Transfer = True and pre(Mode_Annunciations_On) = True and Pilot_Flying = lEFT);
[0106] 2. Connect all sub - expressions with "or" to form the Boolean expression When_FD_Switch_Pressed_Seen = True or AP = engaged or Overspeed_Condition = True or When_Lateral_Mode_Manually_Selected = True or When_Vertical_Mode_Manually_Selected = True or (m_When_Pilot_Flying_Transfer = True and pre(Mode_Annunciations_On) = True and Pilot_Flying = LEFT).
[0107] Part IV: Conversion of Variables, Taking the State Variable NAV and the Input Variable Offside_FGS_Active in the RSML -e model as an example to illustrate the conversion of variables. The RSML -e model is shown in Figure 5 and Figure 6 , where Offside_FGS_Active indicates whether the flight guidance system (FGS) on the other side is activated.
[0108] For the state variable NAV, as an ordinary variable, without considering its parent variable, the steps to convert it to the Luster synchronous data - flow language type are as follows:
[0109] 1. Create a new node: node NAV(Is_This_Side_Active,Select_NAV,Deselect_NAV,Dearm_NAV,Deactivate_NAV:bool2;Mode s:onoff2;Offside_NAV:basestate2;NAV_Selected:selectedstate2)returns(result:basestate2);
[0110] 2. After converting the involved Boolean expressions and and - or tables into the Luster synchronous data - flow language, specify the initial value using the -> symbol in Luster and assign values to variables using if - else statements: result = Undifined_Base_State -> if Is_This_Side_Active = False then Offside_NAV else if pre(result) = Undifined_Base_State and m_Select_NAV = False and Is_This_Side_Active = True then Cleared else if pre(result) = Undifined_Base_State and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Cleared and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Selected and ((Deselect_NAV = True and Is_This_Side_Active = True) or (Dearm_NAV = True and pre(NAV_Selected) = Armed and Is_This_Side_Active = True) or (Deactivate_NAV = True and pre(NAV_Selected) = Active and Is_This_Side_Active = True)) then Cleared else pre(result);
[0111] 3. The final representation in the Luster synchronous data - flow language is as follows:
[0112] node NAV(Is_This_Side_Active,Select_NAV,Deselect_NAV,Dearm_NAV,Deactivate_NAV:bool2;Mode s:onoff2;Offside_NAV:basestate2;NAV_Selected:selectedstate2)returns(result:basestate2);
[0113] let
[0114] result = Undifined_Base_State->if Is_This_Side_Active = False then Offside_NAV else if pre(result) = Undifined_Base_State and m_Select_NAV = False and Is_This_Side_Active = True then Cleared else if pre(result) = Undifined_Base_State and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Cleared and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Selected and ((Deselect_NAV = True and Is_This_Side_Active = True) or (Dearm_NAV = True and pre(NAV_Selected) = Armed and Is_This_Side_Active = True) or (Deactivate_NAV = True and pre(NAV_Selected) = Active and Is_This_Side_Active = True)) then Cleared else pre(result);
[0115] tel;
[0116] For the input variable Offside_FGS_Active, the steps to convert it to the Luster synchronous data flow language type are as follows:
[0117] 1. Create a new node Node Offside_FGS_Active(iv_Offside_FGS_Active:bool) returns (result:bool2);
[0118] 2. After specifying the initial value with the -> symbol in Luster, assign the result using the input parameter iv_Offside_FGS_Active: result = True -> if iv_A = true then True then False;
[0119] 3. Declare iv_Offside_FGS_Active in the input parameters of the main node: node main(iv_Offside_FGS_Active:bool) returns(result:bool);
[0120] 4. Finally, the representation in the Luster synchronous data flow language is as follows:
[0121] node Offside_FGS_Active(iv_Offside_FGS_Active:bool) returns(result:bool2);
[0122] let
[0123] result = Undefined -> if iv_Offside_FGS_Active = true then True else False;
[0124] tel;
[0125] node main(iv_Offside_FGS_Active:bool) returns(result:bool);
[0126] Part Five. Regarding the handling of the flattening problem, take the state variable NAV in the RSML -e model as an example to illustrate the handling of the flattening problem. The RSML -e model details are as follows Figure 5 . From Figure 5 it can be learned that this state variable has a parent variable Modes. When and only when Modes = On holds, the state variable NAV can migrate to the value of the next state according to its state transition conditions. Otherwise, the value of this state variable remains its initial value UNDEF INED unchanged. Since the Luster synchronous data flow language does not support hierarchical structures, flattening processing is required. The processing steps are as follows:
[0127] 1. Take the RSML -eThe parent variable condition of the model is placed at the top of the if-else condition of the Luster synchronous data flow language. Only when the parent variable condition is satisfied can the next condition judgment be carried out; otherwise, the variable will be in the initial value Undefined: result = Undifined_Base_State -> if not (Modes = On) then Undefined_Base_State else if Is_This_Side_Active = False then Offside_NAV else if pre(result) = Undifined_Base_State and m_Select_NAV = False and Is_This_Side_Active = True then Cleared else if pre(result) = Undifined_Base_State and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Cleared and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Selected and ((Deselect_NAV = True and Is_This_Side_Active = True) or (Dearm_NAV = True and pre(NAV_Selected) = Armed and Is_This_Side_Active = True) or (Deactivate_NAV = True and pre(NAV_Selected) = Active and Is_This_Side_Active = True)) then Cleared else pre(result);
[0128] 2. Finally, the manifestation in the Luster synchronous data flow language is as follows:
[0129] node NAV(Is_This_Side_Active,Select_NAV,Deselect_NAV,Dearm_NAV,
[0130] Deactivate_NAV:bool2; Modes:onoff2; Offside_NAV:basestate2; NAV_Selected:selectedst ate2) returns (result:basestate2);
[0131] let
[0132] result = Undifined_Base_State -> if not (Modes = On) then Undefined_Base_State else if Is_This_Side_Active = False then Offside_NAV else if pre(result) = Undifined_Base_State and m_Select_NAV = False and Is_This_Side_Active = True then Cleared else if pre(result) = Undifined_Base_State and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Cleared and Select_NAV = True and Is_This_Side_Active = True then Selected else if pre(result) = Selected and ((Deselect_NAV = True and Is_This_Side_Active = True) or (Dearm_NAV = True and pre(NAV_Selected) = Armed and Is_This_Side_Active = True) or (Deactivate_NAV = True and pre(NAV_Selected) = Active and Is_This_Side_Active = True)) then Cleared else pre(result);
[0133] tel;
[0134] The ultimate goal of the present invention is to RSML -eVerify the safety properties of the model. For example, the flight guidance system mentioned above has a property: if this side is active and the mode signal is off, then when the opposite side FD is on, the mode signal should be on. Represent it in the Luster synchronous data flow language as prop1 = (pre(Mode_Annunciations_On) = False and pre(Onside_FD_On) = False and Is_This_Side_Active = True and Onside_FD_On = True) => Mode_Annunciations_On = True; Finally, after inputting the transformed model and the safety property into the JKIND tool, we get Figure 7 the result, which indicates that this safety property is compliant.
[0135] Based on the same inventive concept as the method embodiment, in another embodiment of the present invention, a conversion system from an RSML -e model to the Luster synchronous data flow language is provided, including:
[0136] A conversion unit determination module for analyzing the RSML -e model and determining the basic units of converting the RSML -e model into the Luster synchronous data flow language as types, boolean expressions, and-or tables, variables, macros, and functions;
[0137] A type conversion module for performing type conversion. For boolean and enumeration types, create a new enumeration type that includes the original values in the RSML -e and a specific enumeration value representing undefined; for integer and real types, create a structure type containing two elements, one element is an enumeration type indicating whether the value is defined, and the other element stores the actual numerical value;
[0138] A boolean expression conversion module for performing boolean expression conversion. The boolean variables in the RSML -e are directly converted to truth value judgments in Luster; the logical not in the RSML -e is converted to a false value judgment in Luster; the PREVIOUS STEP in the RSML -e is converted to a pre() function call in Luster to reference the state of the previous step; the variable comparison in the RSML -e is converted to an equality judgment in Luster, and the When conditional judgment in the RSML -e is also represented as an equality judgment in Luster;
[0139] The AND-OR table conversion module is used to perform AND-OR table conversion, converting the Boolean variables or expressions in RSML -e into Boolean expressions in Luster. Traverse the AND-OR table column by column, construct a sub-expression for each column, which is formed by connecting the Boolean expressions in the corresponding rows or their logical negations through logical AND; connect the sub-expressions of all columns through logical OR to form the final Luster Boolean expression;
[0140] The variable conversion module is used to perform variable conversion. For ordinary variables, convert them into Luster nodes with input parameters, use the -> symbol and if-else statements for initial value and conditional assignment. If state conversion is involved, include the value of the previous state as a condition; for input variables, create a Luster node for them and use the input parameters of the main node as the input parameters of this node;
[0141] The macro and function conversion module is used to perform macro and function conversion, define Luster nodes for the macros and functions in RSML -e including input parameters and return values, convert the AND-OR table logic in the macros and functions into Luster Boolean expressions, and assign the result of the Boolean expression to the return value of the node.
[0142] It should be understood that the conversion system from the RSML -e model to the Luster synchronous data flow language provided in this embodiment can implement all the technical solutions in the above method embodiments. The functions of its respective functional modules can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can refer to the relevant descriptions in the above embodiments and will not be elaborated here.
[0143] The present invention also provides a computer device, including: one or more processors; a memory; and one or more programs, where the one or more programs are stored in the memory and are configured to be executed by the one or more processors. When the program is executed by the processor, it implements the steps of the conversion method from the RSML -e model to the Luster synchronous data flow language as described above.
[0144] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the conversion method from the RSML -e model to the Luster synchronous data flow language as described above.
[0145] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus (system), a computer device, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0146] The present invention is described with reference to the flowchart of the method according to the embodiments of the present invention. It should be understood that each process in the flowchart and the combination of processes in the flowchart can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in one Figure 1 process or multiple processes.
[0147] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in one Figure 1 process or multiple processes.
[0148] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for realizing the functions specified in one Figure 1 process or multiple processes.
Claims
1. A method from RSML -e The method for converting a model into Luster synchronous data flow language is characterized in that: The following steps are involved: About RSML -e The model is analyzed and the RSML -e The basic units of the model conversion into Luster synchronous data flow language are determined as types, Boolean expressions, and-or tables, variables, macros, and functions; Perform type conversion, for Boolean and enumeration types, create new enumeration types, including RSML -e The original value in and the specific enumeration value that represents undefined; for integer and real types, create a structure type with two elements, one element is the enumeration type, indicating whether the value is defined, and the other element stores the actual value; Perform Boolean expression conversion, RSML -e The Boolean variables in RSML are directly converted into truth value judgments in Luster; -e The logical negation in RSML is converted to a false value judgment in Luster; -e The PREVIOUS STEP in RSML is converted to a pre() function call in Luster to reference the state of the previous step; -e The variable comparison in RSML is converted to the equivalent judgment in Luster. -e The When conditional judgment in Luster is also expressed as an equivalence judgment; Perform and-or table conversion to convert RSML -e Convert the Boolean variables or expressions in the and-or table to Boolean expressions in Luster, traverse the and-or table by column, and build a sub-expression for each column. The sub-expression is formed by connecting the Boolean expressions of the corresponding row or their logical negation through logical AND; connect the sub-expressions of all columns through logical OR to form the final Luster Boolean expression; Perform variable conversion. For ordinary variables, convert them into Luster nodes with input parameters. Use the -> symbol and if-else statement to assign initial values and conditions. If state conversion is involved, include the value of the previous state as a condition. For input variables, create a Luster node for it and use the input parameters of the main node as the input parameters of this node. Convert macros and functions to RSML -e The macros and functions in the Luster node are defined, including input parameters and return values. The and-or table logic in the macros and functions is converted into a Luster Boolean expression, and the result of the Boolean expression is assigned to the return value of the node.
2. The method according to claim 1, characterized in that: When performing type conversion, for Boolean types, use True and False with uppercase first letters in the new enumeration type; for enumeration types, the enumeration values in the original enumeration type are added to the new enumeration type with the first letters swapped in upper and lower cases; for undefined types, add different suffixes after Undefined as undefined specific enumeration values and add them to the new enumeration type.
3. The method according to claim 1, characterized in that When performing an and-or table conversion, the and-or table is traversed column by column, and a sub-expression is built for each column, including: Traverse the and-or table by column, and form the Boolean expression of the first column corresponding to each column True or False in the form of expr 1= A1 and not A2 and A3......and not A n , expr 2= not A1 and A2 and notA3......and A n subexpression of .
4. The method according to claim 3, characterized in that Connect all column sub-expressions with logical OR, including: Connect all sub-expressions with or to form the form expr1 or expr2...or expr n A Boolean expression for .
5. The method according to claim 1, characterized in that Variable conversion also includes: instantiating nodes of converted common variables and input variables in the main node of Luster.
6. The method according to claim 1, characterized in that Performing macro and function conversion also includes: referencing and instantiating the converted macro and function nodes in the main node of Luster.
7. The method according to claim 1, characterized in that The method also includes: in the if-else conditional structure of Luster, the condition of the parent variable is used as the primary judgment condition, and the value of the child variable or macro is calculated or assigned according to the subsequent conditions only when the parent variable condition is met, and when the parent variable condition is not met, the default value Undefined is set for the child variable or macro.
8. A method from RSML -e The model to Luster synchronous data flow language conversion system is characterized by: include: Conversion unit determination module for RSML -e The model is analyzed and the RSML -e The basic units of the model conversion into Luster synchronous data flow language are determined as types, Boolean expressions, and-or tables, variables, macros, and functions; Type conversion module, used for type conversion, for Boolean and enumeration types, create new enumeration types, including RSML -e The original value in and the specific enumeration value that represents undefined; for integer and real types, create a structure type with two elements, one element is the enumeration type, indicating whether the value is defined, and the other element stores the actual value; Boolean expression conversion module, used for Boolean expression conversion, RSML -e The Boolean variables in RSML are directly converted into truth value judgments in Luster; -e The logical negation in RSML is converted to a false value judgment in Luster; -e The PREVIOUS STEP in RSML is converted to a pre() function call in Luster to reference the state of the previous step; -e The variable comparison in RSML is converted to the equivalent judgment in Luster. -e The When conditional judgment in Luster is also expressed as an equivalence judgment; and-or table conversion module, used to convert and-or tables to RSML -e Convert the Boolean variables or expressions in the and-or table to Boolean expressions in Luster, traverse the and-or table by column, and build a sub-expression for each column. The sub-expression is formed by connecting the Boolean expressions of the corresponding row or their logical negation through logical AND; connect the sub-expressions of all columns through logical OR to form the final Luster Boolean expression; The variable conversion module is used to convert variables. For ordinary variables, they are converted into Luster nodes with input parameters. The -> symbol and if-else statement are used to assign initial values and conditions. If state conversion is involved, the value of the previous state is included as a condition. For input variables, a Luster node is established for it, and the input parameters of the main node are used as the input parameters of this node. Macro and function conversion module, used to perform macro and function conversion, for RSML -e The macros and functions in the Luster node are defined, including input parameters and return values. The and-or table logic in the macros and functions is converted into a Luster Boolean expression, and the result of the Boolean expression is assigned to the return value of the node.
9. A computer device, characterized in that: include: one or more processors; Memory; and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and when the programs are executed by the processors, the RSML from any one of claims 1 to 7 is implemented -e Steps of the method to convert the model to Luster synchronous data flow language.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the RSML -e Steps of the method to convert the model to Luster synchronous data flow language.
Citation Information
Patent Citations
Avionics system oriented formalized modeling and verifying method based on requirements
CN106598566A
Conversion method of converting RSML-e model into NuSMV model
CN108363631A
Model formalized verification method based on extended Lustre language
CN116150005A
Model conversion method and system
CN116679934A
Applications for low code, internet of things, and highly distributed environments
WO2024148327A1