Common mode analysis method and system for integrated modular system (IMS)
By determining the common mode analysis input, identifying independence requirements and sorting out the common mode sources in the integrated modular system IMS, the problem of insufficient common mode analysis in the existing technology is solved, and a deeper security analysis and improved system design security are achieved.
Patent Information
- Application Number
- CN202510927338.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2045-07-07
AI Technical Summary
Existing common-mode analysis methods take fewer factors into consideration in the design of integrated modular systems (IMS) and cannot effectively solve potential common-mode problems in the design of deep coupling of software and hardware.
A common mode analysis method for an integrated modular system (IMS) is provided, including determining common mode analysis inputs and items, identifying independence requirements, sorting out common mode sources, analyzing design solutions, judging common mode situations, and performing failure/error analysis when common modes exist, and providing improvement measures.
It enables deeper security analysis of the integrated modular system (IMS), identifies common mode impacts, and improves the security level of system design.
Smart Images

Figure CN120471749B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the technical field of common mode analysis of an integrated modular system (IMS), and specifically relates to a common mode analysis method and system for an integrated modular system (IMS). Background Art
[0002] Since the 1970s, with the rapid development of electronic technology, aircraft avionics systems have become increasingly complex. In the 21st century, avionics systems face severe challenges in cost, performance, and reliability. Major global aircraft manufacturers, such as Boeing and Airbus, have adopted an Integrated Modular System (IMS) design for their avionics systems, in line with current avionics technology development trends and research results.
[0003] The Integrated Modular System (IMS) is a universal processing platform that shares hardware and software resources. It provides aircraft with resident functions, data computation, data management, data transmission, timing, and health management. The resident functions are designed to meet top-down decomposition requirements and typically include navigation, trajectory planning, wireless communications, and health monitoring. The IMS platform's main components include hardware such as general processing modules, power modules, switches, and interface units. Software is generally divided into resident software and platform software. Resident software implements resident functions, while platform functions support the operation of resident functions, platform movement, and resource management.
[0004] Common mode analysis is a key task in the design of integrated modular systems (IMSs). It primarily involves input analysis, independence requirement confirmation, common mode type analysis, common mode applicability analysis, and common mode failure / error impact analysis. Currently, common mode analysis is a simple process that considers few factors and cannot effectively address potential common mode issues in IMSs, which involve deep hardware and software coupling.
[0005] This application is proposed in view of the above-mentioned technical defects. Summary of the Invention
[0006] The purpose of the present application is to provide a common mode analysis method and system for an integrated modular system IMS, so as to overcome or alleviate at least one of the existing technical deficiencies.
[0007] The technical solution of this application is:
[0008] On the one hand, a common mode analysis method of an integrated modular system (IMS) is provided, comprising:
[0009] S1. Determine the input of common mode analysis and its common mode items;
[0010] S2. For each common model item, identify the independence requirements of each clause;
[0011] S3. Based on the independence requirements and the common model source table, sort out the common model sources applicable to each common model project;
[0012] S4. Analyze the common mode design scheme based on the common mode source to determine whether there is a common mode situation;
[0013] S5. When common mode conditions exist, conduct common mode failure / error analysis and provide improvement measures for the system logic architecture and functional architecture design;
[0014] S6. When there is no common mode, perform system-level and device-level verification, and review the effectiveness of the verification to determine whether the common mode design solution meets the independence requirements;
[0015] S7. When the common mode design scheme does not meet the independence requirements, conduct common mode failure / error analysis and provide improvement measures for the system logical architecture and functional architecture design.
[0016] Optionally, in the common mode analysis method of the integrated modular system IMS, in S1, it is determined that the types of common mode analysis inputs include failure level class, reconfiguration function class, shared rack class, and shared line replaceable unit (LRM) class.
[0017] Optionally, in the common mode analysis method of the integrated modular system IMS, in S2, the common mode analysis input type is a failure level input, and the corresponding independence requirement is that the functions, systems, or devices to which the type I and II fault trees and the events under the gates belong are independent of each other;
[0018] The common mode analysis input type is the input of the reconstruction function class, and the corresponding independence requirement is that the software and hardware on which the failure state depends are independent of each other;
[0019] The common mode analysis input type is the shared rack input, and the corresponding independence requirement is that the hardware dependent on each function and the platform are independent of each other;
[0020] The common mode analysis input type is the input of the common field replaceable unit (LRM) class. The corresponding independence requirements are that the software and hardware on which the functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other.
[0021] Optionally, in the common mode analysis method of the integrated modular system IMS, in S3, for each independence requirement, the common mode types provided in the common mode source table are traversed, and applicable common mode sources are analyzed one by one;
[0022] The common mode source table is a dedicated common mode analysis table developed based on the characteristics of the integrated modular system (IMS), including common mode type, common mode sub-type, common mode source, solution analysis requirements, and common mode failure / error examples;
[0023] Common mode types include energy, gas source, software, and hardware;
[0024] Common sources of energy include common power supplies, common functions in power distribution, and common distribution cables.
[0025] The common mode sources corresponding to the gas source include shared equipment, shared pipelines, and shared forced ventilation devices;
[0026] The common mode subtypes corresponding to software include shared data information, shared general system management, and shared application software management; the common mode sources corresponding to shared data information include shared discrete signals and shared bus data; the common mode sources corresponding to shared general system management include shared health monitoring functions, shared fault management, shared configuration management, and shared security management; the common mode sources corresponding to shared application software management include shared partitions, shared process scheduling, shared memory, shared inter-zone communication, and shared health monitoring;
[0027] The common mode subtypes corresponding to the hardware include shared communication links and shared hardware installation processes; the common mode sources corresponding to the shared communication links include shared external buses, shared internal buses, and shared interfaces; the common mode sources corresponding to the shared hardware installation processes include the same installation processes, the same installation appearance designs, and the same installation personnel.
[0028] Optionally, in the common mode analysis method of the integrated modular system IMS,
[0029] In S4, based on the input and output of the system logical architecture and functional architecture, it is judged whether the common mode design scheme has eliminated the hazards caused by the common mode. If the common mode design scheme has eliminated the hazards caused by the common mode, it is judged that there is no common mode situation. If the common mode design scheme has not eliminated the hazards caused by the common mode, it is judged that there is a common mode situation.
[0030] On the other hand, a common mode analysis system for an integrated modular system IMS is provided to implement the common mode analysis method for the integrated modular system IMS, comprising:
[0031] A common mode analysis input item determination module is used to determine the input of the common mode analysis and its common mode items;
[0032] Independence requirement identification module, for each common model project, identifies the independence requirement of each clause;
[0033] The common model source sorting module sorts out the common model sources applicable to each common model project based on the common model source table according to the independence requirements;
[0034] The common mode situation judgment module analyzes the common mode design scheme based on the common mode source and determines whether a common mode situation exists;
[0035] The verification validity review module performs system-level and device-level verification when there is no common mode, and reviews the validity of the verification to determine whether the common mode design solution meets the independence requirements;
[0036] The common mode failure / error analysis module performs common mode failure / error analysis when common mode conditions exist and the common mode design scheme does not meet the independence requirements, and provides improvement measures for the system logical architecture and functional architecture design.
[0037] Optionally, in the common mode analysis system of the above-mentioned integrated modular system IMS, in the common mode analysis input item determination module, the types of common mode analysis inputs are determined to include failure level class, reconstruction function class, shared rack class and shared field replaceable unit LRM class.
[0038] Optionally, in the common mode analysis system of the integrated modular system IMS, in the independence requirement identification module, the common mode analysis input type is a failure level input, and the corresponding independence requirement is that the functions, systems, or devices to which the Class I and Class II fault trees and the events under the gates belong are independent of each other;
[0039] The common mode analysis input type is the input of the reconstruction function class, and the corresponding independence requirement is that the software and hardware on which the failure state depends are independent of each other;
[0040] The common mode analysis input type is the shared rack input, and the corresponding independence requirement is that the hardware dependent on each function and the platform are independent of each other;
[0041] The common mode analysis input type is the input of the common field replaceable unit (LRM) class. The corresponding independence requirements are that the software and hardware on which the functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other.
[0042] Optionally, in the common mode analysis system of the integrated modular system IMS, in the common mode source sorting module, for each independence requirement, the common mode types provided in the common mode source table are traversed and applicable common mode sources are analyzed one by one;
[0043] The common mode source table is a dedicated common mode analysis table developed based on the characteristics of the integrated modular system (IMS), including common mode type, common mode sub-type, common mode source, solution analysis requirements, and common mode failure / error examples;
[0044] Common mode types include energy, gas source, software, and hardware;
[0045] Common sources of energy include common power supplies, common functions in power distribution, and common distribution cables.
[0046] The common mode sources corresponding to the gas source include shared equipment, shared pipelines, and shared forced ventilation devices;
[0047] The common mode subtypes corresponding to software include shared data information, shared general system management, and shared application software management; the common mode sources corresponding to shared data information include shared discrete signals and shared bus data; the common mode sources corresponding to shared general system management include shared health monitoring functions, shared fault management, shared configuration management, and shared security management; the common mode sources corresponding to shared application software management include shared partitions, shared process scheduling, shared memory, shared inter-zone communication, and shared health monitoring;
[0048] The common mode subtypes corresponding to the hardware include shared communication links and shared hardware installation processes; the common mode sources corresponding to the shared communication links include shared external buses, shared internal buses, and shared interfaces; the common mode sources corresponding to the shared hardware installation processes include the same installation processes, the same installation appearance designs, and the same installation personnel.
[0049] Optionally, in the common mode analysis system of the above-mentioned integrated modular system IMS, in the common mode situation judgment module, based on the input and output of the system logical architecture and functional architecture, it is judged whether the common mode design scheme has eliminated the hazards caused by the common mode. If the common mode design scheme has eliminated the hazards caused by the common mode, it is judged that there is no common mode situation. If the common mode design scheme has not eliminated the hazards caused by the common mode, it is judged that there is a common mode situation.
[0050] This application has at least the following beneficial technical effects:
[0051] A common mode analysis method and system for an integrated modular system (IMS) are provided, which can achieve a deeper security analysis of the integrated modular system (IMS) during the design process, determine the common mode impact between functions, and analyze the security impact brought by the application of functions. This can serve as a basis for system design iteration and ultimately improve the security level of system design. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Figure 1 Schematic diagram of a common mode analysis method for an integrated modular system IMS provided in an embodiment of the present application;
[0053] Figure 2 Schematic diagram of a common mode analysis system of the integrated modular system IMS provided in an embodiment of the present application.
[0054] In order to better illustrate this embodiment, some contents of the drawings may be omitted, enlarged or reduced, which is only used for illustrative purposes and should not be construed as limiting the present application. DETAILED DESCRIPTION
[0055] To make the technical solution and its advantages of this application more clear, the technical solution of this application will be further described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described here are only some of the embodiments of this application and are only used to explain this application, not to limit this application. It should be noted that for ease of description, only the parts relevant to this application are shown in the accompanying drawings, and other relevant parts can refer to the general design.
[0056] In addition, unless otherwise defined, the technical or scientific terms used in the description of this application shall have the ordinary meanings understood by those skilled in the art to which this application belongs. The term "include" as used in the description of this application means that the concepts preceding the term include the concepts listed after the term and their equivalents, without excluding other related concepts.
[0057] In order to solve the problem that the security risks caused by the high coupling and resource sharing of the integrated modular system IMS cannot be identified, the embodiment of the present application provides a common mode analysis method for the integrated modular system IMS, such as Figure 1 As shown, the focus is on analyzing the failure states of the combined use of software resources and hardware resources to identify common mode problems that are difficult to identify. In addition, for the system with the integrated modular system IMS reconstruction function, common mode analysis and confirmation of the hardware involved in the functions before and after the reconstruction function are added.
[0058] S1. Determine the input of common mode analysis and its common mode items.
[0059] The types of common mode analysis input include failure level class, reconfiguration function class, common rack class and common line replaceable unit (LRM) class.
[0060] The failure level category is the failure state of level I and level II in the functional hazard and task impact analysis results.
[0061] The reconstruction function class is the invalid state of the function corresponding to the reloading changes of the related applications involved when the system is reconstructed.
[0062] The shared rack class performs combined failure analysis on functions installed on the same integrated rack, traversing all possible function combinations. The combined analysis results result in a failure state where the failure level is increased, wherein the functions include system functions.
[0063] The shared field replaceable unit LRM class performs combined failure analysis on the functions installed on the same field replaceable unit LRM, traversing all possible function combinations. The combined analysis results result in a failure state with an increased failure level, wherein the field replaceable unit LRM does not include a system management module.
[0064] S2. For each common model item, identify the independence requirements for each clause.
[0065] When identifying independence requirements, analyze the shared data information, shared communication links, shared general system management functions, and shared application software management in the common mode sources.
[0066] The common data information is analyzed at least for information of discrete signals and bus data.
[0067] At least the external bus, the internal bus and the interface signals are analyzed in the common communication link.
[0068] The common system management functions include at least health monitoring functions, fault management, configuration management, and security management.
[0069] At least partitioning, process scheduling, memory, inter-interval communication and health monitoring are analyzed in the common application software management function.
[0070] The common mode analysis input type is the input of the failure level class. The corresponding independence requirement is that the Class I and Class II fault trees are independent of the functions, systems or devices to which the events under the gate belong. The Class I and Class II fault trees are dynamic fault trees.
[0071] In principle, all AND gates in Type I and II fault trees must be analyzed. However, if the common-mode analysis results of a higher-level AND gate already demonstrate that the system independence requirements are met, analysis of the lower-level AND gates is not required. If the common-mode analysis results of a higher-level AND gate require the independence of a lower-level AND gate, independence requirements for the lower-level AND gates should be established based on the analysis results at this level. If voting gates exist, first convert them into a combination of AND and OR gates, then select the AND gates to be filled in. The independence requirement is described as: XX function / system / device and XX function / system / device must be independent of each other.
[0072] Common mode analysis inputs are inputs to the reconfiguration function class. The corresponding independence requirement is that the software and hardware upon which the failure state depends are independent of each other. When determining the severity level of the reconfiguration function inputs, the common mode of the hardware before and after the reconfiguration is analyzed.
[0073] The common mode analysis input type is a shared rack input, and the corresponding independence requirement is that the hardware that functions depend on and the platforms are independent of each other.
[0074] The common mode analysis input type is the input of the common field replaceable unit (LRM) class. The corresponding independence requirements are that the software and hardware on which the functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other.
[0075] S3. Based on the independence requirements and the common model source table, sort out the common model sources applicable to each common model project.
[0076] For each independence requirement, traverse the common mode types provided in the common mode source table and analyze the applicable common mode sources one by one.
[0077] The common mode source table is a dedicated common mode analysis table developed based on the characteristics of the integrated modular system (IMS). See the table below for details, including common mode type, common mode sub-type, common mode source, solution analysis requirements, and common mode failure / error examples:
[0078]
[0079]
[0080] Common mode types include energy, gas source, software, and hardware.
[0081] Common sources of energy include common power supplies, common functions in power distribution, and common distribution cables.
[0082] The common mode sources corresponding to the gas source include shared equipment, shared pipelines, and shared forced ventilation devices.
[0083] The common model types corresponding to the software include shared data information, shared general system management, and shared application software management.
[0084] The common mode sources corresponding to the shared data information include shared discrete signals and shared bus data.
[0085] Common model sources corresponding to shared general system management include shared health monitoring functions, shared fault management, shared configuration management, and shared security management.
[0086] The common mode sources corresponding to shared application software management include shared partitioning, shared process scheduling, shared memory, shared interval communication, and shared health monitoring.
[0087] The common sub-types corresponding to the hardware include shared communication links and shared hardware installation processes.
[0088] Common mode sources corresponding to the shared communication link include a shared external bus, a shared internal bus, and a shared interface.
[0089] The common model sources corresponding to the shared hardware installation process include the same installation process, the same installation appearance design, and the same installers.
[0090] S4. Analyze the common mode design scheme based on the common mode source and determine whether a common mode situation exists.
[0091] Based on the input and output of the system logical architecture and functional architecture, determine whether the common mode design scheme has eliminated the hazards caused by the common mode. If the common mode design scheme has eliminated the hazards caused by the common mode, the common mode is not applicable, and it is determined that there is no common mode situation. If the common mode design scheme has not eliminated the hazards caused by the common mode, the common mode is applicable, indicating that the common mode problem still exists, and it is determined that there is a common mode situation.
[0092] S5. When common mode conditions exist, perform common mode failure / error analysis and provide improvement measures for the system logical architecture and functional architecture design.
[0093] S6. When common mode does not exist, perform system-level and device-level verification, and review the effectiveness of the verification to determine whether the common mode design solution meets the independence requirements.
[0094] System-level and equipment-level verification include solution effectiveness verification items, solution effectiveness verification methods, and solution effectiveness verification results. Among them, the equipment-level verification is achieved at the field replaceable unit (LRM) level.
[0095] Determine whether the common mode design solution meets the independence requirements based on expert experience.
[0096] S7. When the common mode design scheme does not meet the independence requirements, conduct common mode failure / error analysis and provide improvement measures for the system logical architecture and functional architecture design.
[0097] In a specific example, for the common mode analysis method of the integrated modular system IMS disclosed in the above embodiment, an integrated modular system IMS security assessment analysis table is designed, which is as follows:
[0098]
[0099] In the first column, enter the serial number of the independence requirement.
[0100] The second column contains the type of common mode analysis input, including failure level class, reconfiguration function class, shared rack class, and shared line replaceable unit (LRM) class.
[0101] Currently, the failure states for the failure level category are relatively clear. The other three categories require further analysis. This analysis will identify each of these three failure states through analysis of the current architecture. For shared rack and shared line replaceable unit (LRM) failure states, a functional traversal analysis should be performed.
[0102] For common mode analysis input types of failure level type, fill in the failure state number and description in the third column in the format of "XXX-XX-1: Failure state description". For common mode analysis input types of reconstruction function type, shared rack type, and shared field replaceable unit LRM type, fill in the specific requirements and requirement source in the third column in the format of "Requirement source-category name".
[0103] For common mode analysis inputs of failure level, reconfiguration function, shared rack, and shared line replaceable unit (LRM) types, the fourth column shall be filled with the severity level determined in the functional hazard and mission impact analysis. For common mode analysis inputs of reconfiguration function types, the fourth column is not involved and shall be filled with / .
[0104] Based on the analysis in column 4, fill in the specific independence requirements in column 5.
[0105] The common mode analysis input type is the input of the failure level class, and the corresponding independence requirement is that the functions, systems, or devices to which the events under the class I and II fault trees belong are independent of each other. The common mode analysis input type is the input of the reconstruction function class, and the corresponding independence requirement is that the software and hardware on which the failure state depends are independent of each other. When determining the severity level of the reconstruction function class input, analyze the common mode of the hardware before and after reconstruction. The common mode analysis input type is the input of the shared rack class, and the corresponding independence requirement is that the hardware and platforms on which functions depend are independent of each other. The common mode analysis input type is the input of the shared field replaceable unit LRM class, and the corresponding independence requirement is that the software and hardware on which functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other.
[0106] For each independence requirement, fill in the sixth column by traversing all common mode types provided in the common mode source table. You can also add other common mode types based on development experience and system characteristics.
[0107] In the seventh column, for each independence requirement, analyze the design solution to prove whether the design solution can solve the common mode problem. Fill in the solution description. The solution description should be clear and unambiguous. If the content is long, you can add a report description.
[0108] In column 8, for each independence requirement, enter the common model type applicability.
[0109] Applicability means that the events involved in the independence requirement have not been resolved through the solution design method. If the common mode can be eliminated through the solution design, fill in "No". If the common mode cannot be eliminated through the solution design, fill in "Yes". If the common mode can be partially eliminated through the solution design, fill in "Partial", and explain whether it is resolved or not.
[0110] For common mode type applicability is no, and the input type is failure level type, reconstruction function type, and shared rack type, columns 9, 10, and 11 should fill in the system-level solution validity verification items, solution validity verification methods, and solution validity verification results for the solutions in the corresponding solutions.
[0111] A solution validation project is one that verifies the solution's effectiveness in eliminating common modes. Through design, logical isolation, timing partitioning, and effective partitioning, the solution ensures that the probability of simultaneous software and hardware failure during operation is extremely low, and even theoretically eliminates the probability of failure. Solution validation methods include simulation, experimentation, and testing. During the solution design and verification process, the solution content is explicitly confirmed. Solution validation results refer to the results of simulation, experimentation, and testing. If the relevant report has been completed and archived, the number and file name can be entered. If no materials have yet been prepared, a description can be provided and supplemented during the subsequent design process.
[0112] If the Common Mode Applicability is No and the Input Type is a Shared Line Replaceable Unit (LRM), columns 12, 13, and 14 should contain the device-level solution validation items, solution validation methods, and solution validation results for the corresponding solution. If the Input Type is Failure Level, Reconfiguration Function, or Shared Rack, these three columns should be filled in during the iteration process.
[0113] Fill in the verification result confirmation in column 15. By analyzing the effectiveness of the verification at the system level and device level, confirm whether the common mode can be eliminated and whether the independence requirements are met. If not, you need to fill in column 16.
[0114] Fill in the impact of common mode failures / errors in column 16. If the solutions for the various events involved in the independence requirement are different in terms of common mode type, it is considered that there is no common mode failure / error that causes the simultaneous failure of the events. Fill in / . If the solutions for the various events involved in the independence requirement are similar in terms of common mode type, describe the specific common mode failures / errors that may occur and analyze the impact on related events and, ultimately, the impact on aircraft safety and mission.
[0115] The common-mode analysis method for the integrated modular system IMS disclosed in the above embodiment can achieve a deeper security analysis of the integrated modular system IMS during the design process, determine the common-mode impact between functions, and analyze the security impact brought about by the application of functions. It can serve as a basis for system design iteration and ultimately improve the security level of system design.
[0116] A common mode analysis system of an integrated modular system (IMS), comprising:
[0117] A common mode analysis input item determination module is used to determine the input of the common mode analysis and its common mode items;
[0118] Independence requirement identification module, for each common model project, identifies the independence requirement of each clause;
[0119] The common model source sorting module sorts out the common model sources applicable to each common model project based on the common model source table according to the independence requirements;
[0120] The common mode situation judgment module analyzes the common mode design scheme based on the common mode source and determines whether a common mode situation exists;
[0121] The verification validity review module performs system-level and device-level verification when there is no common mode, and reviews the validity of the verification to determine whether the common mode design solution meets the independence requirements;
[0122] The common mode failure / error analysis module performs common mode failure / error analysis when common mode conditions exist and the common mode design scheme does not meet the independence requirements, and provides improvement measures for the system logical architecture and functional architecture design.
[0123] In the common mode analysis input item determination module, the types of common mode analysis input are determined to include failure level class, reconstruction function class, shared rack class and shared line replaceable unit LRM class.
[0124] In the independence requirement identification module, the common mode analysis input type is the input of the failure level class, and the corresponding independence requirement is that the functions, systems or devices to which the Class I and II fault trees and the events under the gates belong are independent of each other; the common mode analysis input type is the input of the reconstruction function class, and the corresponding independence requirement is that the software and hardware on which the failure state depends are independent of each other; the common mode analysis input type is the input of the shared rack class, and the corresponding independence requirement is that the hardware and platforms on which functions depend are independent of each other; the common mode analysis input type is the input of the shared field replaceable unit LRM class, and the corresponding independence requirement is that the software and hardware on which functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other.
[0125] In the common mode source sorting module, for each independence requirement, the common mode types provided in the common mode source table are traversed, and the applicable common mode sources are analyzed one by one. The common mode source table is a special common mode analysis table developed according to the characteristics of the integrated modular system IMS, including common mode types, common mode sub-types, common mode sources, solution analysis requirements, and common mode failure / error examples.
[0126] Common modes include energy, air source, software, and hardware. Common sources for energy include a common power supply, common functions in power distribution, and common distribution cables. Common sources for air source include shared equipment, shared piping, and shared forced ventilation.
[0127] The common mode subtypes corresponding to the software include shared data information, shared general system management, and shared application software management; the common mode sources corresponding to the shared data information include shared discrete signals and shared bus data; the common mode sources corresponding to the shared general system management include shared health monitoring functions, shared fault management, shared configuration management, and shared security management; the common mode sources corresponding to the shared application software management include shared partitions, shared process scheduling, shared memory, shared interval communication, and shared health monitoring.
[0128] The common mode subtypes corresponding to the hardware include shared communication links and shared hardware installation processes; the common mode sources corresponding to the shared communication links include shared external buses, shared internal buses, and shared interfaces; the common mode sources corresponding to the shared hardware installation processes include the same installation processes, the same installation appearance designs, and the same installation personnel.
[0129] In the common mode situation judgment module, based on the input and output of the system logic architecture and functional architecture, it is judged whether the common mode design scheme has eliminated the hazards caused by the common mode. If the common mode design scheme has eliminated the hazards caused by the common mode, it is judged that there is no common mode situation. If the common mode design scheme has not eliminated the hazards caused by the common mode, it is judged that there is a common mode situation.
[0130] Regarding the common-mode analysis system of the integrated modular system IMS disclosed in the above embodiment, since it corresponds to the common-mode analysis method of the integrated modular system IMS disclosed in the above embodiment, the description is relatively simple. For specific related matters, please refer to the relevant description of the common-mode analysis method of the integrated modular system IMS. Its technical effects can also refer to the technical effects of the relevant parts of the common-mode analysis method of the integrated modular system IMS, which will not be repeated here.
[0131] In addition, those skilled in the art should also be able to realize that the various modules and units of the common-mode analysis system of the integrated modular system IMS disclosed in the embodiments of the present application can be implemented by electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, this application generally describes them according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can choose to adopt different methods to implement the described functions for each specific application and its actual constraints, but such implementation should not be considered to be beyond the scope of this application.
[0132] So far, the technical solution of the present application has been described in conjunction with the preferred embodiments shown in the accompanying drawings. Those skilled in the art should understand that the scope of protection of the present application is obviously not limited to these specific embodiments. Without departing from the principles of the present application, those skilled in the art can make equivalent changes or replacements to the relevant technical features, and the technical solutions after these changes or replacements will fall within the scope of protection of the present application.
Claims
1. A common mode analysis method for an integrated modular system (IMS), characterized in that: include: S1. Determine the input of common mode analysis and its common mode items; S2. For each common model item, identify the independence requirements of each clause; S3. Based on the independence requirements and the common model source table, sort out the common model sources applicable to each common model project; S4. Analyze the common mode design scheme based on the common mode source to determine whether there is a common mode situation; S5. When common mode conditions exist, conduct common mode failure / error analysis and provide improvement measures for the system logic architecture and functional architecture design; S6. When there is no common mode, perform system-level and device-level verification, and review the effectiveness of the verification to determine whether the common mode design solution meets the independence requirements; S7. When the common mode design scheme does not meet the independence requirements, conduct common mode failure / error analysis and provide improvement measures for the system logic architecture and functional architecture design; In S3, for each independence requirement, the common mode types provided in the common mode source table are traversed and the applicable common mode sources are analyzed one by one; The common mode source table is a dedicated common mode analysis table developed based on the characteristics of the integrated modular system (IMS), including common mode type, common mode sub-type, common mode source, solution analysis requirements, and common mode failure / error examples; Common mode types include energy, gas source, software, and hardware; Common sources of energy include common power supplies, common functions in power distribution, and common distribution cables. The common mode sources corresponding to the gas source include shared equipment, shared pipelines, and shared forced ventilation devices; The common mode subtypes corresponding to software include shared data information, shared general system management, and shared application software management; the common mode sources corresponding to shared data information include shared discrete signals and shared bus data; Common model sources corresponding to shared general system management include shared health monitoring functions, shared fault management, shared configuration management, and shared security management; Common mode sources corresponding to shared application software management include shared partitioning, shared process scheduling, shared memory, shared inter-area communication, and shared health monitoring; Common sub-types corresponding to hardware include shared communication links and shared hardware installation procedures; Common mode sources corresponding to the shared communication link include a shared external bus, a shared internal bus, and a shared interface; The common model sources corresponding to the shared hardware installation process include the same installation process, the same installation appearance design, and the same installers; In S2, the common mode analysis input type is the input of the failure level class, and the corresponding independence requirement is that the functions, systems or devices to which the events under the type I and II fault trees belong are independent of each other; The common mode analysis input type is the input of the reconstruction function class, and the corresponding independence requirement is that the software and hardware on which the failure state depends are independent of each other; The common mode analysis input type is the shared rack input, and the corresponding independence requirement is that the hardware dependent on each function and the platform are independent of each other; The common mode analysis input type is the input of the common field replaceable unit (LRM). The corresponding independence requirements are that the software and hardware on which the functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other. Analyze all AND gates in Class I and Class II fault trees. If the common-mode analysis results of the higher-level AND gates can prove that the system independence requirements are met, the lower-level AND gates will no longer be analyzed. When the common-mode analysis results of the higher-level AND gates need to be guaranteed by the independence of the lower-level AND gates, the independence requirements of the lower-level AND gates are proposed based on the analysis results of this level. If there are voting gates, first convert the voting gates into a combination of AND gates and OR gates, and then select the AND gates to fill in. The independence requirement is described as: XX function / system / equipment and XX function / system / equipment should be independent of each other.
2. The common mode analysis method of the integrated modular system IMS according to claim 1, characterized in that: In S1, it is determined that the types of common mode analysis input include failure level class, reconfiguration function class, shared rack class, and shared line replaceable unit (LRM) class.
3. The common mode analysis method of the integrated modular system IMS according to claim 2, characterized in that: In S4, based on the input and output of the system logical architecture and functional architecture, it is judged whether the common mode design scheme has eliminated the hazards caused by the common mode. If the common mode design scheme has eliminated the hazards caused by the common mode, it is judged that there is no common mode situation. If the common mode design scheme has not eliminated the hazards caused by the common mode, it is judged that there is a common mode situation.
4. A common mode analysis system for an integrated modular system (IMS), for implementing the common mode analysis method for an integrated modular system (IMS) according to claim 1, characterized in that: include: A common mode analysis input item determination module is used to determine the input of the common mode analysis and its common mode items; Independence requirement identification module, for each common model project, identifies the independence requirement of each clause; The common model source sorting module sorts out the common model sources applicable to each common model project based on the common model source table according to the independence requirements; The common mode situation judgment module analyzes the common mode design scheme based on the common mode source and determines whether a common mode situation exists; The verification validity review module performs system-level and device-level verification when there is no common mode, and reviews the validity of the verification to determine whether the common mode design solution meets the independence requirements; Common mode failure / error analysis module: When common mode exists and the common mode design solution does not meet the independence requirements, it performs common mode failure / error analysis and provides improvement measures for the system logic architecture and functional architecture design; In the common mode source sorting module, for each independence requirement, the common mode types provided in the common mode source table are traversed and the applicable common mode sources are analyzed one by one; The common mode source table is a dedicated common mode analysis table developed based on the characteristics of the integrated modular system (IMS), including common mode type, common mode sub-type, common mode source, solution analysis requirements, and common mode failure / error examples; Common mode types include energy, gas source, software, and hardware; Common sources of energy include common power supplies, common functions in power distribution, and common distribution cables. The common mode sources corresponding to the gas source include shared equipment, shared pipelines, and shared forced ventilation devices; The common mode subtypes corresponding to software include shared data information, shared general system management, and shared application software management; the common mode sources corresponding to shared data information include shared discrete signals and shared bus data; Common model sources corresponding to shared general system management include shared health monitoring functions, shared fault management, shared configuration management, and shared security management; Common mode sources corresponding to shared application software management include shared partitioning, shared process scheduling, shared memory, shared inter-area communication, and shared health monitoring; Common sub-types corresponding to hardware include shared communication links and shared hardware installation procedures; Common mode sources corresponding to the shared communication link include a shared external bus, a shared internal bus, and a shared interface; The common model sources corresponding to the shared hardware installation process include the same installation process, the same installation appearance design, and the same installers; In the independence requirement identification module, the common mode analysis input type is the failure level input, and the corresponding independence requirement is that the functions, systems or devices to which the events of type I and II fault trees belong are independent of each other; The common mode analysis input type is the input of the reconstruction function class, and the corresponding independence requirement is that the software and hardware on which the failure state depends are independent of each other; The common mode analysis input type is the shared rack input, and the corresponding independence requirement is that the hardware dependent on each function and the platform are independent of each other; The common mode analysis input type is the input of the common field replaceable unit (LRM). The corresponding independence requirements are that the software and hardware on which the functions depend are independent of each other, and the software and hardware on which the failure state depends are independent of each other. Analyze all AND gates in Class I and Class II fault trees. If the common-mode analysis results of the higher-level AND gates can prove that the system independence requirements are met, the lower-level AND gates will no longer be analyzed. When the common-mode analysis results of the higher-level AND gates need to be guaranteed by the independence of the lower-level AND gates, the independence requirements of the lower-level AND gates are proposed based on the analysis results of this level. If there are voting gates, first convert the voting gates into a combination of AND gates and OR gates, and then select the AND gates to fill in. The independence requirement is described as: XX function / system / equipment and XX function / system / equipment should be independent of each other.
5. The common mode analysis system of the integrated modular system IMS according to claim 4, characterized in that: In the common mode analysis input item determination module, the types of common mode analysis input are determined to include failure level class, reconstruction function class, shared rack class and shared line replaceable unit LRM class.
6. The common mode analysis system of the integrated modular system IMS according to claim 5, characterized in that: In the common mode situation judgment module, based on the input and output of the system logic architecture and functional architecture, it is judged whether the common mode design scheme has eliminated the hazards caused by the common mode. If the common mode design scheme has eliminated the hazards caused by the common mode, it is judged that there is no common mode situation. If the common mode design scheme has not eliminated the hazards caused by the common mode, it is judged that there is a common mode situation.