Low-altitude aircraft navigation chip security enhancement method based on fault injection detection
By combining a multimodal fault injection device with an abnormality discrimination model, a multi-level security verification architecture is constructed to achieve adaptive security enhancement of the navigation chip, solve the safety and reliability issues of the navigation chip under multimodal fault injection, and improve the real-time detection and security verification capabilities of the navigation system.
Patent Information
- Application Number
- CN202511196461.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-08-26
AI Technical Summary
Existing navigation chip security enhancement methods are unable to comprehensively and efficiently cope with multimodal fault injection, resulting in insufficient security and reliability of the navigation system. In particular, there are problems with the real-time and accuracy of detection in areas such as voltage fluctuations, clock offsets, and data tampering.
A multimodal fault injection device is used to configure the injection parameters of the navigation chip. The timing correlation acquisition module is combined for real-time signal acquisition. The anomaly discrimination model is used for iterative identification. A multi-level security verification architecture is constructed and a dynamic programming strategy is used for global optimization. A hierarchical security enhancement architecture is established. Through the collaborative work of the policy layer, the adjustment layer and the execution layer, the adaptive update of security parameters is achieved.
It improves the real-time and accuracy of navigation chip detection of multi-modal faults, ensures the comprehensiveness and efficiency of safety verification, enhances the safety, reliability and stability of navigation chips, and provides strong guarantees for the safe operation of low-altitude aircraft.
Smart Images

Figure CN120705783A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of navigation chip safety protection, and in particular to a method for enhancing the safety of a low-altitude aircraft navigation chip based on fault injection detection. Background Art
[0002] The safety and reliability of navigation chips are crucial for the operation of low-altitude aircraft. With the advancement of technology, low-altitude aircraft are finding increasingly diverse applications, such as logistics and distribution, agricultural plant protection, and environmental monitoring. This places higher demands on the performance of navigation chips. However, in practice, navigation chips face various potential failure risks, which can be caused by a variety of factors.
[0003] Voltage fluctuations are a common problem in the external environment. Power grid instability and power supply failures can cause abnormal voltage fluctuations in the navigation chip. When voltage exceeds the chip's normal operating range, it can cause logical errors, functional failure, or even permanent damage. For example, if the voltage is too low, the chip may be unable to maintain its internal circuit state, leading to calculation errors; if the voltage is too high, it may break down the chip's internal transistors, causing irreparable damage.
[0004] Clock skew is also a significant factor affecting the proper functioning of navigation chips. The clock signal serves as the benchmark for the coordinated operation of various modules within the chip. Deviations in the clock frequency can disrupt the working rhythm of various chip components. For example, a clock frequency that is too fast may prevent the chip's internal circuits from completing corresponding operations in time, resulting in data processing errors; a clock frequency that is too slow can affect the chip's overall performance and delay the aircraft's navigation response.
[0005] Data tampering also poses a serious threat to the security of navigation chips. During data transmission, factors such as electromagnetic interference and hacker attacks may affect data, leading to errors or malicious tampering. If the navigation chip receives erroneous data, it will directly affect its calculation and judgment of key information such as the aircraft's position and speed, which may lead to serious accidents such as loss of control and collision.
[0006] Environmental interference noise should also not be ignored. When flying at low altitude, aircraft may be subject to interference from various sources, such as electromagnetic radiation and mechanical vibration. This interference noise can be superimposed on the chip's operating signals, affecting its normal operation. For example, strong electromagnetic interference can cause abnormal output from internal chip sensors, resulting in significant errors in the navigation system.
[0007] Existing navigation chip safety enhancement methods have certain limitations when addressing these faults. Some methods may only detect and handle a single type of fault, failing to fully address multimodal fault injection scenarios. Furthermore, traditional methods lack the real-time and accuracy of fault detection, making it difficult to quickly and accurately identify abnormal chip conditions. The lack of global optimization considerations in the formulation of safety verification and enhancement strategies leads to inefficient verification processes and poor safety enhancement results. Therefore, a navigation chip safety enhancement method that can comprehensively and efficiently address multimodal fault injection is urgently needed to improve the safety and reliability of low-altitude aircraft navigation systems. Summary of the Invention
[0008] The purpose of the present invention is to provide a low-altitude aircraft navigation chip safety enhancement method based on fault injection detection to solve the problems raised in the above background technology.
[0009] To achieve the above objectives, the present invention provides the following technical solution: a method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection, the method comprising: The navigation chip's injection parameters are configured using a multimodal fault injection device, the multimodal fault injection device comprising a voltage perturbation unit, a clock offset unit, and a data tampering unit. The navigation chip's operating signals are collected and processed in real time based on a timing correlation acquisition module to obtain chip state feature data. The chip state feature data is input into a pre-built anomaly discrimination model, which employs a state iteration framework to iteratively identify chip abnormal states based on a feature matching function to generate an anomaly discrimination result. Constructing a multi-level security verification architecture based on the abnormality discrimination results, wherein the multi-level security verification architecture takes maximizing verification coverage and minimizing verification time as optimization goals, and adopts a dynamic programming strategy to globally optimize the verification process, wherein the dynamic programming strategy introduces state transition cost and heuristic evaluation indicators; outputting an optimal security verification solution based on the multi-level security verification architecture; A hierarchical safety enhancement architecture is established based on the optimal safety verification scheme, and the hierarchical safety enhancement architecture includes a strategy layer, a regulation layer and an execution layer, wherein the strategy layer performs global enhancement planning based on the abnormality discrimination result, the regulation layer performs local process correction based on the optimal safety verification scheme, and the execution layer realizes the update of the safety parameters of the navigation chip based on the parameter adaptive algorithm; the safety enhancement instructions are output through the hierarchical safety enhancement architecture to realize the fault injection detection safety enhancement control of the low-altitude aircraft navigation chip.
[0010] Preferably, the chip state feature data is input into a pre-built abnormality discrimination model, and the abnormality discrimination model adopts a state iteration framework to iteratively identify the abnormal state of the chip based on a feature matching function, and generates an abnormality discrimination result including: Acquire real-time operation signals, including chip voltage fluctuation data, clock frequency deviation data, data transmission error data, and environmental interference noise data; construct a state space based on the real-time operation signals, and construct an action space based on the voltage offset, clock jitter, and data bit error rate that the navigation chip can withstand; A multidimensional feature matching function is constructed based on the state space and the action space. The multidimensional feature matching function includes a voltage matching term, a clock alignment term, a data error correction term, and an interference isolation term. The voltage matching term is calculated by the amplitude similarity between the actual chip voltage and the reference voltage. The clock alignment term is calculated by the phase correlation between the actual chip frequency and the reference frequency. The data error correction term is calculated by the numerical deviation between the actual bit error rate and the reference bit error rate. The interference isolation term is calculated by the signal separation between the ambient noise area and the chip working area. Constructing a state iteration framework, which includes an initial state set, a state transfer function, and a feature matching calculation module. The initial state set contains multiple hypothetical samples of chip abnormal states. The state transfer function predicts and updates the state by navigating the chip dynamics model. The feature matching calculation module evaluates the state weight based on the multi-dimensional feature matching function. The initial state set is updated using a resampling method, high-weight states are retained through roulette wheel selection, low-weight states are eliminated and new states are added, and the mean and dispersion of the chip abnormal state are calculated based on the updated state set; and an abnormality discrimination result is output based on the state iteration framework, wherein the abnormality discrimination result includes a state mean parameter, a dispersion matrix, a key feature matching confidence and an interference area isolation probability.
[0011] Preferably, a multi-level security verification architecture is constructed based on the abnormality discrimination result. The multi-level security verification architecture takes maximum verification coverage and shortest verification time as optimization goals, adopts dynamic programming strategy to globally optimize the verification process, and outputs the optimal security verification solution based on the multi-level security verification architecture, including: Construct a multi-objective function for the verification process, wherein the multi-objective function includes a coverage optimization objective function and a time optimization objective function, wherein the coverage optimization objective function is calculated by summing the ratio of the number of verification items to the total number of items, and the time optimization objective function is calculated by weighted summing of the execution time, waiting time, and data processing time of each verification step; Constructing verification process constraints based on the multi-objective function, the verification process constraints include time constraints, resource constraints, accuracy constraints and compatibility constraints. The time constraint is used to limit the execution time range of the single-step verification, the resource constraint is used to limit the range of variation of the chip memory usage, the accuracy constraint is used to limit the error range of the verification result, and the compatibility constraint is used to ensure the degree of matching between the verification process and the original function of the navigation chip; The verification process is encoded using a node sequence, where each node contains a verification step identifier and chip resource usage information. A state transition probability is constructed based on the state transition cost and a heuristic evaluation value, and the next feasible node is determined using the state transition probability. The heuristic evaluation value is obtained by weighted calculation of the verification coverage increment and time reduction between nodes. Introducing an adaptive state transfer cost mechanism, the adaptive state transfer cost mechanism adopts a time-varying weight coefficient, the time-varying weight coefficient changes linearly with the increase of the number of optimization iterations, and the state transfer cost is dynamically adjusted by the time-varying weight coefficient; A dynamic heuristic evaluation mechanism is introduced. The dynamic heuristic evaluation mechanism uses a time-varying impact factor that increases linearly with the number of optimization iterations. The time-varying impact factor is used to adjust the weight of the heuristic evaluation value in the state transition probability. Iterative optimization is performed based on the adaptive state transition cost mechanism and the dynamic heuristic evaluation mechanism. The coverage cost and time cost of the process generated by each iteration are evaluated, and non-dominated solutions are added to the Pareto front solution set. An optimal solution that satisfies the coverage-time trade-off is selected from the Pareto front solution set as the optimal process, and the optimal process is smoothed using a spline curve to generate an optimal node sequence and corresponding verification execution parameters.
[0012] Preferably, the strategy layer performs global enhancement planning based on the abnormality identification result, including: The enhancement process is described using a parameterized curve, where the enhancement process is expressed as a function of a process parameter, where the value of the process parameter ranges from 0 to 1, and the enhancement process includes a voltage regulation component, a clock calibration component, and a data error correction component. The enhancement process is described based on a quintic Bezier curve, and parameter values of the enhancement process are calculated by summing the products of control vertex coordinates and Bezier basis functions, wherein the Bezier basis functions are calculated by power functions of the combination number and the process parameters; Constructing enhanced process constraints, the enhanced process constraints including amplitude constraints, frequency constraints, error constraints, and compatibility constraints. The amplitude constraint is used to limit the voltage adjustment range of the enhanced process, the frequency constraint is used to limit the clock calibration range of the enhanced process, the error constraint is used to limit the error correction accuracy range of the enhanced process, and the compatibility constraint is used to limit the matching range between the enhanced process and the original navigation function; Constructing a global multi-objective optimization function, the global multi-objective optimization function includes a total process length term, a parameter change integral term, a parameter change rate integral term, and a function matching measurement term, and performing a weighted combination of each term in the global multi-objective optimization function using a weighting coefficient; Discretize the enhanced process interval into multiple process segments, discretize the global multi-objective optimization function, and construct a global discretization objective function, wherein the global discretization objective function includes the process segment length, process segment parameter change, parameter change amount, and minimum function matching distance; Iteratively optimizing the global discretized objective function using a gradient descent method, and updating the position coordinates of the control vertex along the negative gradient direction by calculating the gradient value of the objective function with respect to the control vertex; The optimized enhancement process is smoothed by cubic spline interpolation. By maintaining the continuity of the position derivative, parameter derivative and rate of change derivative at the interpolation endpoints, a smooth and continuous enhancement process is generated. A node sequence and a corresponding chip adjustment speed are generated based on the smooth and continuous enhancement process.
[0013] Preferably, the adjustment layer performs local process correction based on the optimal safety verification solution, including: A local correction window is constructed based on the current voltage, current frequency, and current error correction rate of the navigation chip, and the size of the local correction window is adaptively adjusted using a rate correlation coefficient to establish a positive correlation between the size of the local correction window and the current adjustment speed; A local environment model is constructed using multimodal perception data, and the operating data is transformed into parameter data in the local coordinate system. The credibility probability of the grid map is updated based on the parameter data, and the credibility probability value of each grid is calculated using the probability accumulation method. The Kalman filter algorithm is used to track dynamic interference. The state vector of the interference is predicted through the state prediction equation. The predicted state is updated based on the measurement data to obtain the precise location and impact information of the interference. Constructing a process correction model, using the dynamic equation of the navigation chip as a state equation, the state equation including voltage parameters, frequency parameters, and error correction parameters, and constructing state constraints and dynamic constraints. The state constraints are used to limit the value range of the voltage parameter and the value range of the frequency parameter, and the dynamic constraints are used to limit the value range of the voltage change rate, the frequency change rate, and the error correction efficiency change rate; Constructing a multi-objective cost function, the multi-objective cost function including a reference process tracking item, an interference avoidance item, a process smoothing item, and an energy consumption item, and performing a weighted combination of each item in the multi-objective cost function using a weighting coefficient; The Lagrange multiplier method is used to optimize and solve the multi-objective cost function, a Lagrange function is constructed and constraints are introduced, and the optimal control quantity is obtained by solving the partial derivative equation group.
[0014] Preferably, the execution layer implements the update of the safety parameters of the navigation chip based on the parameter adaptive algorithm, outputs the safety enhancement instructions through the hierarchical safety enhancement architecture, and implements the fault injection detection safety enhancement control of the low-altitude aircraft navigation chip, including: Establishing a three-degree-of-freedom dynamic model for the navigation chip, the three-degree-of-freedom dynamic model includes a voltage equation and a frequency equation, the voltage equation includes a regulating force term, an internal resistance loss term, and an environmental interference term, and the frequency equation includes a calibration torque term and an inertial response term; Constructing the three-degree-of-freedom dynamic model into a state space expression, wherein the state vector of the state space expression includes a voltage parameter, a frequency parameter, an error correction parameter, and an adjustment rate, and the control vector of the state space expression includes a voltage adjustment amount and a frequency calibration amount; Linearizing the state space expression, calculating the partial derivatives of the system state equation with respect to the state vector and the control vector, and constructing a linearized prediction model; Constructing a parameter update prediction cost function, wherein the parameter update prediction cost function includes a tracking error term, a control amount penalty term, and a control increment penalty term, and performing a weighted combination of each penalty term through a weight matrix; Constructing state constraints, including voltage parameter constraints and frequency parameter constraints; constructing control constraints, including voltage regulation amount constraints and frequency calibration amount constraints; constructing control increment constraints, including voltage regulation increment constraints and frequency calibration increment constraints; Converting the parameter update prediction cost function into a standard form of a quadratic programming problem, calculating the quadratic form matrix and the linear term coefficients, and constructing the inequality constraint matrix and the equality constraint matrix; The effective set method is used to solve the quadratic programming problem, and the optimal solution is gradually approached by identifying effective constraints and solving sub-problems; Based on the optimization solution, control quantity mapping is performed, and the total regulation quantity is distributed to each voltage regulation module through the voltage distribution matrix, and the total calibration quantity is distributed to each frequency calibration module through the frequency distribution matrix; The output of the regulation module is limited, the output regulation amount is limited according to the module rated power, the parameter change amount is limited according to the maximum regulation speed of the chip, and the final safety enhancement instruction is generated.
[0015] Preferably, the operation signal of the navigation chip is collected and processed in real time based on the timing correlation acquisition module to obtain chip state characteristic data, including: normalizing the real-time operation signals obtained by the voltage disturbance unit, the clock offset unit and the data tampering unit respectively to obtain single-dimensional standard data; performing median filtering and denoising on each standard data, calculating the local mean and variance through a sliding window, and adjusting the data stability; using a time series feature extraction algorithm to extract the local feature points of each data, and establishing the corresponding relationship between different mode data through feature point matching; converting the matched feature point parameters to a unified reference coordinate system, and fusing the multi-mode feature point information through a weighted average method to generate chip state characteristic data containing timing information.
[0016] Preferably, constructing a state iteration framework includes: initializing a state set using a uniform distribution, each state containing the voltage value and frequency value of the navigation chip in the parameter space; calculating the adjustment module parameters corresponding to the state through the forward solution of the navigation chip dynamics, projecting the state parameters to the data plane based on the sensor calibration matrix, and generating predicted feature point parameters; calculating the numerical error between the predicted feature point parameters and the actual operating feature point parameters, and constructing a feature matching function based on the sum of squares of the errors; obtaining the weight value of each state through normalization processing, retaining the states with weight values greater than a preset threshold, and eliminating the states with weight values less than the preset threshold.
[0017] Preferably, constructing the state transfer cost includes: calculating the Euclidean distance between the current node and the next node as the process length cost; calculating the parameter adjustment amount of each module required for the navigation chip to move from the current node to the next node as the resource consumption cost; calculating the minimum matching degree with the original function of the chip in the process, and increasing the penalty cost if it is less than the matching threshold; generating the total state transfer cost by linearly combining the process length cost, resource consumption cost and penalty cost.
[0018] Preferably, the calculation process for the minimum matching degree with the original function of the chip includes: obtaining the parameter range of the original function of the navigation chip, the parameter range including a reference voltage interval, a reference frequency interval and a reference error correction rate interval; calculating the overlapping length of the enhanced process parameters with the reference voltage interval as the voltage matching degree; calculating the overlapping length of the enhanced process parameters with the reference frequency interval as the frequency matching degree; calculating the overlapping length of the enhanced process parameters with the reference error correction rate interval as the error correction matching degree; taking the minimum value among the voltage matching degree, the frequency matching degree and the error correction matching degree as the minimum matching degree between the process and the original function of the chip.
[0019] Compared with the prior art, the present invention has the following beneficial effects: During fault detection, a multimodal fault injection device configures the navigation chip's injection parameters. Combined with the real-time acquisition and processing of operating signals by the timing correlation acquisition module, this system comprehensively and accurately captures chip status characteristic data. A pre-built anomaly discrimination model, employing a state iteration framework and multi-dimensional feature matching functions, enables precise iterative identification of chip anomalies. This significantly improves the real-time and accuracy of fault detection, enabling timely detection of multiple fault types, including voltage fluctuations, clock skew, and data tampering.
[0020] In terms of safety verification, a multi-level safety verification architecture was constructed with the optimization goals of maximizing verification coverage and minimizing verification time. A dynamic programming strategy was employed, along with the introduction of state transition costs and heuristic evaluation metrics, to globally optimize the verification process. This approach not only ensures comprehensive verification and covers a wide range of potential failure scenarios, but also effectively shortens verification time and improves efficiency, providing a reliable verification foundation for enhanced navigation chip safety.
[0021] The design of the security enhancement architecture is a highlight. This hierarchical security enhancement architecture comprises a policy layer, a regulation layer, and an execution layer, all working together in a coordinated manner. The policy layer performs global enhancement planning based on anomaly identification results. It uses parameterized curves and quintic Bezier curves to describe the enhancement process. Iterative optimization, combined with a global multi-objective optimization function and gradient descent, allows for the development of a globally optimal enhancement strategy, ultimately improving the chip's overall security performance. The regulation layer performs local process correction based on the optimal security verification scheme. It tracks dynamic interference by constructing a local correction window, a multimodal perception data environment model, and a Kalman filter algorithm. By combining the process correction model with a multi-objective cost function for optimization and solution, the system achieves precise local process correction, enabling the chip to better adapt to changing operating environments. The execution layer, based on a parameter adaptive algorithm, establishes a three-degree-of-freedom dynamic model of the navigation chip, constructs a state-space representation, and a linearized prediction model. It then transforms the parameter update prediction cost function into a quadratic programming problem and solves it, achieving precise updates of the navigation chip's security parameters and ensuring the effective execution of security enhancement instructions.
[0022] During data processing, real-time operating signals undergo normalization, median filtering for denoising, and time series feature extraction to ensure data stability and reliability. The construction of a state iteration framework, the calculation of state transition costs, and the degree of compatibility between the process and the chip's original functionality further enhance the scientific nature and effectiveness of the entire safety enhancement method. In summary, this method can comprehensively improve the ability of low-altitude aircraft navigation chips to cope with multimodal fault injection, significantly enhancing the chip's safety, reliability, and stability, and providing a strong guarantee for the safe operation of low-altitude aircraft. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 This is a working principle diagram of the method for enhancing safety of low-altitude aircraft navigation chips based on fault injection detection according to the present invention; Figure 2 Flowchart for iterative identification of anomaly discrimination model; Figure 3 Flowchart optimized for multi-level security verification architecture; Figure 4 Flowchart for global enhancement planning at the policy level; Figure 5 Flowchart for the correction of the local process of the adjustment layer. DETAILED DESCRIPTION
[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0025] See also Figure 1-Figure 5 The present invention relates to a method for enhancing the safety of a low-altitude aircraft navigation chip based on fault injection detection, and the specific implementation steps are as follows: The navigation chip's injection parameters are configured using a multimodal fault injection device, which includes a voltage perturbation unit, a clock offset unit, and a data manipulation unit. A timing correlation acquisition module collects and processes the navigation chip's operating signals in real time, generating chip status feature data. This data is then fed into a pre-built anomaly discrimination model. This model employs a state iteration framework, relying on a feature matching function to iteratively identify chip anomalies and generate an anomaly discrimination result.
[0026] Based on the anomaly identification results, a multi-level security verification architecture is constructed. This architecture optimizes verification coverage and minimizes verification time, using a dynamic programming strategy to globally optimize the verification process. This strategy incorporates state transition costs and heuristic evaluation metrics. Based on this multi-level security verification architecture, an optimal security verification solution is output.
[0027] A hierarchical safety enhancement architecture is established based on the optimal safety verification scheme. This architecture comprises a strategy layer, a regulation layer, and an execution layer. The strategy layer performs global enhancement planning based on anomaly identification results, the regulation layer performs local process corrections based on the optimal safety verification scheme, and the execution layer updates the safety parameters of the navigation chip using a parameter adaptive algorithm. The hierarchical safety enhancement architecture outputs safety enhancement commands, enabling fault injection detection safety enhancement control for low-altitude aircraft navigation chips.
[0028] Example 1:
[0029] When processing chip status feature data and inputting it into the anomaly discrimination model, real-time operational signals must be acquired. These signals include chip voltage fluctuations, clock frequency deviations, data transmission errors, and environmental interference noise. After acquiring this data, a state space is constructed based on these real-time operational signals. Simultaneously, an action space is constructed based on the voltage offset, clock jitter, and data error rate that the navigation chip can withstand.
[0030] A multidimensional feature matching function is constructed, consisting of several key components. The voltage matching term is calculated by comparing the amplitude similarity between the chip's actual voltage and the reference voltage; the clock alignment term is calculated by calculating the phase correlation between the chip's actual frequency and the reference frequency; the data error correction term involves calculating the deviation between the actual bit error rate and the reference bit error rate; and the interference isolation term is determined by calculating the signal separation between the ambient noise region and the chip's operating region. Together, these components form the multidimensional feature matching function, which is used for subsequent chip status analysis.
[0031] A state iteration framework is constructed, consisting primarily of an initial state set, a state transition function, and a feature matching calculation module. The initial state set contains multiple hypothetical samples of abnormal chip states, which provide the basis for subsequent analysis. The state transition function uses the navigation chip dynamics model to predict and update the state, enabling prediction of possible future state changes based on the current state. The feature matching calculation module, based on the previously constructed multi-dimensional feature matching function, evaluates state weights to determine the importance of each state.
[0032] After building the state iteration framework, a resampling method is used to update the initial state set. Specifically, a roulette wheel selection process is used to retain high-weighted states, remove low-weighted states, and add new states. This continuously optimizes the state set to more accurately reflect the actual chip conditions. After the state set is updated, the mean and dispersion of chip abnormal states are calculated based on the updated state set. This calculation and analysis of these data provides a deeper understanding of the distribution of chip abnormal states.
[0033] Based on the state iteration framework, the anomaly identification results are output. These results contain several key pieces of information: the state mean parameter reflects the average level of chip anomaly states, the dispersion matrix reflects the dispersion of anomaly states, the key feature matching confidence level indicates the reliability of feature matching, and the interference region isolation probability reflects the likelihood of isolating the interference region. Taken together, these pieces of information provide important insights for subsequent handling of chip security issues.
[0034] Every step in the entire process is closely interconnected. From acquiring real-time operating signals to constructing the state and action spaces, to building the multidimensional feature matching function and state iteration framework, and finally updating the state set and outputting anomaly detection results, each link requires precise processing to ensure accurate identification of chip abnormalities and provide reliable support for subsequent safety enhancement measures. When acquiring real-time operating signals, data accuracy and completeness must be ensured to avoid bias in subsequent analysis due to data errors. When constructing the state and action spaces, the actual tolerances of the navigation chip must be fully considered to ensure that the constructed spaces accurately reflect the chip's operating range. When constructing the multidimensional feature matching function, the calculation methods for each term must be scientific and reasonable to ensure accurate and effective chip status assessment. The state iteration framework must be rigorously constructed, and the various modules must collaborate smoothly to achieve accurate prediction and assessment of chip status. Appropriate resampling methods must be used to ensure that the updated state set better reflects the actual chip conditions. The output of anomaly detection results must be comprehensive and accurate to provide strong support for subsequent processing. Through this series of operations, the abnormal status of the chip can be effectively identified and analyzed, providing important guarantees for the safety enhancement of low-altitude aircraft navigation chips.
[0035] Example 2:
[0036] When building a multi-level security verification architecture and outputting the optimal security verification solution, a multi-objective function for the verification process is constructed. This function consists of a coverage optimization objective function and a time optimization objective function. The coverage optimization objective function is calculated by summing the ratio of the number of verification items to the total number of items, thereby measuring the degree of verification coverage of all items. The time optimization objective function is a weighted sum of the execution time, waiting time, and data processing time of each verification step, thereby evaluating the time consumption of the entire verification process.
[0037] Based on the above multi-objective function, the constraints of the verification process are constructed. These constraints include time constraints, resource constraints, precision constraints, and compatibility constraints. Time constraints are used to limit the execution time range of single-step verification, ensuring that each step of verification can be completed within a reasonable time, avoiding the impact of a certain step taking too long on the progress of the entire verification process; resource constraints are used to limit the variation range of chip memory usage, preventing excessive chip memory usage during the verification process and ensuring the normal operation of other chip functions; precision constraints are used to limit the error range of the verification results to ensure the accuracy and reliability of the verification results; compatibility constraints are used to ensure the degree of matching between the verification process and the original functions of the navigation chip, so that the verification process will not interfere with the original normal functions of the chip.
[0038] The verification process is encoded using a node sequence, with each node containing a verification step identifier and chip resource usage information. This encoding method transforms complex verification processes into a series of ordered nodes, facilitating process analysis and optimization. State transition probabilities are constructed based on state transition costs and heuristic evaluation values, which are then used to determine the next feasible node. The heuristic evaluation value is calculated by weighting the increase in verification coverage and the reduction in verification time between nodes. It comprehensively considers the increase in verification coverage and the reduction in verification time, providing a basis for node selection.
[0039] During this process, an adaptive state transition cost mechanism is introduced. This mechanism uses a time-varying weight coefficient that decays linearly with the number of optimization iterations. This time-varying weight coefficient allows for dynamic adjustment of the state transition cost, allowing the impact of the state transition cost to vary according to actual conditions at different stages of the optimization, thereby better adapting to the needs of the optimization process. Simultaneously, a dynamic heuristic evaluation mechanism is introduced, using a time-varying influence factor that increases linearly with the number of optimization iterations. This time-varying influence factor adjusts the weight of the heuristic evaluation value in the state transition probability. In the early stages of optimization, the heuristic evaluation value has a lower weight, prioritizing global exploration. As the optimization progresses, the weight of the heuristic evaluation value gradually increases, prioritizing local optimization, thereby achieving an organic combination of global and local optimization.
[0040] Iterative optimization is performed based on an adaptive state transition cost mechanism and a dynamic heuristic evaluation mechanism. During each iteration, the generated processes are evaluated for coverage and time costs, and non-dominated solutions are added to the Pareto front solution set. The Pareto front solution set contains solutions that cannot be further optimized for both coverage and time. These solutions are considered optimal candidates.
[0041] The optimal solution that satisfies the coverage-time trade-off is selected from the Pareto front solution set as the optimal process. When selecting the optimal solution, it is necessary to comprehensively consider both coverage and time consumption, finding a solution that strikes a balance between the two. The selected optimal process is then smoothed using a spline curve. This process is smoothed and continuous, reducing mutations and discontinuities, thereby generating an optimal node sequence and corresponding verification execution parameters. These optimal node sequences and verification execution parameters constitute the final optimal safety verification solution, providing scientific and rational guidance for the safety verification of low-altitude aircraft navigation chips.
[0042] Throughout the implementation process, every step requires rigorous consideration. When constructing multi-objective functions, it is crucial to ensure that the coverage and time-consuming calculations accurately reflect the actual situation. When constructing constraints, the chip's actual performance and operating requirements must be fully considered, and the scope of each constraint must be appropriately set. When encoding the verification process, the integrity and accuracy of node information must be ensured to facilitate subsequent analysis and optimization. When introducing the adaptive state transition cost mechanism and dynamic heuristic evaluation mechanism, the time-varying weight coefficients and time-varying influencing factors must be appropriately configured to ensure their effectiveness during the optimization process. During iterative optimization, the resulting process must be comprehensively and accurately evaluated at each iteration to ensure the quality of the Pareto front solution set. When selecting the optimal solution and performing spline curve smoothing, multiple factors must be comprehensively considered to ensure the generated optimal safety verification solution has practical application value. Through this series of detailed and rigorous operations, an efficient and reliable multi-level safety verification architecture can be constructed, and the optimal safety verification solution can be output, providing strong support for safety enhancement of low-altitude aircraft navigation chips.
[0043] Example 3:
[0044] When the strategy layer performs global enhancement planning based on the anomaly identification results, a parameterized curve is used to describe the enhancement process. The enhancement process is expressed as a function of the process parameter. The value range of the process parameter is 0 to 1. The enhancement process includes voltage regulation, clock calibration, and data error correction. The enhancement process is described here based on the quintic Bezier curve. The expression of the quintic Bezier curve is: ; in, Indicates the parameter value of the enhancement process, It is a process parameter, and its value range is 0 to 1; To control the vertex coordinates, used to control the shape of the curve; is the quintic Bessel basis function, which is calculated by the power function of the combination number and the process parameter. The specific calculation method is: ,in Indicates selection from 5 elements The number of combinations of elements.
[0045] Construct constraints for the enhancement process, including amplitude constraints, frequency constraints, error constraints, and compatibility constraints. Amplitude constraints limit the voltage regulation range of the enhancement process, ensuring that voltage regulation is within the chip's safe tolerance range. Frequency constraints limit the clock calibration range of the enhancement process, preventing clock calibration from exceeding the chip's normal operating frequency range. Error constraints limit the error correction accuracy range of the enhancement process to ensure that data error correction meets requirements. Compatibility constraints limit the matching range between the enhancement process and the original navigation function, ensuring that the enhancement process does not adversely affect the chip's original navigation function.
[0046] A global multi-objective optimization function is constructed. This function includes the total process length term, the parameter change integral term, the parameter change rate integral term, and the functional matching metric term. Each term is weighted and combined using weighting coefficients. The total process length term measures the overall length of the enhanced process, the parameter change integral term reflects the change in parameters throughout the process, the parameter change rate integral term reflects the rate of parameter change, and the functional matching metric term is used to evaluate the degree of match between the enhanced process and the original chip function.
[0047] The enhanced process interval is discretized into multiple process segments, and the global multi-objective optimization function is discretized to construct a global discretized objective function. The global discretized objective function includes the process segment length, the change in process segment parameters, the amount of parameter change, and the minimum distance for functional matching. This discretization transforms the continuous optimization problem into a discrete one, facilitating numerical calculation and optimization.
[0048] The global discretized objective function is iteratively optimized using gradient descent. The specific process involves calculating the gradient of the objective function with respect to the control vertices and then updating the position coordinates of the control vertices along the negative gradient. Gradient descent is a commonly used optimization method that finds the optimal control vertex position by continuously adjusting the position of the control vertices to gradually reduce the objective function.
[0049] The optimized enhancement process is smoothed using cubic spline interpolation. By maintaining the continuity of the position derivatives, parameter derivatives, and rate-of-change derivatives at the interpolation endpoints, a smooth and continuous enhancement process is generated. Cubic spline interpolation ensures smooth transitions at the curve connection points, avoiding sudden changes and making the enhancement process more stable and continuous. Finally, based on this smooth and continuous enhancement process, a node sequence and corresponding chip adjustment speed are generated. The node sequence defines the various stages and steps of the enhancement process, while the chip adjustment speed provides the specific parameters for the adjustment operation corresponding to each node.
[0050] Throughout the entire implementation process, from selecting parameterized curves to constructing Bezier curves, to setting various constraints and constructing the optimization function, every step requires precise design and rigorous execution. Quintic Bezier curves were chosen because they can flexibly describe complex curve shapes and meet the diverse needs of the enhancement process. The setting of control vertices directly affects the shape and direction of the curve and requires appropriate adjustments based on the actual enhancement requirements. The determination of various constraints must fully consider the chip's performance indicators and operational requirements to ensure that the enhancement process proceeds safely and reliably. The construction of a global multi-objective optimization function requires comprehensive consideration of multiple factors, achieving balanced optimization of various objectives through the appropriate setting of weighting coefficients. The application of gradient descent requires accurate calculation of gradient values and proper control of the step size and number of iterations to ensure convergence and efficiency of the optimization process. Cubic spline interpolation smoothing can improve the smoothness and continuity of the enhancement process, making chip tuning more stable and reliable. The generated node sequence and chip tuning speed must be operational and practical, providing clear guidance for actual chip security enhancement operations. Through such a series of detailed and rigorous steps, the scientific and reasonable design of global enhancement planning at the strategy layer can be achieved, providing effective strategic support for the safety enhancement of low-altitude aircraft navigation chips.
[0051] Example 4:
[0052] When the regulation layer performs local process corrections based on the optimal safety verification scheme, it constructs a local correction window based on the navigation chip's current voltage, frequency, and error correction rate. The size of the local correction window is adaptively adjusted using a rate correlation coefficient, establishing a positive correlation between the size of the local correction window and the current regulation speed. For example, when the navigation chip's current regulation speed is fast, the size of the local correction window increases accordingly to cover a wider range of possible parameter variations; when the regulation speed is slow, the window size decreases to better focus on the current parameter state.
[0053] Multimodal sensory data is used to construct a local environment model, and the operating data is transformed to obtain parameter data in the local coordinate system. For example, sensory data from different modules such as the voltage disturbance unit and the clock offset unit are converted to the same local coordinate system through coordinate transformation to facilitate unified analysis. Based on these parameter data, the credible probability of the grid map is updated, and the credible probability value of each grid is calculated using the probability accumulation method. For example, in the grid map, each grid represents a possible parameter state area. Based on the current parameter data, the credible probability of each grid is updated. The closer the parameter data is to the state corresponding to a certain grid, the higher the credible probability of the grid. By continuously accumulating these probabilities, the state distribution of the local environment can be more accurately described.
[0054] A Kalman filter algorithm is used to track dynamic disturbances. The state vector of the disturbance is predicted using a state prediction equation. The predicted state is then updated based on the measured data to obtain the precise location and impact information of the disturbance. For example, assuming the state vector of a dynamic disturbance includes parameters such as position and velocity, the state prediction equation is first used to predict the current state based on the state at the previous moment. The actual measured data is then compared with the predicted state. The predicted state is then corrected through Kalman filter gain calculation, resulting in more accurate disturbance location and impact information, such as the intensity and range of the disturbance.
[0055] A process correction model is constructed, using the navigation chip's dynamic equations as state equations. The state equations include voltage parameters, frequency parameters, and error correction parameters. State and dynamic constraints are also constructed. State constraints limit the range of voltage and frequency parameters. For example, voltage parameters must be within the normal operating voltage range of the chip, and frequency parameters must also be within a specific frequency range. Dynamic constraints limit the range of voltage and frequency change rates, as well as the error correction efficiency change rate, to prevent excessively fast or slow parameter changes from affecting the chip's normal operation.
[0056] A multi-objective cost function is then constructed, consisting of a reference process tracking term, an interference avoidance term, a process smoothing term, and an energy consumption term, each of which is weighted and combined using weighting coefficients. The reference process tracking term measures the degree of deviation between the current revised process and the reference process, ensuring that the revised process does not deviate too far from the optimal safety verification solution. The interference avoidance term evaluates the process's ability to avoid dynamic interference, ensuring that the process avoids interference areas as much as possible. The process smoothing term ensures process smoothness and reduces parameter mutations. The energy consumption term considers the energy consumption during process execution and selects solutions with lower energy consumption.
[0057] The Lagrange multiplier method is used to optimize and solve the multi-objective cost function. A Lagrangian function is constructed and constraints are introduced. The optimal control variables are then determined by solving a set of partial derivative equations. For example, when constructing the Lagrangian function, state and dynamic constraints are introduced into the function in the form of Lagrangian multipliers. The partial derivatives of the Lagrangian function with respect to each variable are then taken, resulting in a set of partial derivative equations. By solving this set of equations, the optimal control variables, such as voltage regulation and frequency calibration, are determined, thereby correcting the local process.
[0058] Throughout the implementation process, every step is closely centered around the goal of local process correction. When constructing the local correction window, the window size must be appropriately adjusted based on parameters such as current voltage, frequency, and error correction rate, combined with the rate correlation coefficient, to ensure that the window accurately reflects the parameter range currently requiring correction. When constructing a local environment model using multimodal sensing data, the accuracy of coordinate transformation and the rationality of the grid map credibility probability calculation are crucial, directly impacting the accuracy of the description of the local environmental state. The Kalman filter algorithm's tracking accuracy for dynamic disturbances depends on the establishment of the state prediction equation and the accuracy of the measurement data, requiring appropriate algorithm parameter settings based on actual conditions. The construction of the process correction model must fully consider the dynamic characteristics and various constraints of the navigation chip to ensure that the model accurately describes the chip's operating state. The selection of each term and weighting coefficient in the multi-objective cost function requires comprehensive consideration of the multiple objectives of the correction process, balancing the requirements of tracking the reference process, avoiding disturbances, ensuring process smoothness, and reducing energy consumption. The application of the Lagrangian multiplier method requires the accurate construction of the Lagrangian function and the solution of a system of partial derivative equations to obtain the optimal control variable. Through such a series of specific operations and examples, the adjustment layer can effectively correct the local process based on the optimal security verification scheme, making the security enhancement process of the navigation chip more adaptable to the actual working environment and needs, and improving the security and reliability of the chip.
[0059] Example 5:
[0060] When the execution layer updates the navigation chip's security parameters and outputs safety enhancement instructions based on a parameter-adaptive algorithm, it establishes a three-degree-of-freedom dynamic model for the navigation chip. This model includes a voltage equation and a frequency equation. The voltage equation includes a regulating force term, an internal resistance loss term, and an environmental interference term. For example, when adjusting the voltage of the navigation chip, the regulating force term represents the externally applied regulation effect, the internal resistance loss term reflects the voltage loss caused by the chip's internal resistance, and the environmental interference term reflects the impact of surrounding environmental factors on the voltage. The frequency equation includes a calibration torque term and an inertial response term. The calibration torque term is the force used to calibrate the chip's clock frequency, while the inertial response term describes the chip's inertial characteristics when the frequency changes.
[0061] The three-degree-of-freedom dynamic model is constructed as a state-space expression. The state vector of the state-space expression includes voltage parameters, frequency parameters, error correction parameters, and regulation rate, while the control vector includes the voltage adjustment amount and frequency calibration amount. For example, the voltage parameter in the state vector reflects the current operating voltage state of the chip, the regulation rate indicates the speed of voltage regulation, and the voltage adjustment amount in the control vector is the specific adjustment value to be applied.
[0062] Linearize the state-space expression, calculate the partial derivatives of the system state equation with respect to the state vector and control vector, and construct a linearized prediction model. This linearization approximates complex nonlinear systems into linear systems, facilitating analysis and calculation. For example, linearization near the chip's operating point can accurately predict chip state changes within a certain range.
[0063] A parameter update prediction cost function is constructed, consisting of a tracking error term, a control amount penalty term, and a control increment penalty term. Each penalty term is weighted and combined using a weight matrix. The tracking error term measures the deviation between the actual and target parameters, such as the difference between the actual value of a voltage parameter and the desired safe voltage value. The control amount penalty term considers the magnitude of the control amount to avoid adverse effects on the chip caused by excessive adjustments. The control increment penalty term focuses on the magnitude of the control amount's change to prevent drastic fluctuations during parameter updates.
[0064] Construct state constraints, including voltage parameter constraints and frequency parameter constraints. For example, it is stipulated that voltage parameters must be within the voltage range for safe operation of the chip, such as between 3.3V and 5V, and frequency parameters must be within a specific frequency range, such as 100MHz to 200MHz. Construct control constraints, including voltage adjustment amount constraints and frequency calibration amount constraints, to limit the maximum amplitude of each voltage adjustment and the maximum amount of frequency calibration. Construct control increment constraints, including voltage adjustment increment constraints and frequency calibration increment constraints, to limit the increment size between two adjacent adjustments to avoid rapid parameter changes.
[0065] The parameter update prediction cost function is converted to the standard form of a quadratic programming problem, the quadratic form matrix and the linear term coefficients are calculated, and the inequality constraint matrix and the equality constraint matrix are constructed. This conversion enables the use of mature quadratic programming algorithms to find the optimal solution, such as expressing the problem in matrix form, which facilitates computer numerical calculations.
[0066] The active set method is used to solve quadratic programming problems. By identifying valid constraints and solving subproblems, the optimal solution is gradually approached. During the solution process, the constraints that are effective in the current iteration are first determined, i.e., the valid constraints. Then, the subproblems are solved for these valid constraints to obtain a new solution. The solution is then adjusted through iteration until the optimal solution that satisfies all constraints is found.
[0067] Based on the optimization results, control variables are mapped. The total regulation variable is allocated to each voltage regulation module using the voltage allocation matrix, and the total calibration variable is allocated to each frequency calibration module using the frequency allocation matrix. For example, if the total voltage regulation variable is 0.5V, the voltage allocation matrix will allocate this 0.5V to different voltage regulation modules based on the characteristics and capabilities of each module, such as 0.2V to module A and 0.3V to module B. The frequency calibration variable is similarly allocated to each frequency calibration module according to the frequency allocation matrix.
[0068] The output of the regulation module is limited. The output regulation amount is limited according to the module rated power. For example, the rated power of a voltage regulation module limits its maximum output regulation amount to 0.3V. If the calculated regulation amount is 0.4V, it is limited to 0.3V. The parameter change amount is limited according to the maximum regulation speed of the chip. For example, the maximum voltage regulation speed of the chip is 0.1V / ms. When the parameter change amount exceeds this speed, the parameter is limited, and finally a safety enhancement instruction is generated.
[0069] Throughout the implementation process, establishing an accurate three-degree-of-freedom dynamic model is fundamental. This requires fully considering the chip's voltage and frequency characteristics, as well as various influencing factors, to ensure the model accurately reflects the chip's operating state. When constructing the state-space expression, the composition of the state vector and control vector must be accurately determined so that the expression fully describes the chip's dynamics. Linearization requires selecting an appropriate operating point to ensure the accuracy of the linearized prediction model. The selection of each term and weight matrix in the parameter update prediction cost function is crucial. Factors such as tracking error, control variable, and control increment must be comprehensively considered to balance parameter update accuracy with chip safety. When establishing various constraints, appropriate constraint ranges must be set based on the chip's actual performance indicators and safety requirements to ensure safe parameter updates. When solving quadratic programming problems, the application of the active set method requires accurate identification of valid constraints to ensure efficient and accurate solution. During the control variable mapping process, the design of the voltage and frequency allocation matrices must be based on the actual capabilities and characteristics of each module to achieve a reasonable distribution of control variables. Limiting is a crucial step in ensuring chip safety. It must strictly adhere to the module's rated power and the chip's maximum regulation speed to prevent damage to the chip due to excessive or rapid regulation. Through this series of specific operations and examples, the execution layer accurately updates the navigation chip's safety parameters based on a parameter-adaptive algorithm and outputs reliable safety-enhancing instructions, effectively improving the safety and fault resilience of low-altitude aircraft navigation chips, enabling them to maintain stable operation despite various fault injection scenarios.
[0070] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0071] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection, characterized in that: include: Configuring injection parameters of the navigation chip through a multi-modal fault injection device, wherein the multi-modal fault injection device includes a voltage disturbance unit, a clock offset unit, and a data tampering unit; Based on the time series correlation acquisition module, the operating signal of the navigation chip is collected and processed in real time to obtain chip status feature data; the chip status feature data is input into a pre-built abnormality discrimination model, and the abnormality discrimination model adopts a state iteration framework to iteratively identify the abnormal state of the chip based on the feature matching function to generate an abnormality discrimination result; A multi-level security verification architecture is constructed based on the abnormality discrimination results. The multi-level security verification architecture takes maximizing verification coverage and minimizing verification time as optimization goals, and adopts a dynamic programming strategy to globally optimize the verification process, wherein the dynamic programming strategy introduces state transition cost and heuristic evaluation indicators; Outputting an optimal security verification solution based on the multi-level security verification architecture; Establishing a hierarchical security enhancement architecture based on the optimal security verification scheme, the hierarchical security enhancement architecture includes a strategy layer, a regulation layer, and an execution layer, wherein the strategy layer performs global enhancement planning based on the abnormality discrimination result, the regulation layer performs local process correction based on the optimal security verification scheme, and the execution layer implements security parameter updates of the navigation chip based on a parameter adaptive algorithm; The hierarchical safety enhancement architecture outputs safety enhancement instructions to achieve fault injection detection safety enhancement control of low-altitude aircraft navigation chips.
2. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1 is characterized in that: Inputting the chip state feature data into a pre-built abnormality discrimination model, the abnormality discrimination model adopts a state iteration framework to iteratively identify the abnormal state of the chip based on the feature matching function, and generating an abnormality discrimination result includes: Acquire real-time operation signals, including chip voltage fluctuation data, clock frequency deviation data, data transmission error data, and environmental interference noise data; construct a state space based on the real-time operation signals, and construct an action space based on the voltage offset, clock jitter, and data bit error rate that the navigation chip can withstand; A multidimensional feature matching function is constructed based on the state space and the action space. The multidimensional feature matching function includes a voltage matching term, a clock alignment term, a data error correction term, and an interference isolation term. The voltage matching term is calculated by the amplitude similarity between the actual chip voltage and the reference voltage. The clock alignment term is calculated by the phase correlation between the actual chip frequency and the reference frequency. The data error correction term is calculated by the numerical deviation between the actual bit error rate and the reference bit error rate. The interference isolation term is calculated by the signal separation between the ambient noise area and the chip working area. Constructing a state iteration framework, which includes an initial state set, a state transfer function, and a feature matching calculation module. The initial state set contains multiple hypothetical samples of chip abnormal states. The state transfer function predicts and updates the state by navigating the chip dynamics model. The feature matching calculation module evaluates the state weight based on the multi-dimensional feature matching function. The initial state set is updated using a resampling method, high-weight states are retained through roulette wheel selection, low-weight states are eliminated and new states are added, and the mean and dispersion of the chip abnormal state are calculated based on the updated state set; and an abnormality discrimination result is output based on the state iteration framework, wherein the abnormality discrimination result includes a state mean parameter, a dispersion matrix, a key feature matching confidence and an interference area isolation probability.
3. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that: A multi-level security verification architecture is constructed based on the abnormality identification results. The multi-level security verification architecture takes maximum verification coverage and shortest verification time as optimization goals, and adopts a dynamic programming strategy to globally optimize the verification process. The optimal security verification solution output based on the multi-level security verification architecture includes: Construct a multi-objective function for the verification process, wherein the multi-objective function includes a coverage optimization objective function and a time optimization objective function, wherein the coverage optimization objective function is calculated by summing the ratio of the number of verification items to the total number of items, and the time optimization objective function is calculated by weighted summing of the execution time, waiting time, and data processing time of each verification step; Constructing verification process constraints based on the multi-objective function, the verification process constraints include time constraints, resource constraints, accuracy constraints and compatibility constraints. The time constraint is used to limit the execution time range of the single-step verification, the resource constraint is used to limit the range of variation of the chip memory usage, the accuracy constraint is used to limit the error range of the verification result, and the compatibility constraint is used to ensure the degree of matching between the verification process and the original function of the navigation chip; The verification process is encoded using a node sequence, where each node contains a verification step identifier and chip resource usage information. A state transition probability is constructed based on the state transition cost and a heuristic evaluation value, and the next feasible node is determined using the state transition probability. The heuristic evaluation value is obtained by weighted calculation of the verification coverage increment and time reduction between nodes. Introducing an adaptive state transfer cost mechanism, the adaptive state transfer cost mechanism adopts a time-varying weight coefficient, the time-varying weight coefficient changes linearly with the increase of the number of optimization iterations, and the state transfer cost is dynamically adjusted by the time-varying weight coefficient; A dynamic heuristic evaluation mechanism is introduced. The dynamic heuristic evaluation mechanism uses a time-varying impact factor that increases linearly with the number of optimization iterations. The time-varying impact factor is used to adjust the weight of the heuristic evaluation value in the state transition probability. Iterative optimization is performed based on the adaptive state transition cost mechanism and the dynamic heuristic evaluation mechanism. The coverage cost and time cost of the process generated by each iteration are evaluated, and non-dominated solutions are added to the Pareto front solution set. An optimal solution that satisfies the coverage-time trade-off is selected from the Pareto front solution set as the optimal process, and the optimal process is smoothed using a spline curve to generate an optimal node sequence and corresponding verification execution parameters.
4. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that: The strategy layer performs global enhancement planning based on the abnormality identification results, including: The enhancement process is described using a parameterized curve, where the enhancement process is expressed as a function of a process parameter, where the value of the process parameter ranges from 0 to 1, and the enhancement process includes a voltage regulation component, a clock calibration component, and a data error correction component. The enhancement process is described based on a quintic Bezier curve, and parameter values of the enhancement process are calculated by summing the products of control vertex coordinates and Bezier basis functions, wherein the Bezier basis functions are calculated by power functions of the combination number and the process parameters; Constructing enhanced process constraints, the enhanced process constraints including amplitude constraints, frequency constraints, error constraints, and compatibility constraints. The amplitude constraint is used to limit the voltage adjustment range of the enhanced process, the frequency constraint is used to limit the clock calibration range of the enhanced process, the error constraint is used to limit the error correction accuracy range of the enhanced process, and the compatibility constraint is used to limit the matching range between the enhanced process and the original navigation function; Constructing a global multi-objective optimization function, the global multi-objective optimization function includes a total process length term, a parameter change integral term, a parameter change rate integral term, and a function matching measurement term, and performing a weighted combination of each term in the global multi-objective optimization function using a weighting coefficient; Discretize the enhanced process interval into multiple process segments, discretize the global multi-objective optimization function, and construct a global discretization objective function, wherein the global discretization objective function includes the process segment length, process segment parameter change, parameter change amount, and minimum function matching distance; Iteratively optimizing the global discretized objective function using a gradient descent method, and updating the position coordinates of the control vertex along the negative gradient direction by calculating the gradient value of the objective function with respect to the control vertex; The optimized enhancement process is smoothed by cubic spline interpolation. By maintaining the continuity of the position derivative, parameter derivative and rate of change derivative at the interpolation endpoints, a smooth and continuous enhancement process is generated. A node sequence and a corresponding chip adjustment speed are generated based on the smooth and continuous enhancement process.
5. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that: The adjustment layer performs local process correction based on the optimal security verification solution, including: A local correction window is constructed based on the current voltage, current frequency, and current error correction rate of the navigation chip, and the size of the local correction window is adaptively adjusted using a rate correlation coefficient to establish a positive correlation between the size of the local correction window and the current adjustment speed; A local environment model is constructed using multimodal perception data, and the operating data is transformed into parameter data in the local coordinate system. The credibility probability of the grid map is updated based on the parameter data, and the credibility probability value of each grid is calculated using the probability accumulation method. The Kalman filter algorithm is used to track dynamic interference. The state vector of the interference is predicted through the state prediction equation. The predicted state is updated based on the measurement data to obtain the precise location and impact information of the interference. Constructing a process correction model, using the dynamic equation of the navigation chip as a state equation, the state equation including voltage parameters, frequency parameters, and error correction parameters, and constructing state constraints and dynamic constraints. The state constraints are used to limit the value range of the voltage parameter and the value range of the frequency parameter, and the dynamic constraints are used to limit the value range of the voltage change rate, the frequency change rate, and the error correction efficiency change rate; Constructing a multi-objective cost function, the multi-objective cost function including a reference process tracking item, an interference avoidance item, a process smoothing item, and an energy consumption item, and performing a weighted combination of each item in the multi-objective cost function using a weighting coefficient; The Lagrange multiplier method is used to optimize and solve the multi-objective cost function, a Lagrange function is constructed and constraints are introduced, and the optimal control quantity is obtained by solving the partial derivative equation group.
6. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that: The execution layer updates the safety parameters of the navigation chip based on a parameter adaptive algorithm and outputs safety enhancement instructions through the hierarchical safety enhancement architecture to implement fault injection detection safety enhancement control for the navigation chip of a low-altitude aircraft. The control includes: Establishing a three-degree-of-freedom dynamic model for the navigation chip, the three-degree-of-freedom dynamic model includes a voltage equation and a frequency equation, the voltage equation includes a regulating force term, an internal resistance loss term, and an environmental interference term, and the frequency equation includes a calibration torque term and an inertial response term; Constructing the three-degree-of-freedom dynamic model into a state space expression, wherein the state vector of the state space expression includes a voltage parameter, a frequency parameter, an error correction parameter, and an adjustment rate, and the control vector of the state space expression includes a voltage adjustment amount and a frequency calibration amount; Linearizing the state space expression, calculating the partial derivatives of the system state equation with respect to the state vector and the control vector, and constructing a linearized prediction model; Constructing a parameter update prediction cost function, wherein the parameter update prediction cost function includes a tracking error term, a control amount penalty term, and a control increment penalty term, and performing a weighted combination of each penalty term through a weight matrix; Constructing state constraints, including voltage parameter constraints and frequency parameter constraints; constructing control constraints, including voltage regulation amount constraints and frequency calibration amount constraints; constructing control increment constraints, including voltage regulation increment constraints and frequency calibration increment constraints; Converting the parameter update prediction cost function into a standard form of a quadratic programming problem, calculating the quadratic form matrix and the linear term coefficients, and constructing the inequality constraint matrix and the equality constraint matrix; The effective set method is used to solve the quadratic programming problem, and the optimal solution is gradually approached by identifying effective constraints and solving sub-problems; Based on the optimization solution, control quantity mapping is performed, and the total regulation quantity is distributed to each voltage regulation module through the voltage distribution matrix, and the total calibration quantity is distributed to each frequency calibration module through the frequency distribution matrix; The output of the regulation module is limited, the output regulation amount is limited according to the module rated power, the parameter change amount is limited according to the maximum regulation speed of the chip, and the final safety enhancement instruction is generated.
7. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that: Based on the timing correlation acquisition module, the operation signals of the navigation chip are collected and processed in real time to obtain chip status feature data, including: normalizing the real-time operation signals obtained by the voltage disturbance unit, the clock offset unit and the data tampering unit respectively to obtain single-dimensional standard data; performing median filtering and denoising on each standard data, calculating the local mean and variance through a sliding window, and adjusting the data stability; using a time series feature extraction algorithm to extract the local feature points of each data, and establishing the corresponding relationship between different mode data through feature point matching; converting the matched feature point parameters to a unified reference coordinate system, and fusing the multi-mode feature point information through a weighted average method to generate chip status feature data containing timing information.
8. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 2, characterized in that: Constructing a state iteration framework includes: initializing a state set using a uniform distribution, where each state contains the voltage and frequency values of the navigation chip in the parameter space; calculating the adjustment module parameters corresponding to the state through the forward solution of the navigation chip dynamics, projecting the state parameters to the data plane based on the sensor calibration matrix, and generating predicted feature point parameters; calculating the numerical error between the predicted feature point parameters and the actual operating feature point parameters, and constructing a feature matching function based on the sum of squares of the errors; obtaining the weight value of each state through normalization processing, retaining the states with weight values greater than the preset threshold, and eliminating the states with weight values less than the preset threshold.
9. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 3, characterized in that: Constructing the state transition cost includes: calculating the Euclidean distance between the current node and the next node as the process length cost; calculating the parameter adjustment amount of each module required for the navigation chip to move from the current node to the next node as the resource consumption cost; calculating the minimum matching degree with the original function of the chip in the process, and increasing the penalty cost if it is less than the matching threshold; and generating the total state transition cost by linearly combining the process length cost, resource consumption cost and penalty cost.
10. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 9, characterized in that: The calculation process for the minimum matching degree with the original function of the chip includes: obtaining the parameter range of the original function of the navigation chip, the parameter range including the reference voltage interval, the reference frequency interval and the reference error correction rate interval; calculating the overlapping length of the enhanced process parameters with the reference voltage interval as the voltage matching degree; calculating the overlapping length of the enhanced process parameters with the reference frequency interval as the frequency matching degree; calculating the overlapping length of the enhanced process parameters with the reference error correction rate interval as the error correction matching degree; taking the minimum value among the voltage matching degree, the frequency matching degree and the error correction matching degree as the minimum matching degree between the process and the original function of the chip.
Citation Information
Patent Citations
Spacecraft control system robustness verification method based on model
CN111966073A
TBOX offline detection system and method
CN120491614A
Stochastic Nonlinear Predictive Controller and Method based on Uncertainty Propagation by Gaussian-assumed Density Filters
US20230022510A1
Classification and mitigation of compute express link security threats
US20230394140A1