Security Enhancement Method for Low-Altitude Aircraft Navigation Chips Based on Fault Injection Detection

By combining a multimodal fault injection device and an anomaly discrimination model with a dynamic programming strategy, a multi-level security verification architecture is constructed, which solves the security and reliability problems of navigation chips under multimodal fault injection, and realizes efficient detection and security enhancement of voltage fluctuations, clock offsets and data tampering.

CN120705783BActive Publication Date: 2025-10-31SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511196461.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-10-31
Estimated Expiration
2045-08-26

AI Technical Summary

Technical Problem

Existing methods for enhancing the security of navigation chips cannot comprehensively and efficiently address multimodal fault injection, resulting in insufficient security and reliability of navigation systems, particularly in terms of real-time and accuracy issues in detecting voltage fluctuations, clock skew, and data tampering.

Method used

A multimodal fault injection device is used to configure the injection parameters of the navigation chip. Real-time signal acquisition is performed in conjunction with a timing correlation acquisition module. An anomaly discrimination model is used for iterative identification. A multi-level security verification architecture is constructed and a dynamic programming strategy is used for global optimization. A hierarchical security enhancement architecture is established, including a policy layer, a regulation layer and an execution layer, to realize the update of the chip's security parameters.

Benefits of technology

It significantly improves the navigation chip's ability to detect multimodal faults, ensuring the safety and reliability of the navigation system. It can promptly detect faults such as voltage fluctuations, clock skew, and data tampering, optimizes the efficiency of the verification process, and enhances the overall safety performance of the chip.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705783B_ABST
    Figure CN120705783B_ABST
Patent Text Reader

Abstract

This invention relates to the field of navigation chip security protection technology, and discloses a method for enhancing the security of low-altitude aircraft navigation chips based on fault injection detection. This method configures parameters using a multi-modal fault injection device, collects navigation chip operating signals in real time using a time-series correlation acquisition module, processes the signals, and inputs them into an anomaly discrimination model to generate anomaly discrimination results. Based on this, a multi-level security verification architecture is constructed, aiming for maximum coverage and minimum time consumption. A dynamic programming strategy is used to optimize the verification process and output the optimal security verification scheme. Furthermore, a hierarchical security enhancement architecture is established, including a strategy layer, a regulation layer, and an execution layer, performing global enhancement planning, local process correction, and security parameter updates respectively, ultimately outputting security enhancement commands to achieve security enhancement control. This method can effectively improve the navigation chip's ability to cope with fault injection, enhance its security and reliability, and is suitable for security enhancement scenarios of low-altitude aircraft navigation chips.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of navigation chip security protection technology, specifically to a method for enhancing the security of navigation chips for low-altitude aircraft based on fault injection detection. Background Technology

[0002] The safety and reliability of navigation chips are crucial during the operation of low-altitude aircraft. With technological advancements, the applications of low-altitude aircraft are becoming increasingly widespread, such as logistics delivery, agricultural plant protection, and environmental monitoring, which places higher demands on the performance of navigation chips. However, navigation chips face various potential failure risks in practical operation, which can be caused by a variety of factors.

[0003] From an external environmental perspective, voltage fluctuations are a common problem. Instability in the power grid and malfunctions in power supply equipment can cause abnormal changes in the voltage input to the navigation chip. When the voltage exceeds the chip's normal operating range, it can lead to logic errors, functional failure, or even permanent damage. For example, too low a voltage may prevent the chip from maintaining its internal circuitry, resulting in calculation errors; too high a voltage may damage the transistors inside the chip, causing irreparable damage.

[0004] Clock skew is also a significant factor affecting the normal operation of navigation chips. The clock signal serves as the reference for the coordinated operation of various modules within the chip; deviations in clock frequency can disrupt the working rhythm of different parts of the chip. For example, a clock frequency that is too fast may prevent the internal circuitry of the chip from completing the corresponding operations in time, leading to data processing errors; a clock frequency that is too slow will affect the overall performance of the chip, causing delays in the aircraft's navigation response.

[0005] Data tampering also poses a serious threat to the security of navigation chips. During data transmission, factors such as electromagnetic interference and hacker attacks can cause data errors or malicious tampering. If the navigation chip receives erroneous data, it will directly affect its calculation and judgment of critical information such as the aircraft's position and speed, potentially leading to serious accidents such as loss of control or collisions.

[0006] Environmental interference noise should not be ignored. When an aircraft flies at low altitudes, it may be subject to various electromagnetic radiations, mechanical vibrations, and other interferences from the surrounding environment. These interference noises can be superimposed on the chip's operating signals, affecting the chip's normal operation. For example, strong electromagnetic interference may cause abnormal sensor outputs inside the chip, resulting in significant errors in the navigation system.

[0007] Existing navigation chip safety enhancement methods have limitations in addressing these faults. Some methods may only detect and handle single types of faults, failing to comprehensively address multimodal fault injection scenarios. Furthermore, traditional methods need improvement in the real-time performance and accuracy of fault detection, struggling to quickly and accurately identify abnormal chip states. The lack of global optimization considerations in safety verification and enhancement strategy formulation leads to inefficient verification processes and poor safety enhancement results. Therefore, there is an urgent need for a comprehensive and efficient navigation chip safety enhancement method capable of addressing multimodal fault injection to improve the safety and reliability of low-altitude aircraft navigation systems. Summary of the Invention

[0008] The purpose of this invention is to provide a method for enhancing the safety of navigation chips for low-altitude aircraft based on fault injection detection, so as to solve the problems mentioned in the background art.

[0009] To achieve the above objectives, the present invention provides the following technical solution: a method for enhancing the safety of navigation chips for low-altitude aircraft based on fault injection detection, the method comprising:

[0010] The navigation chip's injection parameters are configured using a multimodal fault injection device, which includes a voltage disturbance unit, a clock offset unit, and a data tampering unit. The navigation chip's operating signals are acquired and processed in real-time using a timing correlation acquisition module to obtain chip state characteristic data. This chip state characteristic data is then input into a pre-constructed anomaly discrimination model. This model employs a state iteration framework and iteratively identifies abnormal chip states based on a feature matching function to generate anomaly discrimination results.

[0011] Based on the anomaly detection results, a multi-level security verification architecture is constructed. The multi-level security verification architecture aims to maximize verification coverage and minimize verification time. A dynamic programming strategy is used to globally optimize the verification process. The dynamic programming strategy introduces state transition costs and heuristic evaluation metrics. Based on the multi-level security verification architecture, the optimal security verification scheme is output.

[0012] A hierarchical safety enhancement architecture is established based on the optimal safety verification scheme. The hierarchical safety enhancement architecture includes a strategy layer, an adjustment layer, and an execution layer. The strategy layer performs global enhancement planning based on the anomaly discrimination results, the adjustment layer performs local process correction based on the optimal safety verification scheme, and the execution layer updates the safety parameters of the navigation chip based on a parameter adaptive algorithm. The hierarchical safety enhancement architecture outputs safety enhancement commands to achieve fault injection detection safety enhancement control of the low-altitude aircraft navigation chip.

[0013] Preferably, the chip state feature data is input into a pre-constructed anomaly discrimination model. This model employs a state iteration framework, iteratively identifying chip anomaly states based on a feature matching function, and generating anomaly discrimination results including:

[0014] Acquire real-time operating signals, including chip voltage fluctuation data, clock frequency deviation data, data transmission error data, and environmental interference noise data; construct a state space based on the real-time operating signals, and construct an action space based on the voltage offset, clock jitter, and data error rate that the navigation chip can withstand;

[0015] A multi-dimensional feature matching function is constructed based on the state space and the action space. The multi-dimensional feature matching function includes a voltage matching term, a clock alignment term, a data error correction term, and an interference isolation term. The voltage matching term is calculated by the amplitude similarity between the chip's actual voltage and the reference voltage. The clock alignment term is calculated by the phase correlation between the chip's actual frequency and the reference frequency. The data error correction term is calculated by the numerical deviation between the actual bit error rate and the reference bit error rate. The interference isolation term is calculated by the signal separation degree between the environmental noise region and the chip's working region.

[0016] A state iteration framework is constructed, which includes an initial state set, a state transition function, and a feature matching calculation module. The initial state set contains multiple chip abnormal state hypothesis samples. The state transition function predicts and updates the state through the navigation chip dynamics model. The feature matching calculation module evaluates the state weights based on the multi-dimensional feature matching function.

[0017] The initial state set is updated using a resampling method. High-weight states are retained and low-weight states are removed and new states are added by roulette wheel selection. The mean and dispersion of the chip's abnormal states are calculated based on the updated state set. Anomaly discrimination results are output based on the state iteration framework. The anomaly discrimination results include state mean parameters, dispersion matrix, key feature matching confidence, and interference region isolation probability.

[0018] Preferably, a multi-level security verification architecture is constructed based on the anomaly detection results. This architecture aims to maximize verification coverage and minimize verification time. A dynamic programming strategy is used to globally optimize the verification process. The optimal security verification scheme output based on this architecture includes:

[0019] A multi-objective function for constructing the verification process is provided, which includes a coverage optimization objective function and a time consumption optimization objective function. The coverage optimization objective function is calculated by summing the ratios of the number of verification items to the total number of items, and the time consumption optimization objective function is calculated by weighted summing of the execution time, waiting time, and data processing time of each verification step.

[0020] Based on the multi-objective function, the verification process constraints are constructed. The verification process constraints include time constraints, resource constraints, accuracy constraints, and compatibility constraints. The time constraints are used to limit the execution time range of a single-step verification. The resource constraints are used to limit the range of changes in chip memory usage. The accuracy constraints are used to limit the range of error values ​​in the verification results. The compatibility constraints are used to ensure the degree of matching between the verification process and the original functions of the navigation chip.

[0021] The verification process is encoded using a node sequence. Each node contains a verification step identifier and chip resource usage information. A state transition probability is constructed based on the state transition cost and a heuristic evaluation value. The next feasible node is determined by the state transition probability. The heuristic evaluation value is obtained by weighted calculation of the verification coverage increment and the time reduction between nodes.

[0022] An adaptive state transition cost mechanism is introduced, which adopts a time-varying weight coefficient. The time-varying weight coefficient decreases linearly with the number of optimization iterations, and the state transition cost is dynamically adjusted through the time-varying weight coefficient.

[0023] A dynamic heuristic evaluation mechanism is introduced, which adopts a time-varying influence factor. The time-varying influence factor increases linearly with the number of optimization iterations. The weight of the heuristic evaluation value in the state transition probability is adjusted by the time-varying influence factor. Iterative optimization is performed based on the adaptive state transition cost mechanism and the dynamic heuristic evaluation mechanism. The coverage cost and time cost of the process generated in each iteration are evaluated, and non-dominated solutions are added to the Pareto front solution set.

[0024] The optimal solution that satisfies the coverage-time tradeoff is selected from the Pareto front solution set as the optimal process. The optimal process is then smoothed by spline curve processing to generate the optimal node sequence and the corresponding verification execution parameters.

[0025] Preferably, the strategy layer performs global enhancement planning based on the anomaly detection results, including:

[0026] The enhancement process is described using parametric curves, and is represented as a function of process parameters, which range from 0 to 1. The enhancement process includes voltage regulation components, clock calibration components, and data error correction components.

[0027] The enhancement process is described based on a quintic Bézier curve. The parameter values ​​of the enhancement process are obtained by summing the product of the vertex coordinates and the Bézier basis functions. The Bézier basis functions are calculated by combining the number of combinations and the power function of the process parameters.

[0028] An enhanced process constraint is constructed, which includes amplitude constraint, frequency constraint, error constraint, and compatibility constraint. The amplitude constraint is used to limit the voltage adjustment range of the enhanced process, the frequency constraint is used to limit the clock calibration range of the enhanced process, the error constraint is used to limit the error correction accuracy range of the enhanced process, and the compatibility constraint is used to limit the matching range between the enhanced process and the original navigation function.

[0029] A global multi-objective optimization function is constructed, which includes a total process length term, a parameter change integral term, a parameter change rate integral term, and a function matching metric term. The terms in the global multi-objective optimization function are weighted and combined using weighting coefficients.

[0030] The enhanced process interval is discretized into multiple process segments, and the global multi-objective optimization function is discretized to construct a global discretized objective function. The global discretized objective function includes process segment length, process segment parameter change, parameter change amount, and minimum functional matching distance.

[0031] The global discretized objective function is iteratively optimized using the gradient descent method. The position coordinates of the control vertex are updated along the negative gradient direction by calculating the gradient value of the objective function with respect to the control vertex.

[0032] The optimized enhancement process is smoothed by cubic spline interpolation. By maintaining the continuity of the position derivative, parameter derivative, and rate of change derivative at the interpolation endpoints, a smooth and continuous enhancement process is generated. Based on the smooth and continuous enhancement process, a node sequence and the corresponding chip adjustment speed are generated.

[0033] Preferably, the adjustment layer performs local process modifications based on the optimal security verification scheme, including:

[0034] A local correction window is constructed based on the current voltage, current frequency, and current error correction rate of the navigation chip. The size of the local correction window is adaptively adjusted through a rate correlation coefficient, and a positive correlation is established between the size of the local correction window and the magnitude of the current adjustment speed.

[0035] A local environment model is constructed using multimodal sensing data. The running data is transformed to obtain parameter data in the local coordinate system. The reliability probability of the raster map is updated based on the parameter data. The reliability probability value of each raster is calculated by the probability accumulation method.

[0036] The Kalman filter algorithm is used to track dynamic interference. The state vector of the interference is predicted by the state prediction equation. The predicted state is updated based on the measurement data to obtain the precise location and impact information of the interference.

[0037] A process correction model is constructed, and the dynamic equation of the navigation chip is used as the state equation. The state equation includes voltage parameters, frequency parameters and error correction parameters. State constraints and dynamic constraints are constructed. The state constraints are used to limit the value range of voltage parameters and frequency parameters. The dynamic constraints are used to limit the value range of voltage change rate, frequency change rate and error correction efficiency change rate.

[0038] A multi-objective cost function is constructed, which includes a reference process tracking term, an interference avoidance term, a process smoothing term, and an energy consumption term. The terms in the multi-objective cost function are weighted and combined by weighting coefficients.

[0039] The Lagrange multiplier method is used to optimize the multi-objective cost function. A Lagrange function is constructed and constraints are introduced. The optimal control quantity is obtained by solving the partial derivative equations.

[0040] Preferably, the execution layer updates the safety parameters of the navigation chip based on a parameter adaptive algorithm, and outputs safety enhancement commands through the hierarchical safety enhancement architecture to achieve fault injection detection safety enhancement control for the low-altitude aircraft navigation chip, including:

[0041] A three-degree-of-freedom dynamic model of a navigation chip is established. The three-degree-of-freedom dynamic model includes voltage equations and frequency equations. The voltage equations include adjustment force terms, internal resistance loss terms, and environmental disturbance terms. The frequency equations include calibration torque terms and inertial response terms.

[0042] The three-degree-of-freedom dynamic model is constructed as a state-space expression. The state vector of the state-space expression includes voltage parameters, frequency parameters, error correction parameters, and regulation rate. The control vector of the state-space expression includes voltage regulation amount and frequency calibration amount.

[0043] The state-space expression is linearized, and the partial derivatives of the system state equation with respect to the state vector and control vector are calculated to construct a linearized prediction model.

[0044] A parameter update prediction cost function is constructed, which includes a tracking error term, a control quantity penalty term, and a control increment penalty term. The penalty terms are weighted and combined using a weight matrix.

[0045] State constraints are constructed, including voltage parameter constraints and frequency parameter constraints; control constraints are constructed, including voltage regulation amount constraints and frequency calibration amount constraints; control increment constraints are constructed, including voltage regulation increment constraints and frequency calibration increment constraints.

[0046] The parameter update prediction cost function is transformed into the standard form of a quadratic programming problem. The quadratic form matrix and the coefficients of the linear terms are calculated, and the inequality constraint matrix and the equality constraint matrix are constructed.

[0047] The quadratic programming problem is solved using the effective set method, which gradually approaches the optimal solution by identifying effective constraints and solving subproblems.

[0048] Based on the optimization results, control quantities are mapped, and the total adjustment quantity is allocated to each voltage regulation module through the voltage allocation matrix, and the total calibration quantity is allocated to each frequency calibration module through the frequency allocation matrix.

[0049] The output of the adjustment module is limited. The output adjustment amount is limited according to the rated power of the module, and the parameter change amount is limited according to the maximum adjustment speed of the chip, so as to generate the final safety enhancement instruction.

[0050] Preferably, the real-time acquisition and processing of the navigation chip's operating signals based on the time-series correlation acquisition module to obtain chip state feature data includes: normalizing the real-time operating signals acquired by the voltage disturbance unit, clock offset unit, and data tampering unit to obtain single-dimensional standard data; performing median filtering to denoise each standard data, calculating the local mean and variance through a sliding window to adjust data stability; extracting local feature points of each data using a time-series feature extraction algorithm, establishing the correspondence between different mode data through feature point matching; converting the matched feature point parameters to a unified reference coordinate system, and fusing multi-mode feature point information through a weighted average method to generate chip state feature data containing time-series information.

[0051] Preferably, the state iteration framework includes: initializing the state set using a uniform distribution, where each state contains the voltage and frequency values ​​of the navigation chip in the parameter space; calculating the adjustment module parameters corresponding to the state using the forward kinematics of the navigation chip dynamics; projecting the state parameters onto the data plane based on the sensor calibration matrix to generate predicted feature point parameters; calculating the numerical error between the predicted feature point parameters and the actual operating feature point parameters; constructing a feature matching function based on the sum of squared errors; obtaining the weight values ​​of each state through normalization; retaining states with weight values ​​greater than a preset threshold; and removing states with weight values ​​less than a preset threshold.

[0052] Preferably, the state transition cost includes: calculating the Euclidean distance between the current node and the next node as the process length cost; calculating the parameter adjustment amount of each module required by the navigation chip from the current node to the next node as the resource consumption cost; calculating the minimum matching degree between the process and the original function of the chip, and increasing the penalty cost if it is less than the matching threshold; and generating the total state transition cost by linearly combining the process length cost, resource consumption cost and penalty cost.

[0053] Preferably, the minimum matching degree between the calculation process and the original function of the chip includes: obtaining the parameter range of the original function of the navigation chip, wherein the parameter range includes a reference voltage range, a reference frequency range, and a reference error correction rate range; calculating the overlap length between the enhanced process parameters and the reference voltage range as the voltage matching degree; calculating the overlap length between the enhanced process parameters and the reference frequency range as the frequency matching degree; calculating the overlap length between the enhanced process parameters and the reference error correction rate range as the error correction matching degree; and taking the minimum value among the voltage matching degree, frequency matching degree, and error correction matching degree as the minimum matching degree between the process and the original function of the chip.

[0054] Compared with the prior art, the beneficial effects of the present invention are:

[0055] In the fault detection stage, the injection parameters of the navigation chip are configured through a multimodal fault injection device, and the real-time acquisition and processing of operating signals by the timing correlation acquisition module enables comprehensive and accurate acquisition of chip state characteristic data. The pre-built anomaly discrimination model adopts a state iteration framework and a multi-dimensional feature matching function, which can accurately iteratively identify abnormal chip states, greatly improving the real-time performance and accuracy of fault detection, and enabling timely detection of various types of faults such as voltage fluctuations, clock offsets, and data tampering.

[0056] In terms of security verification, the constructed multi-level security verification architecture aims to maximize verification coverage and minimize verification time. It employs a dynamic programming strategy and incorporates state transition costs and heuristic evaluation metrics to globally optimize the verification process. This approach not only ensures comprehensive verification covering various potential fault scenarios but also effectively shortens verification time and improves verification efficiency, providing a reliable verification foundation for enhancing the security of navigation chips.

[0057] The design of the security enhancement architecture is a standout feature. The hierarchical security enhancement architecture comprises a strategy layer, a regulation layer, and an execution layer, with each layer working collaboratively. The strategy layer performs global enhancement planning based on anomaly detection results, using parameterized curves and quintic Bézier curves to describe the enhancement process. It iterative optimization using a global multi-objective optimization function and gradient descent method enables the formulation of a globally optimal enhancement strategy, improving the overall security performance of the chip. The regulation layer performs local process correction based on the optimal security verification scheme. By constructing a local correction window, a multimodal perception data environment model, and a Kalman filter algorithm to track dynamic interference, it optimizes the solution using a process correction model and a multi-objective cost function, achieving precise correction of local processes and enabling the chip to better adapt to real-time changing operating environments. The execution layer, based on a parameter adaptive algorithm, establishes a three-degree-of-freedom dynamic model of the navigation chip, constructs a state-space expression and a linearized prediction model, transforming the parameter update prediction cost function into a quadratic programming problem and solving it. This achieves precise updates of the navigation chip's security parameters, ensuring the effective execution of security enhancement commands.

[0058] During data processing, normalization, median filtering for noise reduction, and time series feature extraction are performed on real-time operating signals to ensure data stability and reliability. The construction of the state iteration framework, the calculation of state transition costs, and the calculation of the compatibility between the process and the chip's original functions further enhance the scientific rigor and effectiveness of the entire safety enhancement method. In summary, this method comprehensively improves the ability of low-altitude aircraft navigation chips to cope with multimodal fault injection, significantly enhancing the chip's safety, reliability, and stability, and providing a strong guarantee for the safe operation of low-altitude aircraft. Attached Figure Description

[0059] Figure 1 This is a schematic diagram illustrating the working principle of the low-altitude aircraft navigation chip safety enhancement method based on fault injection detection as described in this invention.

[0060] Figure 2 The flowchart for the iterative identification of anomaly detection models;

[0061] Figure 3 A flowchart for optimizing a multi-level security verification architecture;

[0062] Figure 4 A flowchart for global enhancement planning at the strategy layer;

[0063] Figure 5 A flowchart for local process modification in the adjustment layer. Detailed Implementation

[0064] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0065] Please see Figures 1-5 The present invention relates to a method for enhancing the safety of navigation chips for low-altitude aircraft based on fault injection detection, the specific implementation steps of which are as follows:

[0066] The navigation chip's injection parameters are configured using a multimodal fault injection device, which includes a voltage disturbance unit, a clock offset unit, and a data tampering unit. A timing-correlation acquisition module performs real-time acquisition and processing of the navigation chip's operating signals to obtain chip state characteristic data. This chip state characteristic data is then input into a pre-constructed anomaly discrimination model. This model employs a state iteration framework, relying on a feature matching function to iteratively identify abnormal chip states, thereby generating anomaly discrimination results.

[0067] A multi-level security verification architecture is constructed based on the anomaly detection results. This architecture aims to maximize verification coverage and minimize verification time. A dynamic programming strategy is used to globally optimize the verification process, incorporating state transition costs and heuristic evaluation metrics. The optimal security verification solution is then output based on this multi-level security verification architecture.

[0068] A hierarchical safety enhancement architecture is established based on the optimal safety verification scheme. This architecture includes a strategy layer, a regulation layer, and an execution layer. The strategy layer performs global enhancement planning based on anomaly detection results; the regulation layer performs local process correction based on the optimal safety verification scheme; and the execution layer updates the navigation chip's safety parameters based on a parameter adaptive algorithm. The hierarchical safety enhancement architecture outputs safety enhancement commands to achieve fault injection detection and safety enhancement control for low-altitude aircraft navigation chips.

[0069] Example 1:

[0070] In processing chip state characteristic data and inputting it into the anomaly detection model, real-time operating signals need to be acquired. These signals specifically include chip voltage fluctuation data, clock frequency deviation data, data transmission error data, and environmental interference noise data. After acquiring this data, a state space is constructed based on these real-time operating signals. Simultaneously, an action space is constructed based on the voltage offset, clock jitter, and data error rate that the navigation chip can withstand.

[0071] A multi-dimensional feature matching function is constructed, comprising several important components. The voltage matching term is calculated by assessing the amplitude similarity between the chip's actual voltage and the reference voltage; the clock alignment term is obtained by calculating the phase correlation between the chip's actual frequency and the reference frequency; the data error correction term requires calculating the numerical deviation between the actual bit error rate and the reference bit error rate; and the interference isolation term is determined by calculating the signal separation between the environmental noise region and the chip's operating region. These terms collectively constitute the multi-dimensional feature matching function, used for subsequent analysis of the chip's state.

[0072] A state iteration framework is constructed, which mainly consists of an initial state set, a state transition function, and a feature matching calculation module. The initial state set contains multiple hypothetical samples of abnormal chip states, providing a foundation for subsequent analysis. The state transition function predicts and updates the states using the navigation chip dynamics model, enabling prediction of possible subsequent state changes based on the current state. The feature matching calculation module evaluates the state weights based on the previously constructed multi-dimensional feature matching function, thereby determining the importance of each state.

[0073] After constructing the state iteration framework, a resampling method is used to update the initial state set. Specifically, a roulette wheel selection process is employed to retain high-weight states, remove low-weight states, and add new states. This continuously optimizes the state set, making it more accurately reflect the actual situation of the chip. After updating the state set, the mean and dispersion of the chip's abnormal states are calculated based on the updated state set. Through the calculation and analysis of this data, a deeper understanding of the distribution of abnormal chip states can be obtained.

[0074] The anomaly detection results are output based on a state iteration framework. These results contain several key pieces of information: the state mean parameter reflects the average level of chip anomalies; the dispersion matrix reflects the degree of dispersion of anomalies; the confidence score of key feature matching indicates the reliability of feature matching; and the probability of isolating interference regions reflects the likelihood of isolating the interference regions. Taken together, this information provides crucial information for subsequent handling of chip security issues.

[0075] Throughout the process, every step is closely interconnected. From acquiring real-time operating signals to constructing the state and action spaces, building multi-dimensional feature matching functions and state iteration frameworks, and updating the state set and outputting anomaly detection results, each step requires precise processing to ensure accurate identification of the chip's abnormal states and provide reliable support for subsequent safety enhancement measures. When acquiring real-time operating signals, the accuracy and completeness of the data must be ensured to avoid deviations in subsequent analysis due to data errors. When constructing the state and action spaces, the actual capacity of the navigation chip must be fully considered to ensure that the constructed spaces accurately reflect the chip's operating range. When constructing the multi-dimensional feature matching function, the calculation methods for each item must be scientific and reasonable to ensure accurate and effective evaluation of the chip's state. The construction of the state iteration framework must be rigorous, and the collaboration between modules must be smooth to achieve accurate prediction and evaluation of the chip's state. The application of resampling methods must be appropriate to ensure that the updated state set better reflects the actual situation of the chip. The output of anomaly detection results must be comprehensive and accurate to provide strong support for subsequent processing. Through this series of operations, abnormal states of the chip can be effectively identified and analyzed, providing important protection for enhancing the safety of navigation chips for low-altitude aircraft.

[0076] Example 2:

[0077] When constructing a multi-level security verification architecture and outputting the optimal security verification scheme, a multi-objective function for the verification process is constructed. This function consists of a coverage optimization objective function and a time consumption optimization objective function. The coverage optimization objective function is calculated by summing the ratios of the number of verification items to the total number of items, thereby measuring the degree of verification coverage of all items. The time consumption optimization objective function is a weighted sum of the execution time, waiting time, and data processing time of each verification step, thereby evaluating the time consumption of the entire verification process.

[0078] Based on the aforementioned multi-objective function, the constraints for the verification process are constructed. These constraints include time constraints, resource constraints, accuracy constraints, and compatibility constraints. Time constraints limit the execution time range of each verification step, ensuring that each step is completed within a reasonable timeframe and preventing any step from taking too long and affecting the overall verification process. Resource constraints limit the range of chip memory usage, preventing excessive memory consumption during verification and ensuring the normal operation of other chip functions. Accuracy constraints limit the error range of the verification results, ensuring their accuracy and reliability. Compatibility constraints ensure the compatibility of the verification process with the original functions of the navigation chip, preventing interference with the chip's normal operation.

[0079] The verification process is encoded using a node sequence, with each node containing a verification step identifier and chip resource usage information. This encoding method transforms the complex verification process into a series of ordered nodes, facilitating process analysis and optimization. State transition probabilities are constructed based on state transition costs and heuristic evaluation values ​​to determine the next feasible node. The heuristic evaluation values ​​are obtained by weighting the increase in verification coverage and the reduction in time consumption between nodes, comprehensively considering both the increase in verification coverage and the reduction in time consumption, thus providing a basis for node selection.

[0080] In this process, an adaptive state transition cost mechanism is introduced. This mechanism uses time-varying weight coefficients, which decrease linearly with the number of optimization iterations. This time-varying weight coefficient allows for dynamic adjustment of the state transition cost, enabling the impact of the cost to vary according to the actual situation at different optimization stages, thus better adapting to the needs of the optimization process. Simultaneously, a dynamic heuristic evaluation mechanism is introduced. This mechanism uses a time-varying influence factor, which increases linearly with the number of optimization iterations. The time-varying influence factor adjusts the weight of the heuristic evaluation value in the state transition probability. In the early stages of optimization, the weight of the heuristic evaluation value is smaller, focusing more on global exploration; as optimization progresses, the weight of the heuristic evaluation value gradually increases, focusing more on local optimization, thereby achieving an organic combination of global and local optimization.

[0081] Iterative optimization is performed based on an adaptive state transition cost mechanism and a dynamic heuristic evaluation mechanism. In each iteration, the coverage cost and time cost of the generated process are evaluated, and non-dominated solutions are added to the Pareto front solution set. The Pareto front solution set contains solutions that cannot be further optimized simultaneously on both the coverage and time objectives; these solutions are the optimal candidate solutions.

[0082] The optimal process is selected from the Pareto front solution set, satisfying the coverage-time trade-off. When selecting the optimal solution, both coverage and time consumption factors need to be considered comprehensively to find a scheme that achieves a balance between the two. The selected optimal process is then smoothed using spline curves. This process makes the process smoother and more continuous, reducing abrupt changes and discontinuities, thereby generating the optimal node sequence and corresponding verification execution parameters. These optimal node sequences and verification execution parameters constitute the final optimal safety verification scheme, providing scientific and reasonable guidance for the safety verification of navigation chips for low-altitude aircraft.

[0083] Throughout the implementation process, every step requires meticulous attention. When constructing the multi-objective function, it's crucial to ensure that the calculation methods for coverage and time consumption accurately reflect the actual situation. When constructing constraints, the actual performance and operational requirements of the chip must be fully considered, and the range of each constraint must be reasonably set. When coding the verification process, the integrity and accuracy of node information must be guaranteed for subsequent analysis and optimization. When introducing adaptive state transition cost mechanisms and dynamic heuristic evaluation mechanisms, the changing patterns of time-varying weight coefficients and time-varying influence factors must be reasonably set to ensure their effective role in the optimization process. During iterative optimization, the process generated in each iteration must be comprehensively and accurately evaluated to ensure the quality of the Pareto front solution set. When selecting the optimal solution and performing spline curve smoothing, multiple factors must be comprehensively considered to ensure that the generated optimal safety verification scheme has practical application value. Through this series of detailed and rigorous operations, an efficient and reliable multi-level safety verification architecture can be constructed, and the optimal safety verification scheme can be output, providing strong support for enhancing the safety of low-altitude aircraft navigation chips.

[0084] Example 3:

[0085] When the strategy layer performs global enhancement planning based on anomaly detection results, it uses parametric curves to describe the enhancement process, representing it as a function of process parameters. The parameters range from 0 to 1, and the enhancement process includes voltage regulation, clock calibration, and data error correction components. Here, the enhancement process is described based on a quintic Bézier curve, the expression of which is:

[0086] ;

[0087] in, This indicates the parameter values ​​for enhancing the process. This is a process parameter, and its value ranges from 0 to 1. To control the vertex coordinates, which are used to control the shape of the curve; The fifth-order Bessel basis function is calculated using the power function of the combinatorial number and the process parameters. The specific calculation method is as follows: ,in This indicates selecting from 5 elements. The number of combinations of elements.

[0088] The enhancement process is constrained by several factors, including amplitude constraints, frequency constraints, error constraints, and compatibility constraints. Amplitude constraints limit the voltage adjustment range of the enhancement process, ensuring it remains within the chip's safe operating range. Frequency constraints limit the clock calibration range of the enhancement process, preventing clock calibration from exceeding the chip's normal operating frequency range. Error constraints limit the error correction accuracy range of the enhancement process, ensuring the data error correction effect meets requirements. Compatibility constraints limit the compatibility range between the enhancement process and the existing navigation function, preventing the enhancement process from adversely affecting the chip's original navigation functionality.

[0089] A global multi-objective optimization function is constructed, which includes a total process length term, a parameter variation integral term, a parameter variation rate integral term, and a function matching metric term. These terms are weighted and combined using weighting coefficients. The total process length term measures the overall length of the enhancement process; the parameter variation integral term reflects the parameter changes throughout the process; the parameter variation rate integral term reflects the rate of parameter change; and the function matching metric term evaluates the degree of compatibility between the enhancement process and the chip's original functions.

[0090] The enhanced process interval is discretized into multiple process segments, and the global multi-objective optimization function is discretized to construct a global discretized objective function. The global discretized objective function includes the process segment length, process segment parameter variations, parameter variations, and the minimum functional matching distance. Through discretization, the continuous optimization problem is transformed into a discrete problem, facilitating numerical computation and optimization.

[0091] The gradient descent method is used to iteratively optimize the globally discretized objective function. Specifically, it calculates the gradient of the objective function with respect to the control vertices and then updates the coordinates of the control vertices along the negative gradient direction. Gradient descent is a commonly used optimization method that gradually reduces the objective function by continuously adjusting the positions of the control vertices, thereby finding the optimal control vertex positions.

[0092] The optimized enhancement process is smoothed using cubic spline interpolation. By maintaining the continuity of the position derivative, parameter derivative, and rate of change derivative at the interpolation endpoints, a smooth and continuous enhancement process is generated. Cubic spline interpolation ensures smooth transitions at connection points, avoiding abrupt changes and making the enhancement process more stable and continuous. Finally, a node sequence and corresponding chip adjustment speeds are generated based on the smooth and continuous enhancement process. The node sequence clarifies each stage and step of the enhancement process, while the chip adjustment speed provides specific parameter basis for the adjustment operation corresponding to each node.

[0093] Throughout the implementation process, from the selection of parametric curves and the construction of Bézier curves to the setting of various constraints and the construction of optimization functions, every step requires precise design and rigorous execution. Fifth-order Bézier curves were chosen because they can flexibly describe complex curve shapes and meet the diverse needs of the enhancement process. The setting of control vertices directly affects the shape and direction of the curve and needs to be adjusted reasonably according to actual enhancement requirements. The determination of various constraints must fully consider the chip's performance indicators and operating requirements to ensure that the enhancement process is carried out within a safe and reliable range. The construction of the global multi-objective optimization function requires comprehensive consideration of multiple factors, and balanced optimization of various objectives is achieved by reasonably setting weighting coefficients. The application of the gradient descent method requires accurate calculation of gradient values ​​and reasonable control of the iteration step size and number of iterations to ensure the convergence and efficiency of the optimization process. Cubic spline interpolation smoothing can improve the smoothness and continuity of the enhancement process, making chip adjustment more stable and reliable. The generated node sequence and chip adjustment speed must be operable and practical, providing clear guidance for actual chip safety enhancement operations. Through this series of detailed and rigorous steps, the strategy layer can achieve a scientific and reasonable design of global enhancement planning, providing effective strategy support for the safety enhancement of navigation chips for low-altitude aircraft.

[0094] Example 4:

[0095] When the adjustment layer performs local process corrections based on the optimal safety verification scheme, it constructs a local correction window based on the current voltage, frequency, and error correction rate of the navigation chip. Here, the size of the local correction window is adaptively adjusted through a rate correlation coefficient, establishing a positive correlation between the size of the local correction window and the current adjustment speed. For example, when the current adjustment speed of the navigation chip is fast, the size of the local correction window increases accordingly to cover a wider range of possible parameter changes; when the adjustment speed is slow, the window size decreases to focus more on the current parameter state.

[0096] A local environment model is constructed using multimodal sensing data, and coordinate transformation is performed on the operational data to obtain parameter data in the local coordinate system. For example, sensing data from different modules such as the voltage disturbance unit and the clock offset unit are transformed into the same local coordinate system for unified analysis. The confidence probability of the grid map is updated based on this parameter data, and the confidence probability value of each grid is calculated using a probability accumulation method. For instance, in the grid map, each grid represents a possible parameter state region. The confidence probability of each grid is updated based on the current parameter data; the closer the parameter data is to the state corresponding to a grid, the higher the confidence probability of that grid. By continuously accumulating these probabilities, the state distribution of the local environment can be described more accurately.

[0097] A Kalman filter algorithm is employed to track dynamic interference. The state vector of the interference is predicted using a state prediction equation, and the predicted state is updated based on measured data to obtain the precise location and impact information of the interference. For example, assuming the state vector of the dynamic interference includes parameters such as position and velocity, the state prediction equation is first used to predict the current state based on the state at the previous moment. Then, the actual measured data is compared with the predicted state, and the predicted state is corrected through Kalman filter gain calculation, thereby obtaining more accurate interference location and impact information, such as the intensity and range of the interference.

[0098] A process correction model is constructed, using the dynamic equations of the navigation chip as state equations. These state equations include voltage parameters, frequency parameters, and error correction parameters. Simultaneously, state constraints and dynamic constraints are established. State constraints limit the value ranges of the voltage and frequency parameters; for example, they stipulate that the voltage parameters must be within the normal operating voltage range of the chip, and the frequency parameters must also be within a specific frequency range. Dynamic constraints limit the value ranges of the voltage change rate, frequency change rate, and error correction efficiency change rate, preventing excessively rapid or slow parameter changes from affecting the normal operation of the chip.

[0099] A multi-objective cost function is then constructed, which includes a reference process tracking term, an interference avoidance term, a process smoothing term, and an energy consumption term. These terms are weighted and combined using weighting coefficients. The reference process tracking term measures the deviation between the current modified process and the reference process, ensuring that the modified process does not deviate too far from the optimal safety verification scheme. The interference avoidance term evaluates the process's effectiveness in avoiding dynamic interference, enabling the process to avoid interference areas as much as possible. The process smoothing term ensures the smoothness of the process and reduces parameter abrupt changes. The energy consumption term considers the energy consumption during process execution and selects the lowest energy-consuming solution.

[0100] The Lagrange multiplier method is used to optimize the multi-objective cost function. A Lagrange function is constructed and constraints are introduced. The optimal control quantity is obtained by solving a system of partial derivative equations. For example, when constructing the Lagrange function, state constraints and dynamic constraints are introduced into the function in the form of Lagrange multipliers. Then, partial derivatives of the Lagrange function with respect to each variable are calculated, resulting in a system of partial derivative equations. By solving this system of equations, the optimal control quantity, such as voltage regulation or frequency calibration, is determined, thereby achieving the correction of local processes.

[0101] Throughout the implementation process, each step revolves closely around the goal of local process correction. When constructing the local correction window, the window size needs to be adjusted reasonably based on parameters such as current voltage, frequency, and error correction rate, combined with the rate correlation coefficient, to ensure that the window accurately reflects the range of parameters requiring correction. When constructing a local environment model using multimodal sensing data, the accuracy of coordinate transformation and the rationality of the raster map's reliability probability calculation are crucial, directly affecting the accuracy of the description of the local environment state. The Kalman filter algorithm's tracking accuracy for dynamic interference depends on the establishment of the state prediction equation and the accuracy of the measurement data; therefore, algorithm parameters need to be set reasonably according to the actual situation. The construction of the process correction model must fully consider the dynamic characteristics and various constraints of the navigation chip to ensure that the model can accurately describe the chip's operating state. The setting of each item in the multi-objective cost function and the selection of weighting coefficients need to comprehensively consider multiple objectives of process correction, balancing the needs of tracking the reference process, avoiding interference, ensuring process smoothness, and reducing energy consumption. The application of the Lagrange multiplier method requires accurately constructing the Lagrange function and solving the partial derivative equations to obtain the optimal control quantity. Through this series of specific operations and examples, the adjustment layer can effectively modify local processes based on the optimal security verification scheme, making the security enhancement process of the navigation chip more adaptable to the actual working environment and needs, and improving the chip's security and reliability.

[0102] Example 5:

[0103] When the execution layer updates the safety parameters of the navigation chip and outputs safety enhancement commands based on the parameter adaptive algorithm, a three-degree-of-freedom dynamic model of the navigation chip is established. This model includes voltage equations and frequency equations. The voltage equations contain regulation force terms, internal resistance loss terms, and environmental interference terms. For example, when regulating the voltage of the navigation chip, the regulation force term represents the externally applied regulation action, the internal resistance loss term reflects the voltage loss caused by the chip's internal resistance, and the environmental interference term reflects the influence of surrounding environmental factors on the voltage. The frequency equations contain calibration torque terms and inertial response terms. The calibration torque term is the force that calibrates the chip's clock frequency, and the inertial response term describes the inertial characteristics of the chip when the frequency changes.

[0104] The three-degree-of-freedom dynamic model is constructed as a state-space expression. The state vector of the state-space expression includes voltage parameters, frequency parameters, error correction parameters, and regulation rates, while the control vector includes voltage regulation amounts and frequency calibration amounts. For example, the voltage parameter in the state vector reflects the current operating voltage state of the chip, the regulation rate indicates the speed of voltage regulation, and the voltage regulation amount in the control vector is the specific regulation value that needs to be applied.

[0105] The state-space expression is linearized, and the partial derivatives of the system state equations with respect to the state vector and control vector are calculated to construct a linearized prediction model. By linearizing, complex nonlinear systems are approximated as linear systems, facilitating analysis and computation. For example, linearization near the chip's operating point enables accurate prediction of chip state changes within a certain range.

[0106] A parameter update prediction cost function is constructed, which includes a tracking error term, a control penalty term, and a control increment penalty term. These penalty terms are weighted and combined using a weight matrix. The tracking error term measures the deviation between the actual and target parameters, such as the difference between the actual voltage value and the expected safe voltage value. The control penalty term considers the magnitude of the control input to avoid applying excessive adjustments that could adversely affect the chip. The control increment penalty term focuses on the magnitude of the control input change to prevent drastic fluctuations during parameter updates.

[0107] Establish state constraints, including voltage parameter constraints and frequency parameter constraints. For example, the voltage parameter must be within the safe operating voltage range of the chip, such as 3.3V to 5V, and the frequency parameter must be within a specific frequency range, such as 100MHz to 200MHz. Establish control constraints, including voltage adjustment amount constraints and frequency calibration amount constraints, limiting the maximum amplitude of each voltage adjustment and the maximum amount of frequency calibration. Establish control increment constraints, including voltage adjustment increment constraints and frequency calibration increment constraints, limiting the increment between two adjacent adjustments to avoid excessively rapid parameter changes.

[0108] The parameter update prediction cost function is transformed into the standard form of a quadratic programming problem. The quadratic form matrix and the coefficients of the linear terms are calculated, and inequality and equality constraint matrices are constructed. This transformation allows the use of mature quadratic programming algorithms to find the optimal solution; for example, representing the problem in matrix form facilitates numerical computation by computers.

[0109] The effective set method is used to solve quadratic programming problems. By identifying effective constraints and solving subproblems, the optimal solution is gradually approached. In the solution process, it is first determined which constraints are in effect in the current iteration, i.e., effective constraints. Then, subproblems are solved for these effective constraints to obtain new solutions. The solution is then continuously adjusted through iteration until the optimal solution that satisfies all constraints is found.

[0110] Based on the optimization results, control quantities are mapped. The total regulation quantity is allocated to each voltage regulation module through a voltage allocation matrix, and the total calibration quantity is allocated to each frequency calibration module through a frequency allocation matrix. For example, assuming the total voltage regulation quantity is 0.5V, the voltage allocation matrix allocates this 0.5V to different voltage regulation modules according to the characteristics and capabilities of each module, such as allocating 0.2V to module A and 0.3V to module B; the frequency calibration quantity is similarly allocated to each frequency calibration module according to the frequency allocation matrix.

[0111] The output of the regulation module is limited. The output regulation amount is limited according to the rated power of the module. For example, if the rated power of a voltage regulation module limits its maximum output regulation amount to 0.3V, and the calculated regulation amount is 0.4V, then it is limited to 0.3V. The parameter change amount is limited according to the maximum regulation speed of the chip. For example, if the maximum voltage regulation speed of the chip is 0.1V / ms, when the parameter change amount exceeds this speed, the limitation process is performed, and finally, a safety enhancement instruction is generated.

[0112] Throughout the implementation process, establishing an accurate three-degree-of-freedom dynamic model is fundamental. This requires fully considering the chip's voltage and frequency characteristics, as well as various influencing factors, to ensure the model accurately reflects the chip's operating state. When constructing the state-space expression, the composition of the state vector and control vector must be accurately determined to comprehensively describe the chip's dynamic process. Linearization requires selecting an appropriate operating point to ensure the accuracy of the linearized prediction model. The setting of each term in the parameter update prediction cost function and the selection of the weight matrix are crucial, requiring comprehensive consideration of tracking error, control quantity, and control increment to balance the accuracy of parameter updates with the chip's safety. When constructing various constraints, the constraint range must be reasonably set based on the chip's actual performance indicators and safety requirements to ensure that parameter updates are performed safely. When solving the quadratic programming problem, the application of the effective set method requires accurate identification of effective constraints to ensure the efficiency and accuracy of the solution process. During the control quantity mapping process, the design of the voltage allocation matrix and frequency allocation matrix must be based on the actual capabilities and characteristics of each module to achieve a reasonable allocation of adjustment quantities. Limiting is a crucial step in ensuring chip safety. It must be strictly limited according to the module's rated power and the chip's maximum adjustment speed to prevent damage from excessive adjustment or rapid changes. Through this series of specific operations and examples, the execution layer can accurately update the navigation chip's safety parameters based on a parameter adaptive algorithm and output reliable safety enhancement commands. This effectively improves the safety and fault tolerance of low-altitude aircraft navigation chips, enabling them to maintain stable operation under various fault injection scenarios.

[0113] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0114] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for enhancing the safety of navigation chips for low-altitude aircraft based on fault injection detection, characterized in that, include: The injection parameters of the navigation chip are configured through a multimodal fault injection device, which includes a voltage disturbance unit, a clock offset unit, and a data tampering unit. The navigation chip's operating signals are acquired and processed in real time using a time-series correlation acquisition module to obtain chip state feature data. The chip state feature data is then input into a pre-constructed anomaly discrimination model. The anomaly discrimination model uses a state iteration framework to iteratively identify abnormal chip states based on a feature matching function, generating anomaly discrimination results. Based on the anomaly detection results, a multi-level security verification architecture is constructed. The multi-level security verification architecture aims to maximize verification coverage and minimize verification time. A dynamic programming strategy is used to globally optimize the verification process. The dynamic programming strategy introduces state transition costs and heuristic evaluation metrics. The optimal security verification scheme is output based on the aforementioned multi-level security verification architecture. A hierarchical security enhancement architecture is established based on the optimal security verification scheme. The hierarchical security enhancement architecture includes a strategy layer, an adjustment layer, and an execution layer. The strategy layer performs global enhancement planning based on the anomaly detection results, the adjustment layer performs local process correction based on the optimal security verification scheme, and the execution layer updates the security parameters of the navigation chip based on a parameter adaptive algorithm. The hierarchical safety enhancement architecture outputs safety enhancement commands to achieve fault injection detection and safety enhancement control for low-altitude aircraft navigation chips.

2. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that, The chip state feature data is input into a pre-constructed anomaly detection model. The anomaly detection model adopts a state iteration framework and iteratively identifies chip anomaly states based on a feature matching function, generating anomaly detection results including: Acquire real-time operating signals, including chip voltage fluctuation data, clock frequency deviation data, data transmission error data, and environmental interference noise data; construct a state space based on the real-time operating signals, and construct an action space based on the voltage offset, clock jitter, and data error rate that the navigation chip can withstand; A multi-dimensional feature matching function is constructed based on the state space and the action space. The multi-dimensional feature matching function includes a voltage matching term, a clock alignment term, a data error correction term, and an interference isolation term. The voltage matching term is calculated by the amplitude similarity between the chip's actual voltage and the reference voltage. The clock alignment term is calculated by the phase correlation between the chip's actual frequency and the reference frequency. The data error correction term is calculated by the numerical deviation between the actual bit error rate and the reference bit error rate. The interference isolation term is calculated by the signal separation degree between the environmental noise region and the chip's working region. A state iteration framework is constructed, which includes an initial state set, a state transition function, and a feature matching calculation module. The initial state set contains multiple chip abnormal state hypothesis samples. The state transition function predicts and updates the state through the navigation chip dynamics model. The feature matching calculation module evaluates the state weights based on the multi-dimensional feature matching function. The initial state set is updated using a resampling method. High-weight states are retained and low-weight states are removed and new states are added by roulette wheel selection. The mean and dispersion of the chip's abnormal states are calculated based on the updated state set. Anomaly discrimination results are output based on the state iteration framework. The anomaly discrimination results include state mean parameters, dispersion matrix, key feature matching confidence, and interference region isolation probability.

3. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that, Based on the anomaly detection results, a multi-level security verification architecture is constructed. This architecture aims to maximize verification coverage and minimize verification time. A dynamic programming strategy is used to globally optimize the verification process. The optimal security verification scheme output based on this multi-level security verification architecture includes: A multi-objective function for constructing the verification process is provided, which includes a coverage optimization objective function and a time consumption optimization objective function. The coverage optimization objective function is calculated by summing the ratios of the number of verification items to the total number of items, and the time consumption optimization objective function is calculated by weighted summing of the execution time, waiting time, and data processing time of each verification step. Based on the multi-objective function, the verification process constraints are constructed. The verification process constraints include time constraints, resource constraints, accuracy constraints, and compatibility constraints. The time constraints are used to limit the execution time range of a single-step verification. The resource constraints are used to limit the range of changes in chip memory usage. The accuracy constraints are used to limit the range of error values ​​in the verification results. The compatibility constraints are used to ensure the degree of matching between the verification process and the original functions of the navigation chip. The verification process is encoded using a node sequence. Each node contains a verification step identifier and chip resource usage information. A state transition probability is constructed based on the state transition cost and a heuristic evaluation value. The next feasible node is determined by the state transition probability. The heuristic evaluation value is obtained by weighted calculation of the verification coverage increment and the time reduction between nodes. An adaptive state transition cost mechanism is introduced, which adopts a time-varying weight coefficient. The time-varying weight coefficient decreases linearly with the number of optimization iterations, and the state transition cost is dynamically adjusted through the time-varying weight coefficient. A dynamic heuristic evaluation mechanism is introduced, which adopts a time-varying influence factor. The time-varying influence factor increases linearly with the number of optimization iterations. The weight of the heuristic evaluation value in the state transition probability is adjusted by the time-varying influence factor. Iterative optimization is performed based on the adaptive state transition cost mechanism and the dynamic heuristic evaluation mechanism. The coverage cost and time cost of the process generated in each iteration are evaluated, and non-dominated solutions are added to the Pareto front solution set. The optimal solution that satisfies the coverage-time tradeoff is selected from the Pareto front solution set as the optimal process. The optimal process is then smoothed by spline curve processing to generate the optimal node sequence and the corresponding verification execution parameters.

4. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that, The strategy layer performs global enhancement planning based on the anomaly detection results, including: The enhancement process is described using parametric curves, and is represented as a function of process parameters, which range from 0 to 1. The enhancement process includes voltage regulation components, clock calibration components, and data error correction components. The enhancement process is described based on a quintic Bézier curve. The parameter values ​​of the enhancement process are obtained by summing the product of the vertex coordinates and the Bézier basis functions. The Bézier basis functions are calculated by combining the number of combinations and the power function of the process parameters. An enhanced process constraint is constructed, which includes amplitude constraint, frequency constraint, error constraint, and compatibility constraint. The amplitude constraint is used to limit the voltage adjustment range of the enhanced process, the frequency constraint is used to limit the clock calibration range of the enhanced process, the error constraint is used to limit the error correction accuracy range of the enhanced process, and the compatibility constraint is used to limit the matching range between the enhanced process and the original navigation function. A global multi-objective optimization function is constructed, which includes a total process length term, a parameter change integral term, a parameter change rate integral term, and a function matching metric term. The terms in the global multi-objective optimization function are weighted and combined using weighting coefficients. The enhanced process interval is discretized into multiple process segments, and the global multi-objective optimization function is discretized to construct a global discretized objective function. The global discretized objective function includes process segment length, process segment parameter change, parameter change amount, and minimum functional matching distance. The global discretized objective function is iteratively optimized using the gradient descent method. The position coordinates of the control vertex are updated along the negative gradient direction by calculating the gradient value of the objective function with respect to the control vertex. The optimized enhancement process is smoothed by cubic spline interpolation. By maintaining the continuity of the position derivative, parameter derivative, and rate of change derivative at the interpolation endpoints, a smooth and continuous enhancement process is generated. Based on the smooth and continuous enhancement process, a node sequence and the corresponding chip adjustment speed are generated.

5. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that, The adjustment layer performs local process modifications based on the optimal security verification scheme, including: A local correction window is constructed based on the current voltage, current frequency, and current error correction rate of the navigation chip. The size of the local correction window is adaptively adjusted through a rate correlation coefficient, and a positive correlation is established between the size of the local correction window and the magnitude of the current adjustment speed. A local environment model is constructed using multimodal sensing data. The running data is transformed to obtain parameter data in the local coordinate system. The reliability probability of the raster map is updated based on the parameter data. The reliability probability value of each raster is calculated by the probability accumulation method. The Kalman filter algorithm is used to track dynamic interference. The state vector of the interference is predicted by the state prediction equation. The predicted state is updated based on the measurement data to obtain the precise location and impact information of the interference. A process correction model is constructed, and the dynamic equation of the navigation chip is used as the state equation. The state equation includes voltage parameters, frequency parameters and error correction parameters. State constraints and dynamic constraints are constructed. The state constraints are used to limit the value range of voltage parameters and frequency parameters. The dynamic constraints are used to limit the value range of voltage change rate, frequency change rate and error correction efficiency change rate. A multi-objective cost function is constructed, which includes a reference process tracking term, an interference avoidance term, a process smoothing term, and an energy consumption term. The terms in the multi-objective cost function are weighted and combined by weighting coefficients. The Lagrange multiplier method is used to optimize the multi-objective cost function. A Lagrange function is constructed and constraints are introduced. The optimal control quantity is obtained by solving the partial derivative equations.

6. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that, The execution layer updates the safety parameters of the navigation chip based on a parameter adaptive algorithm, and outputs safety enhancement commands through the hierarchical safety enhancement architecture. This achieves fault injection detection and safety enhancement control for the low-altitude aircraft navigation chip, including: A three-degree-of-freedom dynamic model of a navigation chip is established. The three-degree-of-freedom dynamic model includes voltage equations and frequency equations. The voltage equations include adjustment force terms, internal resistance loss terms, and environmental disturbance terms. The frequency equations include calibration torque terms and inertial response terms. The three-degree-of-freedom dynamic model is constructed as a state-space expression. The state vector of the state-space expression includes voltage parameters, frequency parameters, error correction parameters, and regulation rate. The control vector of the state-space expression includes voltage regulation amount and frequency calibration amount. The state-space expression is linearized, and the partial derivatives of the system state equation with respect to the state vector and control vector are calculated to construct a linearized prediction model. A parameter update prediction cost function is constructed, which includes a tracking error term, a control quantity penalty term, and a control increment penalty term. The penalty terms are weighted and combined using a weight matrix. State constraints are constructed, including voltage parameter constraints and frequency parameter constraints; control constraints are constructed, including voltage regulation amount constraints and frequency calibration amount constraints; control increment constraints are constructed, including voltage regulation increment constraints and frequency calibration increment constraints. The parameter update prediction cost function is transformed into the standard form of a quadratic programming problem. The quadratic form matrix and the coefficients of the linear terms are calculated, and the inequality constraint matrix and the equality constraint matrix are constructed. The quadratic programming problem is solved using the effective set method, which gradually approaches the optimal solution by identifying effective constraints and solving subproblems. Based on the optimization results, control quantities are mapped, and the total adjustment quantity is allocated to each voltage regulation module through the voltage allocation matrix, and the total calibration quantity is allocated to each frequency calibration module through the frequency allocation matrix. The output of the adjustment module is limited. The output adjustment amount is limited according to the rated power of the module, and the parameter change amount is limited according to the maximum adjustment speed of the chip, so as to generate the final safety enhancement instruction.

7. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 1, characterized in that, The navigation chip's operating signals are acquired and processed in real time using a time-series correlation acquisition module to obtain chip status feature data. This includes: normalizing the real-time operating signals acquired by the voltage disturbance unit, clock offset unit, and data tampering unit to obtain single-dimensional standard data; performing median filtering to denoise each standard data point, calculating local mean and variance through a sliding window to adjust data stability; extracting local feature points from each data point using a time-series feature extraction algorithm, establishing correspondences between different mode data through feature point matching; converting the matched feature point parameters to a unified reference coordinate system, and fusing multi-mode feature point information using a weighted average method to generate chip status feature data containing time-series information.

8. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 2, characterized in that, The state iteration framework is constructed as follows: a uniformly distributed initial state set is used, where each state contains the voltage and frequency values ​​of the navigation chip in the parameter space; the adjustment module parameters corresponding to the state are calculated using the forward kinematics of the navigation chip dynamics; the state parameters are projected onto the data plane based on the sensor calibration matrix to generate predicted feature point parameters; the numerical error between the predicted feature point parameters and the actual operating feature point parameters is calculated, and a feature matching function is constructed based on the sum of squared errors; the weight values ​​of each state are obtained through normalization, and states with weight values ​​greater than a preset threshold are retained, while states with weight values ​​less than a preset threshold are removed.

9. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 3, characterized in that, The state transition cost is calculated as follows: the Euclidean distance between the current node and the next node is used as the process length cost; the parameter adjustment of each module required by the navigation chip from the current node to the next node is used as the resource consumption cost; the minimum matching degree between the process and the original function of the chip is calculated, and if it is less than the matching threshold, a penalty cost is added; the total state transition cost is generated by linearly combining the process length cost, resource consumption cost and penalty cost.

10. The method for enhancing the safety of low-altitude aircraft navigation chips based on fault injection detection according to claim 9, characterized in that, The minimum matching degree between the calculation process and the original functions of the chip includes: obtaining the parameter range of the original functions of the navigation chip, wherein the parameter range includes a reference voltage range, a reference frequency range, and a reference error correction rate range; calculating the overlap length between the enhanced process parameters and the reference voltage range as the voltage matching degree; calculating the overlap length between the enhanced process parameters and the reference frequency range as the frequency matching degree; calculating the overlap length between the enhanced process parameters and the reference error correction rate range as the error correction matching degree; and taking the minimum value among the voltage matching degree, frequency matching degree, and error correction matching degree as the minimum matching degree between the process and the original functions of the chip.

Citation Information

Patent Citations

  • TBOX offline detection system and method

    CN120491614A

  • Stochastic Nonlinear Predictive Controller and Method based on Uncertainty Propagation by Gaussian-assumed Density Filters

    US20230022510A1