A fault testing method, system, medium, and device based on functional modules.
By identifying functional coupling interfaces and generating cooperative perturbation sequences, and using functional modules for precise control and monitoring, the problems of low efficiency and poor accuracy of existing fault testing methods are solved, and efficient and accurate fault testing is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XIAN PANWEI DEFENSE TECH CO LTD
- Filing Date
- 2025-09-25
- Publication Date
- 2026-07-17
AI Technical Summary
Existing fault testing methods are inefficient and inaccurate, unable to dynamically adjust testing strategies according to the characteristics of the system under test, and unable to fully cover the key weak links of the system.
By acquiring the interface parameters and application scenario information of the object under test, identifying the initial interface of functional coupling, generating a cooperative perturbation sequence and instantaneous test plan, and using functional modules for precise control and monitoring, a dynamic test strategy can be realized.
It improves the efficiency and accuracy of fault testing, avoids redundant test items, ensures systematicity and integrity, and captures the moment of fault occurrence in a timely manner.
Smart Images

Figure CN121277147B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of fault testing technology, specifically to a fault testing method, system, medium, and device based on functional modules. Background Technology
[0002] Fault testing refers to a testing method that intentionally applies various abnormal conditions, extreme loads, or external disturbances to a system to verify its reliability, stability, and fault recovery capabilities under abnormal operating environments. The core objective of fault testing is to identify potential design flaws, performance bottlenecks, and weaknesses before formal system deployment. By simulating abnormal situations in a real-world environment, it evaluates the system's fault tolerance and the effectiveness of its fault handling mechanisms. With the increasing complexity of modern electronic systems, fault testing has become a crucial step in the system design verification process.
[0003] Fault testing methods in related technologies primarily employ an exhaustive approach to perform fault testing on fixed test items. This involves executing various fault scenarios sequentially using a predefined test case library, such as voltage drop tests, temperature cycling tests, and electromagnetic compatibility tests. However, this exhaustive approach to fixed test items is inflexible in practical applications. It cannot dynamically adjust the testing strategy based on the specific characteristics of the system under test, necessitating the execution of numerous redundant test items that are incompatible with the system's characteristics, resulting in low efficiency. Furthermore, fixed test items cannot adequately cover the system's critical weaknesses, leading to poor accuracy and a weak correlation between test results and actual fault risks. Therefore, these technologies struggle to simultaneously meet the dual requirements of testing efficiency and accuracy. Summary of the Invention
[0004] This application provides a fault testing method, system, medium, and device based on functional modules, which can improve testing efficiency while ensuring fault testing accuracy.
[0005] Firstly, this application provides a fault testing method based on functional modules, the method comprising:
[0006] Obtain the interface parameters of the object under test, and identify multiple initial interfaces with functional coupling based on the interface parameters;
[0007] Obtain the application scenario information of the object under test, and determine several vulnerability test scenarios corresponding to the application scenario information;
[0008] Generate a cooperative perturbation sequence containing multiple test points under the vulnerability test scenario, wherein the test points represent a set of initial interfaces and perturbation parameters of the initial interfaces;
[0009] Obtain the functional module corresponding to the test point, and generate an instantaneous test plan for the functional module based on the disturbance parameters. The instantaneous test plan indicates that the functional module will inject a coordinated disturbance into the object under test.
[0010] The instantaneous test plan is executed sequentially according to the cooperative perturbation sequence, and the running status of the tested object is monitored after the instantaneous test plan is executed;
[0011] When the operating state fails, the disturbance parameters corresponding to the test points of the current instantaneous disturbance scheme are combined to obtain the stability critical point under the fragile test scenario.
[0012] By adopting the above technical solution, the collaborative disturbance sequence generation mechanism, through multi-interface coordinated control, can realistically simulate the concurrent effects of various abnormal conditions in complex environments. Each test point contains a set of initial interfaces and their disturbance parameters, forming a complete fault scenario description. The functional module, as the core carrier of test execution, achieves precise control of disturbance injection and status monitoring through an instantaneous test scheme. The process design of executing the test scheme sequentially according to the collaborative disturbance sequence ensures the systematic nature and integrity of the test. The mechanism for real-time monitoring of the operating status of the tested object can promptly capture the moment of fault occurrence. When a fault is detected, the stability critical point is determined by analyzing the combination of disturbance parameters at the current test point. Compared with the existing method of exhaustively testing fixed test items, the technical solution of this application, through standardized configuration of functional modules and automated execution of instantaneous test schemes, avoids a large number of redundant test items that are incompatible with the characteristics of the tested system, significantly shortening the test execution time. Simultaneously, the collaborative disturbance control overcomes the deficiency that fixed test items cannot fully cover the key weak links of the system, thereby improving test efficiency while ensuring fault testing accuracy.
[0013] Optionally, the step of obtaining the interface parameters of the object under test and identifying multiple initial interfaces with functional coupling based on the interface parameters includes:
[0014] Obtain the interface parameters of the object under test under preset operating conditions. The interface parameters include at least the instantaneous power consumption of the interface, signal integrity indicators, and communication timing of the shared bus.
[0015] The interface parameters are cross-correlated according to the time series to obtain the time-domain correlation coefficient of parameter fluctuations between any two interfaces;
[0016] When the time-domain correlation coefficient exceeds a preset strong coupling threshold, the two interfaces corresponding to the time-domain correlation coefficient are identified as initial interfaces with functional coupling.
[0017] Optionally, obtaining the application scenario information of the object under test and determining several vulnerability test scenarios corresponding to the application scenario information includes:
[0018] The application scenario information of the object under test is obtained, and the application scenario information is decomposed into at least one functional load event and at least one environmental stress event, wherein the functional load event represents the internal resource scheduling behavior of the object under test, and the environmental stress event represents the change in the environment in which the object under test is located.
[0019] Monitor the shared bus occupancy rate associated with each initial interface before and after the functional load event, and calculate the increase in shared bus occupancy rate caused by executing the functional load event;
[0020] The initial interfaces whose occupancy increment is greater than a preset contention threshold are identified as resource contention-type interface groups;
[0021] Monitor the signal integrity indices associated with each of the initial interfaces before and after the environmental stress event; and calculate the signal degradation of the signal integrity indices caused by the execution of the environmental stress event.
[0022] The initial interfaces whose signal degradation exceeds a preset sensitivity threshold are identified as the physical stability interface group.
[0023] Determine the resource contention vulnerability test scenarios corresponding to the resource contention interface group and the physical stability vulnerability test scenarios corresponding to the physical stability interface group;
[0024] By combining the resource contention-based vulnerability test scenario with the physical stability vulnerability test scenario, several vulnerability test scenarios corresponding to the application scenario information are obtained.
[0025] Optionally, determining the resource contention vulnerability test scenario corresponding to the resource contention interface group and the physical stability vulnerability test scenario corresponding to the physical stability interface group includes:
[0026] Select at least one master interface and at least one slave interface from the resource contention interface group, and define the master task operation corresponding to the master interface and the slave task operation corresponding to the slave interface respectively;
[0027] Generate a temporal phase offset sequence of the slave task operation relative to the master task operation, and combine the master task operation, the slave task operation, and the temporal phase offset sequence into a resource contention-type vulnerability test scenario;
[0028] Identify logical state transition events in the interface communication protocol within the physical stability interface group, and determine the synchronization reference for the disturbance injection corresponding to the logical state transition event;
[0029] By associating the synchronization benchmark with the physical disturbance template that applies instantaneous offset, the physical stability vulnerability test scenario corresponding to the physical stability interface group is obtained.
[0030] Optionally, the generation of a cooperative perturbation sequence containing multiple test points under the vulnerability testing scenario, wherein the test points represent a set of initial interfaces and perturbation parameters of the initial interfaces, including:
[0031] The initial interfaces corresponding to the test points in the vulnerability test scenario are divided to obtain a main pressure interface and at least one secondary pressure interface.
[0032] Starting from the benchmark test point, keeping the first perturbation parameter of the secondary pressure interface unchanged, the second perturbation parameter of the main pressure interface is continuously increased with a preset first increment step to generate a main pressure increment sequence with a preset first increment step.
[0033] Starting from the test point with the highest load in the main pressure increment sequence, keeping the second perturbation parameter of the main pressure interface unchanged, the first perturbation parameter of the secondary pressure interface is continuously increased with a preset second increment step to generate an associated pressure increment sequence with a preset second increment step.
[0034] The benchmark test points, the main pressure increment sequence, and the associated pressure increment sequence are combined in the order in which they are generated to obtain a cooperative perturbation sequence.
[0035] Optionally, the step of obtaining the functional module corresponding to the test point and generating an instantaneous test plan for the functional module based on the disturbance parameters, wherein the instantaneous test plan represents controlling the functional module to inject a coordinated disturbance into the object under test, includes:
[0036] Obtain the functional module corresponding to the test point, determine the injection functional module in the functional module, and the injection functional module is used to inject a first physical domain perturbation according to the perturbation parameter;
[0037] Based on a preset mapping relationship, a second physical domain disturbance that is associated with the first physical domain disturbance is determined, wherein the mapping relationship represents the causal relationship between different physical domain disturbances;
[0038] Based on the physical properties of the second physical domain disturbance, a collaborative observation functional module capable of measuring the second physical domain disturbance is selected from the remaining functional modules.
[0039] The disturbance parameters corresponding to the test points are analyzed to generate injection instructions corresponding to the injection function module and observation instructions corresponding to the collaborative observation function module, respectively.
[0040] By combining the injection command and the observation command, a transient test scheme is obtained.
[0041] Optionally, the step of sequentially executing the transient test scheme according to the cooperative perturbation sequence and monitoring the operating status of the tested object after executing the transient test scheme includes:
[0042] The consecutive instantaneous test schemes with the same expected associated perturbation characteristics in the cooperative perturbation sequence are divided into test scheme subsequences;
[0043] Extract the common oscilloscope trigger template applicable to the test scheme subsequence, and the injection parameter list of the instantaneous test scheme in the test scheme subsequence;
[0044] The shared oscilloscope trigger template is loaded into the digital oscilloscope to control the digital oscilloscope to generate capture conditions;
[0045] The injection function modules are driven sequentially according to the order of the injection parameter list to apply injection perturbations, and the waveform dataset is read when the capture condition is triggered;
[0046] The operating status of the object under test is determined based on the waveform dataset.
[0047] Secondly, this application provides a fault testing system based on functional modules, the system comprising:
[0048] The interface identification module is used to obtain the interface parameters of the object under test and identify multiple initial interfaces with functional coupling based on the interface parameters.
[0049] The scenario determination module is used to obtain the application scenario information of the object under test and determine several vulnerability test scenarios corresponding to the application scenario information.
[0050] A sequence generation module is used to generate a cooperative perturbation sequence containing multiple test points under the vulnerability test scenario, wherein the test points represent a set of initial interfaces and perturbation parameters of the initial interfaces;
[0051] The test plan generation module is used to obtain the functional module corresponding to the test point and generate an instantaneous test plan for the functional module according to the disturbance parameters. The instantaneous test plan indicates that the functional module will inject a cooperative disturbance into the object under test.
[0052] The test plan execution module is used to execute the instantaneous test plan sequentially according to the cooperative perturbation sequence, and monitor the running status of the test object after the instantaneous test plan is executed;
[0053] The result output module is used to combine the disturbance parameters corresponding to the test points of the current instantaneous disturbance scheme when the operating state fails, and obtain the stability critical point under the fragile test scenario.
[0054] Thirdly, this application provides a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing any of the methods described above.
[0055] Fourthly, this application provides an electronic device including a processor, a memory, and a transceiver, wherein the memory is used to store instructions, the transceiver is used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to cause the electronic device to perform any of the methods described above.
[0056] In summary, the beneficial effects of the technical solution of this application include:
[0057] By adopting the above technical solution, the collaborative disturbance sequence generation mechanism, through multi-interface coordinated control, can realistically simulate the concurrent effects of various abnormal conditions in complex environments. Each test point contains a set of initial interfaces and their disturbance parameters, forming a complete fault scenario description. The functional module, as the core carrier of test execution, achieves precise control of disturbance injection and status monitoring through an instantaneous test scheme. The process design of executing the test scheme sequentially according to the collaborative disturbance sequence ensures the systematic nature and integrity of the test. The mechanism for real-time monitoring of the operating status of the tested object can promptly capture the moment of fault occurrence. When a fault is detected, the stability critical point is determined by analyzing the combination of disturbance parameters at the current test point. Compared with the existing method of exhaustively testing fixed test items, the technical solution of this application, through standardized configuration of functional modules and automated execution of instantaneous test schemes, avoids a large number of redundant test items that are incompatible with the characteristics of the tested system, significantly shortening the test execution time. Simultaneously, the collaborative disturbance control overcomes the deficiency that fixed test items cannot fully cover the key weak links of the system, thereby improving test efficiency while ensuring fault testing accuracy. Attached Figure Description
[0058] Figure 1 This is a flowchart illustrating a fault testing method based on functional modules according to an embodiment of this application.
[0059] Figure 2 This is a schematic diagram of the structure of a fault testing system based on functional modules according to an embodiment of this application;
[0060] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0061] Explanation of reference numerals in the attached drawings: 300, electronic device; 301, processor; 302, communication bus; 303, user interface; 304, network interface; 305, memory. Detailed Implementation
[0062] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0063] In the description of the embodiments of this application, words such as "illustrative," "for example," or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "illustrative," "for example," or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of words such as "illustrative," "for example," or "for example" is intended to present the relevant concepts in a specific manner.
[0064] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0065] Please see Figure 1 This document presents a flowchart illustrating a functional module-based fault testing method according to an embodiment of this application. This method can be implemented using a computer program, a microcontroller, or run on a functional module-based fault testing system based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone utility application. The specific steps of the functional module-based fault testing method are described in detail below.
[0066] S101: Obtain the interface parameters of the object under test, and identify multiple initial interfaces with functional coupling based on the interface parameters;
[0067] The tested object refers to the electronic device or system that needs to be tested for faults. It can be a complex system with multiple functional interfaces, such as integrated circuits, embedded systems, and communication equipment. Interface parameters refer to the measurable physical quantities and electrical characteristics generated by each interface of the tested object during operation, including key performance indicators such as instantaneous power consumption, signal integrity index, shared bus communication timing, voltage and current waveforms, and frequency response. Functional coupling is used to represent the mutual influence relationship between different interfaces. When a change in the state of one interface causes a corresponding change in the parameters of another interface, there is functional coupling between the two interfaces. The initial interface refers to the set of interfaces in the tested object that have been screened and identified and have significant functional coupling relationships. These interfaces will serve as the basis for subsequent cooperative disturbance tests.
[0068] This step is typically performed during the test preparation phase. When comprehensive fault testing of complex electronic systems is required, it is first necessary to establish a correlation map between system interfaces. Specifically, this step begins by collecting real-time parameter data of each interface of the device under test (DUT) under normal operating conditions using dedicated testing equipment or a built-in monitoring module. This data needs to be continuously sampled over a sufficiently long time window to ensure data integrity and representativeness. Then, time-domain correlation analysis is performed on the collected multi-dimensional interface parameter data. The cross-correlation function between any two interface parameters is calculated to quantify the strength of their correlation. Cross-correlation calculations can identify the time delay relationship and correlation degree of fluctuations in different interface parameters. When the correlation coefficient exceeds a preset strong coupling threshold, the corresponding two interfaces are identified as having a functional coupling relationship. This data-driven coupling identification method can discover dynamic coupling relationships that are difficult to identify using traditional static analysis, providing accurate target interface combinations for subsequent collaborative testing.
[0069] S102: Obtain the application scenario information of the object under test, and determine several vulnerability test scenarios corresponding to the application scenario information;
[0070] Among them, application scenario information refers to the description of various working conditions and external environmental factors that the tested object may encounter in the actual use environment, including key factors affecting system stability such as load change patterns, ambient temperature and humidity conditions, electromagnetic interference levels, and power supply quality; functional load events represent the dynamic behaviors related to internal resource scheduling and task processing of the tested object, such as high-priority task preemption, large-scale data transmission, and concurrent execution of multiple tasks, which can lead to internal events that cause system resource competition; environmental stress events are used to represent various stress factors from the external environment of the tested object, including external disturbances that may affect the physical stability of the system, such as temperature shocks, voltage fluctuations, electromagnetic pulses, and mechanical vibrations; vulnerability test scenarios refer to specific test condition combinations that are most likely to cause system failures, derived from application scenario analysis. These scenarios are designed for the weak points of the system and can effectively expose potential stability problems.
[0071] This step is executed after identifying interface coupling relationships, aiming to transform abstract application requirements into concrete test scenario designs. Specifically, this step first collects detailed application scenario information about the object under test, including typical workload characteristics, environmental usage conditions, and performance requirements. Then, this complex application scenario information is structurally decomposed to identify functional load events and environmental stress events. For functional load events, the change in shared bus occupancy related to each initial interface before and after the event is monitored, and the increment of bus occupancy is calculated. When the increment exceeds a preset contention threshold, the relevant interface is classified into a resource contention-type interface group. For environmental stress events, the change in signal integrity indicators of each initial interface before and after the event is monitored, and the signal degradation is calculated. When the degradation exceeds a preset sensitivity threshold, the relevant interface is classified into a physical stability interface group. Finally, the test scenarios corresponding to these two types of interface groups are combined to form a complete set of vulnerability test scenarios covering different failure modes.
[0072] S103: Generate a cooperative perturbation sequence containing multiple test points in a vulnerable test scenario. Each test point represents a set of initial interfaces and perturbation parameters on the initial interfaces.
[0073] Among them, a test point refers to a test configuration unit that applies a specific combination of perturbation parameters to a set of functionally coupled interfaces under a specific vulnerability test scenario. Each test point contains a complete definition of test parameters, including the target interface set, perturbation type, perturbation intensity, and perturbation timing. Perturbation parameters are used to represent a quantitative description of various test stimuli applied to the initial interface, including key parameters such as perturbation amplitude, frequency, duration, and waveform type. These parameters determine the specific characteristics of the test stimuli. The cooperative perturbation sequence represents an ordered set of multiple test points arranged in a specific logical order. This sequence design follows a progressive test strategy from slight perturbation to strong perturbation, and can systematically explore the multi-dimensional perturbation parameter space. The main pressure interface refers to the core interface that bears the main perturbation load in the cooperative perturbation. Usually, the interface with the greatest impact on system stability is selected as the main pressure interface. The secondary pressure interface refers to the auxiliary perturbation interface that has a functional coupling relationship with the main pressure interface, and is used to simulate complex perturbation scenarios under the cooperative action of multiple interfaces.
[0074] This step, executed after identifying vulnerability testing scenarios, aims to design systematic test sequences for each vulnerability scenario to comprehensively explore the system's stability boundaries. Specifically, this step first assigns roles to the initial interfaces involved in the vulnerability testing scenarios, determining a primary stress interface and several secondary stress interfaces based on their importance and impact scope. Then, a progressive perturbation sequence generation strategy is designed: starting from a benchmark test point representing the standard perturbation level under normal system operation; keeping the perturbation parameters of the secondary stress interfaces constant, the perturbation intensity of the primary stress interface is gradually increased with a preset first increment step, generating a primary stress increasing sequence. This process continues until it approaches the primary stress interface's tolerance limit; then, starting from the test point with the highest load in the primary stress increasing sequence, keeping the primary stress interface parameters constant, the perturbation intensity of the secondary stress interfaces is gradually increased with a preset second increment step, generating a correlated stress increasing sequence. Finally, the benchmark test point, the primary stress increasing sequence, and the correlated stress increasing sequence are combined in the order of their generation to form a complete cooperative perturbation sequence.
[0075] S104: Obtain the functional module corresponding to the test point, and generate the instantaneous test plan of the functional module according to the disturbance parameters. The instantaneous test plan indicates that the control functional module will inject the coordinated disturbance into the object under test.
[0076] Among them, functional modules refer to hardware or software components with specific functions in the test system, including independent functional units such as signal generators, power supply modules, environmental controllers, and data acquisition modules that can generate or monitor specific physical quantities; injection functional modules represent functional components specifically used to apply various types of disturbances to the object under test, such as programmable power supplies for injecting voltage disturbances, signal generators for injecting electromagnetic disturbances, and temperature control devices for injecting temperature disturbances; instantaneous test schemes represent a detailed set of instructions for coordinating the work of various functional modules when executed at a specific test point, including a complete test execution scheme such as timing control of disturbance injection, parameter setting, synchronous triggering, and data acquisition; physical domain disturbances refer to the types of disturbances in a specific physical domain, such as voltage and current disturbances in the electrical domain, temperature disturbances in the thermal domain, vibration disturbances in the mechanical domain, and interference signals in the electromagnetic domain; and collaborative observation functional modules represent functional components that can measure and monitor the indirect effects of disturbances, used to capture the coupling effects between different physical domains.
[0077] This step is executed after the coordinated disturbance sequence is generated. Its purpose is to transform abstract disturbance parameters into specific test equipment control commands. Specifically, this step first analyzes the disturbance parameters defined in the test points, identifies the required disturbance type and intensity, and then selects an injection functional module from the available functional modules that can generate the corresponding disturbance. Based on the preset physical domain mapping relationship, other physical domain disturbances associated with the main disturbance are identified. This mapping relationship reflects the causal relationship between different physical domains; for example, electrical disturbances may cause thermal effects, and mechanical vibrations may affect electrical connections. Based on the characteristics of the second physical domain disturbance, a suitable coordinated observation functional module is selected from the remaining functional modules to monitor these indirect effects. Then, the disturbance parameters of the test points are analyzed in detail, transforming the abstract disturbance requirements into specific equipment control parameters, generating injection commands for the injection functional module and observation commands for the coordinated observation functional module. Finally, all commands are combined according to the correct timing relationship to form a complete instantaneous test scheme, ensuring that each functional module can coordinate and execute its respective tasks at precise time points.
[0078] S105: Execute the instantaneous test plan sequentially according to the cooperative perturbation sequence, and monitor the running status of the tested object after the instantaneous test plan is executed;
[0079] Among them, the operating status refers to the real-time working status of the object under test under disturbance, including comprehensive status information that reflects the health of the system, such as the electrical parameters of each interface, system response time, functional correctness, and stability indicators; the test scheme subsequence represents a subset formed by grouping continuous instantaneous test schemes with similar disturbance characteristics in the cooperative disturbance sequence. This grouping is beneficial for optimizing test execution efficiency and data acquisition strategies; the shared oscilloscope trigger template is used to represent a unified trigger condition setting applicable to a group of similar test schemes, which can ensure consistent data acquisition standards when executing multiple related tests; the waveform dataset refers to the time-domain waveform data of each interface of the object under test under disturbance acquired by a digital oscilloscope or other measurement equipment. This data contains detailed information about the system response; the capture condition represents the specific conditions that trigger the data acquisition device to start recording waveform data, which is usually defined based on characteristics such as signal amplitude, edge, and pulse width.
[0080] This step, executed after the transient test plan is generated, is the core execution phase of the entire testing process, requiring precise control of the test timing and real-time monitoring of the system response. Specifically, this step first intelligently groups the cooperative disturbance sequences, dividing consecutive transient test plans with the same expected associated disturbance characteristics into several test plan subsequences. This grouping strategy reduces the repetitive configuration time of test equipment and improves testing efficiency. For each test plan subsequence, a common oscilloscope trigger template and injection parameter list suitable for that subsequence are extracted. The trigger template defines a unified data acquisition standard, and the injection parameter list contains the disturbance parameters of all test plans in that subsequence. Then, the common trigger template is loaded into the digital oscilloscope, and the corresponding capture conditions, including key parameters such as trigger level, sampling rate, and record length, are configured. During test execution, the injection function modules are driven sequentially according to the order of the injection parameter list to apply the designed disturbances, while monitoring the satisfaction of the capture conditions. When the trigger conditions are met, the complete waveform dataset is immediately read. Through analysis and processing of the waveform dataset, key system response indicators are extracted to comprehensively evaluate whether the operating status of the tested object is normal.
[0081] S106: When a fault occurs in the operating state, the disturbance parameters corresponding to the test points of the current instantaneous disturbance scheme are combined to obtain the stability critical point under the fragile test scenario.
[0082] Among them, the fault state is used to represent the abnormal situation in which the tested object deviates from the normal working state, including various forms of system fault phenomena such as functional failure, performance degradation, parameter over-limit, and abnormal response; the stability critical point refers to the minimum combination of perturbation parameters that causes the tested object to change from a normal state to a fault state under a specific vulnerable test scenario. This critical point marks the boundary condition of system stability; the perturbation parameter combination represents the specific numerical combination of multiple perturbation parameters that cause system faults, including the set of key parameters such as the perturbation type, intensity, and timing of each initial interface; the instantaneous perturbation scheme refers to the test scheme currently being executed. When the system fails, the perturbation parameter combination defined in this scheme represents the specific condition that triggers the fault.
[0083] This step, triggered immediately upon detecting a system fault during test execution, is a crucial outcome phase of the entire testing process, used to accurately pinpoint the system's stability boundaries. Specifically, this step first confirms the presence of a fault in the tested object through real-time monitoring. This requires comprehensive analysis of multiple monitoring indicators, including functional correctness, performance parameters, and electrical characteristics, to make an accurate judgment. Once a fault is confirmed, all disturbance parameters defined in the currently executing transient disturbance scheme are immediately recorded, including complete information such as the disturbance type, intensity, duration, and timing relationship of the main and secondary pressure interfaces. These disturbance parameters are then categorized and organized according to their effects on different initial interfaces, forming a complete set of disturbance parameters leading to the fault. This parameter set, after verification and confirmation, is defined as the stability critical point under this vulnerability test scenario, accurately describing the system's tolerance limit under this specific scenario.
[0084] Based on the above embodiments, as an optional implementation method, the method of determining the initial interface in step S101 can be specifically implemented through the following steps S201-S203.
[0085] S201: Obtain the interface parameters of the object under test under preset operating conditions. The interface parameters include at least the instantaneous power consumption of the interface, signal integrity indicators, and communication timing of the shared bus.
[0086] Among them, the preset operating conditions refer to the standardized working states artificially set for the tested object, including specific load conditions, environmental parameters, and operating modes. Interface instantaneous power consumption refers to the instantaneous electrical power consumed by each interface during real-time operation, obtained by measuring the voltage and current of the interface and calculating their product. Signal integrity indicators are quantitative parameters describing the quality of digital signal transmission, including key indicators such as signal rise time, fall time, overshoot, undershoot, jitter, and eye diagram opening. Shared bus communication timing refers to the time characteristics of the data transmission bus used by multiple interfaces during data exchange, including timing parameters such as bus access delay, data transmission duration, and bus occupancy. For example, when testing a multi-core processor system, the preset operating conditions are set to 80% CPU load, ambient temperature of 25°C, and standard voltage power supply; interface instantaneous power consumption is measured in real-time by connecting precision current sensors in series on the power lines of each interface; signal integrity indicators are obtained by capturing interface signal waveforms and analyzing their quality parameters using a high-speed oscilloscope; and shared bus communication timing is monitored by a logic analyzer to monitor data transmission activities on the bus.
[0087] S202: Perform cross-correlation calculation on the interface parameters according to the time series to obtain the time-domain correlation coefficient of parameter fluctuations between any two interfaces;
[0088] In this context, a time series refers to a sequence of data points arranged chronologically, with each data point corresponding to a parameter measurement at a specific moment. Cross-correlation is a mathematical analysis method used to measure the similarity between two time series at different time delays. It identifies the relationship between them by calculating the correlation between one series and another at various time offsets. Parameter fluctuation refers to the magnitude and pattern of change of interface parameters relative to their average value. The time-domain correlation coefficient, the result of cross-correlation, represents the strength of the linear correlation between the fluctuations of two interface parameters in the time domain. Its value ranges from -1 to +1, with a larger absolute value indicating a stronger correlation. For example, for the power consumption time series of two CPU cores, cross-correlation identifies that when the power consumption peak of core A occurs, the power consumption of core B also reaches a corresponding peak 50 microseconds later. The calculated time-domain correlation coefficient is 0.78, indicating a strong functional coupling relationship between the two cores.
[0089] The execution of this step first preprocesses the acquired raw interface parameter data, including removing DC components, filtering high-frequency noise, and resampling the data to ensure that each parameter sequence has the same sampling rate. The specific implementation of the cross-correlation operation uses the Fast Fourier Transform algorithm to improve computational efficiency. For two time series x(t) and y(t) of length N, their Fourier transforms X(f) and Y(f) are first calculated, then the cross-power spectral density S_xy(f) = X(f) × Y*(f) is calculated, where Y*(f) is the conjugate complex number of Y(f). Finally, the cross-correlation function R_xy(τ) = IFFT[S_xy(f)] is obtained through the inverse Fourier transform, where τ represents the time delay. The time-domain correlation coefficient is calculated by normalizing the cross-correlation function. To obtain a statistically significant correlation coefficient, a sliding window method is used in the calculation process. The entire time series is divided into multiple overlapping time windows, and the cross-correlation coefficient is calculated in each window. Then, the average and standard deviation of all window results are taken. The final time-domain correlation coefficient is the maximum absolute value, which is used as a quantitative indicator of the correlation strength between the two interfaces. For a test object containing n interfaces, the time-domain correlation coefficients of n(n-1) / 2 pairs of interface combinations need to be calculated to form a complete interface correlation matrix.
[0090] S203: When the time domain correlation coefficient exceeds the preset strong coupling threshold, the two interfaces corresponding to the time domain correlation coefficient are determined as the initial interfaces with functional coupling.
[0091] The preset strong coupling threshold is a pre-defined criterion based on system characteristics and testing requirements, used to distinguish between strong and weak coupling relationships between interfaces. Strong coupling indicates a significant mutual influence between two interfaces; a change in the state of one interface will significantly affect the working state of the other. Functional coupling refers to the association between interfaces based on functional logic, distinct from coupling caused by physical connections. Initial interfaces refer to the set of interfaces identified through coupling relationship screening that require collaborative testing. For example, in a graphics processing system, the time-domain correlation coefficient between the GPU core interface and the video memory interface is calculated to be 0.85, exceeding the preset strong coupling threshold of 0.7. Therefore, these two interfaces are identified as initial interfaces with functional coupling, and they will serve as the target objects for subsequent collaborative perturbation tests.
[0092] This step employs a combination of threshold comparison and cluster analysis. First, a mechanism for determining the strong coupling threshold is established. By analyzing interface association data from a large number of similar systems, a suitable threshold range is determined using statistical methods, typically set between 0.6 and 0.8. The specific value is adjusted based on the system's complexity and testing accuracy requirements. For each pair of interfaces, the calculated temporal correlation coefficient is compared with the preset strong coupling threshold. When the absolute value of the correlation coefficient exceeds the threshold, the corresponding two interfaces are marked as having a strong coupling relationship. To avoid misjudgments caused by accidental high correlation, a statistical significance test is introduced, calculating the confidence interval of the correlation coefficient. Only interface pairs that significantly exceed the threshold at a 95% confidence level are confirmed as strongly coupled. Interface clustering analysis uses graph theory, treating all interfaces as nodes in a graph and strong coupling relationships as edges. A community detection algorithm identifies tightly connected interface groups, with each group forming a functionally coupled set. The final initial interface determination uses a comprehensive scoring mechanism, considering factors such as coupling strength, number of couplings, and system importance. A comprehensive coupling score is calculated for each interface, and the interfaces with the highest scores are selected as the initial interfaces. To verify the correctness of the initial interface selection, a cross-validation method was used to repeatedly perform interface parameter collection and correlation analysis at different time periods to ensure the stability and reproducibility of the identified strong coupling relationships.
[0093] Based on the above embodiments, as an optional implementation method, the method of determining the vulnerability test scenario in step S102 can be specifically implemented through the following steps S301-S307.
[0094] S301: Obtain the application scenario information of the object under test, and decompose the application scenario information into at least one functional load event and at least one environmental stress event, wherein the functional load event represents the internal resource scheduling behavior of the object under test, and the environmental stress event represents the change in the environment in which the object under test is located.
[0095] Application scenario information is a comprehensive data set describing the various working conditions and external factors faced by the tested object in its actual use environment. Functional load events refer to the resource scheduling and allocation behavior generated by the tested object due to task processing needs, including internal activities such as CPU scheduling, memory allocation, I / O operations, and network communication. Environmental stress events refer to various physical or electrical changes from the external environment of the tested object, including external factors such as temperature changes, humidity fluctuations, voltage instability, electromagnetic interference, and vibration shock. Internal resource scheduling behavior refers to the process by which the system allocates and manages computing, storage, and communication resources to complete specific tasks. For example, when testing an in-vehicle infotainment system, application scenario information includes usage needs such as navigation calculation, audio playback, and Bluetooth communication, as well as environmental conditions such as vehicle start-stop, temperature changes, and electromagnetic interference; functional load events include high CPU usage caused by GPS data processing, DSP resource contention caused by audio decoding, and storage bus congestion caused by multimedia file reading; environmental stress events include voltage drops during engine start-up, high-temperature environments in summer, and GPS signal interruption when passing through tunnels.
[0096] This step employs a structured information collection and classification approach. First, it comprehensively collects application scenario information of the tested object through user surveys, product specification analysis, and historical usage data mining, establishing a complete information database encompassing dimensions such as usage patterns, load characteristics, environmental conditions, and performance requirements. The decomposition of application scenario information utilizes an event-driven analysis framework, identifying key events within the scenario through time-series analysis and classifying complex application scenarios according to event trigger sources. The identification of functional load events is achieved by monitoring the internal activities of the tested object. System monitoring tools are used to collect time-series data of internal resource indicators such as CPU utilization, memory usage, disk I / O, and network traffic. Peak detection and rate of change analysis identify abrupt changes in resource usage; the activities corresponding to these moments are defined as functional load events. The identification of environmental stress events is achieved through an external sensor network. Temperature and humidity sensors, vibration sensors, power quality analyzers, and electromagnetic field strength meters are deployed to monitor environmental parameters. When environmental parameters exceed normal ranges or undergo abrupt changes, the corresponding time period is marked as an environmental stress event. The specific implementation of event decomposition adopts a combination of sliding window and threshold detection. By setting an appropriate time window size and change threshold, the collected data is analyzed in real time, and the start time, duration and intensity level of various events are automatically identified and marked, ultimately forming a structured event sequence database.
[0097] S302: Monitor the shared bus occupancy rate associated with each initial interface before and after the functional load event, and calculate the increase in shared bus occupancy rate caused by the execution of the functional load event.
[0098] In this context, a shared bus refers to a data transmission channel shared by multiple interfaces or functional modules, such as the system bus, memory bus, and I / O bus. Bus occupancy rate refers to the percentage of time the bus is actually used relative to the total available time within a specific time period. Occupancy increment refers to the increase in bus occupancy rate after a functional load event is executed, relative to the occupancy rate before execution. Monitoring refers to the process of observing and collecting data on bus activity in real time using dedicated equipment or software tools. For example, when testing a multi-core processor system, during a functional load event involving large data processing, a logic analyzer monitored that the system bus occupancy rate increased from the normal 30% to 85%, with a calculated occupancy increment of 55%; simultaneously, the memory bus occupancy rate increased from 20% to 70%, with an occupancy increment of 50%; while the I / O bus occupancy rate remained essentially unchanged, with an occupancy increment close to 0%.
[0099] This step employs high-precision bus monitoring and data analysis methods. First, a baseline measurement is established before the functional load event. A logic analyzer, bus protocol analyzer, or embedded performance counter is used to continuously monitor each shared bus, recording the baseline bus occupancy rate under stable operating conditions. Bus occupancy rate measurement is achieved through hardware monitoring. Monitoring probes are connected to the data and control lines of the target bus, and appropriate sampling depths and trigger conditions are configured to capture all transmission activities on the bus in real time. Occupancy rate calculation uses a time window statistical method, calculating the percentage of time the bus is in transmission within a preset time window. The formula is: Occupancy Rate = (Transmission Time / Total Time) × 100%. To ensure measurement accuracy, the time window selection needs to balance measurement accuracy and response speed, typically set to the millisecond to second level. During the functional load event, the occupancy rate changes of each bus continue to be monitored, using the same measurement method and calculation formula to obtain bus occupancy rate data during the event execution. The occupancy increment is calculated using a difference analysis method, specifically: Occupancy Increment = Average Occupancy Rate During Event Execution - Average Occupancy Rate Before Event Execution. To eliminate the impact of random fluctuations, the average occupancy rate is obtained through statistical calculation using data from multiple measurement periods. The data processing also includes outlier detection and filtering to remove abnormal data points caused by measurement noise or accidental interference, ensuring the accuracy and reliability of the occupancy increment calculation results.
[0100] S303: Initial interfaces whose occupancy increment exceeds a preset contention threshold are identified as resource contention-type interface groups;
[0101] The preset contention threshold is a pre-set judgment standard based on system characteristics and performance requirements, used to identify whether significant resource contention exists. A resource-contention-type interface group refers to a set of interfaces that generate significant bus occupancy increases under functional load events. These interfaces compete for shared bus resources under high load. Resource contention refers to the conflict arising from multiple interfaces or functional modules simultaneously requesting the use of limited shared resources. An interface group is a set of interfaces with similar resource contention characteristics. For example, in a graphics workstation system, when performing a 3D rendering task, the GPU interface's bus occupancy increase is 60%, the video memory interface's is 45%, and the audio interface's is 5%. If the preset contention threshold is 30%, the GPU interface and video memory interface are classified as a resource-contention-type interface group, while the audio interface is not included in this group because its occupancy increase is below the threshold.
[0102] This step employs a combination of threshold comparison and cluster analysis for identification. First, a scientific mechanism for determining the contention threshold is established. By analyzing factors such as system bus bandwidth, number of interfaces, and typical load patterns, combined with system performance requirements and stability indicators, a suitable contention threshold is determined using statistical analysis methods. The threshold is typically set based on the statistical distribution of bus occupancy under normal operating conditions, set as the average occupancy rate plus 1-2 times the standard deviation, ensuring the identification of statistically significant increments. Interface classification is implemented using a one-by-one comparison method. The occupancy increment corresponding to each initial interface is numerically compared with the preset contention threshold. When the occupancy increment exceeds the threshold, the interface is marked as a resource contention-sensitive interface. To improve classification accuracy, a multi-dimensional evaluation mechanism is introduced. In addition to considering the absolute value of the occupancy increment, the duration, rate of change, and peak characteristics of the occupancy increment are also analyzed. The formation of resource contention-type interface groups uses a similarity clustering method. By calculating the similarity of occupancy increment patterns between interfaces, interfaces with similar resource contention behaviors are grouped together. Similarity calculation uses mathematical methods such as Euclidean distance or cosine similarity, based on the time-series characteristics of the occupancy increment for quantitative comparison. The final determination of the interface group also considers the functional relevance and physical connection relationship of the interfaces to ensure that the interfaces in the same group have reasonable functional logic relationships and avoid incorrectly classifying functionally unrelated interfaces into the same group.
[0103] S304: Monitor the signal integrity indices associated with each initial interface before and after an environmental stress event; and calculate the signal degradation of the signal integrity indices caused by the environmental stress event.
[0104] Signal integrity metrics are a set of quantitative parameters describing the quality of digital signal transmission, including key indicators such as rise time, fall time, overshoot, undershoot, jitter, and eye diagram parameters. Signal degradation refers to the degree of deterioration of signal integrity metrics relative to normal conditions under environmental stress events. Monitoring under environmental stress events refers to real-time observation and measurement of signal quality during periods influenced by external environmental factors. Correlation refers to the correspondence between the initial interface and specific signal integrity metrics. For example, when testing a communication device, if an environmental stress event occurs (e.g., ambient temperature rises from 25°C to 70°C), the rise time of the high-speed serial interface increases from 0.2ns to 0.35ns, resulting in a signal degradation of 0.15ns; the eye diagram height decreases from 800mV to 650mV, resulting in a signal degradation of 150mV; and the jitter increases from 10ps to 25ps, resulting in a signal degradation of 15ps.
[0105] This step employs high-precision signal quality monitoring and quantitative analysis methods. First, a baseline measurement of signal integrity is established before the environmental stress event occurs. High-bandwidth oscilloscopes, time-domain reflectometers, and eye diagram analyzers are used to perform detailed measurements of key signals at each initial interface. Standardized testing methods are used to measure signal integrity indicators. For rise and fall times, the time required for the signal to increase from 10% to 90% amplitude is measured by capturing the complete transition waveform. For overshoot and undershoot, the maximum deviation of the signal from the target level after the transition is measured. For jitter measurement, the jitter analysis function of a time interval analyzer or oscilloscope is used to statistically analyze the random changes in signal edge times. For eye diagram parameters, the eye diagram's opening height, width, and quality factor are measured by acquiring a large number of continuous data bit sequences, superimposing them, and displaying the data. During the environmental stress event, a continuous tracking method is used to monitor signal quality in real time throughout the entire process of environmental stress application, recording the dynamic changes of various indicators. The signal degradation was calculated using a combination of difference analysis and statistical processing. The specific formula is: Signal degradation = |Index value during stress event - Baseline index value|. For multi-valued statistical indicators such as jitter, the root mean square value or peak-to-peak value was used for comparison. To ensure the reliability of the measurement results, the measurement of each indicator was repeated multiple times, the mean and standard deviation were calculated, and statistical tests were used to verify the significance of the degradation.
[0106] S305: Initial interfaces with signal degradation exceeding a preset sensitivity threshold are identified as the physical stability interface group;
[0107] The preset sensitivity threshold is a pre-set judgment standard based on signal quality requirements and system fault tolerance, used to identify interfaces sensitive to environmental stress. The physical stability interface group refers to the set of interfaces whose signal integrity indicators significantly deteriorate under environmental stress events. Sensitivity refers to the degree of response of an interface to changes in the external environment. Physical stability refers to the ability of an interface to maintain normal normal performance when the external physical environment changes. For example, in an industrial control system, when an environmental stress event such as electromagnetic interference is applied, the signal jitter degradation of the CAN bus interface is 20 ps, the eye diagram height degradation of the Ethernet interface is 100 mV, and the rise time degradation of the RS485 interface is 0.05 ns. If the preset sensitivity thresholds are set to 15 ps, 80 mV, and 0.08 ns respectively, the CAN bus interface and the Ethernet interface are classified into the physical stability interface group because their degradation exceeds the threshold.
[0108] This step employs a multi-dimensional threshold judgment and comprehensive evaluation method. First, a scientific sensitivity threshold determination mechanism is established. By analyzing factors such as interface design specifications, signal quality standards, and system fault tolerance, combined with industry standards and testing experience, appropriate sensitivity thresholds are set for different types of signal integrity indicators. A hierarchical strategy is adopted for threshold setting, with different threshold levels set according to the importance and impact of the indicators. Stricter thresholds are used for key performance indicators, while relatively lenient thresholds are used for auxiliary indicators. The specific implementation of interface classification uses a combination of item-by-item comparison and comprehensive scoring. The signal degradation of each initial interface is compared with its corresponding sensitivity threshold. When the degradation of any indicator exceeds the threshold, the interface is marked as an environmentally sensitive interface. To improve classification accuracy, a weighted scoring mechanism is used, setting weight coefficients based on the impact of different signal integrity indicators on system functionality to calculate the comprehensive sensitivity score of the interface. The formation of physical stability interface groups uses a hierarchical clustering method. Initial grouping is performed based on the interface's signal type, operating frequency, and electrical characteristics. Then, within each initial group, further classification is carried out based on sensitivity characteristics. The clustering process considers the physical proximity and functional relevance between interfaces to ensure that interfaces within the same group have similar environmental sensitivity characteristics and coping strategies. The final interface group validation employs cross-validation, repeatedly executing tests under different environmental stress conditions to confirm the stability and consistency of the interface groups.
[0109] S306: Determine the resource contention vulnerability test scenarios corresponding to the resource contention interface group and the physical stability vulnerability test scenarios corresponding to the physical stability interface group;
[0110] Among them, the resource contention-type vulnerability test scenario is a test scenario specifically designed for resource contention-type interface groups, simulating the extreme conditions of multiple interfaces competing for shared resources under high load. The physical stability vulnerability test scenario is a test scenario specifically designed for physical stability interface groups, simulating the extreme situation of interface signal quality degradation under harsh environmental conditions. A vulnerability test scenario refers to a specific combination of test conditions that can expose the system's weaknesses to the greatest extent. The correspondence refers to the mapping relationship between the interface group and its applicable test scenario. For example, for a resource contention-type interface group that includes GPU interfaces and video memory interfaces, the designed resource contention-type vulnerability test scenario includes simultaneously executing 4K video decoding, 3D rendering, and AI computing tasks, making the bus utilization rate reach more than 95%; for a physical stability interface group that includes high-speed serial interfaces, the designed physical stability vulnerability test scenario includes signal transmission testing under a composite environmental condition of -40°C to +85°C temperature cycling, 5G electromagnetic interference, and ±10% voltage fluctuation.
[0111] This step employs a design methodology combining scenario modeling and parameter optimization. First, for the design of resource-contention-based vulnerability test scenarios, a test scenario for multi-task concurrent execution is constructed by analyzing the bus usage patterns and resource demand characteristics of the resource-contention interface group. The scenario design utilizes the load superposition principle, combining the high-load operating modes of each interface in the interface group. By adjusting parameters such as task concurrency, data transmission volume, and access frequency, the shared bus occupancy is brought close to saturation. The specific implementation process includes establishing a task load model, defining the resource consumption characteristics of various computing tasks, I / O operations, and communication activities; designing a task scheduling strategy to maximize resource contention intensity by precisely controlling task start time, execution order, and priority allocation; and developing a load parameter table to quantify the numerical range and variation patterns of various test parameters. For the design of physical stability vulnerability test scenarios, extreme test conditions with multiple environmental stress factors are constructed by analyzing the environmental sensitivity characteristics of the physical stability interface group. The scenario design employs the stress amplification principle, superimposing and amplifying the impact of single environmental factors to create extreme environments exceeding normal usage conditions. Specific implementation includes establishing an environmental stress model to quantitatively define the action mechanisms of various environmental factors such as temperature, humidity, vibration, and electromagnetic interference; designing stress application sequences to determine the application order, duration, and intensity change patterns of various environmental stresses; and developing environmental parameter tables to precisely specify the numerical range and control precision of each environmental parameter.
[0112] S307: Combine resource contention-based vulnerability test scenarios with physical stability vulnerability test scenarios to obtain several vulnerability test scenarios corresponding to application scenario information.
[0113] Combination refers to the process of fusing and integrating different types of vulnerability test scenarios according to specific rules. A vulnerability test scenario set is a complete test scenario library obtained through systematic combination, covering various failure modes of the system under complex conditions. Application scenario information correspondence refers to the mapping relationship between the combined test scenarios and the original application requirements. Several represent multiple independent test scenarios generated through different combination methods. For example, combining a GPU high-load resource contention vulnerability test scenario with a high-temperature environment physical stability vulnerability test scenario generates a composite vulnerability test scenario that simultaneously performs intensive computing tasks at an ambient temperature of 45°C; combining a multi-core concurrent resource contention scenario with an electromagnetic interference physical stability scenario generates a composite scenario that performs multi-task parallel processing in a strong electromagnetic environment; through different combination methods, a complete vulnerability test scenario set covering single stress, dual stress, and multiple stresses is ultimately obtained.
[0114] This step employs a systematic approach to scenario combination and optimization. First, a mathematical model for scenario combination is established, modeling resource-competitive vulnerability test scenarios and physical stability vulnerability test scenarios as multi-dimensional parameter vectors. Vector operations are then used to mathematically combine the scenarios. The combination strategy employs a hierarchical approach, including single-factor scenarios, two-factor scenarios, and multi-factor scenarios. Single-factor scenarios retain the original resource-competitive or physical stability vulnerability test scenario as a benchmark test scenario. Two-factor scenarios combine a resource-competitive scenario with a physical stability scenario, generating composite stress conditions through parameter superposition or interaction. Multi-factor scenarios combine multiple vulnerability scenarios of different types to create more complex test environments. The specific combination process uses a parameter space mapping method, establishing a unified coordinate system for resource competition parameters and environmental stress parameters. Coordinate transformation and parameter interpolation are used to achieve smooth combinations of different scenarios. The effectiveness of the combination is verified using a combination of simulation prediction and experimental verification. A system simulation model is used to predict the feasibility and test effects of the combined scenarios, eliminating combination schemes with parameter conflicts or physical impracticality. The final set of vulnerability test scenarios is optimized using coverage analysis. By calculating the coverage of each scenario to the fault mode space, the combination of scenarios with the highest coverage and lowest redundancy is selected as the final set of test scenarios, ensuring the maximum fault discovery efficiency within a limited test time.
[0115] Based on the above embodiments, as an optional implementation method, the method of determining the resource competition vulnerability test scenario and the physical stability vulnerability test scenario in step S307 specifically includes steps S401-S404.
[0116] S401: Select at least one master interface and at least one slave interface from the resource contention interface group, and define the master task operation corresponding to the master interface and the slave task operation corresponding to the slave interface respectively;
[0117] In a resource-contention-based interface group, the primary interface bears the main load and resource consumption. Typically, the interface with the greatest impact on system performance is selected as the primary interface. Secondary interfaces are auxiliary interfaces that compete for resources with the primary interface and generate shared loads when the primary interface is working. Primary tasks are high-intensity tasks designed for the primary interface, generating significant resource consumption and performance pressure. Secondary tasks are auxiliary tasks designed for secondary interfaces, intensifying resource contention when executed in conjunction with primary tasks. A resource-contention-based interface group refers to a set of interfaces that compete for shared resources under high load conditions. For example, in a multimedia processing system, the GPU interface is selected as the primary interface from the resource-contention-based interface group {GPU interface, video memory interface, display interface, audio interface}, while the video memory interface and audio interface are selected as secondary interfaces. The primary task of the GPU interface is defined as performing real-time H.265 encoding of 4K video, which requires significant parallel computing resources and high-bandwidth memory access. The secondary task of the video memory interface is defined as simultaneously loading and caching large amounts of texture data, and the secondary task of the audio interface is defined as performing real-time mixing of multi-channel audio.
[0118] This step employs a load characteristic analysis and hierarchical selection approach. First, load characteristic analysis is performed on all interfaces in the resource-contention-driven interface group. This involves monitoring the resource consumption patterns of each interface under typical operating scenarios, including key indicators such as bus occupancy, power consumption changes, and response time, to establish an interface load characteristic database. The selection of the master interface utilizes a multi-dimensional evaluation mechanism, comprehensively considering factors such as resource consumption intensity, system impact range, and fault sensitivity. The overall load weight of each interface is calculated, and the interface with the highest weight is selected as the master interface. The selection of slave interfaces is based on the intensity of resource contention with the master interface. By analyzing the degree of conflict between each interface and the master interface in the use of shared resources, a correlation analysis method is used to calculate the contention intensity coefficient. Interfaces with coefficients exceeding a preset threshold are selected as slave interfaces. The definition of the master task operation adopts the principle of extreme load design. The technical specifications and performance boundaries of the master interface are analyzed, and a task is designed that enables the interface to reach its maximum load state. Task parameters include data processing volume, computational complexity, and access frequency. The optimal task configuration is determined through iterative optimization. Based on the definition of task operations, a collaborative pressure design method is adopted to analyze the resource contention mode between the main interface and the auxiliary interface. An auxiliary task that can generate the greatest interference effect during the execution of the main task is designed. The task design needs to precisely control parameters such as execution timing, resource requirements, and duration to ensure that an effective resource contention relationship is formed with the main task.
[0119] S402: Generate a timing phase offset sequence of the slave task operation relative to the master task operation, and combine the master task operation, slave task operation, and timing phase offset sequence into a resource contention-based vulnerability test scenario;
[0120] Timing phase offset refers to the time difference between the start time of a slave task operation and the start time of the master task operation, used to control the execution timing relationship between the two tasks. A timing phase offset sequence is a series of time offset values arranged according to a specific pattern, used to systematically explore the resource contention effects under different timing relationships. A resource contention-based vulnerability test scenario refers to a test environment that creates maximum resource contention pressure by precisely controlling the timing relationship between the master and slave tasks. Combination refers to the process of integrating task operations and timing control parameters according to a specific structure. For example, if the master task operation is GPU performing 3D rendering for 100ms, and the slave task operation is memory controller performing large data transfer for 80ms, the generated timing phase offset sequence is {0ms, 10ms, 20ms, 30ms, 40ms, 50ms}, representing the different times the slave task starts execution after the master task starts. The resource contention-based vulnerability test scenario obtained through combination includes complete elements such as master task definition, slave task definition, timing control sequence, and resource monitoring scheme.
[0121] This step employs a systematic timing design and scenario construction approach. First, it analyzes the execution characteristics of the main and secondary tasks, including timing parameters such as task start delay, execution duration, peak resource demand, and cleanup time, to establish a task timing model. The generation of the timing phase offset sequence uses a comprehensive sampling strategy. Based on the execution cycle of the main task and the duration of the secondary task, the theoretically optimal offset interval is calculated. Within this interval, offset value sequences are generated at equal or logarithmic intervals to ensure coverage of all key timing relationships. The calculation of offset values considers the internal stage characteristics of the task, decomposing the main task's execution process into stages such as initialization, main calculation, and data output. Corresponding offset values are designed for each stage, allowing secondary tasks to intervene at different execution stages of the main task, generating different types of resource competition. Sequence optimization uses genetic algorithms or simulated annealing algorithms, with the objective function of maximizing resource competition intensity. Under the conditions of satisfying hardware and timing constraints, the optimal combination of offset values is searched. The specific implementation of scenario combinations uses a structured modeling method, establishing a scenario description model that includes elements such as task definition, timing control, resource configuration, and monitoring schemes. Each test scenario corresponds to a complete set of parameter configurations. The scenario verification adopts a step-by-step verification strategy. First, the rationality of the timing design is verified through theoretical analysis. Then, the feasibility of the scenario is verified through simulation testing. Finally, actual verification is carried out on the target hardware platform to confirm that the scenario can produce the expected resource competition effect.
[0122] S403: Identify logical state transition events in the interface communication protocol within the physical stability interface group, and determine the synchronization reference for the disturbance injection corresponding to the logical state transition event;
[0123] Logical state transition events refer to critical moments in the interface communication protocol where the control logic changes from one stable state to another, such as changes in handshake signals, the start and end of data transmission, and error detection and recovery. Interface communication protocols are standardized specifications that define the data transmission and control signal interaction of interfaces, such as SPI, I2C, PCIe, and Ethernet protocols. Synchronization references are time reference points used to precisely control the timing of disturbance injection, ensuring that disturbances are applied to the system at the most sensitive moments. Disturbance injection refers to the process of applying artificial interference signals to an interface to test its anti-interference capabilities. Physically stable interface groups refer to a set of interfaces sensitive to changes in the external physical environment. For example, in an Ethernet interface, logical state transition events include frame start delimiter detection, preamble synchronization, state switching of the packet receive state machine, and activation of the collision detection signal; established synchronization references include the rising edge of the frame start signal as the reference time for voltage disturbance injection, the packet end signal as the reference time for temperature stress application, and the link renegotiation process as the reference time for electromagnetic interference injection.
[0124] This step employs a combination of protocol analysis and event extraction. First, it involves in-depth analysis of the communication protocols of each interface in the physical stability interface group, establishing a protocol state machine model and detailing the various states, transition conditions, and triggering events. Protocol analysis uses a layered parsing approach, analyzing the protocol's working mechanism from different layers such as the physical layer, data link layer, and transport layer, identifying key control nodes and state transition moments in each layer. Logical state transition event identification utilizes automated protocol monitoring, employing a protocol analyzer or logic analyzer to monitor interface communication activity in real time, automatically identifying the occurrence time and characteristic parameters of state transition events through hardware triggering or software parsing. Event classification uses a hierarchical classification system, categorizing state transition events into critical, important, and general events based on factors such as importance, frequency, and impact scope, prioritizing critical and important events as candidates for synchronization benchmarks. Finally, the determination of the synchronization benchmark employs sensitivity analysis, evaluating the sensitivity of different state transition moments to disturbances through theoretical analysis and experimental testing, selecting the moment with the highest sensitivity as the synchronization benchmark.
[0125] S404: Associate the synchronization reference with the physical disturbance template that applies instantaneous offset to obtain the physical stability vulnerability test scenario corresponding to the physical stability interface group.
[0126] The physical disturbance template refers to a predefined, standardized disturbance signal pattern, containing complete parameters such as the type, amplitude, duration, and waveform characteristics of the disturbance. Instantaneous offset refers to a small time adjustment of the disturbance application time relative to the synchronization reference, used to precisely control the timing of disturbance injection. Correlation refers to the process of establishing the timing correspondence between the synchronization reference and the disturbance template. The physical stability vulnerability test scenario refers to a test environment designed for physical stability interface groups, capable of applying environmental disturbances at the most sensitive moments. The synchronization reference is the time reference point used to control the timing of disturbance injection. For example, for a high-speed serial interface, the physical disturbance template includes a voltage pulse disturbance with a 5V amplitude and a duration of 10ns, an electromagnetic pulse disturbance with a duration of -20dBm and a duration of 1μs, and a temperature shock disturbance with a duration of ±10°C and a duration of 100ms; the instantaneous offset sequence is set to {-5ns, -2ns, 0ns, +2ns, +5ns}, representing the earlier or later application of the disturbance relative to the start time of the data packet, respectively; the physical stability vulnerability test scenario obtained through correlation defines a complete test process for applying different types and intensities of disturbances at critical moments in data transmission.
[0127] This step employs a combination of template-based design and precise timing control. First, a physical disturbance template library is established. Based on the characteristics of the physical stability interface group and common environmental stress types, standardized disturbance templates covering multiple physical domains, including voltage, temperature, electromagnetic, and vibration, are designed. The template design uses parametric modeling, abstracting various physical parameters of the disturbance into configurable numerical variables, including the numerical range of the disturbance amplitude, the time range of the disturbance duration, and the shape parameters of the disturbance waveform, enabling flexible configuration and reuse of the templates. The instantaneous offset design employs a high-precision timing control strategy. Based on the timing characteristics of the interface protocol and critical moments in signal transmission, an offset value sequence covering sensitive time windows is designed, achieving nanosecond-level offset accuracy to ensure precise targeting of the most sensitive moments. The specific implementation of the correlation process uses an event-driven triggering mechanism, establishing a real-time trigger link from the synchronization reference signal to the disturbance device. Precise timing correlation between the synchronization reference and the applied disturbance is achieved through hardware trigger signals or high-speed communication interfaces. The correlation algorithm employs time compensation and delay calibration methods to measure and compensate for various delay factors in the triggering link, including signal transmission delay, device response delay, and control processing delay, ensuring that the actual disturbance application time precisely matches the design timing requirements. Scenario generation uses a combinatorial optimization method, automatically generating the optimal reference-template-offset combination based on factors such as the characteristics of the synchronization reference, the applicability of the disturbance template, and the coverage range of the offset values, maximizing the fault detection capability of the test scenario.
[0128] Based on the above embodiments, as an optional implementation method, the method of generating the cooperative perturbation sequence in step S103 can be specifically implemented through the following steps S501-S504.
[0129] S501: Divide a set of initial interfaces corresponding to the test points in the vulnerability test scenario to obtain a main pressure interface and at least one secondary pressure interface.
[0130] In this context, the primary stress interface (PSI) is the core interface that bears the main disturbance load in the cooperative perturbation test. Typically, the interface with the greatest impact on system stability and the highest resource consumption is selected as the PSI. Secondary stress interfaces are auxiliary interfaces that are functionally coupled with the PSI and can generate a synergistic effect when the PSI is subjected to disturbances. A vulnerability test scenario refers to a specific combination of test conditions that can expose the system's weaknesses to the greatest extent. A test point is a test configuration unit that applies a specific combination of perturbation parameters to a set of functionally coupled interfaces under a specific vulnerability test scenario. An initial set of interfaces refers to the set of interfaces identified through functional coupling analysis that have mutual influence relationships. For example, in a CPU load vulnerability test scenario for a multi-core processor system, the initial interface group includes {CPU-0 interface, CPU-1 interface, memory controller interface, cache controller interface, bus arbitrator interface}. By analyzing the load-bearing capacity and system impact range of each interface, the CPU-0 interface is selected as the PSI because it bears the heaviest computational load and directly affects the overall system performance; the CPU-1 interface and the memory controller interface are selected as secondary stress interfaces because they directly compete with the CPU-0 interface for resource usage.
[0131] This step employs an interface classification method based on load analysis and impact assessment. First, a comprehensive feature analysis is performed on all initial interfaces involved in the vulnerability testing scenario, establishing an interface feature database encompassing multiple dimensions such as interface load capacity, resource consumption patterns, fault impact range, and recovery time. The selection of the primary stress interface utilizes a multi-index weighted scoring mechanism. A scoring system is designed, including evaluation indicators such as disturbance tolerance, system impact weight, resource consumption intensity, and fault propagation range. Appropriate weight coefficients are assigned to each indicator, and the comprehensive score for each interface is calculated. Disturbance tolerance is calculated by analyzing the interface's technical specifications and design margins; system impact weight is determined through fault mode analysis and dependency graphs; and resource consumption intensity is obtained through statistical analysis of historical monitoring data. The score calculation uses a linear weighted summation method, with the formula: Comprehensive Score = Σ(Indicator Value × Weight Coefficient). The interface with the highest score is selected as the primary stress interface. The selection of secondary stress interfaces is based on their coupling strength with the primary stress interface. The coupling strength coefficient is calculated by analyzing the degree of coupling between each interface and the primary stress interface in terms of shared resource usage, signal dependence, and timing correlation. The coupling strength is quantified by correlation analysis. The parameter change data of each interface under different working conditions are collected, and the correlation coefficient with the parameter change of the main pressure interface is calculated. The interface with the correlation coefficient exceeding the preset threshold is selected as the secondary pressure interface.
[0132] S502: Starting from the benchmark test point, keep the first perturbation parameter of the secondary pressure interface unchanged, and continuously increase the second perturbation parameter of the main pressure interface with a preset first increment step to generate a main pressure increment sequence with a preset first increment step.
[0133] The benchmark test point refers to the standard disturbance configuration of the system under normal operating conditions, serving as the starting reference point for generating the disturbance sequence. The first disturbance parameter refers to the disturbance intensity parameter applied to the secondary pressure interface, including disturbance amplitude, frequency, and duration. The second disturbance parameter refers to the disturbance intensity parameter applied to the primary pressure interface, controlling the intensity level of the primary disturbance. The preset first increment step size refers to the fixed value at which the primary pressure interface disturbance parameter increases each time, used to control the granularity of the disturbance intensity increment. The primary pressure increment sequence refers to the test point sequence formed by gradually increasing the primary pressure interface disturbance intensity according to a fixed step size. For example, in the test of a power management system, the benchmark test point is set to a supply voltage disturbance of ±1% for the primary pressure interface (primary power controller) and a load disturbance of 10% for the secondary pressure interface (auxiliary power controller); the first increment step size is set to 0.5%, and the generated primary pressure increment sequence is {±1.5%, ±2.0%, ±2.5%, ±3.0%, ±3.5%, ±4.0%}, with the 10% load disturbance of the secondary pressure interface remaining unchanged during the generation process.
[0134] This step employs a parameterized incremental algorithm and sequence optimization method. First, a standardized definition of the benchmark test points is established. Through parameter monitoring and statistical analysis of the system under normal operating conditions, the standard disturbance level of each interface in a stable state is determined. These values serve as the initial parameter configuration for the benchmark test points. The first incremental step size is set using a system response characteristic analysis method. Pre-experiments with small-amplitude disturbances are conducted to test the system's sensitivity, analyzing the relationship curve between system response and disturbance intensity, and selecting a step size that produces a significant but not overly drastic response change. The step size is calculated using response gradient analysis, with the formula: Optimal step size = Target response change / System response gradient. The target response change is set according to the test accuracy requirements, and the system response gradient is obtained by fitting the first derivative of the response curve. The generation of the main pressure incremental sequence uses an iterative incremental algorithm. Starting from the benchmark test point, each test point in the sequence is calculated progressively according to the formula: New disturbance parameter = Current disturbance parameter + First incremental step size. The sequence length is determined based on the interface's tolerance limit and safety boundary. The maximum allowable disturbance intensity of the main pressure interface is determined through theoretical analysis and simulation prediction, ensuring that the last test point in the sequence approaches but does not exceed the safety limit. The sequence is validated using monotonicity checks and continuity checks to ensure that the generated sequence has monotonically increasing characteristics and that the parameter changes between adjacent test points meet the preset step size requirements.
[0135] S503: Starting from the test point with the highest load in the main pressure increment sequence, keep the second perturbation parameter of the main pressure interface unchanged, and continuously increase the first perturbation parameter of the secondary pressure interface with a preset second increment step to generate an associated pressure increment sequence with a preset second increment step.
[0136] A two-parameter control strategy with a fixed main variable and incremental secondary variables is adopted. First, the test point with the highest load is identified from the main pressure increment sequence. By comparing the disturbance intensity parameters of each test point in the sequence, the test point with the largest second disturbance parameter value is selected as the starting point of the associated pressure increment sequence. Load assessment not only considers the magnitude of the disturbance parameter but also verifies that the test point indeed generates the maximum system load through system response monitoring, including the evaluation of comprehensive indicators such as resource utilization, response time, and power consumption. The setting of the second increment step size adopts a parameter analysis method that matches the characteristics of the secondary pressure interface. By studying the technical specifications, response characteristics, and withstand capabilities of the secondary pressure interface, a disturbance increment granularity suitable for this interface is designed. The step size calculation considers the synergistic effect between the secondary and main pressure interfaces, and a sensitivity analysis method is used to determine the optimal disturbance step size of the secondary pressure interface under high load conditions of the main pressure interface. The generation of the associated pressure increment sequence employs an algorithm combining parameter locking and incremental iteration. First, the second perturbation parameter of the primary pressure interface is locked as the value at the test point with the highest load. Then, starting from the first perturbation parameter of the current secondary pressure interface, each test point in the sequence is generated incrementally according to the formula: New parameter = Current parameter + Second increment step size. The sequence boundary is determined based on the safety constraints of the secondary pressure interface and the overall system stability requirements. Safety analysis ensures that the maximum perturbation of the secondary pressure interface under high load conditions of the primary pressure interface will not cause system damage. The synergistic effect verification of the sequence uses two-parameter sensitivity analysis to evaluate the impact of the combination of perturbation parameters of the primary and secondary pressure interfaces on the system response, ensuring that the generated sequence can effectively explore the system behavior boundary under multi-interface synergistic perturbations.
[0137] S504: Combine the benchmark test points, the main pressure increment sequence, and the associated pressure increment sequence in the order in which they were generated to obtain the cooperative perturbation sequence.
[0138] Employing a serialized data structure and logical sorting algorithm, a unified test point data structure is first established. A standardized data format is defined, including attributes such as test point identifier, perturbation parameter combination, execution order, and dependencies, ensuring that test points from different sources can be processed within a unified framework. The specific implementation of sequence combination uses linked list or array data structures, inserting each test point into the sequence sequentially according to the generation time order. The pseudocode for the combination algorithm is: initializing an empty sequence to inserting the baseline test point to sequentially inserting all test points of the main pressure increasing sequence to sequentially inserting all test points of the associated pressure increasing sequence to returning the complete sequence. Sequence integrity verification employs a multi-check mechanism, including test point count statistics, parameter range verification, and sequential logic checks, ensuring that the combined sequence contains all necessary test points and that the order is correct. Sequence optimization uses redundancy detection and deduplication algorithms to identify duplicate test points with identical parameters in the sequence and remove redundant points through comparison algorithms to improve testing efficiency. Sequence executability verification uses dependency analysis to check whether parameter changes between adjacent test points are within the system's tolerance range, ensuring that the sequence can execute smoothly without sudden shocks.
[0139] Based on the above embodiments, as an optional implementation method, the method of generating the instantaneous test scheme in step S104 can be specifically implemented through the following steps S601-S605.
[0140] S601: Obtain the functional module corresponding to the test point, determine the injection functional module in the functional module, and the injection functional module is used to inject the first physical domain disturbance according to the disturbance parameters.
[0141] An injection module is a functional component specifically designed to apply disturbances to the object under test, such as a programmable power supply, a signal generator, or a temperature control device. First-physical-domain disturbances refer to disturbance signals generated within a specific physical domain, such as voltage disturbances in the electrical domain or temperature disturbances in the thermal domain. For example, if the test point requires applying a ±5V voltage disturbance to the CPU interface, a programmable DC power supply would be selected as the injection module from the functional module library.
[0142] This step first establishes a functional module database, recording the disturbance type, parameter range, accuracy, and other characteristics of each module. By analyzing the disturbance requirements of the test points, a matching algorithm is used to filter modules that meet the criteria from the database. The matching process considers factors such as disturbance type compatibility, parameter range coverage, and accuracy satisfaction, calculates a matching score, and selects the module with the highest score as the injected functional module.
[0143] S602: Based on a preset mapping relationship, determine the second physical domain disturbance that is related to the first physical domain disturbance. The mapping relationship represents the causal relationship between different physical domain disturbances.
[0144] Mapping relationships refer to pre-established causal association rules between perturbations in different physical domains. A second physical domain perturbation refers to an indirect perturbation in other physical domains caused by a perturbation in the first physical domain. Causal association refers to the relationship where a change in one physical domain leads to a corresponding change in another. For example, a voltage perturbation (first physical domain) causes a temperature change (second physical domain) through the Joule heating effect, and a change in current causes a magnetic field perturbation, etc.
[0145] This step employs a pre-defined physical domain mapping matrix, where matrix elements represent the correlation strength between different physical domains. A lookup table is used to find all associated physical domains corresponding to the first physical domain perturbation from the mapping matrix, and perturbations in the second physical domain with significant correlations are selected based on a correlation strength threshold. The mapping relationships are established based on physical laws and experimental data, such as electro-thermal coupling, electro-magnetic coupling, and electromechanical coupling.
[0146] S603: Based on the physical properties of the disturbance in the second physical domain, select a collaborative observation functional module from the remaining functional modules that can measure the disturbance in the second physical domain;
[0147] The collaborative observation module refers to functional components capable of measuring and monitoring disturbances in a specific physical domain, such as temperature sensors, magnetic field probes, and vibration sensors. Physical properties refer to the characteristic parameters of the disturbance in the second physical domain, including magnitude range, frequency characteristics, and spatial distribution. Remaining functional modules refer to other available modules besides the selected injection functional modules. For example, when the disturbance in the second physical domain is a temperature change, a thermocouple sensor is selected as the collaborative observation module.
[0148] This step selects modules with corresponding measurement capabilities from the remaining functional modules based on the type and characteristics of the disturbances in the second physical domain. Selection criteria include measurement range coverage, accuracy requirements, and response time. A multi-dimensional evaluation algorithm is used to calculate a fit score for each candidate module, and the module with the highest score is selected as the collaborative observation functional module to ensure accurate capture of disturbance changes in the second physical domain.
[0149] S604: Analyze the disturbance parameters corresponding to the test point and generate the injection command corresponding to the injection function module and the observation command corresponding to the collaborative observation function module respectively.
[0150] Disturbance parameters refer to quantified parameters describing the characteristics of a disturbance, including amplitude, frequency, and duration. Injection commands are specific control commands that control the injection function module to generate a specified disturbance. Observation commands are control commands that configure the collaborative observation function module to perform data acquisition. For example, if the disturbance parameters are "5V, 1kHz, 10ms voltage pulse," the parsed result will be the power supply module's injection command "OUTPUT 5V FREQ 1000Hz DURATION 10ms."
[0151] This step employs a parameter parsing engine to transform abstract disturbance requirements into specific device control parameters. The parsing process includes parameter extraction, unit conversion, and format adaptation. Based on the control protocols and instruction formats of each functional module, the parsed parameters are encapsulated into standardized control instructions. Injected instructions contain information such as disturbance waveforms and timing control, while observation instructions contain configuration parameters such as sampling rate, trigger conditions, and data format.
[0152] S605: Combine injection and observation commands to obtain a transient test scheme.
[0153] A transient test plan refers to a complete set of instructions that controls the coordinated operation of various functional modules when executed at a specific test point. Combination refers to the process of integrating the control instructions of different functional modules according to their timing relationships. Obtaining the final test plan means generating an executable test plan through these combined operations.
[0154] This step employs a timing scheduling algorithm to arrange the injected and observed instructions according to their correct temporal relationships. The combination process considers factors such as instruction dependencies, execution priorities, and timing constraints. A directed acyclic graph (DAG) is used to represent the dependencies between instructions, and topological sorting is used to determine the execution order. Finally, a transient test plan containing complete timing information, parameter configurations, and synchronized triggers is generated to ensure that all functional modules can execute test tasks in a coordinated and consistent manner.
[0155] Based on the above embodiments, as an optional embodiment, the execution of the transient test scheme further includes the following steps:
[0156] Multiple consecutive instantaneous test schemes with the same expected associated perturbation characteristics in the cooperative perturbation sequence are divided into test scheme subsequences; a common oscilloscope trigger template suitable for the test scheme subsequences and an injection parameter list for the instantaneous test schemes in the test scheme subsequences are extracted; the common oscilloscope trigger template is loaded into the digital oscilloscope, and the digital oscilloscope is controlled to generate capture conditions; the injection function module is driven sequentially according to the order of the injection parameter list to apply the injected perturbation, and the waveform dataset is read when the capture conditions are triggered; the operating state of the object under test is determined based on the waveform dataset.
[0157] Among them, the expected associated disturbance characteristics refer to the type and intensity characteristics of secondary physical domain disturbances caused by the main disturbance in the test scheme, such as the temperature change characteristics caused by voltage disturbances. A transient test scheme refers to a complete set of instructions that controls the coordinated operation of various functional modules when executed at a specific test point. A test scheme subsequence refers to a grouping of consecutive test schemes with similar disturbance characteristics. A shared oscilloscope trigger template refers to a unified trigger condition setting applicable to a group of similar test schemes, including configuration parameters such as trigger source, trigger level, and trigger edge. An injection parameter list refers to an ordered set of disturbance injection parameters for all transient test schemes in the test scheme subsequence. A digital oscilloscope refers to a digital measurement device used to acquire and display electrical signal waveforms. A digital oscilloscope refers to an algorithm module that digitally processes the acquired signal to remove noise and interference. Acquisition conditions refer to the specific condition settings that trigger the oscilloscope to begin data acquisition. An injection function module refers to a functional component specifically used to apply disturbances to the object under test. A waveform dataset is a collection of time-domain signal data acquired by an oscilloscope. Operating status refers to the working state and performance of the object under test under the influence of disturbances. For example, the cooperative perturbation sequence contains 12 instantaneous test schemes. The expected associated perturbations for the first four schemes are a temperature increase of 2-3°C, the middle five schemes are an increase in electromagnetic field strength of 10-15 dBμV, and the last three schemes are an increase in mechanical vibration of 0.5-1.0g. Therefore, the sequence is divided into three test scheme subsequences. The common trigger template for the first subsequence is set to be triggered by the rising edge of the temperature sensor output, and the injection parameter list includes {3V-1ms pulse, 3.5V-1.2ms pulse, 4V-1.5ms pulse, 4.5V-1.8ms pulse}.
[0158] The process employs a comprehensive approach combining feature clustering and automated test execution. First, the cooperative perturbation sequences are intelligently grouped. By extracting the expected associated perturbation feature vector for each instantaneous test scheme, a similarity calculation algorithm is used to perform feature matching on consecutive test schemes. A sliding window and threshold judgment method are used to group consecutive schemes with the same or similar features into the same subsequence. After subsequence division, parameters are extracted for each subsequence. By analyzing the triggering requirements of all test schemes within a subsequence, a unified oscilloscope trigger template is derived. This template includes key parameters such as trigger source selection, trigger level setting, trigger edge type, and pre-trigger time. Simultaneously, the injection parameters for all instantaneous test schemes are extracted and compiled into a parameter list according to the execution order. During the test execution phase, the shared trigger template is first loaded into the digital oscilloscope, and the corresponding digital oscilloscope parameters are configured to generate precise capture conditions. Then, the injection function modules are driven sequentially according to the injection parameter list to apply perturbations. Each time a perturbation is applied, the oscilloscope automatically monitors the satisfaction of the capture conditions. When the conditions are triggered, waveform data acquisition immediately begins, obtaining a complete waveform dataset.
[0159] The following are system embodiments of this application, which can be used to execute the method embodiments of this application. For details not disclosed in the system embodiments of this application, please refer to the method embodiments of the application.
[0160] Please see Figure 2 This illustration shows a schematic diagram of a functional module-based fault testing system provided in an exemplary embodiment of this application. The system can be implemented as all or part of a system through software, hardware, or a combination of both. A functional module-based fault testing system includes:
[0161] The interface identification module is used to obtain the interface parameters of the object under test and identify multiple initial interfaces with functional coupling based on the interface parameters.
[0162] The scenario determination module is used to obtain the application scenario information of the object under test and determine several vulnerability test scenarios corresponding to the application scenario information.
[0163] The sequence generation module is used to generate a cooperative perturbation sequence containing multiple test points in a vulnerable testing scenario. The test point represents a set of initial interfaces and perturbation parameters on the initial interfaces.
[0164] The test plan generation module is used to obtain the functional modules corresponding to the test points and generate instantaneous test plans for the functional modules based on the disturbance parameters. The instantaneous test plan indicates that the control functional modules will inject cooperative disturbances into the test object.
[0165] The test plan execution module is used to execute instantaneous test plans sequentially according to the cooperative perturbation sequence, and monitor the running status of the test object after the instantaneous test plan is executed;
[0166] The result output module is used to combine the disturbance parameters corresponding to the test points of the current instantaneous disturbance scheme when a fault occurs in the running state, and obtain the stability critical point under the fragile test scenario.
[0167] Based on the above embodiments, as an optional embodiment, the interface identification module is also used to obtain the interface parameters of the tested object under preset operating conditions. The interface parameters include at least the instantaneous power consumption of the interface, signal integrity indicators, and communication timing of the shared bus. The interface parameters are cross-correlated according to the time series to obtain the time-domain correlation coefficient of parameter fluctuation between any two interfaces. When the time-domain correlation coefficient exceeds the preset strong coupling threshold, the two interfaces corresponding to the time-domain correlation coefficient are identified as the initial interfaces with functional coupling.
[0168] Based on the above embodiments, as an optional embodiment, the scenario determination module is further used to obtain application scenario information of the object under test, and decompose the application scenario information into at least one functional load event and at least one environmental stress event, wherein the functional load event represents the internal resource scheduling behavior of the object under test, and the environmental stress event represents the change in the environment in which the object under test is located.
[0169] The shared bus occupancy rate associated with each initial interface is monitored before and after a functional load event, and the occupancy increment caused by the functional load event is calculated. Initial interfaces with occupancy increments greater than a preset contention threshold are identified as resource-contention-type interface groups. Signal integrity indices associated with each initial interface are monitored before and after an environmental stress event, and the signal degradation of signal integrity indices caused by the environmental stress event is calculated. Initial interfaces with signal degradation greater than a preset sensitivity threshold are identified as physical stability interface groups. Resource-contention-type vulnerability test scenarios corresponding to resource-contention-type interface groups and physical stability vulnerability test scenarios corresponding to physical stability interface groups are determined. Resource-contention-type vulnerability test scenarios and physical stability vulnerability test scenarios are combined to obtain several vulnerability test scenarios corresponding to application scenario information.
[0170] Based on the above embodiments, as an optional embodiment, the scenario determination module is further configured to select at least one main interface and at least one slave interface from the resource contention interface group, define the main task operation corresponding to the main interface and the slave task operation corresponding to the slave interface respectively; generate a timing phase offset sequence of the slave task operation relative to the main task operation, and combine the main task operation, the slave task operation, and the timing phase offset sequence into a resource contention vulnerability test scenario; identify the logical state transition event in the interface communication protocol within the physical stability interface group, and determine the synchronization benchmark for the disturbance injection corresponding to the logical state transition event; associate the synchronization benchmark with the physical disturbance template for which an instantaneous offset is applied to obtain the physical stability vulnerability test scenario corresponding to the physical stability interface group.
[0171] Based on the above embodiments, as an optional embodiment, the sequence generation module is further used to divide a set of initial interfaces corresponding to the test points in the vulnerability test scenario to obtain a main pressure interface and at least one secondary pressure interface; starting from the benchmark test point, keeping the first perturbation parameter of the secondary pressure interface unchanged, the second perturbation parameter of the main pressure interface is continuously increased by a preset first increment step to generate a main pressure increment sequence with a preset first increment step; starting from the test point with the highest load in the main pressure increment sequence, keeping the second perturbation parameter of the main pressure interface unchanged, the first perturbation parameter of the secondary pressure interface is continuously increased by a preset second increment step to generate an associated pressure increment sequence with a preset second increment step; the benchmark test point, the main pressure increment sequence, and the associated pressure increment sequence are combined according to their generation order to obtain a cooperative perturbation sequence.
[0172] Based on the above embodiments, as an optional embodiment, the test scheme generation module is further configured to obtain the functional modules corresponding to the test points, determine the injection functional module among the functional modules, the injection functional module being used to inject a first physical domain disturbance according to the disturbance parameters; determine a second physical domain disturbance that is related to the first physical domain disturbance according to a preset mapping relationship, the mapping relationship representing the causal relationship between different physical domain disturbances; select a collaborative observation functional module capable of measuring the second physical domain disturbance from the remaining functional modules according to the physical properties of the second physical domain disturbance; parse the disturbance parameters corresponding to the test points, and generate injection instructions corresponding to the injection functional module and observation instructions corresponding to the collaborative observation functional module respectively; combine the injection instructions and observation instructions to obtain the instantaneous test scheme.
[0173] Based on the above embodiments, as an optional embodiment, the test scheme execution module is further configured to divide multiple consecutive instantaneous test schemes with the same expected associated disturbance characteristics in the cooperative disturbance sequence into test scheme subsequences; extract a common oscilloscope trigger template applicable to the test scheme subsequences, and an injection parameter list of the instantaneous test schemes in the test scheme subsequences; load the common oscilloscope trigger template into the digital oscilloscope, and control the digital oscilloscope to generate capture conditions; drive the injection function module to apply injection disturbances sequentially according to the order of the injection parameter list, and read the waveform dataset when the capture conditions are triggered; and determine the operating state of the object under test based on the waveform dataset.
[0174] This application also provides a computer storage medium that can store multiple instructions. The instructions are adapted to be loaded and executed by a processor as described above for the fault testing method based on functional modules. For the specific execution process, please refer to the detailed description of the embodiments, which will not be repeated here.
[0175] Please see Figure 3This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 3 As shown, the electronic device 300 may include: at least one processor 301, at least one network interface 304, user interface 303, memory 305, and at least one communication bus 302.
[0176] The communication bus 302 is used to enable communication between these components.
[0177] The user interface 303 may include a display screen and a camera.
[0178] The network interface 304 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0179] The processor 301 may include one or more processing cores. The processor 301 connects to various parts of the server using various interfaces and lines, and performs various server functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 305, and by calling data stored in the memory 305. Optionally, the processor 301 may be implemented using at least one hardware form of digital signal processing, field-programmable gate array, or programmable logic array. The processor 301 may integrate one or more of the following: a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 301 and may be implemented as a separate chip.
[0180] The memory 305 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 305 may include a non-transitory computer-readable medium. The memory 305 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 305 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), instructions for implementing the various method embodiments described above, etc.; the data storage area may store data involved in the various method embodiments described above, etc. Optionally, the memory 305 may also be at least one storage device located remotely from the aforementioned processor 301. Figure 3 As shown, the memory 305, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and an application program for a fault testing method based on functional modules.
[0181] exist Figure 3 In the electronic device 300 shown, the user interface 303 is mainly used to provide an input interface for the user and to obtain the user input data; while the processor 301 can be used to call an application program stored in the memory 305 for a fault testing method based on functional modules. When executed by one or more processors, the electronic device executes one or more methods as described in the above embodiments.
[0182] An electronic device readable storage medium stores instructions that, when executed by one or more processors, cause the electronic device to perform one or more methods as described in the above embodiments.
[0183] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0184] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0185] In the several embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings or direct couplings or communication connections may be through some service interfaces; indirect couplings or communication connections between apparatuses or units may be electrical or other forms.
[0186] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0187] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0188] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, portable hard drives, magnetic disks, or optical disks.
[0189] The above are merely exemplary embodiments of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Those skilled in the art will readily conceive of other embodiments of this disclosure upon considering the specification and the disclosure of practical truths. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure.
Claims
1. A fault testing method based on functional modules, characterized in that, The method includes: Obtain the interface parameters of the object under test, and identify multiple initial interfaces with functional coupling based on the interface parameters; Obtain the application scenario information of the object under test, and determine several vulnerability test scenarios corresponding to the application scenario information; The step of obtaining the application scenario information of the object under test and determining several vulnerability test scenarios corresponding to the application scenario information includes: The process involves acquiring application scenario information of the tested object and decomposing it into at least one functional load event and at least one environmental stress event. The functional load event represents the internal resource scheduling behavior of the tested object, and the environmental stress event represents changes in the environment in which the tested object is located. The process also involves monitoring the shared bus occupancy rate associated with each initial interface before and after the functional load event, and calculating the occupancy increment caused by the execution of the functional load event. Initial interfaces with occupancy increments greater than a preset contention threshold are identified as resource-contention-type interface groups. Furthermore, the process involves monitoring signal integrity indicators associated with each initial interface before and after the environmental stress event, and calculating the signal degradation amount of the signal integrity indicators caused by the execution of the environmental stress event. Initial interfaces with signal degradation amounts greater than a preset sensitivity threshold are identified as physical stability interface groups. Finally, the process involves determining resource-contention-type vulnerability test scenarios corresponding to the resource-contention-type interface groups and physical stability vulnerability test scenarios corresponding to the physical stability interface groups. Combining the resource-contention-type vulnerability test scenarios with the physical stability vulnerability test scenarios yields several vulnerability test scenarios corresponding to the application scenario information. Generate a cooperative perturbation sequence containing multiple test points under the vulnerability test scenario, wherein the test points represent a set of initial interfaces and perturbation parameters of the initial interfaces; Obtain the functional module corresponding to the test point, and generate an instantaneous test plan for the functional module based on the disturbance parameters. The instantaneous test plan indicates that the functional module will inject a coordinated disturbance into the object under test. The instantaneous test plan is executed sequentially according to the cooperative perturbation sequence, and the running status of the tested object is monitored after the instantaneous test plan is executed; When the operating state fails, the disturbance parameters corresponding to the test points of the current instantaneous test scheme are combined to obtain the stability critical point under the fragile test scenario.
2. The method according to claim 1, characterized in that, The process of acquiring the interface parameters of the object under test, and identifying multiple initial interfaces with functional coupling based on the interface parameters, includes: Obtain the interface parameters of the object under test under preset operating conditions. The interface parameters include at least the instantaneous power consumption of the interface, signal integrity indicators, and communication timing of the shared bus. The interface parameters are cross-correlated according to the time series to obtain the time-domain correlation coefficient of parameter fluctuations between any two interfaces; When the time-domain correlation coefficient exceeds a preset strong coupling threshold, the two interfaces corresponding to the time-domain correlation coefficient are identified as initial interfaces with functional coupling.
3. The method according to claim 1, characterized in that, The step of determining the resource contention vulnerability test scenario corresponding to the resource contention interface group and the physical stability vulnerability test scenario corresponding to the physical stability interface group includes: Select at least one main interface and at least one slave interface from the resource contention interface group, and define the main task operation corresponding to the main interface and the slave task operation corresponding to the slave interface respectively; Generate a temporal phase offset sequence of the slave task operation relative to the master task operation, and combine the master task operation, the slave task operation, and the temporal phase offset sequence into a resource contention-type vulnerability test scenario; Identify logical state transition events in the interface communication protocol within the physical stability interface group, and determine the synchronization reference for the disturbance injection corresponding to the logical state transition event; By associating the synchronization benchmark with the physical disturbance template that applies instantaneous offset, the physical stability vulnerability test scenario corresponding to the physical stability interface group is obtained.
4. The method according to claim 1, characterized in that, The generation of the cooperative perturbation sequence containing multiple test points under the vulnerability test scenario, wherein each test point represents a set of initial interfaces and perturbation parameters of the initial interfaces, including: The initial interfaces corresponding to the test points in the vulnerability test scenario are divided to obtain a main pressure interface and at least one secondary pressure interface. Starting from the benchmark test point, keeping the first perturbation parameter of the secondary pressure interface unchanged, the second perturbation parameter of the main pressure interface is continuously increased with a preset first increment step to generate a main pressure increment sequence with a preset first increment step. Starting from the test point with the highest load in the main pressure increment sequence, keeping the second perturbation parameter of the main pressure interface unchanged, the first perturbation parameter of the secondary pressure interface is continuously increased with a preset second increment step to generate an associated pressure increment sequence with a preset second increment step. The benchmark test points, the main pressure increment sequence, and the associated pressure increment sequence are combined in the order in which they are generated to obtain a cooperative perturbation sequence.
5. The method according to claim 1, characterized in that, The step of obtaining the functional module corresponding to the test point and generating an instantaneous test plan for the functional module based on the disturbance parameters, wherein the instantaneous test plan indicates that the functional module will inject a coordinated disturbance into the object under test, includes: Obtain the functional module corresponding to the test point, determine the injection functional module in the functional module, and the injection functional module is used to inject a first physical domain perturbation according to the perturbation parameter; Based on a preset mapping relationship, a second physical domain disturbance that is associated with the first physical domain disturbance is determined, wherein the mapping relationship represents the causal relationship between different physical domain disturbances; Based on the physical properties of the second physical domain disturbance, a collaborative observation functional module capable of measuring the second physical domain disturbance is selected from the remaining functional modules. The disturbance parameters corresponding to the test points are analyzed to generate injection instructions corresponding to the injection function module and observation instructions corresponding to the collaborative observation function module, respectively. By combining the injection command and the observation command, a transient test scheme is obtained.
6. The method according to claim 5, characterized in that, The step of sequentially executing the instantaneous test plan according to the cooperative perturbation sequence and monitoring the operating status of the tested object after executing the instantaneous test plan includes: The consecutive instantaneous test schemes with the same expected associated perturbation characteristics in the cooperative perturbation sequence are divided into test scheme subsequences; Extract the common oscilloscope trigger template applicable to the test scheme subsequence, and the injection parameter list of the instantaneous test scheme in the test scheme subsequence; The shared oscilloscope trigger template is loaded into the digital oscilloscope, and the digital oscilloscope is controlled to generate capture conditions; The injection function modules are driven sequentially according to the order of the injection parameter list to apply injection perturbations, and the waveform dataset is read when the capture condition is triggered; The operating status of the object under test is determined based on the waveform dataset.
7. A fault testing system based on functional modules, characterized in that, The system includes: The interface identification module is used to obtain the interface parameters of the object under test and identify multiple initial interfaces with functional coupling based on the interface parameters. The scenario determination module is used to acquire application scenario information of the object under test and determine several vulnerability test scenarios corresponding to the application scenario information. Acquiring the application scenario information of the object under test and determining the several vulnerability test scenarios corresponding to the application scenario information includes: acquiring the application scenario information of the object under test and decomposing the application scenario information into at least one functional load event and at least one environmental stress event, wherein the functional load event represents the internal resource scheduling behavior of the object under test, and the environmental stress event represents the change in the environment in which the object under test is located; monitoring the shared bus occupancy rate associated with each initial interface before and after the functional load event, and calculating the shared bus occupancy rate caused by executing the functional load event. The following steps are taken: First, the bus occupancy rate increment is measured. Second, initial interfaces whose occupancy increment exceeds a preset contention threshold are identified as resource-contention-type interface groups. Third, signal integrity indicators associated with each initial interface before and after an environmental stress event are monitored. Fourth, the signal degradation amount of the signal integrity indicators caused by the environmental stress event is calculated. Fifth, initial interfaces whose signal degradation amount exceeds a preset sensitivity threshold are identified as physical stability interface groups. Sixth, resource-contention-type vulnerability test scenarios and physical stability vulnerability test scenarios are determined. Seventh, the resource-contention-type vulnerability test scenarios and physical stability vulnerability test scenarios are combined to obtain several vulnerability test scenarios corresponding to the application scenario information. A sequence generation module is used to generate a cooperative perturbation sequence containing multiple test points under the vulnerability test scenario, wherein the test points represent a set of initial interfaces and perturbation parameters of the initial interfaces; The test plan generation module is used to obtain the functional module corresponding to the test point and generate an instantaneous test plan for the functional module according to the disturbance parameters. The instantaneous test plan indicates that the functional module will inject a cooperative disturbance into the object under test. The test plan execution module is used to execute the instantaneous test plan sequentially according to the cooperative perturbation sequence, and monitor the running status of the test object after the instantaneous test plan is executed; The result output module is used to combine the disturbance parameters corresponding to the test points of the current instantaneous test scheme when the running state fails, and obtain the stability critical point under the fragile test scenario.
8. A computer storage medium, characterized in that, The computer storage medium stores a plurality of instructions, which are adapted to be loaded by a processor and executed as described in any one of claims 1 to 6.
9. An electronic device, characterized in that, The device includes a processor, a memory, and a transceiver, wherein the memory is used to store instructions, the transceiver is used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method as described in any one of claims 1 to 6.