Airborne time-sensitive network data flow priority classification method

By employing an airborne time-sensitive network (AFDX) data flow priority classification method, combined with fault tree modeling and ARP4761 security analysis, the shortcomings of AFDX in terms of flexibility and security are addressed. This enables accurate priority allocation and risk prediction for airborne networks, thereby improving system security and design compliance.

CN121664752APending Publication Date: 2026-03-13BEIJING AERONAUTIC SCI & TECH RES INST OF COMAC +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-30
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing avionics full-duplex switched Ethernet (AFDX) is not flexible and efficient enough to meet dynamic, mixed, and high-bandwidth traffic demands, and lacks mandatory security analysis processes in the aviation industry, resulting in network scheduling strategies failing to provide direct and traceable evidence in aircraft system security assessments.

Method used

An airborne time-sensitive network (TSN) data stream priority classification method is adopted. By acquiring the metadata of the TSN message stream set, a pre-built fault tree model is used for comparison to determine the severity and severity level of message failure, and network priority is determined based on this. Combined with the ARP4761 security analysis process, accurate comparison and mapping of each message is achieved.

Benefits of technology

It improves the scientific and precise nature of network priority allocation, can identify single-point fatal failures and multi-point common-cause failures, dynamically assess the impact of failures, proactively explore dangerous synergistic effects, enhance the system's resilience and risk identification capabilities, and reduce design blind spots and certification barriers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121664752A_ABST
    Figure CN121664752A_ABST
Patent Text Reader

Abstract

The invention relates to the field of aircraft data networks, and discloses an airborne time-sensitive network data flow priority classification method, which comprises the following steps: acquiring a time-sensitive network message flow set which comprises metadata of each message; obtaining a message use device table of each message based on the metadata; determining a receiving state of each message; when the message receiving fails, inputting the failed message into a pre-constructed fault tree model for comparison; determining the severity of message failure based on the comparison result, and determining the severity level based on the severity; and determining the network priority based on the severity level and / or the number of messages reaching the corresponding severity level. According to the method, traditional independent security analysis and real-time scheduling are fused, network priority distribution is dynamically driven through the fault tree cut set, and the problem that a security analysis result is not taken into consideration in priority distribution in an existing scheduling method is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of aircraft data networks, and more specifically, to a method for prioritizing data streams in airborne time-sensitive networks. Background Technology

[0002] As aircraft evolve towards greater intelligence, networking, and integration, modern avionics systems are undergoing a profound transformation. Traditional avionics architectures employ Integrated Modular Avionics (IMA) architectures, which centralize and modularize previously dispersed computing and network resources. Through shared, high-performance universal network interconnections, this reduces the number, weight, and power consumption (SWaP) of devices, while improving resource utilization and system flexibility. Against this backdrop, Avionics Full-Duplex Switched Ethernet (AFDX), as a deterministic network based on standard Ethernet (IEEE 802.3), has been successfully applied to advanced aircraft such as the A380 and B787 over the past two decades, demonstrating the security and reliability of Ethernet technology in the aviation field.

[0003] While Avionics Full-Duplex Switched Ethernet (AFDX) achieves determinism, its statically configured Virtual Link (VL) and Bandwidth Allocation (BAG) mechanisms gradually become bottlenecks in terms of flexibility and efficiency when facing dynamic, mixed, and high-bandwidth traffic demands. This has spurred the need for Time-Sensitive Networking (TSN), a family of Ethernet extension standards developed by the IEEE 802.1 task group. Its core objective is to enable the coexistence and transmission of time-sensitive critical data flows and best-effort general data flows on the same physical network, by introducing key technologies such as time synchronization, bounded low latency, traffic scheduling, and high-reliability seamless redundancy, based on standard Ethernet.

[0004] For example, Chinese Patent Publication No. CN119155358A, entitled "A Low-Latency, High-Determinism Industrial Protocol Conversion Architecture and Algorithm," discloses a method to determine basic priorities based on the waiting time of data in the device, with shorter waiting times resulting in higher basic priorities. Secondly, it combines user-defined priorities with dynamic weighting coefficients to fuse the two types of priorities. The weighting coefficients change with user priorities: when the user priority is low, the weight decreases from high to low; when the user priority is high, the weight increases from low to high. This ultimately generates a dynamic priority for the time-sensitive network, balancing the data waiting time with the importance defined by the user, ensuring low-latency transmission of critical data while preventing long-waiting data from being ignored. However, it lacks a direct connection to the mandatory safety analysis procedures of the aviation industry (such as ARP4761), resulting in the network scheduling strategy failing to provide direct, traceable evidence in aircraft system safety assessments.

[0005] Therefore, it is necessary to design an airborne time-sensitive network data stream priority classification method to solve the problems existing in the current technology. Summary of the Invention

[0006] In view of this, the present invention proposes an airborne time-sensitive network data stream priority classification method, which aims to solve the problem of low efficiency in current aggregated payment.

[0007] This invention proposes a method for prioritizing data streams in airborne time-sensitive networks, including: Obtain a time-sensitive network message stream set, wherein the message stream set contains metadata for each message; The message usage device table for each message is obtained based on the metadata. Determine the reception status of each message; When message reception fails, the failed message is input into a pre-built fault tree model for comparison. The severity of message failure is determined based on the comparison results, and its severity level is determined based on the severity. Network priority is determined based on the severity level and / or the number of messages that reach the corresponding severity level.

[0008] Furthermore, the metadata includes at least the message name, the device that sent the message, the device that the message was sent to, and the device that the message was ultimately used by.

[0009] Furthermore, the pre-constructed fault tree model includes at least the aircraft-level minimum cut set set, the system-level minimum cut set set, the bottom event set, the minimum cut set set, the top event set, and the functional failure level set.

[0010] Furthermore, when inputting the failure message into a pre-built fault tree model for comparison, it includes: Based on each failed message, its corresponding bottom event is determined, and in the pre-built fault tree model, the bottom event is traced upwards based on the bottom event and the minimum cut set to determine its corresponding top event set; The mapping relationship between each invalid message and the bottom event is determined based on the top event set, and the comparison result is determined based on the mapping relationship.

[0011] Furthermore, when determining the severity of message invalidation based on the comparison results, this includes: Based on the set of top events, determine whether the bottom events corresponding to the message failure independently constitute a minimal cut set of the top events; When the bottom event corresponding to the message failure can form a minimal cut set of the top event on its own, the severity of the message failure is determined based on the message failure.

[0012] Furthermore, when determining the severity of message invalidation based on the comparison results, the following also applies: When the underlying event corresponding to the message failure cannot constitute a minimal cut set of the top event on its own and must be combined with a non-message failure underlying event to constitute a minimal cut set of the top event, the severity is determined based on the contribution of the message failure to the occurrence of the top event.

[0013] Furthermore, when determining the severity of message invalidation based on the comparison results, the following also applies: When the minimum cut set of the top event consists only of the combination of multiple message failures corresponding to the bottom events, its final severity is determined by reducing the severity level by one level based on the severity level of its corresponding top event.

[0014] Furthermore, when determining the severity of message invalidation based on the comparison results, the following also applies: The top events are combined to determine their system-level minimal cut set, and compared with the aircraft-level minimal cut set. When the top event corresponding to the message failure exists in the aircraft-level minimal cut set, its final severity is determined based on the severity of the top event corresponding to its combination.

[0015] Furthermore, when determining the severity level based on the severity level, the following are included: The severity levels include Level I, Level II, Level III, Level IV, and Level V; When the severity level is equivalent to personnel death or system failure, it is classified as Level I; When the severity level is serious injury to personnel, a few deaths, or serious damage to the system, it is determined to be Level II; When the severity level is minor personal injury or minor system damage, it is classified as Level III; When the severity level is less than Level III for personnel injury and system damage, it is classified as Level IV. When the severity level is deemed to have no impact on personnel or the system, it is classified as Level V.

[0016] Furthermore, when determining the network priority based on the severity level and / or the number of messages reaching the corresponding severity level, the following steps are included: When the severity of the message stream set is level I, its network priority is determined to be 7; When multiple messages in the message stream set fail and are classified as Level II, their network priority is determined to be 6. When there is only one highest failure in the message flow set and the impact of the message failure is level II, its network priority is determined to be 5; When multiple messages in the message stream set fail and are classified as Level III, their network priority is determined to be 5. When there is only one message failure in the message flow set with a failure impact level of III, its network priority is determined to be 4; When multiple messages in the message stream set fail and are classified as Level IV, their network priority is determined to be 3. When there is only one highest failure in the message flow set and the impact of the message failure is level IV, its network priority is determined to be 2; When the message failure impact in the message stream set is level V, its network priority is determined to be 0 or 1.

[0017] Compared with existing technologies, the beneficial effects of this invention are as follows: 1. By using fault tree analysis, an authoritative security engineering model, as input and criterion, the network priority obtained by each data stream is derived from a precise assessment of its degree of harm to system functionality. This means that the network is no longer a pure communication carrier independent of security considerations, but has evolved into an infrastructure that proactively implements security strategies. The urgency of transmission protection directly reflects the catastrophic or minor impact of functional failures, thereby constructing the first proactive, security-critical resource barrier at the communication link layer. This substantially extends security design principles down to the bit-level transmission process, improving the scientific, precise, and objective nature of priority allocation decisions and reducing inconsistencies and potential risks caused by subjective experience judgments.

[0018] 2. General priority classifications are often broad, such as placing all "control flows" at a high level, failing to distinguish the vast differences in the security importance of different data flows within the same category. This invention, through contribution quantification analysis and a combined impact judgment mechanism, achieves dynamic assessment of failure impact. It can not only distinguish between "single-point fatal failure" and "multi-point common-cause failure," but also quantify the "responsibility weight" of a message failure in various possible paths leading to system failure by calculating its participation in the minimum cut set of the fault tree. The model-derived quantitative output replaces static empirical assignment, making priority allocation no longer a rough "one-size-fits-all" division, but a precise profile reflecting the inherent vulnerability structure of the system.

[0019] 3. By comparing across fault tree models, the system proactively explores the potential dangerous synergistic effects between message failures in different subsystems. This allows for the early detection and warning of "hidden risks" that may appear individually harmless but, when combined, could lead to catastrophic consequences. These risks can then be blocked by proactively prioritizing relevant data flows in network scheduling strategies. This essentially gives the network a "visionary eye" to predict and defend against systemic risks, elevating security design from addressing "known single failures" to preventing "unknown abnormal combinations." This enhances system resilience, improves the ability to identify and mitigate hidden risks within complex systems, particularly cascading failure risks, and reduces the likelihood of being unaware of or overlooking such risks.

[0020] 4. In high-security domains, design decisions must be grounded in clear logical threads and supported by sufficient verification evidence. This invention provides a standardized input, processing, and output process. Each step of this transformation—from message to device, from device failure to event, from event contribution to impact level, and finally to priority mapping—is based on explicit models and algorithmic rules. This ensures that the final priority configuration table is not merely isolated network parameters, but a complete chain of derived requirements that can be traced back to top-level security requirements and linked to specific transmission mechanisms. This facilitates design review, security verification, and airworthiness certification processes, enabling network design to be embedded in and strongly support the entire system's security verification framework, reducing design blind spots and certification barriers caused by domain gaps. Attached Figure Description

[0021] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 A flowchart illustrating the airborne time-sensitive network data stream priority classification method provided in this embodiment of the invention; Figure 2 Functional failure level diagram of the airborne time-sensitive network data stream priority classification method provided in the embodiments of the present invention. Detailed Implementation

[0022] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the disclosure to those skilled in the art. It should be noted that, unless otherwise specified, embodiments and features in the embodiments of the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0023] In some embodiments of this application, see Figure 1 As shown, an airborne time-sensitive network data stream priority classification method includes: Retrieve a collection of time-sensitive network message streams, which contains metadata for each message.

[0024] The device table is used to retrieve each message based on its metadata.

[0025] Determine the reception status of each message.

[0026] When message reception fails, the failed message is input into a pre-built fault tree model for comparison.

[0027] The severity of message failure is determined based on the comparison results, and its severity level is determined based on the severity.

[0028] Network priority is determined based on severity level and / or the number of messages that reach the corresponding severity level.

[0029] Specifically, Time-Sensitive Networking (TSN) is a network technology that supports high real-time communication. Developed on the basis of standard Ethernet, it aims to provide deterministic services for network communication through a series of technical standards and mechanisms, ensuring reliable data transmission within a specified time. Currently, TSN is used in industrial automation, automotive, and other fields, with limited application as a backbone network for civil aircraft. TSN networks use the traditional Ethernet VLAN tagging (IEEE 802.1Q) to label data frames with eight priority levels (0-7). Among them: Priority 7 (highest): Used for time-sensitive critical control flows (such as motion control commands).

[0030] Priority 6-4: High priority data (such as real-time sensor signals).

[0031] Priority 3-1: Medium priority data (such as audio and video streams).

[0032] Priority 0 (lowest): Default traffic (such as normal TCP / IP data).

[0033] This application combines the original priority division of Time-Sensitive Networking (TSN) with the security analysis process and method in ARP4761. It provides an airborne TSN network priority division mechanism based on the impact of message failure in the message flow. By acquiring the TSN message flow with completed message assembly, and then determining the final user device of the message based on the destination device of the message in the TSN message flow and whether the destination device continues to forward and process it, the final user device of the message is obtained, resulting in a message final user device table. This allows it to determine whether each message is received and processed by the corresponding device. When the corresponding device is normal, no further steps are performed. However, when message reception fails, the failed message is input into the system fault tree model for data comparison. That is, each message failure is classified into the bottom event of the system fault tree, and the mapping between message failure and bottom event is determined. Finally, the severity of message failure is determined based on the mapping result, and corresponding severity levels are divided based on the severity level. The severity level corresponds to different network priorities.

[0034] It is understandable that the prioritization of general time-sensitive networks is mainly based on the real-time requirements of data streams, such as control commands, sensor signals, and audio / video streams. However, in high-safety environments such as airborne systems, simply considering "speed" is far from sufficient; it is more crucial to distinguish between "criticality," that is, the different functional hazards caused by different data failures. This invention introduces the ARP4761 security analysis process to accurately compare and map the reception failure event of each network message with the base events in a pre-built fault tree model. This means that the network priority ultimately obtained by a data stream is not solely defined by its transmission cycle or jitter tolerance, but rather by the functional safety criticality of the information it carries. For example, even among periodic real-time messages, control commands that concern flight safety and cabin adjustment signals that only affect comfort will be automatically distinguished and given drastically different network processing treatments through this method. This transformation makes network communication resources a direct tool for implementing the system's top-level security strategy, ensuring that the order of bit transmission serves the ultimate goal of life and property safety, and building a proactive, risk-aware protective barrier from the underlying communication level.

[0035] Traditional classification-based prioritization is often too general, making it difficult to refine within the same category. Furthermore, adjustments rely on engineers' experience and judgment, lacking a consistent and transparent decision-making basis. This invention establishes a quantitative analysis chain from "message failure" to "bottom event of the fault tree" and then to "severity level of the top event," transforming priority determination into a calculable and verifiable model-driven process. It not only identifies single message failures that directly lead to serious consequences but also meticulously assesses their actual impact weight in complex fault scenarios by analyzing the combination relationships and contributions of message failures within the minimum cut set of the fault tree. This judgment method, based on a rigorous logical model and set theory analysis, produces highly objective and consistent results, avoiding decision fluctuations caused by differences in human experience. This makes the invention of network resource allocation appear as a derivation obtained through "secure computation," with its rationality and necessity supported by solid logical and documentary evidence.

[0036] In highly integrated avionics systems, communication problems within a single subsystem can couple with other factors, triggering unexpected, higher-level failures. Conventional network scheduling mechanisms view each data stream in isolation, failing to perceive such cross-domain functional coupling risks. The ingenuity of this invention lies in its comparative analysis, which is not limited to isolated fault trees but can examine the combined effects of different message failures at the system level. By combining and examining multiple system-level impacts obtained after mapping within a higher-level fault tree model, it is possible to proactively identify seemingly independent "risk factor combinations" that, when combined, can lead to catastrophic consequences. Once identified, the risk chain can be blocked at the communication link level by prioritizing the network priority of relevant data streams. This is equivalent to endowing the network with a global perspective and risk prediction capabilities, upgrading it from a passive data transmission conduit to a proactive intelligent entity with risk perception and mitigation functions.

[0037] The development of aviation products must adhere to strict airworthiness regulations and safety standards, and any design decision requires compliant evidence of conformity. This invention successfully establishes a clear, standardized, two-way traceability link between the two key areas of network communication design and security analysis. On the one hand, network priority configuration can be directly traced back to fault tree analysis reports and functional hazard assessment conclusions, making it an integral part of the entire system's safety evidence chain, rather than just an isolated network parameter table. On the other hand, network behavior characteristics (such as ensuring deterministic latency for the highest priority messages) also become specific technical means to support the achievement of relevant safety objectives. This deep integration facilitates cross-disciplinary team collaboration, joint review of design inventions, and conformity statements to airworthiness authorities, enabling complex airborne network designs to be more smoothly integrated into and support the entire product's safety lifecycle. During the system architecture design phase, when defining message flows and their security attributes, their network resource requirements must be considered simultaneously. Conversely, the design of network architecture capacity and scheduling mechanisms must also be based on meeting the identified safety-critical data flow requirements. This collaborative design model of "security as a service and network as a guarantee" ensures that security requirements and network capabilities are fully balanced and matched from the early stages, avoiding design iterations, resource waste, or performance compromises that may result from a disconnect between the two. It guides R&D resources to be invested earlier and more precisely in the most critical functional guarantees, improving the robustness and economy of the overall design from the source.

[0038] In some embodiments of this application, the metadata includes at least the message name, the message sending device, the message destination device, and the message end-use device.

[0039] In some embodiments of this application, the pre-constructed fault tree model includes at least an aircraft-level minimal cut set set, a system-level minimal cut set set, a bottom event set, a minimal cut set set, a top event set, and a functional failure level set.

[0040] Specifically, FTA is an abbreviation for Fault Tree Analysis. It is a top-down, deductive method for analyzing system safety and reliability. Its core idea is to start with an undesirable system-level failure or incident (called the "top event") and trace it backwards, breaking it down layer by layer to identify all possible causes (including hardware failures, software errors, human error, environmental factors, etc.) leading to the top event, until the most basic, indivisible cause of failure (called the "bottom event"). The top event, located at the top of the fault tree, represents the most severe consequence or system failure state of interest in the analysis. In your invention, this corresponds to functional failures such as "loss of primary flight control" or "engine shutdown," and is classified into safety levels I to V according to the ARP4761 standard. The bottom event, located at the bottom of the fault tree, represents the fundamental cause of failure that cannot or does not require further decomposition. In this invention, message transmission failures (such as timeouts, loss, and errors) are a specific type of bottom event. Minimal cut set: This is a key quantitative result of the FTA output. It is the most basic, non-simplifiable combination of failure events that can lead to the top event. A "cut set" is a set of basic events; if all of these basic events occur, the top event will inevitably occur. "Minimum" means that if any basic event is removed from this set, the remaining combinations no longer guarantee the occurrence of the top event. Basic information about the message flow can be obtained through metadata, and an index can be built using this basic information to determine who the message is for. The purpose is to locate the relevant information, and based on this location, it helps to find the corresponding analysis node during FTA comparison. During the aircraft design phase, safety engineers have already performed Functional Hazard Analysis (FHA) and Fault Tree Analysis (FTA) for each important function (such as "providing pitch control") according to standards such as ARP4761. When constructing the FTA, analysts decompose it layer by layer until they reach the most basic cause of failure, i.e., the basic events. These basic events include the failure modes of various equipment (or LRUs, Line Replaceable Units). For example, for the "flight control computer" device, its underlying events may include: "permanent CPU failure", "power failure", "failure to receive valid control surface command data", etc. Therefore, by using metadata and fault tree model, the principle is traced back based on network routing and system functional logic. The purpose is to find the device that is ultimately responsible for converting each virtual data stream into an action or state in the real aircraft physical / functional architecture.

[0041] Understandably, traditional methods often rely on textual annotations in design documents or engineers' consensus, lacking an automated and unambiguous path from underlying metadata to the top-level security model. This invention establishes a unique "identity coordinate" and "endpoint" for each message within the physical and functional architecture. This precise index forms a natural interface with the underlying event library in the fault tree model, centered on device failure modes. This allows the communication layer event "message reception failure" to be automatically and accurately located to the corresponding "device input failure" underlying event in the fault tree, which has been rigorously evaluated by security engineering. Therefore, network priority allocation is no longer based on indirect estimation or repeated judgment of data flow security attributes, but directly inherits and utilizes existing analysis conclusions certified by authoritative security processes (such as ARP4761). This is equivalent to building a "security semantic web" on top of the communication network, so that the importance of data no longer requires additional explanation, but is uniquely determined by the mapping result of its own metadata in the security model, improving the directness and fidelity of security policy execution. Previously, when prioritizing massive message streams, even when recognizing the need to consider security impacts, it was difficult to perform refined processing. This invention utilizes the key quantitative tool of "minimum cut sets" pre-built in fault tree models to transform impact analysis into a computable set operation problem. By analyzing which minimum cut sets the underlying events corresponding to message failures belong to, and whether they act alone or in combination with other events within these cut sets, the "contribution strength" and "effect mode" of the failure to various top events (functional failures) can be dynamically calculated. This determination based on set theory and logical relationships ensures that behind the priority assigned to each message stream lies a clear and verifiable "mathematical story," such as whether it is identified as a key factor through contribution calculation or appropriately downgraded due to belonging to a combination of multiple messages. The decision-making process becomes transparent and auditable, completely avoiding vague classifications or subjective trade-offs, ensuring that messages with the same security logic always receive consistent network treatment in different scenarios and by different personnel.

[0042] In some embodiments of this application, when inputting the failure message into a pre-built fault tree model for comparison, the following steps are included: For each failed message, its corresponding bottom event is determined, and in the pre-built fault tree model, the bottom event is traced upwards based on the bottom event and the minimum cut set to determine its corresponding top event set.

[0043] The mapping relationship between each failed message and the bottom event is determined based on the top event set, and the comparison result is determined based on the mapping relationship.

[0044] Understandably, in traditional methods, assessing the impact of a message transmission failure often relies on an engineer's partial understanding of the system architecture and personal experience. This can easily lead to incomplete impact assessments due to cognitive limitations or a singular perspective, focusing only on the most direct and obvious consequences while overlooking indirect or deeper chain reactions. However, the mandatory "upward tracing" logic of the FTA (Fault Tree Analysis) requires starting from each bottom event mapped by the failed message and systematically and exhaustively finding all possible top events triggered by that bottom event using predefined logic gates and minimal cutset networks in the fault tree model. This process is like navigating on a pre-drawn "fault propagation map," ensuring that every possible path of deterioration is retrieved and examined. Human analysis is inevitably influenced by the analyst's knowledge background, experience level, and even current focus, potentially leading to different conclusions for the same failure event at different times or by different personnel. By embedding the analytical logic within the structure and data (minimum cutset set) of the fault tree model, this approach addresses the issue. Once the model is defined, the process of tracing upwards from a specific base event to the set of top events is a deterministic logical reasoning or set operation that can be rigorously executed by an algorithm. Regardless of when or where it is executed, as long as the input is the same (the same base event), the same model will output the exact same set of top events. This eliminates subjective arbitrariness in the assessment process, making security impact assessment a stable, reliable, and predictable technical activity, providing a solid and consistent factual basis for subsequent prioritization decisions. Modern complex systems have intricate internal relationships; a failure at one point can spread along non-intuitive paths. Simple linear thinking cannot handle this complexity. Fault tree models and their minimum cut sets are essentially encoded expressions of system vulnerability patterns. The process of tracing upwards and forming the "set of top events" is precisely the process of decoding and revealing the encoded information. It can automatically reveal whether a seemingly ordinary communication failure is a common premise of multiple high-risk failure scenarios, or whether it will combine with other seemingly unrelated failures to form a greater threat.

[0045] In some embodiments of this application, determining the severity of message invalidation based on comparison results includes: Based on the set of top events, determine whether the bottom events corresponding to the message failure independently constitute a minimal cut set of the top events.

[0046] When the underlying events corresponding to a message failure can individually constitute a minimal cut set of the top event, the severity of the failure is determined based on the message failure.

[0047] In some embodiments of this application, when determining the severity of message invalidation based on the comparison results, the method further includes: When the underlying event corresponding to a message failure cannot form a minimal cut set of the top event on its own and must be combined with a non-message-type failed underlying event to form a minimal cut set of the top event, the severity is determined based on the contribution of the message failure to the occurrence of the top event.

[0048] In some embodiments of this application, when determining the severity of message invalidation based on the comparison results, the method further includes: When the minimum cut set of the top event consists only of the combination of multiple message failures corresponding to the bottom events, its final severity is determined by reducing the severity by one level based on the severity of its corresponding top event.

[0049] Specifically, let C be the input message stream, and let C be the messages it contains. ,but Where i represents the number of messages in the message stream, the message is mapped to the final user device according to the final user table, and the final user device is mapped to the system FTA event. Assuming the message... The failure corresponding to the underlying event is represented as ,information The top event corresponding to the failure is Its minimal cut set is The formula for determining the message invalidity level is as follows: Directly led to the top event:

[0050] (where Ψ is) Minimal cut set, In this formula, the independent underlying event corresponds to message failure. Combination with non-message failures: When there is no independent bottom event corresponding to message failure in the bottom events of the fault tree, only When a combination of non-message-invalidated bottom events causes the top event to occur:

[0051] δ is Contribution in the minimum cut set of FTA: , in, for The number of minimum cut sets for all corresponding FTAs For inclusion The minimum number of cut sets.

[0052] Combination with message failure: When there is no independent bottom event corresponding to message failure in the bottom events of the fault tree, only When the combination of bottom events leads to the occurrence of the top event: , This invention proposes a contribution factor for message failures in composite scenarios using a dynamic algorithm, replacing the traditional static level inheritance. It also defines failure level degradation rules to prevent high-risk failures from being underestimated.

[0053] Understandably, by clearly distinguishing between different failure modes such as "directly caused" and "combined caused," and applying differentiated judgment rules, the accuracy of identifying the essential attributes of risks and the specificity of assessment are improved, reducing resource misallocation and risk misjudgment caused by "one-size-fits-all" treatment. Traditional methods often treat all causes that trigger the same top event equally, ignoring the fundamental differences in the nature of risks among different failure paths. This invention captures single-point fatal risks by identifying whether message failures "independently constitute" a minimal cut set. This failure mode means that the unimpeded flow of the message is an absolute necessity for the functional safety of the system, and its failure has the highest urgency and severity. Assigning such messages the highest severity level, equivalent to their top event, ensures that network resources can be concentrated on protecting the most vulnerable links without compromise, thereby improving the accuracy of identifying and responding to the highest level of risks. Conversely, for failures that must be combined with other factors to constitute a risk, it avoids overreacting to non-single-point failures, allowing valuable network resources to be allocated more rationally. Secondly, the "contribution" factor calculation represents a profound shift in security impact assessment from "qualitative attribution" to "quantitative contribution," enhancing the scientific rigor and fairness of priority allocation decisions and reducing assessment distortion caused by ignoring failure probabilities and path diversity. In scenarios involving "combinations with non-message-related failures," it is unreasonable to assign the same level to all participating bottom events, as different bottom events exhibit varying frequencies and importance among the numerous possible paths leading to the top event. This invention quantifies the "responsibility weight" of a message failure in triggering a specific functional failure by defining a contribution factor δ, which is the proportion of the number of cut sets where the message failure bottom event occurs to the total number of cut sets. When δ=1, it means that the message failure appears in all possible failure combinations and is an absolutely critical factor, with a severity equivalent to the top event. When δ<1, it indicates the existence of other failure paths independent of the message failure, and their impact is correspondingly reduced. This dynamic quantification mechanism improves the precision and rationality of the assessment, enabling priorities to truly reflect the actual weight of the message flow in the system's security risk structure, rather than simply inheriting a potentially overestimated static label. When a top event is triggered by the simultaneous failure of multiple messages, a mandatory degradation process is applied to all related message failures. In the absence of other non-message-related failures, a single message failure is not sufficient to pose a direct threat; the risk only materializes when multiple specific communication links collapse simultaneously. Therefore, compared to failures that can individually cause disasters, the individual criticality of such messages is relatively low. Systematic degradation avoids overestimating the individual risks in collaborative failure scenarios and prevents the excessive distribution of high-priority resources across a large number of message flows that require "collusion" to constitute a threat. This ensures that network assurance capabilities can be more focused on truly vulnerable single points of failure.The overall judgment logic integrates deterministic rules (direct causes, pure message combinations) with semi-quantitative analysis (contribution calculation), improving the transparency, interpretability, and verifiability of the entire priority derivation process, and reducing the trust costs and compliance risks caused by the black box nature of the decision-making process. The severity level ultimately obtained for each message stream can be clearly explained by tracing its corresponding fault tree structure, minimum cut set composition, and contribution value. This traceability not only facilitates self-inspection and optimization by designers but also provides convenience for independent review and verification.

[0054] In some embodiments of this application, when determining the severity of message invalidation based on the comparison results, the method further includes: The top events are combined to determine their system-level minimal cut set, and compared with the aircraft-level minimal cut set. When the top event corresponding to the message failure exists in the aircraft-level minimal cut set, the final severity is determined based on the severity of the top event corresponding to the combination.

[0055] Specifically, the results of the FTA process are examined at the aircraft level, for any issues that exist. If a combination of factors leads to a higher-level aircraft-level FTA top event, the impact level is calculated as follows:

[0056] Where Ψ is Rather than causing an aircraft-level top event Minimal cut set, The impact level of message failure, The failure level is defined as follows: when a message fails, the corresponding device can be identified, and this device belongs to the system-level minimum cut set. In other words, the top event at the system level is the bottom event at the aircraft level, and its severity is ultimately judged.

[0057] Understandably, in highly integrated systems, a fault within a single subsystem (such as system-level functional degradation caused by communication failure) may be assessed and controlled. However, when this fault combines with seemingly unrelated faults or states in other subsystems, it can trigger a higher-level, more severe overall failure along an unexpected path. Traditional analysis methods based on isolated fault trees, due to their analysis boundaries typically limited to specific systems or functions, struggle to proactively capture such risk coupling effects that cross these boundaries. This invention constructs a risk coupling detector by forcibly comparing the combined results of different system-level top events with the "aircraft-level minimal cut set set," representing the overall safety status of the aircraft. It automatically reveals how independent faults, assessed as lower-level or accepted within their respective subsystems, interact to form entirely new and more dangerous threat patterns. This is equivalent to equipping safety analysis with a "wide-angle lens" and a "combination lens," enhancing insight into the nonlinear superposition and evolution of risks, shifting the focus of safety work from preventing only "known single faults" to preventing "unknown combinations of faults," thus advancing the concept of safety protection. The achievement of security objectives relies on a hierarchical design guarantee. If lower-level designs (such as network scheduling) only take the requirements of their direct superiors (such as system functions) as input, ignoring that these superior requirements may only be a component or triggering condition of higher-level objectives, then the safeguards may meet local requirements but be insufficient at the global level. When it finds a combination of system-level failures that satisfies the aircraft-level minimum cut set condition, it directly elevates the severity level of the affected lower-level message failure to the level of the aircraft-level top event it contributes. This means that the setting of network priorities not only considers the direct impact of the message on a certain system function, but also proactively incorporates the final "seat" and weight of this impact in the overall aircraft-level security landscape. This bottom-up, consistent impact tracing ensures that even the lowest-level design decisions (such as the priority of a message) are strongly correlated with the highest-level security objectives they carry, improving the logical consistency and goal alignment of the overall security architecture. During system operation, different subsystems may be in various normal or degraded states. Traditional static priority configurations are difficult to dynamically respond to the risk changes implied by these state combinations. By pre-prioritizing message flows at these "risk-coupled hubs," the network is essentially injected with "immune memory" against specific combinations of high-risk states. When early signs of such combinations appear during system operation (even if each individual sign seems insignificant), the network has already provided reinforced transmission safeguards for its critical information exchange links, potentially preventing the further propagation of the risk chain. This enhances the network's proactive role as an enabler of systemic risk mitigation, transforming it from a mere service provider into an intelligent infrastructure with a certain degree of risk foresight and proactive defense capabilities.

[0058] In some embodiments of this application, see Figure 2 As shown, when determining its severity level based on severity, it includes: The severity levels include Level I, Level II, Level III, Level IV, and Level V.

[0059] When the severity level is equivalent to personnel death or system failure, it is classified as Level I.

[0060] When the severity level is serious injury to personnel, a few deaths, or severe damage to the system, it is classified as Level II.

[0061] When the severity level is minor personal injury or minor system damage, it is classified as Level III.

[0062] When the severity of personal injury and system damage is less than Level III, it is classified as Level IV.

[0063] When the severity level is such that it has no impact on personnel or the system, it is classified as Level V.

[0064] Understandably, this grading system transforms the abstract concept of "safety" into a concrete and clearly hierarchical ethical and engineering consensus principle directly linked to human life, health, and asset value. This significantly enhances the clarity of the value of safety objectives and the indisputability of their priority ranking. In complex engineering systems, discussions of "safety" often tend to become abstract. By defining Level I as "personnel death or system failure," with Levels II through IV corresponding to decreasing degrees of harm and damage, down to Level V's "no impact," a value ranking system is successfully established. This forces any technical failure analysis to ultimately be measured on this scale, from "catastrophic" to "negligible." This metric possesses inherent moral weight and intuitive consistency, compelling design decisions to explicitly answer: which level of unacceptable consequences does a potential failure place us on, eliminating potential value disputes regarding priority ranking. This classification scheme improves the interoperability, comparability, and inheritability of security assessment results across different systems, projects, and even organizations. It reduces communication barriers and integration risks caused by ambiguous custom classifications or descriptions. When security levels are defined as project-specific or loosely described (e.g., using only "high," "medium," or "low"), analysis results delivered by different teams or vendors are difficult to directly compare and integrate. The five-level classification and its specific consequences, clearly defined in this invention, form a universal "security language." An analysis report indicating a failure mode as "Level II" can be accurately understood by any engineer, auditor, or manager familiar with this standard framework, without requiring additional explanation.

[0065] In some embodiments of this application, determining network priority based on severity level and / or the number of messages reaching the corresponding severity level includes: When the severity of the message stream set is Level I, its network priority is determined to be 7.

[0066] When multiple message failures in a message stream set have an impact level of II, their network priority is determined to be 6.

[0067] When there is only one highest failure in the message flow set and the message failure impact is level II, its network priority is determined to be 5.

[0068] When multiple message failures in a message stream set have an impact level of III, their network priority is determined to be 5.

[0069] When the highest failure in the message flow set is only one message failure with a failure impact level of III, its network priority is determined to be 4.

[0070] When multiple message failures in a message stream set have an impact level of IV, their network priority is determined to be 3.

[0071] When there is only one highest failure in the message flow set and the message failure impact level is IV, its network priority is determined to be 2.

[0072] When the message failure impact in the message flow set is level V, its network priority is determined to be 0 or 1.

[0073] Specifically, for ease of formula calculation, the message failure impact level is... With functional failure level Assign values ​​according to the following criteria: Class I = 5, Class II = 4, Class III = 3, Class IV = 2, Class V = 1. When a value of 0 appears in the calculation, it is calculated as 1.

[0074] The priority allocation formula is as follows:

[0075] Where step function for:

[0076] The highest priority message in the message stream is:

[0077] In the above formula, For the i-th message, For the message The fault tree base event corresponding to the failure. This is the top event of a system functional failure. To cause the top event The set of all minimal cut sets that occur. Top event The total number of corresponding minimal cut sets. In order to be in In all minimal cut sets, those containing the bottom event The number of minimum cut sets, This is considered a top-level event of an aircraft-level functional failure, with a severity greater than or equal to that of a system-level top-level event. For aircraft-level top events The severity level, its numerical rules and same, To cause the aircraft-level top incident The set of all minimal cut sets that occur. The network priority ultimately assigned to message stream C is output as an integer from 0 to 7 as defined by the TSN standard, where C is a message stream, i.e., a collection of messages. , This represents the highest impact level value for all message failures in message flow C. Let C be the set of impact levels of all message failures. For the message The impact level of the failure, i.e. , In message flow C, the impact level has reached the highest level. The number of messages.

[0078] In summary, the beneficial effects of this invention are as follows: 1. By using fault tree analysis, an authoritative security engineering model, as input and criterion, the network priority obtained by each data stream is derived from a precise assessment of its degree of harm to system functionality. This means that the network is no longer a pure communication carrier independent of security considerations, but has evolved into an infrastructure that proactively implements security strategies. The urgency of transmission protection directly reflects the catastrophic or minor impact of functional failures, thereby constructing the first proactive, security-critical resource barrier at the communication link layer. This substantially extends security design principles down to the bit-level transmission process, improving the scientific, precise, and objective nature of priority allocation decisions and reducing inconsistencies and potential risks caused by subjective experience judgments.

[0079] 2. General priority classifications are often broad, such as placing all "control flows" at a high level, failing to distinguish the vast differences in the security importance of different data flows within the same category. This invention, through contribution quantification analysis and a combined impact judgment mechanism, achieves dynamic assessment of failure impact. It can not only distinguish between "single-point fatal failure" and "multi-point common-cause failure," but also quantify the "responsibility weight" of a message failure in various possible paths leading to system failure by calculating its participation in the minimum cut set of the fault tree. The model-derived quantitative output replaces static empirical assignment, making priority allocation no longer a rough "one-size-fits-all" division, but a precise profile reflecting the inherent vulnerability structure of the system.

[0080] 3. By comparing across fault tree models, the system proactively explores the potential dangerous synergistic effects between message failures in different subsystems. This allows for the early detection and warning of "hidden risks" that may appear individually harmless but, when combined, could lead to catastrophic consequences. These risks can then be blocked by proactively prioritizing relevant data flows in network scheduling strategies. This essentially gives the network a "visionary eye" to predict and defend against systemic risks, elevating security design from addressing "known single failures" to preventing "unknown abnormal combinations." This enhances system resilience, improves the ability to identify and mitigate hidden risks within complex systems, particularly cascading failure risks, and reduces the likelihood of being unaware of or overlooking such risks.

[0081] 4. In high-security domains, design decisions must be grounded in clear logical threads and supported by sufficient verification evidence. This invention provides a standardized input, processing, and output process. Each step of this transformation—from message to device, from device failure to event, from event contribution to impact level, and finally to priority mapping—is based on explicit models and algorithmic rules. This ensures that the final priority configuration table is not merely isolated network parameters, but a complete chain of derived requirements that can be traced back to top-level security requirements and linked to specific transmission mechanisms. This facilitates design review, security verification, and airworthiness certification processes, enabling network design to be embedded in and strongly support the entire system's security verification framework, reducing design blind spots and certification barriers caused by domain gaps.

[0082] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program goods. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program goods embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0083] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program goods according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0084] These computer program instructions may also be stored in a computer-readable storage device that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable storage device produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0085] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0086] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A method for prioritizing data streams in an airborne time-sensitive network, characterized in that, include: Obtain a time-sensitive network message stream set, wherein the message stream set contains metadata for each message; The message usage device table for each message is obtained based on the metadata. Determine the reception status of each message; When message reception fails, the failed message is input into a pre-built fault tree model for comparison. The severity of message failure is determined based on the comparison results, and its severity level is determined based on the severity. Network priority is determined based on the severity level and / or the number of messages that reach the corresponding severity level.

2. The airborne time-sensitive network data stream priority classification method according to claim 1, characterized in that, The metadata includes at least the message name, the device that sent the message, the device that sent the message, and the device that ultimately used the message.

3. The airborne time-sensitive network data stream priority classification method according to claim 2, characterized in that, The pre-built fault tree model includes at least the aircraft-level minimum cut set set, the system-level minimum cut set set, the bottom event set, the minimum cut set set, the top event set, and the functional failure level set.

4. The airborne time-sensitive network data stream priority classification method according to claim 3, characterized in that, When inputting failure messages into a pre-built fault tree model for comparison, the following are included: Based on each failed message, its corresponding bottom event is determined, and in the pre-built fault tree model, the bottom event is traced upwards based on the bottom event and the minimum cut set to determine its corresponding top event set; The mapping relationship between each invalid message and the bottom event is determined based on the top event set, and the comparison result is determined based on the mapping relationship.

5. The airborne time-sensitive network data stream priority classification method according to claim 4, characterized in that, When determining the severity of message failure based on comparison results, the following are included: Based on the set of top events, determine whether the bottom events corresponding to the message failure independently constitute a minimal cut set of the top events; When the bottom event corresponding to the message failure can form a minimal cut set of the top event on its own, the severity of the message failure is determined based on the message failure.

6. The airborne time-sensitive network data stream priority classification method according to claim 5, characterized in that, When determining the severity of message invalidation based on the comparison results, the following also applies: When the underlying event corresponding to the message failure cannot constitute a minimal cut set of the top event on its own and must be combined with a non-message failure underlying event to constitute a minimal cut set of the top event, the severity is determined based on the contribution of the message failure to the occurrence of the top event.

7. The airborne time-sensitive network data stream priority classification method according to claim 6, characterized in that, When determining the severity of message invalidation based on the comparison results, the following also applies: When the minimum cut set of the top event consists only of the combination of multiple message failures corresponding to the bottom events, its final severity is determined by reducing the severity level by one level based on the severity level of its corresponding top event.

8. The airborne time-sensitive network data stream priority classification method according to claim 7, characterized in that, When determining the severity of message invalidation based on the comparison results, the following also applies: The top events are combined to determine their system-level minimal cut set, and compared with the aircraft-level minimal cut set. When the top event corresponding to the message failure exists in the aircraft-level minimal cut set, its final severity is determined based on the severity of the top event corresponding to its combination.

9. The airborne time-sensitive network data stream priority classification method according to claim 8, characterized in that, When determining its severity level based on the aforementioned severity, the following are included: The severity levels include Level I, Level II, Level III, Level IV, and Level V; When the severity level is equivalent to personnel death or system failure, it is classified as Level I; When the severity level is serious injury to personnel, a few deaths, or serious damage to the system, it is determined to be Level II; When the severity level is minor personal injury or minor system damage, it is classified as Level III; When the severity level is less than Level III for both personal injury and system damage, it is classified as Level IV. When the severity level is deemed to have no impact on personnel or the system, it is classified as Level V.

10. The airborne time-sensitive network data stream priority classification method according to claim 9, characterized in that, When determining network priority based on the severity level and / or the number of messages reaching the corresponding severity level, the following methods are included: When the severity of the message stream set is level I, its network priority is determined to be 7; When multiple messages in the message stream set fail and are classified as Level II, their network priority is determined to be 6. When there is only one highest failure in the message flow set and the impact of the message failure is level II, its network priority is determined to be 5; When multiple messages in the message stream set fail and are classified as Level III, their network priority is determined to be 5. When there is only one message failure in the message flow set with a failure impact level of III, its network priority is determined to be 4; When multiple messages in the message stream set fail and are classified as Level IV, their network priority is determined to be 3. When there is only one highest failure in the message flow set and the impact of the message failure is level IV, its network priority is determined to be 2; When the message failure impact in the message stream set is level V, its network priority is determined to be 0 or 1.

Citation Information

Patent Citations

  • Low-delay high-certainty industrial protocol conversion architecture and algorithm

    CN119155358A